ä»æ¥ããããæ°æéã§ã20äžçŽå šäœãããå€ãã®ãã«ãŠã§ã¢ãäœæãããŸãã ç®æšã¯å€åããæè¡ã¯ããè€éã«ãªããæ»æãã¯ãã«ã®æ°ã¯å¢å ããæ»æãå®è¡ããããã®ããŒã«ã¯ããåå¥ã«ãªããç¹å®ã®ç®æšã®ããã«äœæãããŠããŸãã æ»æè ã¯ãæŠç¥ã調æŽããŠæ倧éã®å¹æãåŸãããã«ãç ç²è ãæ éã«èª¿æ»ããŸãã
ãµã€ããŒæ»æã®æå¹æ§ãå¹çæ§ãããã³åçæ§ã¯ãæ°åã«ãã£ãŠåžžã«ç¢ºèªãããŠããŸãã2017幎ã«ã¯ãå¹³åã§æ¯æ¥æ倧285,000ã®æ°ãããµã³ãã«ãæ€åºãããŸããã
PandaLabs Antivirus Labã¯å¹Žæ¬¡å ±åæžãäœæãã 2018幎ã®äºæž¬ãçºè¡šããŸãã ã
ã¯ããã«
ã«ã€ã»ã³ãã³ãº
PandaLabs Antivirus Labã®ãã¯ãã«ã«ãã£ã¬ã¯ã¿ãŒ
äŒç€Ÿã®äžå¿ã§
æ å ±ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãéçºããŠããäŒç€Ÿã§ã¯ããŠã€ã«ã¹å¯Ÿçã©ãã¯åœŒå¥³ã®é è³ã§ãã ãããããè åšã®ç 究掻åãšãµã€ããŒé²åŸ¡æè¡ã調æŽãããŸãã
ç§ãã¡ã¯ãã客æ§ã®å®å šã«å¯Ÿãã責任ã®å šè²¬ä»»ãæ ããŸãã ãããã®1ã€ãææããŠããå Žåãç§ãã¡ã«ãšã£ãŠã¯å€±æã«ãªããŸãã 幞ããªããšã«ãPandaLabsãåæãããã«ãŠã§ã¢ã€ã³ã·ãã³ãã®æ°ã¯ãŒãã«ãªãåŸåããããŸãã
æ¬åœã«è¯ãä»äºãããŠãããšè©äŸ¡ãã1ã€ã®æ¹æ³ã¯ãç¬ç«ãããã¹ãã©ãã§ãœãªã¥ãŒã·ã§ã³ãåæããã³è©äŸ¡ããããšã§ãã ä»æ¥ãæã培åºçãªç 究ã¯ãã¡ããã AV-Comparativesã®ãªã¢ã«ã¿ã€ã ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ïŒReal World TestïŒã®ãã¹ãã®äžç°ãšããŠå®æœãããŠããŸãã ãã®ãã¹ãã¯ãè åšãæ€åºããããã®æé«ã®è©äŸ¡ãäžããåœç€Ÿã®ãœãªã¥ãŒã·ã§ã³ã«æäžãããŸããïŒ
ãã®ç§å¯ã¯äœã§ããïŒ
ãã®ã¬ããŒãã®æåŸã®ç« ã§ã¯ããã®ããšã«ã€ããŠããã«è©³ãã説æããŸãããäžè¬çã«ãç§å¯ã¯ãã«ãŠã§ã¢ããå¿ãããããšã§ãã ãã«ãŠã§ã¢ãšã®æŠãã«çŠç¹ãåããããšãæŠãã¯å§ãŸãåã«å€±ãããŸãã
Machine Learningãã¯ãããžãŒã䜿çšããŠãŠãŒã¶ãŒãä¿è·ãããšããããšã¯ãPandaLabsã®æè¡è ãæ»æãã®ãã®ã調æ»ããããã®æéãšãªãœãŒã¹ãå€§å¹ ã«å¢ããããšãæå³ããŸãã
ãããŠãããã¯æ»æè ã«ãšã£ãŠéåžžã«æªããã¥ãŒã¹ã§ãã åŒç€Ÿã®Threat HuntingããŒã ã¯ãäžèŠãã©ãã ãç¡å®³ã«èŠãããããããŸããããç°åžžãªè¡åãã¿ãŒã³ãåæããã³è¿œè·¡ããŠããŸãã ãã®çµæãèšå€§ãªæ°ã®æ°ããæ»æãæ€åºããããšãã§ããŸããããã®ãã¡ã®ããã€ãã«ã€ããŠã¯ããã®ã¬ããŒãã§èª¬æããŸãã
æå 端ã®ãã¯ãããžãŒãšãããŒãžããµãŒãã¹ã®çµã¿åããã«ãããã¢ã¯ãã£ããªããã»ã¹ã100ïŒ åé¡ããå®è¡äžã«äœãèµ·ããããæ確ã«ç¥ãããšãã§ããŸãã ç¡å¶éã®å¯èŠæ§ãšçµ¶å¯Ÿçãªå¶åŸ¡ã«ãããè åšã®åœ±é¿åºŠããŒãã«ãªããŸãã
æ»æã®é²å
äŒæ¥ãéè¡ã§ã¯ããããŸã§ã«ãªãã»ã©åŒ·çã®äºäŸããããŸããããçŸåšã§ã¯æ»æè ã被害è ããæ°åããé¢ããå Žæã«ããŠãç©ççã«åœŒå¥³ã«è¿ã¥ãããšã¯ãããŸããã
å®éãæ»æãããããã€ã¹ã¯ããµã€ããŒç¯çœªè ã«ãšã£ãŠé¢å¿ã®ããããŒã¿ããªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããªãå ŽåããããŸãããã®ãããªããã€ã¹ã¯ãæ»æã®éå§ç¹ãšããŠãã䜿çšã§ããªãããã§ãã
é¢å¿ã®ããããŒã¿ãŸãã¯ç¡å¹ã«ããã·ã¹ãã ãèŠã€ãããŸã§ãäŒæ¥ãããã¯ãŒã¯ã§æ°Žå¹³ããã¢ãŒã·ã§ã³ã䜿çšããŸãã
ãããã£ãŠããã«ãŠã§ã¢ä¿è·ããã³é èœã·ã¹ãã ã«äŸµå ¥ããããã®ãããã®æ°ããææ³ã«ãããäŒæ¥ãããã¯ãŒã¯ã§ã¯è åšãé·æéæ€åºãããªããªããŸãã
ä»
ãµã€ããŒç¯çœªã¯é åçã§åçæ§ã®é«ãããžãã¹ã§ãã æ»æè ã¯ããå€ãã®ïŒãããŠããè¯ãïŒããžã¿ã«ãªãœãŒã¹ãšéèãªãœãŒã¹ã䜿çšããŠããããããŸããŸãé«åºŠãªæ»æãè¡ãããšãã§ããŸãã
ãã¯ãããžãŒããã©ãã¯ããŒã±ããããªãŒãã³ãœãŒã¹ããŒã«ã®å¹ åºãå¯çšæ§ã®ãããã§ãã»ãŒå šå¡ãæ»æãä»æããããšãã§ããŸãã ãã®çµæãå¹æçãªããªã·ãŒãšã»ãã¥ãªãã£å¯Ÿçã«åãçµã¿å§ããã«ã¯ããã¹ãŠã®äŒæ¥ãé«åºŠãªæ»æã®æšçã«ãªãå¯èœæ§ããããšããåæããé²ãå¿ èŠããããŸãã ããããçš®é¡ã®çŸä»£çãªè åšãæ€åºããããã¯ãããã³æé€ããã¡ã«ããºã ã䜿çšãããšãäŒç€Ÿã®ãéãšè©å€ãä¿è·ã§ããŸãã
ãããã®ç¯çœªã®ã»ãšãã©ãã¹ãŠã«çµæžçåºç€ããããŸããããã¯ãã¹ãŠãéã®ããã«è¡ãããŸãã ããã«ãŒã¯åçæ§ã®é«ã被害è ã«æ¹ãããŸãã ãã®ãããæ»æãè€éã«ããç®æšãéæã§ããªãããã«ãããã察çãè¬ããå¿ èŠããããŸãããã®çµæãå¹æãäœäžããŸãã
ã»ãšãã©ã®å Žåãæ»æãå°é£ã«ãªããæ»æè ãæçµç®æšã«å°éã§ããªãå Žåãæ»æè ã¯å¥ã®è¢«å®³è ã«ç§»åãããããªããæ»æãããè¿ éãã€ç°¡åã«å®è¡ã§ãããæè³ãã«å¯Ÿããé«ãã¬ãã«ã®åçãåŸãããšãã§ããŸãã
ãã®ãããªæ»æã®è€éããç解ããããã«ãäŒæ¥ã®ã»ãã¥ãªãã£äŸµå®³ã®äºäŸã®62ïŒ ã§ãããã³ã°æè¡ã䜿çšããããšããŸãããã å®éã ããã«ãŒããã«ãŠã§ã¢ã䜿çšããã®ã¯ããã51ïŒ ã§ãã ã ä»ã®ã±ãŒã¹ã§ã¯ãã»ãšãã©ã®äŒæ¥ãä¿è·ãããŠããªãä»ã®ããŒã«ã䜿çšããŸããã
ããªãã®äŒç€Ÿããµã€ããŒæ»æã®ç ç²ã«ãªã£ãå Žåãã©ã®ãããªå¯Ÿçãè¬ããã¹ãããç¥ãããã«å°é家ã®æ å ±ãæã£ãŠããããšãéåžžã«éèŠã§ãã
ãŸããæ»æãã©ãããå§ãŸã£ãã®ããã©ã®ææ³ã䜿çšãããã®ããã©ã®ãããªé²æ©ããªãããã®ããé²åŸ¡ãã©ã®ããã«å æãããã®ããªã©ãç¥ãããšã圹ç«ã¡ãŸãã
ãã®ä»ã®åæ©ä»ãèŠå
ã»ãšãã©ã®æ»æã¯ééçã«åæ©ä»ããããŠããŸãããç®æšããŸã£ããç°ãªãæ»æã®å²åã¯ãŸã ãããã§ãã
2017幎ã«ããŠã¯ã©ã€ãã®äŒæ¥ã«å¯Ÿããããã£ã¢/ãŽãŒã«ãã³ã¢ã€ã®æ»æã確èªãããŸããã åæ©ã¯æ¿æ²»çã§ããããŠã¯ã©ã€ãæ¿åºã¯ãã·ã¢æ¿åºããããã®æ»æã®èåŸã«ãããšå ¬ç¶ãšéé£ããã
ããããããã¯å€ç«ããã±ãŒã¹ã§ã¯ãããŸããã ç§ãã¡ã¯ãµã€ããŒè»æ¡ç«¶äºã®éæºå°ã«ããŸããåœã ã¯æ»æäœæŠã®ããã ãã§ãªããå€éšã®è åšã«å¯Ÿããä¿è·ã匷åããéèŠãªã€ãã·ã¢ãããšããŠãµã€ããŒè»éãäœæããŠããŸãã
ããšãã°ãåç±³åœå€§çµ±é ãªãã倧統é ãæ¡çšããæ å ±ã»ãã¥ãªãã£èšç»ã§ã¯ã2020幎ãŸã§ã«åŸç¶è ã«100,000人ã®æ°ããã³ã³ãã¥ãŒã¿ãŒã»ãã¥ãªãã£ã®å°é家ãæºåãããã匷å¶ããŠããŸãã å®éã2018幎ã®ç®æšã¯ããµã€ããŒããã·ã§ã³ãã©ãŒã¹ã®ããã«133ããŒã ãæã€ããšã§ãã
ãã¹ãŠã®åœã¯ãè»éã«ãµã€ããŒè»ãå¥ã®äœæŠéšéãšããŠå«ããããšãåªå äºé ã§ãããšèããŠããŸãã 確ãã«ããã®ãããªãŠãããã¯ãå€ãã®å Žåãèªç±ã«äœ¿ããããªã倧ããªäºç®ãæã£ãŠããŸãã
ãã¬ã³ã
æµãç¥ã
æ°ããæ»æãã¯ãã«ã¯ãããè€éãªæ»æã®äœæã«åœ¹ç«ã¡ãŸãã ãµã€ããŒç¯çœªè ã¯ããšã¯ã¹ããã€ããå©çšããæ°ããããŒã«ãäœæããŠããŸãã ç¶æ³ãè€éã«ããããã«ã圌ãã¯ãã¯ãæ»æã®æåã®ããã«äººéã®çžäºäœçšã«äŸåããŠããŸããã
ãã®ã¢ãããŒãã«ã¯ãç ç²è ã®åŸ¹åºçãªèª¿æ»ãéåžžã«ç¹æ®ãªã»ãã¥ãªãã£ããŒã«ã®æªçšã«å¯ŸããæŠè£ ããåå¿ãããã³äººéã®ä»å ¥ãå¿ èŠãšããªããã«ãŠã§ã¢ã®èªåãã€è¿ éãªæ¡æ£ã®äœ¿çšãå«ãŸããŸãã
被害è ã®ãããã¯ãŒã¯ãšãã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãšãªã¢ã«ã¿ã€ã ã§ããåãããç®æšãéæããããã«ç°å¢ã«é©å¿ããŸãã
äœãæ±ã£ãŠããããç¥ãããšãéèŠã§ãã
Panda Securityã§ã¯ããµã€ããŒãã«ãã§ãŒã³ãäœæããŠãæ»æè ã®èŠ³ç¹ããç©äºãèŠèŠåããæåã®æ®µéããæçµç®æšã«å°éãããŸã§ã®ããŸããŸãªæé ãæããã«ããŸããã
ãã®ã·ãŒã±ã³ã¹ã¯ãæ»æã®ã©ã€ããµã€ã¯ã«ã®ãããã段éã§è åšãæ€åºããŠãããã¯ããããšã«ãããäŒæ¥ãã©ã®ããã«é²åŸ¡ãå€§å¹ ã«åŒ·åã§ããããç解ããããã®åªããããŒã«ã§ãã
ãµã€ããŒãã«ãã§ãŒã³ã¯ãããã«ãŒãæåããã«ã¯ãã§ãŒã³ã®ããããã¹ãŠã®æ®µéãçµãªããã°ãªããªãããç§ãã¡ãããå¿ èŠãããã®ã¯ããããã段éã§æ»æãããã ãæ¢ããããšã ãã§ããããšã瀺ããŠããŸãã
ãã®ããã¥ã¡ã³ãã§ã¯ãåã»ã¯ã·ã§ã³ã®è©³çŽ°ãªèª¬æãæäŸããŸãã ãããªãã芧ãã ããã
ç®æšã¯ãšã³ãããã€ã¹ã§ã
èšåãã䟡å€ã®ããéèŠãªãã€ã³ãã®1ã€ã¯ãæ»æã«ã€ããŠè©±ããšãã§ãã å€ãã®å Žåãã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãããã€ããŒã¯ããããã¯ãŒã¯ã®å¢çãç©äºã®ã€ã³ã¿ãŒããããããã³ä¿è·ãå¿ èŠãªä»ã®ãã¯ãã«ã«ã€ããŠå€ãã®æéãè²»ãããŸãããæãéèŠãªããšã¯ãèŠèœãšãããã¡ãªããšã§ãïŒãšã³ãããã€ã¹èªäœã
ãªãããããããªã«éèŠãªã®ã§ããïŒ æ»æè ããšã³ãããã€ã¹ã«å°éã§ããªãå Žåãä»ã®ã¿ãŒã²ããã«ã¢ã¯ã»ã¹ããããæ å ±ãæœåºãããããããã¯ãŒã¯ããŒã¿ãåéããããæ°ããæ»æãä»æãããããããšã¯ã§ããŸããã ãã®åŸåã¯ã次ã®ã°ã©ãã«æ確ã«ç€ºãããŠããŸãïŒç®æšã«å¿ããã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®å²åïŒã
ããã«ãããããããäŒæ¥ã®ã»ãã¥ãªãã£äºç®ã®ããªãã®è³éã¯ããããã¯ãŒã¯ã®å¢çãä¿è·ããããã«å²ãåœãŠãããéèŠãªéšåã§ãããšã³ãããã€ã¹ãç¡èŠããŠããŸãã
ããã¯ç¡ç¥ãé倱ã«ãããã®ã§ã¯ãããŸããã éå»ã«ã¯ããããã¯ãŒã¯ã®å¢çã«çŠç¹ãåœãŠãããšã¯æ¬åœã«çã«ããªã£ãŠããŸããã äŒæ¥ãããã¯ãŒã¯å ã§ã¯ããšã³ãããã€ã¹ã¯ã»ãšãã©å®å šã§ãã£ããããåªå é äœã¯ãå¢çãå æããã¯ãã®å€éšæ»æããã®ä¿è·ã«ã·ãããããŸããã
ä»æ¥ãç¶æ³ã¯åçã«å€åããŸãããå¢çã¯ãŒãããŠãããã©ã®äŒæ¥ã§ãã¢ããªãã£ãæšæºã«ãªããäŒæ¥ãããã¯ãŒã¯ã¯ãã倧ããªåœ±é¿ãåããŠããŸãã
æ»æè ã¯ãåã ã®ã³ã³ãã¥ãŒã¿ãŒã«ç®ãåããããšããããããŸããå°ãªããšã1ã€ã«ã¢ã¯ã»ã¹ã§ããã°ãçºèŠãããåã«åŸç¶ã®ã¢ã¯ã·ã§ã³ãå®è¡ã§ããå¯èœæ§ãéåžžã«é«ããªããŸãã
ãããã£ãŠãåªå é äœã®èšå®ãã€ãŸã æè³ãå¢ããå¿ èŠæ§ã«ã€ããŠã§ã¯ãªããã©ãã«æè³ãããã«ã€ããŠã§ãã ããã¯Capgeminiã®èª¿æ»ã§å®èšŒãããŠãããã»ãã¥ãªãã£æè³ã®ã¬ãã«ãšäŒæ¥è³ç£ã®å®éã®ä¿è·ã¬ãã«ãæ¯èŒããŸããã
ãã£ã®ã¥ã¢
æ»æã®å°éåã®æãæãããªçµæã®1ã€ã¯ããã«ãŠã§ã¢ã®ææ°é¢æ°çãªå¢å ã§ãã Verizonã«ãããšãæå·äœæè ãé¢äžããæ»æã®æ°ã®ã¿ãã»ãŒ50ïŒ å¢å ããŠããŸãã
ããã¯ãæ»æã®æ°ãå¢ãããšããäºå®ã ãã§ã¯ãããŸããïŒãããäºå®ã§ãïŒã äž»ã«ããµã€ããŒç¯çœªè ã䜿çšããæè¡ã®ç¯å²ãæ¡å€§ããããšã«äŸåããŠããŸãã
10幎以äžåã«ããã®åŸåã説æããèšäºãå ¬éããŸããã ã¬ããã¹ãã¯ãã£ãåæã§ã¯ã2002幎ã«æãäžè¬çãª10ã®è åšããã¹ãŠã®ææã®40ïŒ ãåŒãèµ·ããã2006幎ã«ã¯ãã®æ°å€ã10ïŒ ã«äœäžããããšãããããŸããã
2017幎ã®ç¶æ³ã¯ïŒ
ãªããªã ãã¹ãŠã®æ±ºå®ãã¯ã©ãŠããšçžäºäœçšãããã®åŸåãããé¡èã«ãªã£ããã©ãããåæããããã®ãã¹ãŠã®ããŒã¿ããããŸãã
ææšãèšç®ããããã«ã2017幎1æ1æ¥ãŸã§ã«èŠãããšã®ãªãæªæã®ããããã°ã©ã ïŒPEãã¡ã€ã«ïŒããã¹ãŠçµã³ä»ããŸããã 2017幎9æ20æ¥ã®æç¹ã§ã15 107 232åã®ããŸããŸãªæªæã®ãããã¡ã€ã«ãåãåããŸããã ãããŠããããã¯ç§ãã¡ã以åã«äŒã£ãããšã®ãªããã®ã ãã§ãã äœæãããæªæã®ããããã°ã©ã ã®ç·æ°ã¯ã¯ããã«å€ããªããŸããããã§ã¯ããã¹ãŠã®çš®é¡ã®ãã¡ã€ã«ïŒã¹ã¯ãªãããããã¥ã¡ã³ããªã©ïŒãããã³äœæãããã°ããã§ãããã客æ§ã«ææããããšããããšã®ãªããã¡ã€ã«ãè¿œå ããå¿ èŠãããããã§ãã å®éã®æ°ã¯ãçŽ75,285,000ã®æ°ãããã«ãŠã§ã¢ãµã³ãã«ã§ãã
以äžã¯ãåœç€Ÿã®ã¯ã©ãŠãã§æãé »ç¹ã«åãäžããããŠãããã«ãŠã§ã¢ã®10åã®ãµã³ãã«ã§ãã
ãã®ãããã10ãã«ã¯ã2017幎ã«çºçããæãæ·±å»ãªã±ãŒã¹ã«é¢é£ãããã¡ã€ã«ã衚瀺ãããã®ã¯åœç¶ã§ããããšãã°ãWannaCryïŒ3ã7ã9ã10ç®æïŒãšCCleanerã®ãããã¯ãã¢ãããŒãžã§ã³ïŒ1ã4ç®æïŒã§ãã æ®ãã¯ããŠã³ããŒããŒïŒãã¹ãŠã®çš®é¡ã®ãã«ãŠã§ã¢ãã€ã³ã¹ããŒã«ããããã®åªä»ãšããŠäœ¿çšãããããã€ã®æšéŠ¬ïŒãšãããã§ãã
15åã®107 232åã®ãã«ãŠã§ã¢ãµã³ãã«ãã¹ãŠã®ãã¡ãäžåºŠã ãèŠããã®ã¯ããã€ã§ããïŒ 99.10ïŒ ãã€ãŸã 14 972 010ãµã³ãã«ã
å察åŽã®æ°åãèŠããšãè åšã®ç·æ°ã®ãã¡ããäžéšããåºãã£ãŠããªãããšãããããŸãã
åèš989åã®æªæã®ãããã¡ã€ã«ã1000å°ãè¶ ããã³ã³ãã¥ãŒã¿ãŒã«ååšããŠããããšãããããŸããã ããã0.01ïŒ ã
ããã«ããããã§ã«ããã£ãŠããããšã確èªã§ããŸããããã€ãã®äŸå€ïŒWannaCryãHackCCleanerãªã©ïŒãé€ããã»ãšãã©ã®ãã«ãŠã§ã¢ã¯æ°ããææããšã«å€åãããããåãµã³ãã«ã®ååžã¯éåžžã«éãããŠããŸãã
ãããã家æãŸãã¯ã¿ã€ãå¥ã«ã°ã«ãŒãåãããšãã©ã³ãµã ãŠã§ã¢ãé¡èã«åºå¥ãããããšã¯é©ãããšã§ã¯ãããŸããã ããã¯ãæãåçæ§ã®é«ãã¿ã€ãã®æ»æã®1ã€ã§ãããããæã人æ°ããããŸãïŒæ¯å¹Žããã®äººæ°ãé«ãŸãã ãã§ãïŒã
ãããã«ãããç§ãã¡ãçŽé¢ããŠããææãªã¹ã¯ãç¥ãããå Žåãæ°ãããã«ãŠã§ã¢ãµã³ãã«ã®ç·æ°ã¯ããããã«ééããé »åºŠãšã¯å¯Ÿç §çã«ãããã»ã©éèŠã§ã¯ãããŸããã ãã®ææšãèšç®ããããã«ãæªæã®ããæ»æããã¡ã€ã«ã¬ã¹æ»æããŸãã¯å®å šã«æ£åœãªã·ã¹ãã ããŒã«ã䜿çšããæ»æãå«ããã·ã°ããã£ãŸãã¯ãã¥ãŒãªã¹ãã£ãã¯ã«ãã£ãŠæ€åºãããªããã«ãŠã§ã¢ã«ææããè©Šã¿ã®ã¿ã枬å®ããŸããïŒããã¯äŒæ¥ç°å¢ã§äžè¬çã«ãªãã€ã€ããã 6æã«Goldeneye / Petyaã®å Žåã«èŠãããã«ïŒã
枬å®ã«ã¯ãã³ã³ããã¹ãã€ã³ããªãžã§ã³ã¹ãšåŒã°ãããã®ãæ§æããå€ãã®ç¬èªã®ãã¯ãããžã«ãã£ãŠåéãããããŒã¿ã䜿çšããŸããã æªæã®ããåäœã®ãã¿ãŒã³ãèå¥ããæ¢ç¥ããã³æªç¥ã®è åšã«å¯Ÿããé«åºŠãªãµã€ããŒé²åŸ¡ã¢ã¯ã·ã§ã³ãçæããã®ã«åœ¹ç«ã¡ãŸãã
次ã«ãååŸããæ»æã®ããŒã¿ã®åæãéå§ããŸããã
ç§ãã¡å šå¡ãåãä¿è·å ·ãæã£ãŠããããã§ã¯ãããŸããããªããªã èªå® ã®PCãäžå°äŒæ¥ã®ã³ã³ãã¥ãŒã¿ãŒã¯åºæ¬çãªä¿è·ã¬ãã«ïŒãªã¹ã¯ãé«ãïŒãæã£ãŠããå¯èœæ§ãé«ããäžèŠæš¡ããã³å€§äŒæ¥ã¯ããŒã¿ãä¿è·ããããã«ããå€ãã®ãªãœãŒã¹ãå²ãåœãŠãŠããŸãã
ãã®ã¬ããŒãã§ã¯ããã¹ãŠã®ä¿è·ã¬ãã«ãééããæ€åºããããã³ã³ãã¥ãŒã¿ãŒã䟵害ãããçŽåã®æåŸã®ç¬éã«åæ¢ããæ»æã®ã¿ãèæ ®ããŸãã ããå€ãã®è³éãã»ãã¥ãªãã£ã«å²ãåœãŠãäŒæ¥ã¯ããã®ãããªæ»æãå°ãªãããå¿ èŠããããŸã-å®éããã®çµ±èšã¯ç¢ºèªããŠããŸãã ããŒã ãŠãŒã¶ãŒãšäžå°äŒæ¥ã®éã§ã®ãã®ãããªæ»æã®å²åã¯4.41ïŒ ã«éããŸãããäžèŠæš¡ããã³å€§èŠæš¡äŒæ¥ã§ã¯ãã®æ°å€ã¯2.41ïŒ ã«äœäžããŸãã
ãã®ããŒã¿ã¯äŒç€Ÿããæ¹sãããå¯èœæ§ããããŸãããããŸãããªãã§ãã ãããäŒç€Ÿãå·ã€ããããã«ãæ»æè ã¯äŒæ¥ãããã¯ãŒã¯äžã®ãã¹ãŠã®ã³ã³ãã¥ãŒã¿ãŒãæ»æããå¿ èŠã¯ãããŸããã å®éãå°æ°ã®ã³ã³ãã¥ãŒã¿ãŒãæ»æããŠæ€åºããããæ€åºã®ãªã¹ã¯ãæå°éã«æããç®æšãéæããŸãã
æ»æã®å°ççååžã
ååœã§æ»æãããè»ã®å²åãèšç®ããŸãããå²åãé«ãã»ã©ããã®åœã§ã³ã³ãã¥ãŒã¿ãŒã䜿çšãããšãã«æ°ããè åšã®è¢«å®³è ã«ãªãå¯èœæ§ãé«ããªããŸãã
2017幎ã®æ§å
2017幎ã®æ倧ã®æ»æã远跡ããããšã¯ããžã§ããã³ãŒã¹ã¿ãŒã®ä¹ãç©ã«å°ã䌌ãŠããŸãããããã®ã»ã¯ã·ã§ã³ãééãããŸã§ãåã«ãããã®ãèŠãããšãã§ãããããªããã©ãã ãé«ãäžããããã©ãã ãèœã¡ããããããŸããã ãããããã®äžç¢ºå®æ§ã«ããããããã1ã€ç¢ºããªããšããããŸãããã®ãããªãã®ãèŠãããšããªããããç°¡åã«å¿ããããšã¯ã§ããŸããã
EquifaxãCCleanerãSabreãWPA2ãVault7ãCIAãKRACKãNSAãElection Hacking ...ãããã¯ã以äžã§åæããã»ãã®äžéšã§ãã ãããã¯ã倧éææãããŒã¿çé£ãã©ã³ãµã ãŠã§ã¢ã«ããæ»æããããã³ã°ãããã¢ããªã±ãŒã·ã§ã³ããµã€ããŒæŠäºã倧äŒæ¥ã«å¯Ÿããæšçåæ»æãããã³æ°ååã®ããã€ã¹ã«åœ±é¿ãåãŒãè匱æ§ã®åå ã§ãã
ãããã圱é¿ã®çšåºŠãšåŒãèµ·ãããããã¡ãŒãžã®ã¬ãã«ã®ããã«ãä»ã®ãã®ããéç«ã£ã2ã€ã®æ»æããããŸãïŒWannaCryãšGoldenEye / Petyaã
WannaCryã¯2017幎5æã«ç»å ŽããäŒæ¥ãããã¯ãŒã¯ã«å€§æ··ä¹±ããããããäžçäžã«åºãããæŽå²äžæãæ·±å»ãªæ»æã®1ã€ã«ãªããŸããã 被害è ã®æ°ãšé ä¿¡ã®é床ã®èŠ³ç¹ãããéå»ã®ãã匷åãªæ»æïŒããšãã°ãBlasterãŸãã¯SQLSlammerïŒã§èŠãã«ããããããã以åã®æ»æã«ãã被害ã¯ãé ä¿¡ã®ã¬ãã«ã«æ¯ã¹ãŠäºæ¬¡çã§ããã ãã ãããã®å Žåããããã¯ãŒã¯ã¯ãŒã ã®æ©èœãåããæå·åããã°ã©ã ã§ããWannaCryã¯ãææããåã³ã³ãã¥ãŒã¿ãŒäžã®ããŒã¿ããããã¯ããã³æå·åããŸããã
PandaLabsã®ãã¯ãã«ã«ãã£ã¬ã¯ã¿ãŒã§ããLuis Corronsã¯ãŠã§ãããŒãå®æœããçºçãããã¹ãŠã詳现ã«åæãããã®ã¿ã€ãã®ä»ã®æ»æããä¿è·ããããã«è¬ããã¹ã察çãæ€èšããŸããã ããã§ãŠã§ãããŒãèãããšãã§ããŸã ã
Goldeneye / NotPetyaã¯ãWannaCryå°éã®éã®ããã·ã¥ã®ããã«ã2017幎ã«2çªç®ã«ç®ã«èŠããæ»æã§ããã 被害è ã¯åœåãç¹å®ã®å°ççé åïŒãŠã¯ã©ã€ãïŒã«éå®ãããŠããŸããããäžç60ãåœã®äŒæ¥ãäŸç¶ãšããŠãã®æ»æã«èŠããã§ããŸããã
æ éã«èšç»ãããæ»æã¯ããŠã¯ã©ã€ãã®äŒæ¥ã®éã§éåžžã«äººæ°ã®ããçµçã¢ããªã±ãŒã·ã§ã³MEDocãéããŠå®è¡ãããŸããã æ»æè ã¯ãã®ããã°ã©ã ã®æŽæ°ãµãŒããŒã䟵害ããŸããããã®çµæãMEDocããã°ã©ã ãã€ã³ã¹ããŒã«ããããã¹ãŠã®ã³ã³ãã¥ãŒã¿ãŒããã®ãã«ãŠã§ã¢ã«èªåçã«ææããå¯èœæ§ããããŸããã
ãã¡ã€ã«ã®æå·åã«å ããŠãã³ã³ãã¥ãŒã¿ãŒã§ã»ãã·ã§ã³ãéå§ããããŠãŒã¶ãŒã«ç®¡çè æš©éãããå Žåããã«ãŠã§ã¢ã¯ããŒããã©ã€ãã®ã¡ã€ã³ããŒãé åïŒMBRïŒã«ç§»åããŸããã æåã¯WannaCryã¹ã¿ã€ã«ã®æå·åããã°ã©ã ã§ããããã«èŠããŸããããæ éã«åæããçµæãããã«ãŒããã¡ã€ã«ãå埩ããæ©èœãå®éã«æäŸããã€ããã¯ãªãããšãæããã«ãªããŸããã æ°æ¥åŸããŠã¯ã©ã€ãæ¿åºã¯ãã·ã¢ãæ»æã«é¢äžãããšå ¬ç¶ãšéé£ããã
Louis Corronsã¯ããã®æ»æãšãã®äœè ã«ã€ããŠã圌ã®ãŠã§ãããŒã§è©±ããŸãã ã
ãµã€ããŒç¯çœª
ç±³åœFBIãäœæããFBIãçºè¡ãããªã³ã©ã€ã³ç¯çœªã¬ããŒãã§ãã2016 Internet Crime Reportã«ãããšããµã€ããŒç¯çœªã«ãã被害ã¯24ïŒ å¢å ããŠ1ã«éããŸããã 30åãã«ã ã»ã³ã¿ãŒã«ãããšãç±³åœããã®IC3ç ç²è ã«ãã£ãŠå ±åãããéã«ã€ããŠã®ã¿è©±ããŠããããšã«æ³šæããå¿ èŠããããŸãã ãããã£ãŠãç±³åœã ãã§ã®æ¬åœã®æ害ã¯ã2016幎ã«ã®ã¿90åç±³ãã«ã«éããå¯èœæ§ããããŸãã
æ»æãéå§ããããã®æãé åçãªãšã¯ã¹ããã€ãã¯ããŒããã€ãšã¯ã¹ããã€ããšããŠç¥ãããŠããŸãã ãœãããŠã§ã¢ã¯å®å šã«æŽæ°ãããŠããã«ããããããããœãããŠã§ã¢ã¡ãŒã«ãŒã«ã¯ç¥ãããŠããªããããããã«ãŒããŠãŒã¶ãŒã䟵害ããå¯èœæ§ããããŸãã
2017幎4æãMicrosoft Wordã®äžéšã®ããŒãžã§ã³ã«åœ±é¿ãããŒããã€è匱æ§ãçºèŠãããå°ãªããšã1æããããã«ãŒã«ãã£ãŠäœ¿çšãããŠããããšãå€æããŸããã åãæã«ãMicrosoftã¯OfficeãŠãŒã¶ãŒã«å¿ èŠãªæŽæ°ããã°ã©ã ããªãªãŒã¹ããŸããã
RDPPatcherã¯ããµã€ããŒç¯çœªã®ããæèãé«ãŸã£ãŠããããšã瀺ããŠããŸãã PandaLabsã®ç 究æã§çºèŠããããã®æ»æã¯ãéåžå Žã§ã®ããªãŒã¹ãã®ããã«è¢«å®³è ã®ã³ã³ãã¥ãŒã¿ãŒãæºåããŠããŸãã
ãµã€ããŒç¯çœªè ã¯æ€åºãåé¿ããããã«å¯èœãªãã¹ãŠã®ããšãè¡ã£ãŠããŸãããããã«å¯Ÿããæãå¹æçãªæ¹æ³ã¯ãã«ãŠã§ã¢ã䜿çšããªãããšã§ãã ãã®ããããã«ãŠã§ã¢ã䜿çšããªãæ»æãéåžžã«äžè¬çã«ãªã£ãŠããŸãã PandaLabsã©ãã§çºèŠãããã±ãŒã¹ã§ã¯ãã³ã³ãã¥ãŒã¿ãŒã®ããã«ãŒã¯ãå°å ¥ããããªãŒãã³ããã¯ãã¢ãæ®ããŸããããã®åŸããã«ãŠã§ã¢ãã€ã³ã¹ããŒã«ããã«ã¹ãã£ãããŒããŒãªãã·ã§ã³ã䜿çšããã«ããã€ã¹ã«ã¢ã¯ã»ã¹ããŸããã
2016幎åŸåã«ã¯ãã¡ãã£ã¢ã§åºãè°è«ãããDDoSæ»æãããã€ãèŠãããŸãããã2017幎ã«ã¯ããã«å€ãã®DDoSæ»æããããŸããããããã»ã©åŒ·åã§ã¯ãããŸããã§ããã ããšãã°ããã€ãºéè¡ã®é¡§å®¢ã¯ããµãŒããŒã«åœ±é¿ãäžããDDoSæ»æã®çµæããªã³ã©ã€ã³ãã³ã¯ãžã®ã¢ã¯ã»ã¹ã«åé¡ããããŸããã
ã€ã¿ãªã¢ã®èŠå¯ã¯ã2017幎1æã«2人ã®ã€ã¿ãªã¢åžæ°ïŒåœŒãã¯èŠªæïŒã«ãã£ãŠçµç¹ãããæ©é¢ãåœå±ãäŒæ¥ãããžãã¹ãã³ãæ¿æ²»å®¶ãã¹ãã€ããEye PyramidãšåŒã°ãããµã€ããŒã¹ãã€ãããã¯ãŒã¯ãéèšããŸããã
ãœãŒã·ã£ã«ãããã¯ãŒã¯ã§ã®ã¢ã«ãŠã³ãã®ãããã³ã°ãäžè¬çã«ãªããæãé¡èãªã±ãŒã¹ã®1ã€ã¯ããããã³ã°ããããã¥ãŒãšãŒã¯ã¿ã€ã ãºã®å ¬åŒTwitterã¢ã«ãŠã³ãã§1æã«çºçããŸããã ã¢ã«ãŠã³ãã®å¶åŸ¡ãåãæ»ããåŸãããã«ãŒã«ãã£ãŠæçš¿ããããã€ãŒããåé€ããŸããã
以äžã¯ããããã³ã°ãããã¢ã«ãŠã³ãã«æçš¿ããããã€ãŒãã®1ã€ã®äŸã§ãã ãã·ã¢ã¯ç±³åœã«å¯Ÿããæ»æãéå§ããäºå®ã§ãããšè¿°ã¹ãŠããŸãã
åãã°ã«ãŒãã®ããã«ãŒããNetflixãMarvelãªã©ã®ä»ã®äŒæ¥ã®ã¢ã«ãŠã³ãããããã³ã°ããŸããã
ããã«ã³ç¯çœªãã¡ããªãŒããšããŠç¥ããããµã€ããŒç¯çœªè ã®ã°ã«ãŒãã¯ã2å5åäžäººã®ãŠãŒã¶ãŒãææããiPhoneãiPadãããã³Macã®ããŒã¿ç Žå£ãè ãã身代éãèŠæ±ããŠAppleãè è¿«ããŸããã Appleã¯æmailã«å±ããŸããã§ããã
äŒæ¥ããŒã¿ã®çé£
2017幎ã«ã¯ãããŒã¿çé£äºä»¶ããã¥ãŒã¹ã®èŠåºãã«ç»å ŽããŸããã ãããããä»å¹Žæãç®èãªè©±ã¯ãç¹ã«ã¢ãã€ã«ããã€ã¹ããããŒã¿ãæœåºããããã«é»è©±ããããã³ã°ãããµãŒãã¹ãæäŸããã€ã¹ã©ãšã«ã®äŒæ¥Cellebriteã§èµ·ãã£ããã®ã§ãã ãã®ããããã®äŒç€Ÿã¯ãããã³ã°ããããã®çµæãã¯ã©ã€ã¢ã³ãããŒã¿ããŒã¹ãããŒã¿ããŒã¹ãäŒç€Ÿã®è£œåã«é¢ããæè¡æ å ±ãªã©ã900 GBã®ããŒã¿ãçãŸããŸããã
ãã¥ãŒãšãŒã¯ïŒç±³åœïŒã®ããã³ã¯ã¹ã¬ããã³ç é¢ã»ã³ã¿ãŒã§ã®ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®çµæãå°ãªããšã7,000人ã®å»çèšé²ã䟵害ãããŸããã
æ»æè ãé¢äžããŠããªãå¥ã®çš®é¡ã®ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã¯ãšã©ãŒãŸãã¯é倱ã§ããããã®çµæã確å®ã«ä¿è·ããå¿ èŠã®ããããŒã¿ãå ¬éãããŸãã ããã¯ãå ±åå ãéçšããããŒã±ãã£ã³ã°ãã£ã³ããŒã³ã«ããã1å9,800äžäººã®ç»é²ææš©è ïŒç»é²ææš©è ã®ã»ãŒãã¹ãŠïŒã®ããŒã¿ã誀ã£ãŠå ¬éãããããã«çºçããŸããã
ããŠã»ãžã§ãŒã³ãºã¯ãèšå®ãšã©ãŒã®çµæãšããŠãAmazonã¯ã©ãŠããµãŒãã¹ãä»ããŠã200äžäººã®ãŠãŒã¶ãŒã®ããŒã¿ãžã®ã¢ã¯ã»ã¹ã誀ã£ãŠèš±å¯ããŸããã ãã®ããŒã¿ã§ã¯ããŠãŒã¶ãŒã®ååãã¡ãŒã«ã¢ãã¬ã¹ãéè¡ã«ãŒãçªå·ãèŠã€ããããšãã§ããŸãã
22人ã¯Appleã®é¡§å®¢ããŒã¿ã®ååŒã§äžåœã§é®æãããŸããã ãã¹ãŠã®èšŒæ ã¯ã€ã³ãµã€ããŒã®äºå®ã瀺ãã äžéšã®è¢«æçŠè ã¯ããã®ããŒã¿ã«ã¢ã¯ã»ã¹ã§ããAppleããŒãããŒäŒæ¥ã§åããŠããŸããã
ä»å¹ŽãHBOã¯è€æ°ã®ãµã€ããŒæ»æã®ç ç²ã«ãªããŸããã ãã®ãã¡ã®1ã€ã§ã¯ãäŒç€Ÿã®ãµãŒããŒããããã³ã°ããããã®åŸããŸã 衚瀺ãããŠããªããšããœãŒãã®ãšããœãŒããå€æ°ã®ç€Ÿå ããŒã¿ãšãšãã«çãŸããŸããã
InterContinental Hotels GroupïŒIHGïŒã¯ã顧客ããŒã¿ãçãæ»æã®ç ç²ã«ãªããŸããã å瀟ã¯2æã«ãã®æ»æã«ãã圱é¿ãåããããã«ã¯çŽ12ã«éããªããšè¿°ã¹ããããã以éããããã«å±ãã1000ãè¶ ããæœèšã®POS端æ«ãææããŠããããšãå€æããã ãã®ã°ã«ãŒãã«ã¯ãHoliday InnãHoliday Inn ExpressãInterContinentalãKimpton HotelsãCrowne Plazaãªã©ã®ããŸããŸãªããã«ãã©ã³ããå«ãŸããŸãã
Sabre Corporationã¯ãäžçäžã®70ãè¶ ããèªç©ºäŒç€Ÿããã®100,000ã®ããã«ãšãã±ããã®ããã«äºçŽã管çããåç±³äŒæ¥ã§ãã ããã«ãŒã¯ããã®äŒç€Ÿã®äºçŽã·ã¹ãã ã®1ã€ã«ã¢ã¯ã»ã¹ããããã®ç»é²ããŒã¿ãåä¿¡ãããã®åŸãæ¯æãæ å ±ãšäºçŽããŒã¿ãå©çšå¯èœã«ãªããŸããã
ãã®ç¹å®ã®ã·ã¹ãã ã¯ã35,000ã®ããã«ããã³ãã®ä»ã®äžæçãªå± äœå°ã®å人ããã³æ è¡ä»£çåºã®éšå±ã®äºçŽã管çããŸãã æ»æã®çµæã2016幎8æ10æ¥ãã2017幎3æ9æ¥ãŸã§ã®7ãæéã®ããŒã¿ã䟵害ãããŸããã
ã»ã€ããŒãžã®æ»æã®çµæããã©ãŒã·ãŒãºã³ããã«ãºïŒãªãŸãŒãããã©ã³ãããã«ãºããã³ããã³ããã«ãºïŒã¬ã¹ãã©ã³ãã¬ããã©ã€ãªã³ããã«ãºã³ãŒãã¬ãŒã·ã§ã³ãããŒãããã¯ããã«ãºãããŠãºããã«ãºãªã©ãå€ãã®ããã«ãã§ãŒã³ã圱é¿ãåããŸããã
ã©ãã³ã¢ã¡ãªã«ã§äººæ°ã®ãœãŒã·ã£ã«ãããã¯ãŒã¯ã§ããTaringaã¯ããŠãŒã¶ãŒåãã¡ãŒã«ã¢ãã¬ã¹ãMD5ãã¹ã¯ãŒãããã·ã¥ãªã©ã2800äžäººä»¥äžã®ãŠãŒã¶ãŒããæ å ±ãçãã»ãã¥ãªãã£äŸµå®³ã«èŠèãããŸããã
ãããã2017幎ã®æ倧ã®ã»ãã¥ãªãã£äŸµå®³ïŒããã³å²äžææªã®ã»ãã¥ãªãã£äŸµå®³ïŒã¯ãä¿¡çšå ±åã®å·šäººã§ããEquifaxã䟵害ãããå°ãåŸã«çºçããå¯èœæ§ããããŸããã æäŸããããµãŒãã¹ã®æ§è³ªã«ãããå瀟ã¯ç€ŸäŒä¿éçªå·ãå«ãäœçŸäžäººãã®äººã ã«é¢ããéåžžã«æ©å¯æ§ã®é«ãæ å ±ãæã£ãŠããŸãã
æ»æã¯ãå瀟ã®ãµãŒããŒã®1ã€ã«ããApache Strutsã®è匱æ§ã䜿çšããŠå®è¡ãããŸããã è匱æ§ïŒããã³ãããä¿®æ£ãã察å¿ããæŽæ°ããã°ã©ã ïŒã¯3æ6æ¥ã«å ¬éãããŸããã æ°æ¥åŸãããã«ãŒã¯äŒç€Ÿã®ãµãŒããŒãæ»æããŸããããã®ãµãŒããŒã¯ããã®æ»æãçºèŠããã7ææ«ãŸã§ãããã³ã°ãããç¶æ ã®ãŸãŸã§ããã ãã®æéäžãçŽ2å人ã被害ãåãããã®70ïŒ ã¯ç±³åœåžæ°ã§ãããæ®ãã¯è±åœãšã«ããã§ãã ãã®åŸã圱é¿ãåããåœã®ãªã¹ãã«ã¢ã«ãŒã³ãã³ããã©ãžã«ããŠã«ã°ã¢ã€ããã«ãŒããã©ã°ã¢ã€ããšã¯ã¢ãã«ãããªãè£å ãããŸããã
ããã«æªãããšã«ãäŒç€Ÿã®3人ã®ããããããŒãžã£ãŒã¯ãæ»æãçºèŠããããšããšãäŒç€Ÿã®æ ªã180äžãã«ã§å£²ãããšã§äžè¬ã«ç¥ãããããã«ãªã£ããšããå©çšããããšãå€æããŸããã å瀟ã®ã»ãã¥ãªãã£ãµãŒãã¹ã®è²¬ä»»è ã解éãããããã1ãæåŸãEquifax CEOã®Richard Smithã¯2005幎ã«èŸä»»ãããšçºè¡šããŸããã
ããã€ã®æšéŠ¬
Goldeneye / Petyaã®åŸãNetsarangã¯æ»æã«çŽé¢ããŸããããã®çµæã5ã€ã®ããã°ã©ã ïŒXmanager Enterprise 5.0ãXmanager 5.0ãXshell 5.0ãXftp 5.0ããã³Xlpd 5.0ïŒã®ããŒãžã§ã³ã®ããã¯ãã¢ãä»ããŠãã¡ã€ã«ãå°å ¥ãããŸããã 圌ã¯äŒç€Ÿã®æå¹ãªããžã¿ã«çœ²åãæã£ãŠãããããããããã¬ãã«ã§ããã«ãŒãäŒç€Ÿã«å®å šã«äŸµå ¥ããŠããŸããã ãããããã®äŒç€Ÿã®é¡§å®¢ã®äžã«ã¯éè¡ããšãã«ã®ãŒäŒç€ŸããããŸãã
2017幎ã®ãœãããŠã§ã¢ã®ããã¯ãã¢ã«é¢ããæ倧ã®ã±ãŒã¹ã¯ãééããªãCCleanerã§çºçããŸããã
200äžäººãè¶ ãããŠãŒã¶ãŒãã䟵害ãããããŒãžã§ã³ã®ããã°ã©ã ãã€ã³ã¹ããŒã«ããŠããŸãã ãããã³ã°ããããœãããŠã§ã¢ã¯ã³ãã³ããåŸ æ©ããŠãããããããæªæã®ããã¢ã¯ã·ã§ã³ãå®è¡ããããšã¯ãããŸããã
ããããã·ã¹ã³ã®ç 究è ã¯ãããã«ãŒãã³ã³ãã¥ãŒã¿ãŒã䟵害ãããäŒæ¥ã®ãªã¹ããæã£ãŠããããšãçºèŠããŸããã ãããã«ã¯ãSamsungãCiscoãSonyãIntelãMicrosoftãªã©ã®20ã®æåãªå€§äŒæ¥ãå«ãŸããŸãã
ãããã®3ã€ã®æ»æã¯ãèåŸã«éåžžã«å°éçãªçµç¹ããã£ãããšã瀺ããŠãããäžéšã®åœã®æ¿åºã«ãã£ãŠæ¯æŽããããšèããããšãã§ããŸãã ã¡ãªã¿ã«ã NATO㯠ãGoldenEye / Petyaæ»æããããããã®åœã®æ¿åºã«ãã£ãŠãµããŒããããŠãããšè¿°ã¹ãŸããã
æå·äœæè
ã©ã³ãµã ãŠã§ã¢æ»æã®æ°ã¯ãŸã å¢ãç¶ããŠãããäŒæ¥ãããŒã¿ãè¿ãããã«å·šå€§ãªèº«ä»£éãæ¯æãããšããéããããã¯ç¶ç¶ããŸãã
ããç¥ãããæå·åãã¡ããªïŒLockyãCerberãªã©ïŒã«å ããŠããã®ã¿ã€ãã®è¢«å®³è åãã®ç¹å¥ãªãããããŒãœãã©ã€ãºãããããŒãžã§ã³ããããŸãã
ãããã®1ã€ã¯PandaLabsã©ãã§çºèŠãããŸãããWYSIWYEãšåŒã°ããç¬èªã®ããŠãŒã¶ãŒãã¬ã³ããªãŒãã€ã³ã¿ãŒãã§ã€ã¹ãåããæå·åããã°ã©ã ã§ããµã€ããŒç¯çœªè ãæ»æãéå§ããåã«æ»æãèšå®ã§ããŸãã
äŒæ¥ãããã¯ãŒã¯ã«äŸµå ¥ããæãäžè¬çã§æãç°¡åãªæ¹æ³ã®1ã€ã¯ãWindowsã®ãªã¢ãŒããã¹ã¯ãããïŒRDPïŒãä»ãããã«ãŒããã©ãŒã¹æ»æã䜿çšããããšã§ãã æ»æè ã¯ã€ã³ã¿ãŒããããã¹ãã£ã³ããŠããã®æ©èœãæå¹ã«ãªã£ãŠããã³ã³ãã¥ãŒã¿ãŒãæ€çŽ¢ããæœåšçãªè¢«å®³è ãèŠã€ãã£ãåŸãæ£ãããã°ã€ã³æ å ±ãååŸãããŸã§ãã«ãŒããã©ãŒã¹æ»æãéå§ããŸãã
2017幎ã«ã¯ããã®ã¿ã€ãã®æ»æã®äŸãæ°å€ãèŠãããŸããããããã«ãŒã¯äž»ã«ãã·ã¢åºèº«ã§ãããåæ§ã®ãã¿ãŒã³ã§è¡åããŠããŸãã.RDPãä»ããŠã³ã³ãã¥ãŒã¿ãŒã«ã¢ã¯ã»ã¹ãããšããã«ããããã³ã€ã³ããã€ãã³ã°ããããã®ãœãããŠã§ã¢ãïŒã¢ããªã³ãšããŠïŒã€ã³ã¹ããŒã«ãããã®åŸãã¡ã€ã«ãæå·åããŸãããŸãã¯ã³ã³ãã¥ãŒã¿ãŒãžã®ã¢ã¯ã»ã¹ããããã¯ããŸããã
ãããã圌ãã¯ãã®ããã«åžžã«æªæã®ããããã°ã©ã ã䜿çšãããšã¯éããŸããã ããšãã°ãåæããã±ãŒã¹ã®1ã€ã§ã¯ãããã«ãŒã¯åçšã¢ããªã±ãŒã·ã§ã³ãDesktop Lock Express 2ãã䜿çšããŠã³ã³ãã¥ãŒã¿ãŒãããã¯ããŸããã
æå·åæ»æã®çŽæ¥çãªçµæã¯æããã§ãããã¡ã€ã«ãžã®ã¢ã¯ã»ã¹ã倱ããŸãã
ãã ããããžã¿ã«ã®ãèªkidãã®ã±ãŒã¹ã¯ãããã¯ããã«è¶ ããå¯èœæ§ããããŸãã ãªãŒã¹ããªã¢ã®ããã«ã®1ã€ã®äŸã®ããã«ããµã€ããŒç¯çœªè ãé»åããã¯ã®ãœãããŠã§ã¢ããªãã«ããåŸã宿æ³å®¢ãéšå±ã«éã蟌ããããŸããã
1人ã®æå·äœæè ã¯ãéåœã®Nayana Webãã¹ãã£ã³ã°äŒç€Ÿãææãã153å°ã®LinuxãµãŒããŒäžã®ããŒã¿ãæå·åããŸããã ããã«ãŒã¯ã162äžãã«ã®èº«ä»£éãèŠæ±ããŸããã äŒç€Ÿã¯ç¯çœªè ã«åæããéé¡ã100äžã«æžããã3åã®æ¯æãã§æ¯æãããŸããã
ã¢ãã®ã€ã³ã¿ãŒãããïŒIoTïŒ
é·å¹Žã«ããã£ãŠãã¢ãã®ã€ã³ã¿ãŒãããïŒIoTïŒããã€ã¹ã«é¢é£ããå±éºæ§ã«ã€ããŠå€ãã®èŠåããããŸãããããã¯ãäž»ã«ãããã®ããã€ã¹ã®å€ããäœæãããšãã«ãéçºè ãã»ãã¥ãªãã£åé¡ã«ååãªæ³šæãæããªãã£ããšããäºå®ã«ãããã®ã§ãã
ãŸãããããã®ããã€ã¹ã¯ã€ã³ã¿ãŒãããã«æ¥ç¶ãããŠããªããããç¹å®ã®ãªã¹ã¯ã¯ãããŸããã§ããããã€ã³ã¿ãŒãããæ¥ç¶ãªãã·ã§ã³ãå®è£ ãããåŸãæ»æã«å¯ŸããŠè匱ã«ãªããŸããã
圌ãã¯ãããã®èŠåã«æ³šæãæãå§ããããã§ãããç±³åœã§ã¯ãæ°äž»å ãšå ±åå ã®äžé¢è°å¡ãéãŸã£ãŠããã®ç¶æ³ãéšåçã«ä¿®æ£ããæ³åŸãäœæããŸããã
ã¢ã€ãã¢ã¯ããšããããã€ã³ã¿ãŒãããã«æ¥ç¶ãããªãã·ã§ã³ãåãã補åã®ã¡ãŒã«ãŒã«æŽæ°å¯èœã«ããïŒã»ãã¥ãªãã£ããŒã«ãæé€ããïŒããã«èŠæ±ããåºå®ãã¹ã¯ãŒãã®äœ¿çšãçŠæ¢ããæ¢ç¥ã®ã»ãã¥ãªãã£ããŒã«ãæã€è£œåã®è²©å£²ãé²æ¢ããããšã§ãã
ã¹ããŒããã«
è¿å¹Žãå€ãã®å»ºç©ãå€æŽãããŸããã ããšãã°ãã©ããã§ã家åºããªãã£ã¹ã§ã®ãšãã«ã®ãŒæ¶è²»ãå¶åŸ¡ããããã«ã¹ããŒãã¡ãŒã¿ãŒãå°å ¥ãããŸããã æ¶è²»è ä¿è·åäŒã«ãã£ãŠå ±åãããé»æ°æéã®ãã€ãã¹ã®å¯èœæ§ã®ããçµæã«å ããŠããã®ãããªããã€ã¹ã®æ®åã«é¢é£ããããŸãç¥ãããŠããªãã»ãã¥ãªãã£åé¡ããããŸãã
ãã€ãã®ãã³ãã«ã°ã§éå¬ãããæè¿ã®ã«ãªã¹ã³ãã¥ãã±ãŒã·ã§ã³äŒè°ã§ç 究è ã®ãã¿ãã«ã«ãŒãã³ã説æããããã«ããããã®ã¹ããŒãã¡ãŒã¿ãŒã¯ããŸããŸãªã¬ãã«ã§è åšããããããŸãã 第äžã« 家åºããªãã£ã¹ã§ã®ãšãã«ã®ãŒæ¶è²»ã«é¢é£ãããã¹ãŠã®ããŒã¿ãèšé²ãããããããŠãŒãã£ãªãã£ã«éä¿¡ããŸãããã®ãããªããã€ã¹ãå¶åŸ¡ã§ããæ»æè ã¯ããã®æ å ±ãèŠãŠãç¯çœªç®çã«äœ¿çšã§ããŸãã
ããšãã°ã圌ã¯ã建ç©ã奪ãããã«æ¶è²»ãæå°éã«ãªãïŒã€ãŸãã建ç©ã空ã«ãªãïŒããšã確èªã§ããŸãã ãã¹ãŠã®é»å補åããããã¯ãŒã¯äžã«ããŒã¯ãæ®ããŠããããšãèãããšã圌ã¯ãã®æ å ±ã䜿çšããŠãçãŸããå¯èœæ§ã®ãã貎éãªé»å補åãæ€åºããããšããã§ããŸãã
ã¹ããŒããã¬ã
ããã«äžè¬çãªããã€ã¹ã¯ã¹ããŒããã¬ãã§ãã ãããã®ããã€ãã¯ãé·æãšçæãæã€Androidãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãå®è¡ããŠããŸãã ããã«ã€ããŠã¯ã圌ã®èŠªrelativeã®ãã¬ããæ»æãããåŸãç±³åœã®ITéçºè ã§ããDarren CotonãTwitterã§æžããŠããŸãã Cotonã説æããããã«ãããããã¹ãŠã¯ã被害è ããµãŒãããŒãã£ã®ãµã€ãããã€ã³ã¿ãŒãããã§æ ç»ãèŠãããã®ã¢ããªã±ãŒã·ã§ã³ãã€ã³ã¹ããŒã«ããåŸã«èµ·ãããŸããã
ãã®ãã¬ãã¯2014幎ã«ãªãªãŒã¹ãããLGã®ã¢ãã«ã§ãããTVåãAndroidã®ç¹å¥ããŒãžã§ã³ã§ããGoogle TVã§åäœããŸããã ããã€ã¹ãææãããšããã«ãŠã§ã¢ã¯ç»é¢ã®ããã¯ã解é€ããããã«500ãã«ã®èº«ä»£éãèŠæ±ããŸããã ããã«ããã®èŠä»¶ã¯ãç±³åœåžæ³çããã®éç¥ãšãã圢ã§æºããããŸããã
ããã«ããã®é åã§äœãèµ·ãã£ãŠãããã瀺ãå¯èœæ§ã®ããä»ã®å€ãã®å±éºãªæ»æããããŸãã 2æãæ å ±ã»ãã¥ãªãã£ã«é¢ãã欧å·æŸéé£åã»ãããŒã§ãã»ãã¥ãªãã£ã®å°é家ã§ããRafael Scheelã¯ã圌ãäœæãããšã¯ã¹ããã€ãã玹ä»ããŸããã ããã«ãŒãTDTä¿¡å·ãä»ããŠæ»æãéå§ããã ãã§ãã¹ããŒããã¬ãããªã¢ãŒãã§å¶åŸ¡ã§ããããã«ãªããŸãã
ã¹ããŒãã·ãã£
ãªãŒã¹ãã©ãªã¢ã§ã¯ãä¿¡å·æ©ãšäº€å·®ç¹ã«èšçœ®ããã55å°ã®ã«ã¡ã©ããäžè«ãæ¥è ãã³ã³ãã¥ãŒã¿ãŒãæ¥ç¶å ã®ãããã¯ãŒã¯ã«æ¥ç¶ããåŸã«ãããã³ã°ãããŸããã
4æ7æ¥ããã©ã¹ïŒç±³åœãããµã¹å·ïŒã§ãç·æ¥èŠå ±ã®156ãµã€ã¬ã³ã23:40ã«åæã«ãªã³ã«ãªããŸãããåœå±ã¯çŽ40ååŸã«ãããããªãã«ã§ããŸããããããã¯èŠåã·ã¹ãã å šäœããªãã«ããåŸã®ã¿ã§ããæ»æã®è²¬ä»»è ã¯ãŸã äžæã§ãã
èªåè»
ç£æ¥èªåè»ãç¹ã«ãããã«åœ±é¿ãåãŒãæ°ããè匱æ§ãå ±åãããŠããŸãããã ãã以åã®å Žåãšã¯ç°ãªããè»ã®ITã·ã¹ãã ã䟵害ããããã«ãããã«ãŒã¯ãšã³ãžã³ãç¹å®ã®ã¢ãŒãã«ãããšãã«USBããã€ã¹ãæ¿å ¥ããå¿ èŠããããŸãã
è»ãä»ã®è»ãã€ã³ã¿ãŒãããã«æ¥ç¶ã§ãããããæ»æãåããå¯èœæ§ãããã®ãäžæè°ã§ã¯ãããŸããããã®åéã«ã¯ä»ã®ç®æšããããŸããããšãã°ãæŽè»ãã©ã¹ãã¬ã¹ïŒç±³åœïŒã§éå¬ãããBlack Hatã«ã³ãã¡ã¬ã³ã¹ã§ãç 究è ã®Billy RiosãšJonathan Buttsã¯ãã€ã³ã¿ãŒãããã«æ¥ç¶ãããèªåæŽè»æ©ã«äŸµå ¥ããæ¹æ³ã瀺ããŸããã圌ãã¯ãè»ãšä¹å®¢ãç©ççã«æ»æã§ãããããªæ¹æ³ã§ã·ã¹ãã ããããã³ã°ããŸããã
ãŸããèªåè»éšéããïŒã»ã°ãŠã§ã€ã¯ãªã¢ãŒããããããã³ã°ãããå¯èœæ§ãããããã®çµæãããã«ãŒã¯ãªã¢ãŒãã§ããããå¶åŸ¡ã§ããŸãã
IOActiveã®ç 究è Thomas Kilbrideã¯ãããŸããŸãªè匱æ§ãšã»ãã¥ãªãã£ã€ã³ã·ãã³ããæããã«ããŸãããå®éãSegwaysã¯é©çšãããæŽæ°ããã§ãã¯ããªããããããã«ãŒãå¿ èŠãšãããã¹ãŠã®ããšãè¡ãæªæã®ãããã¡ãŒã ãŠã§ã¢ã§èª°ã§ããã€ã§ãããã€ã¹ãæŽæ°ã§ããŸãã
éèŠã€ã³ãã©
ãªã©ã³ãã®ç 究è Willem Westerhofã¯ã倪éœå ããã«ã§äœ¿çšãããå€å§åšãåæããŠãçŽæµã亀æµã«å€æãããã®åéã®å€§æäŒæ¥ã§ããSMA Solar Technologiesã®ãããã¯ãŒã¯ã«äŸçµŠããŸããã
åèšã§ã圌ã¯ããã«ãŒããããã¯ãŒã¯ã«äŸçµŠãããé»åéãå¶åŸ¡ããããšãå¯èœã«ãã21ã®è匱æ§ãæããã«ããŸããããã®ãããªè匱æ§ã¯ãã€ã³ã¿ãŒããããä»ããŠãªã¢ãŒãã§æªçšãããå¯èœæ§ããããŸãã
ãããã®ã€ã³ã¹ããŒã«ããããã³ã°ããæ»æè ã¯ã倧ããªæ害ãäžããå¯èœæ§ããããŸãã詳现ã«ã€ããŠã¯ãã¡ããã芧ãã ããã
ãã«ã¹ã±ã¢
ãããã¯ãŒã¯ã®ãããã³ã°ã¯ããã¡ãããå€ãã®äººã ã®ç掻ã«åœ±é¿ãäžããå¯èœæ§ãããéåžžã«æ·±å»ãªç¯çœªã§ãããããã«ãŒãç é¢ã®ããŒã¹ã¡ãŒã«ãŒãå»çæ©åšãå¶åŸ¡ããææªã®å Žåã¯é éå°ã§äººã殺ãããšã«ãªãæœåšçãªå±éºããã¯ã»ã©é ãã§ãã¬ããŒãã«ç€ºãããã«ã
ç±³åœä¿å¥çŠç¥çïŒFDAïŒé£åå»è¬åå±ã¯ãçŽ50äžäººã®æ£è ãå»åž«ã蚪ããŠãããŸããŸãªã¢ãããããŒã¹ã¡ãŒã«ãŒã¢ãã«ã®ãã¡ãŒã ãŠã§ã¢ãæŽæ°ããããèŠåããŠããŸãã
ã¢ãã€ã«æ©åš
ã¢ãã€ã«ããã€ã¹å°çšã«èšèšãããæªæã®ãããœãããŠã§ã¢ã¯ãPCçšã«èšèšããããã«ãŠã§ã¢ããå£ã£ãŠããŸãããåºæ¬çãªåäœã¯åãã§ãã
ãµã€ããŒç¯çœªè ã«åªããçµæãããããæå·äœæè ã®äººæ°ã¯ãã¢ãã€ã«ããã€ã¹ãžã®æ³šåã«ãã£ãŠã確èªãããŠããŸãã
ã¢ãã€ã«ããã€ã¹ãžã® è åšAndroidã«å¯Ÿããæ°ããè åšã§ãã
Chargerã¯ãã¢ãã€ã«ããã€ã¹çšã®ãã«ãŠã§ã¢ã®éçºæ¹æ³ã®è¯ãäŸã§ããå é»åšã¯é£çµ¡å æ å ±ãšSMSã¡ãã»ãŒãžãçã¿ã端æ«ããããã¯ãã30åããšã«éåžå Žã§ããªãã®æ å ±ã®äžéšã売ããšè è¿«ãã身代éãèŠæ±ããŸããè²·æ»ãé¡ã¯0.2ãããã³ã€ã³ã§ãã
倧äŒæ¥ã¯ãã®åé¡ãå¿é ããŠãããæãæ·±å»ãªãŒããã€è匱æ§ïŒä»¥åã¯æ€åºãããŠããªãã£ãïŒãèŠã€ãã人ã®å ±é ¬ãå¢ããGoogle Project Zero Contestãªã©ã®ã€ãã·ã¢ããã«ã€ãªãããŸãã第äžäœã®ä¿éºæã¯50,000ãã200,000ç±³ãã«ã«å¢å ãã
第äºäœã¯30,000ãã150,000ç±³ãã«ã«å¢å ããŸããã
è匱æ§
Broadcom Wi-Fi HardMAC SoCãããã®ãã¡ãŒã ãŠã§ã¢ã®è匱æ§ïŒCVE-2017-6975ïŒã«ãããAppleã¯iOSã¢ããããŒãïŒ10.3.1ïŒã®ç·æ¥ãªãªãŒã¹ãäœåãªããããŸããããã®è匱æ§ã¯ãããªããã®Wi-Fiã«åæ¥ç¶ãããšãã«ãçºçããã¢ããã«è£œåã ãã§ãªãã圱é¿ãäžããã ãã§ãªãã2017幎4æã«ãã®åé¡ã«å¿çããŠããã®ã¢ããããŒãããªãªãŒã¹ãµã ã¹ã³ãGoogleãªã©ã®ä»ã®ã¡ãŒã«ãŒããã®ã¢ãã€ã«ããã€ã¹äžã§
ããããããããããã«ãã«çå£ã«åã€è匱æ§ããããããã¯KRACKã§ããå¿ èŠããããWPA2ãããã³ã«ã«åœ±é¿ããŸããã¢ãã€ã«ããã€ã¹ã ãã§ãªãã WPAãå®è£ ãããŠãããã¹ãŠã®çš®é¡ã®ããã€ã¹ïŒPCãã«ãŒã¿ãŒãªã©ïŒã«åœ±é¿ãåãŒããŸããããã®åé¡ã¯äž»ã«Androidã¢ãã€ã«ããã€ã¹ã®ãŠãŒã¶ãŒã«é¢ä¿ããŠããããšã«æ³šæããŠãã ããã
ãã®åé¡ã¯ã2016幎ã«ãã«ã®ãŒã®ç 究è Mati VanhofãšFrank Pessensã«ãã£ãŠçºèŠãããŸãããã2017幎10æãŸã§å ¬è¡šãããŸããã§ããã Linuxããã³Androidã§äœ¿çšããããã®ãããã³ã«ã®ãªãŒãã³ãœãŒã¹å®è£ ã®1ã€ã§ãããwpa_supplicantãã¯ããã®æ»æã«å¯ŸããŠç¹ã«è匱ã§ãã
Googleããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«é©åãªã»ãã¥ãªãã£ãããããªãªãŒã¹ããåŸãèšå€§ãªæ°ã®ããã€ã¹ã¡ãŒã«ãŒãæ°ããæŽæ°ããã°ã©ã ãå°å ¥ããå¿ èŠããããŸããããã«ãäžçäžã«ã¯äœåãã®ããã€ã¹ãããããããã®ããã€ã¹ã¯è£œé å ã«ãã£ãŠãµããŒããããªããªã£ãŠãããããå¿ èŠãªæŽæ°ããã°ã©ã ãåãåãããšã¯ãããŸããããã®åé¡ã¯ããã®ãšã³ã·ã¹ãã ã«ç¹æã®ãã®ã§ãã
ãµã€ããŒæŠäº
ãããããä»å¹Žã®2ã€ã®äž»èŠãªæ»æïŒWannaCryãšGoldenEye / PetyaïŒã¯ã2ã€ã®å·ã®æ¿åºïŒWannaCryã®å Žåã¯DPRKãGoldenEye / Petyaã®å Žåã¯ãã·ã¢ïŒã«ãã£ãŠå®è¡ãããŸãããããã®èšŒæ ã¯ãããŸããããããã«ãããããã¯æ¿ãããã²ããã«é²è¡äžã®ãµã€ããŒæŠäºã®æ çµã¿ã®ã»ãã®æ°äŸã§ãã
äž»ãªãã£ã©ã¯ã¿ãŒã¯åãã§ããã¢ã¡ãªã«ããã·ã¢ãåæé®®ãäžåœãã€ã©ã³ã§ãããã»ãšãã©ã®å Žåã誰ãå®éã«æ»æã®èåŸã«ããã®ãã確èªããããšã¯äžå¯èœã§ããã»ãšãã©ã®å Žåãæ»æè ã¯ãã¹ãŠã®ãã©ãã¯ããæé€ãããã®ã«åªããä»äºãããæã«ã¯ä»ã®ç¯çœªè ã«ä»£ããããšããããŸãã
ãµã€ããŒæ»æãšæ¿æ²»ã¯ããã€ãŠãªãã»ã©çµ¡ã¿åã£ãŠããŸããååã®å€§çµ±é éžæããçãæ®ã£ããåŸããã¯ã€ãããŠã¹ãå»ãåã«ããªããã¯ãã·ã¢ã«å¯Ÿããæ°ããå¶è£ãçºè¡šããããã«ãã»ãã©ã³ããæ¯æããŠæ°äž»å åè£ã®ãã©ãªãŒã»ã¯ãªã³ãã³ã®éžæãã£ã³ããŒã³ã«å¯Ÿãããµã€ããŒæ»æãçµç¹ãããšéé£ããããã®çµæã35人ã®ãã·ã¢ã®å€äº€å®ãè¿œæŸããããã·ã¢ã«å±ãã2ã€ã®ã»ã³ã¿ãŒãééãããŸããã
ãã®çµæã¯äžçäžã§æããããŸãããã©ã³ã¹ã¯ããµã€ããŒæ»æã®ãéåžžã«é«ããªã¹ã¯ãã®ãããæµ·å€ã«å± äœããåžæ°ã«å¯Ÿããé»åæ祚ã®äœ¿çšãæŸæ£ããŸããããªã©ã³ãã¯ããã«é²ãã ïŒåœŒãã¯éžæåŸã®å€ã«æ祚ãæåã§ç¢ºèªãããµã€ããŒæ»æã®å¯èœæ§ã®ãããªã¹ã¯ãåé¿ããããã«é»è©±ã§çµæãéä¿¡ãå§ããŸããã
2æããªã©ã³ãã¯NATOå ã§ã®åœéçãªãµã€ããŒé²è¡åçã®åµèšãåŒã³ãããŸãããããã¯ããµã€ããŒæ»æã®è åšã®å¢å€§ãé²åŸ¡ãç£èŠã察å¿ããå¯èœæ§ãç§ããŠããŸãã
ãã€ãã®ã¢ã³ã²ã©ã»ã¡ã«ã±ã«éŠçžã¯ãæœåšçãªãµã€ããŒæ»æããåœå®¶ã€ã³ãã©ãä¿è·ããããšããã€ãã®æåªå äºé ã®1ã€ã«ãªããšè¿°ã¹ãŸããã
ãã®åŸããã«ããã€ãè»ããªã³ã©ã€ã³é²è¡ã匷åããããã«ç¬èªã®ãµã€ããŒè»éã圢æãããšå ±åãããŸããã 260人ã®åŸæ¥å¡ãæ¡çšããäºå®ã§ããã®æ°ã¯2021幎ãŸã§ã«14,500人ã«å¢å ããŸãã
ç±³åœã®CIAãé€ããŠãä»å¹Žã¯ãµã€ããŒã¹ãã€ã®åéã§æããã¥ãŒã¹ã®å€ãã€ãã³ãã®1ã€ã«æ³šç®ãããŸããã
3æ7æ¥ãWikiLeaksã¯ãVault 7ããšåŒã°ããäžé£ã®ããã¥ã¡ã³ãã®å ¬éãéå§ããŸããããã®ããã¥ã¡ã³ãã«ã¯ãã¹ããŒããã©ã³ãã³ã³ãã¥ãŒã¿ãŒãããã«ã¯ã¹ããŒãTVã«äŸµå ¥ããããã®æè¡ãšãœãããŠã§ã¢ããŒã«ã®è©³çŽ°ãå«ãŸããŠããŸãããŠã£ããªãŒã¯ã¹ã¯ããã¥ã¡ã³ãã®å ¬éãç¶ããŠããããŠã§ããµã€ãã®ãªãŒã¯ã«å¥ã®ã»ã¯ã·ã§ã³ãèšããŠããŸãã
幞ããªããšã«ããã®ãããªäžè¬çãªç¥èã䜿çšããŠããã®ãããªè åšããä¿è·ããããšãã§ããŸãããããåé¡ã¯ãä»ã®ç¯çœªè ããããã®ææ³ãç¿åŸãããããã䜿çšããŠåžæ°ã®ãã©ã€ãã·ãŒã䟵害ããå¯èœæ§ãããããšã§ãã
ç±³åœã¯ãç±³åœã®æ©é¢ã«å¯Ÿããæ»æãæããã«æžå¿µããŠããŸããç±³åœã®presidentå ±å§å¡äŒã¯ã2016幎ã®å€§çµ±é éžæã§ãã·ã¢ã®æ»æã®çµæã«é¢ããå ¬èŽäŒãéå¬ããŸãããããã§ã¯ããªããæ¿æš©ã®äžã§ã®ç±³åœåœåå®å šä¿éçã®å äºåå±é·ã§ããJeh Johnsonãããã·ã¢ã®ãŠã©ãžããŒã«ããŒãã³å€§çµ±é ãç±³åœã®éžæã«åœ±é¿ãäžããããæ»æãåœããããšã確èªããŸããã圌ã¯ãŸãããã·ã¢ããããã®æ»æã®ãããã§ç¥šãæäœããããšãã§ããªãã£ããšèšããŸããã
6æãç±³åœæ¿åºã¯2009幎以éã®äžé£ã®ãµã€ããŒæ»æã§åæé®®æ¿åºãéé£ããç¶ç¶ã®å¯èœæ§ãé«ããšèŠåããŸããã
WBãšFBIããã®èŠåã¯ãç±³åœããã®ä»ã®åœã®éèŠãªã€ã³ãã©ã¹ãã©ã¯ãã£ã ãã§ãªããã¡ãã£ã¢ãèªç©ºå®å®ãéèã»ã¯ã¿ãŒãæ»æãããé ãã³ãã©ãããã«ãŒã®ã°ã«ãŒãã«å±ããŸããæè¿ã®WannaCryæ»æãšããã©ã¶ãã°ã«ãŒãããšããŠç¥ããããã®ãé ãããã³ãã©ãã°ã«ãŒããçµã³ä»ãã蚌æ ããããŸãã
æé®®æ°äž»äž»çŸ©äººæ°å ±ååœã«èµ·å ããæ»æã®èãããã説æã®1ã€ã¯ã圌ãã«å¯Ÿããåœé£ã®å¶è£ã®æ¡å€§ã§ããã代æ¿ã®è³é調éãæ±ããããåŸãªãããšã§ãã
2017幎6æã«ã¯ã·ã³ãã³ã§éå¬ãããGartner Security and Risk Management Summitã§ãCIAã®å ãã£ã¬ã¯ã¿ãŒã§ããJohn BrennanããYahooã¢ã«ãŠã³ãããããŒã¿ãçãéã®ãã·ã¢æ¿åºãšãµã€ããŒç¯çœªè ãšã®åçé¢ä¿ã«ã€ããŠè©±ããŸããããã¬ãã³ã«ãããšãããã¯æ°·å±±ã®äžè§ã«ãããŸããã圌ã¯ãããã€ãã®æ¿åºã«ããå°æ¥ã®ãµã€ããŒæ»æããã®å ¬åŒã«åŸãç¶ãããã®é »åºŠãå¢å ããã ãã ãšèŠåããŸããã
Financial Timesã«ãããšãã¢ã«ãŠã³ãã¯è±åœè°äŒã®å€æ°ã®ã¡ã³ããŒã«ãã£ãŠããããã³ã°ãããŠãããã¡ã³ããŒã¯ãã®æ»æãæµ·å€ããã®è³éæäŸãåããŠãããšç¢ºä¿¡ããŠããŸãã
ãã®æ¿æ²»çã«åæ©ä»ãããããµã€ããŒæ»æã®æžŠã¯ããã¯ãããžãŒäŒæ¥ã«ã圱é¿ãäžããŸãããã·ã¢ã®FSBã¯ãCISCOãSAPãIBMãªã©ã®äŒæ¥ã«ãå¯èœæ§ã®ããããã¯ãã¢ãæ€çŽ¢ããããã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã®ãœãŒã¹ã³ãŒããæäŸããããèŠæ±ããŸãããæ°æ¥åŸãç±³åœæ¿åºã¯ããã·ã¢æ¿åºãšFSBã«è¿æ¥ããŠãããããåœå ã®ãã¹ãŠã®é£éŠæ¿åºéšéãã«ã¹ãã«ã¹ããŒã®ãœãªã¥ãŒã·ã§ã³ã䜿çšããããšãçŠæ¢ããŸããã
ã«ã¹ãã«ã¹ããŒã«ããæªæã®ãã掻åããµããŒããã決å®çãªèšŒæ ã¯ãŸã æåºãããŠããŸããããäž¡åœéã®ç·åŒµã®çŸç¶ã§ã¯ãç±³åœæ¿åºããããªãå Žåã§ãæžå¿µãããããšã¯æããã§ããç±³åœã¯ãäŒç€Ÿãæš©åãã»ãšãã©æš©åšäž»çŸ©ãšèŠãªããŠããåœã«ãããšæ³å®ããŠããŸãã
圌ãã¯ããã·ã¢æ¿åºããã€ã§ãã«ã¹ãã«ã¹ããŒã«æ瀺ããŠããã®ãœãããŠã§ã¢ã䜿çšããŠæ»æãéå§ããããçŽäºã®ãšã¹ã«ã¬ãŒã·ã§ã³ã®ä»®æ³ã±ãŒã¹ã§æ å ±ãçãã ãã§ãããšèããŠããŸãã
è åšãã³ãã£ã³ã°ã·ã¹ãã ã«ã€ããŠ
Panda Security
ã®Inaki Urzai ããŒãã»ãã¥ãªãã£ã¹ãã©ããžã¹ãäžçäžã®ã»ãã¥ãªãã£å°é家ã®æ°ã¯ææ°é¢æ°çã«å¢å ããŠããŸãããã®æé·ã¯äž»ã«ãããŸããŸãªåœã®æ¿åºã®è¡åã«ãããã®ã§ãããååœæ¿åºã¯ã誰ãå芳ããããšãã§ããªãä»®æ³çŽäºã§ç©æ¥µçãªåœ¹å²ãæããå¿ èŠããããŸãïŒç¬èªã®ã€ãã·ã¢ãããŸãã¯å¯Ÿå¿ã®åœ¢ã§ïŒãå€ãã®åœã®æ¿åºã¯ããã°ããã®éãç¹å¥ãªãµã€ããŒé²è¡æ©é¢ãèšç«ããŠããŸãããæè¿ããã€ãã«13,000人以äžã®ãµã€ããŒå µå£«ãæããéšéãèšç«ããã2020幎ãŸã§ã«100,000人以äžã®ãšãŒãžã§ã³ããç±³åœã«ããã¯ãã§ãããã·ã¢ãäžåœãã€ã®ãªã¹ããã©ã³ã¹ãã¹ãã€ã³ãã€ã¹ã©ãšã«ãã€ã©ã³ãããã³ãã®ä»ã®åœã«ã¯ã6,000ã®ãŠããããšåæ§ã®ãŠããããååšããå¯èœæ§ããããŸãã
ããã«ãäžçäžã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã®ã¡ãŒã«ãŒããµãã©ã€ã€ãŒãšååããå°é家ãããŸããããããã¹ãŠã®äŒæ¥ã«ã¯ãäžçã®ãã¹ãŠã®åœã«æ å ±ã»ãã¥ãªãã£ã®å°é家ãããŸãããããŠæåŸã«ãæ å ±ã»ãã¥ãªãã£ã®å°é家ã®å¢å ãšãã®åéãžã®äžççãªé¢å¿ã®é«ãŸãã®çµæãèšç·Žãããå°é家ãã¯ããã«ç°¡åãã€è¿ éã«èŠã€ããããšãã§ãããµã€ããŒç¯çœªè ãããŸãã
é«åºŠãªã¹ãã«ãæã€åŸæ¥å¡ã®æœåšèœåã®ãã®æé·ã«ããããœãããŠã§ã¢ã®è匱æ§ãäœç³»çã«æ€åºã§ããç°å¢ãçãŸããŸããããŸããç¯çœªè ã«ãã£ãŠå®è¡ãããæªæã®ããããã°ã©ã ã䜿çšããã被害è ã®ç°å¢ã«æ倧éã®é床ã§é©å¿ã§ãããæ»æãå®è¡ããããã®ãããã§ãã·ã§ãã«ããŒã«ã®éçºã«è²¢ç®ããŸãïŒå®å®æ§ãšã¹ã±ãŒã©ããªãã£ã®åäžïŒã
Panda Adaptive Defenseã§ãããããã«ããã«ãŠã§ã¢ããŒã¹ã®æ»æã¯ãPanda Securityã«ãã£ãŠäœæããããå³å¯ã«è¯å®çãªãã¢ãã«ã«åºã¥ããœãªã¥ãŒã·ã§ã³ã§å®å šã«æå¶ã§ããŸãã
ã³ã³ãã¥ãŒã¿ãŒã§å®è¡ããããšãããã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ãåé¡ãããæ¬åœã«å®å šãªã¢ããªã±ãŒã·ã§ã³ã®ã¿ãå®è¡ãèš±å¯ããããšãåŸæ¥ã®ãŠã€ã«ã¹å¯Ÿçã¢ãã«ã®ç¹åŸŽã§ãããæ€åºã®ã£ãããã¯ãªããªããŸããæªæã®ããããã°ã©ã ã¯ãåŸæ¥ã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã§ç¡èŠãããæªç¥ã®ãã¡ã€ã«ã«é ããããšãã§ããªããªããŸããã
åžå Žã§ã¯ããã®ã»ãã¥ãªãã£ã¢ãã«ã®æ»æãé²ãèœåãç¡èŠããäœè£ã¯ãªãããããã®ã¢ãã«ãåžå Žã·ã§ã¢ãæ¡å€§ââããããšã¯æããã§ãã
ãã®ã¢ãããŒãã¯ãåŸæ¥ã®ãŠã€ã«ã¹å¯Ÿçã¢ãã«ã«åã£ãŠä»£ãããã®ã§ãããããæ»æè ã¯ããããã€ãã¹ããããã«ãã¯ããã¯ãé©å¿ãããŸãããããŠããã®å Žåããã«ãŠã§ã¢ã®äœ¿çšã«åºã¥ããŠããªãæ»æãåã€å¯èœæ§ãå®å šã«ãããŸãã
ãã«ãŠã§ã¢ã䜿çšããªãæ»æã®ç¹åŸŽã¯ãæ£èŠã®ãããã¯ãŒã¯ç®¡çè ããã䜿çšããããŒã«ã®äœ¿çšã§ããããšãã°ãããã°ã©ã ã®ãªã¢ãŒãã€ã³ã¹ããŒã«ãããŒã¿ããã¯ã¢ãããªã©ã®ã¢ããªã±ãŒã·ã§ã³ã§ãã
ãã®ã¢ãããŒãã§ã¯ãããã«ãŒã¯ãããã¯ãŒã¯ç»é²ãååŸããåŸã管çè ã«ãªãããŸããããã£ãŠãå€éšã®èŠ³æž¬è ããèŠããšãããŒã¿ã¯æ£åœãªãããã¯ãŒã¯ç®¡çè ãä»äºãããŠããããã«èŠããŸãã
ãªããªããã«ãŠã§ã¢ã¯äœ¿çšãããŸãããã»ãã¥ãªãã£ã·ã¹ãã ã¯ããããã¯ãŒã¯ãŠãŒã¶ãŒã®è¡åã«åºã¥ããŠãããã®ã¿ã€ãã®æ»æãèå¥ã§ããå¿ èŠããããŸãããã®ãããªåé¡ã解決ã§ããæè¡ã¯ãè åšãã³ãã£ã³ã°ã®æŠå¿µã«è©²åœããŸãã
Threat Huntingãã©ãããã©ãŒã ã¯ããšããããã¢ããªã±ãŒã·ã§ã³ãå®è¡ããŠããã³ã³ãã¥ãŒã¿ãŒãç¹ã«ãŠãŒã¶ãŒã®åäœãç£èŠã§ããå¿ èŠããããŸãã
å žåçãªè¡åãããã¡ã€ã«ã¯ããããã®ã³ã³ããŒãã³ãããšã«åçã«æ±ºå®ããå¿ èŠãããããã®åŸããªã¢ã«ã¿ã€ã ã§ãå®éã«èµ·ããŠããããšãšäžèŽãããŠã誰ããçãŸããããšã瀺ãå¯èœæ§ã®ããè¡åãæ ¹çµ¶ããå¿ èŠããããŸãå¥ã®åŸæ¥å¡ã®ç»é²ããŒã¿ãšåœŒã«ä»£ãã£ãŠè¡åããŸãã
æè¡çã«èšãã°ãThreat Huntingããã»ã¹ã¯ãå¶åŸ¡ãããã³ã³ããŒãã³ãã®ãã¹ãŠã®åäœãã¿ãŒã³ãèšè¿°ããèšå€§ãªããŒã¿ã®ããŒã«ã«åºã¥ããŠãããæ°ããã€ãã³ããçºçãããšãªã¢ã«ã¿ã€ã ã§æŽæ°ãããŸãããã®ã³ã³ããã¹ãã§ã¯ã䜿çšããããã©ãããã©ãŒã ã¯ããã®èšå€§ãªæ å ±ãæ¢çŽ¢ããŠæ°ããæ»æ仮説ãäœæãããµã³ãã«ããŒã¿ã°ã«ãŒãã§ãªã¢ã«ã¿ã€ã ã«ãã¹ãããŠããã¡ã€ã³ããŒã¿ã¹ããªãŒã ã§ã¢ã¯ãã£ãåããŠãè¡åãããã¡ã€ã«ç°åžžã®æ€çŽ¢ã«åºã¥ããŠã¢ãã«ãçæã§ããå¿ èŠããããŸãããã®æ®µéã§ãæ©æ¢°åŠç¿ã·ã¹ãã ã¯ãããªã¬ãŒãããåŸããã©ãããã©ãŒã ã«çµ±åããããªã¢ãŒãã®å°é家åæããŒã«ã䜿çšããŠæ éã«åæããå¿ èŠãããæœåšçãªã€ã³ã·ãã³ãã«ãŸããŸã泚æãæããŸãã
ãã®ãããªããŒã«ã«ãããã¢ããªã¹ãã¯åœ±é¿ãåããã³ã³ãã¥ãŒã¿ãŒã§ããŒãœãã©ã€ãºããããã§ãã¯ãå®è¡ããåã³ã³ãã¥ãŒã¿ãŒã®ã€ãã³ãå±¥æŽãŸãã¯åãŠãŒã¶ãŒã®ã¢ã¯ãã£ããã£ã®ä»»æã®æç¹ã§èªåèªèº«ããé 眮ãããæ»æã確èªããæé ãåæ§ç¯ã§ããŸãã
è¿ãå°æ¥ãæããã«æªæã®ããç¹å®ã®ããã°ã©ã ãšãã圢åŒã®åŸæ¥ã®æªæã®ããããã°ã©ã ã¯ããã«ãŠã§ã¢ã䜿çšããã«å®è¡ãããæäœã«çœ®ãæããããæ»æè ã¯ãããã¯ãŒã¯ãŠãŒã¶ãŒã®èº«å ã奪ããäžèŠæ£åœãªãããã¯ãŒã¯ãŠãŒã¶ãŒãè£ ã£ãŠå¿ èŠãªã¢ã¯ã·ã§ã³ãå®è¡ããŸãã
ãã®ç¹ã§ãå³å¯ã«ç®¡çãããããžãã£ãã¢ãã«ã®å®è£ ã®æ©äŒãæäŸããããšã«å ããŠãã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãã¹ã±ãŒã©ãã«ãªè åšãã³ãã£ã³ã°ãµãŒãã¹ããã³ãã©ãããã©ãŒã ãæäŸããããšãäžå¯æ¬ ã§ãã
Panda Adaptive Defenseã¯ããããã®æ©èœã®äž¡æ¹ãçµã¿åãããåžå Žåã®ãœãªã¥ãŒã·ã§ã³ã§ããèªååãããThreat HuntingãµãŒãã¹ãšããŠãŒã¶ãŒããããã¯ãŒã¯ãã¹ãã£ã³ããã³åµå¯ããŠæ£åœãªäŒæ¥è³æ Œæ å ±ã®èåŸã«é ããŠããããã«ãŒãæ€çŽ¢ã§ããAPIããã³ã³ã³ãœãŒã«ã®åœ¢ã®ããŒã«ãŠãŒã¶ãŒã
æ»æäŸ
æ»æã¯ããå®ç§ã«ãªããŸãããç®æšãå€æŽãããŸããããã¯ããã¯ã¯æŽç·Žãããæ»æãã¯ãã«ã®æ°ãå¢å ããããããå®è¡ããããŒã«ã¯ããã«æŽç·ŽãããŠããŸãã
æ»æè ã¯ãå¯èœãªéãæ倧ã®çµæãéæããããã«æ»ææŠç¥ãããããé©å¿ãããããã«ãæœåšçãªè¢«å®³è ã泚ææ·±ãç 究ããŸããè åšã®62ïŒ ã®èåŸã«ã¯ãåæã«ç©æ¥µçã«é¢äžããæ»æãããã«å¿ããŠå€ç§ç粟床ã§é©å¿ãããããã«ãŒãããŸãã
ãããã®æå¹æ§ãå¹çæ§ãåçæ§ã¯åžžã«ç¢ºèªãããŠããŸãã 2017幎ã ãã§ããæ倧100,000ã®æ°ããã»ãã¥ãªãã£ããŒã«ãšã€ã³ã·ãã³ããäŒæ¥ç°å¢ã«çŸããŸããã
ãã®ã¬ããŒãã®äžéšãšããŠãæ»æè ããããã©ã®ããã«è¡ããäœãéæããããèŠãŸãããåæã«ããµã€ããŒæ»æã®è¢«å®³è ã«ãªãå¯èœæ§ãã¯ããã«é«ããªã£ãŠããããã§ããéšåçã«ãã®å£°æã¯çå®ã§ããããããäºé²ãæ€åºã察å¿ãããã³å埩ã·ã¹ãã ãã¯ããã«å¹æçã«ãªããŸãããPanda Adaptive Defenseã®å Žåã®ããã«ã圌ãã¯ãœãªã¥ãŒã·ã§ã³ãšãµãŒãã¹ãçµã¿åãããŠä¿è·ãæé©åããæ»æãšãªã¢ãæžããããœãªã¥ãŒã·ã§ã³ãšãµãŒãã¹ãçµã¿åãããŠä¿è·ãæé©åããæ»æãšãªã¢ãæžãããè åšã®åœ±é¿ãæå°éã«æããŸãã
ãã®æè¡éçºã®ãããã§ãPanda Securityãæééãã«æ»æãäžæããå€ãã®ç¶æ³ã«ã€ããŠèª¬æããããšãã§ããŸããããã§ã¯ãå°é家ã®ç 究ã決å®çãªåœ¹å²ãæãããŸããããããã®æ»æã¯ã
ã»ãã¥ãªãã£æ»æã®95ïŒ ã9ã€ã®ã¢ãã«ã«åæžã§ãããšäž»åŒµããVerizonã®ç 究ãè£ä»ãããæ°ããæ»æã®åŸåãšææ³ã®éçºã瀺ããŠããŸãã
ãããã£ãŠãPanda Adaptive Defenseããå³åº§ã«ä¿è·ãããŠããªãã¯ãŒã¯ã¹ããŒã·ã§ã³ãã·ã¹ãã ã§ãã£ãŠããäŒæ¥ã®ãããã³ã«ãšé²åŸ¡æ§é ã®æ¹åãæ¯æŽããŸããã
æ°Žå¹³åé²
æ»æã®é²åã®äŸãšããŠãé©å¿åã®æ°Žå¹³æ¹åã®åé²ã䌎ãç§å¯æ»æãå°å ¥ããããšããå§ããŸãããã®ã¿ã€ãã®æ»æã¯éåžžã«äžè¬çã«ãªã£ãŠããŸããä»åãå瀟ã¯ãã¹ãŠã®æ€åºããã³ä¿è·ã·ã¹ãã ïŒãã¡ã€ã¢ãŠã©ãŒã«ãIPSãSoCããã¡ã€ã³ã³ã³ãããŒã©ãŒããããã·ãåŸæ¥ã®ä¿è·ãªã©ïŒã
ä¿æããŠããŸãããã¯ã©ã€ã¢ã³ãã®è³ç£ã«å¯Ÿããæ»æã®æåã«ã€ãªããå¯èœæ§ã®ããæ°Žå¹³çãªé²æ©ã«æ°ã¥ããã·ã¹ãã ã¯1ã€ããããŸããã§ããã
ããããç¯çœªè ã¯ãäŒç€Ÿãé©å¿é²è¡ãæã£ãŠããããšãæåŸ ããŠããªãã£ããããå®éã«æå³ãçºèŠããæ»æèšç»ãé»æ¢ããŸãã
ãRDPïŒãã«ãŠã§ã¢ã䜿çšããªãæ»æ
ãã«ãŠã§ã¢ã®ãªãæ»æã¯ããµã€ããŒç¯çœªè ã®ãæ°ã«å ¥ãã®è åšã®1ã€ã«ãªããŸããã 2017幎ã«èšé²ãããã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®51ïŒ ã®ã¿ããæ»ææäœãšããŠäœããã®ãã«ãŠã§ã¢ã䜿çšããŸãããããã«ãŒã¯åŸæ¥ã®ä¿è·ã«æ°ä»ãããã被害è ã®ã¹ã¿ãããšã®ããåãã«é Œããªãããšã奜ã¿ãŸãããã®çµæãäŸã«ç€ºãããã«ãæ»æã®å¹æãæé©åããããšã§å©çãå¢ãããŸãã
æ»æã®æœåšçãªè¢«å®³è ãç¹å®ããããšããã«ãRDPæ»æãéå§ããã2ã€ã®æ¹åã§å©çãåŸãããŸãã1ïŒãµãŒãããŒãã£ã®Webãµã€ãã«è²©å£²ã§ãããªã³ã©ã€ã³ãã©ãã£ãã¯ãçæããããŸãã¯2ïŒäŸµå®³ããããã·ã³ãžã®ã¢ã¯ã»ã¹ã販売ããç§ãã¡ã¯ãããããŸããé »åºŠã§ãã®ãããªã±ãŒã¹ãèŠãŠããŸããããã®ãããªã¹ããŒã ã¯ã次ã®ã€ã³ãã©ã°ã©ãã£ãã¯ã«èŠçŽã§ããŸãã
å åŸæ¥å¡ã«ããæEx
äŒç€Ÿã«å¯Ÿããæ»æãéå§ããæãäžè¬çãªåæ©ã®1ã€ã¯ãæããšåŸ©reãžã®æ¬²æ±ã§ãã
2017幎ã«ã¯ãå åŸæ¥å¡ã解éãããäŒç€Ÿãè è¿«ããããšããã±ãŒã¹ãèŠãŸãããããã«ãå éšã®å®è¡è ã«ãã£ãŠéå§ãããæ»æã¯ããã§ã«äžççãªè åšã®25ïŒ ã«éããŠããã
ãããã®å Žåã®å ±éç¹ã¯ãé²è¡æ¿çã®åŒ±ããšãå åŸæ¥å¡ã®äŒæ¥ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã§ãã
äžæ£ã¢ã¯ã»ã¹ã®81ïŒ ã¯ãå®å šã§ãªããã¹ã¯ãŒããåå ã§çºçãããããã¹ã¯ãŒãçé£ã®çµæãšããŠçºçããŸããã
ããã«ãããããããå éšã§ã¯ãåŸæ¥å¡ã¯æé«ã®ããã«ãŒã«ãµããããæ¡åŒµããã³å¶åŸ¡æŠç¥ã䜿çšããŠãä»ã®ã»ãã¥ãªãã£ã·ã¹ãã ãåé¿ããäŒç€Ÿã®è©å€ãšè²¡åãæãªããŸãã
äžè¬çãªåŽé¢
ããã€ãã®éãã«ããããããããããã®ãã¹ãŠã®ã±ãŒã¹ã«ã¯å€ãã®é¡äŒŒç¹ããããŸãïŒ
- æ»æã®æºåã«ãããäŒç€Ÿã®åŒ±ç¹ã®äºå調æ»
- ãããã®æ¬ ç¹ãžã®æ»æã®é©å¿ãåŸæ¥ã®ãŠã€ã«ã¹å¯Ÿçãœãªã¥ãŒã·ã§ã³ã®èŠåã·ã¹ãã ã«ããçããããªã¬ãŒãåŒãèµ·ãããªãç§å¯ã®ã¢ã¯ã»ã¹ã
- ç®æšãéæããããã«æ éã«èšç»ããã³èšç»ãããå éšã®é²æ©ã
ããããã¹ãŠã®æ»æã®å ±éã®ç®æšã¯ããã€ãã®ããã«ãéã§ãã Verizonã«ãããšãééçç®æšã¯æ»æã®73ïŒ ã§èŠãããã¹ãã€è¡çºã¯æ»æã®21ïŒ ã®åæ©ã§ãã
ããããã¹ãŠã®ã±ãŒã¹ã®ãã1ã€ã®å ±éç¹ã¯ãããããã¹ãŠã®æ»æãThreat HuntingããŒã ãšPanda Securityãéçºããé«åºŠãªä¿è·ãœãªã¥ãŒã·ã§ã³ã«ãã£ãŠæéå ã«æ€åºããã³é²æ¢ãããããšã§ãã
æ»æã®äŸ¡æ Œ
ããã«ãŒã®å°éåããã¯ãããžãŒã®é²åãããŒã¿ãžã®ã¢ã¯ã»ã¹ã®å®¹æãã«ãã£ãŠããµã€ããŒæ»æã®ãæ°äž»åãããã»ã¹ãã©ã®ããã«ä¿é²ãããããèŠãŸããã
ãã¡ãããããããã¹ãŠããããã®ã¿ã€ãã®è åšã®æ®åã«è²¢ç®ããŸããããããã«ããããããããããã®ã¢ã¯ã·ã§ã³ã¯æ»æã®é«ãåçæ§ã«ãããã®ã§ãã
å®äŸ¡ãªãµã€ããŒè»ã¯ããµã€ããŒç¯çœªè ãæ·±å»ãªçµæžçå ±é ¬ãç²åŸã§ããããã«ããŸãã
GDPRïŒãšãŒãããã®èŠå¶
欧å·é£åã®æ°ããäžè¬ããŒã¿ä¿è·èŠåïŒGDPRïŒã¯ããµã€ããŒæ»æã®æ°ã®æ確ãªå¢å ã«å¯Ÿå¿ããŠéçºãããåœå®¶ãšåæ¥ã®äŒæ¥ããã³çµç¹éã®ååã®æ çµã¿ã§ããããšæŠãããšãç®çãšããŠããŸãã
ãã§ã«çºå¹ããŠããŸãããGDPRã¯2018幎5æãã欧å·é£åã§å šé¢çã«æ©èœãå§ããŸããçŸåšãäŒæ¥ã¯æ°ããæ³åŸã«åŸã£ãŠæŽ»åãè¡ã£ãŠããŸãã
2018幎5æããããã¹ãŠã®EUå çåœã¯ãé¢é£ããçŸè¡ã®åœå æ³ããGDPRã«ç§»è¡ããå¿ èŠããããŸããæ°ããæ³åŸã¯ãäŒæ¥ãããå³æ Œã§å³ããèŠä»¶ã«ããªã·ãŒãé©åãããããšãèŠæ±ããŠããŸãã
ããšãã°ãäŒæ¥ã¯å人ããŒã¿ã®éåãé©åãªããŒã¿ä¿è·æ©é¢ã«å ±åãã矩åããããŸããããã§ãªãå ŽåãäŒæ¥ã¯å¹Žé売äžé«ã®æ倧4ïŒ ã®çœ°éãç§ãããå¯èœæ§ããããŸãã
ãŸããçµç¹ã¯ãããŒã¿ãæ±ããã¹ãŠã®ã¬ãã«ã§æå·åããã³2èŠçŽ èªèšŒã·ã¹ãã ã®å®è£ ãäœåãªããããŸããæ°ããæ³åŸã§èŠå®ãããŠããæãéèŠãªå€æŽã®1ã€ã¯ãããŒã¿ä¿è·è²¬ä»»è ïŒDPOïŒã®å¯çšæ§ã§ãããã®è·äœãä¿æããåŸæ¥å¡ã¯ãGDPRã®èŠå®ãé å®ããããã«ãé¢é£ããæ³åŸãšå¿ èŠãªæè¡ã€ã³ãã©ã®ç¥èãæã£ãŠããå¿ èŠããããŸãã
ãã ããDPOã®å šç¯å²ã®è²¬ä»»ã¯æªå®ã§ãããŸãããããç®èº«çãªåŸæ¥å¡ã§ããã¹ããã圌ã®è·åãæ å ±ã»ãã¥ãªãã£æ åœè ã«å§ä»»ã§ãããã«ã€ããŠãå®å šã«ã¯æ±ºçããŠããŸããã
GDPRã®äžè¬çãªåŽé¢ïŒ
â¢æ¬§å·é£åå€ã«ç»é²ãããäŒæ¥ãå«ãã欧å·é£åã®å± äœè ã®ããŒã¿ãåŠçããããã®èŠåãããæ確ã«ç¢ºç«ããŸãã
â¢å人ããŒã¿ã®åéãšåŠçãããã³äœ¿çšã®å¯èœæ§ã«é¢ããŠãEUå± äœè ã®æ瀺çãªåæãå¿ èŠã§ãã
â¢å人ããŒã¿ã«é¢é£ãããã®ãå®çŸ©ããŸããããã«ã¯ããœãŒã·ã£ã«ãããã¯ãŒã¯ãããã¡ã€ã«ããŒã¿ãåçãé»åã¡ãŒã«
ã¢ãã¬ã¹ãããã«ã¯IPã¢ãã¬ã¹ãå«ãŸããŸãã
â¢ãªãŒãã³ã§äžè¬çãªãã¡ã€ã«åœ¢åŒã«ããããŒã¿è»¢éãæ€èšããŸãã
â¢ãå¿åŽæš©ããèŠå¶ããŸããããã«ãããå人ã¯èŠæ±ã«å¿ããŠããŒã¿ãå®å šã«åé€ãŸãã¯ä¿®æ£ã§ããŸãã
â¢ããããèŠæš¡ã®çµç¹ã
ãé¢ä¿åœå±ãšã®GDPRæ¡é ã®éµå®ã«è²¬ä»»ãæã€ããŒã¿ä¿è·æ åœè ãæå®ããå¿ èŠãããããšã確ç«ããŸãã
â¢ãã©ã€ãã·ãŒã®åé¡ããã¹ãŠã®ããžãã¹ããã»ã¹ã«çµ±åããå¿ èŠããããŸãã
â¢å人ããŒã¿ãå«ãã€ã³ã·ãã³ãã«é¢ããæ å ±ãæ°æ¥ä»¥å ã«å ±åããå¿ èŠããããŸãã
â¢æ倧2000äžãŠãŒããŸãã¯å¹Žé売äžé«ã®æ倧4ïŒ ã®å·šé¡ã®çœ°éãæäŸããŸããããã¯çŸåšã®å€ãããã¯ããã«é«ãé¡ã§ãã
GDPRã®å°å ¥ã®åœ±é¿
ã»ãšãã©ã®ç±³åœã®å·ã«ã¯ã顧客ããŒã¿ã»ãã¥ãªãã£ã®éåãçŽã¡ã«å ±åããããšã矩åä»ããæ³åŸããããŸãã
ã¡ãã£ã¢ã§å ±åãããããŒã¿ã®éåã®å€§éšåãã¢ã¡ãªã«äŒæ¥ã«é¢é£ããŠããããšã¯é©ãããšã§ã¯ãããŸããã
GDPRã®æ¡çšåã¯ãå€ãã®EUè«žåœã¯åœå æ³ã§åæ§ã®åºæºãæã£ãŠããŸããã§ããã
æè¿ã®æ³šç®åºŠã®é«ãäŸã¯ãEquifaxã€ã³ã·ãã³ãã§ããããã¯ãå²äžæãé倧ãªå人ããŒã¿ã®ãã©ã€ãã·ãŒäŸµå®³ãšèŠãªãããŠããŸãã GDPRã®çºå¹åã«æ¬§å·é£åã§ãããçºçããå Žåããããã圱é¿ãåãã顧客ãåœå±ãããã®äºä»¶ã«ã€ããŠèª°ãç¥ããªãã£ãã§ãããã
GDPRã®ãã¹ãŠã®èŠåãšèŠå¶ãæœè¡ãããåŸã«ããã欧å·é£åã§çºçããå ŽåãEqui FAXã¯æ¬§å·é£åãšåœ±é¿ãåãããã¹ãŠã®é¡§å®¢ããã®èšŽèšã«çŽé¢ããŸããEquifaxã¯ãå¹³å幎é売äžé«5åãã«ãèãããšã欧å·é£åã«ãã£ãŠ2000äžãã«ã®çœ°éãç§ããããå¯èœæ§ããããŸãããããŠãããã¯ã圱é¿ãåãããã¹ãŠã®é¡§å®¢ããã®èšŽèšãèæ ®ããåŸã«äŒç€Ÿã被ã£ãã§ãããæ倱ãã«ãŠã³ãããŠããŸããã
GDPRã®ãã¹ãŠã®èŠåãšèŠå¶ã®çºå¹ã«ãããæ·±å»ãªå€åãåŸ ã£ãŠããŸãããã®çµæã欧å·é£åã§ã®ããŒã¿çé£ã®ä»¶æ°ãæ¥å¢ããå¯èœæ§ããããŸãããã§ã«ãã®ãããªäºä»¶ããããŸãããéãã¯ãä»ãããã«ã€ããŠåŠã¶ããšã§ãã
æ å ±ã»ãã¥ãªãã£ã®äºæž¬
äžèšã®åæãããæ å ±ã»ãã¥ãªãã£ã®åé¡ã¯ãç¹ã«äžèŠæš¡ããã³å€§èŠæš¡äŒæ¥ã«ãšã£ãŠãŸããŸãéèŠã«ãªãã€ã€ããããã®å€§éšåãäžæçã«ããŒã¿æŽåæ§éåã«èŠããã§ããããšãããããŸãã
ããŒã¿æŒæŽ©ãšãã®ã€ã³ã·ãã³ãã®æ€åºã®ééã¯æ¡å€§ããŠãããããŒã¿æ倱ãé²æ¢ããåŸæ¥ã®æ¹æ³ã®å¹æã¯äœäžããŠããŸãã
ãããã¯ãæ å ±ã»ãã¥ãªãã£ã®åéã«ãããä»æ¥ã®åé¡ã®ã»ãã®äžéšã§ããã2018幎ã«ã¯ã©ã®ãããªè åšãåŸ ã¡åããŠããŸããïŒ
ãã®ã»ã¯ã·ã§ã³ã§ã¯ãæ å ±ã»ãã¥ãªãã£ã®äžçã2018幎ã«äœãæåŸ ãããã«ã€ããŠã®äºæž¬ãè°è«ããŸãã
ãµã€ããŒæŠäºãšãã®çµæ
ãµã€ããŒæŠäºã¯ãç§ãã¡ããã§ã«çããŠããçŸå®ã§ããåœäºè éã®åºå¥ãæ確ã«è¡ãããéãããæŠäºã®ä»£ããã«ããµã€ããŒæŠäºã¯ããã¯ã°ã©ãŠã³ãã§è¡ãããå€ç«ããã²ãªã©ã¹ã¿ã€ã«ã®æ»æã§æ§æãããŸãã
ããå€ãæ¯æãããšã«ãªã人ãã¡ã®ãµãŒãã¹ã§ããªãŒã©ã³ãµãŒ
äžçã®äž»èŠå€§åœã¯ãã§ã«ãµã€ããŒå µå£«ã®è»å£ãæã£ãŠãæ°åãµã€ããŒã¹ããŒã¹ã§æ»æããããšãã§ããŸãèšç·Žãåããå µå£«ã®äœåãã®ããã®ãã¡ã圌ãã®äžéšã¯ããªãŒã©ã³ãµãŒã«ãªããæããéãæã人ã«ãµãŒãã¹ãæäŸããŸããããã®ãµã€ããŒç¯çœªè ã®ã®ã£ã³ã°ã¯ããµã€ããŒå µåšã«ã¢ã¯ã»ã¹ããæ»æãéå§ããããã®è²Žéãªç¥èãæã€ãååã«èšç·Žãããå°é家ã®ã°ã«ãŒããèŠã€ããã§ãããããã®çµæãæãè€éã§é«åºŠãªæ»æã®æ¥éãªæé·ãèŠãããŸãã
æäœãåœã®ãã©ã°ã
ãµã€ããŒæ»æãçŽäºã«é¢äžããåœã«æäŸããæãé åçãªæ©èœã®1ã€ã¯ãã€ã³ã¿ãŒãããã«ãã£ãŠæäŸãããå¿åæ§ã§ãããã¡ãããæ»æã®å 害è ã«ã€ããŠã¯åžžã«ç念ããããããšãã°è¢«å®³è ãåæãããã®æ»æãã誰ãå©çãåŸããã«ã€ããŠçµè«ãå°ãåºããŸãã
å¥ã®æ¹æ³ã¯ãæ»æè ãæ®ãå¯èœæ§ã®ãããã¬ãŒã¹ã調ã¹ãããšã§ãïŒäœ¿çšãããæªæã®ããã³ãŒãã®ç¹æ§ãå¿ èŠãªéä¿¡ãå®è¡ããããã«æ»æäžã«æ¥ç¶ããããµãŒããŒãªã©ã
ããã«ãããããããå¿åæ§ã¯ãã®ãããªæ»æã®è¿œå ã®æŠåšã§ããããªããšé¢ä¿ã®ãªã第äžè ãéããŠæ»æãè¡ãããšã¯éåžžã«ç°¡åã§ãããã®ã¿ã€ãã®ãåœã®ãã©ã°ãæäœã¯éåžžã«äžè¬çã«ãªããããã©ã®åœã®æ¿åºã«ãã£ãŠãµããŒããããŠãããµã€ããŒæ»æã®èåŸã«ããã®ããæ£ç¢ºã«èŠã€ããããšã¯ã¯ããã«å°é£ã«ãªããŸããæ ä¿
被害è
WannaCryã¯ãäŒæ¥ãããã¯ãŒã¯ã«äŸµå ¥ããããããè匱ãªè¢«å®³è ãç¡å·®å¥ã«æ»æã§ããæ»æãããããšãæããã«ããŸããã
ããããç®æšãéåžžã«æ確ã«å®çŸ©ãããŠãããå€ç§çãæ»æããããŸããããã¯ãPetya / GoldenEyeã®å ŽåãšãŸã£ããåãã§ããPetya/ GoldenEyeã¯ããŠã¯ã©ã€ãã®åœå®¶æ©é¢ãšæ°éäŒæ¥ã«å¯ŸããŠæ確ã«æ瀺ãããŸãããããããçŸå®ã«ã¯ã€ã³ã¿ãŒãããã«ã¯å¢çç·ããªããæ°åã«åœã®äŒæ¥ããã®æ»æã«èŠããã§ããã圌ãã¯äœã®é¢ä¿ããªãçŽäºã®äºæ¬¡è¢«å®³è ã«ãªã£ãŠããŸãã
ç§ãã¡ã®éã®æµ
æ³åã§ããææªã®æªå€¢ã®1ã€ã¯ãä¿è·ãããç°å¢ã§æ»æãåããããšã§ããä¿è·ãããç°å¢ã§ã¯ãããšãã°èªå® ã§å®å šã«æããããšãã§ããŸããããã¯ã次ã®çç±ã«ãããååãªæºåãæŽã£ãŠããªãç¶æ³ã§ããaïŒèªå® ã«æåŸ ãã人ãä¿¡é Œããã bïŒãã€ããæŠåšãšããŠäœ¿çšã§ããå Žåã§ãããããã³çšåã®çã£inäžã«ããç§ãã¡å šå¡ãããã家ã«æã£ãŠããŸãããã®é¡æšã¯ãç§ãã¡ãçŽé¢ããæ»æã®ã¿ã€ãã瀺ããŠããŸãïŒ
ãã«ãŠã§ã¢ã䜿çšããªãããã«ãŒæ»æ
2018幎ã«èŠãããåŸåã®1ã€ã¯ã
æªæã®ããããã°ã©ã ã䜿çšããªãæ»æãšæªæã®ããããŒã«ãæªçšããæ»æã®æ°ã®å¢å ã§ãã
2017幎ã«ã¯ãäŒæ¥ã®ã»ãã¥ãªãã£äŸµå®³ã®62ïŒ ã®ã±ãŒã¹ã§ããã«ãŒã®ãã¯ããã¯ã䜿çšããããã®ãããªã€ã³ã·ãã³ãã®ã»ãŒåæ°ïŒ49ïŒ ïŒããã«ãŠã§ã¢ããŸã£ãã䜿çšããŠããŸããã§ããïŒVerizonãç·šéãã2017幎ã®ããŒã¿äŸµå®³èª¿æ»ã¬ããŒãã«ããïŒã
ãããã³ã°ãããã¢ããªã±ãŒã·ã§ã³
人æ°ã®ããMEDocã¢ã«ãŠã³ãã£ã³ã°ãœãããŠã§ã¢ããããã³ã°ããããšããç§ãã¡ã¯ãã§ã«ãããPetya / GoldenEyeæ»æã®äžéšãšããŠèŠãŠããŸãããç¹ã«æ³šç®ãéããå¥ã®ã±ãŒã¹ã¯ãCCleanerã§ãããCCleanerã¯ã倧èŠæš¡ãªãã¯ãããžãŒäŒæ¥ã®ç¹å®ã®è¢«å®³è ãçã£ãæ»æãå®è¡ããããã«æªç¥ã®ããã«ãŒã«ãã£ãŠä¿®æ£ãããŸããã
ã¢ãã€ã«æ©åš
ã¢ãã€ã«ç°å¢ã®è åšãã©ã®çšåºŠå¿é ããå¿ èŠããããŸããïŒåçïŒçç±ã®ç¯å²å ãäžçã®ã³ã³ãã¥ãŒã¿ãŒãããã¹ããŒããã©ã³ã®æ¹ãå€ãããšãèŠããŠãããŠãã ãããããããã¹ããŒããã©ã³ã«å¯Ÿããæ»æã®æ°ã¯ãPCã察åŠããªããã°ãªããªãããšã®ã»ãã®äžéšã§ãã
ããã¯ãã¢ãã€ã«ããã€ã¹ã®ã»ãã¥ãªãã£åé¡ã«ç¡é¢å¿ã§ããã¹ããšããæå³ã§ã¯ãããŸãããæ»æã¯åŒãç¶ãçºçããŸãããGoogleã¯äž»ãªåé¡ã«æ³šæãæããåŸã ã«ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ïŒã¢ãã€ã«ããã€ã¹ã»ã¯ã¿ãŒã§äžçæ倧ã®åžå Žã·ã§ã¢ãèªãAndroidïŒãä¿è·ããããã®æªçœ®ãè¬ããŠããããã§ãã
ããããäºå®ã¯äŸç¶ãšããŠæ®ã£ãŠããŸããAndroidã«å¯Ÿããç¡æ°ã®è åšãããããããã¡ãããã¢ãã€ã«ããã€ã¹ããæ¥ç¶ãããã¹ãŠã®ããŒã¿ãé©åã«ä¿è·ããå¿ èŠããããŸãã
ã¢ãã®ã€ã³ã¿ãŒããã
ã€ã³ã¿ãŒãããã«æ¥ç¶ãããŠããããã€ã¹ã®æ°ã¯å¢ãç¶ããŠããŸããããã¯ã©ã®ããã«ã»ãã¥ãªãã£ã«åœ±é¿ããŸããïŒæ°åã®IoTããã€ã¹ïŒIPã«ã¡ã©ããããªã³ã¿ãŒïŒã§æ§æããããããããããæ¢ã«ååšãããµã€ããŒç¯çœªè ã倧èŠæš¡ãªæ»æãä»æããèœåãäžããŠããŸãã
äžè¬çã«ãIoTããã€ã¹ã¯ãµã€ããŒç¯çœªè ã®äž»èŠãªæšçã§ã¯ãããŸããããã ãããã®ãããªããã€ã¹ã¯æ»æã®ç¯å²ãæ¡å€§ãããããäŒæ¥ãããã¯ãŒã¯ãžã®æ»æã®ãšã³ããªãã€ã³ããšããŠäœ¿çšãããããšããŸããŸãå¢ããŠããŸãã
ãã¹ãŠãéã®ãã
æå·äœæè
ãµã€ããŒç¯çœªçµç¹ã®äž»ãªç®æšãå©çãäžããããšã§ããããšã¯ééããããŸããã
æå·åæ»æã2018幎ã«æµè¡ããŸããããããžã®æœåšçãªæè³åççã¯éåžžã«é«ãããªã¹ã¯ã¯æ¥µããŠäœããŸãŸã§ãã
ããé«åºŠãªæ»æ
ïŒç¹ã«æœåšçãªå©ç¹ãé«ãå Žåãæ»æã¯ããå°éçã«ãªããŸããæ°ãããµã€ããŒç¯çœªææ³ãæåãããšããããã¯å³åº§ã«å€§ã çã«è¡ãããŸããããã¯ã2018幎ã«é«åºŠãªæ»æã®æ°ãå€§å¹ ã«å¢å ããäž»ãªçç±ã®1ã€ã§ãã
è¿å¹Žã®åŸåã«åŸãã2018幎ã«ã¯æ»ææ°ã2017幎ãšæ¯èŒããŠ50ïŒ å¢å ããŸãã
2018ïŒäŒæ¥ã«å¯Ÿããæ»æã®å¹Ž
ãããããéå»æ倧èŠæš¡ã®æ»æã®ããã€ãã倩æåŠçãªéã®ããŒã¿ãçãŸããŠçãæ®ã£ãã®ã¯äºå®ã§ããããããšãã°ãã€ããŒã®äºä»¶ãäœåãã®ç»é²ããŒã¿ã®çé£ã誰ããèŠããŠããŸãã
ãããŠãã¡ããã2017幎ã«ã¯ãã»ã€ããŒãšãšã¯ã€ãã¡ãã¯ã¹ãšã®äºä»¶ããããŸãããã§ã¯ããªã2018幎ã¯ãäŒæ¥ã«å¯Ÿããæ»æã®å¹Žããšããã¿ã€ãã«ã«ãµãããããšæãã®ã§ããããïŒãã®è³ªåã«ã¯ãGDPRãšãã4æåã®ç¥èªã§çããããšãã§ããŸãã
ããã¯ã2018幎ã«äŒæ¥ãå幎ãããå€ãã®æ»æã«ãããããããšãæå³ãããã®ã§ã¯ãããŸããã
ãããããå²äžåããŠãäžè¬ã®äººã ã¯ãGDPRã®çºå¹åã«ãããŸã§ç¥ãããŠããªããããŸãã¯é瀺ãããŠããªãã£ããã®ãå«ãããã¹ãŠãŸãã¯ã»ãŒãã¹ãŠã®ããŒã¿ã®äºä»¶ã«æ°ä»ãã§ãããã
ãœãŒã·ã£ã«ãããã¯ãŒã¯ãšãããã¬ã³ã
æŽå²äžãããã»ã©å€ãã®æ å ±ã«äººã ãã¢ã¯ã»ã¹ããããšã¯ãããŸããã§ããããããç®èãªããšã«ãä¿¡é Œã§ããæ å ±ãèŠã€ããããšã¯ä»ãŸã§ã«ãªãé£ããããšã§ã¯ãããŸããã§ããã
ç°¡åã«èšãã°ããœãŒã·ã£ã«ãããã¯ãŒã¯ã¯æ å ±ã亀æã§ããããŒã«ã§ãããäžçäžã®äœååãã®äººã ããããã䜿çšãããšãäžè«ã«åœ±é¿ãäžããã人ã«ãšã£ãŠæãããªã¿ãŒã²ããã«ãªããŸããããæå³ã§ã¯ã圌ãã®åœ¹å²ã¯ã¡ãã£ã¢ã«å¹æµããŸããç±³åœå€§çµ±é B.ãªãããFacebookã®åµèšè å ŒCEOã®ããŒã¯ã»ã¶ãã«ãŒããŒã°ã倧統é éžæäžã®åœãã¥ãŒã¹ã®è åšã«ã€ããŠéåžžã«çå£ã«èŠåããŠããã®ãèããŸããã
äžçæ倧ã®ãœãŒã·ã£ã«ãããã¯ãŒã¯ã§ããFacebookã¯ããã§ã«ãã®æ¹åã§è¡åãèµ·ãããŠããŸãã FacebookããŒãžã
åœã®ãã¥ãŒã¹ãç¹°ãè¿ãé ä¿¡ããŠããããšãå€æããå ŽåãFacebook ã¯ãããã¯ãŒã¯äžã®ã©ãã§ãåºåãçŠæ¢ããŸããå瀟ã¯ãŸãããããã¯ãŒã¯ãšã¡ãã£ã¢ã«åºåãæ²èŒããèªè ã«åœã®ãã¥ãŒã¹ãèå¥ããæ¹æ³ã説æããŸãããçŸåšã圌ãã¯éžæåºåããªã·ãŒãå€æŽããŠãã§ããã ãæ確ã«ããããã«ããŠããŸãã
æå·é貚
ãããã³ã€ã³ããã³ãã®ä»ã®æå·é貚ã¯ãããžã¿ã«æ¯æãã®æ段ãšããŠãŸããŸã䜿çšãããŠããŸãããŸãã圌ãã®å°æ¥ã«ã€ããŠå€ãã®æ¶æž¬ããããŸããããããã®é貚ã§ã®æ¯æããåãå ¥ããåæ¥å£äœã¯ãŸããŸãå¢ããŠããŸããæå·é貚ã®æåã®ãã1ã€ã®çç±ã¯ããµã€ããŒç¯çœªè ã«ãšã£ãŠã®ã¡ãªããã§ãã圌ãã¯åœŒããè¿ éãã€å¿åã§å€§éã®ãéãåŠçã§ããããã«ããŸãã
ãããã®æ»æã®ã»ãšãã©ãã¹ãŠããããã³ã€ã³ã®èº«ä»£éãå¿ èŠãšãããããæå·äœæè ã¯ããã®æè¯ã®äŸã§ããæå·é貚ã®
䟡å€ãšäœ¿ããããã¯åŒãç¶ãåäžããŸããããµã€ããŒç¯çœªã¯ããããšãšãã«çºå±ããŸãã
â¢ã³ã³ãã¥ãŒã¿ãŒããã³ãµãŒããŒã«æå·é貚ãã€ãã³ã°ããã°ã©ã ã
ææããã
ã
â¢æå·ãŠã©ã¬ããã®çé£ã
ãããã«
äžçäžã®äŒæ¥ãæ©é¢ã襲ã£ãã°ããŒãã«ãªæ»æãèŠãåŸãã€ã³ã¿ãŒãããäžã®ãã©ã€ãã·ãŒãšã»ãã¥ãªãã£ãä¿è·ããæ¹æ³ãç¥ãããšãéèŠã§ãã
ãœãããŠã§ã¢ãšã»ãã¥ãªãã£ã®æŽæ°ã¯ããã¹ãŠã®äŒæ¥ã«ãšã£ãŠåªå äºé ã§ãã WannaCryãEquifaxãªã©ã®ã±ãŒã¹ã§ã¯ãããã確èªããŠããŸããè匱ãªã·ã¹ãã ãæŽæ°ããã«æ¯æ¥ãçµéãããšãäŒæ¥å šäœãå±éºã«ãããããã ãã§ãªãã顧客ããµãã©ã€ã€ãŒã«é¢ããæ å ±ãå«ãããŒã¿ã®æŽåæ§ãå±éºã«ãããããŸãã
çç£ãå±éºã«ãããããäœçŸäžãã®æ倱ãçºçããå¯èœæ§ããããŸããäžäŸïŒAP Moller-Maerskã¯GoldenEye / NotPetyaæ»æã®ç ç²è ã®1人ã§ããããã®èšç®ã«ãããšãæ倱ã¯2åãã3åç±³ãã«ã«ã®ãŒããŸããã
ååœã¯ãéèŠãªã€ã³ãã©ã¹ãã©ã¯ãã£ã«éç¹ã眮ããŠãé²åŸ¡ããã³æ»æèœåã«ãŸããŸãæè³ããŠããŸãã
厩å£ã«ã€ãªããå¯èœæ§ã®ããæ»æããªã¢ãŒãã§éå§ããæ©èœã¯ããã¯ãçè«ã§ã¯ãããŸãããããã¯ãã§ã«ãŠã¯ã©ã€ãã§çºçããŠãããããã¯äžçã®ã©ã®åœã§ãåã³çºçããå¯èœæ§ããããŸãããã ããè³éãéãããŠããç¯çœªã°ã«ãŒãã¯ãéèŠãªã€ã³ãã©ã¹ãã©ã¯ãã£ã«ç Žå£çãªæ»æãä»æããã®ã«å¿ èŠãªç¥èãšããŒã«ãå©çšã§ããŸããããã«ããã®ãããªæ»æã¯ãäžéšã®ç¹å¥ãªãµãŒãã¹ã ãã§å®è¡ãããããšã¯ã§ããŸããã ISISïŒãã·ã¢ã§çŠæ¢ïŒãªã©ã®ãããªã¹ãã°ã«ãŒãã¯ããããããã«æ¡æ£ãããããã«ãããããæ段ãèªç±ã«äœ¿çšããæºåãã§ããŠããããšãç¥ãããŠããŸãã
2018幎ã¯ããå±éºãªç«å Žã«ãããŸããå€ãã®å°é家ã¯ãæé«ã¬ãã«ã®ã»ãã¥ãªãã£ãå®çŸããäŒæ¥ãããã¯ãŒã¯ã®è³ç£ãä¿è·ããããã«ãèãæ¹ïŒããã³æŠç¥ïŒãå€æŽããå¿ èŠããããŸãã
ãã«ãŠã§ã¢å¯Ÿçã¯å§ãŸãã«ãããŸãããç§ãã¡ã¯ãããè¯ãã»ãã¥ãªãã£æŠç¥ãäœãã«å¯Ÿããä¿¡é Œã®æ¬ åŠãæå³ããæ代ã«çªå ¥ããŠããŸãããããã¯ãŒã¯ã«æ¥ç¶ãããããã€ã¹ã§éå§ããæ°ããããã»ã¹ã¯ãäºåã«æ¿èªããå¿ èŠããããŸãããŸããä¿¡é Œã§ããããã»ã¹ã¯ãç°åžžãªåäœãã§ããã ãæ©ãæ€åºããããã«ãç¶ç¶çãã€ç¶ç¶çã«ç£èŠããå¿ èŠããããŸãã
家ã«ãããã®ããªãã£ã¹ã«ãããã®ãéèŠãªåŽé¢ã¯æè²ãšæèã§ãããã®ããã管çè ããã°ãã°å¿ããæ å ±ã»ãã¥ãªãã£ã«ã¯ããŸããŸãå€ãã®æè³ãå¿ èŠã«ãªããŸãã
æ»æãšãã®æ§æã«ã€ããŠã®æ·±ãç¥èã¯ãåªããé²åŸ¡æŠç¥ã®åºç€ãšãªãã¯ãã§ãããªã¢ã«ã¿ã€ã ã®æ€åºãšå¿çã«åºã¥ãã»ãã¥ãªãã£ã¯ãå°é家ã®åæãšæ»æã®çºçæ¹æ³ã«é¢ãã詳现æ å ±ãšçµã¿åãããŠãå°æ¥ã®äŸµå ¥ãåæ ããããã«éèŠã§ããGartner Peer Insightsã¯ãäž»èŠãªEDRãœãªã¥ãŒã·ã§ã³ãšããŠPanda Adaptive Defenseãæšå¥šããŠããŸãã
眲åãã¡ã€ã«ã¯ãã¯ãæ©èœãããæ°åã¯ããèªäœãç©èªã£ãŠããŸãããã¹ãŠã®æªæã®ããããã°ã©ã ã®99ïŒ ä»¥äžãä»ã®ã©ãã«ãèŠã€ãããŸããã眲åã®åéã¯ããã§ã«æ€åºãæäŸããããã®äžååã§éå¹ççãªæ¹æ³ã§ããã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã®å€ãã®ã¡ãŒã«ãŒã¯ããã¹ãç 究æãåŸã§çœ²åã«ãããã«ãŠã§ã¢æ€åºãã¹ããå®æœãããå Žåã«ã®ã¿ããããè¿œå ããŸãïŒãããŠãããã¯ããã»ã©äžè¬çã§ã¯ãªããªã£ãŠããŠããŸãïŒã補åãè åšãæ€åºãããã©ããã
ãã«ãŠã§ã¢ãšã®æŠãã«åŒãç¶ãçŠç¹ãåœãŠããœãªã¥ãŒã·ã§ã³ïŒçŸåšåžå Žã§å ¥æå¯èœãªãœãªã¥ãŒã·ã§ã³ã®ã»ãšãã©ïŒã¯ãæŠç¥ãå€æŽããªããã°æ¶æ» ããéåœã«ãããŸãããã«ãŠã§ã¢ã䜿çšããªãæ»æã®æ°ã¯å¢ãç¶ããŠããŸãããããŠããã®çŸå®ã«çŽé¢ããŠãã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãšãã®ãŠãŒã¶ãŒã¯å®å šã«å€±ãããç¡é²åã§ãã
ãããŠãã¡ãããåœéçãªååãšãGDPRãªã©ã®åäžã®èŠå¶æ çµã¿ã®äœæãå¿ããããšã¯ã§ããŸãããé©åãªè¡åèšç»ãšåæ§ã«ãæ¿æ²»çããã³çµæžçæ¯æŽã®å©çšå¯èœæ§ã¯ãææ°ã®æè¡çé²æ©ã®å®å šãªäœ¿çšããå©çãåŸãã§ãããã
æåŸã«ãå šäœã®ãã€ã³ãã¯ãæ å ±ã»ãã¥ãªãã£ã®ååãæ¹èšããå¿ èŠããããšããããšã§ãã