
å°éçãªæŽ»åã®äžç°ãšããŠãéçºè ããã³ãã¹ã¿ãŒãããã³ã»ãã¥ãªãã£ã®å°é家ã¯ãVulnerability ManagementïŒVMïŒãïŒSecureïŒSDLCãªã©ã®ããã»ã¹ã«å¯ŸåŠããå¿ èŠããããŸãã
ãããã®ãã¬ãŒãºã®äžã«ã¯ãæ¶è²»è ã¯ç°ãªããŸããã䜿çšãããããŸããŸãªãã©ã¯ãã£ã¹ãšããŒã«ã絡ã¿åã£ãŠããŸãã
æè¡ã®é²æ©ã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ãšãœãããŠã§ã¢ã®ã»ãã¥ãªãã£ãåæããããã®1ã€ã®ããŒã«ã«äººã眮ãæãããšããç¹ã«ã¯ãŸã éããŠããŸããã
ããããªããããªã®ãããããŠããªããçŽé¢ããªããã°ãªããªãåé¡ãç解ããããšã¯èå³æ·±ãã§ãã
ããã»ã¹
è匱æ§ç®¡çããã»ã¹ã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã»ãã¥ãªãã£ãšããã管çã®ç¶ç¶çãªç£èŠãç®çãšããŠããŸãã
Secure SDLCããã»ã¹ïŒãå®å šãªéçºãµã€ã¯ã«ãïŒã¯ãéçºããã³éçšäžã®ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ããµããŒãããããã«èšèšãããŠããŸãã
ãããã®ããã»ã¹ã®é¡äŒŒããéšåã¯ãè匱æ§è©äŸ¡ããã»ã¹ã§ã-è匱æ§è©äŸ¡ãè匱æ§ã¹ãã£ã³ã
VMãšSDLCã®ãã¬ãŒã ã¯ãŒã¯å ã§ã®ã¹ãã£ã³ã®äž»ãªéãã¯ãæåã®ã±ãŒã¹ã®ç®æšã¯ããµãŒãããŒãã£ãœãããŠã§ã¢ãŸãã¯æ§æã®æ¢ç¥ã®è匱æ§ãæ€åºããããšã§ãã ããšãã°ãå€ãããŒãžã§ã³ã®WindowsãŸãã¯SNMPã®ããã©ã«ãã®ã³ãã¥ããã£ã¹ããªã³ã°ã
2çªç®ã®ã±ãŒã¹ã®ç®æšã¯ããµãŒãããŒãã£ã®ã³ã³ããŒãã³ãïŒäŸåé¢ä¿ïŒã ãã§ãªããäž»ã«æ°è£œåã®ã³ãŒãã®è匱æ§ãæ€åºããããšã§ãã
ããã«ãããããŒã«ãšã¢ãããŒãã«éããçããŸãã ç§ã®æèŠã§ã¯ãã¢ããªã±ãŒã·ã§ã³ã®æ°ããè匱æ§ãèŠã€ããã¿ã¹ã¯ã¯ããã£ã³ã¬ãŒããªã³ãããŒãžã§ã³ããããŒã®åéããã¹ã¯ãŒãã®ãœãŒããªã©ã«èŠçŽãããªããããã¯ããã«èå³æ·±ãã§ãã
ã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ã®é«å質ã®èªåã¹ãã£ã³ã«ã¯ãã¢ããªã±ãŒã·ã§ã³ã®ã»ãã³ãã£ã¯ã¹ããã®ç®çãç¹å®ã®è åšãèæ ®ããã¢ã«ãŽãªãºã ãå¿ èŠã§ãã
avleonovãè¿°ã¹ãããã«ãã€ã³ãã©ã¹ãã©ã¯ãã£ã¹ãã£ããŒã¯å€ãã®å Žåãã¿ã€ããŒã«çœ®ãæããããšãã§ããŸãã ãã€ã³ãã¯ãçŽç²ã«çµ±èšçã«ãããšãã°1ãæéæŽæ°ããªãã£ãå Žåãã€ã³ãã©ã¹ãã©ã¯ãã£ãè匱ã§ãããšèããããšãã§ãããšããããšã§ãã
ããŒã«
ã¹ãã£ã³ããã³ã»ãã¥ãªãã£åæã¯ããã©ãã¯ããã¯ã¹ãŸãã¯ãã¯ã€ãããã¯ã¹ãšããŠå®è¡ã§ããŸãã
ãã©ãã¯ããã¯ã¹
ãã©ãã¯ããã¯ã¹ã¹ãã£ã³ã®å ŽåãããŒã«ã¯ããŠãŒã¶ãŒãæäœããã®ãšåãã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠãµãŒãã¹ãæäœã§ããå¿ èŠããããŸãã
ã€ã³ãã©ã¹ãã©ã¯ãã£ã¹ãã£ããŒïŒTenable NessusãQualysãMaxPatrolãRapid7 Nexposeãªã©ïŒã¯ãéããŠãããããã¯ãŒã¯ããŒããæ¢ããããããŒããåéããã€ã³ã¹ããŒã«ãããŠãããœãããŠã§ã¢ããŒãžã§ã³ã決å®ããç¥èããŒã¹ã§ãããã®ããŒãžã§ã³ã®è匱æ§ã«é¢ããæ å ±ãæ¢ããŸãã ãŸããããã©ã«ãã®ãã¹ã¯ãŒãããªãŒãã³ããŒã¿ã¢ã¯ã»ã¹ã匱ãSSLæå·ãªã©ã®æ§æãšã©ãŒãæ€åºããããšããŸãã
Webã¢ããªã±ãŒã·ã§ã³ã¹ãã£ããŒïŒAcunetix WVSãNetsparkerãBurp SuiteãOWASP ZAPãªã©ïŒããæ¢ç¥ã®ã³ã³ããŒãã³ããšãã®ããŒãžã§ã³ïŒCMSããã¬ãŒã ã¯ãŒã¯ãJSã©ã€ãã©ãªãªã©ïŒãå€å¥ããæ¹æ³ãç¥ã£ãŠããŸãã ã¹ãã£ããŒã®äž»ãªæé ã¯ãã¯ããŒã«ãšãã¡ãžã³ã°ã§ãã
ã¯ããŒã«äžã«ãã¹ãã£ããŒã¯æ¢åã®ã¢ããªã±ãŒã·ã§ã³ã€ã³ã¿ãŒãã§ã€ã¹ãHTTPãã©ã¡ãŒã¿ãŒã«é¢ããæ å ±ãåéããŸãã ãã¡ãžã³ã°äžã«ããšã©ãŒãåŒãèµ·ãããŠè匱æ§ãæ€åºããããã«ãæ€åºããããã¹ãŠã®ãã©ã¡ãŒã¿ãŒãå€ç°ãŸãã¯çæãããããŒã¿ã«çœ®ãæããããŸãã
ãã®ãããªã¢ããªã±ãŒã·ã§ã³ã¹ãã£ããŒã¯ãããããDASTã¯ã©ã¹ãšIASTã¯ã©ã¹ïŒåçããã³å¯Ÿè©±åã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãã¹ãïŒã«å±ããŸãã
ãã¯ã€ãããã¯ã¹
ãã¯ã€ãããã¯ã¹ã¹ãã£ã³ã«ã¯ããã«éãããããŸãã
ããã»ã¹å šäœãéããŠãVMã¹ãã£ããŒïŒVulnersãIncsecurity CouchãVulsãTenable Nessusãªã©ïŒã¯ãèªèšŒã¹ãã£ã³ãå®è¡ããããšã«ãããã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ãèš±å¯ãããããšããããããŸãã ãããã£ãŠãã¹ãã£ããŒã¯ããããã¯ãŒã¯ãµãŒãã¹ã®ãããŒã§æšæž¬ããããšãªããã€ã³ã¹ããŒã«ãããããŒãžã§ã³ã®ããã±ãŒãžãšæ§æãã©ã¡ãŒã¿ãŒãã·ã¹ãã ããçŽæ¥ããŠã³ããŒãã§ããŸãã
ã¹ãã£ã³ã¯ããæ£ç¢ºã§å®å šã§ãã
ã¢ããªã±ãŒã·ã§ã³ã®ãã¯ã€ãããã¯ã¹ã¹ãã£ã³ïŒCheckMarxãHP FortifyãCoverityãRIPSãFindSecBugsãªã©ïŒã«ã€ããŠè©±ãå Žåãéåžžãéçã³ãŒãåæãšãSASTã¯ã©ã¹ã®å¯Ÿå¿ããããŒã«ã®äœ¿çš-éçã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãã¹ãã«ã€ããŠè©±ããŸãã
åé¡
ã¹ãã£ã³ã«ã¯å€ãã®åé¡ããããŸãïŒ ã»ãã¥ãªãã£åæäœæ¥ãè¡ããšãã ãã§ãªããã¹ãã£ã³ããã»ã¹ã®æ§ç¯ãšå®å šãªéçºã®ããã®ãµãŒãã¹ãæäŸãããã¬ãŒã ã¯ãŒã¯ã§ããããã®ã»ãšãã©ã«å人çã«å¯ŸåŠããå¿ èŠããããŸãã
ããŸããŸãªäŒæ¥ã®æ å ±ã»ãã¥ãªãã£ãµãŒãã¹ã®ãšã³ãžãã¢ããããŒãžã£ãŒãšã®äŒè©±ã«ãã£ãŠç¢ºèªããã3ã€ã®äž»èŠãªåé¡ã°ã«ãŒããéžã³åºããŸãã
Webã¢ããªã±ãŒã·ã§ã³ã¹ãã£ã³ã®åé¡
- å®è£ ã®è€éãã ã¹ãã£ããŒã¯ãã¢ããªã±ãŒã·ã§ã³ããšã«å±éãæ§æãã«ã¹ã¿ãã€ãºããã¹ãã£ã³çšã®ãã¹ãç°å¢ãå²ãåœãŠãCI / CDããã»ã¹ã«å®è£ ããŠæå¹ã«ããå¿ èŠããããŸãã ãããªããã°ãããã¯åœ¹ã«ç«ããªãæ£åŒãªæé ã«ãªããåœéœæ§ã®ã¿ãåºããŸã
- ã¹ãã£ã³æéã ã¹ãã£ããŒã¯ã2019幎ã§ãã£ãŠããã€ã³ã¿ãŒãã§ã€ã¹ã®éè€æé€ãäžååã§ãããããããç°ãªã10ã®ãã©ã¡ãŒã¿ãŒã䜿çšããŠ10æ¥éãæ°åããŒãžãã¹ãã£ã³ã§ããŸãããåãã³ãŒããåå ã§ãã åæã«ãéçºãµã€ã¯ã«å ã§éçšç°å¢ã«å±éãã決å®ãè¿ éã«è¡ãå¿ èŠããããŸã
- äžååãªæšå¥šäºé ã ã¹ãã£ããŒã¯ããªãäžè¬çãªæšå¥šäºé ãæäŸããŸãããéçºè ã¯åžžã«ãªã¹ã¯ã¬ãã«ãæžããæ¹æ³ãæãç°¡åã«ç解ã§ããããã§ã¯ãããŸãããæãéèŠãªããšã¯ãä»ããè¡ãå¿ èŠãããã®ãââãæãããªãã®ã
- ã¢ããªã±ãŒã·ã§ã³ãžã®ç Žå£çãªåœ±é¿ã ã¹ãã£ããŒã¯ãã¢ããªã±ãŒã·ã§ã³ã«å¯ŸããŠDoSæ»æãå®è¡ããå¯èœæ§ããããŸãããŸããå€æ°ã®ãšã³ãã£ãã£ãäœæããããæ¢åã®ãšã³ãã£ãã£ãå€æŽãããããããšãã§ããŸãïŒããšãã°ãããã°ã«äœäžãã®ã³ã¡ã³ããäœæããŸãïŒã
- äœå質ã®è匱æ§æ€åºã ã¹ãã£ããŒã¯éåžžãåºå®ãã€ããŒãé åã䜿çšããæ¢ç¥ã®ã¢ããªã±ãŒã·ã§ã³åäœã·ããªãªã«é©åããªãè匱æ§ãç°¡åã«èŠèœãšãå¯èœæ§ããããŸãã
- ã¹ãã£ããŒã¯ãã¢ããªã±ãŒã·ã§ã³ã®æ©èœãç解ããŠããŸããã ã¹ãã£ããŒèªäœã¯ããã€ã³ã¿ãŒããããã³ãã³ã°ãããæ¯æãããããã³ãã³ã¡ã³ãããäœã§ããããç¥ããŸããã 圌ãã«ãšã£ãŠã¯ããªã³ã¯ãšãã©ã¡ãŒã¿ãŒã®ã¿ãååšãããããããžãã¹ããžãã¯ã®æœåšçãªè匱æ§ã®å·šå€§ãªå±€ãå®å šã«çºèŠããããŸãŸã§ãããIDã§ä»ã®äººã®ããŒã¿ãäºéã«æžããããèŠãèŠããããäžžãã«ãã£ãŠãã©ã³ã¹ããšã£ããããããšã¯ãããŸãã
- ããŒãžã®ã»ãã³ãã£ã¯ã¹ã«å¯Ÿããã¹ãã£ããŒã®èª€è§£ã ã¹ãã£ããŒã¯FAQã®èªã¿æ¹ãããããããã£ããã£ãèªèããæ¹æ³ããããããç»é²æ¹æ³ãæšæž¬ããããšãããã°ã€ã³ããå¿ èŠããããŸãããããã°ã¢ãŠãããã¯ãªãã¯ã§ããªãããšããã©ã¡ãŒã¿ãŒå€ãå€æŽããéã«ãªã¯ãšã¹ãã«çœ²åããæ¹æ³ããããŸãã ãã®çµæãã»ãšãã©ã®ã¢ããªã±ãŒã·ã§ã³ããŸã£ããã¹ãã£ã³ãããªãå ŽåããããŸãã
ãœãŒã¹ã³ãŒãã¹ãã£ã³ã®åé¡
- 誀æ€ç¥ã éç解æã¯ãå€ãã®åŠ¥åã«é Œãå¿ èŠããã解決ã«ãããŠå°é£ãªã¿ã¹ã¯ã§ãã å€ãã®å Žåã粟床ãç ç²ã«ããå¿ èŠããããé«äŸ¡ãªãšã³ã¿ãŒãã©ã€ãºã¹ãã£ããŒã§ããã倧éã®èª€æ€ç¥ãçºçããŸãã
- å®è£ ã®è€éãã éçåæã®ç²ŸåºŠãšå®å šæ§ãé«ããã«ã¯ãã¹ãã£ã³ã«ãŒã«ãæ¹è¯ããå¿ èŠãããããããã®ã«ãŒã«ã®äœæã«ã¯æéãããããããå ŽåããããŸãã ãã®ãããªã±ãŒã¹ãæ€åºããããã®ã«ãŒã«ãèšè¿°ããããããã³ãŒãå ã®ããçš®ã®ãã°ãèŠã€ããŠä¿®æ£ããæ¹ãç°¡åãªå ŽåããããŸã
- äŸåé¢ä¿ã®ãµããŒãã®æ¬ åŠã 倧èŠæš¡ãªãããžã§ã¯ãã¯ãããã°ã©ãã³ã°èšèªã®æ©èœãæ¡åŒµããå€æ°ã®ã©ã€ãã©ãªãšãã¬ãŒã ã¯ãŒã¯ã«äŸåããŠããŸãã ã¹ãã£ããŒã®ãã¬ããžããŒã¹ã«ãããã®ãã¬ãŒã ã¯ãŒã¯ã®ãã·ã³ã¯ãã«é¢ããæ å ±ããªãå Žåãããã¯ç²ç¹ã«ãªããã¹ãã£ããŒã¯ã³ãŒããç解ããããšããã§ããªããªããŸãã
- ã¹ãã£ã³æéã ã³ãŒãå ã®è匱æ§ãèŠã€ããããšã¯ãã¢ã«ãŽãªãºã ã®èŠ³ç¹ããé£ããäœæ¥ã§ãã ãã®ãããããã»ã¹ãé ããããšããããããªãã®ã³ã³ãã¥ãŒãã£ã³ã°ãªãœãŒã¹ãå¿ èŠã«ãªããŸãã
- äœã«ãã¬ããžã ãªãœãŒã¹ã®æ¶è²»ãšã¹ãã£ã³ã®æéã«ãããããããSASTããŒã«ã®éçºè ã¯äŸç¶ãšããŠåŠ¥åã«é Œããªããã°ãªãããããã°ã©ã ãååšããå¯èœæ§ã®ãããã¹ãŠã®æ¡ä»¶ãåæããå¿ èŠã¯ãããŸããã
- æ€çŽ¢çµæã®åçŸæ§ã è匱æ§ã«ã€ãªããç¹å®ã®åç·ãšåŒã³åºãã¹ã¿ãã¯ãæãããšã¯åé¡ãããŸããããå®éã«ã¯ãã¹ãã£ããŒã¯å€éšã®è匱æ§ããã§ãã¯ããã®ã«ååãªæ å ±ãæäŸããªãããšããããããŸãã çµå±ã®ãšãããæ¬ é¥ã¯ãããã³ãŒãã«ããå¯èœæ§ããããããã¯æ»æè ã«ãšã£ãŠã¯éæäžå¯èœã§ã
ã€ã³ãã©ã¹ãã©ã¯ãã£ã¹ãã£ã³ã®åé¡
- åšåº«äžè¶³ã ç¹ã«å°ççã«é¢ãã倧èŠæš¡ãªã€ã³ãã©ã¹ãã©ã¯ãã£ã§ã¯ãå€ãã®å Žåãã©ã®ãã¹ããã¹ãã£ã³ããå¿ èŠãããããç解ããã®ãæãå°é£ã§ãã ã€ãŸããã¹ãã£ã³ã¿ã¹ã¯ã¯è³ç£ç®¡çã¿ã¹ã¯ãšå¯æ¥ã«é¢é£ããŠããŸã
- åªå 床ãäœãã ãããã¯ãŒã¯ã¹ãã£ããŒã¯å€ãã®å Žåãå®éã«ã¯æªçšã§ããªãæ¬ ç¹ã䌎ãå€ãã®çµæããããããŸãããæ£åŒã«ã¯ãªã¹ã¯ã¬ãã«ã¯é«ããªããŸãã æ¶è²»è ã¯è§£éãå°é£ãªã¬ããŒããåãåããŸãããäœãæåã«ä¿®æ£ããå¿ èŠããããã¯æ確ã§ã¯ãããŸãã
- äžååãªæšå¥šäºé ã å€ãã®å Žåãã¹ãã£ããŒã®ãã¬ããžããŒã¹ã«ã¯è匱æ§ãšãã®ä¿®æ£æ¹æ³ã«é¢ããéåžžã«äžè¬çãªæ å ±ããå«ãŸããŠããªãããã管çè ã¯Googleã§æŠè£ ããå¿ èŠããããŸãã ä¿®æ£ããç¹å®ã®ã³ãã³ããçºè¡ã§ãããã¯ã€ãããã¯ã¹ã¹ãã£ããŒã®å Žåãç¶æ³ã¯å°ãè¯ããªããŸãã
- æä»äº ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ã¯å€ãã®ããŒããååšããå¯èœæ§ããããŸããã€ãŸããæœåšçã«å€ãã®æ¬ ç¹ããããã¬ããŒããåå埩ã§æåã§å解ããã³åæããå¿ èŠããããŸãã
- æªãã«ãã¬ããžã ã€ã³ãã©ã¹ãã©ã¯ãã£ã¹ãã£ã³ã®å質ã¯ãè匱æ§ãšãœãããŠã§ã¢ããŒãžã§ã³ã«é¢ããç¥èããŒã¹ã®éã«çŽæ¥äŸåããŸãã åæã«ãåžå Žã®ãªãŒããŒã§ããå æ¬çãªããŒã¿ããŒã¹ãæã£ãŠããªãããšãããããç¡æã®ãœãªã¥ãŒã·ã§ã³ã®ããŒã¿ããŒã¹ã«ã¯ãªãŒããŒãæã£ãŠããªãå€ãã®æ å ±ããããŸã
- ãããã®åé¡ã ã€ã³ãã©ã¹ãã©ã¯ãã£ã®è匱æ§ã«å¯Ÿããæãäžè¬çãªãããã¯ãããã±ãŒãžã®æŽæ°ãŸãã¯æ§æãã¡ã€ã«ã®å€æŽã§ãã ããã§ã®å€§ããªåé¡ã¯ãã·ã¹ãã ãç¹ã«ã¬ã¬ã·ãŒããæŽæ°ã®çµæãšããŠäºæž¬ã§ããªãåäœãããå¯èœæ§ãããããšã§ãã æ¬è³ªçã«ã補åã®ç掻ã€ã³ãã©ã¹ãã©ã¯ãã£ãŒã§çµ±åãã¹ããå®è¡ããå¿ èŠããããŸã
ã¢ãããŒã
ã©ãããïŒ
次ã®ããŒãã§ã¯ãäŸãšãããã®åé¡ã®å€ãã«å¯ŸåŠããæ¹æ³ã«ã€ããŠè©³ãã説æããŸãããããã§ã¯ãäœæ¥ã§ããäž»ãªé åã瀺ããŸãã
- ããŸããŸãªã¹ãã£ã³ããŒã«ã®éçŽã è€æ°ã®ã¹ãã£ããŒãæ£ãã䜿çšããããšã§ãç¥èããŒã¹ãšæ€åºã®å質ãå€§å¹ ã«åäžãããããšãã§ããŸãã åå¥ã«èµ·åããããã¹ãŠã®ã¹ãã£ããŒãããããã«å€ãã®è匱æ§ãèŠã€ããããšãã§ããŸããããªã¹ã¯ã®ã¬ãã«ãããæ£ç¢ºã«è©äŸ¡ããããå€ãã®æšå¥šäºé ãäžããããšãã§ããŸã
- SASTãšDASTã®çµ±åã ãããã®éã§æ å ±ãå ±æããããšã«ãããDASTã«ãã¬ããžãšSASTã®ç²ŸåºŠãé«ããããšãã§ããŸãã ãœãŒã¹ããæ¢åã®ã«ãŒãã«é¢ããæ å ±ãååŸã§ããDASTã䜿çšããŠè匱æ§ãå€éšããèŠãããã©ããã確èªã§ããŸã
- æ©æ¢°åŠç¿â¢ ã 2015幎ã«ãçµ±èšæ å ±ã䜿çšããŠããã«ãŒã«ã¹ãã£ããŒã®çŽæãäžããé«éåããããšã«ã€ã㊠ïŒãããŠãŸã ïŒ è©±ããŸããã ããã¯ééããªããå°æ¥ã®èªååãããã»ãã¥ãªãã£åæã®éçºã®ããã®é£æã§ãã
- IASTãšèªåãã¹ãããã³OpenAPIã®çµ±åã CI / CDãã€ãã©ã€ã³ã®ãã¬ãŒã ã¯ãŒã¯å ã§ãHTTPãããã·ãšããŠæ©èœããããŒã«ãšHTTPã§æ©èœããæ©èœãã¹ãã«åºã¥ããŠã¹ãã£ã³ããã»ã¹ãäœæããããšãã§ããŸãã OpenAPI / Swaggerãã¹ããšã³ã³ãã©ã¯ãã«ãããã¹ãã£ããŒã«ããŒã¿ã¹ããªãŒã ã«é¢ããæ¬ èœæ å ±ãæäŸãããããŸããŸãªç¶æ ã§ã¢ããªã±ãŒã·ã§ã³ãã¹ãã£ã³ã§ããããã«ãªããŸãã
- æ£ããæ§æã ã¢ããªã±ãŒã·ã§ã³ãšã€ã³ãã©ã¹ãã©ã¯ãã£ããšã«ã䜿çšããã€ã³ã¿ãŒãã§ã€ã¹ããã¯ãããžã®æ°ãšæ§è³ªãèæ ®ããé©åãªã¹ãã£ã³ãããã¡ã€ã«ãäœæããå¿ èŠããããŸãã
- ã¹ãã£ããŒã®ã«ã¹ã¿ãã€ãºã å€ãã®å Žåãã¢ããªã±ãŒã·ã§ã³ã¯ãã¹ãã£ããŒããã¡ã€ãã©ã€ãºããªããšã¹ãã£ã³ã§ããŸããã äŸã¯ãåãªã¯ãšã¹ãã«çœ²åããå¿ èŠãããæ¯æãã²ãŒããŠã§ã€ã§ãã ã²ãŒããŠã§ã€ãããã³ã«ãžã®ã³ãã¯ã¿ãèšè¿°ããããšãªããã¹ãã£ããŒã¯ééã£ã眲åã䜿çšããŠãèŠæ±ã«æ°ä»ããã«åã¡ãŸãã Insecure Direct Object Referenceãªã©ãç¹å®ã®ã¿ã€ãã®æ¬ é¥ã«ç¹åããã¹ãã£ããŒãäœæããå¿ èŠããããŸãã
- ãªã¹ã¯ç®¡çã ããŸããŸãªã¹ãã£ããŒã䜿çšããAsset ManagementãThreat Managementãªã©ã®å€éšã·ã¹ãã ãšçµ±åãããšãå€ãã®ãã©ã¡ãŒã¿ãŒã䜿çšããŠãªã¹ã¯ã®ã¬ãã«ãè©äŸ¡ã§ããããã管çè ã¯éçºãŸãã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã®çŸåšã®ã»ãã¥ãªãã£ã¹ããŒã¿ã¹ãé©åã«ææ¡ã§ããŸã
åŒãç¶ãã泚ç®ããã ããè匱æ§ã¹ãã£ã³ãäžæããŸãããïŒ