Microsoftã¯ãã®ã»ã©ããToken tactics: How to prevent, detect, and respond to cloud token theft - Microsoft Security Blogãã«ããã¦ãèªè¨¼ã«ç¨ãããããã¼ã¯ã³ã®çé£ãæ¥å¢ãã¦ããã¨ä¼ãããçµç¹ãå¤è¦ç´ èªè¨¼(MFA: Multi-Factor Authentication)ã®é©ç¨ç¯å²ãæ¡å¤§ããã«ã¤ãããµã¤ãã¼æ»æè ã¯ä¼æ¥ã®ãªã½ã¼ã¹ã侵害ã§ãããããããæ´ç·´ãããææ³ã«ç§»è¡ãã¦ãã¦ããã¨è¦åãã¦ããã Token tactics: How to prevent, detect, and respond to cloud token theft - Microsoft Security Blog ãµã¤ãã¼æ»æã®æå£ã¨ãã¦ããã¼ã¯ã³çé£ãå¢å ãã¦ãããã¨ãMicrosoft Detection
Windowsã§ã¯ãUEFI UpdateCapsule颿°ã使ç¨ãã¦å¦çããããã©ã¤ãã¼ ããã±ã¼ã¸ã使ç¨ãã¦ãã·ã¹ãã ã¨ããã¤ã¹ã®ãã¡ã¼ã ã¦ã§ã¢æ´æ°ããã°ã©ã ãã¤ã³ã¹ãã¼ã«ããããã®ãã©ãããã©ã¼ã ããµãã¼ãããã¦ãã¾ãã ãã®ãã©ãããã©ã¼ã ã¯ãä¸è²«æ§ã®ããä¿¡é ¼æ§ã®é«ããã¡ã¼ã ã¦ã§ã¢æ´æ°ã¨ã¯ã¹ããªã¨ã³ã¹ãæä¾ããã¨ã³ã ã¦ã¼ã¶ã¼ã«ã¨ã£ã¦éè¦ãªã·ã¹ãã ãã¡ã¼ã ã¦ã§ã¢æ´æ°ããã°ã©ã ã®æ¤åºå¯è½æ§ãåä¸ããã¾ãã UEFI ãã¡ã¼ã ã¦ã§ã¢æ´æ°ãã©ãããã©ã¼ã ã®ã¬ã¤ãã³ã¹ã¯ãWindows ãå®è¡ãããã¼ãã¦ã§ã¢ ãã©ãããã©ã¼ã ãæ§ç¯ãã¦ãã SoC ãã³ãã¼ããã³ OEM ã対象ã¨ãã¦ãã¾ãã UEFI ãã¡ã¼ã ã¦ã§ã¢æ´æ°ãã©ãããã©ã¼ã ã¯ã次ã®ãªãã¬ã¼ãã£ã³ã° ã·ã¹ãã ãã¼ã¸ã§ã³ã§ãµãã¼ãããã¦ãã¾ãã Windows 8 Windows 8.1 Windows 10 ãã¹ã¯ããã
ãã°ããç°¡åã«ã注æãå¯è½ 注æå 容ã®è¡¨ç¤ºãé éç¶æ³ããã©ã㯠ä¼å¡éå®ã®ç¹å ¸ãå²å¼ã®ãå©ç¨ 製åãªã¹ãã®ä½æã¨ã¢ã¯ã»ã¹ãå¯è½
ãPLOS Oneãã«æ²è¼ãããæ°ããç ç©¶ã§ãã¤ã§ã¼ã«å¤§å¦ã®ç ç©¶è ãã¡ã¯ãç¬åµçãªæè¡ã使ããå¾é é é åã¨ãã¦ç¥ããã¦ããèªéçã®ç¤¾ä¼ççåã¨é¢é£ããè³ã®ç¹å®ã®é åãçªãæ¢ããã èªéçã®äººã ã®å¤§å¤æ°ã¯ã社ä¼çãªäº¤æµã®éã«ç®ã¨ç®ãåãããªãã¨ãã鏿ããããèªéã¹ãã¯ãã©ã çï¼ASDï¼ã®æç çã¯å°ãªãã¨ã500人ã«1人ã ãããã¾ã ã«åºã誤解ãããã¹ãã£ã°ãåããã¦ããè¤éãªç¥çµçºéçã§ããã¨ããã¦ããã 2人以ä¸ã®äººéã«ãããªã¢ã«ã¿ã¤ã ã®ããã¨ãã¯ã人ã®è¡¨æ ãã¢ã¤ã³ã³ã¿ã¯ããä¸»ãªæ å ±æºã¨ãããåçãã¤ç¸äºä½ç¨çãªãã®ã«ãªãå¾åãããã å®çæ´»ã§ã®ä¼è©±ã交æµã®ä¸ã§ãé¡ããéè¦ãªæ å ±ãã·ã¼ã ã¬ã¹ãã¤æ¦ç¥çã«å¾ããã¨ã¯ãèªéçã®æäººã«ã¨ã£ã¦å¤§ããªé害ã¨ãªã£ã¦ããããASDã«ãããç¾å®ã®é¡ã«ããããã¨ãã調æ»ãããã¨ã®éè¦æ§ã¯ãæè¿ãäºäººç§°ã®ç¥çµç§å¦ããæ±ãã声ã«ãã£ã¦èªèããã¦ãã¾ããã¨ãç ç©¶è
æ±åé»åãï¼ï¼æ¥ãå®¶åºåã黿°æéï¼è¦å¶æéï¼ã®å¤ä¸ããçµæ¸ç£æ¥çã«ç³è«ããæ±äº¬ãåé¸ãä¸å½ãªã©å¤§æé»åï¼ç¤¾ãå¤ä¸ãã®æºåãé²ãã¦ããã䏿¹ã§é¢è¥¿ãä¹å·ã®é»åï¼ç¤¾ã¯ç¾ç¶ã§ã¯å¤ä¸ãã表æãã¦ããªãããã®èæ¯ã«ã¯åååçºé»ãä¸å¿ã¨ãã黿ºæ§æã®éããããããã ã é¢è¥¿é»åãï¼ï¼æï¼ï¼æ¥ã«çºè¡¨ãã令åï¼å¹´ï¼æä¸éé£çµæ±ºç®ã§ã¯ãæçµæçãï¼ï¼ï¼ååã®èµ¤åã§ãä¸é決ç®ã§ã¯ï¼ï¼å¹´ã¶ãã®èµ¤åã¨ãªã£ããã¦ã¯ã©ã¤ã屿©ã¨åå®ãèæ¯ã¨ããçæä¾¡æ ¼é«é¨°ãå½±é¿ããã¨èª¬æããããè¦å¶æéã®å¤ä¸ãã«ã¤ãã¦ã¯ç¾å¨ã¾ã§ã決ã¾ã£ããã®ã¯ãªããã¨ãã¦ããã åç¤¾ã®æ£®æ(ã®ãã)社é·ãåæ¥ã®æ±ºç®ä¼è¦ã§ãå¤ä¸ãã®æ¹éã«ã¤ãã¦åãããã¨ãé常ã«å¤åã®æ¿ããçµå¶ç°å¢ãè¦æ¥µããç·åçã«å¤æãããã¨è¿°ã¹ãã«ã¨ã©ããã é»åä¼ç¤¾ãã¨ã«å¤ä¸ãã®å¤æãåããã¦ããã®ã¯ãªãããé¢ä¿è ã«ããã¨ãé»åä¼ç¤¾ãã¨ã«é»æ°æéã®ãã¨ã¨ãªããå価ãã®ç®å®ã«é
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}