æ å ±ã»ãã¥ãªãã£ã«é¢ããŠã¯ã2017幎ã®ç¬¬2ååæã¯å²äžææªã®1ã€ã§ããã èªåŒµããã«ã5æã®WannaCryæ»æãš6æã®GoldenEye / Petyaæ»æã¯ä»ã®è¿œéãèš±ããŸããã§ããã äžçã®ã»ãŒãã¹ãŠã®åœãšéåžžã«å€ãã®äŒæ¥ããããã«èŠããã§ããããã®å€ãã¯ãŸã ã·ã¹ãã ã埩å ããŠããŸãã ããŸããŸãªæšå®ã«ãããšããããã®æ»æã«ãã被害ã®åèšã¯10åãã40åãã«ã®ç¯å²ã§ããã
ãããã®æ»æã¯ããµã€ããŒæŠäºããã³ããããšæŠãããã®ããŸããŸãªåœã®åªåãšå¯æ¥ã«é¢é£ããŠããŸãã äž¡æ¹ã®æ»æã¯ãNSAã«ãã£ãŠçºèŠãããè匱æ§ãå©çšããŸãããNSAã¯ã4æã«å ¬éãããShadow BrokersãšåŒã°ããããã«ãŒã®ã°ã«ãŒãã«ãã£ãŠçãŸããŸããã å€ãã®å°é家ã«ãããšããŽãŒã«ãã³ã¢ã€/ããã£ã¢æ»æã¯ãæé®®æ°äž»äž»çŸ©äººæ°å ±ååœãæ²æ³èšå¿µæ¥ã®åæ¥ã«ãŠã¯ã©ã€ãã®äŒæ¥ãæ©é¢ã®æŽ»åãæ··ä¹±ãããããšãç®çãšãããã®ã§ããäžæ¹ã§ãåæé®®ãWannaCryæ»æã®åå ãšããããã€ãã®èšŒæ ãããããã®æ»æã¯ãã·ã¢ã§ããã
ããããã°ããŒãã«ãªãµã€ããŒæŠäºããã§ã«é²è¡äžã§ãããšå ¬åŒã«èšãããšã¯ã§ããŸããããäœããã®åœ¢ã§ãWannaCryãPetyaã®ãããªæ»æã¯ç§ãã¡äžäººäžäººã«åœ±é¿ãåãŒããŸãã ãããã®2ã€ã®æ³šç®ãã¹ãæ»æã«é¢ãããã€ãºã®äžã§ãä»ã®æ»æã¯æ³šæãæãããšãªãéãã«ééããŸãã ãããããããã¯åãªãæ·±å»ãªæ»æã§ã¯ãªããããããããã«å±éºãªäºä»¶ã§ãã ãã©ã³ã¹ãã¢ã¡ãªã«ãªã©ã®åœã ã§ã®éžæã«åœ±é¿ãäžããããšãã倧èãªè©Šã¿ã¯ãæ¿æ²»çèŠè§£ãæ»æè ã®ç®æšãšäžèŽããåè£è ã«æå©ãªãµã€ããŒã¹ãã€æŠè¡ã䜿çšããŠè¡ãããŸãïŒç±³åœã®ãã©ã³ãããã©ã³ã¹ã®ã«ãã³ã®å ŽåïŒãµã€ããŒã¹ããŒã¹ã§çºçããäžçã®åºæ¥äºã«å€§ããªåœ±é¿ãäžããå¯èœæ§ã®ããé ããæŠäºã®äŸã
äžæ¹ãäžè¬åžæ°ã¯æ¯æ¥å€æ°ã®ãµã€ããŒç¯çœªã«çŽé¢ããŠããããã®çµæãæ»æè ã¯ç ç²è ãç ç²ã«ããŠè«å€§ãªå©çãäžããŠããŸãã
æ°åã®ååã®äž
ç§ãã¡ã®ã¬ããŒãã§ã¯ãã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã®ä»ã®éçºè ãå ¬éããã¬ããŒããšåæ§ã«ãæªæã®ããããã°ã©ã ã«é¢ããåæ§ã®çµ±èšæ å ±ãåžžã«æäŸããŠããŸãïŒã¬ããŒãæéã«åºçŸããæ°ããè åšã®æ°ãè åšã®çš®é¡ãªã©ã ãããã®æ°åã¯èå³æ·±ããã®ã§ããããã¥ãŒã¹ã®æããèŠåºãã«ãªãå¯èœæ§ããããŸãããä»å¹Žã¯PandaLabsã§ããã«é²ãã§ãæ°ããæå³ãæã¡ãçã®äŸ¡å€ãããããŒã¿ã衚瀺ããããšã«ããŸããã
以äžã«ç€ºãçµ±èšãèšç®ããããã«ãã·ã°ããã£ã«ãã£ãŠæ€åºããããã¹ãŠã®è åšãèæ ®ããªãããšã«ããŸããïŒãã®æ°ã¯æ°åã«éããå¯èœæ§ããããŸãïŒã ããã¯ããç¥ãããŠãããã«ãŠã§ã¢ã§ãããåºæ¬çãªãŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã䜿çšããŠããåãŠãŒã¶ãŒã¯ããã®ãã«ãŠã§ã¢ããã»ãŒä¿è·ãããŠããŸãã äžæ¹ã以åã¯æªç¥ã ã£ãè åšãæ€åºã§ãããã¥ãŒãªã¹ãã£ãã¯æ€åºãå«ããªãããšã決å®ããŸããã
ããã¯ãããã®ããã«ãŒããŠã€ã«ã¹å¯Ÿçã®æå°éã®ãã¹ããå®æœããŠããäœæããæ°ä»ãããªããã©ããã確èªããããã§ãããããã®ãŠã€ã«ã¹å¯Ÿçã«ã¯çœ²åããã³ãã¥ãŒãªã¹ãã£ãã¯æ€åºãå«ãŸããŸãã èšãæããã°ããŠãŒã¶ãŒãåžžã«ä¿è·ãããææã®æ¬åœã®ãªã¹ã¯ããªãã£ããã®ããã«ããããã®æ°å€ãèœãšãããšãã§ããŸãã
ã·ã°ããã£ãšãã¥ãŒãªã¹ãã£ãã¯ã«ãã£ãŠæ€åºãããªãæ°ããè åšã«é¢ããããŒã¿ã®ã¿ãèæ ®ããŸãïŒæªæã®ããæ»æããã¡ã€ã«ã¬ã¹æ»æãããã³åæ³çãªã·ã¹ãã ããŒã«ã䜿çšããŠå®è¡ããããã®ä»ã®æ»æã 6æã®ããã£ã¢ã
ããããæ€åºã§ããªããã®ãã©ã®ããã«æž¬å®ããŸããïŒ
å®éã«ã¯ã以åã«çœ²åããã¥ãŒãªã¹ãã£ãã¯ã«èŠãããããšããªãå Žåã§ããå®éã«ãã®ãããªæ»æãæ€åºããŠé»æ¢ããããšãã§ããŸãã ãããè¡ãããã«ããã³ã³ããã¹ãã€ã³ããªãžã§ã³ã¹ããšåŒã°ããç¬èªã®ãã¯ãããžãŒã»ããã䜿çšããŠãæªæã®ããåäœãæ€åºããæ¢ç¥ããã³æªç¥ã®è åšã«å¯Ÿããæ¹åããããµã€ããŒé²åŸ¡ã¡ã«ããºã ãäœæããŸãã
ãã®ã¬ãã«ã®Contextual Intelligenceã¯ãå®éã®æ»æãã·ãã¥ã¬ãŒããããã¹ãã§åªããæ€åºã¬ãã«ãéæããã®ã«åœ¹ç«ã¡ãŸããã 2017幎ååã®AV-Comparativesãã¹ãã§ãPanda Securityã¯Real-World Protection Testã§æé«ã®çµæã瀺ããPanda Free Antivirusã§æé«ã®ãAdvance +ãè³ãåè³ããŸãããããã¯ãåœç€Ÿã®æ å ±ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³è£œåã®äžã§æãã·ã³ãã«ãªãœãªã¥ãŒã·ã§ã³ã§ãã
次ã«ãååŸããæ»æããŒã¿ãåæããŸããã Panda Securityãœãªã¥ãŒã·ã§ã³ã«ãã£ãŠä¿è·ããããã¹ãŠã®ãã·ã³ã®ãã¡ã3.44ïŒ ãæªç¥ã®è åšã«æ»æãããŸãã ã ããã¯ãåååæãããã»ãŒ40ïŒ é«ããªã£ãŠããŸãã ã¯ã©ã€ã¢ã³ãã®ã¿ã€ããèŠããšãããŒã ãŠãŒã¶ãŒãšäžå°äŒæ¥ã§ã¯ãã®ãããªãã·ã³ãçŽ3.81ïŒ ã§ããããäžå€§äŒæ¥ã§ã¯çŽ2.28ïŒ ã§ããã
ããŒã ãŠãŒã¶ãŒã¯ä¿è·ãã¯ããã«å°ãªããããæ»æã«å¯ŸããŠããè匱ã«ãªããŸãã èªå® ã§æ£åžžã«å®è£ ãããæ»æã®å€ãã¯ã圱é¿ãäžããåã«äŒæ¥ãããã¯ãŒã¯ã§ç°¡åã«é²æ¢ãããŸããã
äŒæ¥ã¯ã©ã€ã¢ã³ãã®äžã«ã¯ãåŸæ¥ã®ãœãªã¥ãŒã·ã§ã³ã䜿çšãã人ãšããŠã€ã«ã¹å¯Ÿçã®éçãã¯ããã«è¶ ããè¿œå æ©èœãä¿è·ã¬ãã«ã®å€§å¹ ãªæ¡å€§ãè åšã®åé¡ããªã¢ã«ã¿ã€ã ã®EDRãœãªã¥ãŒã·ã§ã³ïŒ Adaptive Defense ïŒãéžæãã人ãããŸããµãŒããŒããã³ã¯ãŒã¯ã¹ããŒã·ã§ã³ã§å®è¡ãããŠãããã¹ãŠã®ããã»ã¹ã®ç£èŠãããã³å°é家ã«ããåæãªã©ãæäŸããŸãããã®çµæãAdaptive Defense EDRãœãªã¥ãŒã·ã§ã³ã®ãã¹ãŠã®ä¿è·ã¬ãã«ãå æã§ããæ»æã®æ°ã¯ã¯ããã«å°ãªããªããŸãã å¯äžã®äŒçµ±çãªã»ãã¥ãªãã£æè¡ã«éãspondingã
åŸæ¥ã®ãœãªã¥ãŒã·ã§ã³ã§ä¿è·ãããããã€ã¹ã®2.67ïŒ ãæªç¥ã®è åšã«ééããŸãããã Adaptive Defenseã§ä¿è·ãããããã€ã¹ã®1.21ïŒ ã®ã¿ãé·æã«ããã£ãŠé«ãã¬ãã«ã®æ»æé²åŸ¡ã瀺ããŠããŸãã
ãããã®æ»æã¯å°ççã«ã©ã®ããã«åæ£ãããŠããŸããïŒ ååœã§æ»æãããè»ã®å²åãèšç®ããŸããã å²åãé«ãã»ã©ãããããã®åœã§æªç¥ã®è åšã䜿çšããŠæ»æãããå¯èœæ§ãé«ããªããŸãã
ãã®ååæã¯ã2ã€ã®äž»èŠãªæ»æã«ãã£ãŠæ確ã«ããŒã¯ãããŸããã 5æã«æåã®WannaCryæ»æãçºçããå°çã®é ã ã«ãããã¹ãŠã®äŒæ¥ãããã¯ãŒã¯ã«æ¥è¥²ãããŸããã
WannaCryã¯ãå²äžæ倧ã®æ»æã®1ã€ã§ãã éå»ã«è¢«å®³è ã®æ°ãé åžé床ãé«ãæ»æïŒããšãã°ãBlasterãSQL SlammerïŒããããŸãããããããã®æ»æã«ãã被害ã¯æ¥éãªåºããã®åœ±ã«ãšã©ãŸããŸããã WannaCryã®å Žåãã¯ãŒã æ©èœãåããæå·åè£ çœ®ã«ã€ããŠè©±ããŠããŸããã€ãŸããææãããã¹ãŠã®ãããã¯ãŒã¯ãæå·åãåé¿ã§ããªãã£ãããšãæå³ããŸãã 被害ãåããã³ã³ãã¥ãŒã¿ãŒã®æ°ã¯23äžå°ãè¶ ããŠããã被害é¡ã¯10åãã40åç±³ãã«ã§ãã å¹³åçãªè¢«å®³é¡ã¯ãåã³ã³ãã¥ãŒã¿ãŒã§4 300ãã«ãã17000ãã«ãè¶ ããŠããŸããã ãããã£ãŠãããã¯å²äžæãç Žå£çãªæ»æã§ãããšèªä¿¡ãæã£ãŠèšããŸãã
äœãèµ·ãã£ããã®è©³çŽ°ãªåæãšå¿ èŠãªæšå¥šäºé ã«ã€ããŠã¯ ãPandaLabsãã¯ãã«ã«ãã£ã¬ã¯ã¿ãŒã®ã«ã€ã¹ã³ãã³ãºãå®æœããWannaCryæ»æã«é¢ãããŠã§ãããŒãã芧ãã ããã
ä»ååæã®2çªç®ã®äž»èŠãªæ»æã¯ãWannaCryå°éåŸã®äžçš®ã®æ®çè¡æã§ããGoldenEye / Petyaã§ãã ãããã圌ã®ç ç²è ã®ã»ãšãã©ã¯ç¹å®ã®å°åïŒç¹ã«ãŠã¯ã©ã€ãïŒã«éäžããŠãããšããäºå®ã«ãããããããäžç60ãåœä»¥äžã®äŒæ¥ã被害ãåããŸããã
ãŠã¯ã©ã€ãã§éåžžã«äººæ°ã®ããMeDocãšåŒã°ããäŒèšãœãããŠã§ã¢ã䜿çšããŠãæ éã«èšç»ãããæ»æãå®è¡ãããŸããã æ»æè ããã®ããã°ã©ã ã®æŽæ°ãµãŒããŒãã¯ã©ãã¯ãããããMeDocããã°ã©ã ãã€ã³ã¹ããŒã«ãããã³ã³ãã¥ãŒã¿ãŒã¯ãæŽæ°ããã°ã©ã ã®ã€ã³ã¹ããŒã«æã«èªåçã«ææããå¯èœæ§ããããŸããã
ãã®æ»æã¯è€éã§éåžžã«å±éºã§ããã ããã§ã¯ãæå·åããããã¡ã€ã«ã ãã§ãªããæ¥ç¶ãŠãŒã¶ãŒã管çè æš©éãæã£ãŠããå Žåã®ã¡ã€ã³ããŒããšãªã¢ããããŸãã æåã¯WannaCryãšåãã©ã³ãµã ãŠã§ã¢ã®ããã«èŠããŸãããããã®è åšã培åºçã«åæããçµæãæ»æè ã¯æå·åãããããŒã¿ã®å埩ãèš±å¯ããã€ããã¯ãªãããšãããããŸããã
GoldenEye / Petyaã®å ŽåããŠã¯ã©ã€ãã®äŒæ¥ãæ©é¢ã®ã³ã³ãã¥ãŒã¿ãŒã®åäœã劚害ããããã«èšèšãããæšçåæ»æã«çŽé¢ããŠããããšã¯æããã§ãã ãããã倧éç Žå£å µåšã®å Žåã®ããã«ãä»éçãªæ害ã¯é¿ããããŸããã GoldenEye / PetyaãäŒæ¥ãããã¯ãŒã¯ã«äŸµå ¥ããåŸãåºç¯ãªå¹æçãªæè¡ã䜿çšããŠé ä¿¡ãããŸãã ãŠã¯ã©ã€ãã«ãªãã£ã¹ãæã€å€åœäŒæ¥ãææããŠããŸãã
æ»æã®æ°æ¥åŸããŠã¯ã©ã€ãæ¿åºã¯ãã·ã¢ãæ»æãè¡ã£ããšããŠå ¬ç¶ãšéé£ããã
ããã§èŠãããšãã§ãããã¬ãŒã³ããŒã·ã§ã³ã§ã¯ãPandaLabsã¯ãã®æ»æãšãã®äœè ã®ããŒãã€ã³ããåæããŸããã
æå·äœæè
WannaCryãšGoldenEye / Petyaã¯äžéã®æ³šç®ããã¹ãŠããããŸããããä»ã«ãå€ãã®æå·äœæè ãããŸããã Nayanaã®Webãã¹ãã£ã³ã°ã¯éåœã§æ»æãããããã§ã¯153ã®LinuxãµãŒããŒã§ã©ã³ãµã ãŠã§ã¢ãããŒã¿ãæå·åããŸããã
æ»æè ã¯ã162äžãã«ã®èº«ä»£éãèŠæ±ããŸããã äŒç€Ÿã¯ç¯çœªè ãšäº€æžäžã§ããã®æ°åã100äžãã«ã«æžããã3åã®æ¯æãã§æ¯æããŸããã
ãµã€ããŒæŠäº
2017幎ã®2ã€ã®äž»èŠãªæ»æã«ãããç¹å®ã®åœã®æ¿åºãèåŸã«ããå¯èœæ§ããããšããç念ãçããŸããïŒWannaCryã®å Žåã¯DPRKãGoldenEye / Petyaã®å Žåã¯ãã·ã¢ïŒã ãããããããã¯ããµã€ããŒã¹ããŒã¹ã§è¡ãããå€ããå°ãªããäžæè°ãªæŠäºã®æµ·ã®2ã€ã®äŸã«ãããŸããã
ãã®ãµã€ããŒæŠäºã²ãŒã ã®äž»ãªãã¬ãŒã€ãŒã¯éåžžã®å®¹çè ã§ãïŒç±³åœããã·ã¢ãåæé®®...ããããäžåœãéå»æ°ã¶æã§ãã®ãªã¹ãããäœããã®åœ¢ã§è±èœããããšã¯é©ãã¹ãããšã§ãã 圌ã¯ããããã¹ãŠã®ã¹ãã£ã³ãã«ã«é¢äžããŠããŸããã§ããã ããã«ã€ããŠã®å¯äžã®èª¬æã¯ã2015幎ã«ç±³åœãšäžåœã®éã§çœ²åããããµã€ããŒã»ãã¥ãªãã£å¥çŽã§ããããŸã ç¹å®ãããŠããªãæ»æãç¶ããå¯èœæ§ããããŸãã
ç±³åœã¯ãç±³åœã®äŒæ¥ãæ©é¢ã«å¯Ÿããæ»æãæããã«æžå¿µããŠããŸãã åœåå®å šä¿éçïŒDHSïŒã®ãµã€ããŒéšéã®äºåå±é·ã§ãããµãã¥ãšã«ãªã«ãºã¯ãç±³åœäžé¢Intelligenceå ±å§å¡äŒã®åã§ã21ãè¶ ããå·ã®å€§çµ±é éžæã«é¢é£ãããã·ã¢æ¿åºã®æšçã·ã¹ãã ã«ãã£ãŠãµããŒããããããã«ãŒæ»æã蚌èšããŸããã
ç±³åœè°äŒIntelligenceå ±å§å¡äŒã¯ã2016幎ã®å€§çµ±é éžæã«å¯Ÿãããã·ã¢ã®æµ·å€æ»æã®åœ±é¿ãè°è«ããããã«èŽèäŒãéå¬ããŸããã ãªããæ¿æš©ã®å åœåå®å šä¿éé·å®ã§ãããžã§ãŒã»ãžã§ã³ãœã³ã¯ããã·ã¢ã®ããŒãã³å€§çµ±é ãç±³åœå€§çµ±é éžæã®çµæã«åœ±é¿ãäžããæ»æãåœããããšãæ³èµ·ããã ãŸãããããã®æ»æã䜿çšããŠãããã«ãŒã¯éžæçµæãæ¹ããããããšã¯ã§ããªããšäž»åŒµããŸããã
6æãç±³åœæ¿åºã¯2009幎以éã«è¡ãããäžé£ã®ãµã€ããŒæ»æã«ã€ããŠåæé®®æ¿åºãéé£ããå°æ¥æ°ããæ»æãè¡ãããå¯èœæ§ãããããšãèŠåããèŠåãçºè¡ããŸããã åœåå®å šä¿éçãšFBIããã®èŠåã¯ããé ããã³ãã©ãããã«ãŒã®ã°ã«ãŒãã«é¢é£ããŠããããšããããã¡ãã£ã¢ãèªç©ºå®å®ãéèç£æ¥ãããã³ç±³åœããã³äžçã®ä»ã®åœã ã®éèŠãªã€ã³ãã©ã¹ãã©ã¯ãã£ãæ»æããŸããã
ãHidden Cobraããšããååã¯ããŸãç¥ãããŠããŸãããããã®ã°ã«ãŒãã¯ãLazarus GroupããšããŠãç¥ããã2014幎ã®ãœããŒã®ãããã³ã°ãªã©ã®æ»æã«é¢é£ä»ããããŠããŸãã
Hidden Cobra / Lazarus Groupã®æŽ»åã«é¢ãããã¹ãŠã®ããŒã¿ãšèšŒæ ãåæããããšã§ãWannaCryèªäœã«çŽæ¥ã¢ã¯ã»ã¹ããéäžã§ãã³ã°ã©ãã·ã¥ã®äžå€®éè¡ã«å¯Ÿããæ»æãªã©ãéèæ©é¢ã®æ»æãæ¢ããããšãã§ããŸãã
6æã«ã¯ã·ã³ãã³ã§éå¬ãããGartner SecurityïŒRisk Managementãµãããã§ãå CIAãã£ã¬ã¯ã¿ãŒã®John Brennanã¯ããã·ã¢æ¿åºãšYahooã¢ã«ãŠã³ããçãã ãµã€ããŒç¯çœªè ãšã®åçé¢ä¿ã¯æ°·å±±ã®äžè§ã«ãããªããšè¿°ã¹ãŸãããå°æ¥ã®æ¿åºã®ãµã€ããŒæ»æã¯ãã®å ¬åŒã䜿çšããããé »ç¹ã«ãªããŸãã
åãã¹ããŒãã®äžã§ã圌ã¯ãã·ã¢ã®ç¹å¥ãµãŒãã¹ã¯å®éã«ã¯æ³åŸã«ãã£ãŠèŠå¶ãããŠããªãããç±³åœã§ã¯ãã®å察ãçå®ã§ãããšè¿°ã¹ãã 誰ãããããã®æãå¥åŠã ãšæããããããŸãã ïŒWikiLeaksã®ãããã§ïŒèª°ããé·å¹Žã«ããã£ãŠCIAãèªå® ãäŒæ¥ãå ¬å ±ã®Wi-Fiãããã¯ãŒã¯ã®ã«ãŒã¿ãŒãã¯ã©ãã¯ããŠãç§å¯ã®ç£èŠãè¡ã£ãŠããããšãç¥ã£ãŠããŸãã
ååã®ã¬ããŒãã§ã¯ããµã€ããŒæ»æã®ãªã¹ã¯ããéåžžã«é«ããããããã©ã³ã¹ãæµ·å€ã«äœãåžæ°ã«é»åæ祚æ¹æ³ã䜿çšããããšãæåŠããæ¹æ³ã«ã€ããŠè©±ããŸããã å°ãªããšã1åã®ãµã€ããŒæ»æããããéžæã®ãããæ°æ¥åã«å人æ å ±ãå ¬éããããšããã¥ãšã«ãã¯ãã³ã¯ãããã³ã°ããããšãããã¬ã¹ãªãªãŒã¹ãããã«é åžããŸããã
æè¿ã®ç 究ã§ã¯ããã·ã¢æ¿åºã«ãã£ãŠãµããŒããããŠãããšæããããã¡ã³ã·ãŒãã¢ã°ã«ãŒãã«ããã¯ããªã³ã¯ããŠããŸãã
Financial Timesã«ãããšãè±åœè°äŒã®ã¡ã³ããŒã¯ããã«ãŒããã©ãŒã¹æ¹åŒã䜿çšããŠã¡ãŒã«ã¢ã«ãŠã³ãããããã³ã°ããããšããŸããã å€åœå¢åãåŸæŽããããã«ãŒããã®æ»æã®çãããããŸãã
ãã®ããªãã¯ãšåœéçŽäºã®æ颚ã¯ããã¯ãããžãŒäŒæ¥ã«åœ±é¿ãäžããŠããŸãã ãã·ã¢ã®FSBã¯ãå¯èœæ§ã®ããããã¯ãã¢ããã§ãã¯ããããã«ãCISCOãSAPãIBMã«ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã®ãœãŒã¹ã³ãŒããèŠæ±ããŸããã æ°æ¥åŸãç±³åœæ¿åºã¯ããã·ã¢æ¿åºããã³FSBã«è¿æ¥ããŠããããããã¹ãŠã®é£éŠéšéãã«ã¹ãã«ã¹ããŒã®ãœãªã¥ãŒã·ã§ã³ã䜿çšããããšãçŠæ¢ããŸããã
ãµã€ããŒç¯çœª
IC3ïŒ ã€ã³ã¿ãŒãããç¯çœªèŠæ ã»ã³ã¿ãŒãç±³åœFBIãåç §ïŒãå ¬éãã2016幎ã®ã€ã³ã¿ãŒãããç¯çœªã¬ããŒãã«ãããšããµã€ããŒç¯çœªã«ããæ倱ã¯24ïŒ å¢å ãã13åãã«ãè¶ ããŸããã
ãã®æ°å€ã¯ãIC3ã§å ±åãããæå·ã®ã¿ãèæ ®ã«å ¥ããŠããããšã«çæããå¿ èŠããããŸãã ããã¯ã2016幎ã«ç±³åœã§ã®ã¿ãåèšã®æ害é¡ãçŽ90åç±³ãã«ã«ãªãå¯èœæ§ãããããšãæå³ããŸãã
æã人æ°ã®ãããšã¯ã¹ããã€ãã¯ããŒããã€æ»æãèµ·åããããã«äœ¿çšãããŸãããŒããã€æ»æã¯ããœãããŠã§ã¢ã®è£œé å ã«ã¯å®çŸ©ãããŠãããããœãããŠã§ã¢ãæŽæ°ãããŠãããã«ãŒãã³ã³ãã¥ãŒã¿ãŒãã¯ã©ãã¯ã§ããããã«ããŸãã 4æã«ãMicrosoft Wordã®ããŸããŸãªããŒãžã§ã³ã«åœ±é¿ãäžããè匱æ§ãçºèŠãããå°ãªããšã1æããããã«ãŒã«ãã£ãŠäœ¿çšãããŠããããšãããããŸããã åã4æã«ãMicrosoftã¯OfficeãŠãŒã¶ãŒãä¿è·ããããã®æŽæ°ããã°ã©ã ãå ¬éããŸããã
ãã¥ãŒãšãŒã¯ã®ããã³ã¯ã¹ã¬ããã³ç é¢ã»ã³ã¿ãŒã§ã®ã»ãã¥ãªãã£éåã®çµæãå°ãªããšã7,000人ã®æ£è ã®å»çèšé²ã䟵害ãããŸããã
æ»æè ãçŽæ¥é¢äžããªãã£ãä»ã®ã»ãã¥ãªãã£ã€ã³ã·ãã³ãããããŸããã ãããã®å Žåãæè¡çãªãšã©ãŒã®çµæãšããŠããŸãã¯åã«é倱ã«ãã£ãŠãå®éã«ãçå£ã«ä¿è·ãããã¹ãããŒã¿ã¯ããããã«ã¢ã¯ã»ã¹ããããã¹ãŠã®äººãå©çšã§ããããã«ãªããŸããã ããã¯èªåè»åäŒïŒAAïŒã§çºçãã4æã«13 GBã®ããŒã¿ãæ°æ¥éããªãŒãã³ãã«ãªãããã®äžã«ã¯ã¬ãžããã«ãŒãæ å ±ã«é¢é£ãã100,000ãè¶ ããé»åã¡ãŒã«ã¢ãã¬ã¹ãèŠã€ãããŸããã
åæ§ã®ã±ãŒã¹ãç±³åœã§ããã«é«ãã¬ãã«ã§çºçããŸããã ç±³åœå ±åå ãæ¡çšããããŒã±ãã£ã³ã°ãã£ã³ããŒã³ã«ããã1å9800äžäººã®ææš©è ïŒç±³åœã§ã¯2å人ãè¶ ããææš©è ïŒã®ããŒã¿ãå ¬éãããŠããŸãã ãã®ããŒã¿ã¯æ°æ¥éå©çšå¯èœã§ããããååãç幎ææ¥ãäœæãªã©ãåææš©è ã«é¢ãã詳现æ å ±ãå«ãŸããŠããŸããã
äžåœã§ã¯ãAppleã®é¡§å®¢ããŒã¿ã®éæ³ååŒã«ãã22人ãé®æãããŸããã äžéšã®è¢«æçŠè ã¯Appleãšäžè«ãäŒç€Ÿã§åããŠããããã®åŸè²©å£²ãããããŒã¿ã«ã¢ã¯ã»ã¹ã§ããããããã¹ãŠã®å åã¯ã€ã³ãµã€ããŒãæã瀺ããŠããŸãã
InterContinental Hotels GroupïŒIHGïŒã¯ã顧客ã«åœ±é¿ãäžããããŒã¿çé£ã®ç ç²ã«ãªã£ããšè¿°ã¹ãŸããã 2æã«ãå瀟ã¯çŽ10ã®ããã«ãæ»æã®åœ±é¿ãåãããšå ±åããŸããããçŸåšã§ã¯1000ãè¶ ããæœèšã§POS端æ«ã®ææã«ã€ããŠæ¢ã«ç¥ãããŠããŸãã 声æã®äžã§ãå瀟ã¯2016幎9æ29æ¥ãã12æ29æ¥ãŸã§ã«æ¯æãããã«ãŒãã«é¢ããåé¡ã確èªããã å瀟ã¯ãŸãã12æ29æ¥ä»¥éã¯æ¯æãæ å ±ãžã®äžæ£ã¢ã¯ã»ã¹ã«é¢ããæ å ±ãæã£ãŠããªããšèª¬æãããã2017幎3æãŸã§ãã«ãŠã§ã¢ã®å®å šãªé€å»ã®ç¢ºèªã¯ãªãã£ãã ãã®äŒæ¥ã°ã«ãŒããææããããŸããŸãªåœ±é¿ãåããããã«ãã§ãŒã³ã«ã¯ãHoliday InnãHoliday Inn ExpressãInterContinentalãKimpton HotelsãCrowne PlazaããããŸããã
OneLoginãµãŒãã¹ã¯ããŠãŒã¶ãŒã«ã¯ã©ãŠãå ã®ãã¹ãŠã®ãã©ãããã©ãŒã ãžã®ã·ã³ã°ã«ãµã€ã³ãªã³ãæäŸãããã䟿å©ã§å®å šãªæäœãæäŸããŸãããç®èã«ããããã³ã°ãããŸããã å瀟ã¯ããã°ã§æ»æãåããããã«ãŒã¯ç±³åœã®ããŒã¿ã»ã³ã¿ãŒã«äŸµå ¥ããããŒã¿ããŒã¹ãžã®ã¢ã¯ã»ã¹ãååŸãããŠãŒã¶ãŒæ å ±ãã¢ããªã±ãŒã·ã§ã³ããã¹ã¯ãŒããããã«ãŒã«å ¬éãããšè¿°ã¹ãŸããã
ã¢ãã€ã«æ©åš
6æ1æ¥ãããGoogleã¯ã補åã§æãæ·±å»ãªã»ãã¥ãªãã£äžã®è匱æ§ïŒä»¥åã¯æ€åºãããŠããªãã£ãïŒãèŠã€ãã人ã«ãããé«ãå ±é ¬ãæäŸãå§ããŸããã æåã®å ±é ¬ã¯50,000ãã«ãã200,000ãã«ã«å¢å ãã2çªç®ã®å ±é ¬ã¯30,000ãã«ãã150,000ãã«ã«å¢å ããŸããã
Broadcom Wi-Fi HardMAC SoCãããã®ãã¡ãŒã ãŠã§ã¢ã®è匱æ§ïŒCVE-2017-6975ïŒã¯ãWi-Fiãããã¯ãŒã¯ãžã®åæ¥ç¶æã«çŸãããããAppleã«iOSã¢ããããŒãïŒ10.3.1ïŒã®ãªãªãŒã¹ã匷å¶ããŸããã
ãã ãããã®è匱æ§ã¯iPhoneããã³iPadã ãã§ãªãããã®ã»ãã¥ãªãã£åé¡ã解決ããããã«4æã«æ°ããã»ãã¥ãªãã£ã¢ããããŒããåãåã£ãä»ã®ã¢ãã€ã«ããã€ã¹ïŒããšãã°ãSamsungãŸãã¯Google NexusïŒã«ã圱é¿ããŸãã
ã¢ãã®ã€ã³ã¿ãŒããã
çžäºæ¥ç¶ãããäžçã«äœãããšã¯éåžžã«å¿«é©ã«ãªããŸããã ãã ããåãåãå©äŸ¿æ§ã¯ã³ã€ã³ã®çåŽã«ãããŸããã
å察åŽã¯ãããšãã°WannaCryæ»æãªã©ã®ããŸããŸãªå±éºã«é¢é£ããŠããŸããWannaCryæ»æã¯ãã€ã³ã¿ãŒãããããã³ãããã¯ãŒã¯ãã¯ãããžãŒã®é«åºŠãªéçºã®ãããã§ãã¯ããã«æ·±å»ãªåœ±é¿ãåãŒããŸããã
éåžžã«é«ã¬ãã«ã®ãããã¯ãŒã¯æ¥ç¶ãæã¡ããããã¯ãŒã¯ã«æ¥ç¶ããã100äžå°ã®ããã€ã¹ã§æ§æãããã¹ããŒãã·ãã£ã¯ãæ¥åžžç掻ã«ãã¯ãããžãŒãå°å ¥ãããŠããæ確ãªäŸã§ãã äžçäžã®éœåžã¯ãŸããŸããã¹ããŒããã«ãªãã2020幎ãŸã§ã«500åãè¶ ããããã€ã¹ãã€ã³ã¿ãŒãããã«æ¥ç¶ããããšäºæž¬ãããŠããŸãã ããã«ãããã»ãã¥ãªãã£ãªã¹ã¯ãå€§å¹ ã«å¢å ããéœåžã€ã³ãã©ãä¿¡å·æ©ããŸãã¯éœåžçµŠæ°Žã·ã¹ãã ã®äœæ¥ã«æªåœ±é¿ãäžããå¯èœæ§ããããŸãã 6æããªãŒã¹ãã©ãªã¢ã®WannaCryã¯ãäžè«æ¥è ãææããã³ã³ãã¥ãŒã¿ãŒããããã¯ãŒã¯ã«æ¥ç¶ããåŸãä¿¡å·æ©ãšç£èŠé床ã«ãã55å°ã®ã«ã¡ã©ã«ææããŸããã ãã®äºä»¶ã®åŸãèŠå¯ã¯8,000件ã®çœ°éããã£ã³ã»ã«ããããåŸãŸããã§ããã
4æ7æ¥ååŸ11æ30åããã©ã¹ïŒç±³åœããããµã¹å·ïŒã§156ã®ç·æ¥ãµã€ã¬ã³ãåæã«é³ŽããŸããã åœå±ã¯ãç·æ¥éç¥ã·ã¹ãã å šäœããªãã©ã€ã³ã¢ãŒãïŒãªãã©ã€ã³ïŒã«ç§»è¡ããŠããããã40ååŸã«ãããããªãã«ã§ããŸããã ææ»å®ã¯ããã®äºä»¶ã®åå ãšãªã£ããã®æ»æã®èåŸã«èª°ãããã®ãããŸã ç¥ããŸããã
æè¿ãæ°ããè匱æ§ãçãŸãããããããããè»ã被害ãåããŸããã ãã ããéå»ã«èŠ³å¯ããä»ã®ã±ãŒã¹ãšã¯ç°ãªããè»ã®ã·ã¹ãã ãã¯ã©ãã¯ããã«ã¯ãç¹å®ã®ã¢ãŒãã§ã®ãšã³ãžã³é転äžã«ããã©ãã·ã¥ãã©ã€ãããæ¿å ¥ããå¿ èŠããããŸãã
ãããã«
ããã«ãŒã®ã°ã«ãŒããShadow Brokersãã¯ãçãŸããè³æãNSAã§å ¬éãç¶ããããšãèšç»ããŠããããµã€ããŒè»ã®ç«¶äºãæ¿åããã ãã§ãã ãã®ç¹ã§ãããŒã ãŠãŒã¶ãŒããã³äŒæ¥ãŠãŒã¶ãŒã¯è¿œå ã®ã»ãã¥ãªãã£å¯Ÿçãè¬ããå¿ èŠããããŸãã
ããŒã ãŠãŒã¶ãŒãšäžå°äŒæ¥ã¯ãææã®ãªã¹ã¯ãæãé«ããªããŸãã æªç¥ã®è åšããããå±éºã«ãããããŠããåœã«ã¯ããšã«ãµã«ããã«ããã©ãžã«ããã³ã°ã©ãã·ã¥ããã³ãžã¥ã©ã¹ããã·ã¢ããããºãšã©ããããŸãã
WannaCryãšPetyaã¯ãäžçäžã®æ¿åºããµã€ããŒæ»æãéå§ããå¿ èŠããããšãã«ããã¿ã³ãæŒããããšãæ¥ããããããªããããããªãããšã瀺ããŸããã ã€ã³ã¿ãŒããããšããã«æ¥ç¶ãããããã€ã¹ã䜿çšãããã¹ãŠã®äººããæçµçã«äžççãªãµã€ããŒæŠäºã®ç ç²è ã«ãªãå¯èœæ§ããããŸãã ãã®ãããäžçã®ãã¹ãŠã®å·ã«ããµã€ããŒæ»æãä»æããå·ã®èœåãå¶éããããã«ãããçš®ã®åœéæ¡çŽïŒãžã¥ããŒãæ¡çŽã®ç¹å®ã®é¡äŒŒç©ïŒãç· çµããæ¹æ³ãæ¢ãããšãæ±ããŸãã
æå·åæ»æã¯ãŸã å¢ãç¶ããŠãããããã«å¯Ÿããå¯äžã®èª¬æã¯ã被害è ããŸã 身代éãæ¯æã£ãŠãããšããããšã§ãã ããã§ãªããã°ããã®çš®ã®æ»æã¯ç¡é§ã«ãªããŸãã ãã®çæ°ã«çµæ¢ç¬Šãæã€ããšãã§ãããã©ããã¯ãç§ãã¡å šå¡ã«ããã£ãŠããŸãïŒäžæ¹ã§ã¯ã被害è ã«ãªããªãããã«è åšããèªåã確å®ã«ä¿è·ããå¿ èŠããããä»æ¹ã§ã¯ã身代éãæ¯æããªããŠæžãããã«åžžã«ããŒã¿ã®ããã¯ã¢ãããä¿æããªããã°ãªããŸããã
ãããããŒããã€æ»æãä»æããããã®æã人æ°ã®ãããšã¯ã¹ããã€ãã¯ããœãããŠã§ã¢ã¡ãŒã«ãŒã«ãŸã ç¥ãããŠããªãè匱æ§ã§ãã ã€ã³ãµã€ããŒæ»æã¯ãPOSãŠãŒã¶ãŒã«å¯Ÿããæ»æãšåæ§ã«ãããŒã ãŠãŒã¶ãŒããã³äŒæ¥ãŠãŒã¶ãŒã«ã倧ããªãªã¹ã¯ããããããŸãã
ã¢ãã€ã«ããã€ã¹ããããããçš®é¡ã®ã¢ãã®ã€ã³ã¿ãŒãããããã€ã¹ãŸã§ãã€ã³ã¿ãŒãããæ¥ç¶ã®æ°ã絶ããå¢å ããŠãããããæ»æã®æ°ã¯éå»ã«äžåºŠããªãã£ãã¬ãã«ãŸã§å€§å¹ ã«å¢å ããŸãã
ãã®åŸåã¯ã æ°çŸåã®ããã€ã¹ãéããªãã€ã³ã¿ãŒãããã«æ¥ç¶ããããã®æ°ã¯å¢å ããã ãã§ãã
æšå¥šäºé
åŸæ¥ã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã¯ãã»ãšãã©ã®æªæã®ããããã°ã©ã ã«å¯Ÿããä¿è·ã«äŸç¶ãšããŠæå¹ã§ãããç¡å®³ãªããŒã«ããã®ä»ã®é«åºŠãªæè¡ã䜿çšããæ»æã«ã¯å¯ŸåŠã§ããŸããã
çŽé¢ããè åšã®ã¬ãã«ã«é©ããã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã䜿çšããå¿ èŠããããŸãã Adaptive Defenseãªã©ã®EDRãœãªã¥ãŒã·ã§ã³ïŒãšã³ããã€ã³ãã®æ€åºãšå¿çããšã³ãããã€ã¹ãžã®æ»æã®æ€åºãšããããžã®å¿çïŒã¯ãæ°ããè åšãè€éãªæ»æããä¿è·ããããã«å¿ èŠãªãã¹ãŠã®ããŒã«ãæäŸã§ããå¯äžã®ãœãªã¥ãŒã·ã§ã³ã§ãã
æ»æããä¿è·ããéã«æãéèŠãªããšã¯ãå¿ èŠãªãã¹ãŠã®æ å ±ãå©çšã§ããããšã§ããäœãèµ·ãã£ããããã€ãã©ã®ããã«ãããŒã¿ãçãŸãããã©ãããªã©ã§ãã 䜿çšããã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã¯ããã®ããŒã¿ããã¹ãŠãªã¢ã«ã¿ã€ã ã§æäŸããå¿ èŠããããŸãããã®çµæãã€ã³ã·ãã³ãã®åŸ¹åºçãªåæãå®è¡ã§ããŸãã ããã¯ãå人ããŒã¿ä¿è·æ³ã®éµå®ã«ãšã£ãŠç¹ã«éèŠã§ãã
æ»æã®å Žåã®ã¢ã¯ã·ã§ã³ãã©ã³ãå¿ èŠã§ãã é ããæ©ãããç§ãã¡äžäººäžäººãæ»æã®è¢«å®³è ã«ãªãå¯èœæ§ããããããæ確ãªè¡åã§è¢«å®³ãå€§å¹ ã«æå°éã«æããããšãã§ããŸãã
äžçäžã®å€ãã®æ¿åºæ©é¢ãæ°éäŒæ¥ãåžæ°ç€ŸäŒçµç¹ã¯ãã§ã«åœç€Ÿã®æŠç¥ã«äŸåããŠããã Adaptive Defenseã¯Panda Securityã®æŽå²ã®äžã§æã売ããŠããã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãšãªã£ãŠããŸãã çµæžã®ããŸããŸãªéšéïŒéèãITãæŠåšããšãã«ã®ãŒãªã©ïŒã®å€§äŒæ¥ã¯ãAdaptive Defenseã䜿çšããŠã·ã¹ãã ãä¿è·ããŠããŸãã