ãã¹ãã£ã³ã°ã¯å®å šã§ããïŒ
ä»®æ³ãã·ã³ïŒVMïŒã®å Žåããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãã¢ããªã±ãŒã·ã§ã³ãååŸããããããè€æ°ã®VMãã¡ã€ã«ã«ã«ãã»ã«åããåãã·ã¹ãã äžã§è€æ°ã®ä»®æ³ãã·ã³ïŒå Žåã«ãã£ãŠã¯æ°åïŒãåæã«å®è¡ããæ©äŒãåŸãŸãã ä»®æ³ãã·ã³ã¯ã移è¡ãããã¯ã¢ãããã¬ããªã±ãŒã·ã§ã³ã®ããã»ã¹ãç°¡çŽ åããŸãããVMå šäœãä»®æ³ãµãŒããŒå šäœããããã¯ãŒã¯çµç±ã§ããŸãã¯USBãã©ãã·ã¥ãã©ã€ãã«å€æŽãããã³ããŒãããããããšã容æã«ãªã£ãããšãæå³ããŸãã
ããã¯åçšã ãã§ãªããäŒæ¥ã®ããŒã¿ã»ã³ã¿ãŒã«ãé©çšãããŸãã äŸãšããŠãããŒã¿ã»ã³ã¿ãŒã«å±éããããã¡ã€ã³ã³ã³ãããŒã©ãŒã ãã¡ã€ã³ã³ã³ãããŒã©ãçµç¹ãé¢ããå Žåãæ³åããŠãã ããã ããã¯æåéãããéã®ããã¢ããŒãã®éµãã§ãã ãã¹ãŠãäžå çã«ä¿åããããããå€æ°ã®VMãåãåºããŠå¥ã®å Žæã§å®è¡ã§ããŸãã ãããŠããµãŒãããŒãã£ã®ãããã€ããŒã§ãã¹ãã£ã³ã°ããå Žåãåé¡ã¯ããã«æ·±å»ã«ãªããŸãã
ãã®ããããããªãã¯ã¯ã©ãŠããšãã©ã€ããŒãå éšã¯ã©ãŠãã®äž¡æ¹ã§ãã¹ããããä»®æ³ãã·ã³å ã®ããŒã¿ä¿è·åé¡ã®é¢é£æ§ã«ã€ããŠè©±ãå¿ èŠã¯ãããŸããã ããã«ãVMwareãHyper-VãXenãKVMãªã©ãä»®æ³åãã©ãããã©ãŒã ã§ã¯äžè¬çã§ããããŒã¿ãã©ã®ããã«ããŸã誰ããä¿è·ããå¿ èŠããããŸããïŒ ç°ãªã圹å²ãæã€ç®¡çè ã¯ãä»®æ³å管çè ããã¡ã€ã³ç®¡çè ããããã¯ãŒã¯ç®¡çè ããã£ã¹ã¯ã¹ãã¬ãŒãžç®¡çè ã«ã¢ã¯ã»ã¹ã§ããŸããïŒ
æå·åãšTPM-äžèœè¬ã§ã¯ãããŸãã
Windows Serverããã¹ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãšããŠäœ¿çšããå Žåãæå·åã«ãã£ãŠåé¡ã¯è§£æ±ºããŸãã ä»®æ³Trusted Platform ModuleïŒTPMïŒãVMã«è¿œå ããã ãã§ãBitLockerã䜿çšããŠãã®ã³ã³ãã³ããæå·åã§ããŸãã ã¢ã€ãã¢ã¯è¯ãã®ã§ãããããŸããããŸããã 管çè ã®é°è¬ããã®åŒ·åãªä¿è·ãå¿ èŠã§ãã çµå±ã®ãšããã管çè ã¯çè«çã«ã¯ã·ã¹ãã ã§äœã§ãã§ããŸããã€ãŸããç¹å¥ãªå¯Ÿçãè¬ããŠããªããã°ãVMã®ä¿è·ã解é€ã§ããŸãã ããšãã°ãä»®æ³TPMïŒvTPMïŒã®å Žåãã¡ã¢ãªå ã®æå·åããŒãèŠã€ããŠVMã埩å·åã§ããŸãã
å®éã®VMä¿è·ãå¿ èŠã§ããããã«ãããç¹å®ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ç°å¢ã§ã®ã¿å®è¡ã§ããããã«ãªãã管çè ã®æäœããå®å šã«ä¿è·ãããŸããããã«ããã管çè ã¯ã ãŸããè³briããŸãã¯è è¿«ã«ãã£ãŠäœãã匷å¶ãããå¯èœæ§ããããããæ å ±ã»ãã¥ãªãã£ã·ã¹ãã ã®è匱ãªãªã³ã¯ãæé€ããŸãã ããã«ããã®æ¹æ³ã¯ãããã«ãŒã®ãµã€ããŒæ»æãããã¯ããã«å®äŸ¡ã§æé ãªäŸ¡æ Œã§ãã
ãã®ããã«ãWindows Server 2016ã®ã·ãŒã«ããããVMãã¯ãããžã¯ïŒMicrosoftã®çšèªã§ã¯ã·ãŒã«ããããä»®æ³ãã·ã³ïŒãæäŸãã管çè ã®VMãžã®ã¢ã¯ã»ã¹ãå¶éããæªæã®ããã³ãŒãããä»®æ³ãã·ã³ãä¿è·ããŸãã ã·ãŒã«ããããVMä»®æ³ãã·ã³ã®ã·ãŒã«ããã¯ãããžãŒã¯ãWindows Server 2016ã«æ³šæãæããã1ã€ã®çç±ã§ãã誰ãæåã«ãããå¿ èŠãšããŸããïŒ
ã«
| ãªã
|
ãã¹ãã£ã³ã°äºæ¥è | ããŒã¿ã»ã³ã¿ãŒç®¡çè
ã®ããããè¡åãã顧客ããŒã¿ãä¿è·ããããšãã§ããŸãã
|
ã客æ§åã
| ã¯ã©ãŠããŸãã¯åæ¥ããŒã¿ã»ã³ã¿ãŒã«è² è·ã転éãããšåæã«ãæ
å ±è³ç£ã®å®å
šæ§ãæ©å¯æ§ãããã³æŽåæ§ãæãããèŠå¶åœå±ã®èŠä»¶ãæºãããŸãã
|
äŒæ¥ãž
| éèŠãªã¯ãŒã¯ããŒãããHyper-V管çè
ãæ確ã«åé¢ããæ©èœãååŸããŸãã
|
ããã¯ã©ã®ããã«å®è£ ãããŸããïŒ
ã·ãŒã«ããããVMã¯ã©ã®ããã«ä¿è·ãããŸããïŒ ãŸããããŒããŠã§ã¢ããŒã¹ã®ã»ãã¥ãªãã£æ©èœãåããæ å ±ã»ãã¥ãªãã£æè¡ã«ãããVMããã¹ã管çè ããéé¢ãããŸãã 次ã«ãHost GuardianãµãŒãã¹ã¯æ£åœãªHyper-Vãã¹ããèå¥ããç¹å®ã®ã·ãŒã«ããããVMã®æå·åããŒãä¿è·ã§ããŸãã 第äžã«ãããã¯ãVMã®ç¬¬2äžä»£ä»®æ³Trusted Platform ModuleïŒvTPMïŒããµããŒãããããšã«ããè¡ãããŸãã åºã䜿çšãããŠããæå·åãšèªèšŒã ã ãããé çªã«ã
ã·ãŒã«ããããVMã¯ã Windows Server 2016ã®ç»æçãªãã¯ãããžãŒã§ãã ãã ããå€ãè¯ãæå·åã䜿çšãããŸãã ããã¯äžèœè¬ã§ã¯ãããŸãããããããªãã§ã¯ã§ããŸããã ä»®æ³ãã·ã³ã®ææè ã¯ãããšãã°åãBitLockerã䜿çšããŠãã²ã¹ãOSå ã§ããªã¥ãŒã æå·åãæå¹ã«ã§ããŸãã ãããã£ãŠãæªæã®ããã³ãŒãïŒVMãé 眮ãããŠããHyper-Vãã¹ãã«è¡šç€ºãããå ŽåïŒãšãã®ããŒãã®ç®¡çè ã®äž¡æ¹ã«å¯ŸããŠãVMã®ã³ã³ãã³ãã«ã¢ã¯ã»ã¹ã§ããªããªããŸãã
ã·ãŒã«ãVMãã¯ãããžãŒã¯ããã©ã€ããšVMã®ã¹ããŒã¿ã¹ãæå·åããããšã«ãããææè ã®ã¿ãã¢ã¯ã»ã¹ã§ããããã«ããããšã§ãä»®æ³ãã·ã³ã䟵害ãããããããããã¬ãã«ã®ç®¡çè ããä¿è·ãããŸãã ãããŠãæãèå³æ·±ãã®ã¯ãæå·åããŒãã·ãŒã«ããããVMãåããHyper-Vãã¹ãã«ä¿åãããªãããšã§ããããã«ããããœãªã¥ãŒã·ã§ã³å šäœã®ã»ãã¥ãªãã£ãå€§å¹ ã«åäžããŸãã
å¥ã®æ°ããWindows ServerããŒã«ã§ããHost Guardian ServiceïŒHGSïŒ-ã·ãŒã«ããããVMããã®ãã¹ãã§å®è¡ã§ãããã©ãããæ£åœãªãã¹ãã§ããããä¿¡é Œã§ãããã¹ããµãŒããŒã§ãããããã§ãã¯ããŸãã ãããè¡ãã«ã¯ããã¹ãèªèšŒããŒã«ãšããŒããŠã§ã¢ããŒãã¡ããªãã¯ãããã³ã³ãŒãæ€èšŒæ©èœïŒã³ãŒãæŽåæ§ïŒã䜿çšãããŸãã ããã«ããããã¹ããå¿ èŠãªåºæºãæºãããŠãããã©ãããããã³ãã¹ãäžã§VMãå®è¡ã§ãããã©ããã確èªã§ããŸãã
Host GuardianãµãŒãã¹ã¯ãèªèšŒãæäŸããŸãâã·ãŒã«ããããVMã»ãã¥ã¢ä»®æ³ãã·ã³ãå®è¡ããããã«å¿ èŠãªHyper-Vãã¹ãæ€èšŒãšããŒä¿è·ã HGSã¯Windows Server 2016ã®åœ¹å²ãšããŠéå§ãããèªèšŒãšããŒä¿è·ãšãã2ã€ã®åå¥ã®ãµãŒãã¹ãå«ãŸããŠããŸãã
ãããã£ãŠãVMãã¹ãããã§ç°¡åã«ã·ãŒã«ãããããã»ã¹ã¯æ¬¡ã®ããã«ãªããŸãã
- VMã®ç¶æ
ãšãã®ããŒã¿ã®æå·åãä»®æ³ãã·ã³ãžã®é床ã®ç®¡çã¢ã¯ã»ã¹ã®æé€ã ãã®ãããªVMãã³ããŒããŠãæå³ããããŸããã
- æå·åããŒã¯å€éšã·ã¹ãã ã«ä¿åãããŸãã ä»®æ³ãŸãã¯ããŒããŠã§ã¢ã®TPMã¯ã次ã®2ã€ã®çç±ã§ããã«ã¯é©ããŠããŸãããVMã¯ãµãŒããŒãããµãŒããŒã«ã移åãããããããšãšããµãŒããŒç®¡çè
ãTPMã«ã¢ã¯ã»ã¹ã§ããããšã§ãã Server 2016ã§ã¯ããã®ãããªå€éšã¹ãã¬ãŒãžã«Host GuardianãµãŒãã¹ã䜿çšãããŸãã
- èµ·åæã®VMã¯ãHGSãä»ããŠä¿¡é Œã§ãããã¹ãããããŒãåãåããŸãã åæ§ã«ãã²ã¹ãOS Windows Server 2016ã2012 R2ã2008ãä¿è·ã§ããŸããèšç»-Linuxã
Host Guardian Host Securityã¯ãWindows Server 2016ã®æ°ãã圹å²ã§ãããHyper-V管çè ã«ããäžæ£ã¢ã¯ã»ã¹ããä»®æ³ãã·ã³ãšãã®ããŒã¿ãä¿è·ããã®ã«åœ¹ç«ã¡ãŸãã æå·åããŒã¯ãã·ãŒã«ããããVMãåããHyper-Vãã¹ãã«ã¯ä¿åãããªãããããœãªã¥ãŒã·ã§ã³å šäœã®ã»ãã¥ãªãã£ãå€§å¹ ã«åäžãããããšãã§ããŸãã
HGSã¯æ¬¡ã®ããã«æ©èœããŸãã
- Hyper-Vãã¹ããHGSã«ããŒãèŠæ±ããŠããŸãã
- HGSã¯ãHyper-Vãã¹ãã«é¢ããæå¹æ§ããŒã¿ããªããšå¿çããŸãã
- 次ã«ãHyper-Vãã¹ãã¯èªèº«ã®IDãHGSã«éä¿¡ããŸãã
- HGSã¯ã³ã³ãã©ã€ã¢ã³ã¹èšŒææžãHyper-Vãã¹ãã«éä¿¡ããŸãã
- Hyper-Vãã¹ãã¯èŠæ±ãå床éä¿¡ããHGS蚌ææžãéä¿¡ããŸãã
- å¿çãšããŠãHGSã¯æå·åããŒãHyper-Vãã¹ãä»®æ³åç°å¢ã®ã»ãã¥ãªãã£ãŸãŒã³ã«éä¿¡ããŸãã
ãããã£ãŠãVMãé 眮ãããŠããHyper-Vãã¹ãäžã®æªæã®ããã³ãŒããšããã®ãã¹ãã®ç®¡çè ã®äž¡æ¹ã«ãšã£ãŠãVMã®ã³ã³ãã³ãã«ã¯ã¢ã¯ã»ã¹ã§ããŸããã Shielded VMãã¯ãããžãŒã¯ã©ã®ãããªçš®é¡ã®æ»æããä¿è·ããŸããïŒ ãããã以äžã«ãªã¹ãããŸãã
æ»æãã¯ãã«
| ã·ãŒã«ããããVMä¿è·
|
ã·ã¹ãã 管çè
ã«ããVHDçé£
| ã·ãŒã«ããããVMã¯VHDæå·åãæäŸããããŒã¯ãã¹ãã®å€éšã«ä¿åãããŸãã
|
Hyper-Vã§ãããã°ã¢ãŒãã䜿çšãã
| HGSãã¹ãã¯ããããã°ããããã¹ãã«ããŒãçºè¡ããŸããã HGSã§ã¯ãããå¶åŸ¡ã§ããŸãã
|
æªæã®ããã³ãŒãã«ããHyper-Vãã¹ãã®ææã
| ãã¹ãäžã®ãã¹ãŠã®ãœãããŠã§ã¢ïŒã«ãŒãã«ã¢ãŒãããŠãŒã¶ãŒã¢ãŒããããã³ãã©ã€ããŒïŒãç£èŠãããã³ãŒãæŽåæ§ïŒCIïŒãç£èŠãããŸãã
|
VMãã£ã¹ã¯ãã³ãã¬ãŒãã®ææã
| ã·ãŒã«ããããVMã¯ãå®çžŸã®ãããã³ãã¬ãŒãããã®ã¿å±éãããŸãã
|
ã·ãŒã«ããããVMãä¿¡é Œã§ããªããã¹ãã«ç§»è¡ããããšããŸããã
| ä¿¡é Œã§ãããã¹ãã¯ãTPMã®äžæã®èå¥åãšãšãã«HGSã«è¿œå ãããŸãã è¿œå ãããŠããªãæ°ãããã¹ãã¯èªèãããŸããã
|
ã·ãŒã«ããããVMã¯DDoSæ»æããä¿è·ããªãããšã«æ³šæããŠãã ããã å¥ã®ãµãŒãã¹ãå¿ èŠã§ãã
ã·ãŒã«ããããVMãèµ·åããã«ã¯ãåŸæ¥ã®BIOSã§ã¯ãªããUnified Extensible Firmware InterfaceïŒUEFIïŒã䜿çšãããã»ãã¥ã¢ããŒãä¿è·ãæäŸãããBitLockerã䜿çšããŠVMãã£ã¹ã¯æå·åãæå¹ã«ãªããŸãã VMããŒã¿ã¯ãã©ã€ããã€ã°ã¬ãŒã·ã§ã³äžã§ãBitLockerã«ãã£ãŠä¿è·ãããŸãã
ã·ãŒã«ããããVMã¯ãä»®æ³ãã·ã³ã«å¯ŸããããŸããŸãªã¬ãã«ã®ç®¡çè ãžã®ã¢ã¯ã»ã¹ãå¶éããŸãã VM管çè èªèº«ã ãããã®ãããªã¢ã¯ã»ã¹æš©ãæã£ãŠããŸãã
ãããã£ãŠãWindows Server 2016ã®æ°ãã圹å²ã§ããHost GuardianãµãŒãã¹ã¯ãHyper-Vãã¹ã管çè ã«ããäžæ£ã¢ã¯ã»ã¹ããVMãä¿è·ããã®ã«åœ¹ç«ã¡ãŸãã ã·ãŒã«ããããVMã«å¯Ÿããå®å šãªæš©éãæããªã管çè ã¯ããã®ãããªä»®æ³ãã·ã³ãèµ·åãŸãã¯åæ¢ããããšã¯ã§ããŸãããèšå®ãå€æŽãããå 容ã衚瀺ãããããããšã¯ã§ããŸããã
ã·ãŒã«ããããVMã«ã¯ãã²ã¹ãOS Windows Server 2012ãŸãã¯Windows 8以éãå¿ èŠã§ãã ã·ãŒã«ããããVMã·ãŒã«ããããä»®æ³ãã·ã³ã¯ãAzure Management PackããŒã¿ã«ã§äœæããããšãã§ããŸãã æšæºã®ä»®æ³ãã·ã³ãã»ãã¥ã¢ã«å€æã§ããŸãã åæã«ãæ¢ã«è¿°ã¹ãããã«ãä»®æ³ãã£ã¹ã¯ã¯BitLockerã䜿çšããŠæå·åãããŸãã
ä¿¡é Œãããæ€èšŒãã
ãã¹ããèªèšŒããã«ã¯ãã€ãŸããä¿¡é Œãããã·ã¹ãã ãšãã¡ã€ã³ã¡ã³ããŒã§VMãèµ·åããããšã確èªããã«ã¯ã©ãããã°ããã§ããïŒ ãããè¡ãã«ã¯ã軜éïŒAdmin-TrustedïŒãšæ¡åŒµïŒTPMããŒã¹ïŒã®2ã€ã®æ¹æ³ããããŸãã
1ã€ç®ã¯ãäž»ã«ãšã³ã¿ãŒãã©ã€ãºããŒã¿ã»ã³ã¿ãŒãŸãã¯ç¹ã«ä¿¡é Œã§ãããã¹ãã£ã³ã°ãããã€ããŒåãã§ãããActive Directoryã«åºã¥ããŠããŸããVMã®èµ·åããã¹ãã«èš±å¯ãããããADã°ã«ãŒãã«å«ãŸããŠããŸãã ããŒããŠã§ã¢ã®ãã§ãã¯ã¯ãããŸãã-ä»»æã®ãµãŒããŒãé©åã§ãïŒæå·ããã»ããµãªãïŒã ããã¯ãä¿¡é Œã§ãããµã€ããæ€èšŒãããœãããŠã§ã¢ã®æ¹æ³ã§ãã
2çªç®ã¯ã倧éšåã®ãã¹ãã£ã³ã°äºæ¥è åãã«èšèšãããŠãããããè€éã§ãããTPM 2.0æå·ããã»ããµãšUEFI 2.3.1ããµããŒãããæ©åšãå¿ èŠã§ãã ãã®ãããªæ©åšã¯ãŸã ãŸãã§ãã ãããã£ãŠãç¹å®ã®ä¿è·æ¹æ³ã®éžæã¯ãããŒããŠã§ã¢ã®æ©èœã«ãäŸåããŸãã ããŒããŠã§ã¢èªèšŒããã»ã¹ã¯æ¬¡ã®ããã«ãªããŸãã
- ã·ãŒã«ããããVMãèµ·åããŸãã
- ã¯ã©ã€ã¢ã³ãã¯èªèšŒãããã³ã«ãéå§ããŸãã
- ãã¹ãã¯ã¡ããªãã¯ãšã³ãŒãæŽåæ§ã®çµæãéä¿¡ããŸãã
- ãã¹ãã¡ããªãã¯ãæ€èšŒãããŸãã
- ãã¹ãã«ã¯çœ²åæžã¿ã®èšŒææžãçºè¡ãããŸãã ããã«ãããVMãèµ·åã§ããŸãã
TMPãååšããå ŽåãããŒããŠã§ã¢æ€èšŒãé©çšãããŸã-èšå®ã«å¿ããŠããã€ããªããã€ããŒãã€ã¶ãŒãªã©ããã§ãã¯ãããŸã察å¿ããããŒããŠã§ã¢ããªãå Žåã¯ã©ããªããŸãã-TPM 2.0ããã³UEFI ãœãããŠã§ã¢ã䜿çšã§ããŸãã ãã¹ãã®èªèšŒã¯ãKerberosãšãã¡ã€ã³ã³ã³ãããŒã©ãŒãä»ããŠè¡ãããŸãã VMããŒã¿ãæå·åããã管çè ããä¿è·ãããŸããããŠã€ã«ã¹ãããŒãã¬ãŒãªã©ãã·ã¹ãã ã¬ãã«ã§ã®VMä¿è·ã¯ãããŸããã ãã ããã»ãšãã©ã®å Žåããã®ã¬ãã«ã®ã»ãã¥ãªãã£ã¯é©åãšèŠãªãããŸãã ADã°ã«ãŒãã®èšå®ã®ã¿ãå¿ èŠã§ãã
TMPã®ä»£ããã«ãããã°ã©ã ã¡ãœããïŒAdmin-TrustedïŒã䜿çšããADãæ å ±ã®ä¿åã«äœ¿çšãããŸãã ããŒããŠã§ã¢æ¹åŒã§ã¯ãVMãããŒãã®ãã«ã¹ã¹ããŒã¿ã¹ãªã©ãããå€ãã®ãã§ãã¯ãå®è¡ãããŸããããœãããŠã§ã¢æ¹åŒã§ã¯ãæ¢åã®ITã€ã³ãã©ã¹ãã©ã¯ãã£ã䜿çšã§ããããã«ãªããããè¿ãå°æ¥ã¡ã€ã³ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ãªããŸãã é害ããä¿è·ããããã«ã3ã€ã®HGSãµãŒããŒãå±éããããšããå§ãããŸãã DNSã䜿çšããŠHGSãã¹ããæ€çŽ¢ã§ããŸãã HGSã¯ä»®æ³åãã¹ãã§æŽæ°ããå¿ èŠãããããšã«æ³šæããŠãã ããã
çè«çã«ã¯ããããã®HGSãµãŒããŒã¯ä»®æ³ïŒã·ãŒã«ãVMã®ããã«åäœïŒã«ããããšãã§ããŸããããã®ãããªæ§æã¯ä¿¡é Œæ§ãäœããé害åŸã«èµ·åããŸãã-å°ãªããšã1ã€ã®ç©çHGSãµãŒããŒãŸãã¯å°ãªããšãéåžžã®ä»®æ³ïŒã·ãŒã«ãVMã§ã¯ãªãïŒãæšå¥šãããŸãã
PowerShellãŸãã¯ã³ã³ãœãŒã«ããHGSã«ãã£ãŠç®¡çãããé«å¯çšæ§ïŒHAïŒãã¹ã±ãŒãªã³ã°ããµããŒãããŸãã HGSã»ãã¥ãªãã£ã«ã¯ç¹ã«æ³šæãæãå¿ èŠããããŸã-ç©çãµãŒããŒä¿è·ãæšå¥šãããŸãã ãŸããHGSã«å¯ŸããŠBitLockerãšSecureBootãæå¹ã«ãããã¡ã€ã¢ãŠã©ãŒã«ãæå¹ã«ããŠãåHGSã«å°ãªããšã1ã€ã®éçIPãå²ãåœãŠãããšããå§ãããŸãã REST APIåŒã³åºãã§SSLãæå¹ã«ããã«ã¯ãæå¹ãªSSL蚌ææžãå¿ èŠã§ãã HGSãµãŒãã¹FQDNã®ååã瀺ããŸãã
å®å šãªä¿è·
ããã¯ãã¹ãŠããã€ããŒãã€ã¶ãŒããããã¯ãŒã¯ãªã©ã®ä¿è·ãå«ãMicrosoft Virtualization Based SecurityïŒVBSïŒã®æŠå¿µã«é©åããŸããã»ãã¥ãªãã£ãšåé¢ã確ä¿ããããã«ãVBSã¯ä»®æ³åãã©ãããã©ãŒã ã®æ¡åŒµæ©èœã䜿çšããŸãã Hyper-Vã¯VBSã䜿çšããŠããã¹ãOSãšã²ã¹ãVMããµãŒããŒãããã³ã¯ã©ã€ã¢ã³ããä¿è·ããŸãã
ä»®æ³åããŒã¹ã®ã»ãã¥ãªãã£ïŒVBSïŒã¯ãããŒããŠã§ã¢ããŒã¹ã®ä¿è·æè¡ã䜿çšããŠãã«ãŒãã«ãââãã³ã¢ããªã±ãŒã·ã§ã³ããåé¢ãããã»ãã¥ãªãã£ãŸãŒã³ãäœæããŸãã ããã«ãããå€éšæ»æã«å¯Ÿããä¿è·ãæäŸãããŸãã
VBSããŒããŠã§ã¢ãã©ãããã©ãŒã ã«ã¯æ¬¡ã®èŠä»¶ããããŸãïŒå®å šã§å¶åŸ¡ãããããŒãã®ããã®UEFI 2.3.1cã®å¯çšæ§ããªãœãŒã¹ä¿è·ã®ããã®TPM v2.0ãä»®æ³åæ¡åŒµïŒIntel VT-XãAMD-VïŒãã¢ãã¬ã¹å€æïŒIntel EPTãAMD RVIïŒããã€ããŒãã€ã¶ãŒã«ããã¡ã¢ãªä¿è·ã
éèŠãªã¿ã¹ã¯ã¯ãã³ãŒãã®æŽåæ§ã®æ€èšŒã確å®ã«ããããšã§ãïŒHypervisor Enforced Code IntegrityïŒã çŸåšãCIãã§ãã¯ã¯ã«ãŒãã«ããå®è¡ãããã«ãŒãã«ãå±éºã«ããããããšãã³ãŒããå®è¡ãããŸãã VBSã§ã¯ãããã¯å®å šã«è¡ãããŸãã ãã€ããŒãã€ã¶ãŒã¯ãåã¡ã¢ãªããŒãžãžã®ã¢ã¯ã»ã¹æš©ãããã«é 眮ãããã³ãŒãã®å®è¡æš©ãããã³ããŒã¿ã®æŽåæ§ããã§ãã¯ããŸãã ããã«ãããã¡ã¢ãªæäœã«ããæœåšçãªæ»æãå€§å¹ ã«å¶éãããäžæ£ãªãã©ã€ããŒã«å¯Ÿããä¿è·ãå®è£ ãããŸãã
ä»®æ³åããŒã¹ã®ã»ãã¥ãªãã£ã䜿çšããã³ãŒãæŽåæ§ã«ãããã·ã¹ãã ãèµ·åãããæç¹ããæ¿èªããããã€ããªã³ãŒãã®ã¿ãã·ã¹ãã ã§èµ·åãããŸãã
VBSã«ã¯ãå€ãã®ã¢ãŒããã¯ãã£ã®å€æŽãšåã ã®ããŒã«ãå«ãŸããŠããŸãã ããšãã°ãä»®æ³ã»ãã¥ãªãã£ã¢ãŒãïŒVSMïŒã¯ããã¹ããšVMã®ã¢ã¯ãã£ããã£ãå³ããå¶éããŸãã VMSã®ãã¬ãŒã ã¯ãŒã¯å ã§ãOSããã³ã²ã¹ãVMã®å®å šãªã©ã³ã¿ã€ã ç°å¢ãå®è£ ããããããã®æŽåæ§ããã§ãã¯ãããã·ãŒã«ãVMã§äœ¿çšãããVMã¯ãŒã«ãŒããã»ã¹ã®ã»ãã¥ãªãã£ã匷åãããVMã®ç¶æ ã«é¢ããæ å ±ãä¿è·ãããŸãã ã²ã¹ããã·ã³ã®ä»®æ³TMPïŒvTPMïŒã¯ããã£ã¹ã¯æå·åãªã©ã®TPMãµãŒãã¹ããµããŒãããŠããŸãã
ãã¹ã管çè ã®ã¢ã¯ã»ã¹æš©ãã²ã¹ãVMã«å¶éããã ãã§ã¯ãããŸããã 管çè ã¯ããã¹ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®åäœã«å¹²æžããªãã§ãã ããããã€ããŒãã€ã¶ãŒããã®ã¢ã¯ã·ã§ã³ããä¿è·ããå¿ èŠããããŸãã ãããã®ã¡ã«ããºã ã¯ããã©ãããã©ãŒã ãä»®æ³ãã·ã³ãããã³ä»®æ³æ©åšã®ä¿è·ãå«ãVSMã®å®è£ ã«ãããŠéèŠã§ãã
æ¬è³ªçã«ãVMSã¯RAMïŒä¿è·ãé åžãã¢ã¯ã»ã¹æš©ïŒãå¶åŸ¡ãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããã©ãããã©ãŒã ã®ãç§å¯ããæäœããã«æäœãåºå¥ããããã®äžé£ã®ã¡ãœããã§ãã VMSã䜿çšãããšãæ°ããã¬ãã«ã®ã»ãã¥ãªãã£-ä»®æ³ä¿¡é Œã¬ãã«ïŒVTLïŒãæ§ç¯ã§ããŸãã Windows Server 2016ã§ã¯ãçµã¿èŸŒã¿ã®ã»ãã¥ãªãã£ã¬ãã«ãšå ±ã«ãããå³ããèŠä»¶ãæã€æ°ããVTLãäœæã§ããŸãã VTLã¯ã¡ã¢ãªåé¢ãæäŸããç©çã¡ã¢ãªãžã®ã¢ã¯ã»ã¹ãä¿è·ããŸãã VTL0ã¬ãã«ã§ã¯ãä¿è·ãããŠããªãVMãæ©èœããVTL1ã¬ãã«ã§ã¯ãã·ãŒã«ããããVMãæ©èœããŸãã è¿œå ã®VTLã¬ãã«ãäœæã§ããŸã-ãããã¯éå±€çã§ãã 管çè ã¯ãã¹ãOSããVTLãå€æŽã§ããŸããã
VSMã¢ãŒãã§å®è¡ãããŠããVMãšã¯äœã§ããïŒ ããã¯ãIntel VT-dã䜿çšããŠIUMïŒIsolated User ModeïŒãä»ããŠéåžžã®ã«ãŒãã«ã«ã¢ã¯ã»ã¹ãããããå°ããªã«ãŒãã«ïŒãããã·ã«ãŒãã«ãSMARTãŸãã¯SKERNELïŒã§ãã ãã®ã¡ã«ããºã ã¯ããã¹ã管çè ã®ã¢ã¯ã»ã¹ããä»®æ³ããŒããŠã§ã¢ãªãœãŒã¹ãä¿è·ããŸãã
éèŠãªãã€ã³ãã¯ãããããDMAæ»æãããšãã°VSMã¡ã¢ãªã䟵害ããããšãããåœã®ããã©ã€ãã«å¯Ÿããä¿è·ã§ãã ãã€ããŒãã€ã¶ãŒã¯ãIOMMUã·ã¹ãã ã䜿çšããŠDMAã¡ã¢ãªãå¶åŸ¡ããŸãã
ä»®æ³ãã·ã³ã¯ããªããå®è¡äžããŸãã¯ã移åäžãã®ç¶æ ã§ä¿è·ããå¿ èŠããããŸãã ãããè¡ãã«ã¯ãUEFIã®ãµããŒããVMã®ã»ãã¥ã¢ããŒããããã³TPM 2.0ã®ãµããŒããåãããã¶ãŒããŒããå¿ èŠã§ãã
ãã©ã¹ããããã©ãããã©ãŒã ã¢ãžã¥ãŒã«ïŒTPMïŒã¯ãåœéæšæºã®æå·ããã»ããµã§ãã Windows Server 2016 Hyper-Vã䜿çšãããšãä»®æ³TPMã§VMãä¿è·ã§ããŸãã ãã®çµæãVMã¯ãããšãã°BitLockeræ©èœã䜿çšã§ããŸãã ä»®æ³TPMã¯ç©çTPMãå¿ èŠãšããŸããã vTPMã¯ãã²ã¹ãVMçšã®ä»®æ³TPMããã€ã¹ã®äžçš®ã§ããã£ã¹ã¯ãæå·åã§ããŸãã
ãã¢ã€ãã«ç¶æ ãã®VMãä¿è·ããããã«ãvTPMã䜿çšãããŸãã ä»®æ³TPMã¯ç©çTPMãå¿ èŠãšãããVMã移åã§ããŸãã ããã¯ä»®æ³TPM 2.0ããã€ã¹ã§ãã ããã«ãã²ã¹ãVMãã£ã¹ã¯ã¯BitLockerã䜿çšããŠæå·åãããŸãã VM移è¡ãã©ãã£ãã¯ãæå·åãããŸãã
ä»®æ³ãã·ã³ã¯ãŒã«ãŒããã»ã¹ïŒVMWPïŒã¯ãVMããšã«äœæãããŸãã ã·ãŒã«ããããVMã®å Žåãããã¯ãããã¬ãŒã¢ã¯ã»ã¹ãæåŠãããå€ãã®æ©èœãå¶éãããå®å šãªããã»ã¹ã§ãã ã·ãŒã«ããããVMãžã®ç®¡çã¢ã¯ã»ã¹ãå¶éãããŠããŸãã VMconnectãä»ããã¢ã¯ã»ã¹ïŒåºæ¬ã¢ãŒãïŒãéããããRemoteFXãæåŠãããä¿è·ãããŠããªãWMIãKVPåŒã³åºããçµ±åã³ã³ããŒãã³ããç¡å¹ã«ãªããIMCã¬ãžã¹ããªæ¿å ¥ãä¿è·ãããŠããªãVDEVããã€ã¹ãåé€ãããŸãã ãã®ãããªVMã¯ãçµã¿èŸŒã¿ã®ã¡ã«ããºã ãä»ããŠå¶åŸ¡ã§ããŸãã VMããç ŽæãããŠããå Žåã修埩ããã«ã¯ãã·ãŒã«ãVMã¢ãŒããç¡å¹ã«ããããããã¯ã¢ãããã埩å ããå¿ èŠããããŸãã
æ°ããHyper-Vã»ãã¥ãªãã£ããã³ãã£ã¢ã OSã®ãã€ããªããã§ãã¯ããããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãå¶éããèªèšŒãåºã䜿çšãããŠããŸãã ã²ã¹ãOSã¯ãå®å šãªVMWPãä»ããŠãã¹ããšé£æºããŸãã ä»®æ³TPMã¯VMããŒã¿ãæå·åããæå·åããŒã¯å€éšãµãŒããŒã«ä¿åãããŸãã ãã€ããŒãã€ã¶ãŒãVSMãã²ã¹ãOSã¯ãåå¥ã®ã»ãã¥ãªãã£ã¬ãã«ãå®è£ ããŸãã
ãã¡ãããVMã®ã·ãŒã«ãïŒä¿è·ïŒã¬ãã«ã¯èª¿æŽã§ããŸãã ãã¹ã管çè ãä¿¡é Œããå ŽåããŸãã¯ãã¹ãã·ã¹ãã ãã·ãŒã«ããããVMã®èŠä»¶ã®ãã¹ãŠããµããŒãããŠããªãå Žåããã匱ãã¬ãã«ã®ä¿è·ã䜿çšã§ããŸãã ãã®å Žåãã·ãŒã«ãã«ããéçç£çãªæ倱ãæžå°ããŸãã
- åºæ¬ã¬ãã«ã TPMæ©èœã®äœ¿çš-vTPMã¯VMã§åäœããã»ãã¥ã¢ããŒãããã£ã¹ã¯æå·åãVSCãªã©ããµããŒããããŸãã
- ãã®ã¬ãã«ã®ä¿è·ã¯ãVMã®ç¶æ ãšç§»è¡ãã©ãã£ãã¯ã®æå·åã«ãã£ãŠè£å®ãããŸãã
- ãã¹ã管çè ã®æäœã®å¶éãå«ãå®å šãªãšã¹ã±ãŒãã
ãããæ©èœãããããã«ããã€ããŒãã€ã¶ãŒã®ã»ãã¥ãªãã£ã¢ãŒããå€æŽãããŸããã ããã©ã«ãã§ã¯ããã¹ãã·ã¹ãã ãä¿¡é Œããããã¹ãã·ã¹ãã ããã®ãã€ããŒãã€ã¶ãŒãžã®çŽæ¥ã¢ã¯ã»ã¹ã¯ãããŸãããäž»èŠãªã·ã¹ãã ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã¯å¶éãããŠããŸãã å¿ èŠãªãã®ã¯ãã¹ãŠã²ã¹ãVM OSããå®è¡ãããŸãã ãã¹ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¯ãäž»ã«ç®¡çæ©èœãå®è£ ããŠããŸãã äŒæ¢ç¶æ ãã¡ã€ã«ã®ãã€ããŒãã€ã¶ãŒã®ç¶æ ã¯æå·åãããŠããŸãã
ãããã£ãŠãã·ãŒã«ããããVMã®ããŒã¿ãšã¹ããŒã¿ã¹ã¯ç®¡çè ããã«ãŠã§ã¢ããä¿è·ããããã¹ãVSMã¯vTPMã«ãã£ãŠä¿è·ããããã£ã¹ã¯æå·åããµããŒããããã·ãŒã«ããããVMã¯ä¿¡é Œã§ãããã¹ãã§ã®ã¿å®è¡ã§ããŸãã ãã®ããã¥ã¡ã³ãã§ã¯ãã·ãŒã«ãVMã®å±éãšã·ãŒã«ãVMæ©èœã«ã€ããŠèª¬æããŸãã
ãã¹ãã£ã³ã°äŒç€Ÿã倧èŠæš¡çµç¹ã«æ³šç®ããŠãWindows Server 2016ã¯Guarded FabricããŒã«ãå®è£ ããŠããŸãã ãã®å©ããåããŠããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ãæè»ã«æ§æããã»ã°ã¡ã³ãã«åå²ããŠãããŒã¿ãååããããããä»®æ³ãã·ã³ããå¥ã®ä»®æ³ãã·ã³ã«ä»å ¥ããããã»ãã¥ãªãã£ããªã·ãŒã«åããä»ã®æäœãå®è¡ãããããããšãã§ããŸãã ã¯ã©ãŠããµãŒãã¹ãããã€ããŒã®ãããã¯ãŒã¯ã§ã¯ãæ°äžå°ã®ä»®æ³ãã·ã³ãæ©èœããIPã®ç«¶åãçºçããå¯èœæ§ã®ããã€ã³ãã©ã¹ãã©ã¯ãã£ã§ãæªæã®ããããã°ã©ã ãåããä»®æ³åã·ã¹ãã ãåºçŸããå ŽåããããŸãã Guarded Fabricã®ä»äºã¯ãããé²ãããšã§ãã
å ±æãã¹ãã£ã³ã°ãšã¯ã©ãŠãã¯ãã¯ãå®å šã§ã¯ãããŸãã-ã¯ã©ãŠããµãŒãã¹ã䜿çšããéã®äž»ãªé害ã®1ã€ãæé€ããŸãã ä»®æ³ãµãŒããŒã¯ã以åã¯ã»ãã¥ãªãã£äžã®çç±ã§ããŒããŠã§ã¢ãã©ãããã©ãŒã ã§ããå®è¡ã§ããªãã£ãè² è·ã«äœ¿çšã§ããããã«ãªããŸããã