å瀟ã®ããŒã¿ããŒã¹çé£ãé«åºŠãªæç¶çè åšãå©çšããç£æ¥ã¹ãã€ãéèŠãªããŒã¿ã®ã©ã³ãµã ãŠã§ã¢ã«ãã人質ã®åç· ãã«é¢ããè±å¯ãªã¬ããŒãã«é¢é£ããŠãæ å ±ã»ãã¥ãªãã£ã®åéã§å€ãã®äººãäºé²æªçœ®ãæŸæ£ãå§ããçç±ãæããã«ãªããŸãããè åšãç¹å®ããç·æ¥äºæ ã«ã¿ã€ã ãªãŒã«å¯Ÿå¿ããããšã«çŠç¹ãåœãŠãŸãã
ææ°ã®ä¿è·ã·ã¹ãã ã®åºæ¬ã¯ããã©ãã¯ãªã¹ããã§ãã ãã ããã·ã°ããã£ãšIPã¬ãã¥ããŒã·ã§ã³ãªã¹ããåæãããŠã€ã«ã¹å¯Ÿçã·ã°ããã£ã¯ããã©ãã¯ãªã¹ãããŒã¹ã®ãã¯ãããžãŒããã§ã«å¹æããªãããšãäŸã§ç€ºããŠããŸãã çµå±ã®ãšãããæ»æè ã¯IPãå€æŽããããæ°ããå®è¡å¯èœãã¡ã€ã«ãäœæãããããå¿ èŠã¯ãããŸããã ãã ããå€ãã®äŒæ¥ã¯ãããã¯ãŒã¯ã®æ¡åŒµãç¶ããŠããããã®ã»ãã¥ãªãã£ã¯ãã©ãã¯ãªã¹ãã«å®å šã«äŸåããŠããŸãã ãããŠãè åšã®ç¹å®ãšã¿ã€ã ãªãŒãªå¯Ÿå¿ã®åéãžã®åªåã®ç§»è»¢ã¯ãã»ãšãã©ã®æ»æã確å®ã«ãããã¯ããæ¹æ³ãåŠã¶ãŸã§ç¶æ³ãæ¹åããå©ãã«ã¯ãªããŸããã ããã«ãIPv4ã¢ãã¬ã¹ç©ºéã®æ¯æžã«é¢é£ããŠãæ°åã®ç°ãªããã¡ã€ã³ãã³ã³ãã³ãé ä¿¡ãããã¯ãŒã¯ïŒCDNïŒãä»ããŠåãã¢ãã¬ã¹ã䜿çšã§ãããããIPã¢ãã¬ã¹ã®ãã©ãã¯ãªã¹ããã³ã³ãã€ã«ããã³ç¶æããããšã¯éåžžã«å°é£ã§ãã
倧ããªæ倱ãåŒãèµ·ãããŠã€ã«ã¹ã®é¡èãªäŸã¯CryptoLockerã§ãã éåžžãã¢ãŒã«ã€ããããå®è¡å¯èœãã¡ã€ã«ãå«ããã£ãã·ã³ã°ã¡ãŒã«ã§é åžãããŸãã èµ·åãããšãã¢ããªã±ãŒã·ã§ã³ã¯çŸåšã®WindowsãŠãŒã¶ãŒãããã¡ã€ã«ã®Application Dataãã©ã«ããŒã«èªèº«ãã€ã³ã¹ããŒã«ããŸãã 次ã«ãããã€ã®æšéŠ¬ã¯ãªã¢ãŒã管çãµãŒããŒã«ã¢ã¯ã»ã¹ããæå·ããŒãèŠæ±ããå°éå¯èœãªã³ã³ãã¥ãŒã¿ãŒäžã®ãã¹ãŠã®ããŒã¿ãæå·åããŸãã ãã®åŸã埩å·åããŒãæäŸããããã®éã®åŒ·èŠãå§ãŸããŸãã 被害è ãæ¯æããæãŸãªãããŸãã¯æ¯æãããšãã§ããªãå Žåãããã¯ã¢ããããããŒã¿ã埩å ããå¿ èŠããããŸãã ãŠã€ã«ã¹ã®äœæè ã¯ãå®è¡å¯èœãã¡ã€ã«ã®æ°ããããŒãžã§ã³ãè¿ éã«çæããããã®ããŒã«ãåŠçããŸãããããã«ããããã¹ãŠã®çœ²åããŒã¹ã®æ€åºã·ã¹ãã ãç¡å¹ã«ãªããŸãã ãããŠãæ°ããæªæã®ãããã€ããŒããçæããããšã¯ã»ãšãã©äŸ¡å€ããããŸããã
CryptoLockerã«å¯ŸåŠããå¹æçãªæ¹æ³ã¯ããŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒäžã®ã¢ããªã±ãŒã·ã§ã³ã®ãã¯ã€ããªã¹ãã䜿çšããããšã§ãã ã¢ããªã±ãŒã·ã§ã³ãä¿¡é ŒãããŠããªãå Žåããã®å®è¡ã¯èš±å¯ãããŸããã æ®å¿µãªãããã»ãšãã©ã®å®è£ ã¯ããŸãã«ãäžå¿«ã§éãããšãå€æããŠããããããã®ã¢ãããŒãã¯ããŸã人æ°ããããŸããã äžæ¹ã§ã¯ãWindowsã®ãã¹ãŠã®äŒæ¥ããã³ãµãŒããŒããŒãžã§ã³ã«ã¯ãœãããŠã§ã¢å¶éããªã·ãŒãŸãã¯AppLockerããããããäŒæ¥ã®ãœãããŠã§ã¢ã®è¿œå ã³ã¹ãã¯ç¡èŠã§ããŸãã ãã ãããã¯ã€ããªã¹ãç»é²ã¡ã«ããºã ãå®è£ ããã«ã¯æéãšåŽåãè²»ããå¿ èŠããããŸãã ãããããã®ãµããŒãã®è²»çšã¯ããææãåŸã®å埩ã®è²»çšãè¶ ããŸããã ãããŠæãéèŠãªããšãšããŠããã¯ã€ããªã¹ãã¯ã»ãã¥ãªãã£äŸµå®³ã®ãªã¹ã¯ãç¹°ãè¿ã軜æžããŸãã
ãã¯ã€ããªã¹ãã¯ã Tripwire以æ¥é¡èã«é²åããŠããŸãã ããšãã°ãéçããã·ã¥ã¯å€æŽãèå¥ããããã«äœ¿çšãããŸãã AppLockerãªã©ã®æ°ãããœãªã¥ãŒã·ã§ã³ã§ã¯ã眲åããã¡ã€ã«ããã·ã¥ãããã³ãã¹ã«ãŒã«ã䜿çšããŠãããæè»ãªã«ãŒã«ãäœæã§ããŸãã ããšãã°ã眲åã䜿çšãããšãç¹å®ã®ããŒãžã§ã³ããå§ãŸãã¢ããªã±ãŒã·ã§ã³ããã¯ã€ããªã¹ãã«ç»é²ã§ããä»ã®ãã¹ãŠã®ãªãªãŒã¹ã¯èŠå®ã®ããªã·ãŒãç¶æ¿ããŸãã
é 眮ãã¹ã®å¶åŸ¡ã¯ãããã·ã¥ããããªãã·ã£ãŒã®å¶åŸ¡ã»ã©æè¡çã«ã¯å¹æçã§ã¯ãããŸãããããã¯ã€ããªã¹ãã¯ç®¡çè 以å€ã®ã¢ã«ãŠã³ãããç·šéã§ããªããããæ»æè ã®äœæ¥ã¯äŸç¶ãšããŠè€éã§ãã æ»æè ã¯ãèªåã®ãè¯ããã¢ããªã±ãŒã·ã§ã³ãè£ ã£ãŠãŠãŒã¶ãŒãjustãããšã¯ã§ããŸãã;ç¹æš©ã®è»¢éã®è匱æ§ãæªçšããå¿ èŠããããç®æšãéæããã®ãé£ãããªããŸãã ããã«ããããªãã·ã£ãŒãšãã¬ãŒã¹ã¡ã³ããã¹ãå¶åŸ¡ããããšã§ãé±æ«ã®ãµããŒãããŒã ã¯ããã¯ã€ããªã¹ãã«ç»é²ããã«ãã¹ãŠã®æéå€å€åã¢ããªã±ãŒã·ã§ã³ã«å¯ŸåŠã§ããŸãã ãŸããã¯ã©ã€ã¢ã³ããã·ã³ãäŒæ¥ãããã¯ãŒã¯ã«å ¥ããšããã«ãVPNã«ããããªã¢ãŒããŠãŒã¶ãŒåãã«æºåãããæ°ããã¢ããªã±ãŒã·ã§ã³ã®ããªã·ãŒãæŽæ°ã§ããŸãã
ææè²»çš
ããã€ãã®åçŽãªãŠã€ã«ã¹ã«ããææããå埩ããã³ã¹ããèæ ®ããŠãã ããã ã»ãšãã©ã®äŒæ¥ã¯ãææããã³ã³ãã¥ãŒã¿ãŒãä¿¡é Œã§ãããšèŠãªãããšãã§ããªããªã£ããããã€ã¡ãŒãžããã·ã¹ãã ãåã€ã³ã¹ããŒã«ããå¿ èŠããããšèããŠããŸãã ããšãã°ã System Center Configuration Managerã䜿çšããŠã€ã¡ãŒãžãäœæã§ããŸãã ææããã³ã³ãã¥ãŒã¿ãŒããããŒã¿ãã³ããŒããæž æœãããã§ãã¯ããç»åããã·ã¹ãã ãããŒãªã³ã°ããã³ã³ãã¥ãŒã¿ãŒã«ããŒã¿ãã¢ããããŒãããæè¡å°é家ãšæçµãã§ãã¯ãè¡ãã«ã¯ãå°ãªããšã2æéããããŸãã ãã®æç¹ã§ãŠãŒã¶ãŒã«ããã¯ã¢ããã©ããããããæäŸãããŠããŠãã亀ææéã¯ãããã倱ãããŸãã ãããŠã埩å ããããã·ã³ã圌ã«è¿ããããšãäžæçãªæ倱ãçºçããã·ã¹ãã ããŠãŒã¶ãŒã«éŠŽæã¿ã®ããç¶æ ã«ãªããŸãã æè¡è ã®1æéã¯25ãã«ããŠãŒã¶ãŒã®1æéã¯50ãã«ã ãšããŸãã 埩å ã®ç·è²»çšã¯çŽ150ãã«ã«ãªããŸããããã¯ãã€ã¡ãŒãžãã埩å ããããã®ã€ã³ãã©ã¹ãã©ã¯ãã£äœæ¥ã®è²»çšãã«ãŠã³ãããããã®ä»ã®èããããæ害ãæé€ããŸãã ãŠãŒã¶ãŒã«ããã¯ã¢ããã©ããããããæäŸãããšããŠã³ã¿ã€ã ãççž®ã§ããŸããããããã®å Žåã§ãããã¡ã€ã«ãšããŒã¿ã®äº€æã転éãããã³ã©ããããããžã®å¿ èŠãªãœãããŠã§ã¢ã®ã€ã³ã¹ããŒã«ã®æé ã«ãããããã©ãŒãã³ã¹ãäœäžããŸãã
800人ã®åŸæ¥å¡ãæ±ããäŒç€Ÿã®ä¿®åŸ©è²»çšã®æ¯èŒè¡šïŒ
è²»çšã¿ã€ã | ãã¯ã€ããªã¹ããªã | ãã¯ã€ããªã¹ãä»ã |
---|---|---|
ã€ã¡ãŒãžããã®å埩ã®æ°ãšã«ãŒã«ã®æ° | æ¯é±1-2å°ã®ã³ã³ãã¥ãŒã¿ãŒã埩å ããå¿ èŠããããŸã | æ¯é±ã2ã3åã®æ°ããã¢ããªã±ãŒã·ã§ã³ã調æ»ãããããã®ã«ãŒã«ãäœæããå¿ èŠããããŸãã |
ã€ã³ã·ãã³ããããã®ã³ã¹ã | ã³ã³ãã¥ãŒã¿ãŒã®åŸ©æ§ã«50ãã« | ã·ã¹ãã 管çè ã®1æéã®äœæ¥ã«å¯ŸããŠ50ãã« |
æ§èœäœäž | $ 50ä¿çäžã®ãŠãŒã¶ãŒããã¯ã¢ãã | ãŠãŒã¶ãŒãã¢ããªã±ãŒã·ã§ã³ããã¯ã€ããªã¹ãã«ç»é²ããã®ãåŸ ã€25ãã« |
幎éè²»çš | 5,200ã10,400ãã«ãæ·±å»ãªã»ãã¥ãªãã£äŸµå®³ã®é«ããªã¹ã¯ã¯èæ ®ãããŠããŸãã | 5,200ã6,800ãã« |
ãŠã€ã«ã¹ãéèŠãªããŒã¿ã«å°éããå Žåãã³ã¹ãã¯å€§å¹ ã«å¢å ããŸãã ã³ã³ãã¥ãŒã¿ãŒãã©ã¬ã³ãžãã¯ã¯ã1æéãããæ°çŸãã«ãããå ŽåããããŸãã 倧èŠæš¡ãªæ»æäžã«é »ç¹ã«çºçãããããã¯ãŒã¯å šäœã䟵害ãããå Žåãä¿¡é Œã§ããæ€æ»ã¯100,000ãã«ãè¶ ããããšããããŸãã2014幎ã®ããŒã¿ãªãŒã¯ã®å¹³åã³ã¹ãã¯çŽ350äžãã«ã§ãããããã¯ãã¹ãŠã®äŒæ¥ãªãŒããŒã«ãšã£ãŠæªå€¢ã§ãã
ãã¯ã€ããªã¹ãäŸ¡æ Œ
ããã§ãäž»ãªè²»çšã¯ãã·ã¹ãã 管çè ãã¢ããªã±ãŒã·ã§ã³ããã¯ã€ããªã¹ãã«ç»é²ããã®ã«ãããæéã«äŸåããŸãã çµ±èšã«ãããšã1ã€ã®ã¢ããªã±ãŒã·ã§ã³ã®æèŠæéã¯30åæªæºã§ãã ãã®æç¹ã§ãŠãŒã¶ãŒãåŸ ããªããã°ãªããªãå Žåãäœæ¥ã³ã¹ãã¯2åã«ãªããŸãã ãããããã®å Žåã§ããææåŸã®æãåçŽãªå埩ã«æ¯ã¹ãŠååã®äŸ¡æ Œã§ããããšãããããŸããã ããã«ãããŒã¿æŒæŽ©ã®ãªã¹ã¯ãããã«è€æ°åæžããŸããããã¯ããã¯ã€ããªã¹ãã䜿çšããã³ã¹ãã®ååãšèŠãªãããšãã§ããŸãã
è¡šã«ç€ºãããŠãã幎éã³ã¹ãããŒã¿ã¯ããã¯ã€ããªã¹ãã®å°å ¥ååŸã«ã¢ãŒãã³ããŒãªã³ã°ãšã«ã€ã«ãµã«ã¹ãåããŠããäŒç€Ÿã§çºçããã€ã³ã·ãã³ãã®çµ±èšã«åºã¥ããŠååŸãããŸããã ãã®ITç°å¢ã®ã³ã³ããã¹ãã§ã¯ããã¯ã€ããªã¹ããç¶æããã³ã¹ãã¯ææããå埩ããã³ã¹ããè¶ ããããªã¹ã¯ã¯ã¯ããã«äœããªããŸãã
ãŸãããã¹ãŠã®èšç®ã¯ãåãå ¥ããããäœæ¥ããã»ã¹ãšãã®äŒç€Ÿã®å ±é ¬ã¬ãã«ã«åºã¥ããŠè¡ãããããšã«ã泚æããŠãã ããã ãããããããªãã®çµç¹ã§ã¯ããã¯ã€ããªã¹ããç¶æããã³ã¹ãã¯åŸ©å ã®ã³ã¹ãããã¯ããã«å°ãªãã§ãããã ããã«ãæãéèŠãªããŒã¿ãæäœããå ŽåãæãéèŠãªé åã§ã®ã¿ãã¯ã€ããªã¹ãã®äœ¿çšã劚ãããã®ã¯ãããŸããã ããããæãéèŠãªããšã¯ã³ã¹ããæ¯èŒããããšã§ã¯ãªãããªã¹ã¯ãæžããããšã§ãã ãã¯ã€ããªã¹ãã®äž»ãªå©ç¹ã¯ããµããŒãã®ã³ã¹ãããè©å€ããŒã¿ãå«ãéèŠãªããŒã¿ã®æŒæŽ©ã«ããæ倱ã®å¯èœæ§ãšæ¯èŒã§ããªãããã§ãã
ãã¯ã€ããªã¹ããå®è£ ãã
ããªã¹ã¯ãå°å£²åºã®ç«¯æ«ãªã©ããã£ãã«æŽæ°ãããªãã·ã¹ãã ã®å ŽåãããŽãŒã«ãã³ãã€ã¡ãŒãžã«åºã¥ããŠéå®çãªAppLockerããªã·ãŒãé©çšã§ããŸãã ãã®ã€ã¡ãŒãžã«ããã¢ããªã±ãŒã·ã§ã³ã®ã¿ãå®è¡ã§ããŸãã ããåçãªã·ã¹ãã ã§ã¯ã管çè ã®ã¿ãå ¥åã§ãããã©ã«ãããã®ã¿å®è¡ããèš±å¯ã䜿çšããŠãæšæºã«ãŒã«ãšç®¡çè æš©éã®å¶éãçµã¿åãããããšãã§ããŸãã ãããªãã·ã£ãŒå¶åŸ¡ã®å©ããåããŠãã«ãŒã«ã®æè»æ§ãé«ããããšãã§ããŸããã€ãŸããä¿¡é Œã§ãããã³ããŒã«ãã£ãŠçœ²åãããã¢ããªã±ãŒã·ã§ã³ã®ã¿ãå®è¡ããŸãã ããã¯ãã¡ããäžèœè¬ã§ã¯ãªãããã®ã·ã¹ãã ã«ã¯ç¬èªã®è匱æ§ããããŸãã ããšãã°ãã¹ã¯ãªããèšèªãŸãã¯ãœãããŠã§ã¢ã®ãšã¯ã¹ããã€ãã ãããã®å¯èœæ§ã®ããäŸµå ¥ã«ãŒãã¯ãã¹ãŠãç¹å¥ãªæ³šæãæãå¿ èŠããããŸãã
æ å ±ã»ãã¥ãªãã£ã確ä¿ããããã®ãã¹ããã©ã¯ãã£ã¹ã«ãããšããšã³ããŠãŒã¶ãŒã¯ç®¡çè ã§ãã£ãŠã¯ãªãããèªåã®ã³ã³ãã¥ãŒã¿ãŒã®ç®¡çè æš©éããæã£ãŠã¯ãªããŸããã ãŠã€ã«ã¹ã¯ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ããé©åã«èšèšãããã¢ãããŒãã䜿çšããŠææããããšããããããŸãã å žåçãªããªãã¯ã«ã¯ããŠãŒã¶ãŒããªã³ã¯ãã¯ãªãã¯ãããããã¥ã¡ã³ããéãããŸãã¯ã¢ããªã±ãŒã·ã§ã³ãçŽæ¥ã€ã³ã¹ããŒã«ããããã«èª¬åŸããããšãå«ãŸããŸãã ãŠãŒã¶ãŒããã®ãããªtrapã«é¥ãããšãæ瀺çã«é»æ¢ããæ¹æ³ã¯ãããŸããã ããã¯ãã³ã³ãã¥ãŒã¿ãŒãšãããã¯ãŒã¯ãä¿è·ããããã«ãå®è¡å¯èœãªã³ãŒãã®å§ä»»ç¶ã®ã¬ãã«ã確èªããã³ç¢ºèªããå¿ èŠãããããšãæå³ããŸãã ããã«ãåã¢ããªã±ãŒã·ã§ã³ã®æ£åœæ§ã確èªã§ãã人ã¯ãããè¡ãå¿ èŠããããŸãã ãã®èãã¯ãæ å ±ã»ãã¥ãªãã£æ¥çã®å€ãã®åå è ãæããããŠããããã«èŠããŸãããããã§ãããã¯ãããŸã§ã§æãå¹æçãªä¿è·æ¹æ³ã§ãã ãã®ã¢ã€ãã¢ã¯ãŸã£ããé©æ°çãªãã®ã§ã¯ãªããITã»ãã¥ãªãã£ã®å°é家ã§ããç§ãã¡ãæ¢ã«äœæããããªã·ãŒãšæé ã®åŒ·å¶çãªäœ¿çšã®ã¿ãæå³ããŸãã
ãšã³ããŠãŒã¶ãŒã«ã¯ãé©åãªããŒãžã§ã³ã®æ¿èªæžã¿ã¢ããªã±ãŒã·ã§ã³ãã€ã³ã¹ããŒã«ããããã®æ©èœãšäºææ§ããã¹ããããã³ã³ãã¥ãŒã¿ãŒãæäŸãããŸãã ãã¯ã€ããªã¹ãã®äœ¿çšã¯ãããã°ã©ã ãèå¥ããããããå®è¡ããããã®æ瀺çãªèš±å¯ãæäŸããå¿ èŠãããããšãæå³ããŸãã æ°ããã¢ããªã±ãŒã·ã§ã³ã¯ãããããæåã«ãã¯ã€ããªã¹ãã«ç»é²ããŠããããã·ã³ãŸãã¯ãããã¯ãŒã¯åãããäœæ¥ç°å¢ã«å±éããå¿ èŠããããŸãã
VPNã䜿çšãããšãããŒã«ã«ããã³ãªã¢ãŒãã®äž¡æ¹ã§ãã¯ã€ããªã¹ãããã°ããå±éã§ããŸãã æ¢å®ã§ã¯ãProgram FilesãŸãã¯Windowsãã©ã«ããŒã«ã€ã³ã¹ããŒã«ãããŠããã¢ããªã±ãŒã·ã§ã³ãå®è¡ã§ããŸãã ãããªãã·ã£ãŒã³ã³ãããŒã«ã䜿çšãããšãä¿¡é Œã§ãããã³ããŒã眲åããã³ãŒããã€ã³ã¹ããŒã«ããŠå®è¡ã§ããŸãã ããã«ãããæªçœ²åã®ã¢ããªã±ãŒã·ã§ã³ã«å¯ŸããŠã®ã¿ã«ãŒã«ãäœæããå¿ èŠãããå Žåã«ããã¯ã€ããªã¹ããç¶æããããã®äœæ¥éãåæžãããŸãã æ£ããæ§æãããŠããå ŽåããŠãŒã¶ãŒã¯ç®¡çè æš©éãæãããProgram Filesããã³Windowsãã©ã«ããŒã®å 容ãå€æŽã§ãããã¢ããªã±ãŒã·ã§ã³ãã€ã³ã¹ããŒã«ã§ããŸããã åãã·ã³ã§ããµããŒããµãŒãã¹ã䜿çšããŠãœãããŠã§ã¢ããªã¢ãŒãã§ã€ã³ã¹ããŒã«ã§ããåºæã®ãã¹ã¯ãŒãã䜿çšããŠãåå¥ã®ç®¡çè ã¢ã«ãŠã³ããæ§æã§ããŸãã
ãã¯ã€ããªã¹ãã䜿çšãããšãäžè¬çãªææãã¯ã¿ãŒãšäžè¬çãªæ°žç¶åææ³ããããã¯ã§ããŸãã æ»æè ããããããŒã«äŸåã§ããªãå Žåããªã¢ãŒãã§ã³ãŒããå®è¡ããããã«ã¯ããœãããŠã§ã¢ã®ãšã¯ã¹ããã€ãã«äŸåããå¿ èŠããããŸãã ããã¯éåžžãæ»æè ã«ãªã¢ãŒãã¢ã¯ã»ã¹ãæäŸããŸãããã·ã¹ãã ãåèµ·åããããã察å¿ããããã»ã¹ãäžæããããšããªã¢ãŒãã¢ã¯ã»ã¹ã¯å€±ãããŸãã éåžžãæ»æã®å®å®æ§ã¯ãããã¯ãã¢ãã€ã³ã¹ããŒã«ããããšã§ä¿èšŒãããŸãã ã»ãšãã©ã®å Žåã管çè æš©éãå¿ èŠãšããªããããAppDataãŠãŒã¶ãŒãã©ã«ããŒã«é 眮ãããŸãã ãããããã¯ã€ããªã¹ããProgram FilesãšWindows以å€ã®å Žæããã®å®è¡ãçŠæ¢ããŠããå Žåãããã¯ãã¢ã¯éå§ã§ããŸããã 次ã«ãæ»æè ã¯ç¹æš©ãæ¡åŒµããæ¹æ³ãæ¢ãå¿ èŠããããŸãã
å€ãã®ãŠã€ã«ã¹ã¯ãæ¢ç¥ã®è匱æ§ã«å¯Ÿãããšã¯ã¹ããã€ãã䜿çšããŠãææãããµã€ãã蚪åäžã«ãŠãŒã¶ãŒã®ãã·ã³ã«ææããŸãã éåžžãé »ç¹ã«äœ¿çšããããœãããŠã§ã¢ã«å®æçã«ããããé©çšããããšã«ããããã®æ»æãã¯ãã«ããèªåãå®ãããšãã§ããŸãã æ»æè ãæ¢ç¥ã®ãšã¯ã¹ããã€ãã䜿çšããèœåãæã£ãŠããªãå Žåãç¬èªã®ãŒããã€æ»æãéçºããå¿ èŠããããŸãã Bug Bountiesããã°ã©ã ã§ã®è³ã®ã¬ãã«ãšéåžå Žã§ã®äŸ¡æ Œã§å€æã§ããéããããã¯ç°¡åãªäœæ¥ã§ã¯ãããŸããã ä¿¡é Œã§ãããŒããã€æ»æã«ã¯100,000ãã«ãè¶ ããè²»çšããããå¯èœæ§ããããŸãããåæã«ãæ»æè ã¯è匱æ§ãç¥ããããããã§ã«ããŒãããªãããã«è³¢æã«äœ¿çšããå¿ èŠããããŸãã ããã«ãæœåšçãªå©çãè²·åã®ã³ã¹ããååã§ããå Žåããã®ãããªæ»æã䜿çšããå¿ èŠããããŸããããããªããšããã¹ãŠã®æå³ã倱ãããŸãã
ãœãããŠã§ã¢éçºè ã¯ãå€ãã®æ段ã䜿çšããŠããµã€ããŒç¯çœªè ã®ãšã¯ã¹ããã€ããéçºããã¿ã¹ã¯ãå€§å¹ ã«è€éåã§ããŸãã ããšãã°ãDEPïŒ ããŒã¿å®è¡é²æ¢ ïŒãASLRïŒ ã¢ãã¬ã¹ç©ºéã®ã©ã³ãã å ïŒãSEHOPïŒæ§é çãªäŸå€åŠçïŒãªã©ã®ã¡ã¢ãªåŒ·åæè¡ã䜿çšããŸãã 䜿çšããã¢ããªã±ãŒã·ã§ã³ã®å®è¡å¯èœãã¡ã€ã«ãã³ã³ãã€ã«ããããã«ãããã®ãã¯ãããžãŒã䜿çšãããŠãããã©ããã確èªããã«ã¯ã BinScopeãŠãŒãã£ãªãã£ãŸãã¯PowerShellã¹ã¯ãªããã䜿çšã§ããŸãã ãã®ãããªä¿è·ææ³ã䜿çšãããŠããªãå Žåã¯ãEMET ããŒã«ããã ïŒ Enhanced Mitigation Experience Toolkit ïŒã䜿çšããŠã匷å¶çã«ä¿è·ãé©çšã§ããŸãã 調æ»ã«ãããšãããªãã¯ãŸã ãããåé¿ããããšãã§ããŸãããããã¯ããå€ãã®æéãšåŽåãããããŸãã
äŒç€Ÿã§SIEM ïŒã»ãã¥ãªãã£æ å ±ç®¡çã·ã¹ãã ïŒã䜿çšããŠããå Žåã倧èŠæš¡ã§ããžãŒãªãããã¯ãŒã¯ã«ã¯åžžã«å€ãã®ãã€ãºãããããšãããããŸãã SIEMã¯ããã¹ãŠã®ã¡ã€ã³ãããã¯ãŒã¯åå è ãšãšã³ããŠãŒã¶ãŒã®ã¢ã¯ãã£ããã£ãã°ãåéããããããæ£èŠåããããã€ãã®æ å ±ãœãŒã¹ã«åºã¥ããŠã€ãã³ããçžé¢ãããçãããã¢ã¯ãã£ããã£ã®çºçã«ã€ããŠèŠåããŸãã ãããã®ãã¹ãŠã®æé ã䜿çšããŠäœã¬ãã«ããã³äžã¬ãã«ã®æ»æãé²ãå ŽåãSIMETã·ã¹ãã ã¯ãEMETãAppLockerããŸãã¯ãã¡ã€ã¢ãŠã©ãŒã«ããã€ãã¹ããè©Šã¿ã瀺ãããªãè€éãªã€ãã³ãããé©åãªèŠåãšãšãã«æ€çŽ¢ããããã«æ§æã§ããŸãã ãã®ãããªæ»æãæåããäŸµå ¥è ãã·ã¹ãã ã«äŸµå ¥ãããšããŠããããããç°¡åã«æ€åºããŠç¡ååã§ããŸãã
ãã¡ããããã¯ã€ããªã¹ãããã¹ãŠã®ã»ãã¥ãªãã£åé¡ã解決ããããã§ã¯ãããŸããã ããã§ããããããåœãŠãããŠããªããšã¯ã¹ããã€ããŸãã¯ãŒããã€æ»æãä»ããŠèª°ãããããã¯ãŒã¯ã«äŸµå ¥ã§ããå¯èœæ§ããããŸãã ãã ãããã®å Žåã§ãããã¯ã€ããªã¹ããäœæãããšãäŸµå ¥æµæãæžå°ããŸãã ããã«ãæ»æè ãç¹æš©ã·ã¹ãã ã«ã¢ã¯ã»ã¹ããããšã¯ã¯ããã«å°é£ã§ãã ã€ãŸãããããã¯ãŒã¯ã§ã®ãããã³ã°ãšãã¬ãŒã³ã¹ã®ããã»ã¹ãè€éã«ãªããããäžçŽã®ããã«ãŒã¯ããç°¡åãªã¿ãŒã²ãããéžæããããšã«ãªããŸãã
ããããã¡ã€ã«èšèªãVBScriptãPowerShellãªã©ã®çµã¿èŸŒã¿ã¹ã¯ãªããèšèªã®å ŽåãAppLockerã¯ãã€ã³ã¿ãŒããªã¿ãŒã®ã€ã³ã¹ããŒã«ãšèµ·åãé²ãããã«äœ¿çšã§ããã¢ãã¬ã¹ã¹ã¯ãªãããå®è¡ããŸãã ãã¯ã€ããªã¹ãæè¡ã§ã¯ãèæ ®ãã¹ãå€ãã®ãã¥ã¢ã³ã¹ããããŸãã ããšãã°ãMicrosoft Officeããã¥ã¡ã³ãã®ãã¯ããPDFããã³JavaScriptã®JavaScriptã ãããããããã«ããŠããå®è¡å¯èœãã¡ã€ã«ãšåçã«æ¥ç¶ãããã©ã€ãã©ãªã®ãã¯ã€ããªã¹ãèªäœã¯ãã»ãšãã©ãã¹ãŠã®å€§èŠæš¡ãŠã€ã«ã¹ãšã»ãšãã©ã®é«åºŠãªæç¶çè åšããããã¯ããŸãã ããšãã°ã Mandiantã¬ããŒãã§ã¯ãPDFã¢ã€ã³ã³ãå«ãŸããå®è¡å¯èœãã¡ã€ã«ã䜿çšããŠZIPã¢ãŒã«ã€ãã«ãªã³ã¯ããããã£ãã·ã³ã°ã¡ãŒã«ã«ã€ããŠèª¬æããŸããã ããŒãã³ã¢ã³ããŠã€ã«ã¹ã¯ãããæ€åºããããã¯ã€ããªã¹ãã¯å®è¡ã劚ããŸãã
ã»ãã¥ãªãã£ã·ã¹ãã ã«äŸµå ¥ã§ãã人ã®èŒªãããã¯ã€ããªã¹ããšãšã¯ã¹ããã€ããããã¯ããã€ãã¹ããŠæ»æãæåãããã®ã«ååãªãªãœãŒã¹ãåããè³æ Œã®ããå人ãšçµç¹ã«éå®ã§ããå Žåããªã¹ã¯ãå€§å¹ ã«åæžããæ»æãæ€åºããæ©äŒãå¢ããããšãã§ããŸãã éåžå Žã§ãŠã€ã«ã¹ãè³Œå ¥ãããã£ãã·ã³ã°ã¡ãŒã«ãéä¿¡ãã人ãå¿é ããå¿ èŠã¯ãããããŸããã ãããããªãªãŒã¹ããããªãœãŒã¹ã䜿çšããŠãããå·§åŠãªäŸµå ¥è ã®ã¢ã¯ãã£ããã£ãæ€åºã§ããŸãã