â¨nori @00oichan SESâéèç³»SIerâå¤è³SaaSã¨ã³ã¸ã㢠ServiceNowï¼çæAIããã³ãããã§ãï¼ITILéç¨è¨è¨ï¼UiPathï¼Power Automate PowerBIãæããæå¹åºèº«ç¸æ¨¡åå¨ä½ã®2å ã®ç¶ Amazonã¢ã½ã·ã¨ã¤ã
ç§ã¯ãã®å±åºå¶åº¦ã®æå±è ã»è¨è¨è ã»éç¨ååè ã»æèè ç 究ä¼å§å¡ã§ãããIPAã®åºå ±ãåæã«ãããªåçãããã®ã§ããã°ãåºé±ç®ã§ããã社ä¼ã¸ã®æªå½±é¿ï¼ç´ã¡ã«å ¬è¡¨ãããã¨ãæå¹ã§ããäºæ¡ãç ã£ã¦ãã¾ãï¼ãç¡è¦ã§ããªãã®ã§ãããããIP⦠https://t.co/UMZMnodpiE
åºæ¬æ å ±ã»å¿ç¨æ å ±æã¡ã®å¤§å¦ç4å¹´çã 大å¦ã®ã¬ãã«ã¯æ¥æ±é§å°ãããã ããã¤ã³ã¿ã¼ãããã§IPAã®è³æ ¼ã¯æå³ãªãã¨èããã©ã就活ã«ããã¦ã¯æ» è¶è¦è¶æå©ã ã£ãã 楽天ã¿ãå°±ITä¼æ¥ã©ã³ãã³ã°ã§11~100ä½ã®ä¼æ¥ã9社åãã¦ã1社ã ããã£ã¬ã³ã¸ã¨ãã¦èº«ã®ä¸ã«åããªãä¼ç¤¾ãåãã¦ã¿ãã çµæã¯ã10社åãã¦ï¼åãè½ã¡ãªãã£ãã ã¤ã³ã¿ã¼ãããã§ã¯IPAã®è³æ ¼ãåã£ã¦ãä½ã®ã¹ãã«ã身ã«ã¤ããç¡é§ã ã¨ããè¨ãããã 確ãã«ãã®éãã ã¨æãããã®è³æ ¼ãåã£ãã¨ããã§ä½ãåºæ¥ããã¨è¨ããããç¹ã«ãªããããæ å ±ç³»ã®åºç¤çãªç¥èãã¨ãé·ãæç« ãç解ã§ããè½åãã示ãããããã ã§ãã就活ã«ããã¦ã¯ãã®è³æ ¼ã¯æå¼·ã ã£ããç¹ã«èªåã®ãããªä¸å 大å¦ã®å¦çãæ©æ ¶ä¸çãçããããªä¼æ¥ã«ãã£ã¬ã³ã¸ããç¹ã«è³ã£ã¦ã¯ã ãã就活åã®æ å ±ç³»å¤§å¦çããããããããã®IPAè³æ ¼æå³ãªãè«äºã«æããããã«åå¼·ãã¦è³æ ¼åã£ã¦ãã
å®æçã«å¤ããã®ã¯ããã£ã¦å±éºââãç·åçãã¤ã³ã¿ã¼ãããå©ç¨æã®ãã¹ã¯ã¼ãã«ã¤ãã¦ãå¾æ¥ã®"常è"ãè¦ããããªæ³¨æåèµ·ãå§ããããæ¨æ¸¬ããããæååã«ãªã£ã¦ä¸æ£ã¢ã¯ã»ã¹ã®ãªã¹ã¯ãå¢ããã¨ããã®ãçç±ã§ãè¤éãªãã¹ã¯ã¼ãã使ãç¶ããããå¼ã³ããã¦ãããæ¹é転æã«å°æãã声ãå°ãªããªãããå®æçã«ãã¹ã¯ã¼ããå¤æ´ãã¾ããããã3æ1æ¥ãç·åçã®ãå½æ°ã®ããã®æ å ±ã»ãã¥ãªãã£ãµã¤ãããããããªè¨è¿°
æ¦è¦ ç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ã½ããã¦ã§ã¢é«ä¿¡é ¼åã»ã³ã¿ã¼ï¼ä»¥ä¸ãIPA/SECï¼ã¯2018å¹´3æ6æ¥ããã½ããã¦ã§ã¢éçºãã¼ã¿ãèªãã¡ãã»ã¼ã¸2017ãï¼ä»¥ä¸ãæ¬æ¸ï¼ãå ¬éãã¾ããã æ¬æ¸ã¯ããã½ããã¦ã§ã¢éçºãã¼ã¿ç½æ¸2018-2019ãï¼2018å¹´10æçºè¡äºå®ï¼ä½æç¨ã«åéããææ°ã®ããã¸ã§ã¯ããã¼ã¿ã«åºã¥ãã¦ãã½ããã¦ã§ã¢éçºã®å¾åãåæãããã®ã§ãã åæã®çµæãã½ããã¦ã§ã¢éçºã®ä¿¡é ¼æ§ã¯åä¸ãã¦ãããã®ã®ãã½ããã¦ã§ã¢ã®å質ã«å¯¾ããè¦æ±ã®é«ã¾ãã«ãããçç£æ§ã¯ä½ä¸å¾åã«ãããã¨ãåããã¾ãããã¾ããçç£æ§ã»ä¿¡é ¼æ§ã®åä¸ã«ã¯å®éç管çãæ¨é²ããå質è¦æ±ã¬ãã«ã«è¦åã£ãçç£æ§ç®æ¨ãè¨å®ãã¹ããã¨ãããã«ãè¦å¡ã®äººæè²æãéè¦ã§ãããã¨ãåããã¾ããã èæ¯ã¨ç®ç è¿å¹´ãã½ããã¦ã§ã¢ã®å¤§è¦æ¨¡åï¼è¤éåãé²ãä¸æ¹ãä¿¡é ¼æ§åä¸ãçç£æ§åä¸ãéçºæéç縮çã®è¦æ±ã¯é«ã¾ã£ã¦ãã¾ãããã®
2017å¹´3æ15æ¥(æ¥æ¬æé)ã«Microsoft製åã«é¢ããèå¼±æ§ã®ä¿®æ£ããã°ã©ã MS17-010ãå ¬è¡¨ããã¾ããã ãã®èå¼±æ§ãã©ã³ãµã ã¦ã§ã¢ã®ææã«æªç¨ããå½å ãå«ãä¸çåå½ã§è¢«å®³ã確èªãããè±å½ã§ã¯å»çæ©é¢ã«ããã¦æ¥åã«æ¯éãåºããªã©ã®æ·±å»ãªå½±é¿ãçºçãã¦ãã¾ãã ã©ã³ãµã ã¦ã§ã¢ã«ææããã¨ã³ã³ãã¥ã¼ã¿ã®ãã¡ã¤ã«ãæå·åãããã³ã³ãã¥ã¼ã¿ã使ç¨ã§ããªã被害ãçºçããå¯è½æ§ãããã¾ãã ä»å観測ããã¦ããã©ã³ãµã ã¦ã§ã¢ã¯ Wanna Cryptor ã¨å¼ã°ãããã«ã¦ã§ã¢ (WannaCrypt, WannaCry, WannaCryptor, Wcry çã¨ãå¼ã°ãã) ã®äºç¨®ã§ããã¨èãããã¾ãã â»ã©ã³ãµã ã¦ã§ã¢ã¨ã¯ããRansomï¼èº«ä»£éï¼ãã¨ãSoftwareï¼ã½ããã¦ã§ã¢ï¼ããçµã¿åãããé èªã§ããææãããã½ã³ã³ã«ç¹å®ã®å¶éãããããã®å¶éã®è§£é¤ã¨å¼ãæãã«ééãè¦æ±
ãã¸ã¿ã«ãã¸ãã¹ã®æ¡å¤§ã¯æ代ã®è¦è«ã ãããããæ¨é²ããã¯ãã®IT人æãåã³è °ã«ãªã£ã¦ããããããªè¡æçãªçµæããæ å ±å¦çæ¨é²æ©æ§ï¼IPAï¼ã2017å¹´4æ24æ¥ã«å ¬éãããIT人æç½æ¸2017ãã§æããã«ãªã£ãã AIï¼äººå·¥ç¥è½ï¼ãIoTãªã©ã®ITãé§ä½¿ãããã¸ã¿ã«ãã¸ãã¹ã®æ¨é²ã¯æ代ã®æµããããã¾ã§ã®æ¥åã·ã¹ãã ã®éçºã¨ã¯åæãéãã¨ã¯ãããIT人æã¸ã®æå¾ ã¯å¤§ãããã«ãããããããèå¿ã®IT人æãæ°ãããã¨ã«ãã£ã¬ã³ã¸ãããã¨ããæ欲ãã5å¹´åã®èª¿æ»ããã大ããä¸ãã£ã¦ããã調æ»ãæ å½ããIPAã®å±±ï¨ æ±æ´¥éæ°ï¼IT人æè²ææ¬é¨ IT人æè²æä¼ç»é¨ ä¼ç»ã°ã«ã¼ãï¼ã¯ãã³ã¡ã³ãã«å°ãçµæã ãã¨ãã¼ãã ãæ°ããé¨ç½²ãä¼ç»ãç«ã¡ä¸ããããã20ãã¤ã³ã以ä¸æ¸å° IT人æããã£ã¬ã³ã¸ã«åã³è °ã«ãªã£ã¦ãããã¨ã示ã調æ»çµæã¯ãIT人æç½æ¸2017ã®ç¬¬3é¨ç¬¬6ç« ã«ããããã®ç« ã§ã¯ãä»äºãè·å ´ç°å¢
IPAï¼ç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ãçäºé·ï¼å¯ç° é夫ï¼ã»ãã¥ãªãã£ã»ã³ã¿ã¼ã¯ãã¬ãããããæ ªå¼ä¼ç¤¾æä¾ã®OSï¼åºæ¬ã½ããï¼ãRed Hat Enterprise Linux 4ãã®å»¶é·ãµãã¼ããããã³ãRed Hat Enterprise Linux 5ãï¼ä»¥å¾ãRHELï¼ã®é常ãµãã¼ãã2017å¹´3æ31æ¥ãåæã«çµäºãã(*1)ãã¨ãè¸ã¾ããã·ã¹ãã 管çè ã«éãããªç§»è¡ãæ±ããããã注æåèµ·ãè¡ãã¾ãã URLï¼https://www.ipa.go.jp/security/announce/rhel45_eos.html Linuxã¯ãªã¼ãã³ã½ã¼ã¹ã½ããã¦ã§ã¢ï¼OSSï¼ã®åºæ¬ã½ããã¨ãã¦ãç¡åã§å©ç¨å¯è½ãªãã¨ããåºãæ®åãã¦ãã¾ããã¾ãRHELã®å ´åããã®ä½¿éã¯å¤é¨ããã¤ã³ã¿ã¼ãããã§ã¢ã¯ã»ã¹ããããµã¼ãã¼ã«ãæ´»ç¨ããã¦ãã¾ãããã®ããããµãã¼ãçµäºã«ããä¿®æ£ããããæä¾ãããªããª
ãµã¤ãã¼æ»æã®å¢å ã»é«åº¦åã«å ãã社ä¼çãªITä¾å度ã®é«ã¾ãããããµã¤ãã¼æ»æã«ãã社ä¼çè å¨ãæ¥éã«å¢å¤§ãã¦ãã¾ããããªãã¡ãµã¤ãã¼ã»ãã¥ãªãã£å¯¾çã¯ãçµå¶ãªã¹ã¯ã¨ãã¦ãããã¦ç¤¾ä¼ç責任ã¨ãã¦ãé常ã«éè¦ãªèª²é¡ã«ãªãã¤ã¤ããããã®è²¬ä»»ãæ ãã人æã®ç¢ºä¿ãæ¥åã¨ãªã£ã¦ãã¾ãããã®äººæã®ç¢ºä¿ã®ããã«2016å¹´10æã«ãæ å ±å¦çã®ä¿é²ã«é¢ããæ³å¾ããæ¹æ£ãããæ°ããªå½å®¶è³æ ¼ãèªçãã¾ãããããããæ å ±å¦çå®å ¨ç¢ºä¿æ¯æ´å£«ï¼ç¥ç§°ï¼ç»é²ã»ãã¹ãï¼ãã§ãã æ¬ãã¼ã¸ã§ã¯ããæ å ±å¦çå®å ¨ç¢ºä¿æ¯æ´å£«ï¼ç»é²ã»ãã¹ãï¼ãå¶åº¦ã«é¢ããæ å ±ãæ²è¼ãã¦ãã¾ãããã²ã覧ãã ããã æ å ±å¦çå®å ¨ç¢ºä¿æ¯æ´å£« æ°è¦ç»é²ã»æ´æ°ã®ãæ¡å 2024å¹´7æï½8æã«ãå½å®¶è³æ ¼ãæ å ±å¦çå®å ¨ç¢ºä¿æ¯æ´å£«ãããããï¼èª¬æä¼ããå®æ½ãã¾ããã å½å®¶è³æ ¼ãæ å ±å¦çå®å ¨ç¢ºä¿æ¯æ´å£«ãããããï¼èª¬æä¼(2024å¹´7æ4æ¥ï½8æ15æ¥ãªã³ããã³ãé ä¿¡
å°å·ãã ã¡ã¼ã«ã§éã ããã¹ã HTML é»åæ¸ç± PDF ãã¦ã³ãã¼ã ããã¹ã é»åæ¸ç± PDF ã¯ãªããããè¨äºãMyãã¼ã¸ããèªããã¨ãã§ãã¾ã ç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ï¼IPAï¼ã¯4æ27æ¥ããIT人æç½æ¸2016ããçºè¡ãããæ¬æ¸ã¯IPAãæ¯å¹´ãITä¼æ¥ãã¦ã¼ã¶ã¼ä¼æ¥ã大å¦çæè²æ©é¢ã対象ã¨ããIT人æåå調æ»ãããã³ITæè¡è å人ã対象ã¨ããæè調æ»ãè¡ãã調æ»çµæãã¾ã¨ãã¦çºè¡ãã¦ãããã®ã ä»åã®ç½æ¸ã§ã¯ãIPAã«ãã2015年度調æ»çµæããæ¥æ¬éè¡ãä¼æ¥çæçµæ¸è¦³æ¸¬èª¿æ»ãï¼æ¥éç観ï¼ã®ãã¼ã¿ãå ã«ããããå½ã®IT人æã®å ¨ä½åããç´¹ä»ãã¦ããã ãã®ä¸»ãªçµæã¯ä»¥ä¸ã®éãã æ å ±ãµã¼ãã¹ç£æ¥ã«ãããéç¨ã®åå ã¾ããæ¥æ¬éè¡ãä¼æ¥çæçµæ¸è¦³æ¸¬èª¿æ»ãï¼æ¥éç観ï¼ã«ããã°ãéç¨äººå¡ã¯å ¨ç£æ¥ã§è¦ãã¨2013å¹´3æãããã¤ãã¹ã«ãªããä¸è¶³ããç¶ç¶ãã¦ããããæ å ±ãµã¼ãã¹æ¥ãã«
ãã®ã¨ããã®ã¦ã¤ã«ã¹ææ被害ã®å ±éã§ã¯ãå¤é¨ã®æ©é¢ããã®éå ±çã«ãã£ã¦åãã¦ææã«æ°ã¥ããããã±ã¼ã¹ãã»ã¨ãã©ã§ãããããããã¨ãããèªçµç¹ã«ããã¦ãææã«æ°ãä»ããªãã¾ã¾ãæ½ä¼ããã¦ããã®ã§ã¯ãã¨ã®æ¸å¿µãé«ã¾ã£ã¦ãããã®ã¨èãããã¾ããIPAã§ã¯6æ1æ¥ã®å ¬çæ©é¢ããã®å人æ å ±æ¼æ´©ã®å ±éãåãã対çã¨éç¨ç®¡çã«é¢ãã注æåèµ·ã6æ2æ¥ï¼*1ï¼ã6æ10æ¥ï¼*2ï¼ã«è¡ã£ã¦ãã¾ããæ¬æ¥ã®æ³¨æåèµ·ã§ã¯ãâæ¤ç¥ãããæãã¦ä¾µå ¥ãã¦ãã¾ã£ãã¦ã¤ã«ã¹ã«ããææâã®æ¤æ»ãæ¨å¥¨ããç®çã§ã端æ«å ã«æ½ä¼ããã¦ã¤ã«ã¹ã®æç¡ã確èªããããã®æ å ±ã¨ãã¦ãã¦ãå ¬éãã¾ãã ãã¨ãçµç¹å å ¨ã¦ã®ç«¯æ«æ¤æ»ã¯å°é£ã§ããæ¥åã§å¤é¨ããã®ã¡ã¼ã«ãé »ç¹ã«åãä»ãã¦ãã¦ãâçµç¹å ã¸ã®ææã®çªç ´å£ã¨ãªãå¾ãâé¨ç½²ã®ç«¯æ«ãªã©ãåªå é ä½ã®é«ã端æ«ãããå¯è½ãªéãæ¤æ»ãé²ãããã¨ãæ¨å¥¨ãã¾ãã æ¨çåæ»æã¡ã¼ã«ã使ã£ãæ»æã¯ã(1)ã¡ã¼
IPAã¯2æ2æ¥ãæ å ±ã»ãã¥ãªãã£ã«é¢ãããä»æã®å¼ã³ãããã¨ãã¦ãWebãµã¤ããé²è¦§ãã¦ããæã«è¡¨ç¤ºãããPCã®ä¸èª¿ã示åãããããªã¡ãã»ã¼ã¸ã«æ³¨æããããããã®æå£ã¨è¢«å®³ãåé¿ããããã®å¯¾çãå ¬éããã ããã£ã¨ã»ãã®åçãã¿ãã Webãµã¤ãã®é²è¦§ä¸ã«ãPCã®æ§è½ãä½ä¸ãã¦ãã¾ããããã«ã¨ã©ã¼ãä¿®æ£ãã¦ãã ãããã¨ããã¡ãã»ã¼ã¸ã表示ãããããPCã«åé¡ãããã®ãã¨ããç¸è«ããIPAã«å¤ãå¯ãããã¦ããã¨ããã IPAã«ããã¨ããã®ã¡ãã»ã¼ã¸ã¯ãã½ããã¦ã§ã¢ã®è³¼å ¥ãä¿ãããã®æå£ãã®ä¸é¨ã§ãçªç¶ãã¦ã¤ã«ã¹ã¹ãã£ã³ãå§ã¾ã£ããããªç»é¢ã表示ãã æçµçã«æåçã½ããã¦ã§ã¢ã®è³¼å ¥ã«èªå°ãã¦ããã¨ããã Webãµã¤ãé²è¦§ä¸ã«è¡¨ç¤ºãããPCã®ä¸èª¿ã示åãããããªã¡ãã»ã¼ã¸ã¯ãä¸ç¹å®å¤æ°ã«é²è¦§ããããã¨ãæå³ããWebãµã¤ãã®ã³ã³ãã³ãã§ãããPCãç°å¸¸ãªç¶æ ã«ãããã¨ã示ãã·ã¹ãã ã«ãã
IPAï¼ç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ãçäºé·ï¼è¤æ±ãä¸æ£ï¼ã¯ã2011å¹´2æ28æ¥ãWAFã®å°å ¥ã»éç¨ã«ãããè¦ç¹ãæ¡å ããå®ä¾ãç´¹ä»ãããWeb Application Firewallï¼WAFï¼èªæ¬ æ¹è¨ç¬¬2çããIPAã®ã¦ã§ããµã¤ãã«ã¦å ¬éãã¾ããã URLï¼ãhttp://www.ipa.go.jp/security/vuln/waf.html IPAã¯ã¦ã§ããµã¤ãã®éç¨é¢ã§ã®èå¼±æ§å¯¾çã®ä¸ã¤ã¨ãã¦Web Application Firewallï¼ã¦ã§ãã»ã¢ããªã±ã¼ã·ã§ã³ã»ãã¡ã¤ã¢ã¦ã©ã¼ã«ãWAFï¼ãæå¹ã¨èãã¦ãã¾ãã ããããIPAãä¼æ¥ã«è¢«å®³ç¶æ³èª¿æ»(*1)ããããªã£ãã¨ãããWAFããå°å ¥æ¸ã¿ãã¨åçããä¼æ¥ã¯å ¨ä½ã®25.8%ã«çã¾ããªã©ãWAFã®å°å ¥ãé²ãã§ããªãç¶æ³ãæããã«ãªãã¾ããããã®èæ¯ã«ã¯ããWAFã®å°å ¥ã«é¢ããæ å ±ãå°ãªããWAFã®å°å ¥ã«ãããè²»ç¨ãå·¥æ°ãã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}