Equifaxæ å ±æ¼æ´©äºä»¶ã¨ã¯ãApache Strutsã®èå¼±æ§ãæªç¨ãããç´1.5åä»¶ã®ã¬ã³ã¼ããæ¼æ´©ããäºä»¶ã§ãå²ä¸TOP10å ¥ãããè¦æ¨¡ã®ã¤ã³ã·ãã³ãã§ãããã®äºä»¶ã«ã¤ãã¦ã¯ããã®è¦æ¨¡ãæ»æãã¯ã¿ãé¡èã§ãããã¨ããããè²ã å¦ã¶ã¹ãç¹ãå¤ãã¤ã³ã·ãã³ãã ã¨èãã¦ãã¾ãã
2018å¹´12æ19æ¥ã«ãç±³å½ä¸é¢ç£æ»æ¿åºæ¹é©å§å¡ä¼ï¼The US House of Representatives Committee on Oversight and Government Reformï¼ãEquifaxã«é¢ããå æ¬çãªã¬ãã¼ããå ¬éãã¾ããï¼ãã®å¾ããã©ã³ãæ¿æ¨©ã«ããGovernment Shutdownã®å½±é¿ã§ã¢ã¯ã»ã¹ã§ããªãããã«ãªã£ã¦ãã¾ããããç¾å¨ã¯ã¢ã¯ã»ã¹ã§ããããã§ãï¼ã
é常ã«é¢ç½ãã¬ãã¼ãã§ãããããæ¡ä»¶ä»ã翻訳ãè¡ãã¾ããã
- Google翻訳ãä¸è¨³ã¨ãã¦ããã®å¾äººéã«ãã翻訳
- 注éã«ã¤ãã¦ã¯ç¿»è¨³ãçç¥
- è¦ç´ããªãï¼ãã®ããã翻訳ã®åèªãããã¦ããå¯è½æ§ãããã¾ãï¼
é常ã«å æ¬çã§ãããã¾ã伿¥ãã©ãã®ãããªã¬ãã¼ãã§ãã®ã§ããã²ç¿»è¨³ããèªã¿ããã ãããã¨æãã¾ãã
ã¾ãã以ä¸ã¯ãèªãã§ããã¹ãã¬ãã¼ãã ã¨æãã¾ãã
ä¸ã¤ã¯ãç±³å½æ¿åºç£æ»é¢ï¼GAOï¼ã¬ãã¼ãã§ãã
ããä¸ã¤ã¯ãä¸ä½è°å¡Elizabeth Warren女å²ã®ã¬ãã¼ãã§ãã
ããã«ããããè¸ã¾ãããµããªã使ãã¾ããï¼åç §URLããªããã®ã¯åºæ¬çã«ä¸è¨ã¬ãã¼ããåç §ãã¦è¨è¼ãã¦ãã¾ãï¼
åºç¤æ å ±
Equifax社ã¨ã¯ï¼
- ç±³å½å ã§ä¸å¤§æ¶è²»è ä¿¡ç¨æ å ±ãµã¼ãã¹ã®ä¸ã¤ï¼æ®ãï¼ç¤¾ï¼Experian社ã¨TransUnion社ï¼
- å ¨ä¸ç24ãå½ã§ãã¸ãã¹ãå±éãã¦ããã10å人ï¼å³å¯ã«ã¯ã8å2000ä¸äººï¼è¿ãæ¶è²»è å人ã®ä¿¡ç¨æ å ±ã¨ï¼å人ï¼å³å¯ã«ã¯9100ä¸äººï¼ä¼æ¥ã®ä¿¡ç¨æ å ±ãåãæ±ã£ã¦ããããã®ãã¼ã¿éã¯ããæ¯æ¥ãç±³å½è°ä¼å³æ¸é¤¨ã®1200åã®ãã¼ã¿ãåãæ±ã£ã¦ããããã¨ã«ç¸å½ããã
- ã¯ã¬ã¸ããã¹ã³ã¢ãè©ä¾¡ãããããã¯ã¬ã¸ããã«ã¼ãå©ç¨æ´ãå ¥åºå½å±¥æ´ãåå ¥ãè³ç£ãéè¡å£åº§ã使ãåå ¥å±¥æ´ãæ¯æãå±¥æ´ãªã©å種å人æ å ±ãåéãã¦ãããå人è³ç£ãã¼ã¿ã®ä¾¡å¤ã¯ã20å ãã«ã«ç¸å½ããè³ç£ãæã£ã¦ããã
- CEO Richard Smithæ°ã2005å¹´ã«å°±ä»»ãã¦ä»¥éãè²·åãéãã¦äºæ¥ãæ¡å¤§ãæ ªä¾¡ã38ãã«ï¼2005.12ï¼â 138ãã«ï¼2017.09ï¼ã¾ã§ä¸æãã¤ã³ã·ãã³ãå ¬è¡¨åæ¥ã®å¸å ´ä¾¡å¤ã¯ãç´170åãã«ã§ããã33åã®åçãæã¤å¤§ä¼æ¥ã«æé·ããã
ACISã·ã¹ãã
- æ¶è²»è è¦æ ãã¼ã¿ã«ã§ããACISã·ã¹ãã ï¼Automated Customer Interview Systemï¼
- æ³è¦å¶å¯¾å¿ã®ããã1970年代ã«ã¤ã³ã¿ã¼ãããå ¬éåãã«éçºãããã·ã¹ãã ã§ããä¿¡ç¨ãã¡ã¤ã«ã®èª¤ããè¨æ£ããããç°è°ãç³ãç«ã¦ããã¨ãã§ãããµã¼ãã¹ã®æ ¹å¹¹ãæ ããµã¼ãã¹
ã¤ã³ã·ãã³ã詳細
ã¤ã³ã·ãã³ã詳細ãããã«ç¤ºãã¾ãã
ã¿ã¤ã ã©ã¤ã³
翻訳ã主è¦ãªã¤ãã³ãã®ã¿ã¤ã ã©ã¤ã³ããåèã«ãã¦ãã ããã
æä½éã®ã¿ã¤ã ã©ã¤ã³ã以ä¸ã«ç¤ºãã¾ãã
- 2017/03/06ï¼Apache Strutsã®èå¼±æ§ãå ¬é
- 2017/03/10ï¼Apache Strutsã®èå¼±æ§ã使ã£ãåµå¯è¡çºãè¡ãããçè·¡ãã
- 2017/03/15ï¼Apache Strutsã®èå¼±æ§ãçºè¦ããããã«ã¹ãã£ã³ãå®è¡
- 2017/05/13ï¼ï¼èª¿æ»ããï¼æ å ±æ¼æ´©ã«ã¤ãªããä¾µå ¥ãåããã¨ãããæåã®æ¥
- 2017/07/29ï¼Equifaxã䏿£ãªéä¿¡ãæ¤ç¥ãããµã¤ããå®å ¨åæ¢
- 2017/09/07ï¼Equifaxãæ å ±å ¬éãæ ªä¾¡ã¯ã35%ä¸è½
侵害åå
2017å¹´3æ7æ¥ã«å ¬éãããWebã¢ããªã±ã¼ã·ã§ã³ãã¬ã¼ã ã¯ã¼ã¯ Apache Struts2ã®æ¢ç¥ã®èå¼±æ§ CVE-2017-5638ï¼S2-045/S2-046ï¼ãæªç¨ãããããã§ãã
以ä¸ã®ä¸éæ å ±ã¯ä»¥ä¸ã®éãã§ãã
- Equifaxå é¨ã§US-CERTããå½è©²èå¼±æ§ã«é¢ããæ å ±ãå ±æããã¦ãããèå¼±æ§ã®å±éºåº¦ãããEquifaxå é¨ã§ã¯48æé以å ã«ããããå½ã¦ãã«ã¼ã«ã¨ãªã£ã¦ãããããããã人çºçãªãã¹ãã«ãããããé©ç¨ã¯è¡ãããªãã£ãã
- ãã®å¾ã03/15ã«å é¨ã§ã¹ãã£ã³ãå®è¡ããããApache Strutsã使ããã¦ããã¤ã³ãã³ããªãè¡ããã¦ããªããã¨ããããçºè¦ã§ããããã®ããã7ææ«ã«ã¤ã³ã·ãã³ããçºè¦ããã¾ã§ã®ç´4.5ãæéãããããé©ç¨ããã¦ããªãã£ãã
- CVE-2017-5638ã¯ãCVSS Base Scoreã10.0ï¼Criticalï¼ãæã¤ããªã¢ã¼ãããä»»æã®ã³ãã³ãå®è¡ãã®èå¼±æ§ã§ããããã®ãããå ¬éããæ°æ¥éã«æ»æãçºçããæ»æã³ã¼ããGUIæ»æãã¼ã«ãå ¬éãããã
- å½è©²èå¼±æ§ã¯ãæ¥æ¬ã§ã大ããªå½±é¿ãããããããGMOãã¤ã¡ã³ãã²ã¼ãã¦ã§ã¤ç¤¾ãæ§ç¯ããï¼ã¤ã®ãµã¤ãï¼é½ç¨ã¯ã¬ã¸ããã«ã¼ããæ¯æããµã¤ããä½å® éèæ¯æ´æ©æ§ï¼ã§ã¯ãã¯ã¬ã¸ããã«ã¼ãæ å ±ãä¸é¨å«ã70ä¸ä»¶ã®æ å ±æ¼æ´©ã¨ãã大ããªã¤ã³ã·ãã³ãã«ãªã£ã*1ã
- 䏿¹ãNTTã³ãã¥ãã±ã¼ã·ã§ã³ã¯ãOCN IDãµã¼ãã§Apache Struts 2ãå©ç¨ãã¦ãããã¨ã夿ãã3/7ã®èå¼±æ§å ¬éå¾ã3/8ã®æãµã¤ã忢ãè¡ã夿ãããã¨ã§ç¥ããã¦ããã*2
ãã詳ããã¾ã¨ãã¯ãpiyologãåç §ãã¦ãã ããã
æ¼æ´©ããæ å ±
1å4550ä¸ä»¶ã®ç±³å½æ¶è²»è æ å ±ãæ¼æ´©ããå¤§è¦æ¨¡æ¼æ´©ã®ä¸ã¤ã¨ãã¦ç¥ããã¦ãã¾ãã
ç±³å½è¨¼å¸åå¼å§å¡ä¼ã®çºè¡¨ã«ããã以ä¸ã®æ å ±ãæ¼æ´©ããã¨ãã¦ç¥ããã¦ãã¾ãï¼ä»¥ä¸ã«ã翻訳çãè¼ãã¦ãã¾ãï¼ãç´1.5åã®ç¤¾ä¼ä¿éçªå·ãæ¼æ´©ãã¦ãããã¨ããã彿°ã®ç´åæ°ã®æ å ±ãæ¼æ´©ããã¨èãããã¾ãã

調æ»ã¯ä¸»ã«ç±³å½ä¸»å°ã§è¡ããã¦ãã¾ãããã°ãã¼ãã«ä¼æ¥ã§ããããç±³å½æ¶è²»è 以å¤ã®æ å ±ãæ¼æ´©ãã¦ãã¾ããä¾ãã°ãBBCã«ããã¨ãå½¹69ä¸ä»¶ã®æ å ±ãæ¼æ´©ããã¨å ±éããã¦ãã¾ãã
äºæ 対çè²»ç¨
äºæ 対å¿è²»ç¨ã«ã¤ãã¦ã¯ãç¾å¨ãåãã¦ãããã確å®çãªãã¨ãè¨ãã¾ãããã財åå ±åæ¸ãã以ä¸ã®ãã¨ãèªã¿åãã¾ãã
- 2018å¹´12ææ«ã¾ã§ã®ï¼å¹´éã®ç·è²»ç¨ã¯ã5å6520ä¸ãã«ï¼$565.2Mï¼ã«ãªãã
- ãµã¤ãã¼ä¿éºã¯ã1å2500ä¸ãã«ï¼$125Mï¼ãæãå¥ç´ã«ãªã£ã¦ãããï¼å¹´éã«ãããå ¨é¡æ¯æããã¦ãããã«ãã¼çã¯22.1%ã§ãããããã¯æ¢åã®ã¿ã¼ã²ãã社ããã¼ã ã»ãã社ã®ã«ãã¼çã¨æ¯è¼ããã¨ä½ããï¼è©³ç´°ã¯ã³ãã©ï¼
- å®è³ªçè² æ é¡ã¯ã4å4020ä¸ãã«ï¼$440.2Mï¼ã§ããã
Â
2017å¹´ã®æ¯åº
2017å¹´ã®ååæå ±åæ¸ãã¾ã¨ããã¨ã以ä¸ã®éãã§ãã
2018å¹´ã®æ¯åº
2018å¹´ã®ååæå ±åæ¸ãã¾ã¨ããã¨ã以ä¸ã®éãã§ãã

- ITã¨ãã¼ã¿ã»ãã¥ãªãã£ã¯ãã¢ããªã±ã¼ã·ã§ã³ããããã¯ã¼ã¯ããã¼ã¿ã»ãã¥ãªãã£ãã·ã¹ãã éçºè²»ãLock & Alertãµã¼ãã¹ã®ç«ã¡ä¸ããªã©ãæè¡åºç¤ã®ç§»è¡ã³ã¹ãã§ããã
- ãªã¼ã¬ã«ã»èª¿æ»è²»ç¨ã¨ã¯ãæ³çãæ¿åºå¯¾å¿ãè¦å¶å¯¾å¿ãªã©ã®å¯¾å¿è²»ç¨ã§ããã
- Product Liablityã¨ã¯ãTrustedIDãµã¼ãã¹ãå©ç¨ããããã®ã³ã¹ããæå³ããã
- 2017å¹´ã«5000ä¸ãã«æ¯æãããä¿éºéãã2018å¹´ã¯7500ä¸ãã«æ¯æãããã
ACISã·ã¹ãã ã«å¯¾ããæ»æ
- 3æ10æ¥æç¹ã§ãæ¬èå¼±æ§ãå©ç¨ããæ»æã®çè·¡ãããä½ããwhoisã³ãã³ãã®å®è¡çè·¡ã®ã¿ã§ããããåµå¯ãã®è¦ç´ ãå¼·ãã¨å¤æããããæ¬ä»¶ã®æè¡ç調æ»ã«å½ãã£ãMandiant社ã¯ãä»åã®æ å ±æ¼æ´©ã«ã¤ãªãã5æ13æ¥ããå§ã¾ã£ãæ å ±æ¼æ´©æ»æã¨ã®é¢é£æ§ã示ã証æ ã確èªã§ãã¦ããªãã
-
5æ13æ¥ãæ»æè ã¯Equifaxã¸ã®ãµã¤ãã¼æ»æãéå§ãæ»æã¯76æ¥éç¶ãã
-
Equifaxã®ãããã¯ã¼ã¯ãé éæä½ãããããWeb Shellï¼Webãã¼ã¹ã®ããã¯ãã¢ï¼ãé ç½®ãå é¨ã®ãããã¯ã¼ã¯ããã¼ã¿ãã¼ã¹ãã»ã°ã¡ã³ãåã§ãã¦ããªããã¨ãæå·åããã¦ããªãèªè¨¼æ å ±ï¼ã¦ã¼ã¶åã¨ãã¹ã¯ã¼ãï¼ãå«ããã¡ã¤ã«ããã¡ã¤ã«å ±æä¸ã«é ç½®ããã¦ãããã¨ãªã©ãããACISã·ã¹ãã ã¨ç¡é¢ä¿ãªãã¼ã¿ãã¼ã¹48åã¸ã¢ã¯ã»ã¹ãã¦æ å ±ãåå¾ãç´9000åã®ãªã¯ã¨ã¹ããçºè¡ãããã¡265åã¯å人æ å ±ãå¼ãåºãã¯ã¨ãªã ã¨æ¨å®ããã¦ããã
- åå¾ããå人æ å ±ã¯ãã¡ã¤ã«ãå§ç¸®ãã¦ãWebããã¢ã¯ã»ã¹å¯è½ãªãã£ã¬ã¯ããªã¸é ç½®ãã¦æ å ±æåºãè¡ããï¼ä¸é¨ãWeb Shellã®æ©è½ãå©ç¨ããæ¨¡æ§ï¼
- æ»æãéãã¦ã35種é¡ã®IPã¢ãã¬ã¹ã使ã£ã¦ACISã·ã¹ãã ã¨ããåããã¦ããã
Project Sierraï¼ã¤ã³ã·ãã³ã対å¿
ã¤ã³ã·ãã³ã対å¿ã¨ãã¦ã以ä¸ã宿½ãã¦ããã
- æ³å¾äºåæï¼King and Spaldingï¼ã¨å¥ç´ããªã¼ã¬ã«ã¢ããã¤ã¶ã¨ãã¦å¥ç´
- Equifaxã®ã»ãã¥ãªãã£ãã¼ã + Mandiant社ã«ããæè¡èª¿æ»
Project Spartaï¼ï¼æï¼æ¥ã¸ã®æ å ±å ¬éã«åãã顧客対å¿
æ å ±å ¬éã®æºåã®ããã以ä¸ã®ä½æ¥ãè¡ã£ã¦ããã
- å°ç¨ãµã¤ãã®ä½æï¼æ å ±æ¼æ´©æç¡ï¼å種ãµã¼ãã¹ã¸ã®ç»é²ï¼
- 500åè¦æ¨¡ã®ã¹ã¿ãããé ç½®ããç·æ¥ã³ã¼ã«ã»ã³ã¿ã¼ã®ç«ã¡ä¸ã
- ã¤ã³ã·ãã³ããåããäºå¾å¯¾å¿ãµã¼ãã¹ã¸ã®æ¡å ï¼ï¼å¹´éç¡åï¼
- ã¯ã¬ã¸ããã«ã¼ãå©ç¨ç£è¦ãµã¼ãã¹ï¼Credit Monitoringï¼
- ã¢ã¤ãã³ãã£ãã£çé£ç£è¦ãµã¼ãã¹ï¼Identity Theft Serviceï¼
æ ¹æ¬åå ã»æ¨å¥¨ç
ç±³å½ä¸é¢ç£æ»æ¿åºæ¹é©å§å¡ä¼ã«ããæ¨å¥¨ç
ã»ãã¥ãªãã£ä¸ã®ä»åã®åé¡ç¹ã¨ãã¦ãæ¬ã¬ãã¼ãã§ã¯ï¼ç¨®é¡æãã¦ãã¾ãã
-
ã»ãã¥ãªãã£ä¸ã®æ¸å¿µï¼ï¼Sunã¢ããªã±ã¼ã·ã§ã³ãµã¼ãã¨Equifaxãããã¯ã¼ã¯ã®ä»ã®é¨åã¨ã®éã«ã»ã°ã¡ã³ãã¼ã·ã§ã³ã¯ããã¾ãããã¤ã³ã¿ã¼ãããããã¢ããªã±ã¼ã·ã§ã³ãµã¼ããé éæä½ã§ããæ»æè ã¯ãã°ãã¼ãã«ã«ãEquifaxãããã¯ã¼ã¯å ã®ä»ã®ããã¤ã¹ããã¼ã¿ãã¼ã¹ããµã¼ãã¸ç§»åãããã¨ãã§ãã¾ããï¼ããã«ããã°ããã¼ã¿ãã¼ã¹å ãåé¢ããã¦ããªãã£ãã¨èãããã¾ãï¼
-
ã»ãã¥ãªãã£ä¸ã®æ¸å¿µï¼ï¼ãã¡ã¤ã«æ´åæ§ç£è¦ï¼FIMï¼File Integrity Monitoringï¼ã¯ãç°å¢å ã«ããã許å¯ããã¦ããªã夿´ãè¦åã»æ¤åºã§ãã¾ãããã¢ããªã±ã¼ã·ã§ã³ãWebãµã¼ãã®ã©ã¡ãã«ãè¨å®ããã¦ãã¾ããã§ããã
-
ã»ãã¥ãªãã£ä¸ã®æ¸å¿µï¼ï¼Sunã·ã¹ãã ã¯ãç°å¢å ¨ä½ã§å ±æãã¡ã¤ã«ã·ã¹ãã ã使ç¨ãã¦ãããããããã·ã¹ãã ããå¥ã®ã·ã¹ãã ã¸ã©ã®ç®¡çãã¡ã¤ã«ã«ãã¢ã¯ã»ã¹ã§ãã¾ããããã«ãããããã·ã¹ãã ã«ããã¡ã¢ãè¨å®ãã¡ã¤ã«ã«ãä»ã®ã·ã¹ãã ããã¢ã¯ã»ã¹ã§ããããã«ãªãã¾ãã
-
ã»ãã¥ãªãã£ä¸ã®æ¸å¿µï¼ï¼ Webãµã¼ããã°ã¯14æ¥éããªã³ã©ã¤ã³ã§30æ¥éããä¿æãããªããããæªæã®ããã¢ã¯ãã£ããã£ãåç¾ãããã¨ã¯å°é£ã§ãã»ã¼ä¸å¯è½ã§ãã
-
ã»ãã¥ãªãã£ä¸ã®æ¸å¿µï¼ï¼ã¢ããªã±ã¼ã·ã§ã³å ã§ä½¿ç¨ããã¦ãããªã½ã¼ã¹ã®å®å ¨ãªã½ããã¦ã§ã¢æ£å¸ã管çããã¦ãã¾ãããããã¯ãåã ã®ãªã¼ãã³ã½ã¼ã¹ã³ã³ãã¼ãã³ããååã«çè§£ããããææ¸åããã¦ããªããããåã ã®ã³ã³ãã¼ãã³ãã®èå¼±æ§ãè¿ éã«ç¹å®ãããã¨ããããæ½å¨çãªèå¼±æ§ãç¹å®ããããã®å®å ¨ãªã³ã¼ãã¬ãã¥ã¼ãå¿ è¦ã§ãã
-
ã»ãã¥ãªãã£ä¸ã®æ¸å¿µï¼ï¼ä¸è¬çãªè¦³å¯ã¨ãã¦ãã¬ã¬ã·ã¼ãªSun / Solarisã·ã¹ãã ã¸ã®ä¸è²«ããã¿ã¤ã ãªã¼ãªãããé©ç¨ãæ¸å¿µäºé ã§ãã
ãã®ä»ãã¬ãã¼ãããèªã¿åãã課é¡ã以ä¸ã«åæãã¾ãã
Mandiant社ã«ããæ¨å¥¨ç
ã»ãã¥ãªãã£ä¸ã®ä»åã®åé¡ç¹ã¨ãã¦ãMandiant社ã¯ï¼ï¼ç¨®é¡ã®æ¨å¥¨çãä¸ãã¦ãã¾ãã
- èå¼±æ§ã¹ãã£ã³ããã³ããã管çã®ããã»ã¹ã»æé ãå¼·åããã
- ããã¯ã¨ã³ããã¼ã¿ãã¼ã¹ã«ä¿æããã¦ããæ©å¯ãã¼ã¿ã®ç¯å²ã縮å°ããã
- éè¦ãªãã¼ã¿ãã¼ã¹å ã«æ ¼ç´ããã¦ãããã¼ã¿ã«ã¢ã¯ã»ã¹ããããã®å¶éã¨ç®¡çãå¼·åããã
- ã¤ã³ã¿ã¼ãããå ¬éã·ã¹ãã ããããã¯ã¨ã³ããã¼ã¿ãã¼ã¹ããã³ãã¼ã¿ä¿åå ã¸ã®ã¢ã¯ã»ã¹ãå¶éããããããããã¯ã¼ã¯ã»ã°ã¡ã³ãã¼ã·ã§ã³ãå¼·åããã
- 追å ã®WAFï¼Web Application Firewallï¼ãå±éããã·ã°ããã£ãæå¹ã«ãã¦æ»æããããã¯ããã
- ã¢ããªã±ã¼ã·ã§ã³ãWebãµã¼ãã¸ã®ãã¡ã¤ã«æ´åæ§ç£è¦æè¡ã®å±éãæ¥ãã
- ãããã¯ã¼ã¯ãã¢ããªã±ã¼ã·ã§ã³ããã¼ã¿ãã¼ã¹ãã·ã¹ãã ã¬ãã«ã«ããã¦ã追å ã®ãã°åå¾ãè¡ãã
- ç¹æ¨©ã¢ã«ã¦ã³ã管çï¼PAMï¼Privileged Account Managementï¼è£½åã®å±éãæ¥ãã
- 追å ã®ã¤ã³ã©ã¤ã³ãããã¯ã¼ã¯ãã©ãã£ãã¯å¾©å·è£ ç½®ãå°å ¥ããæå·éä¿¡ã¸ã®ãã¿ããåããè¡ãã
- 追å ã®EDRï¼Endpoint Detection and Responseï¼ãã¯ããã¸ã¼ãå°å ¥ããã
- 追å ã®é»åã¡ã¼ã«ä¿è·ã»ç£è¦æè¡ãå°å ¥ããã
ç±³å½æ¿åºç£æ»é¢ã«ããã¬ãã¼ã
ç±³å½æ¿åºç£æ»é¢ã«ããã¬ãã¼ãã«ããã°ãï¼ç¨®é¡ã®å¼±ç¹ãææãã¦ãã¾ãã
- ã½ããã¦ã§ã¢ã®æ´æ°
- ã½ããã¦ã§ã¢æ§æ
- ã¢ã¯ã»ã¹å¶å¾¡
- ãããã¯ã¼ã¯ç£è¦
- å¢çé²å¾¡
è£è¶³çãªèª²é¡
ä¸è¨ã«ä¸ãããªãä»éçãªèª²é¡ã以ä¸ã«ç¤ºãã¾ãã
課é¡ï¼ï¼ã¡ã¼ãªã³ã°ãªã¹ãã®ç®¡ç
- US-CERTçµç±ã§æ¬èå¼±æ§ã«é¢ããéç¥ãåãåã£ã¦ãããGTVMãã¼ã ï¼Global Threat and Vulnerability Managementãã¼ã ï¼ã®ã¡ã¼ãªã³ã°ãªã¹ãçµç±ã§430åã«å¯¾ãã¦ãã®å 容ãå ±æãã¦ãããã¾ãã3/16æç¹ã§ããGTVMãã¼ã è³æã«ã¦ãããé©ç¨ããªãã¤ã³ããã¦ããã
- GAOã¬ãã¼ãã«ããã°ããã®ã¡ã¼ã«åä¿¡è ãªã¹ãã¯æ´æ°ããã¦ããããé©åãªæ å½è ã«å¯¾ãã¦ã¡ã¼ã«ãå±ãã¦ããªãã£ãã¨ææããã¦ããã
- 10æï¼æ¥ã«ãACISç°å¢ã®æ å½ã§ãã£ãGraeme Payneæ°ã¯ã3æ9æ¥ã®Apache Strutsãããã¢ã©ã¼ãã®è»¢éã«å¤±æãããã¨ãçç±ã«è§£éãããã
課é¡ï¼ï¼ããã管çããã»ã¹ã¨ã¹ãã£ã³
- ããã管çããã»ã¹ãé©åã«è¡ããã¦ããããACISã·ã¹ãã ã¸ã®ãã¸ãã¹ææè ãæ å½è ããããé©ç¨ã®è²¬ä»»è ãæç¢ºåããã¦ãããããããé©ç¨ã«ã¤ãã¦ãå®éç¨ã¬ãã«ã§è²¬ä»»ç¯å²ãä¸æç¢ºã§ãããç¥èãæã¤å人ã«ããã«ãã¼ããã¦ããã¨èããããã
- èå¼±æ§ã¹ãã£ã³ã宿½ãã¦ããããæ¤åºããã¦ããªãï¼ã¬ãã¼ãã§ã¯ãã¤ã³ãã³ããªç®¡çãã§ãã¦ããªããã¨ãã³ã³ããã¹ããã¹ã«èå¼±æ§ã¹ãã£ã³ã宿½ãã¦ããªããã¨ãæ¤åºã§ããªãã£ãã¨ãã¦ãããä½ãããã®Apache Strutsèå¼±æ§ã¯ããã¼ã«ã«ããã¹ãã£ã³ã§ã¯æ¤åºã§ããªãå¯è½æ§ãããã¨èãããããï¼
課é¡ï¼ï¼è¨¼ææ¸ç®¡çããã»ã¹ï¼ç®¡çã»ãã¥ãªãã£æ©è½è¨å®ã®ä¸åï¼
å é¨ã®ã»ãã¥ãªãã£è¨¼ææ¸ã®æå¹æéãåãã¦ãããSSLå¯è¦åã¢ãã©ã¤ã¢ã³ã¹ã¯ãè¨¼ææ¸ããªããããæå·åéä¿¡ãè¤åããªãç¶æ ã§ãIDS/IPSãééãã¦ãããã¨ã«ãªãã¾ãããã®ãããIDS/IPSã¯æ¤ç¥ãããã¨ãã§ãã¾ããã§ããã
ã»ãã¥ãªãã£è¨¼ææ¸ã¯ã2016å¹´1æ31æ¥ã§æå¹æéãåãã¦ããã324åã®è¨¼ææ¸ãæå¹æéåãã«ãªãã19ãæééä¿¡ãç£è¦ã§ãã¦ããªãç¶æ ãç¶ãã¦ãã¾ãã
ã¾ããæ¬å ±åæ¸ã«ã¯æ¸ããã¦ããªãããæ¨æ¸¬ã«ãªãã¾ããã19ãæãã¢ã©ã¼ãããªããã°Security Operationãã¼ã ãæ¤ç¥çã®ä½ãã«æ°ä»ãã¹ãã ã¨ãèãããã¾ãã

課é¡ï¼ï¼ITçµç¹æ§é ã®ä¸å
Equifaxã®ã¬ãã¼ããèªã¿è§£ãã¨ãã»ãã¥ãªãã£ãã¼ã ã¨ITãã¼ã ã®ãµã¤ãåããã£ããã¨ãæµ®ã彫ãã«ãªã£ã¦ãã¾ããç¹ã«ãã»ãã¥ãªãã£ãã¼ã ã¯CLOï¼Chief Legal Officerï¼é ä¸ã«ãããããITãã¼ã ã¨ã®é£æºã責任ç¯å²ãæç¢ºã«ãªãããä»åã®äºè±¡ãçºçãã¦ããã¨èãããã¾ãã
- CIO Robert Webbæ°ã¨CSO Tony Spinelliæ°ãåºæ¬çã«æè¦ã®ä¸ä¸è´ãå¤ããããã»ãã¥ãªãã£æ©è½ãITé¨éããæ³åé¨ã«ç§»ç®¡ããã以éãCLOï¼Chief Legal Officerï¼ã "Head of Security"ã¨ãã¦æ©è½ãã¦ããã
- ãã®ä½å¶ã¯æ å ±æ¼æ´©ã¤ã³ã·ãã³ãçºè¦ã¾ã§å¤åãããæ å½è ãå¤åããå¾ããCIOã¨CSOã¨ã®ãã¼ããã¼ã·ããã¯é²ã¾ãããµã¤ãåããã¦ããï¼ãã®ããã両ãã¼ã ã®è²¬ä»»ç¯å²ãæç¢ºã«ãªã£ã¦ããªãã£ãã¨èããããï¼ã
- 2016å¹´ã«ITå ã®çµç¹ä½å¶å¤æ´ãåããGraeme Payneæ°ãIT Risk and Compliance Groupãæ å½ãããã¨ã«ãªã£ãããã®ãããPayneæ°ã¯CLOé ä¸ã«ããã»ãã¥ãªãã£ãã¼ã ã¨ã®èª¿æ´ã»é£æºãæ å½ã¨ãããã¨ã«ãªã£ãã
- ã¾ããCSO Susan Mauldin女å²ã¯ã1983å¹´ããHewlett Packard社ã®ã½ããã¦ã§ã¢ã¨ã³ã¸ãã¢ã¨ãã¦ãã¯ããã¸ã¼åéã®ãã£ãªã¢ãéå§ããä»ã®ä¼æ¥ã§ITã¨ã»ãã¥ãªãã£ã®å½¹è·ãçµé¨ããå¾ããã®å½¹è·ã«ã¤ãã¦ããããããã大å¦ã§ITãã»ãã¥ãªãã£ãå°éçã«å¦ãã çµé¨ããªãããã°åå¾ãï¼ï¼æ¥ã§ååã§ãããªã©ã¨å°ãã»ãã¥ãªãã£å°éå®¶ã¨ãã¦å¸¸èã¨ã¯ç°ãªãèããæã£ã¦ããã

課é¡ï¼ï¼ãµã¤ãã¼ã»ãã¥ãªãã£ã«é¢ããçµå¶å±¤ã®åªå 度
Equifaxã§ã¯ãã»ãã¥ãªãã£ãéè¦ããã¦ãã¾ããã§ããã
- CEO Richard Smithæ°ã¯ãååæã«ä¸åº¦ã®çµå¶ä¼è°ã§ãããã»ãã¥ãªãã£ã®ç¶æ ã確èªãã¦ããããã¿ã¤ã ãªã¼ã«æ å ±ãåãåã£ã¦ãããªãã£ãã
- CSO Susan Mauldin女å²ã¯ãçµå¶å±¤ã ã¨è¦ãªããã¦ããªãããããã®ãã¼ãã£ã³ã°ã«åå ãã¦ããããCLOçµç±ã§å ±åãè¡ããã¦ããã
- 2015å¹´ã®ããã管çããã»ã¹ã®ç£æ»ã§ï¼é ç®ã®ææãåãã¦ãããã対çãè¡ããã¦ããªãã£ãã
課é¡ï¼ï¼è¤éãã¤ã¬ã¬ã·ã¼ãªITç°å¢
- ACISç°å¢ã¯ã1970年代å¾åã«æ§ç¯ãããã·ã¹ãã ã§ãããè¤éãã¤ã¬ã¬ã·ã¼ãªITç°å¢ãç¶ç¶ãã¦ä½¿ãç¶ãã¦ãããACISã·ã¹ãã ã¯ãç¾å¨ãéç¨ããã¦ããããã©ã³éçºè ã«ãã£ã¦ãªãã¨ãåç¶ãã¦ããï¼Sun Microsystems社ãéçºããSolaris OSã«ç¬èªéçºãçµã¿è¾¼ãã§ãããããªãèæ½åãã¦ããã¨æãããï¼ã
- ITç°å¢ãè¤éã§ããããããã©ã¬ã³ã¸ãã¯èª¿æ»ã«æéãããã£ãã¨ãããã¦ãããã¾ããæ¼æ´©ä»¶æ°ãç¹å®ããä¸ã§ããã¼ã¿ã®æå³ã»æ´åæ§ãç¶æããä¸ã§ããã¼ã¿ãã¼ã¹ç®¡çè ã¨ååããå¿ è¦ããããããã®ãªã¹ããé©åã«ç®¡çããã¦ããªãã£ãã
- ã¤ã³ã·ãã³ãçºè¦å¾ã®èª¿æ»ãããSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ãã¢ã¯ã»ã¹ã³ã³ããã¼ã«ã®ä¸åãªã©ãæ¤åºããã¦ãã¾ãããã®ãããèå¼±æ§è¨ºæãªã©ã®å®æ½ããã»ã¹ãªã©ãé©åã«è¡ããã¦ããªãã£ãã¨èããããã
- ç¾å¨ã§ã¯ãProject Bluebirdã¨å¼ã°ããããã¸ã§ã¯ããåãã¦ãããACISã·ã¹ãã ã®åæ§ç¯ãè¡ããã¦ãããÂ
ä¸éããè¢«å®³ç¶æ³
æ¬ã¤ã³ã·ãã³ãã«ä¼´ãã以ä¸ã®ãããªå½±é¿ãåºã¦ãã¾ãã
伿¥ä¾¡å¤ã®å®ä¾¡ã¨æ ¼ä»ã
- ã¤ã³ã·ãã³ãå ¬éå¾ãç´140ãã«ã§å®å®ãã¦ããæ ªä¾¡ãã35ï¼ ç¨åº¦æ¥è½ãã¦ã93ãã«ç¨åº¦ã«ãªã£ãã
- Moody's社ã¯2017å¹´ã®å¤§éãã¼ã¿æ¼æ´©ã«ããæå¤±ãåºãç¶ãããã¨ãããEguifaxç¤¾ã®æ ¼ä»ãè¦éããã¹ãã¼ãã«ãããã¬ãã£ãã«å¼ãä¸ãããæ ¼ä»ãè¦éãã®ä¿®æ£ã¯ãEquifax社ã仿åãSECï¼ç±³è¨¼å¸åå¼å§å¡ä¼ï¼ã«æåºããææ¸ãåãã¦å®æ½ãããã2017å¹´ã«çºçãã1å4000ä¸ä»¶ãè¶ ããæ å ±æµåºé¢é£ã§è¦ãã2019å¹´1Qã®6å9000ä¸ãã«ã®æ¯åºãçç±ã«æãã¦ãããããã¯ä¿¡ç¨æ ¼ä»ãæ©é¢ãããµã¤ãã¼æ»æã«ãã財æ¿çå½±é¿ãçç±ã«ã伿¥ã®æ ¼ä»ãè¦éããå¼ãä¸ããåã®äºä¾ã¨ãã¦ç¥ããã¦ããã
æ³è¦å¶ã¸ã®æµè§¦ã¨æ¿åºæ©é¢çã«ãã調æ»
- ä»åã®æ å ±æ¼æ´©ã¯ã以ä¸ã®æ³è¦å¶ã«é¢ä¿ãã¦ããã
- é£é¦åå¼å§å¡ä¼æ³ï¼Federal Trade Commission Actï¼
- ãããã»ãã©ã³ã¯æ³ï¼Dodd-Frank Actï¼
- å ¬æ£ä¿¡ç¨å ±åæ³ (Fair Credit Reporting Act)
- ã°ã©ã ã»ãªã¼ãã»ãã©ã¤ãªã¼æ³ï¼GLBAï¼Gramm-Leach-Bliley Actï¼
- åå·ãå®ããæ å ±æ¼æ´©éç¥æ³
- FBIãFS-ISACãSECãFTCãªã©ã«å¯¾ãã¦ãæ å ±é£æºãè¡ãã
- æ¿åºæ©é¢ã«ããµã¼ãã¹ãæä¾ãã¦ãããããæ¿åºæ©é¢ã«ãã調æ»ãè¡ã£ããç±³å½ç¤¾ä¼ä¿éå±ï¼SSAï¼ã¯Equifaxã®ã³ã³ãã©ã¤ã¢ã³ã¹ç¶æ³ã«ã¤ãã¦ãNISTã»ãã¥ãªãã£ãã¼ã¹ã©ã¤ã³ç®¡çã使ã£ã¦è©ä¾¡ãããã®æ å ±ãç±³å½å 彿³å ¥åºï¼IRSï¼ã¨ç±³å½éµæ¿å ¬ç¤¾ï¼USPSï¼ã¨å ±æããã
訴è¨
- ãµã³ãã©ã³ã·ã¹ã³å¸ããã1500ä¸äººä»¥ä¸ã®ã«ã«ãã©ã«ãã¢ä½äººã®å人æ å ±ä¿è·ã«å¤±æãããã¨ãã¦è¨´è¨ãéå§ã*3
-
Equifax社ãå·ã¨é£é¦æ¿åºã«ããææ»ã®åè§£ã顧客ããã®è¦æ±ã¸ã®å¯¾å¿ã¨ãã¦ãæé«ã§7åUSãã«ãæ¯æããã¨ã決å®ãå社ã¯å·æ¿åºãç±³æ¶è²»è éèä¿è·å±ãéä¸ä¸ä¿¡ãã¡ã³ãã«å¯¾ã5å7500ä¸USãã«ãæ¯æããã¾ãå¿ è¦ã«å¿ãã¦ããã¡ã³ãã«å¯¾ã追å ã§1å2500ä¸USãã«ãæ¯æããã¨ãåæãã¦ããã*4
äºå¾å¯¾å¿ã«ãããæ¹å¤
æ¹å¤1ï¼æ å ±å ¬éç¨ç¹è¨ãã¼ã¸ï¼ã³ã¼ã«ã»ã³ã¿ã¼ã¸ã®æ¹å¤
- ã³ã¼ã«ã»ã³ã¿ã¼ãæ¥ãã§æ§ç¯ãããããé»è©±ãã¤ãªãããªããæç¢ºãªåçãå¾ãããªããªã©ã®æ¹å¤ãåºãã
- 顧客ãèªåã®æ å ±ãæ¼æ´©ãã¦ãããå¦ã確èªãããããequifaxsecurity2017.comã¨ãããµã¤ããæ§ç¯ããããæ¬æ¥ã®ä¼ç¤¾ãã¡ã¤ã³equifax.comã¨ã¯ç°ãªããããããã¥ããã¨ææãåããã
- Twitterã®å ¬å¼ã¢ã«ã¦ã³ããã誤ã£ãURLï¼securityequifax2017.comï¼ã¨æ¸ãã¦ãã¾ãã2é±éã®éãã£ãã·ã³ã°ãµã¤ãã¸èªå°ãå½è©²ãã¡ã¤ã³èªä½ã¯ãã»ãã¥ãªãã£ç ç©¶è ã«ããåå¾ããã¦ããããã£ãã·ã³ã°ãµã¤ãã¨ãããããåèãµã¤ãã¨ãã¦æ©è½ããã
- ãµã¤ãããã¾ãæ©è½ãããã¯ã¬ã¸ããç£è¦ãµã¼ãã¹ã¸ã®ç»é²ããã¾ãæ©è½ããªããåãã¦ã¼ã¶ã§æºå¸¯é»è©±ã¨PCã§çµæãç°ãªããªã©ãä¸å ·åãææããã¦ããã
- ãµã¤ãã®ã»ãã¥ãªãã£å¯¾çããç²æ«ã ã¨ææããããå ·ä½çã«ã¯ããµã¼ãè¨¼ææ¸ã¨ãã¦CloudFlareã®å ±ç¨è¨¼ææ¸ãå©ç¨ããå®å¨æ§è¨¼æãæ ä¿ããã¦ããªããWordPressã§æ§ç¯ããã¦ãããåºåä¼ç¤¾Edelman PRã使ã£ã¦ãããã¨ãªã©ãBrian Krebsæ°ã«ãã£ã¦é²åããã
Not only did @Equifax suffer a massive data breach, but their site about the breach is using a free shared CloudFlare SSL cert. ಠ_ಠpic.twitter.com/r4bvPpde1i
â Daniel Lo Nigro (@Daniel15) September 8, 2017
æ¹å¤2ï¼å¹¹é¨ã®éè·
ï¼æï¼æ¥ã«ã¤ã³ã·ãã³ããå ¬éããå¾ãMandiant社ã®èª¿æ»ãçµäºããåã«ãï¼äººã®å¹¹é¨ç¤¾å¡ãéè·ãã¦ãã¾ãã
- ï¼æï¼ï¼æ¥ï¼CIO David Webbæ°ãCSO Susan Mauldin女å²
- ï¼æï¼ï¼æ¥ï¼CEO Richard Smithæ°
æ¹å¤ï¼ï¼Equifaxã®çµå¶é£ã«ããã¤ã³ãµã¤ãã¼åå¼
æ å ±æ¼æ´©äºå®ã社å ã§çºè¦ããå¾ãï¼æï¼æ¥ï½ï¼æ¥ã«ï¼äººã®ä¸ç´å¹¹é¨ãæ ªã売å´ããã¨ç¥ãããã¤ã³ãµã¤ãã¼åå¼çæãæãããã¾ããã*5*6
- Chief Financial Officer & Corporate VPï¼John Gamble (946,374ãã«ã®æ ªä¾¡)
- President of U.S. Information Solutionsï¼Joseph Loughranï¼584,099ãã«ã®æ ªä¾¡ï¼
- President of Workforce Solutionsï¼Rodolfo Ploderï¼250,458ãã«ã®æ ªä¾¡ï¼
ã¾ããã»ãã«ãã¤ã³ãµã¤ãã¼åå¼ããã社å¡ã¯ã»ãã«ãããããããã½ããã¦ã§ã¢è£½åéçºããã¼ã¸ã£ã¼Sudhakar Reddy Bonthuãæç½ªå¤æ±ºãåããããEquifax CIO Jun Yingãæ¹é£ããã¦ããã¨ããè¨äºãåºã¦ãã¾ãã
ã¾ã¨ã
Equifaxç¤¾ã®æ å ±æ¼æ´©ã¯ãé常ã«å¦ã³ã®å¤ãã¤ã³ã·ãã³ãã§ããããããã¤ã³ã·ãã³ãã®çµç¹å é¨ã®ç¶æ ãªã©ã¯ã大æä¼æ¥ãä¸å¿ã«ä»äººäºã¨ã¯æå¯ãªãé¨åãããã®ã§ã¯ãªãã§ããããã
Â
*1:https://piyolog.hatenadiary.jp/entry/20170311/1489253880
*2:https://www.nic.ad.jp/ja/materials/iw/2017/proceedings/d1/d1-3-kamiyama.pdf
*3:https://blog.hatena.ne.jp/security_consultant/scientia.hatenadiary.com/edit?entry=17680117126997303370
*4:https://www.ftc.gov/system/files/documents/cases/172_3203_equifax_proposed_order_7-22-19.pdf
*5:https://techcrunch.com/2017/09/07/equifax-managers-dumped-stock/
*6:https://www.bloomberg.com/news/articles/2017-09-07/three-equifax-executives-sold-stock-before-revealing-cyber-hack
