ASMå°å ¥æ¤è¨ãé²ããããã®ã¬ã¤ãã³ã¹ï¼åºç¤ç·¨ï¼ #æ¬ããã¥ã¡ã³ãã®ç®ç #ãAttack Surface Managementï¼ASMãæ»æ対象é å管çãæ»æ表é¢ç®¡çï¼ãã¸ã®æ³¨ç®ãé«ã¾ãã¨ã¨ãã«ãæ§ã ãªãµã¼ãã¹ãããã¥ã¡ã³ããç»å ´ãã¦ãã¾ãã ãããããASMãã«ã¯è¤æ°ã®åãçµã¿æ¹æ³ãåå¨ããç¨èªã®å®ç¾©ãããã¥ã¡ã³ãã解éããã®ãé£ããããASMããæ´»ç¨ãããçµç¹ãç®çã«æ²¿ã£ã¦ãã¼ã«ããµã¼ãã¹ãè¦åãããã¨ãé£ãããªã£ã¦ãã¾ãã æ¬ããã¥ã¡ã³ãã¯ããASMãã«é¢é£ããç¨èªãæ´»ç¨æ¹æ³ãç解ããç®çã«æ²¿ã£ããµã¼ãã¹ãé¸å®ãããã¨ããæ¢åã®ããã¥ã¡ã³ãï¼æ§ã ãªçµç¹ãä½æããããã¥ã¡ã³ãï¼ãèªã¿è§£ãä¸ã§å©ãã¨ãªãæ å ±ã®æä¾ãç®çã¨ãã¦ãã¾ãã å·çè ä¸è¦§ #å·çè #å¤§å¡ æ·³å¹³ï¼NRIã»ãã¥ã¢ãã¯ããã¸ã¼ãºæ ªå¼ä¼ç¤¾ï¼æ´²å´ ä¿ï¼ä¸äºç©ç£ã»ãã¥ã¢ãã£ã¬ã¯ã·ã§ã³æ ªå¼ä¼ç¤¾ï¼é«æ±æ´² å²ï¼ä¸äºç©ç£ã»ãã¥ã¢ã
2024å¹´8æ20æ¥ã«éå¬ããããVulsç¥ã#10 | èå¼±æ§ç®¡çã®æåç·ããªã¹ã¯è©ä¾¡ããSSVCãVEXãAIã¾ã§ããã®ã»ãã·ã§ã³ããæ®æ¥ï¼ æ¥é±ã§OK?ãéæåå¾ã®èå¼±æ§å¯¾å¿å¤æã«ä½¿ããSSVCã®ã㢠ãã®è¦ç¹ãæ¸ãèµ·ããè¨äºã§ãã YouTubeã¢ã¼ã«ã¤ãã¯ãã¡ãã§ãã ä¼å ´ã¸ã®è³ªå å æ¥IPAã®ä¸æ ¸äººæè²æããã°ã©ã åæ¥ããã¸ã§ã¯ãããããèå¼±æ§å¯¾å¿ã«ããããªã¹ã¯è©ä¾¡ææ³ã®ã¾ã¨ããã¨ããè³æãå ¬éããã¾ããããã®è³æã¯æ¬æ¥ç´¹ä»ããSSVCãEPSS, KEVãªã©ãæ¥æ¬èªã§ãããããã説æããã¦ãããã¾ãããªã¢ã¼ã¸ã«ã¤ãã¦ããã¤ãã®æ¹æ³ãè¨è¼ããã¦ããã®ã§ä¸èªããããããã¾ããããã®ä¸ã§ãã®å³ã®éã60社ã¸ã®ä¼æ¥ã«ã¢ã³ã±ã¼ããåã£ã¦ãã¾ãã æå¤ã«ããã£ãã®ããCVSSã®ç°å¢è©ä¾¡åºæºã60社ä¸15社ã使ã£ã¦ããç¹ã§ããç§ã¯2016å¹´ã«Vulsãéçºãã¦ä»¥éèå¼±æ§ç®¡çããã¼ãã«æ´»å
2024å¹´7æ12æ¥ã«éå¬ãããã製é æ¥ã«ãããèå¼±æ§ç®¡çã®èª²é¡ã¨å¯¾å¿æ¹æ³@大éªãã»ããã¼ã®ãSSVC Supplier Treeã®æ¦è¦ã¨èªååãã»ãã·ã§ã³ã®ã¹ã©ã¤ãã§ãã ç±³å½CISAãæ¨å¥¨ããèå¼±æ§ç®¡çã®åªå é ä½ä»ãææ³ã§ããSSVCï¼Stakeholder-Specific Vulnerability Categorizationï¼ã®æ¦è¦ã説æããPSIRTç¨ã®æ±ºå®æ¨ã§ããSupplier Treeãç´¹ä»ãã¾ããSSVCã¯èå¼±æ§ããªã¹ã¯ãã¼ã¹ã§åªå 度ä»ããããã¬ã¼ã ã¯ã¼ã¯ã§ããããã®ã¾ã¾çµç¹ã«é©ç¨ããã¨äººçå·¥æ°ã¨å°éç¥èãå¿ è¦ã§ããè¬æ¼è ã¯SSVCã®å°å ¥ã«ã¯èªååãèè¦ã§ããã¨èããèªååã®æ¹æ³ã模索ãã¦ãã¾ããæ¬ã»ãã·ã§ã³ã§ã¯ãSSVC Supplier Treeãç¨ãã¦è£½é æ¥ã®PSIRTã®èå¼±æ§ããªã¢ã¼ã¸ãèªååããæ¹æ³ãæ¢æ±ãã¾ããå ·ä½çã«ã¯ãSupplier Treeã®åDe
ããã«ã¡ã¯ãGunosy R&D ãã¼ã ã®æ£®ç°ã§ãã GPT-4o ãçºè¡¨ããããã®ã¿ã¤ãã³ã°ã§ï¼ï¼ã¨ããåãããããã¨ãããã¾ãããLLMã®ä¸çã¯ä¸ã¶æãããã°ã¾ã£ããéãç¶æ³ã«ãªã£ã¦ããã®ã常ãªã®ã§ãããã㯠GPT-4o ãè¶ ããã¢ãã«ãçºè¡¨ãããæãæ¥ãã§ãããã Claude 3 Opus ã¯ä¸ææ GPT-4 ã®ã¹ã³ã¢ãè¶ ãã Claude 3 Haiku ã§ã¯ GPT-3.5-Turbo ã®ãã¼ã¯ã³å½ããã§ç´åé¡ã¨ã³ã¹ãããã©ã¼ãã³ã¹ã«åªãã¦ãã¾ããã AWS Bedrock çµç±ã§å®å®ãã¦å©ç¨ã§ãããã¨ããããClaude 3 ã¯ä¹ãæãå ã®åè£ã®ä¸ã¤ã§ãã Claude 3 ã¸ã®ä¹ãæãã«ã¯ãç¹ã ã¨ã¤ã¾ã¥ããã¤ã³ããããã®ã§ãå¼ã£ããã£ãæã¨åé¿æ¹æ³ããç´¹ä»ãã¾ãã ä»åç´¹ä»ããå 容ã¯Claude 3ã«éããªããã®ãããã¾ãã®ã§ããã¼ã«ã«LLM ãä»ã®LLM ã¸ã®ä¹ãæã
ãï¼ï¼ï¼ããã®ã¾ã¾ ä»ãèµ·ãã£ãäºã話ããï¼ ãããã¯ãcat ã®æ¹ã grep "." ãããéããã¨ã示ãããã«ã両æ¹ã®åºåã /dev/null ã«æ¨ã¦ãã grep ã®æ¹ã ãå¦çé度ãç°å¸¸ã«éããªã£ã¦ããã ãªã»ã»ã»ãä½ãè¨ã£ã¦ããã®ããããããã¼ã¨æãã ããããä½ãèµ·ããã®ããããããªãã£ãã»ã»ã» é ãã©ãã«ããªãããã ã£ãã»ã»ã»ãå¬ç è¡ã ã¨ãè¶ ã¹ãã¼ãã ã¨ã ãããªãã£ããªããããããæãã¦ãã ãã£ã¨æããããã®ã®çé±ããå³ãã£ããã»ã»ã» ãï¼ããããè¶ ã¹ãã¼ããå³ãã£ãã ã¯ããã« ä½ãã®ããã©ã¼ãã³ã¹ãã¹ãããã¨ãã«ãåºåãç»é¢ããã¡ã¤ã«ã«è¡ãã¨é度ãä½ä¸ãã¦ãã¾ãã®ã§ããããé¿ããããã« /dev/null ã«æ¨ã¦ãã¨ããã®ã¯ããããäºã ã¨æãã¾ããå¥ä»¶ã§ã¨ããããã©ã¼ãã³ã¹ãã¹ãããã¦ããã¨ããä½ããä¸æè°ãªçµæãã§ã¦ãã¾ã£ãã®ã§èª¿ã¹ãã®ã§ãããã©ããã GNU g
sift ã¨ãããã¼ã«ãããã¾ãã https://sift-tool.org/ sift 㯠better grep ãªãã¼ã«ã§ãä¸è¨ãµã¤ãã®ããã©ã¼ãã³ã¹ã«ããã¨ãã¹ã¦ã®å ´åã«ãã㦠grep ããéããå ´åã«ãã£ã¦ã¯ 40 åé以ä¸ã®ããã©ã¼ãã³ã¹ãåºãã¨ãããåã ãæ¿å¤ªéï¼ï¼ãªç¶æ ãªã®ã§ãã®æªããä¼èª¬ãæ¤è¨¼ãã¦ã¿ã¾ãã https://sift-tool.org/info.html ç°å¢ åã®ç°å¢ã¯ãã¡ãã CPU: Intel Corei7 4790 ã¡ã¢ãª: 16GB ã¹ãã¬ã¼ã¸: SSD 256GB OS: Ubuntu 14.04 64bit ã¤ã³ã¹ãã¼ã« https://sift-tool.org/download.html ããé©åãªã¢ã¼ã«ã¤ãããã¦ã³ãã¼ããã¦è§£åã $ tar zvxf sift_0.3.4_linux_amd64.tar.gz sift_0.3.4
â ããã°ã©ã ã«ã¨ã£ã¦éãã¯æ£ç¾©ã ã ããã°ã©ã ã¯å½ä»¤ãå®è¡ãããã¼ã«ã§ããã¢ã¼ãã§ã¯ãªããããæ©è½æ§ãé«ãè©ä¾¡ãããã ä¾ãã°å¤§éã®ãã¡ã¤ã«ã対象ã«æ¤ç´¢ãè¡ãéã«ã³ã³ã1ç§ã§ãéãçµããã°ã©ãã»ã©å¬ãããã¨ããããã100åã1000åãç¹°ãè¿ã使ããããããªããã°ã©ã ãªããªãã®ãã¨ã ã å æ¥ãç¥äººããgrep ãã find + xargsã®æ¹ãéãã¨ã®è©±ã伺ã£ãã®ã§ä»æ¥ã¯ãã®æ¤è¨¼ãè¡ãã ã¾ãæå ã«2500ä¸æåã®ãã¡ã¤ã«ã5ã¤ç¨æããããã®ä¸ã«ãtestãã¨ããæåãããã¤ãå«ã¾ãã¦ããããã®ãã¡ã¤ã«ã5ã¤è¤è£½ããããããæ¤ç´¢ããå®è¡é度ãè©ä¾¡ããã ãã¡ã¤ã«ã®æåæ°ããã®ãã¡ã¤ã«ã5ã¤ããããã®ä¸ããç¹å®èªãæ¤ç´¢ããã textfile1.txt $ cat milchars.txt| wc -m 26116283 â 測å®æ¹æ³ macï¼linuxï¼ã§ã³ãã³ãã®å®è¡é度ã測ãéã¯
ã¿ãªããgrepãã¦ã¾ãã!? 便å©ã§ãããgrepãèªåã¯Linuxã触ãã¯ãããããã grepã使ãããªããããã«ãªãã°ä¸äººåã ã£ã¦è¨ããã¦ããªã«ãã£ã¦ãã®ãã®äººãããã¨ãæã£ã¦ãªãã§ããå ¨ç¶ã ã¾ãä»ã¨ãªã£ã¦ã¯grepããããªãã«ä½¿ãããã§ãããã§ããã $ find . -name "*hoge" -type -f | grep -v '\.svn' | xargs grep piyopiyo ã¨ããã£ã¦ãã ãªããfind|xargs|grepã¨ãã¾ãã«UNIXçã§ããããç´ æµããã ç°¡åãªã³ãã³ããçµã¿åããã¦ã§ã£ãããã¨ãã£ã¡ããï¼ï¼ã¿ãããªï¼ï¼ ããã©ããã¼ãã£!!! ã£ã¦ãã¨ã§ãackã使ãã¾ãããã ackæ¨æ¥ç¥ãã¾ããã ã§ãä»æ¥ã使ãã¯ããã¦2æ¥ç®ã ã¨ãããããå ¬å¼(Beyond grep: ack 2.12, a source code search too
ç§ã®ä»ã¾ã§çµé¨ãã¦ããå ¨ã¦ã®LLMãã¦ãã¦ãè©°ãè¾¼ãã ãLLMã·ã¹ãã ã®éçºã¬ã¤ãã§ãã åãã¦LLMã·ã¹ãã ãéçºãããã¨æã£ãæã§ãã精度æ¹åãéç¨ã«è¡ãè©°ã£ãæã§ããä½ãããå½¹ã«ç«ã¤ã¨æãã¾ãã ç¾å¨200ãã¼ã¸è¶ ã ä»å¾ãéææ´æ°ãã¦ããã¾ãã 2023/7/28 ä½è£ä¿®â¦
ãã¯ãããããã¾ãã 3æ8æ¥ã«ã主è¦ãªè¨¼å¸ä¼ç¤¾ãä¸æã«ãã¯ã¬ã«ç©ç«ãæ10ä¸åã«æ¡å¤§ãããçºè¡¨ãè¡ãã¾ããã www.watch.impress.co.jp ããã§ãæ°NISAã®ãã¤ã¿ãã¦æè³æ ãã®å¹´é120ä¸åï¼æ¯æ10ä¸åï¼ã«é¢ãã¦ã¯ãã¯ã¬ã«ç©ç«ã«ä¸æ¬åãã§ãããã¨ã«ãªãã¾ãã ä¼ç¤¾ã«ãã£ã¦ã¯ã5ä¸åãè¶ ããåã«é¢ãã¦ã¯ãã¤ã³ãéå çãä¸ãããã¿ã¼ã³ãããã¾ãããããã§ãã¯ã¬ã«ç©ç«ã®æ ãæ¡å¤§ãã¦ããããã¨ã«ã¯æè¬ããããã¾ããã SBI証å¸ã®ãã¤ã³ãéå çãçºè¡¨ããããã¨ãåããæ¬æ¥ã¯SBI証å¸ã楽天証å¸ããããã¯ã¹è¨¼å¸ãauã«ãã³ã 証å¸ã®ã¯ã¬ã«ç©ç«ã®ç¶æ³ãæ´çãã¦ã¿ã¾ãã æè³ä¿¡è¨ã®ã¯ã¬ã«ç©ç«æ10ä¸åã¸ãSBI証å¸ã楽天証å¸ããããã¯ã¹è¨¼å¸ãauã«ãã³ã 証å¸ãã©ãã®è¨¼å¸ä¼ç¤¾ããå¾ï¼ æè³ä¿¡è¨ã®ã¯ã¬ã«ç©ç«æ10ä¸åã¸ãSBI証å¸ã楽天証å¸ããããã¯ã¹è¨¼å¸ãauã«ãã³ã 証å¸ãã©ãã®è¨¼
Recently, Iâve been interested in the DuckDB project (like a SQLite geared towards data applications). And one of the amazing features is that it has many data importers included without requiring extra dependencies. This means it can natively read and parse JSON as a database table, among many other formats. I work extensively with JSON day to day, and I often reach for jq when exploring document
ãç¥ãã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}