å°éè·ã®é«ã人æ°ããããªãã¯ãã¡ã€ã³ã®è±å¯ãªæ å ±ãªãœãŒã¹ãšè³æã«ãããããããåžå Žã«ã¯è³æ Œã®ãã人æãç¹ã«å®çšçãªæ å ±ã»ãã¥ãªãã£ã«é¢é£ãã人æãäžè¶³ããŠããŸãã
ãã®èšäºã§ã¯ãæ å ±ã»ãã¥ãªãã£ã®ã¹ãã·ã£ãªã¹ãã«å¯ŸããéèŠãç¹å®ã®èŠä»¶ããã³ã¹ãã«ã«ã€ããŠèª¬æããŸãã
çµ±èš
HRãšãŒãžã§ã³ã·ãŒã®1ã€ã®çµ±èšã«ãããšã2015幎ã®çµããã«ãæ å ±ã»ãã¥ãªãã£ã®å°é家ã¯2015幎1æãããå¹³å21ïŒ å€ãæäŸãããŸãããããã¯ãå±æ©ã®å Žåã§ãè³æ Œã®ããå°é家ãéèŠããããããã«åžå ŽãæããŠããããšã瀺ããŠããŸã圌ãã®äžè¶³ã
å®éãæ å ±ã»ãã¥ãªãã£ã®ãããã¯ã¯ãããŸã§ä»¥äžã«éèŠã«ãªã£ãŠããŸã-ãããã¯ãïŒæ害ãšé »åºŠã®ç¹ã§ïŒå¢ããå¢ããŠããéè¡ã»ã¯ã¿ãŒæ»æïŒSWIFTãéä¿¡ã¢ã«ãŠã³ãïŒãæšçæ»æïŒAdvanced Persistent ThreatãAPTïŒãªã©ã®å¢å ã§ãã
æ å ±ã»ãã¥ãªãã£ã¹ãã·ã£ãªã¹ããå€åããäŒæ¥ã§ãããã»ãã¥ãªãã£ã·ã¹ãã ãå¢çã»ãã¥ãªãã£ãWebã¢ããªã±ãŒã·ã§ã³ãããã³ãã®ä»ã®ã€ã³ãã©ã¹ãã©ã¯ãã£èŠçŽ ã®æç床ãé©åã«è©äŸ¡ããå¿ èŠããããŸãã
ä»äº
è·æ¥çŽ¹ä»æã§æ瀺ãããããŒã¿ã«åºã¥ããŠã1ã3幎ã®çµéšãæã€æ å ±ã»ãã¥ãªãã£å°é家ã®å¹³å絊äžã¯40,000ã70,000ã«ãŒãã«ã®ã¬ãã«ã§ãã ããã¯ãæåã®ã°ã«ãŒãïŒãžã¥ã㢠ïŒã®ã¹ãã·ã£ãªã¹ãã«é©çšãããå®åçµéšãã»ãšãã©ãªããããå°éçãªèŠä»¶ãšè²¬ä»»ã«ãã£ãŠæ確ã«ç¢ºèªã§ããŸãïŒä»¥äžããå¹³åãææšã瀺ããŸãïŒã
責任ïŒ
- Cisco ASAãã¡ã€ã¢ãŠã©ãŒã«ãšKerio Connectã®ç®¡ç
- ã¢ã³ããŠã€ã«ã¹ä¿è·ãµãŒããŒã®ç®¡çãã¯ã©ã€ã¢ã³ãã®ç¶æ ã®ç£èŠããŠã€ã«ã¹ã®é€å»ãä¿è·ã®åŸ®èª¿æŽã
- ç¹æ®ãªãœãããŠã§ã¢ãšãã®é€å»ã®å©ããåããŠè匱æ§ãæ€çŽ¢ããŸãã
- OSããœãããŠã§ã¢ãããã³ãããã¯ãŒã¯æ©åšã®ã¢ããããŒãã®ãªãªãŒã¹ã®ç£èŠã
- ã¹ã€ããã³ã°æ©åšã®ã»ããã¢ãããšç®¡çã
- ã»ãã¥ãªãã£ã·ã¹ãã ã®ç®¡çãæé©åããã¹ã¯ãªãããäœæããŸãã
- ã¢ã¯ã»ã¹ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ç®¡ç
- ãã°ã®å®æçãªåæã
èŠä»¶ïŒ
- 1幎ããWindowsã管çããçµéšã
- Linuxã®1幎ããã®åºç€ç¥èãã³ãã³ãã©ã€ã³ã§ã®èªä¿¡ãæã£ãäœæ¥ã
- ãããã¯ãŒã¯ã®åºç€ç¥èã IPã¢ãã¬ã¹æå®ãéçã«ãŒãã£ã³ã°ãISO OSIãTCPã¢ãã«ã
- Active Directory管çãšã¯ã¹ããªãšã³ã¹ïŒã°ã«ãŒãããªã·ãŒïŒGPOïŒã®ã»ããã¢ããããŠãŒã¶ãŒæš©å©ç®¡çã
- Windowsã«åºã¥ããäžæ£ã¢ã¯ã»ã¹ã«å¯Ÿããä¿è·ã·ã¹ãã ã®èšå®çµéšã
- ãŠã€ã«ã¹å¯Ÿçã·ã¹ãã ã®èª¿æŽã®çµéšã
- è€éãªIPTablesãã¡ã€ã¢ãŠã©ãŒã«æ§æã®éçºçµéšã
- Apache2ãnginxãAuditedãMySQLãPostgreSQLãRsyslogãèšå®ããæ©èœã
説æãããããããã«ãããã¯ãã¯ãªãŒã³ãªãã»ãã¥ãªãã£ã¬ãŒããšããããããæ å ±ã»ãã¥ãªãã£ã«åãã®ããã·ã¹ãã 管çè ã§ãã ã¹ãã«ã®ç¹å®ã®ç¹ç°æ§ãç¹å®ããããšã¯å°é£ã§ãã åè£è ãæ¢ããŠãã人-ããããæ¹åã®äŒæ¥ãå°åãç¹å®ããããšã¯å°é£ã§ãã
3-6幎ã®çµéšãæã€ã¹ãã·ã£ãªã¹ãã¯ãã§ã«äžçŽã§ãã ã¹ãã«ãšçµéšããã£ãšå¿ èŠã§ãããè³éã®ã¬ãã«ã¯ãã£ãšé«ããªã£ãŠããŸãã ãããã®ã¹ãã·ã£ãªã¹ãã¯ãååãšããŠãåªããæè¡çèæ¯ïŒã·ã¹ãã 管çãIDã®æ€çŽ¢ïŒãæã¡ãã¢ããªã±ãŒã·ã§ã³ãæè¡ãããã³æ¹æ³è«ãçç¥ããŠããŸãã ãããã®ã¹ãã·ã£ãªã¹ãã¯ãæ¡ä»¶ä»ãã§æ»æãšé²åŸ¡ã®2ã€ã®é åã«åããããšãã§ããŸãã ãã®ã¬ãã«ã®æ®é䞻矩è ïŒãã³ãã¹ã¿ãŒ+æ å ±ã»ãã¥ãªãã£ã¹ãã·ã£ãªã¹ãïŒ-å®éã«ã¯ååšããŸããïŒãŸãã¯ãããã¯æ¢ã«äžçŽã¬ãã«ã§ãïŒã å¹³åãã©ãŒã¯ã¯70,000ã100,000ã«ãŒãã«ã§ãã
æ å ±ã»ãã¥ãªãã£ã¹ãã·ã£ãªã¹ãïŒ
責任ïŒ
- ã»ãã¥ãªãã£ãµãã·ã¹ãã ãæ§æããã³ç®¡çããŸãã
- ã»ãã¥ãªãã£ã€ã³ã·ãã³ã管ç
- ã¹ã€ããã³ã°æ©åšã®ã»ããã¢ãããšç®¡çã
- ã»ãã¥ãªãã£ã·ã¹ãã ã®ç®¡çãæé©åããã¹ã¯ãªãããäœæããŸãã
- ã¢ã¯ã»ã¹ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ç®¡ç
- ãã°ãã¡ã€ã«ãšã€ãã³ããã°ã®åæã
- ã客æ§ã®ITã€ã³ãã©ã¹ãã©ã¯ãã£ã®ãµããŒããžã®åå ïŒæ å ±ã»ãã¥ãªãã£ã®ç¢ºä¿ãšå人ããŒã¿ã®ä¿è·ã
- æ å ±ã»ãã¥ãªãã£ããŒã«ã®æ©èœã®ç£èŠãšå¶åŸ¡ã
- ç¹å¥ãªæ å ±ä¿è·ããŒã«ã®ããã©ãŒãã³ã¹ã管çãäžæã®ãªãæäœã®ãµããŒãã
- èªç©ºæ©ãžã®æ»æã®å åãæ€åºããéã«å®å šãªã€ã³ã¿ãŒã¯ãŒãã³ã°ã確ä¿ããæ段ã®èšå®ãå€æŽããã
- å éšèªç©ºæ©ãŠãŒã¶ãŒã®ç°åžžãªæŽ»åã®ç£èŠã
- ISã€ã³ã·ãã³ããšãã®è§£æ±ºçã®åæã
- ç£æ»ã®å®æœãçµç¹ããã³ç®¡çææžã®äœæãæ å ±ã»ãã¥ãªãã£ã«é¢ããã¬ããŒãã
èŠä»¶ïŒ
- é«çæè²ïŒITãæ å ±ã»ãã¥ãªãã£ïŒ;
- TCP / IPã¹ã¿ãã¯ã®ãããã¯ãŒã¯ãšãããã³ã«ã®æ§ç¯ãšæäœã®ååã«é¢ããç¥èã
- ISO / OSIã¢ãã«ã®ç¥èã
- ã³ã³ãã¥ãŒã¿ããã³ãããã¯ãŒã¯ã»ãã¥ãªãã£ãWebã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã®ååãç解ããã
- ã»ãã¥ãªãã£ããŒã«ã®ååã«é¢ããç¥èïŒäŒæ¥ã®ãŠã€ã«ã¹å¯ŸçãWAFãäŸµå ¥æ€ç¥ã·ã¹ãã ãªã©ïŒã
- 管çè ã¬ãã«ã®Windowsããã³Linuxã
- èªååã®çµéšïŒbashãperlãpythonïŒ;
- ã»ãã¥ãªãã£åæã®çµéš;
- éçšäž»ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã§äœ¿çšãããå°éçãªãœãããŠã§ã¢ã®å°éç¥èïŒäŒæ¥ã®ãŠã€ã«ã¹å¯ŸçããDLP / IDS / IPS / SIEMãªã©ïŒã
ãã³ã¿ã¹ã¿ãŒïŒ
責任ïŒ
- äŒç€Ÿã®æ å ±ç°å¢ãšãœãããŠã§ã¢è£œåã®ãã¹ãã
- ãã©ãŒã«ããã¬ã©ã³ã¹ã«é¢ããæ å ±ã·ã¹ãã ã®ãã¹ãã
- æ å ±ã·ã¹ãã ã®æ©åšåæ;
- OWASP TOP 10åé¡ã«åºã¥ãçŸåšã®è åšã®ç¹å®ãè£åæ段ã®éçºã
- äŸµå ¥ãã¹ãã
- ãœãããŠã§ã¢ãœãŒã¹ã³ãŒãã®ã»ãã¥ãªãã£åæã
å¿ èŠæ¡ä»¶
- ã·ã¹ãã ã®è匱æ§ãç¹å®ããçµéšã
- Hydraã®Burp Suiteã®äœ¿çšçµéš;
- SQLMapãOpenVASãMetasploit FrameworkãFortifyãAppScanãäœéšããŠãã ããã
- Acunetixãw3afãX-SpiderãMax-PatrolãNmapãäœéšããŠãã ããã
- Webã¢ããªã±ãŒã·ã§ã³ã®æ§ç¯ãšéçšã®ååã«é¢ããç¥èã
- OWASPããã10ã«ãªã¹ããããŠããWebã¢ããªã±ãŒã·ã§ã³ã®å žåçãªè åšãšè匱æ§ã«é¢ããç¥èã
- Webã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã®æåããã³èªåãã¹ãã®ã¹ãã«ã
- äŸµå ¥ãã¹ãã®çµéš
- ITããã³æ å ±ã»ãã¥ãªãã£ã·ã¹ãã ã®ç£æ»ã®çµéšã
ãã®ãããªå°é家ã®èŠä»¶ã¯ããå ·äœçã§ããã䜿çšãããœãããŠã§ã¢ã®æ¹æ³è«ãçš®é¡ãªã©ãç¹å®ã®åéã®ã¢ããªã±ãŒã·ã§ã³åéã«çŠç¹ãåœãŠãŠããŸãã é»ååååŒãéèã»ã¯ã¿ãŒãã€ã³ãã°ã¬ãŒã¿ãŒã倧èŠæš¡/åæ£å°å£²äŒæ¥ãªã©ã®ä»£è¡šè ã¯ããã®ãããªå°é家ãæ¢ããŠããŸãã
5-6幎ã®ã·ãã¢ã®å®åçµéšãæã€å°é家ã éåžžãããã¯ç®¡çè·ã§ããã»ãã¥ãªãã£åæéšéã®é·ã æ å ±ã»ãã¥ãªãã£ç®¡çéšé·; ã¢ããªã¹ã IBãã³ããŒã®å€§é販売ã éåžžã«å°éçãªãã³ãã¹ã¿ãŒã 絊äžã¬ãã«ã¯120,000ãã200,000ã«ãŒãã«ã§ãã
ãã®ã«ããŽãªã«ã¯ããªãã®æ°ã®äººã ãããŸãããããŠãååãšããŠã圌ãã¯æ¥çã§ãè³ãåŸããŠãããŸãã ãããã¯ã察象åéã«ç²Ÿéããå°é家ã§ãããååãšããŠãçãå°éåéã®å°é家è³æ Œãæã£ãŠããŸãã äŒè°ãä»ã®ç€ŸäŒæŽ»åã§è©±ãçµéšã¯æè¿ãããŸã-ããã¯ãåè£è ãåŸåã«åŸã£ãŠãå°é家ã³ãã¥ããã£ã®ã¿ã€ã ãªãŒãªè©äŸ¡ãåããããšãæå³ããŸãã
ããã§ã®èŠä»¶ã¯æ¬¡ã®ãšããã§ãã
- é«çIB / ITæè²;
- 蚌ææžã®å ¥æå¯èœæ§;
- äž»é¡åéã§ã®åºçç©ããã³èšäºã®å ¥æå¯èœæ§;
- 人åã§è©±ãçµéš;
- äž»ãªæ¹æ³ãåé¡ãåœéæ £è¡ã«é¢ããç¥èïŒOSSTMMãOWASPãWASCãNIST SP800-115ãªã©ïŒã
- è匱æ§ã«é¢ããæ å ±ã«åºã¥ããŠISè åšãèå¥ããã¹ãã«ïŒè åšã®åé¡ãè匱æ§ãæé€ããããžãã¹ãªã¹ã¯ãæå°éã«æããããã®æšå¥šäºé ã®éçºïŒ;
- æ å ±ä¿è·ã«é¢ããèŠå¶ã®æ çµã¿ã«é¢ããç¥èïŒå¶éãããã¢ã¯ã»ã¹æ å ±ã®ä¿è·ã«é¢é£ããé¢ä¿ã管çãããã·ã¢é£éŠã®æ³åŸããã³ãã®ä»ã®èŠå¶äžã®æ³åŸè¡çºïŒåœå®¶ç§å¯ã«é¢é£ããªãïŒãFSTECãFSBã¬ã€ãã³ã¹ææžãéè¡ç§å¯ãç£æ¥å¶åŸ¡ã·ã¹ãã ãããã³åæ¥ã®ä¿è·ãå«ãç§å¯ãSTO BR IBBSãPCI DSSãISO 27xxxã®ç¥è;
- è±èª
- ãªãŒããŒã·ããã®è³ªã®ååšãç®æšãéæããèœåãã€ãã·ã¢ããã掻åãèªå·±çµç¹åã¹ãã«ã責任;
- 1ã€ä»¥äžã®ã¹ã¯ãªããèšèªã§ããã°ã©ã ããæ©èœã
- å°éãœãããŠã§ã¢ïŒIBM QradarãSplunk EnterpriseãImperva DAMãMaxpatrolãSymantec Critical System ProtectionãTuffinãGigamon NetworksãCisco ASAãªã©ïŒã®å°éç¥èã
- é«åºŠã«å°éåãããã·ã¹ãã ã®å°éç¥èïŒïŒããšãã°ãSCADA / ERP / SS7 /ããŒããŠã§ã¢ïŒ;
- ç¬èªã®ããŒã«/ãŠãŒãã£ãªãã£/ãã¯ããã¯ã®éçºçµéš;
- æè¡ææžããã³åæææžã®éçºã®çµéšã
- çµ±èšèª¿æ»ã®å®æœçµéš;
- ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®èª¿æ»ã蚌æ ã®åéãæ³å»åŠã®çµéšã
- ã»ãã¥ãªãã£åæãŸãã¯æ å ±ã»ãã¥ãªãã£ç£æ»ã«é¢ãã倧èŠæš¡ãããžã§ã¯ããžã®åå çµéšã
äžèšã®å°é家åãã®èŠä»¶ã¯ãå¹³åããŒãžã§ã³ã§ç€ºãããŠããŸãã ååãšããŠãç³è«è ã®å°éçã¹ãã«ã¯æ¢ç¥ã§ããããã®ãããªäººã ã¯ç¹å®ã®ã¿ã¹ã¯ã§ã¯ãªããäŒç€Ÿã®ã©ã€ãã¢ã¯ãã£ããã£ã®ã¹ããŒãžå šäœãŸãã¯ã¬ãã«ã§ããã³ãã£ã³ã°ããããŸãã ãã®ãããªå°é家ã¯ãéèã»ã¯ã¿ãŒãITã€ã³ãã°ã¬ãŒã¿ãŒãæ å ±ã»ãã¥ãªãã£ãã³ããŒã倧èŠæš¡ãªITäŒæ¥ã§éèŠããããŸãã
ãã©ãããã®ãããïŒ ãªãŒã ïŒ-10幎ã®çµéšãæã€å°é家ã ãã®ã«ããŽãªã«ã¯ãCTOãCISOãã·ã¹ãã ã¢ãŒããã¯ããããŒã ãªãŒããŒãå«ãŸããŸãã 絊äžã¬ãã«ã¯200,000ããã§ãã ååãšããŠããããã¯æ å ±ã»ãã¥ãªãã£æ¥çã®æåãªäººã ã§ãããè±å¯ãªçµéšãšã€ãªããããããŸãã
èŠä»¶/ã¹ãã«ïŒåœŒãã¯éåžžãå®äºãããããžã§ã¯ãã掻åã®æ¹åãèŠãŸãã ã¹ãã«ã«ãã£ãŠã圌ãã¯ä»¥åã®ããžã·ã§ã³ããå®å šãªãªã¹ããèŠæ±ããããšãã§ããŸãïŒãããŠãéåžžããã®æ®µéãŸã§åºç¯å²ã«åã¶ïŒããŸãã¯å¿ èŠãªä»äºã®çµæãåã«ç€ºãããŸãã ãããã®ããžã·ã§ã³ã®å Žåã圌ãã¯ãã¯ãç¥èã§ã¯ãªããææãèŠãŠããŸãã
ãã®ãããªå°é家ã¯ã倧èŠæš¡ãªã€ã³ãã°ã¬ãŒã¿ãŒãæ å ±ã»ãã¥ãªãã£ãã³ããŒã倧æãã¯ãããžãŒäŒæ¥ãéèã»ã¯ã¿ãŒãããã³å ¬å ±ã»ã¯ã¿ãŒã§å¿ èŠãšãããŠããŸãã
ãŸãšãããš
åžå Žåå è ã®æ å ±ä¿è·ã¯ãåªå 課é¡ã®1ã€ã«ãªãã€ã€ãããŸãã èªååãããæ段ã®ã¿ã§ãã®ãããªä¿è·ãæäŸããããšã¯ã»ãšãã©äžå¯èœã§ãã æ å ±ã»ãã¥ãªãã£ã®åéã®å°é家ã«å¯ŸããéèŠã¯ãæ å ±æè¡èªäœã®éçºãšåãé床ã§æé·ããŠããŸãã
æè²ãšãããªãéçšã®åé¡ã¯ããä»äºããªããçµéšããªããããä»äºããªããã...ããšããæ°žé ã®åé¡ã«ããããã®ãã¬ãŒãºãç¡éã«èªãããšãã§ããŸãã åæ¥èšŒæžèªäœãåªå æš©ãäžããªãããšã¯ãäžè¬ã«èªèãããŠããäºå®ã§ãã ãªãªãŒã¹æãŸã§ã«ãã»ãšãã©ã®ç¥èã¯åŒçšãããªããªããŸããã
ç¶æ³ããæãåºãæãéããŠæãæåããæ¹æ³ã¯ç¬åŠã§ãã