NPO Institute of Digital Forensics. NPOæ³äºº ãã¸ã¿ã«ã»ãã©ã¬ã³ã¸ãã¯ç ç©¶ä¼ ã141-0031 æ±äº¬é½åå·åºè¥¿äºåç°7-15-4 第ä¸è±ç°ãã«4F TELï¼FAXï¼03-6431-8200 Emailï¼info@digitalforensic.jp
ãã¸ã¿ã«ã»ãã©ã¬ã³ã¸ãã¯ç 究ä¼ï¼IDFï¼ã§ã¯ããã©ã¬ã³ã¸ãã¯èª¿æ»ã»è§£ææ¥åãè¡ã£ã¦ããå£ä½ä¼å¡ä¼æ¥ã«ã¤ãã¦ã®ç´¹ä»ããã®ãã¼ã ãã¼ã¸ãéãã¦è¡ãã¾ãã ããã§ãç´¹ä»ããä¼æ¥ã¯ãæ¢ã«IDFã®ãã¼ã ãã¼ã¸ã§å ¬éãã¦ããã¾ããå£ä½ä¼å¡ãªã³ã¯ãããå£ä½ä¼å¡ã製åã»ãµã¼ãã¹åºåãªã¹ãããã«æ²è¼ãã¦ããæ å ±ã«å ãããã©ã¬ã³ã¸ãã¯èª¿æ»ã»è§£ææ¥åãå®æ½ãã¦ãããæ²è¼ãå¸æããä¼æ¥ã§ãã çæ§ããã©ã¬ã³ã¸ãã¯èª¿æ»ã»è§£ææ¥åãä¾é ¼ãããã¨ããéã«ä¼æ¥é¸å®ã®ãå½¹ã«ç«ã¦ã°å¹¸ãã§ãã ãªããæ²è¼å£ä½ä¼å¡ä¼æ¥ã¯ããã©ã¬ã³ã¸ãã¯èª¿æ»ã»è§£ææ¥åã«é¢ããå½è©²ç¤¾ã®å ¬éæ å ±çã«åºã¥ããæ²è¼æç¹ã§ä¸é©åãªç¤¾ä¼çäºæ¡ãäºæ å ±åçãå ¬çæ©é¢ã«ãããªããã¦ããªãå£ä½ä¼å¡ä¼æ¥ã¨ãã¦ããã¾ãããIDFãå½è©²ä¼æ¥ã®å®åå 容ã«è²¬ä»»ãè² ããã®ã§ã¯ãªãä¸é©åãªç¤¾ä¼çäºæ¡ãäºæ å ±åçããã£ãå ´åã«ã¯ãæ²è¼ãåãæ¶ããã¨ãããã¾ãã â»æ²è¼é ã¯ãæ²è¼ã
Forkwell Library 第48åç®ã¯ã詳解 ã¤ã³ã·ãã³ãã¬ã¹ãã³ã¹ããåãä¸ãã¾ããã¤ã³ã·ãã³ã対å¿ã«ã¯ãæ§ã ãªå°éåéã®ç¥èãå¿ è¦ã¨ããæ§ã ãªåéã®ãã¬ã¼ãã³ã°ãç¶ç¶çã«åããå¿ è¦ãããã¾ããæ¬æ¸ã¯ã»ãã¥ãªãã£ä¾µå®³ã試ã¿ãæ»æè ã®æ´»åã«å¯¾ããæ¥å¸¸çã«äºé²ã»æ¤ç¥ã»å¯¾å¿ãè¡ãå®å家ã«ãã£ã¦æ¸ãããå®å家ã®ããã®æ¸ç±ã§ã2022å¹´1æã«çºå£²ããã¾ãããä»åã¯è¨³è ã®ç³å· æä¹ æ°ãæããæ¬æ¸ã®æ¦èª¬ãå®è·µçãªæè¡ã®å¦ã³æ¹ãæ¬æ¸ã«é¢é£ããæè¡ã®å¦ã³æ¹ãªã©ã解説ããã ãã¾ãã
ååã®è¨äºã§ãã»ãã¥ãªãã£ããã¼ã¸ã£ã¨ãã¦ãã½ããã¹ãã«ãã³ã³ããã³ã·ãæ§è³ªããéè¦ã¨æ¸ãã¾ããã ãã½ããã¹ãã«ãã³ã³ããã³ã·ãã¨ã¯ã課é¡ã®ææ¡åã解決ã¾ã§ã®æ¹åæ§ã®æ±ºãæ¹ã段åãåãã³ãã¥ãã±ã¼ã·ã§ã³åããã¬ã¼ã³åãªã©æ§ã ã§ãã ãæ§è³ªãã¨ã¯ãç¶ç¶çã«åå¼·ã§ããããç´ ç´ãã¨ãããããããã¾ã両ç«ã§ããããä»é¨éã¨æããæã®æ¼ãå¼ãã«å¼·ãããä½ãæãéããããªãã£ãæã«ã¸ããããªãããããã¨ããæã«äººåã§ææ®ãããã¨ã好ãããã¿ãããªæ確ã«å®ç¾©ã§ããªãã¡ã³ã¿ã«é¢ã®é¨åãå¤ãã«ããã¾ãã ä¸è¨ã®ãã¡ç ä¿®ãæ¸ç±ã§ãã¦ãã¼ãç´¹ä»ããã¦ãããã¼ããå¤ã ããã¾ããããä»é¨éã¨æããæã®æ¼ãå¼ãã«å¼·ãããã¯ãã¾ãè¦ããã¨ãªãããã¨æããèªåã®çµé¨ã¨æããå解ãã¦ã¿ã¾ããã ãã®è¨äºã¯ãããæå³ã§ã¯è ¹ã®é»ãã¨ãããè¦ãããããªãèªã¿æã«ã¨ã£ã¦ã¯å«æªæãæã¤å 容ããããã¾ããã ããã§ããããããæ å ±ã
ã¯ããã« å æ¥ãJPCERT/CCãäºåå±ã¨ãã¦åå ãããå°éçµç¹å士ã®æ å ±å ±ææ´»åã®æ´»æ§åã«åããããµã¤ãã¼æ»æã«ãã被害ã«é¢ããæ å ±å ±æã®ä¿é²ã«åããæ¤è¨ä¼ãã®å ±åæ¸ãå ¬éãããé¢é£ææç©ã®ãããªãã¯ã³ã¡ã³ããå§ã¾ãã¾ããã çµæ¸ç£æ¥çããµã¤ãã¼æ»æã«ãã被害ã«é¢ããæ å ±å ±æã®ä¿é²ã«åããæ¤è¨ä¼ https://www.meti.go.jp/shingikai/mono_info_service/sangyo_cyber/cyber_attack/index.html JPCERT/CCã¯ããã¾ã§ã«ä¸è¨ã®åãçµã¿ãéãã¦ãæ å ±å ±ææ´»åã®ä¿é²ã«åããã«ã¼ã«æ´åã«åãçµãã§ãã¾ããã 令åï¼å¹´åº¦ç·åçããµã¤ãã¼æ»æã®è¢«å®³ã«é¢ããæ å ±ã®æã¾ããå¤é¨ã¸ã®æä¾ã®ããæ¹ã«ä¿ã調æ»ã»æ¤è¨ã®è«è² ãã®èª¿æ»å ±åï¼2021å¹´7æå ¬éï¼[1] ããµã¤ãã¼æ»æ被害ã«ä¿ãæ å ±ã®å ±æã»å ¬è¡¨ã¬ã¤ãã³ã¹ãï¼2023å¹´3
å é£å®æ¿å é£ãµã¤ãã¼ã»ãã¥ãªãã£ã»ã³ã¿ã¼ï¼NISCï¼ã¯ããµã¤ãã¼ã»ãã¥ãªãã£å¯¾çã«ããã¦åç §ãã¹ãé¢ä¿æ³ä»¤ãQ&Aå½¢å¼ã§è§£èª¬ããããµã¤ãã¼ã»ãã¥ãªãã£é¢ä¿æ³ä»¤Q&Aãã³ãããã¯ãï¼ä»¥ä¸ãæ¬ãã³ãããã¯ãã¨ããã¾ããï¼ãä½æãã¦ãã¾ãã ä¼æ¥ã«ãããå¹³æã®ãµã¤ãã¼ã»ãã¥ãªãã£å¯¾çåã³ã¤ã³ã·ãã³ãçºçæã®å¯¾å¿ã«é¢ããæ³ä»¤ä¸ã®äºé ã«å ããæ å ±ã®åæ±ãã«é¢ããæ³ä»¤ãæ å¢ã®å¤åçã«ä¼´ãçããæ³ç課é¡çãå¯è½ãªéãå¹³æãªè¡¨è¨ã§è¨è¿°ãã¦ãã¾ãã ä¼æ¥å®åã®åèã¨ãã¦ãå¹ççã»å¹æçãªãµã¤ãã¼ã»ãã¥ãªãã£å¯¾çã»æ³ä»¤éµå®ã®ä¿é²ã¸ã®ä¸å©ã¨ãªãã°å¹¸ãã§ãã â»Ver2.0ã¯ã令å5å¹´9æã«ããµã¤ãã¼ã»ãã¥ãªãã£ãåãå·»ãç°å¢å¤åãé¢ä¿æ³ä»¤ã»ã¬ã¤ãã©ã¤ã³çã®æç«ã»æ¹æ£ãè¸ã¾ããé ç®ç«ã¦ã»å 容ã®å å®ãæ´æ°ãè¡ãæ¹è¨ããããã®ã§ãã Qï¼Aã§åãä¸ãã¦ãã主ãªãããã¯ã¹ã«ã¤ã㦠ãµã¤ãã¼ã»ãã¥ãªãã£åºæ¬æ³é¢é£ ä¼ç¤¾æ³
ã¯ããã« ç 究éçºç¬¬äºé¨ãªã¼ãã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®ä¸ç¬ã§ããã»ãã¥ãªãã£ã¨ã³ã¸ãã¢å士ã®ä¼è©±ã§ã¯ãã"ã·ãµ"ãæè¿ã¾ãã¬ãã¼ãåºãã¦ãã¦â¦ãã¨ãã"ã¢ã¤ãã¼ã¨ã¼"ãã注æåèµ·åºã¦ãããã¨ãã£ããåå¦è ã«ã¯è¬ã®åèªãããããåºã¦ãã¾ããæ¬è¨äºã§ã¯ããããã£ãä¼è©±ã«åºã¦ããåèªã®ãã¡ãå½å å¤ã®ã»ãã¥ãªãã£é¢é£ã®ä¸»ãªçµç¹ã«ã¤ãã¦ã¾ã¨ãã¾ãããã»ãã¥ãªãã£ã«èå³ãããã°ãããã«æããçµç¹ã¨ããã®çµç¹ãé¢ããæ¿çãæ´»åã«ã¤ãã¦ãäºåã«æãã¦ããã¦æã¯ããã¾ãããããããã»ãã¥ãªãã£ãå¦ã¼ãã¨ããæ¹ã®åèã«ãªãã°å¹¸ãã§ãã ãªããè¨è¼ããæ å ±ã¯ãã¹ã¦å·çæç¹ (2023 å¹´ 6 æ) ã®ãã®ã§ãã ã2023/06/30 追è¨ãNISC ããã³ ENISA ã®æ¥æ¬èªå称ãä¿®æ£ãCISA ã®èªã¿æ¹ã«ã¤ãã¦ä¿®æ£ã»è¿½è¨ãNCSC ã«ã¤ãã¦è¿½è¨ãã¾ããã ã¯ããã« ä¸å¤®çåº å é£ãµã¤ãã¼ã»ãã¥ãªãã£ã»ã³ã¿
J-CLICS æ»æçµè·¯å¯¾çç·¨ã§ã¯ãæ»æè ãä¾µå ¥ããéã«ä½¿ç¨ãããæããããå¶å¾¡ã·ã¹ãã ï¼ä»¥ä¸ããICSãã¨ãããï¼ã¨ã®æ¥ç¶ç¹ãæ»æçµè·¯ã¨å®ç¾©ããæ³å®ããã4ã¤ã®æ»æçµè·¯ãè¨å®ãã¦ãã¾ããè¨å®ããæ»æçµè·¯ãã¨ã«ä¾µå®³æé ã¨å®æ½ãã¹ãã»ãã¥ãªãã£å¯¾çãæ¤è¨ãã¦ããããã®å¯¾çã®å®æ½ç¶æ³ã確èªããããã§ãã¯ãªã¹ããããã³ãã®ãè¨åé ç®ã¬ã¤ããã§æ§æããã¦ãã¾ããããã«ãæ»æçµè·¯ãã¨ã«æ»æãæç«ããæ¡ä»¶ãæ´çããã対çãããããå ããè©ä¾¡ããéã®åèå³æ¸ã¨ãã¦ãã¾ãã J-CLICSã®å称ããã¤ICSã®èªå·±è©ä¾¡ãã¼ã«ã«ã¯ããJ-CLICS STEP1ï¼STEP2ãã¨ãJ-CLICS æ»æçµè·¯å¯¾çç·¨ãã®2種ãããã¾ããJ-CLICS STEP1ï¼STEP2ã¯ãããããICSã®ã»ãã¥ãªãã£å¯¾çã«åãçµãæ¹åãã§ããã¼ã¹ã©ã¤ã³ã¢ããã¼ãã¨ãã¦ç¾å¨ã®ICSã«ãããã»ãã¥ãªãã£å¯¾çç¶æ³ãå¯è¦åããéè¦åº¦ãé«ã
ã»ãã¥ãªãã£å¯¾å¿çµç¹ã®æç§æ¸ 第3.1ç (2023å¹´10æ) 2023å¹´10æ18æ¥ã«ç¬¬3.1çã®PDFã®ããã¹ããç»åã®ã³ãã¼ãã§ããããã«ä¿®æ£ãã¦åé å¸ãã¾ããããææ°ã§ããå¿ è¦ãªæ¹ã¯åãã¦ã³ãã¼ãããé¡ããã¾ãã 2023å¹´10æã«ããã»ãã¥ãªãã£å¯¾å¿çµç¹ã®æç§æ¸ 第3.1çããå ¬éãã¾ãããä»é²ã¨ãªãããµã¼ãã¹ãã¼ããã©ãªãªã·ã¼ãããå ¬éãã¾ããããã²ãæ´»ç¨ãã ããã ãWG6ã ã»ãã¥ãªãã£ãªãã¬ã¼ã·ã§ã³é£æºWGã«ããã¦ããã»ãã¥ãªãã£å¯¾å¿çµç¹ã®æç§æ¸ 第2.1çãã®æ¹çã«åãã¦è°è«ãç¶ãã¦ãã¾ããã2021å¹´10æã«å ¬éãããITU-Tå§åX.1060ãX.1060ã®æ¥æ¬èªçã®æ¨æºã¨ãªãTTCæ¨æºJT-X1060ã«åãããå½¢ã§ã®å ¨é¢çãªæ¹çã¨ãªãã¾ãã 第3.1ç å·çé¢ä¿è (社åäºåé³é ) éå°» æ³°å¼ NECã½ãªã¥ã¼ã·ã§ã³ã¤ããã¼ã¿æ ªå¼ä¼ç¤¾ æ©å· æ¦å² NECã½ãªã¥ã¼ã·ã§ã³
During my career in digital forensics and incident response, I have had to, on several occasions, explain to clients/co-works/students how best to classify and prioritise security alerts. This is a common challenge for security operation centre (SOC) staff and those in DFIR teams monitoring alerts. The question I always hear is, âwhich alert is more important than the other?â. One very rudimentary
ãã¸ãã¹ã¡ã¼ã«è©æ¬ºã®å®æ 調æ»å ±åæ¸ ä¸è¬ç¤¾å£æ³äºº JPCERT ã³ã¼ãã£ãã¼ã·ã§ã³ã»ã³ã¿ã¼ 2020 å¹´ 3 æ 25 æ¥ JPCERT Coordination Center : JPCERT Coordination Center DN : c=JP, st=Tokyo, l=Chuo-ku, o=Japan Computer Emergency Response Team Coordination Center, cn=JPCERT Coordination Center, email=office@jpcert.or.jp : 2020.03.25 10:33:19 +09'00' ç®æ¬¡ 1. ã¯ããã«...........................................................................................
çµæ¸ç£æ¥çã¯ãä¼æ¥ããµã¤ãã¼ã»ãã¥ãªãã£çµå¶ã¬ã¤ãã©ã¤ã³ã«åºã¥ãã¦çµç¹ä½å¶ãæ§ç¯ããå¿ è¦ãªäººæã確ä¿ããããã®ãã¤ã³ããã¾ã¨ããããµã¤ãã¼ã»ãã¥ãªãã£ä½å¶æ§ç¯ã»äººæ確ä¿ã®æå¼ããï¼ä»¥ä¸ããæå¼ããï¼ããªãã¥ã¼ã¢ã«ãã第2.0çã¨ãã¦æ¬æ¥å ¬éãã¾ããã ãµã¤ãã¼æ»æãé«åº¦åã»å·§å¦åããããããä¼æ¥ãæ»æã®å¯¾è±¡ã¨ãªãä¸ãçµå¶è ã®ãªã¼ãã¼ã·ããã®ä¸ã§ã®ãµã¤ãã¼ã»ãã¥ãªãã£å¯¾çã®æ¨é²ãæ¥åã¨ãªã£ã¦ãã¾ãã ããã§ãçµæ¸ç£æ¥çã§ã¯ãç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ï¼IPAï¼ã¨ã¨ãã«ãããµã¤ãã¼ã»ãã¥ãªãã£çµå¶ã¬ã¤ãã©ã¤ã³ããçå®ãã¦ãã¾ãã æ¬æå¼ãã§ã¯ãããµã¤ãã¼ã»ãã¥ãªãã£çµå¶ã¬ã¤ãã©ã¤ã³ãã®ä»é²ã¨ãã¦ãä¼æ¥ã«ããããµã¤ãã¼ã»ãã¥ãªãã£å¯¾çã®æ¨é²ã®åºç¤ã§ãããçµå¶è ãç©æ¥µçã«é¢ããã¹ãããªã¹ã¯ç®¡çä½å¶ã®æ§ç¯ã¨äººæã®ç¢ºä¿ã«ã¤ãã¦ãå ·ä½çãªæ¤è¨ãè¡ãéã®ãã¤ã³ãã解説ãã¦ãã¾ãã æ¬æ¥å ¬éãã第2.0ç
ã³ã³ãã¥ã¼ã¿ã»ãã¥ãªã㣠ã¤ã³ã·ãã³ã対å¿ãã¼ã ï¼CSIRTï¼ã®ããã® ãã³ããã㯠æ¬ç¿»è¨³ææ¸ã¯ãæé責任ä¸éæ³äºº JPCERT ã³ã¼ãã£ãã¼ã·ã§ã³ã»ã³ã¿ã¼ããåæ¸ ã®èä½æ¨©ãä¿æãã Carnegie Mellon University/Software Engineering Institute(CMU/SEI) ãã許諾ãå¾ã¦ç¿»è¨³ãããã®ã§ãã CMU/SEI: http://www.sei.cmu.edu/ æ¥æ¬èªçã®å 容ã«ã¤ãã¦ãåæ¸ã«æ²¿ã£ã¦ã§ããã ãå¿ å®ã«ç¿»è¨³ããããåªã㦠ãã¾ãããå®å ¨æ§ãæ£ç¢ºæ§ãä¿è¨¼ãããã®ã§ã¯ããã¾ããã ã¾ãã翻訳ç£ä¿®ä¸»ä½ã¯æ¬ææ¸ã«è¨è¼ããã¦ããæ å ±ããçããæ失ã¾ãã¯æ害 ã«å¯¾ãããããªã人ç©ãããã¯å£ä½ã«ã責任ãè² ããã®ã§ã¯ããã¾ããã ã³ã³ãã¥ã¼ã¿ã»ãã¥ãªã㣠ã¤ã³ã·ãã³ã対å¿ãã¼ã ï¼CSIRTï¼ã®ããã® ãã³ããã㯠Moira J. W
ã»ãã¥ãªãã£å¯¾å¿çµç¹ã®æç§æ¸ v2.1 (2018å¹´9æ) 2023å¹´2æã«ããã»ãã¥ãªãã£å¯¾å¿çµç¹ã®æç§æ¸ç¬¬3.0çãããªãªã¼ã¹ãã¾ããããã¡ãããæ´»ç¨ãã ããã ã»ãã¥ãªãã£å¯¾å¿çµç¹ã®æç§æ¸ã第3.0ç 2019å¹´2æã«ããã»ãã¥ãªãã£å¯¾å¿çµç¹æç度ã»ã«ããã§ãã¯ã·ã¼ãããè£è¶³ãè¨å ¥ã§ããããã«ããv2.2çã«æ´æ°ãã¦ããã¾ããåçµç¹ã§ã®å±éã®éã«åçµç¹ã®å½¢æ ãæ¥åã«åãããè£è¶³ãè¨å ¥ãããªã©ãæ´»ç¨ãã ããã 2018å¹´9æã«ããã»ãã¥ãªãã£å¯¾å¿çµç¹ã®æç§æ¸ãã®æ¦è¦çã¨ãªãããã³ããã㯠v1.0çãã¨54ã®å½¹å²ãä¸è¦§ã§ããå¥ç´ã追å ãã¦ããã¾ãã 2018å¹´3æã«ããã»ãã¥ãªãã£å¯¾å¿çµç¹æç度ã»ã«ããã§ãã¯ã·ã¼ããã®ã¢ã¦ãã½ã¼ã¹ã«é¢ããåºæºãè¦ç´ããv2.1çã«æ´æ°ãã¦ããã¾ãã ãWG6ã ã»ãã¥ãªãã£ãªãã¬ã¼ã·ã§ã³é£æºWGã«ããã¦ããã»ãã¥ãªãã£å¯¾å¿çµç¹ã®æç§æ¸ v1.0ãã®æ¹ç
ãµã¤ãã¼ã»ãã¥ãªãã£çµå¶ã¬ã¤ãã©ã¤ã³ Ver2.0 ä»é²F ãµã¤ãã¼ã»ãã¥ãªãã£ä½å¶æ§ç¯ã»äººæ確ä¿ã®æå¼ã ï½ å¤åãããµã¤ãã¼ã»ãã¥ãªãã£ãªã¹ã¯ã«å¯¾å¦ããããã® çµç¹ã®å¨ãæ¹ã¨å¾äºãã人æã®é ç½®ã»å½¹å²åæ ï½ ç¬¬ï¼ç çµæ¸ç£æ¥ç ååæ å ±æ¿çå± ãµã¤ãã¼ã»ãã¥ãªãã£èª² ç¬ç«è¡æ¿æ³äºº æ å ±å¦çæ¨é²æ©æ§ï¼IPAï¼ 2 ç®æ¬¡ 1. ã¯ããã« 3 1.1 æ¬æ¸ã®ç®ç 3 1.2 主ãªå¯¾è±¡èªè 4 1.3 æ¬æ¸ã®æ§æ 4 1.4 ããµã¤ãã¼ã»ãã¥ãªãã£çµå¶ã¬ã¤ãã©ã¤ã³ãæ示ï¼ã¨æ示ï¼ã®å®è·µã®é²ãæ¹ 5 2. ãµã¤ãã¼ã»ãã¥ãªãã£ãªã¹ã¯ã®ç®¡çä½å¶ã®æ§ç¯ï¼æ示ï¼ï¼ 7 2.1 ãSTEP1ã ãµã¤ãã¼ã»ãã¥ãªãã£ã«é¢ãã¦ãããã¹ããã¨ãã®æ確å 8 2.2 ãSTEP2ã ã»ãã¥ãªãã£çµ±æ¬æ©è½ãæ¤è¨ãã¾ããã 12 2.3 ãSTEP3ã ãµã¤ãã¼ã»ãã¥ãªãã£é¢é£ã¿ã¹ã¯ãæ ãé¨éã»é¢ä¿ä¼ç¤¾ã®ç¹å®ã»è²¬ä»»
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}