ã¯ããã«
ãAjaxï¼Asynchronous JavaScript + XMLï¼ãããã·ã¥ã¢ããï¼Mashupï¼ã«ä»£è¡¨ãããWeb 2.0æè¡ã¯ããã®ãªããã§ä½¿ããããã¦ã¼ã¶ã¼ã¤ã³ã¿ã¼ãã§ã¤ã¹ãé«éãªã¬ã¹ãã³ã¹æ§ãããç¾å¨ã®Webã¢ããªã±ã¼ã·ã§ã³éçºã®ãã¬ã³ãã®ä¸ã¤ã¨ãªã£ã¦ãã¾ããç¾å¨æ³¨ç®ãéãã¦ããã¯ã©ã¦ãã»ã³ã³ãã¥ã¼ãã£ã³ã°ã«ããã¦ããé²ï¼ï¼ã¤ã³ã¿ã¼ãããï¼ããæä¾ããããµã¼ãã¹ã使ç¨ãããé£æºããããã«ãAjaxãJavaScriptã¯ããç¨ãããã¾ããããããã»ãã¥ãªãã£ã¼ã®è¦³ç¹ããè¦ãã¨ããããWebã¢ããªã±ã¼ã·ã§ã³ããã®ä¸»è¦ãªå®è¡ç°å¢ç°å¢ã§ããWebãã©ã¦ã¶ã¼ã«ã¯ããã¾ãã¾ãªã»ãã¥ãªãã£ã¼ä¸ã®è å¨ãåå¨ãã¾ããå³1ã¯ãIBMã®ã»ãã¥ãªãã£é¨éã®ä¸ã¤ã§ããISSãå ¬éãã¦ããã»ãã¥ãªãã£è å¨ã®ãã¬ã³ãã¨ãªã¹ã¯ã«é¢ããã¬ãã¼ã2008å¹´çã«ãããã®ã§ãISSãæ¤ç¥ããWebã¢ããªã±ã¼ã·ã§ã³ã«é¢ããèå¼±æ§ã®ä»¶æ°ãããæ°å¹´ã§é常ã«å¢å ãã¦ãããã¨ã示ãã¦ãã¾ãã
ãã¾ããåã¬ãã¼ãã§ã¯ãçºè¦ãããWebã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ã®æ°ããä»ã®ãã©ãããã©ã¼ã ã®èå¼±æ§ã®æ°ãä¸åã£ããã¨ãå ±åããã¦ãã¾ãããã®ãã¨ã¯ãWebã¢ããªã±ã¼ã·ã§ã³ããITã·ã¹ãã ã®ä¸æ ¸ãæ ãããã«ãªã£ã¦ããã¨å ±ã«ãã»ãã¥ãªãã£ã¼ä¸ã®è å¨ã¨ããã«èµ·å ãããªã¹ã¯ãé«ã¾ã£ã¦ãããã¨ãæå³ãã¦ãã¾ãã
ãWebã¢ããªã±ã¼ã·ã§ã³ããä¼æ¥ã¬ãã«ã®ä½¿ç¨ã«èããããã«ã¯ãä¿¡é ¼æ§ãã»ãã¥ãªãã£ã¼ã¨è¨ã£ãåºç¤æè¡ãå¿ è¦ã§ãããã®è¨äºã§ã¯ãWebã¢ããªã±ã¼ã·ã§ã³ãéçºãããã¯ä½¿ç¨ããéã®ã»ãã¥ãªãã£ã¼ä¸ã®åé¡ç¹ã対çãçè ãåãçµãã§ããç 究éçºããã¸ã§ã¯ããªã©ã«ã¤ãã¦ç´¹ä»ãã¾ãã
ãWeb 2.0ã«ç¹æã®ã»ãã¥ãªãã£ã¼ãããã®ãï¼ ã¨èããããã¨ãããããã¾ããWebã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã¥ãªãã£ã¼ãé«ããããã®æ å ±ããã¼ã«ãæä¾ãã¦ããOWASPããã¸ã§ã¯ãï¼Open Web Application Security Projectã§ã¯ã2004å¹´ã¨2007å¹´ã«Webã¢ããªã±ã¼ã·ã§ã³ã«ããã10åã®ã»ãã¥ãªãã£ã¼ä¸ã®è å¨ãããã¦ãã¾ãã2007å¹´ã®ãªã¹ãã¯æ¬¡ã®ããã«ãªã£ã¦ãã¾ãã
- ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ï¼Cross Site Scripting, XSSï¼
- ã¤ã³ã¸ã§ã¯ã·ã§ã³æ»æ
- æªæãæã£ããã¡ã¤ã«ã®å®è¡
- å®å ¨ã§ãªããªãã¸ã§ã¯ãã®ç´æ¥åç §
- ã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãªã¼
- æ å ±æ¼æ´©ã¨ä¸é©åãªã¨ã©ã¼å¦ç
- èªè¨¼ã¨ã»ãã·ã§ã³ç®¡çã®ä¸å
- å®å ¨ã§ãªãæå·ãã¼ã¿ä¿å
- å®å ¨ã§ãªãéä¿¡
- URLã«ããã¢ã¯ã»ã¹å¶éã®ä¸å
ãå¾ã§ç´¹ä»ããã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ããã¹ã¯ãªãããSQLã³ã¼ããæ³¨å ¥ãå®è¡ãããã¤ã³ã¸ã§ã¯ã·ã§ã³æ»æãæå³ããªãWebãã¼ã¸ã®æ¸ãè¾¼ã¿ãååè³¼å ¥ãå¼ãèµ·ããã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãªã¼ï¼Cross Site Request Forgery, CSRFï¼ãªã©ãWeb 2.0ã¢ããªã±ã¼ã·ã§ã³ã«å¤ãè¦ãããè å¨ãä¸ä½ã«æ¥ã¦ãã¾ãããã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ãã¤ã³ã¸ã§ã¯ã·ã§ã³æ»æã¯ã2004å¹´ã®Top 10ãªã¹ãã«ãå ¥ã£ã¦ãã¾ããã¤ã¾ããæ»æææ³ãã®ãã®ã¯ãWeb 2.0æè¡ãæ®åããåå¾ã§å¤§ããå¤åãã¦ãã訳ã§ã¯ãªããWebãåãå·»ãç°å¢ãã¢ããªéçºã®ããæ¹ãå¤åãããã¨ã«ãããããæ·±å»ããå¢ãã¦ããã¨è¨ããã§ãããã
ãWeb 2.0ã®ç¹å¾´ã®ä¸ã¤ã¯ãã³ã³ãã³ãããå¤ãã®å ´åå¿åã®ã¦ã¼ã¶ã«ãã£ã¦çæãããå¥ã®ã¦ã¼ã¶ã¼ç¾¤ã«ãã£ã¦ã¢ã¯ã»ã¹ããããã¨ã§ããã³ã³ãã³ãã®éãè¨å¤§ã«ãªãã¨å ±ã«ã質ã¨ããé¢ã§ã¯ãä¼æ¥ãä¿¡é ¼ãããæ å ±æºããã®ã³ã³ãã³ãã¨ã¯ç°ãªããå¿ ãããæ£ç¢ºãªæ å ±ã°ããã¨ã¯éããªããªã£ã¦ãã¦ãã¾ããä¿¡é ¼ã§ããWebãµã¤ããé¨ããã£ãã·ã³ã°æ»æãåé¡ã«ãªã£ã¦ãã¦ãã¾ãããWikiãSNSãªã©ã§ã®èª¹è¬ä¸å·ã社ä¼çãªåé¡ã«ãªã£ã¦ããã®ã¯ãåãã®éãã§ããã¾ããã³ã³ãã³ãã«æªæãæã£ãJavaScriptã³ã¼ãããã«ã¦ã¨ã¢ï¼malwareï¼ãå«ã¾ããå±éºæ§ãå¢å ãã¦ãã¾ãããã®ããã«Webä¸ã®ã³ã³ãã³ããã³ã¢ãã£ãã¤ã¼åããä¿¡é ¼æ§ã価å¤ãç¸å¯¾çã«ä½ä¸ãã¦ãããã¨ããåè¿°ã®ãã¾ãã¾ãªèå¼±æ§ãå¼ãèµ·ããåå ã®ä¸ã¤ã¨ãªã£ã¦ãã¾ãã
ãã¾ãããããã®ã³ã³ãã³ããæ±ãWebã¢ããªã±ã¼ã·ã§ã³æ§ç¯ã®ããæ¹ãå¤ããã¤ã¤ããã¾ããä¾ãã°ãWebãã©ã¦ã¶ã¯ãéçãªHTMLææ¸ã®é²è¦§ç°å¢ãããåçãªã³ã³ãã³ããWebã¢ããªã±ã¼ã·ã§ã³ã®å®è¡ãã©ãããã©ã¼ã ã¸ã¨å½¹å²ãå¤ãã¤ã¤ããã¾ããDojoãªã©ã®JavaScriptãã¼ã¹ã®ã©ã¤ãã©ãªã¼ãå å®ãããã¸ãã¯ãã¯ã©ã¤ã¢ã³ãï¼ï¼Webãã©ã¦ã¶ï¼å´ã§ãåãããã«ãªã£ããã¨ã§ãå¾æ¥ãµã¼ãã¼å´ã主ã«å®ã£ã¦ããã°ããã£ãã»ãã¥ãªãã£ã¼ããã¯ã©ã¤ã¢ã³ãå´ã§ã®ããã°ã©ã å®è¡ã«ã注æãæãå¿ è¦ãåºã¦ãã¦ãã¾ããWebãã©ã¦ã¶ã®ã»ãã¥ãªãã£ã¼ã¢ãã«ã¯ãå¾æ¥ããã®éçãªHTMLææ¸ã®é²è¦§ç°å¢ãæ³å®ãããã®ã§ãããWebã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã¥ã¢ãªå®è¡ç°å¢ã¨ãã¦ã¯ä¸ååã§ããWebãã©ã¦ã¶ã®å®è£ ãå¤æ°åå¨ããããã«ãã¼ã¸ã§ã³ã®éãã«ãã£ã¦å¤ããæ¯ãèãããã»ãã¥ãªãã£çã«ãåé¡ã«ãªãã¾ããFlashãªã©ãã©ã¦ã¶ä¸ã§åããã©ã°ã¤ã³ã®ããªã¨ã¼ã·ã§ã³ãèããã¨ãéçºè ã¯è¨å¤§ãªçµã¿åããã®ã¯ã©ã¤ã¢ã³ãç°å¢ãä»®å®ããªãã¨ããã¾ããã
ãããã«ãWeb 2.0æè¡ãç¨ãããã¨ã§ãWebãã©ã¦ã¶ä¸ã«è¤æ°ã®æ©è½ãAPIãã³ã³ãã¼ãã³ãåãã¦ããã·ã¥ã¢ãããããã¨ãå¯è½ã«ãªãã¾ãããSaaSãã¯ã©ã¦ãã»ã³ã³ãã¥ã¼ãã£ã³ã°ã®æ®åã¨ç¸ã¾ã£ã¦ãä¼æ¥ã¢ããªã«ããã¦ãã社å ã®ã³ã³ãã¼ãã³ãã¨Webä¸ã®ã³ã³ãã¼ãã³ããããã·ã¥ã¢ããããã±ã¼ã¹ãä»å¾å¢ãã¦ããã¨èãããã¾ãããããã®ã³ã³ãã¼ãã³ãã¯ãã»ãã¥ãªãã£ã¼çã«ã¯ãç°ãªããã¡ã¤ã³ã«å±ãããã®ã§ãããä¿¡é ¼ã§ãããã®ã¨ããã§ãªããã®ãã©ã®ããã«çµã¿åããããã¯é常ã«éè¦ãªåé¡ã§ããä¿¡é ¼ã§ããªãã³ã³ãã¼ãã³ããæªæãæã£ãã¹ã¯ãªãããå«ãã§ããã¨ãä¿¡é ¼ã§ããã³ã³ãã¼ãã³ããã³ã³ããã¼ã«ããéè¦ãªæ å ±ãçã¿åºãããå¯è½æ§ãããã¾ãã
ã以éãWebã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã¥ãªãã£ã¼ã«ã¤ãã¦ãããã¤ãã®ãããã¯ãç´¹ä»ãã¾ãã