
ã¯ããã«
ã¯ã¬ãžããã«ãŒãã®æŒæŽ©ãå人æ å ±ã®çé£ãã©ã³ãµã ãŠã§ã¢ïŒWannaCryãªã©ïŒãç¥ç財ç£ã®çé£ããã©ã€ãã·ãŒäŸµå®³ããµãŒãã¹æåŠ-ãããã®æ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã¯äžè¬çãªãã¥ãŒã¹ãšãªã£ãŠããŸãã 被害è ã®äžã«ã¯ãæ¿åºæ©é¢ã倧èŠæš¡ãªå°å£²ãã§ãŒã³ãéèæ©é¢ãããã«ã¯æ å ±ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã¡ãŒã«ãŒãªã©ãæ倧ãã€æãè£çŠã§æãä¿è·ãããäŒæ¥ããããŸãã
ãã®ãããªäŒæ¥ã¯ãæ°çŸäžãã«ã®äºç®ãæ å ±ã»ãã¥ãªãã£ã«å²ãåœãŠãŠããŸãããåŸæ¥ã®æ»æã«å¯ŸåŠããããšã¯ã§ããŸããã ãããã®æ»æã®å€ãã¯ãå®æçãªæŽæ°ãã»ãã¥ãªãã£ã§ä¿è·ãããæ§æã®äœ¿çšãªã©ãããç¥ãããŠããæ å ±ä¿è·æ¹æ³ã«ãã£ãŠé²ãããšãã§ããŸããã
ããã§ã¯ãä»ã®èª°ãäœããã¹ãã§ããããïŒ äºç®ãå°ãªãã¹ã¿ãããéãããŠããçµç¹ã¯ãå¢ãç¶ãããµã€ããŒç¯çœªã«ã©ã®ããã«å¯Ÿå¿ã§ããŸããïŒ ãã®ããã¥ã¡ã³ãã¯ãCISã³ã³ãããŒã«ã«åºã¥ããŠããžãã¹ãä¿è·ããããŒã«ãSMBææè ã«æäŸããããšãç®çãšããŠããŸãã CIS Controlsã¯ãæãäžè¬çãªè åšãšè匱æ§ã«å¯Ÿæããå®èšŒæžã¿ã®æ å ±ä¿è·æ¹æ³ã®å æ¬çãªã»ããã§ãã ãããã®æ å ±ä¿è·æ¹æ³ã¯ã察象åéã®å°é家ã«ãã£ãŠéçºãããŠããŸãã
SMBã«å¯Ÿããè åšã«ã¯æ¬¡ã®ãã®ããããŸãã
æ©å¯æ å ±ã®çé£ã¯ãå€éšã®äŸµå ¥è ãäžæºãæ±ããŠããåŸæ¥å¡ãäŒç€Ÿã«ãšã£ãŠéèŠãªæ å ±ãçãæ»æã®äžçš®ã§ãã
ãµã€ãé害ã¯ãWebãµã€ãã®ããŒãžãå¥ã®ããŒãžã«çœ®ãæããããã¿ã€ãã®æ»æã§ãããã»ãšãã©ã®å Žåãåºåãè åšããŸãã¯èŠåã¡ãã»ãŒãžãå«ãŸããŸãã
ãã£ãã·ã³ã°ã¯ãä¿¡é Œã§ãããœãŒã¹ããã¡ãã»ãŒãžãåœé ããããšã«ãããæ»æè ãéèŠãªæ å ±ïŒãã°ã€ã³ããã¹ã¯ãŒããã¯ã¬ãžããã«ãŒãæ å ±ãªã©ïŒãåä¿¡ããã¿ã€ãã®æ»æã§ãïŒããšãã°ãæªæã®ãããŠãŒã¶ãŒãç¹å®ããé»åã¡ãŒã«å ã®ãªã³ã¯ãã¯ãªãã¯ããããã«æ£åœãªããªãã¯ãšããŠæ§æãããé»åã¡ãŒã«ã³ã³ãã¥ãŒã¿ãœãããŠã§ã¢ïŒã
ã©ã³ãµã ãŠã§ã¢ã¯ãã³ã³ãã¥ãŒã¿ãŒäžã®ããŒã¿ãžã®ã¢ã¯ã»ã¹ããããã¯ãããã«ãŠã§ã¢ã®äžçš®ã§ãããã®çµæãç¯çœªè ã¯èº«ä»£éã匷èŠããŠããã¯ãããããŒã¿ã®ããã¯ã解é€ããŸãã
èªç¶çŸè±¡ãäºæ ã«ããããŒã¿ã®æ倱ã
ãã®ããã¥ã¡ã³ãã«ã¯ãSMBãä¿è·ããããã«ç¹å¥ã«éžæããããCISã³ã³ãããŒã«ã®æ å ±ã»ãã¥ãªãã£å¯Ÿçã®å°ããªã»ãããå«ãŸããŠããŸãã æ å ±ã»ãã¥ãªãã£ããŒã«ã¯çµ¶ããå€åããŠããããã ãµã€ãã§åŒç€Ÿã«é£çµ¡ããŠææ°æ å ±ãå ¥æã§ããŸãã
埩ç¿
ã»ãã¥ãªãã£ã¯ãITã€ã³ãã©ã¹ãã©ã¯ãã£ç®¡çãšå¯æ¥ã«é¢é£ããŠããŸããé©åã«ç®¡çããããããã¯ãŒã¯ã¯ãé©åã«ç®¡çãããŠããªããããã¯ãŒã¯ãããã¯ã©ããã³ã°ãå°é£ã§ãã çµç¹ãæ å ±ãã©ã®çšåºŠä¿è·ããŠããããç解ããã«ã¯ã次ã®è³ªåãèªåããŠãã ããã
- åŸæ¥å¡ãã³ã³ãã¥ãŒã¿ãŒã«æ¥ç¶ããŠãããã®ãç¥ã£ãŠããŸããïŒ ããŒã«ã«ãããã¯ãŒã¯å ã§ã©ã®ããã€ã¹ãæ¥ç¶ãããŠããŸããïŒ
- æ å ±ã·ã¹ãã ã§äœ¿çšãããŠãããœãããŠã§ã¢ãç¥ã£ãŠããŸããïŒ
- æ å ±ã»ãã¥ãªãã£èŠä»¶ãæºããããã«ã³ã³ãã¥ãŒã¿ãŒãæ§æããŸãããïŒ
- æ©å¯æ å ±ãžã®åŸæ¥å¡ã®ã¢ã¯ã»ã¹ã管çããŠããŸããããŸãã¯ã·ã¹ãã ã§ã¢ã¯ã»ã¹æš©ãé«ããããŠãã人ã管çããŠããŸããïŒ
- åŸæ¥å¡ã¯ãæ å ±ã»ãã¥ãªãã£ã®è åšããçµç¹ãä¿è·ãã圹å²ãç解ããŠããŸããïŒ
以äžã«ãããŸããŸãªç¡æãŸãã¯äœã³ã¹ãã®ããŒã«ãšããããã®è³ªåã«çããŠçµç¹ã®ã»ãã¥ãªãã£ã¬ãã«ãåäžãããã®ã«åœ¹ç«ã€æé ã瀺ããŸãã ãªã¹ããããŠããããŒã«ã¯ãã¹ãŠãç¶²çŸ ããŠããããã§ã¯ãããŸããããæ å ±ã»ãã¥ãªãã£ã®ã¬ãã«ãäžããããã«SMBã䜿çšã§ããå¹ åºãç¡æãŸãã¯äœã³ã¹ãã®ããŒã«ãåæ ããŠããŸãã
ãããã®æšå¥šäºé ã§ã¯ãæ å ±ã»ãã¥ãªãã£ã·ã¹ãã ãæ§ç¯ããããã«æ®µéçãªã¢ãããŒãã䜿çšããããšãæšå¥šããŠããŸãã
- ã¹ããŒãž1ã§ã¯ããããã¯ãŒã¯äžã«ãããã®ãç解ããæ å ±ã»ãã¥ãªãã£ã®åºæ¬èŠä»¶ãå®çŸ©ã§ããŸãã
- ã¹ããŒãž2ã¯ãåºæ¬çãªã»ãã¥ãªãã£èŠä»¶ã®æäŸãšãæ å ±ã»ãã¥ãªãã£ã®åŸæ¥å¡ã®ãã¬ãŒãã³ã°ã«éç¹ã眮ããŠããŸãã
- ã¹ããŒãž3ã¯ãçµç¹ãæ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«åããã®ã«åœ¹ç«ã¡ãŸãã
å段éã§ãåçãå¿ èŠãªè³ªåãšãç®æšã®éæã«åœ¹ç«ã€ã¢ã¯ã·ã§ã³ãšããŒã«ãæ瀺ãããŸãã
ã¹ããŒãž1.ã€ã³ãã©ã¹ãã©ã¯ãã£ãç¥ã

åœåãæ å ±ã»ãã¥ãªãã£ã®åé¡ãé²ããã«ã¯ãããŒã«ã«ãããã¯ãŒã¯ãæ¥ç¶ãããããã€ã¹ãéèŠãªããŒã¿ããã³ãœãããŠã§ã¢ã«å¯ŸåŠããå¿ èŠããããŸãã ä¿è·ããå¿ èŠããããã®ãæ確ã«ç解ããªããšã蚱容ã§ããã¬ãã«ã®æ å ±ã»ãã¥ãªãã£ã確å®ã«æäŸããããšãå°é£ã«ãªããŸãã
çæãã¹ãéèŠãªè³ªåïŒ
- ä¿è·ããå¿ èŠãããæ å ±ãç¥ã£ãŠããŸããïŒ ãããã¯ãŒã¯äžã®æãéèŠãªæ å ±ã¯ã©ãã«ä¿åãããŠããŸããïŒ
- ãããã¯ãŒã¯ã«æ¥ç¶ãããŠããããã€ã¹ãç¥ã£ãŠããŸããïŒ
- åŸæ¥å¡ã®ã³ã³ãã¥ãŒã¿ãŒã«ã€ã³ã¹ããŒã«ãããŠãããœãããŠã§ã¢ãç¥ã£ãŠããŸããïŒ
- ã·ã¹ãã 管çè ãšãŠãŒã¶ãŒã¯åŒ·åãªãã¹ã¯ãŒãã䜿çšããŠããŸããïŒ
- åŸæ¥å¡ã䜿çšããŠãããªã³ã©ã€ã³ãªãœãŒã¹ãç¥ã£ãŠããŸããïŒã€ãŸãããœãŒã·ã£ã«ãããã¯ãŒã¯ã§ä»äºãããã座ã£ããããŸãïŒïŒ
ä¿è·ããå¿ èŠãããæ å ±ã æãéèŠãªæ å ±ããããã¯ãŒã¯äžã«ä¿åãããŠããå Žæ
äŒç€Ÿã®éèŠãªããŒã¿ã倱ãããããçãŸããããç Žæããããããšãããžãã¹ã倱ãå¯èœæ§ããããŸãã å¶çºçãªåºæ¥äºãèªç¶çœå®³ããæ°žä¹ çãªæ害ãåŒãèµ·ããå¯èœæ§ããããŸãã ããã«ãæœåšçãªæ»æè ã¯ã䟡å€ã®ããããŒã¿ãæšçã«ããŸãã ãããã®ããã«ãŒã¯ã顧客ãéèæ å ±ããŸãã¯ç¥ç財ç£ãçãããšããããã«ãŒãŸãã¯äŒç€Ÿã®åŸæ¥å¡ã§ãã 貎éãªæ å ±ã䜿çšããã«ã¯ããã®æ å ±ã«ã¢ã¯ã»ã¹ããå¿ èŠããããååãšããŠçµç¹ã®ããŒã«ã«ãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ããå¿ èŠããããŸãã
ããžãã¹ãä¿è·ããã«ã¯ãããŒã¿ã®äŸ¡å€ãšãã®äœ¿çšæ¹æ³ãç解ããå¿ èŠããããŸãã ãŸããæ¯æãæ å ±ãå人ããŒã¿ãªã©ãæ³åŸã§ä¿è·ããå¿ èŠãããæ å ±ã決å®ããå¿ èŠããããŸãã 以äžã¯ãèå¥ããã³ã€ã³ãã³ããªããå¿ èŠãããããŒã¿ã®äŸã§ãã
- ã¯ã¬ãžããã«ãŒããéè¡ããã³è²¡åæ å ±ã
- å人ããŒã¿;
- 顧客ããŒã¿ããŒã¹ãè³Œå ¥/äŸçµŠäŸ¡æ Œ;
- äŒç€Ÿã®äŒæ¥ç§å¯ãå ¬åŒãæ¹æ³è«ãã¢ãã«ãç¥ç財ç£ã
æ å ±ã®ä¿è·ã®èŠä»¶ã決å®ããäž»èŠãªé£éŠæ³ãæ瀺ãããŠããŸãïŒSMBã«é©çšãããå ŽåããããŸãïŒ [翻蚳è ããïŒãã·ã¢ã®æ³åŸã«åŸã£ãŠææžãæ¿å ¥ãããŸã] ã
- 2006幎7æ27æ¥ã®é£éŠæ³N152-ãå人ããŒã¿ã«ã€ããŠãã
- 2011幎6æ27æ¥ã®é£éŠæ³N161-ãåœæ°æ¯æãã·ã¹ãã ã«ã€ããŠãã
- 2011幎11æ21æ¥ã®é£éŠæ³N323-ããã·ã¢é£éŠã®åžæ°ã®å¥åº·ãå®ãããã®åºç€ã«ã€ããŠãã
- 2010幎11æ29æ¥ã®é£éŠæ³N326-ïŒããã·ã¢é£éŠã®åŒ·å¶å¥åº·ä¿éºã«ã€ããŠã;
- 2006幎7æ27æ¥ã®é£éŠæ³N149-ãæ å ±ãæ å ±æè¡ãããã³æ å ±ä¿è·ãã
- 2004幎7æ29æ¥ã®é£éŠæ³N98-ãåæ¥ç§å¯ã«ã€ããŠãã
ãããã¯ãŒã¯ã«æ¥ç¶ãããŠããããã€ã¹
ãããã¯ãŒã¯ã«æ¥ç¶ãããŠããããã€ã¹ãããã£ãŠããå Žåãã€ã³ãã©ã¹ãã©ã¯ãã£ã®ç®¡çã容æã«ãªããä¿è·ããå¿ èŠãããããã€ã¹ãããããŸãã 以äžã¯ããããã¯ãŒã¯äžã®ããã€ã¹ã«ã€ããŠåŠã¶ããã«å®è¡ã§ããæé ã§ãã
ã¢ã¯ã·ã§ã³ïŒ
- ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ãããå Žåã¯ãã«ãŒã¿ãŒïŒã¯ã€ã€ã¬ã¹ã¢ã¯ã»ã¹ã³ã³ãããŒã©ãŒïŒã§ãæ¥ç¶ãããŠããããã€ã¹ãšã匷åãªæå·åïŒWPA2ïŒã䜿çšãããŠãããã©ããã確èªããŸãã
- 倧èŠæš¡ãªçµç¹ã§ã¯ããããã¯ãŒã¯ã¹ãã£ããŒïŒåçšãŸãã¯ç¡æïŒã䜿çšããŠããããã¯ãŒã¯äžã®ãã¹ãŠã®ããã€ã¹ãèå¥ããããšããå§ãããŸãã
- DHCPãä»ããŠIPã¢ãã¬ã¹ãåä¿¡ãããããã¯ãŒã¯ããã€ã¹ã®æ¥ç¶ã«é¢é£ããã€ãã³ãã®ãã°ãæå¹ã«ããŸãã ãã®ãããªã€ãã³ãã®ãã°ãèšé²ãããšããããã¯ãŒã¯äžã«ãã£ããã¹ãŠã®ããã€ã¹ãç°¡åã«è¿œè·¡ã§ããŸãã ïŒãµããŒããå¿ èŠãªå Žåã¯ãITæ åœè ã«ãåãåãããã ãããïŒ
- å°ããªçµç¹ã§ã¯ãæ©åšïŒã³ã³ãã¥ãŒã¿ãŒããµãŒããŒãã©ããããããããªã³ã¿ãŒãé»è©±ãªã©ïŒã®ãªã¹ããšãæ°ããæ©åšãŸãã¯ããŒã¿ã衚瀺ããããšãã«æŽæ°ããå¿ èŠãããã¹ãã¬ããã·ãŒãã®ä¿è·æ å ±ã®ãªã¹ããä¿æã§ããŸãã
ããŒã«ïŒ
- Nmap ïŒäžçäžã®ã·ã¹ãã 管çè ãããã«ãŒããããã¯ãŒã¯ã«æ¥ç¶ãããŠããããã€ã¹ãç¹å®ããããã«äœ¿çšãããããç¥ãããå€ç®çãããã¯ãŒã¯ã¹ãã£ããŒã
- ZenMap ïŒNmapã®äœ¿ããããGUI
- Spiceworks ïŒãããã¯ãŒã¯çšã®ç¡æã®ã€ã³ãã³ããªããã³ãªãœãŒã¹ç®¡çãœãããŠã§ã¢ïŒããã€ã¹ããã³ã€ã³ã¹ããŒã«æžã¿ãœãããŠã§ã¢ïŒ
åŸæ¥å¡ã®ã³ã³ãã¥ãŒã¿ãŒã«ã€ã³ã¹ããŒã«ãããŠãããœãããŠã§ã¢
ã€ã³ã¹ããŒã«ããããœãããŠã§ã¢ã®ç£èŠã¯ãåªããIT管çãšå¹æçãªæ å ±ã»ãã¥ãªãã£ã®äž¡æ¹ã®éèŠãªã³ã³ããŒãã³ãã§ãã ãããã¯ãŒã¯äžã®æªæã®ãããœãããŠã§ã¢ã¯ãªã¹ã¯ãæå°éã«æããå¿ èŠããããã©ã€ã»ã³ã¹ã®ãªããœãããŠã§ã¢ã䜿çšããå Žåã®æ³ç責任ãããã«èµ·å ããŸãã æŽæ°ãããŠããªããœãããŠã§ã¢ã¯ããã«ãŠã§ã¢ã®äŸµå ¥ã®äžè¬çãªåå ã§ãããæ å ±ã·ã¹ãã ãžã®æ»æã«ã€ãªãããŸãã ãããã¯ãŒã¯ã«ã€ã³ã¹ããŒã«ãããŠãããœãããŠã§ã¢ãç解ããã€ã³ã¹ããŒã«ãããŠãããœãããŠã§ã¢ãå¶åŸ¡ãã管çè æš©éã§ã¢ã«ãŠã³ããä¿è·ãããšãæ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®å¯èœæ§ãšåœ±é¿ã軜æžã§ããŸãã
ã¢ã¯ã·ã§ã³ïŒ
- çµç¹ã䜿çšããã¢ããªã±ãŒã·ã§ã³ãWebãµãŒãã¹ããŸãã¯ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³ã®ãªã¹ããäœæããŸãã
- 管çè ç¹æš©ãæã€ãŠãŒã¶ãŒã®æ°ãå¯èœãªéãæå°ã®å€ã«å¶éããŸãã äžè¬ãŠãŒã¶ãŒãã·ã¹ãã ã§ç®¡çè æš©éã§äœæ¥ããããšãèš±å¯ããªãã§ãã ããã
- 管çè ã¯ã·ã¹ãã ã«å€§ããªå€æŽãå ããããšãã§ããããã管çã¢ã«ãŠã³ãã«ã¯è€éãªãã¹ã¯ãŒãã䜿çšããŠãã ããã åŸæ¥å¡ãè€éãªãã¹ã¯ãŒããäœæããããã®æ瀺ãäœæããŸã[翻蚳è ããïŒè€éãªãã¹ã¯ãŒãã®äœæäŸã¯ãã¡ã ] ã
- ã·ã¹ãã 管çè ãå¥ã®ãŠãŒã¶ãŒã¢ã«ãŠã³ãã䜿çšããŠãé»åã¡ãŒã«ã®èªã¿åããã€ã³ã¿ãŒããããžã®ã¢ã¯ã»ã¹ãææžã®äœæãè¡ã£ãŠããããšã確èªããŠãã ããã
- ãããã¯ãŒã¯ã«ãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ããæé ãéçºããApplockerãªã©ã䜿çšããŠæªæ¿èªã®ã¢ããªã±ãŒã·ã§ã³ã®ã€ã³ã¹ããŒã«ãçŠæ¢ããŸãã
ããŒã«ïŒ
- Applocker ïŒå®è¡ãèš±å¯ãããŠãããœãããŠã§ã¢ãèå¥ããã³å¶éããããã®ç¡æã®Microsoft WindowsããŒã«
- Netwrix ïŒã·ã¹ãã äžã®ç®¡çã¢ã¯ã»ã¹æ å ±ãèå¥ããããã®å€ãã®ç¡æããŒã«
- OpenAudIT ïŒãµãŒããŒãã¯ãŒã¯ã¹ããŒã·ã§ã³ããããã¯ãŒã¯ããã€ã¹äžã®ãœãããŠã§ã¢ã€ã³ãã³ããª
ã¹ããŒãž2.è³ç£ãä¿è·ãã

åŸæ¥å¡ã¯æãéèŠãªè³ç£ã§ããããã®è¡šçŸã¯ããžãã¹ã ãã§ãªãæ å ±ã»ãã¥ãªãã£ã«ãåœãŠã¯ãŸããŸãã æ å ±ãä¿è·ããã«ã¯ãæè¡çãªãœãªã¥ãŒã·ã§ã³ã ãã§ãªããã·ã¹ãã ã®å¶çºçãªèª€åäœãé²ãããã®åŸæ¥å¡ã®æèãå¿ èŠã§ãã ãã®ãã§ãŒãºã®äžç°ãšããŠãã³ã³ãã¥ãŒã¿ãŒã®ä¿è·ã ãã§ãªããæ å ±ã»ãã¥ãªãã£ã®éèŠãªåŽé¢ã«é¢ããåŸæ¥å¡ã®ãã¬ãŒãã³ã°ã«ã€ããŠã説æããŸãã
ããªããçããå¿ èŠãããããã€ãã®è³ªåïŒ
- æ å ±ã»ãã¥ãªãã£èŠä»¶ãæºããããã«ã³ã³ãã¥ãŒã¿ãŒãæ§æããŸãããïŒ
- ãããã¯ãŒã¯ã«ã¯ãåžžã«æŽæ°ããããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ããããŸããïŒ
- åŸæ¥å¡ã«æ å ±ã»ãã¥ãªãã£ã®ææ°ã®æ¹æ³ã«ã€ããŠæããŠããŸããïŒ
åºæ¬çãªæ å ±ã»ãã¥ãªãã£èŠä»¶ãæ§æãã
æ å ±ã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ãåŸãããã«ãæªæã®ããããã°ã©ã ãæ»æè ã¯ãã»ãšãã©ã®å Žåãå®å šã§ãªãæ§æã®ã¢ããªã±ãŒã·ã§ã³ãŸãã¯è匱æ§ã®ããã¢ããªã±ãŒã·ã§ã³ã䜿çšããŸãã ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãšã¢ããªã±ãŒã·ã§ã³ïŒç¹ã«Webãã©ãŠã¶ãŒïŒãææ°ã§ãããé©åã«æ§æãããŠããããšã確èªããå¿ èŠããããŸãã ããã«ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«çµã¿èŸŒãããšãã§ãããã«ãŠã§ã¢å¯Ÿçã¡ã«ããºã ã䜿çšããããšããå§ãããŸãã ããšãã°ãWindows Device GuardãWindows Bitlockerãããã³ä»¥äžã§èª¬æããä»ã®ãŠãŒã¶ãŒã
ã¢ã¯ã·ã§ã³ïŒ
- Microsoft Security Analyzerã»ãã¥ãªãã£ã¹ãã£ããŒãå®æçã«å®è¡ããŠãWindowsãªãã¬ãŒãã£ã³ã°ã·ã¹ãã çšã«ã€ã³ã¹ããŒã«ãããŠããªãããã/æŽæ°ããã°ã©ã ãšãæ§æã®å€æŽãå¿ èŠãªãã®ãå€æããŸãã
- ãã©ãŠã¶ãšãã©ã°ã€ã³ãææ°ã§ããããšã確èªããŠãã ããã Google Chromeãªã©ã®ã³ã³ããŒãã³ããèªåçã«æŽæ°ãããã©ãŠã¶ã䜿çšããŠã¿ãŠãã ãã[翻蚳è ããïŒYandex.Browserã¯ãã·ã¢ã®é¡äŒŒåãããããŸãã] ã
- ãã«ãŠã§ã¢ããã·ã¹ãã ãä¿è·ããããã«ãææ°ã®ãŠã€ã«ã¹å¯ŸçããŒã¿ããŒã¹ã®æŽæ°ã§ãŠã€ã«ã¹å¯Ÿçã䜿çšããŸãã
- ãªã ãŒããã«ã¡ãã£ã¢ïŒUSBãCDãDVDïŒã®äœ¿çšããå ¬åãè¡ãããã«æ¬åœã«å¿ èŠãªåŸæ¥å¡ã«å¶éããŸãã
- Windowsã³ã³ãã¥ãŒã¿ãŒã«Enhanced Mitigation Experience Toolkit ïŒEMETïŒãã€ã³ã¹ããŒã«ããŠãã³ãŒãã®è匱æ§ããä¿è·ããŸã
- ç¹ã«å éšãããã¯ãŒã¯ãŸãã¯é»åã¡ãŒã«ãžã®ãªã¢ãŒãã¢ã¯ã»ã¹ã®å Žåã¯ãå¯èœã§ããã°å€èŠçŽ èªèšŒãå¿ èŠã§ãã ããšãã°ããã¹ã¯ãŒãã«å ããŠè¿œå ã®ã»ãã¥ãªãã£ã¬ãã«ãšããŠã³ãŒãä»ãã®ã»ãã¥ã¢ããŒã¯ã³/ã¹ããŒãã«ãŒããŸãã¯SMSã¡ãã»ãŒãžã䜿çšããŸãã
- ãããã¯ãŒã¯ã«è¿œå ãããšãã«ããã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãã«ãŒã¿ãŒããã¡ã€ã¢ãŠã©ãŒã«ãã¯ã€ã€ã¬ã¹ã¢ã¯ã»ã¹ãã€ã³ããããªã³ã¿ãŒ/ã¹ãã£ããŒãããã³ãã®ä»ã®ããã€ã¹ã®ããã©ã«ããã¹ã¯ãŒããå€æŽããŸãã
- æå·åã䜿çšããŠããã€ã¹ããªã¢ãŒãã§å®å šã«ç®¡çããæ©å¯æ å ±ãéä¿¡ããŸãã
- æ©å¯æ å ±ãå«ãã©ããããããŸãã¯ã¢ãã€ã«ããã€ã¹ã®ããŒããã©ã€ããæå·åããŸãã
ããŒã«ïŒ
- Bitlocker ïŒMicrosoft Windowsããã€ã¹ã®çµ±åæå·å
- FireVault ïŒMacããã€ã¹åãã®çµ±åæå·å
- Qualys Browser Check ïŒææ°ã®æŽæ°ããã©ãŠã¶ã§ç¢ºèªããããŒã«
- OpenVAS ïŒã·ã¹ãã ãåºæ¬çãªæ å ±ã»ãã¥ãªãã£èŠä»¶ã«æºæ ããŠãããã©ããã確èªããããã®ããŒã«
- Microsoft Baseline Security Analyzer ïŒWindowsã³ã³ãã¥ãŒã¿ãŒãå®å šã«æ§æããæ¹æ³ãç解ããããã®ç¡æã®MicrosoftããŒã«
- CISãã³ãããŒã¯ ïŒ100ãè¶ ãããã¯ãããžã®æ å ±ã»ãã¥ãªãã£æ§æãæäŸããç¡æã®PDFãã¡ã€ã«ã
ISããã»ã¹éçº
æ å ±ã»ãã¥ãªãã£ã¯ããã¯ãããžãŒã ãã§ãªããããã»ã¹ãšäººã«é¢ãã話ã§ããããŸãã æ å ±ã»ãã¥ãªãã£ããŒã«ã ãã§ã¯äžååã§ãã çµç¹ã®ã»ãã¥ãªãã£ã確ä¿ããã«ã¯ãåŸæ¥å¡ãæ å ±ã»ãã¥ãªãã£èŠä»¶ãå³å¯ã«éµå®ããå¿ èŠããããŸãã åŸæ¥å¡ã«æ å ±ã»ãã¥ãªãã£ã®åé¡ãæããã«ã¯ã2ã€ã®éèŠãªèŠçŽ ããããŸããæ å ±ãåŸæ¥å¡ã«äŒããããšãåžžã«ç¥èã¬ãã«ãç¶æããããšã§ãã
åŸæ¥å¡ã«äŒããããæ å ±ïŒ
- çµç¹å ã®æ©å¯æ å ±ã«ã¢ã¯ã»ã¹ãããåŠçãããããåŸæ¥å¡ãç¹å®ãããã®æ å ±ãä¿è·ãã圹å²ãç解ããŠãã ããã
- æãäžè¬çãª2ã€ã®æ»æã¯ãé»åã¡ãŒã«ãšé»è©±ã®ãã£ãã·ã³ã°æ»æã§ãã ã¹ã¿ãããæ»æã®äž»ãªå åã説æããã³ç¹å®ã§ããããšã確èªããŠãã ããã ãã®ãããªå åã«ã¯ã人ã ãéåžžã«ç·æ¥æ§ã®é«ãããšã話ãããã貎éãªæ å ±ãæ©å¯æ å ±ãæ±ãããããããŸããªçšèªãæè¡çšèªã䜿çšããããã»ãã¥ãªãã£æé ãç¡èŠããããã€ãã¹ãããããããã«æ±ããç¶æ³ãå«ãŸããŸã
- åŸæ¥å¡ã¯ãåžžèãæåã®é²åŸ¡ã§ããããšãç解ããå¿ èŠããããŸãã äœãèµ·ãã£ãŠããããå¥åŠãçãããããŸãã¯ããŸãã«ãè¯ããšæãããå Žåããããã¯æ»æã®å åã§ããå¯èœæ§ãæãé«ãã§ãã
- å¯èœã§ããã°ãåã¢ã«ãŠã³ãã«è€éã§ãŠããŒã¯ãªãã¹ã¯ãŒãã®äœ¿çšããã³/ãŸãã¯äºèŠçŽ èªèšŒã奚å±ããŸãã
- ååãã¢ãã€ã«ããã€ã¹ã§ãç»é¢ããã¯ãã䜿çšããããšã奚å±ããŸãã
- ãã¹ãŠã®åŸæ¥å¡ãããã€ã¹ãšãœãããŠã§ã¢ãåžžã«æŽæ°ããŠããããšã確èªããŠãã ããã
ãµããŒãç¥èã¬ãã«ïŒ
- çµç¹ãä¿è·ããæ¹æ³ãšããããã®æ¹æ³ãå人ã®ç掻ã«ã©ã®ããã«é©çšã§ããããåŸæ¥å¡ã«èª¬æãããããç解ããŠããããšã確èªããŠãã ããã
- æ å ±ã»ãã¥ãªãã£ãä»äºã®éèŠãªéšåã§ããããšããã¹ãŠã®åŸæ¥å¡ãç解ããŠããããšã確èªããŠãã ããã
- SANS OUCHãã¥ãŒã¹ã¬ã¿ãŒãªã©ã®ç¡æã®æ å ±ã»ãã¥ãªãã£è³æãåŸæ¥å¡ã«é åžããŠãã ããïŒ ããã³MS-ISACæåãã¥ãŒã¹ã¬ã¿ãŒã
- National Cyberââsecurity Allianceã®StaySafeOnline.orgãªã©ã®ãªã³ã©ã€ã³ãªãœãŒã¹ã䜿çšããŸãã
ããŒã«ïŒ
- ãµã³ãºçãïŒ ãã¥ãŒã¹ã¬ã¿ãŒ ãä»æã®ãããªãæ¯æ¥ã®ãã³ããšãã¹ã¿ãŒã
- MS-ISACæåãã¥ãŒã¹ã¬ã¿ãŒ
- Staysafeonline.com ;
- Safe-surf.ru [翻蚳è ããïŒãã·ã¢èªç] ;
ã¹ããŒãž3ïŒçµç¹ãæºåãã

çµç¹ãæ å ±ã»ãã¥ãªãã£ã®åŒ·åºãªåºç€ãéçºããããã€ã³ã·ãã³ã察å¿ã¡ã«ããºã ãæ§ç¯ããå¿ èŠããããŸãã ãã®ã¢ãããŒãã«ã¯ãæ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ããžã®å¯ŸåŠæ¹æ³ãšããã®åŸã®äŒç€Ÿã®åŸ©æ§æ¹æ³ã®ç解ãå«ãŸããŸãã
äž»ãªåé¡ïŒ
- 貎éãªãã¡ã€ã«ãæåŸã«ããã¯ã¢ããããã®ã¯ãã€ã§ããïŒ
- ããã¯ã¢ãããå®æçã«ãã§ãã¯ããŠããŸããïŒ
- ã€ã³ã·ãã³ããçºçããå Žåãã©ã®ååã«é£çµ¡ããã¹ããç¥ã£ãŠããŸããïŒ
ããã¯ã¢ãã管ç
ããã¯ã¢ããã®äœæãšç®¡çã¯æ¥åžžçãªäœæ¥ã§ãããããŸãèå³æ·±ãäœæ¥ã§ã¯ãããŸããããããã¯ããŒã¿ãä¿è·ããé害ããå埩ããããžãã¹ãæ£åžžã«æ»ãããã®æè¯ã®æ¹æ³ã®1ã€ã§ãã ã©ã³ãµã ãŠã§ã¢ã¯ãã¹ãŠã®ããŒã¿ãæå·åãã身代éãŸã§ãããã¯ããããšãã§ãããããããã¯éèŠã§ãã çŸåšããã³ç¶æãããŠããããã¯ã¢ããã«ãã£ãŠè£å®ãããå ç¢ãªå¯Ÿå¿èšç»ã¯ãæ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«å¯ŸåŠããéã®æåã®é²åŸ¡çã§ãã
ã¢ã¯ã·ã§ã³ïŒ
- éèŠãªæ å ±ãå«ããã¹ãŠã®ã³ã³ãã¥ãŒã¿ãŒã®æ¯é±ã®ããã¯ã¢ãããèªåçã«å®è¡ããŸãã
- ããã¯ã¢ãããå®æçã«ç¢ºèªããããã¯ã¢ããã䜿çšããŠã·ã¹ãã ã埩å ããŸãã
- å°ãªããšã1ã€ã®ããã¯ã¢ããããããã¯ãŒã¯äžã§å©çšã§ããªãããšã確èªããŠãã ããã ããã¯ããã®ããã¯ã¢ããããã«ãŠã§ã¢ã«ã¢ã¯ã»ã¹ã§ããªããããã©ã³ãµã ãŠã§ã¢æ»æããä¿è·ããã®ã«åœ¹ç«ã¡ãŸãã
ããŒã«ïŒ
- Microsoftããã¯ã¢ãããšåŸ©å ïŒMicrosoftãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«çµã¿èŸŒãŸããããã¯ã¢ãããŠãŒãã£ãªãã£
- Apple Time Machine ïŒAppleãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«ã€ã³ã¹ããŒã«ãããããã¯ã¢ããããŒã«
- Amanda Network Baââckup ïŒç¡æã®ãªãŒãã³ãœãŒã¹ããã¯ã¢ããããŒã«
- Bacula ïŒãªãŒãã³ãœãŒã¹ã®ãããã¯ãŒã¯ããã¯ã¢ããããã³ãªã«ããªãœãªã¥ãŒã·ã§ã³
ã€ã³ã·ãã³ãã®æºå
æ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®çºçã誰ãæãã§ããŸããããæºåãäžå šã§ããã°ããã»ã©ãã€ã³ã·ãã³ãããè¿ éã«åŸ©æ§ã§ããŸãã æ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«ã¯ããµã€ããžã®ã¢ã¯ã»ã¹ã«éåãããµãŒãã¹æåŠæ»æãã·ã¹ãã ãŸãã¯ããŒã¿ããããã¯ããã©ã³ãµã ãŠã§ã¢ã«ããæ»æãã¯ã©ã€ã¢ã³ããŸãã¯åŸæ¥å¡ããã®ããŒã¿ã®æ倱ã«ã€ãªããæªæã®ãããœãããŠã§ã¢ã«ããæ»æãããã³æå·åãããŠããªãããŒã¿ãå«ãã©ããããããçã¿ãŸãã
æºåããã«ã¯ãã€ã³ã·ãã³ãã®å Žåã«èª°ã«é£çµ¡ããããç¥ãå¿ èŠããããŸãã 瀟å ã®ITã¹ã¿ããã«å©ããæ±ãããããµãŒãããŒãã£ã®ã€ã³ã·ãã³ã管çäŒç€Ÿã«é Œãããšãã§ããŸãã ãããã«ãããã€ãã³ããçºçããåã«ã€ã³ã·ãã³ãã管çãã責任è ã®åœ¹å²ãç¥ã£ãŠããå¿ èŠããããŸãã
ã¢ã¯ã·ã§ã³ïŒ
- ã€ã³ã·ãã³ããçºçããå Žåã«ææ決å®ãè¡ããã¬ã€ãã³ã¹ãæäŸããçµç¹ã®åŸæ¥å¡ãç¹å®ããŸãã
- ITã¹ã¿ããããµãŒãããŒãã£ã«é£çµ¡å æ å ±ãæäŸããŸãã
- æ å ±ã®å ±æãšæ å ±ã»ãã¥ãªãã£ã®ä¿é²ã«éç¹ã眮ãåäŒã«åå ããŸãã
- èšç»ã®äžéšãšããŠå€éšé£çµ¡å ã®ãªã¹ããä¿æããŸãã ãããã«ã¯ãæ³åŸé¡§åãä¿éºä»£çåºãæ å ±ã»ãã¥ãªãã£ãªã¹ã¯ã«ä¿éºããããŠããå Žåãã»ãã¥ãªãã£ã³ã³ãµã«ã¿ã³ããå«ãŸããŸãã
- ããªãã®åœã®æ å ±ã»ãã¥ãªãã£äŸµå®³ã«é¢é£ããæ³åŸãèªãã§ãã ããã
ã€ã³ã·ãã³ããçºçããå Žåã®å¯ŸåŠïŒ
- ã€ã³ã·ãã³ãã®æ§è³ªãšç¯å²ãæ確ã§ãªãå Žåã¯ãæ å ±ã»ãã¥ãªãã£ã³ã³ãµã«ã¿ã³ãã«é£çµ¡ããããšãæ€èšããŠãã ããã
- äºä»¶ã§ç¬¬äžè ã®æ©å¯æ å ±ã䟵害ãããããšãå€æããå Žåã¯ãåŒè·å£«ã«é£çµ¡ããããšãæ€èšããŠãã ããã
- éåã®çµæãšããŠæ å ±ãé瀺ãããã圱é¿ãåãããã¹ãŠã®å人ã«éç¥ããæºåãããŸãã
- å¿ èŠã«å¿ããŠæ³å·è¡æ©é¢ã«éç¥ããŸãã