åºæ ãã£ã©ã¯ã¿ãŒäœè ïŒãžã£ã¹ãã£ã³ã»ãã€ã©ã³ããšãã³ã»ããŒã¢ã³ã
SecDevOpsãšã¯äœã§ããïŒ DevSecOpsã¯ã©ãã§ããïŒ éãã¯äœã§ããïŒ ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£-ããã¯äœã§ããïŒ ãªãå€å žçãªã¢ãããŒãã¯ããæ©èœããªãã®ã§ããïŒ Swordfish Securityã® Yury Shabalin㯠ãããããã¹ãŠã®è³ªåã«å¯Ÿããçããç¥ã£ãŠããŸãã ãŠãŒãªã¯ããã¹ãŠã«è©³çŽ°ã«çããåŸæ¥ã®ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã¢ãã«ããDevSecOpsããã»ã¹ãžã®ç§»è¡ã®åé¡ãåæããŸããDevOpsããã»ã¹ã«å®å šãªéçºããã»ã¹ãé©åã«åã蟌ã¿ãåæã«äœãå£ããªãæ¹æ³ãã»ãã¥ãªãã£ãã¹ãã®äž»èŠæ®µéãééããæ¹æ³ã䜿çšã§ããããŒã«ããããã¯ç°ãªããèœãšãç©Žãé¿ããããã«ããããæ£ããæ§æããæ¹æ³ã§ãã
ã¹ããŒã«ãŒã«ã€ããŠïŒ Yuri Shabalin- Swordfish Securityã®ããŒãã»ãã¥ãªãã£ã¢ãŒããã¯ãã 圌ã¯ãSSDLã®å®è£ ãã¢ããªã±ãŒã·ã§ã³åæããŒã«ã®åäžã®éçºããã³ãã¹ããšã³ã·ã¹ãã ãžã®äžè¬çãªçµ±åãæ åœããŠããŸãã æ å ±ã»ãã¥ãªãã£ã®7幎ã®çµéšã 圌ã¯ãAlfa BankãSberbankãããã³ãœãããŠã§ã¢ã®éçºãšãµãŒãã¹ãæäŸããPositive Technologiesã§åããŠããŸããã åœéäŒè°ZerONightsãPHDaysãRISSPAãOWASPã®ã¹ããŒã«ãŒã
ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ïŒããã¯äœã§ããïŒ
ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã¯ãã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãæ åœããã»ãã¥ãªãã£ã»ã¯ã·ã§ã³ã§ãã ããã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ããããã¯ãŒã¯ã®ã»ãã¥ãªãã£ãã€ãŸããç§ãã¡ãæžããŠãããã®ãéçºè ãåãçµãã§ãããã®ã«ã¯åœãŠã¯ãŸããŸããããããã¯ãã¢ããªã±ãŒã·ã§ã³èªäœã®æ¬ é¥ãšè匱æ§ã§ãã
SDLãŸãã¯SDLCã®æ¹å- ã»ãã¥ãªãã£éçºã©ã€ããµã€ã¯ã« -ã¯ãã€ã¯ããœããã«ãã£ãŠéçºãããŸããã ãã®å³ã¯ãæšæºã®SDLCã¢ãã«ã瀺ããŠããŸãããã®äž»ãªã¿ã¹ã¯ã¯ãèŠä»¶ãããªãªãŒã¹ãå®çšŒåãžã®ãªãªãŒã¹ãŸã§ãéçºã®ãããã段éã§ã®ã»ãã¥ãªãã£åå ã§ãã ãã€ã¯ããœããã¯ãããã ã«ãã°ãå€ãããŠãããã«å€ãã®ãã°ããããäœãããå¿ èŠãããããšã«æ°ã¥ãããã®ã¢ãããŒããææ¡ããŸããã
Application SecurityãšSSDLã¯ãäžè¬ã«èããããŠããããã«è匱æ§ãæ€åºããããšãç®çãšãããè匱æ§ã®çºçãé²ãããšãç®çãšããŠããŸãã æéãçµã€ã«ã€ããŠãMicrosoftã®æšæºçãªã¢ãããŒããæ¹åãéçºãããããæ·±ã詳现ãªæ²¡å ¥æãçŸããŸããã
Canonical SDLCã¯ãOpenSAMMãBSIMMãOWASPãªã©ã®ããŸããŸãªæ¹æ³è«ã§éåžžã«è©³çŽ°ã«èšè¿°ãããŠããŸãã æ¹æ³è«ã¯ç°ãªããŸãããäžè¬çã«äŒŒãŠããŸãã
æçã¢ãã«ã§ã®ã»ãã¥ãªãã£ã®æ§ç¯
ç§ã¯BSIMMãæã æçããã»ãã¥ãªãã£ã¢ãã«ã§ããã®ã奜ãã§ã ã æ¹æ³è«ã®åºç€ã¯ãã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ããã»ã¹ã4ã€ã®ãã¡ã€ã³ïŒã¬ããã³ã¹ãã€ã³ããªãžã§ã³ã¹ãSSDLã¿ãããã€ã³ããå±éïŒã«åé¢ããããšã§ãã åãã¡ã€ã³ã«ã¯12ã®ãã©ã¯ãã£ã¹ãããã112ã®ã¢ã¯ãã£ããã£ãšããŠè¡šãããŠããŸãã
112ã®åã¢ã¯ãã£ããã£ã«ã¯ã 3ã€ã®æç床ã¬ãã«ããããŸã ïŒãã©ã€ããªãäžçŽãäžçŽã 12ã®ãã©ã¯ãã£ã¹ãã¹ãŠãã»ã¯ã·ã§ã³ã§åŠç¿ããéèŠãªãã®ãéžæãããããã®å®è£ æ¹æ³ãç解ããéçããã³åçãªã³ãŒãåæãã³ãŒãã¬ãã¥ãŒãªã©ã®èŠçŽ ãåŸã ã«è¿œå ã§ããŸãã éžæããã¢ã¯ãã£ããã£ã®å®è£ ã®äžç°ãšããŠãèšç»ããã€ã³ãããå·éã«äœæ¥ããŸãã
DevSecOpsãéžã¶çç±
DevOpsã¯ãã»ãã¥ãªãã£ã®é¢åãèŠãå¿ èŠãããäžè¬çãªå€§ããªããã»ã¹ã§ãã
æåã DevOpsã«ã¯ã»ãã¥ãªãã£ãã§ãã¯ãå«ãŸããŠããŸãã ã å®éã«ã¯ãã»ãã¥ãªãã£ããŒã ã®æ°ã¯çŸåšãããã¯ããã«å°ãªããããã»ã¹ã®åå è ãšããŠã§ã¯ãªãããªãªãŒã¹ã®æåŸã«ãããèŠæ±ãã補åã®å質ããã§ãã¯ãã管çããã³ç£ç£æ©é¢ãšããŠè¡åããŸããã ããã¯ãã»ãã¥ãªãã£ããŒã ãéçºã®å£ã®åŸãã«ããŠãããã»ã¹ã«é¢äžããŠããªãã£ãå€å žçãªã¢ãããŒãã§ãã
äž»ãªåé¡ã¯ãæ å ±ã»ãã¥ãªãã£ãéçºãšã¯å¥åã§ããããšã§ãã éåžžãããã¯IBåè·¯ã®äžçš®ã§ããã2ã3åã®å€§åã§é«äŸ¡ãªããŒã«ãå«ãŸããŠããŸãã 6ãæã«1åããœãŒã¹ã³ãŒããŸãã¯ã¢ããªã±ãŒã·ã§ã³ãå°çããŸãã®ã§ããã§ãã¯ããå¿ èŠãããã1幎ã«1åãã³ãã¹ããäœæãããŸãã ããã¯ãã¹ãŠãããã ã«å ¥ãããã®æéã延æãããèªååããŒã«ããã®èšå€§ãªæ°ã®è匱æ§ãéçºè ã«èœã¡ããšããäºå®ã«ã€ãªãããŸãã éå»6ãæéã®çµæãæŽçãããŠããªããããããããã¹ãŠå解ããã³ä¿®åŸ©ããããšã¯ã§ããŸããããããã«æ°ãããããããããŸãã
åŒç€Ÿã®ããã»ã¹ã§ã¯ããã¹ãŠã®åéãšæ¥çã®ã»ãã¥ãªãã£ãã ã¢ãžã£ã€ã«ã® 1ã€ã®ãã€ãŒã«ã§ã®éçºã§èªåèªèº«ãåŒããã¹ãã³ããæã ãšç解ããŠããããšãããããŸãã DevSecOpsãã©ãã€ã ã¯ãã¢ãžã£ã€ã«éçºæ¹æ³è«ãå®è£ ããµããŒããããã³åãªãªãŒã¹ãšã€ãã¬ãŒã·ã§ã³ãžã®åå ã«ããŸãé©åããŸãã
DevSecOpsãžã®ç§»è¡
ã»ãã¥ãªãã£éçºã©ã€ããµã€ã¯ã«ã§æãéèŠãªèšèã¯ãããã»ã¹ãã§ã ã ããŒã«ã®è³Œå ¥ãæ€èšããåã«ããããç解ããå¿ èŠããããŸãã
DevOpsããã»ã¹ã«ããŒã«ãçµã¿èŸŒãã ãã§ã¯ååã§ã¯ãããŸãããããã»ã¹ã®åå è éã®çžäºäœçšãšç解ã¯éèŠã§ãã
ããŒã«ããã人ãããéèŠ
å€ãã®å Žåãå®å šãªéçºããã»ã¹ã®èšç»ã¯ããŒã«ã®éžæãšè³Œå ¥ããå§ãŸããããŒã«ãçŸåšã®ããã»ã¹ã«çµ±åããããšããè©Šã¿ã§çµãããŸãã ãã¹ãŠã®ããŒã«ã«ã¯ç¬èªã®ç¹æ§ãšå¶éããããããããã¯æ²ããçµæã«ã€ãªãããŸãã
ã»ãã¥ãªãã£éšéãåªããæ©èœãåããåªããé«äŸ¡ãªããŒã«ãéžæããéçºè ã«æ¥ãŠããã»ã¹ã«çµã¿èŸŒããšããäžè¬çãªã±ãŒã¹ã ããããããŸããããŸãããããã»ã¹ã¯ããã§ã«è³Œå ¥ããããŒã«ã®å¶éãçŸåšã®ãã©ãã€ã ã«é©åããªãããã«æ§æãããŠããŸãã
æåã«ãåžæããçµæãšããã»ã¹ã®å€èŠ³ã説æããŸãã ããã¯ãããã»ã¹ã«ãããããŒã«ã®åœ¹å²ãšå®å šæ§ãç解ããã®ã«åœ¹ç«ã¡ãŸãã
ãã§ã«äœ¿çšãããŠãããã®ããå§ããŸãã
é«äŸ¡ãªããŒã«ãè³Œå ¥ããåã«ããã§ã«æã£ãŠãããã®ãèŠãŠãã ããã åäŒç€Ÿã«ã¯éçºã®ããã®å®å šèŠä»¶ãããããã§ãã¯ããã³ãã¹ãããããŸã-ããããã¹ãŠã®äººã«ãšã£ãŠç解ãããã䟿å©ãªåœ¢ã«å€ããŠã¿ãŸãããïŒ
éåžžãèŠä»¶ã¯çŽã®ã¿ã«ã ãŒãã§ãããæ£ã®äžã«ãããŸãã äŒç€Ÿã«æ¥ãŠããã»ã¹ã確èªãããœãããŠã§ã¢ã®ã»ãã¥ãªãã£èŠä»¶ã瀺ãããã«äŸé Œããå ŽåããããŸããã ãããè¡ã£ãå°é家ã¯é·ãéæ¢ããŠããŸããã
-ããŠãã¡ã¢ã®ã©ããã«ããã®ææžãååšããæ¹æ³ããããŸããã
ãã®çµæã1é±éåŸã«ããã¥ã¡ã³ããåãåããŸããã
èŠä»¶ããã§ãã¯ãªã©ã«ã€ããŠã¯ãããšãã°Confluenceã§ããŒãžãäœæããŸã-ããã¯èª°ã«ãšã£ãŠã䟿å©ã§ãã
ãã§ã«ãããã®ãåãã©ãŒãããããããã䜿çšããŠéå§ããæ¹ãç°¡åã§ãã
ã»ãã¥ãªãã£ãã£ã³ããªã³ã䜿çšãã
éåžžã100ã200人ã®éçºè ãæ±ããäžèŠæš¡ã®äŒç€Ÿã§ã¯ã1人ã®ã»ãã¥ãªãã£æ åœè ãåããŠãããè€æ°ã®æ©èœãå®è¡ããç©ççã«ãã¹ãŠããã§ãã¯ããæéã¯ãããŸããã 圌ãæåãå°œãããŠããéçºè ãçæãããã¹ãŠã®ã³ãŒãããã§ãã¯ããããã§ã¯ãããŸããã ãã®ãããªå Žåã®ããã«ãã³ã³ã»ãããéçºãããŸãã-Security Champions ã
ã»ãã¥ãªãã£ãã£ã³ããªã³ã¯ã補åã®ã»ãã¥ãªãã£ã«é¢å¿ã®ããéçºããŒã å ã®äººã§ãã
ã»ãã¥ãªãã£ãã£ã³ããªã³ã¯éçºããŒã ãžã®å ¥ãå£ã§ãããã»ãã¥ãªãã£ãšãã³ãžã§ãªã¹ãã¯ãã¹ãŠ1ã€ã«ãªããŸããã
éåžžãé庫ãéçºããŒã ã«æ¥ãŠãã³ãŒãã«ãšã©ãŒãããããšã瀺ããšãé©ãã®çããåãåããŸãã
ãããªãã¯èª°ã§ããïŒã åããŠäŒããŸããã ç§ã¯å æ°ã§ã-ã³ãŒãã¬ãã¥ãŒã®ã·ãã¢ãã¬ã³ããç§ã«ãé©çšãããããã«èšå®ããŸããã
ããã¯å žåçãªç¶æ³ã§ãããªããªããéçºè ãä»äºãã³ãŒãã¬ãã¥ãŒã§çµ¶ããããåãããŠããå 茩ãããŒã ã¡ã€ãã«å€ãã®ä¿¡é Œãããããã§ãã ã»ãã¥ãªãã£ã¬ãŒãã®ä»£ããã«ãã»ãã¥ãªãã£ãã£ã³ããªã³ããšã©ãŒãšçµæã瀺ãå Žåã圌ã®èšèã¯ããéèŠã«ãªããŸãã
ãŸããéçºè ã¯ã©ã®ã»ãã¥ãªãã£ãããã€ããŒãããã³ãŒããããç¥ã£ãŠããŸãã éçåæããŒã«ã«å°ãªããšã5ã€ã®ãããžã§ã¯ãããã人ã«ãšã£ãŠããã¹ãŠã®ãã¥ã¢ã³ã¹ãèŠããããšã¯éåžžå°é£ã§ãã ã»ãã¥ãªãã£ãã£ã³ããªã³ã¯èªç€Ÿã®è£œåãç¥ã£ãŠããŸããã€ãŸããäœãäœãšçžäºäœçšããäœãèŠãªããã°ãªããªãã-圌ãã¯ããå¹æçã§ãã
ãã®ãããã»ãã¥ãªãã£ãã£ã³ããªã³ãå®è£ ããã»ãã¥ãªãã£ããŒã ã®åœ±é¿åãæ¡å€§ããããšãæ€èšããŠãã ããã ãã£ã³ããªã³èªèº«ã«ãšã£ãŠããããã¯æçšã§ããæ°ããåéã§ã®å°éèœåéçºãæè¡ã®èŠéã®æ¡å€§ãæè¡ã管çããªãŒããŒã·ããã®ã¹ãã«ã®åäžãåžå ŽäŸ¡å€ã®åäžã ããã¯ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®äžéšã§ãããéçºããŒã ã®ãç®ãã§ãã
ãã¹ãæé
20ãã80ã®ãã©ãã€ã ã§ã¯ãåªåã®20ïŒ ãçµæã®80ïŒ ãçã¿åºããŸãã ãããã®20ïŒ ã¯ãèªååã§ããã¢ããªã±ãŒã·ã§ã³ã®ãã©ã¯ãã£ã¹ã§ãã ãã®ãããªã¢ã¯ãã£ããã£ã®äŸãšããŠã¯ãéçåæ-SAST ãåçåæ-DASTãããã³ãªãŒãã³ãœãŒã¹ç®¡çããããŸãã ã¢ã¯ãã£ããã£ãããŒã«ãããã»ã¹ã«å°å ¥ããããšãã«éåžžééããæ©èœãããã³ãããæ£ããè¡ãæ¹æ³ã«ã€ããŠè©³ãã説æããŸãã
ããŒã«ã®äž»ãªåé¡
泚æãå¿ èŠãªãã¹ãŠã®ããŒã«ã«é¢é£ããåé¡ã匷調ããŸãã ãã以äžç¹°ãè¿ããªãããã«ããããããã詳现ã«åæããŸãã
é·æéã®åæã ã³ããããã補åã«è³ããŸã§ã®ãã¹ãŠã®ãã¹ããšã¢ã»ã³ããªãå®äºããã®ã«30åãããå Žåãæ å ±ã»ãã¥ãªãã£ãã§ãã¯ã«ã¯1æ¥ããããŸãã ãããã£ãŠã誰ãããã»ã¹ãé ãããããšã¯ãããŸããã ãã®æ©èœãæ€èšããçµè«ãå°ãåºããŸãã
é«ãåœé°æ§ãŸãã¯åœéœæ§ã ãã¹ãŠã®è£œåã¯ç°ãªãã誰ããç°ãªããã¬ãŒã ã¯ãŒã¯ãšç¬èªã®ã¹ã¿ã€ã«ã®ã³ãŒãã䜿çšããŠããŸãã ããŸããŸãªã³ãŒãããŒã¹ããã³ãã¯ãããžã§ãããŒã«ã¯ããŸããŸãªã¬ãã«ã®False Negativeããã³False Positiveã衚瀺ã§ããŸãã ãããã£ãŠãäŒæ¥å ããã³ã¢ããªã±ãŒã·ã§ã³ã§äœãæ£ç¢ºãã€ä¿¡é Œã§ããçµæãããããããæ£ç¢ºã«ç¢ºèªããŠãã ãã ã
æ¢åã®ããŒã«ãšã®çµ±åã¯ãããŸãã ã ãã§ã«äœ¿çšããŠããããã«ãçµ±åã®èŠ³ç¹ããããŒã«ãèŠãŠãã ããã ããšãã°ãJenkinsãŸãã¯TeamCityã䜿çšããŠããå Žåã¯ã䜿çšããªãGitLab CIã§ã¯ãªãããã®ãœãããŠã§ã¢ãšããŒã«ã®çµ±åã確èªããŠãã ããã
ã«ã¹ã¿ãã€ãºã®æ¬ åŠãŸãã¯é床ã®è€éãã ããŒã«ã«APIããªãå Žåããªãå¿ èŠãªã®ã§ããïŒ ã€ã³ã¿ãŒãã§ã€ã¹ã§ã§ããããšã¯ãã¹ãŠãAPIãä»ããŠã¢ã¯ã»ã¹ã§ããå¿ èŠããããŸãã çæ³çã«ã¯ãããŒã«ã¯ãã§ãã¯ãã«ã¹ã¿ãã€ãºã§ããå¿ èŠããããŸãã
ããŒãããã補åéçºã¯ãããŸããã éçºã¯æ¢ãŸãããšãªããåžžã«æ°ãããã¬ãŒã ã¯ãŒã¯ãšæ©èœã䜿çšããå€ãã³ãŒããæ°ããèšèªã«æžãæããŸãã è³Œå ¥ããããŒã«ãæ°ãããã¬ãŒã ã¯ãŒã¯ãšãã¯ãããžãŒããµããŒãããããšã確èªããããšæããŸãã ãããã£ãŠã補åã«ã¯å®éã®é©åãªéçºããŒãããããããããšãç¥ã£ãŠããããšãéèŠã§ãã
ããã»ã¹æ©èœ
ããŒã«ã®æ©èœã«å ããŠãéçºããã»ã¹ã®æ©èœãæ€èšããŠãã ããã ããšãã°ãéçºã®åŠšå®³ã¯å žåçãªééãã§ãã ä»ã®ã©ã®æ©èœãæ€èšããã»ãã¥ãªãã£ããŒã ãäœã«æ³šæãæãã¹ãããèŠãŠã¿ãŸãããã
éçºæ¥ãšãªãªãŒã¹æ¥ãäžæãããªãããã«ãç°ãªãç°å¢ã«å¯ŸããŠã ç°ãªãã«ãŒã«ãšç°ãªãã·ã§ãŒã¹ããã㌠ïŒè匱æ§ãååšããå Žåã«ãã«ãããã»ã¹ãåæ¢ããããã®åºæºïŒãäœæããŸã ã ããšãã°ãçŸåšã®ãã©ã³ãã¯éçºã¹ã¿ã³ããŸãã¯UATã«ç§»åããããšãç解ããŠãããããåæ¢ããã次ã®ããã«èšã£ãŠããŸããã
-ããªãã¯ããã«è匱æ§ããããŸããããªãã¯ãã以äžã©ãã«ãè¡ããªãã§ãããïŒ
ãã®æ®µéã§ã¯ã泚æãã䟡å€ã®ããã»ãã¥ãªãã£ã®åé¡ãããããšãéçºè ã«äŒããããšãéèŠã§ãã
è匱æ§ã®ååšã¯ ãæåãçµ±åããŸãã¯æåã®ãããªããã¹ãã®é害ã«ã¯ãªããŸãã ã äžæ¹ã補åã®ã»ãã¥ãªãã£ãäœããã®æ¹æ³ã§åŒ·åããå¿ èŠããããŸãããã®ãããéçºè ãå®å šæ§ãèŠã€ããããšãå¿ããªãããã«ããŸãã ãã®ããããããè¡ãããšããããŸããã¹ã¿ã³ãã§ã¯ãéçºç°å¢ã«å±éãããšãã«ãéçºã«éç¥ããã ãã§ãã
-çãããåé¡ããããŸãã®ã§æ³šæããŠãã ããã
UATã¹ããŒãžã§ã¯ãè匱æ§ã«é¢ããèŠåãå床衚瀺ããããã ã®çµäºã¹ããŒãžã§ã¯æ¬¡ã®ããã«èšããŸãã
-ã¿ããªãç§ãã¡ã¯äœåºŠãèŠåããŸãããããªãã¯äœãããŸããã§ãã-ç§ãã¡ã¯ããªãã«ãããææŸããŸããã
ã³ãŒããšãã€ããã¯ã¹ã«ã€ããŠè©±ãå Žåããããã®æ©èœã®è匱æ§ãšãã®æ©èœã§äœæãããã°ããã®ã³ãŒãã«ã€ããŠã®ã¿è¡šç€ºããŠèŠåããå¿ èŠããããŸãã éçºè ããã¿ã³ã3ãã¯ã»ã«ç§»åããããã«SQLã€ã³ãžã§ã¯ã·ã§ã³ããããç·æ¥ã«ä¿®æ£ããå¿ èŠãããããšãäŒããå Žåãããã¯ééã£ãŠããŸãã çŸåšèšè¿°ãããŠããå 容ãšãã¢ããªã±ãŒã·ã§ã³ã«çããå€æŽã®ã¿ã確èªããŠãã ããã
ç¹å®ã®æ©èœäžã®æ¬ é¥ããããšä»®å®ããŸã-ã¢ããªã±ãŒã·ã§ã³ãåäœããªãæ¹æ³ïŒãéãééãããªãããã¿ã³ãã¯ãªãã¯ãããšã次ã®ããŒãžã«é·ç§»ããªãããŸãã¯è£œåãããŒããããªã ã»ãã¥ãªãã£ã®æ¬ é¥ã¯åãæ¬ é¥ã§ãããã¢ããªã±ãŒã·ã§ã³ã®ã³ã³ããã¹ãã§ã¯ãªããã»ãã¥ãªãã£ã§ãã
ãã¹ãŠã®ãœãããŠã§ã¢å質ã®åé¡ãã»ãã¥ãªãã£ã®åé¡ã§ã¯ãããŸããã ãã ãããã¹ãŠã®ã»ãã¥ãªãã£åé¡ã¯ãœãããŠã§ã¢ã®å質ã«é¢é£ããŠããŸãã ã·ã§ãªããã³ã¹ãŒã«ããšã¯ã¹ããã£ã¢ã
ãã¹ãŠã®è匱æ§ã¯åãæ¬ é¥ã§ããããããã¹ãŠã®éçºæ¬ é¥ãšåãå Žæã«é 眮ããå¿ èŠããããŸãã ã ãã誰ãèªãŸãªãã¬ããŒããæãPDFãå¿ããŠãã ããã
éçºäŒç€Ÿã§åããŠãããšããéçåæããŒã«ããã¬ããŒããåãåããŸããã ç§ã¯ãããéãããã£ãšãããã³ãŒããŒãbrewãã350ããŒãžãããã£ãŠãéããŠäœæ¥ãç¶ããŸããã 倧ããªã¬ããŒãã¯æ»ãã ã¬ããŒãã§ãã éåžžã圌ãã¯ã©ãã«ãè¡ãããæçŽã¯åé€ãããããå¿ããããããçŽå€±ãããããŸãã
ã©ããã 確èªããæ¬ é¥ãéçºã«äŸ¿å©ãªåœ¢åŒã«å€æããã ãã§ããããšãã°ãJiraã®ããã¯ãã°ã«è¿œå ããŸãã æ©èœã®æ¬ é¥ãšãã¹ãã®æ¬ é¥ãšãšãã«ãåªå é äœã®é«ãæ¬ é¥ãåªå ããŠæé€ããŸãã
éçåæ-SAST
ããã¯è匱æ§ã®ã³ãŒãåæã§ãããSonarQubeãšã¯ç°ãªããŸãã ãã¿ãŒã³ãã¹ã¿ã€ã«ã ãã§ã¯ãããŸããã åæã§ã¯ãè匱æ§ããªãŒã DataFlow ãæ§æãã¡ã€ã«ã®åæãªã©ãå€ãã®ã¢ãããŒãã䜿çšãããŸãã ããã¯ãã¹ãŠã³ãŒãã«çŽæ¥é¢é£ããŠããŸãã
ã¢ãããŒãã®å©ç¹ ïŒã¹ã¿ã³ãããã³å®æããããŒã«ããªãéçºã®åæ段éã§ã³ãŒãã®è匱æ§ãç¹å®ãã ã€ã³ã¯ãªã¡ã³ã¿ã«ã¹ãã£ã³ã®å¯èœæ§ ïŒå€æŽãããã³ãŒãã®ã»ã¯ã·ã§ã³ãã¹ãã£ã³ããçŸåšå®è¡ããŠããæ©èœã®ã¿ãã¹ãã£ã³ããããšã§ãã¹ãã£ã³æéãççž®ããŸãã
çæ -ããã¯ãå¿ èŠãªèšèªã®ãµããŒãã®æ¬ åŠã§ãã
ç§ã®äž»èŠ³çãªæèŠã§ã¯ãããŒã«ã«å¿ èŠãªçµ±å ïŒ
- çµ±åããŒã«ïŒJenkinsãTeamCityãããã³Gitlab CIã
- éçºç°å¢ïŒIntellij IDEAãVisual Studioã éçºè
ã«ãšã£ãŠã¯ãèŠããŠããå¿
èŠã®ãããããã«ããã€ã³ã¿ãŒãã§ãŒã¹ã«ç»ãã®ã§ã¯ãªããèªåã®éçºç°å¢ã®è·å Žã§ãå¿
èŠãªãã¹ãŠã®çµ±åãšè匱æ§ã確èªããæ¹ã䟿å©ã§ãã
- ã³ãŒãã¬ãã¥ãŒïŒSonarQubeããã³æåã¬ãã¥ãŒã
- æ¬ é¥ãã©ãã«ãŒïŒJiraããã³Bugzillaã
åçã¯ãéç解æã®æè¯ã®ä»£è¡šã®ããã€ãã瀺ããŠããŸãã
éèŠãªã®ã¯ããŒã«ã§ã¯ãªãããã»ã¹ã§ãããããããã»ã¹ã®å®è¡ã«ãé©ãããªãŒãã³ãœãŒã¹ãœãªã¥ãŒã·ã§ã³ããããŸãã
SAST Open Sourceã¯ãèšå€§ãªæ°ã®è匱æ§ãè€éãªDataFlowãçºèŠããŸããããããã»ã¹ãæ§ç¯ããéã«äœ¿çšããããšãã§ãã䜿çšããå¿ èŠããããŸãã ããã»ã¹ãã©ã®ããã«æ§ç¯ããããã誰ããã°ã«å¯Ÿå¿ãããã誰ãå ±åãããã誰ãå ±åããããç解ããã®ã«åœ¹ç«ã¡ãŸãã ã³ãŒãã®ã»ãã¥ãªãã£ãæ§ç¯ããåæ段éãéããããå Žåã¯ããªãŒãã³ãœãŒã¹ãœãªã¥ãŒã·ã§ã³ã䜿çšããŠãã ããã
éã®åãã«ããå ŽåãCIãJenkinsãTeamCityã®ããããäœããªãå Žåããããã©ã®ããã«çµ±åã§ããŸããïŒ ããã»ã¹ãžã®çµ±åãæ€èšããŠãã ããã
CVSçµ±å
BitbucketãŸãã¯GitLabãããå Žåã¯ã Concurrent Versions Systemã¬ãã«ã§çµ±åãè¡ãããšãã§ããŸãã
ã€ãã³ãå¥ -ãã«ãªã¯ãšã¹ããã³ãããã ã³ãŒããã¹ãã£ã³ãããã«ãã¹ããŒã¿ã¹ã§ã»ãã¥ãªãã£ãã§ãã¯ãæåãŸãã¯å€±æããããšã瀺ããŸãã
ãã£ãŒãããã¯ã ãã¡ããããã£ãŒãããã¯ã¯åžžã«å¿ èŠã§ãã åã«ã»ãã¥ãªãã£åŽã§å®è¡ããå Žåã¯ãããã¯ã¹ã«å ¥ããŠèª°ã«ãèšããã«ãææ«ã«å€§éã®ãã°ããã³ãããŸãããããã¯æ£ãããè¯ãããããŸããã
ã³ãŒãã¬ãã¥ãŒãšã®çµ±å
äžåºŠãå€ãã®éèŠãªãããžã§ã¯ãã§ãAppSecæè¡ãŠãŒã¶ãŒã®ããã©ã«ãã®ã¬ãã¥ãŒæ åœè ãèšå®ããŸããã æ°ããã³ãŒãã§ãšã©ãŒãæ€åºããããã©ããããŸãã¯ãšã©ãŒããªããã©ããã«å¿ããŠãã¬ãã¥ã¢ãŒã¯ãã«ãªã¯ãšã¹ãã®ã¹ããŒã¿ã¹ããåãå ¥ããããŸãã¯ãäœæ¥ãå¿ èŠãã«ããŸã-ãã¹ãŠãæ£åžžã§ããããæçµåãããã®ãæ£ç¢ºã«çµã蟌ãã§ãªã³ã¯ããå¿ èŠããããŸãã 補åçã®ããŒãžã§ã³ãšçµ±åããããã«ãIBãã¹ãã倱æããå Žåã«ããŒãžçŠæ¢ããªã³ã«ããŸããã ãããæåã®ã³ãŒãã¬ãã¥ãŒã«å«ããããã»ã¹ã®ä»ã®åå è ã¯ãã®ç¹å®ã®ããã»ã¹ã®ã»ãã¥ãªãã£ã¹ããŒã¿ã¹ã確èªããŸããã
SonarQubeãšã®çµ±å
å€ãã«ã¯ãã³ãŒãå質ã®å質ã²ãŒãããããŸãã ããã§ãåãããš-SASTããŒã«ã«å¯ŸããŠã®ã¿åãã²ãŒããäœæã§ããŸãã åãã€ã³ã¿ãŒãã§ãŒã¹ãåãå質ã²ãŒãããããããã ããã»ãã¥ãªãã£ã²ãŒããšåŒã°ããŸãã ãŸããSonarQubeã䜿çšããããã»ã¹ãããå Žåã¯ãããã«ãã¹ãŠãç°¡åã«çµ±åã§ããŸãã
CIçµ±å
ããã§ãããã¹ãŠãéåžžã«ç°¡åã§ãã
- autotestsãšåãã¬ãã«ã§ ãåäœãã¹ãã
- éçºã®æ®µéã«ããåé¢ ïŒ éçº ããã¹ãã補åã ããŸããŸãªã«ãŒã«ã»ãããå«ãŸããŠããå ŽåããããŸããŸãªå€±ææ¡ä»¶ïŒã¢ã»ã³ããªãåæ¢ãããã¢ã»ã³ããªãåæ¢ããªãïŒãå«ãŸããå ŽåããããŸãã
- åæ/éåæã¹ã¿ãŒã ã ã»ãã¥ãªãã£ãã¹ãã®çµäºãåŸ
ã£ãŠããããåŸ
ã£ãŠããŸããã ã€ãŸããç§ãã¡ã¯ããããèµ·åããŠå
ã«é²ã¿ããã¹ãŠãè¯ããæªããã®ã¹ããŒã¿ã¹ãåãåããŸãã
ãã¹ãŠãå®ç§ãªãã³ã¯ã®äžçã«ãããŸãã å®éã«ã¯ãããã¯ããã§ã¯ãããŸããããç§ãã¡ã¯åªåããŠããŸãã ã»ãã¥ãªãã£ãã§ãã¯ã®çµæã¯ãåäœãã¹ãã®çµæãšé¡äŒŒããŠããå¿ èŠããããŸãã
ããšãã°ã倧èŠæš¡ãªãããžã§ã¯ããåãäžããSAST'omã§ã¹ãã£ã³ããããšã«ããŸãã-OKã ãã®ãããžã§ã¯ããSASTã«æŒã蟌ã¿ã20,000ã®è匱æ§ãäžããŸããããããŠã匷ãæå¿ã§ããã¹ãŠãé 調ã§ããããšãåãå ¥ããŸããã 20,000ã®è匱æ§ã¯æè¡çãªçŸ©åã§ãã åéãç®±ã«å ¥ããŠããã£ãããšãããåããæ¬ é¥è¿œè·¡ã·ã¹ãã ã§ãã°ãéå§ããŸãã äŒç€Ÿãéã£ãŠãèªåã§ããããã»ãã¥ãªãã£ã®ãã£ã³ããªã³ãå©ããŠããã-ãããŠæè¡çãªè² åµãæžãã ããã
ãããŠãæ°ããã³ãŒãã«æ°ãã«åºçŸãããã¹ãŠã®è匱æ§ãšããŠããããŸãã¯èªåãã¹ãã®ãšã©ãŒãä¿®æ£ããå¿ èŠããããŸãã æ¯èŒçèšãã°ãã¢ã»ã³ããªãéå§ãããè¿œãåºããã2ã€ã®ãã¹ããš2ã€ã®ã»ãã¥ãªãã£ãã¹ããèœã¡ãŸããã OK-ç§ãã¡ã¯è¡ã£ãŠãäœãèµ·ãã£ãã®ããèŠãŠã1ã€ã®ããšãä¿®æ£ãã2çªç®ã®åé¡ãä¿®æ£ãã次åã«ãããè¿œãåºããŸãã-ãã¹ãŠãæ£åžžã§ãæ°ããè匱æ§ã¯ãªãããã¹ãã¯å€±æããŸããã§ãã ãã®ã¿ã¹ã¯ãããæ·±ãããããããç解ããå¿ èŠãããå ŽåããŸãã¯è匱æ§ã®ä¿®æ£ãå éšã«ãããã®ã®å€§ããªã¬ã€ã€ãŒã«åœ±é¿ããå ŽåïŒãã°ãæ¬ é¥ãã©ãã«ãŒã«æã¡èŸŒãã å Žåãããã¯åªå é äœãä»ããããŠä¿®æ£ãããŸãã æ®å¿µãªãããäžçã¯å®å šã§ã¯ãªãããã¹ãã¯æã 倱æããŸãã
ã»ãã¥ãªãã£ã²ãŒãã®äŸã¯ãã³ãŒãå ã®è匱æ§ã®ååšãšæ°ã«ããå質ã²ãŒãã®é¡äŒŒç©ã§ãã
SonarQubeãšçµ±åããŸã-ãã©ã°ã€ã³ãã€ã³ã¹ããŒã«ããããã¹ãŠãéåžžã«äŸ¿å©ã§ã¯ãŒã«ã§ãã
éçºç°å¢ã®çµ±å
çµ±åæ©èœïŒ
- ã³ãããåã«éçºç°å¢ããã¹ãã£ã³ãéå§ããŸãã
- çµæã衚瀺ããŸãã
- çµæã®åæã
- ãµãŒããŒãšã®åæã
ãµãŒããŒããçµæãååŸããããã«èŠããŸãã
Intellij IDEAéçºç°å¢ã§ã¯ãã¹ãã£ã³äžã«ãã®ãããªè匱æ§ãæ€åºãããããšãå ±åããè¿œå é ç®ã衚瀺ãããŸãã ã³ãŒããããã«ç·šéã§ããŸããæšå¥šäºé ãšãããŒã°ã©ããåç §ããŠãã ããã ãããã¯ãã¹ãŠéçºè ã®è·å Žã«ãããéåžžã«äŸ¿å©ã§ããä»ã®ãªã³ã¯ã«ã¢ã¯ã»ã¹ããŠäœåãªãã®ãèŠãå¿ èŠã¯ãããŸããã
ãªãŒãã³ãœãŒã¹
ããã¯ç§ã®ãæ°ã«å ¥ãã®ãããã¯ã§ãã 誰ãããªãŒãã³ãœãŒã¹ã®ã©ã€ãã©ãªã䜿çšããŠããŸã-ãã¹ãŠããã§ã«å®è£ ãããŠããæ¢è£œã®ã©ã€ãã©ãªãå ¥æã§ããã®ã«ããªãæŸèæãèªè»¢è»ãããããæžãã®ã§ããïŒ
ãã¡ãããããã¯äºå®ã§ãããã©ã€ãã©ãªã人ã«ãã£ãŠäœæãããŠãããç¹å®ã®ãªã¹ã¯ãå«ãŸããŠããŸãããŸããå®æçãŸãã¯çµ¶ããå ±åãããè匱æ§ããããŸãã ãããã£ãŠãã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã®æ¬¡ã®ã¹ãããã¯ããªãŒãã³ãœãŒã¹ã³ã³ããŒãã³ãã®åæã§ãã
ãªãŒãã³ãœãŒã¹åæ-OSA
ãã®ããŒã«ã«ã¯3ã€ã®å€§ããªã¹ããããå«ãŸããŠããŸãã
ã©ã€ãã©ãªã®è匱æ§ãæ€çŽ¢ããŸãã ããšãã°ããã®ããŒã«ã¯ãããçš®ã®ã©ã€ãã©ãªã䜿çšããŠããããšãããã³ãã®ããŒãžã§ã³ã®ã©ã€ãã©ãªã«é¢é£ããCVEãŸãã¯ãã°ãã©ãã«ãŒã«è匱æ§ãããããšãèªèããŠããŸãã ãã®ããŒã«ã䜿çšããããšãããšãããŒã«ã¯ã©ã€ãã©ãªãè匱ã§ããããšãèŠåããè匱æ§ã®ãªãå¥ã®ããŒãžã§ã³ã䜿çšããããã«ã¢ããã€ã¹ããŸãã
èªå¯ãããæž æœãã®åæã ããã¯ãŸã ããŸã人æ°ããããŸããããå€åœã§åããŠããå Žåã䜿çšãŸãã¯å€æŽã§ããªããªãŒãã³ãœãŒã¹ã³ã³ããŒãã³ãã䜿çšããããã®ATAãå®æçã«åãåãããšãã§ããŸãã ã©ã€ã»ã³ã¹ã©ã€ãã©ãªã®ããªã·ãŒã«ãããšããããè¡ãããšã¯ã§ããŸããã ãŸãã¯ãå€æŽããŠäœ¿çšããå Žåã¯ãã³ãŒããã¬ã€ã¢ãŠãããå¿ èŠããããŸãã ãã¡ããã圌ãã®è£œåã®ã³ãŒããã¢ããããŒãããã人ã¯ããŸããããããããããªãèªèº«ãå®ãããšãã§ããŸãã
ç£æ¥ç°å¢ã§äœ¿çšãããã³ã³ããŒãã³ãã®åæã ããããéçºãå®äºãããã€ã¯ããµãŒãã¹ã®ææ°ã®ææ°ãªãªãŒã¹ãpromã§ãªãªãŒã¹ãããšããä»®æ³çãªç¶æ³ãæ³åããŠãã ããã 圌ã¯ãã°ãããããã«äœãã§ããŸã-äžé±éãäžã¶æãäžå¹Žã ç§ãã¡ã¯ãããåéãããã»ãã¥ãªãã£ãã§ãã¯ãå®æœããŸããããã¹ãŠãããŸãããããã§ãã ããããçªç¶ããªãªãŒã¹ã®2é±éåŸã«ããã®ã¢ã»ã³ããªã§äœ¿çšãããªãŒãã³ãœãŒã¹ã³ã³ããŒãã³ãã«ç£æ¥ç°å¢ã§é倧ãªè匱æ§ãçºçããŸãã äœãã©ãã§äœ¿çšããããèšé²ããªããšããã®è匱æ§ã¯èŠãããŸããã äžéšã®ããŒã«ã«ã¯ãçŸåšããã ã§äœ¿çšãããŠããã©ã€ãã©ãªã®è匱æ§ãç£èŠããæ©èœããããŸãã ããã¯éåžžã«åœ¹ç«ã¡ãŸãã
æ©èœïŒ
- éçºã®ããŸããŸãªæ®µéã®ããŸããŸãªããªã·ãŒã
- ç£æ¥ç°å¢ã§ã®ç£èŠã³ã³ããŒãã³ãã
- çµç¹ã«ãŒãå
ã®ã©ã€ãã©ãªå¶åŸ¡ã
- ããŸããŸãªãã«ãã·ã¹ãã ãšèšèªã®ãµããŒãã
- Dockerã€ã¡ãŒãžã®åæã
ãªãŒãã³ãœãŒã¹ãåæãããšãªã¢ãªãŒããŒã®ããã€ãã®äŸã
å¯äžç¡æã®ãã®ã¯ãOWASPã®Dependency-Checkã§ãã æåã®æ®µéã§æå¹ã«ããã©ã®ããã«æ©èœããäœããµããŒããããã確èªã§ããŸãã åºæ¬çã«ããããã¯ãã¹ãŠã¯ã©ãŠã補åãŸãã¯ãªã³ãã¬ãã¹ã§ããããã®åºç€ã®èåŸã§ã¯ã€ã³ã¿ãŒãããã«éä¿¡ãããŸãã ã©ã€ãã©ãªã¯éä¿¡ããŸããããããã·ã¥ãŸãã¯ãã®å€ãèšç®ãããµãŒããŒã«ãã£ã³ã¬ãŒããªã³ãããŠè匱æ§ã®ãã¥ãŒã¹ãåä¿¡ããŸãã
ããã»ã¹çµ±å
å€éšãœãŒã¹ããããŠã³ããŒããããå¢çã©ã€ãã©ãª ã å€éšãªããžããªãšå éšãªããžããªããããŸãã ããšãã°ãNexusã¯Event Centralå ã«ããããªããžããªå ã«ã¹ããŒã¿ã¹ããã¯ãªãã£ã«ã«ããŸãã¯ãé«ãã®è匱æ§ããªãããšã確èªããå¿ èŠããããŸãã Nexus Firewallã©ã€ããµã€ã¯ã«ããŒã«ã䜿çšããŠãããã·ãèšå®ãããšããã®ãããªè匱æ§ãé®æãããå éšãªããžããªã«åé¡ãããªããªããŸãã
CIã§ã®çµ±å ã èªåãã¹ãããŠããããã¹ããéçºæ®µéããšã®åé¢ãšåãã¬ãã«ïŒdevãtestãprodã å段éã§ãä»»æã®ã©ã€ãã©ãªãããŠã³ããŒãããŠãäœã§ã䜿çšã§ããŸãããã¹ããŒã¿ã¹ããã¯ãªãã£ã«ã«ãã§é£ãããã®ãããå Žåã¯å¯èœã§ããããã ã«å ¥ã段éã§ããã«æ³šæããå¿ èŠããããŸãã
ã¢ãŒãã£ãã¡ã¯ããšã®çµ±å ïŒNexusããã³JFrogã
éçºç°å¢ãžã®çµ±åã éžæããããŒã«ã«ã¯ãéçºç°å¢ãšã®çµ±åãå¿ èŠã§ãã éçºè ã¯ãè·å Žã®ã¹ãã£ã³çµæã«ã¢ã¯ã»ã¹ããããCVSã«ã³ãããããåã«ã³ãŒããã¹ãã£ã³ããŠè匱æ§ããã§ãã¯ããæ©èœãæã£ãŠããå¿ èŠããããŸãã
CDãžã®çµ±åã ããã¯ç§ãæ¬åœã«æ°ã«å ¥ã£ãŠããããã§ã«ã話ãããã¯ãŒã«ãªæ©èœã§ããç£æ¥ç°å¢ã§ã®æ°ããè匱æ§ã®åºçŸãç£èŠããŸãã ãã®ããã«æ©èœããŸãã
ãããªãã¯ã³ã³ããŒãã³ããªããžã㪠-å€éšã®ããŒã«ãšå éšãªããžããªããããŸãã ä¿¡é Œã§ããã³ã³ããŒãã³ãã®ã¿ãå¿ èŠã§ãã ãªã¯ãšã¹ãããããã·ããå ŽåãããŠã³ããŒãããã©ã€ãã©ãªã«è匱æ§ããªãããšã確èªããŸãã ç§ãã¡ã確ç«ããéçºãšèª¿æŽããå¿ èŠãããç¹å®ã®ããªã·ãŒã«è©²åœããå Žåã¯ãã¢ããããŒããããå¥ã®ããŒãžã§ã³ã䜿çšããããã«ãªããŸãã ãããã£ãŠãã©ã€ãã©ãªã«æ¬åœã«é倧ã§æªããã®ãããå Žåãéçºè ã¯ã€ã³ã¹ããŒã«æ®µéã§ã©ã€ãã©ãªãåãåããŸãããããé«ãããŒãžã§ã³ãŸãã¯ããäœãããŒãžã§ã³ã䜿çšããŠãã ããã
- ãã«ãäžã«ã誰ãæªãããšããã¹ããªãããšããã¹ãŠã®ã³ã³ããŒãã³ããå®å
šã§ããããšãããã³ãã©ãã·ã¥ãã©ã€ãã«å±éºãªãã®ãæã¡èŸŒãŸãªãããšã確èªããŸãã
- ãªããžããªã«ã¯ãä¿¡é Œã§ããã³ã³ããŒãã³ãã®ã¿ããããŸãã
- ãããã€ãããšããããã±ãŒãžèªäœãå床ãã§ãã¯ããŸãïŒããªã·ãŒãšäžèŽããwarãjarãDLãŸãã¯Docker-imageã
- ç£æ¥ã«è¡ããšãã¯ãç£æ¥ç°å¢ã§äœãèµ·ãã£ãŠããããç£èŠããŸããé倧ãªè匱æ§ãçŸãããã©ããã§ãã
åçåæ-DAST
åçåæããŒã«ã¯ãåè¿°ã®ãã¹ãŠã®ãã®ãšæ ¹æ¬çã«ç°ãªããŸãã ããã¯ãã¢ããªã±ãŒã·ã§ã³ã§ã®ãŠãŒã¶ãŒã®äœæ¥ãæš¡å£ãããã®ã§ãã ãããWebã¢ããªã±ãŒã·ã§ã³ã§ããå Žåãã¯ã©ã€ã¢ã³ãã®åäœãã·ãã¥ã¬ãŒããããªã¯ãšã¹ããéä¿¡ããåé¢ã®ãã¿ã³ãã¯ãªãã¯ãããã©ãŒã ãã人工ããŒã¿ãéä¿¡ããŸãïŒåŒçšç¬Šãæ¬åŒ§ãç°ãªããšã³ã³ãŒãã£ã³ã°ã®æåãã¢ããªã±ãŒã·ã§ã³ãã©ã®ããã«åäœããå€éšããŒã¿ãåŠçãããã確èªããŸãã
åãã·ã¹ãã ã䜿çšãããšããªãŒãã³ãœãŒã¹ã®ãã¿ãŒã³ã®è匱æ§ã確èªã§ããŸãã DASTã¯ã䜿çšããŠãããªãŒãã³ãœãŒã¹ãèªèããŠããªããããåã«ãæªæã®ããããã¿ãŒã³ãã¹ããŒãããµãŒããŒã®å¿çãåæããŸãã
-ãããéã·ãªã¢ã«åã®åé¡ããããŸãããããã§ã¯ãããŸããã
ããã«ã¯å€§ããªãªã¹ã¯ããããŸãããã¹ã¿ãŒãäœæ¥ããã®ãšåãã¹ã¿ã³ãã§ãã®ã»ãã¥ãªãã£ãã¹ããå®æœãããšãäžå¿«ãªããšãèµ·ããå¯èœæ§ãããããã§ãã
- ãããã¯ãŒã¯\ã¢ããªã±ãŒã·ã§ã³ãµãŒããŒã®é«è² è·ã
- çµ±åãªãã
- åæãããã¢ããªã±ãŒã·ã§ã³ã®èšå®ãå€æŽããæ©èœã
- å¿
èŠãªæè¡ã«å¯ŸãããµããŒãã¯ãããŸããã
- èšå®ã®è€éãã
AppScanãããããç«ã¡äžãããšãã®ç¶æ³ããããŸãããé·ãéãã¢ããªã±ãŒã·ã§ã³ãžã®ã¢ã¯ã»ã¹ãããã¯ã¢ãŠããã3ã€ã®ã¢ã«ãŠã³ããååŸããŠåãã§ããŸãããæåŸã«ãã¹ãŠããã§ãã¯ããŸãã ã¹ãã£ã³ãéå§ããAppScanãæåã«è¡ã£ãã®ã¯ã管çããã«ã«ç»ãããã¹ãŠã®ãã¿ã³ãæŒããŠãããŒã¿ã®ååãå€æŽããŠããã ã¡ãŒã«ãã©ãŒã ãªã¯ãšã¹ãã§ãµãŒããŒã匷å¶çµäºããããšã§ããã ãã¹ãã«ããéçºã¯æ¬¡ã®ããã«è¿°ã¹ãŠããŸãã
-ã¿ããªãåè«ã§ããïŒ ç§ãã¡ã¯ããªãã«èšé²ãäžããŸããããããŠããªãã¯ã¹ã¿ã³ãã眮ããŸããïŒ
èµ·ãããããªã¹ã¯ãèæ ®ããŠãã ããã çæ³çã«ã¯ãISããã¹ãããããã®å¥åã®ã¹ã¿ã³ããæºåããŸããããã¯ãå°ãªããšãäœããã®åœ¢ã§ç°å¢ã®ä»ã®éšåããéé¢ãããæåã¢ãŒãã§ç®¡çããã«ãæ¡ä»¶ä»ãã§ç¢ºèªããããšããå§ãããŸãã ããã¯ãã³ãã¹ãã§ã-çŸåšæ€èšããŠããªãåªåã®æ®ãã®å²åã
ãããè² è·ãã¹ãã®é¡äŒŒç©ãšããŠäœ¿çšã§ããããšãæ€èšãã䟡å€ããããŸãã æåã®æ®µéã§ã¯ã10ã15ã¹ã¬ããã§ãã€ãããã¯ã¹ãã£ããŒããªã³ã«ããŠãäœãèµ·ãããã確èªã§ããŸãããéåžžãå®è·µã瀺ãããã«ãäœãè¯ãããšã¯ãããŸããã
ãã䜿çšããããã€ãã®ãªãœãŒã¹ã
Burp Suiteã匷調ãã䟡å€ããããŸããããã¯ãã»ãã¥ãªãã£ã®å°é家ã«ãšã£ãŠã¯ãã¹ã€ã¹ãã€ããã§ãã 誰ããããã䜿çšããããã¯éåžžã«äŸ¿å©ã§ãã - enterprise edition. stand alone , - , . , .
: .
mock-, â , .
- â .
- .
- â .
ããã»ã¹
, . â , , OpenSource, - , , Waf .
.
, , , , -.
. , , . , , . , .
API, , , , â AppSec , .
, security- , , , , , . , , â Confluence , Jira -, / CI/CD.
Key Takeaways
. â . , , . â «» , â - high mega super critical, , .
â , . , , . DevSecOps, SecDevOps, .
, : , , , , . â . â .
.
, . , â . - , . , .
â Security Champions .
, , , - â . , . , community, , . , .
.
- False Positive.
- .
- .
- .
- Roadmap .
- .
DevOpsConf 2018. 27 28 DevOpsConf ++ . , , 21 .