é·ã使ãã°ä½¿ãã»ã©ãã®éããããã Seagateæè¡æ¬é¨ æ¬é¨é·ãèªãBarraCuda 120 SSDã®èä¹ æ§&ä¿¡é ¼æ§ãé«ãçç± æå¹æéã®å»¶é·ãã製åèªè¨¼ãã¼ã®ç¢ºèªãã¤ã³ã¹ãã¼ã«ãã¡ã¤ã«ã®ãã¦ã³ãã¼ãã¾ã§ ESETã¦ã¼ã¶ã¼ãªã使ããªãã®ã¯ãã£ãããªããµã¼ãã¹ãCLUB ESETãå©ç¨ã¬ã¤ã LINEã§ç°¡åæä½ã§ãããã¼ã IoTãµã¼ãã¹ã§ã家ãè¦å®ãï¼é»æ°ä»£ãç¯ç´ï¼ ããã³ãªã³ãã¼ã ãã©ã¹ãã§ã¤ã³ãã«ã¨ã³ã¶ãç±ä¸çã¨ã¯ç¡ç¸ã®å¿«é©çæ´»ã®ã¹ã¹ã¡ ç»é¢ãç´æ¥æä½ããã«å©ç¨ã§ããã«ã¼ããã¢ããªã®å®å ¨æ§ ããªããé転ãå³ç½°åãã§ã¹ãããããå ¨æ» !?ãé³å£°æä½ãããªãå¿é ç¡ç¨ï¼ åä½ã§ããã¡ãã便å©ã ããçµã¿åããã¦ä½¿ãã¨ããã«ä¾¿å©ï¼ ãã¡ã¼ã¦ã§ã¤ã®ã¹ããã¨ã¤ã¤ãã³ã¨ã¹ãã¼ãã¦ã©ããã§æ¥å¸¸ãã¬ãã«ã¢ããï¼ ç¢ºå®ç³åãã®ãã¼ã¯ããã«æ³¨æï¼ ã2020å¹´æåºã確å®ç³åãããæããããªãï¼ããã
ã©ã¤ã¶ã ã¼ã³æ»æã«å¯¾ããè¡ãå±ãã解説ãèªã¿ã¾ããã 大è¦æ¨¡ã¤ã³ã¸ã§ã¯ã·ã§ã³ ãLizaMoonãæ»æã«ã¤ãã¦èª¿ã¹ã¦ã¿ãã - piyolog ããã§ç´¹ä»ããã¦ããå 容ã¯ç´ æ´ãããã¨æãã®ã§ãããä¸ç¹ãWAFã«é¢ãã以ä¸ã®è¨è¿°ãå¼ã£ãããã¾ããã SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã§ããã°æ¢ç¥ã®æ»æææ³ã§ããWAFã§é²ããã¨ã¯åºæ¥ãã®ã§ã¯ã¨ããèãæ¹ãããã¾ãããä¾ãã°ãã©ãã¯ãªã¹ãã¿ã¤ãã®WAFã§ãã®æ°å¤ãªãã©ã«åãã¤ãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ãé²ããã¨ãåºæ¥ã¾ãããHTTPãªã¯ã¨ã¹ãã¨ãã¦åããæååã ãã§ãæçµçã«ãã¼ã¿ãã¼ã¹ã«å¯¾ãã¦çºè¡ãããSQLã§ãã®æååãã©ã®ãããªæ±ãã«ãªãã(æ°å¤ãªãã©ã«ã«ãªãã®ãã©ãã)å¤æãããã¨ãåºæ¥ãªãããã§ãã æ¬å½ã«ãã©ãã¯ãªã¹ãã¿ã¤ãã®WAFã§é²ããã¨ãã§ããªãã®ã§ãããããIBMã®ã¬ãã¼ãã«ç´¹ä»ããã¦ãã以ä¸ã®æ»æã§èãã¦ã¿ã¾ãã /target.asp
ãã©ã¼ãã£ãããã¯ãWebã¢ããªã±ã¼ã·ã§ã³ãã¡ã¤ã¢ã¦ã©ã¼ã«ã®æ°è£½åã¨ãã¦ããããã¬ã³ã¸åãã¨ãã¤ã¨ã³ãåãã®2ã¢ãã«ãçºè¡¨ããã ãã©ã¼ãã£ãããã¸ã£ãã³ã¯9æ9æ¥ãWebã¢ããªã±ã¼ã·ã§ã³ãã¡ã¤ã¢ã¦ã©ã¼ã«ï¼WAFï¼ã®æ°è£½åã¨ãªããããã¬ã³ã¸åãã®ãFortiWeb-1000Cãããã³ãã¤ã¨ã³ãåãã®ãFortiWeb-3000Cããçºè¡¨ãããææ°ãã¡ã¼ã ã¦ã§ã¢ãFortiWeb 4.0 MR1ãã®æ¡ç¨ã«ãããã³ã³ãã³ãã®èªå復æ§ãèå¼±æ§ã®æ¤æ»æ©è½ãæè¼ããã¦ããã FortiWeb-1000Cã¯ãæ大ã¹ã«ã¼ãããã500MbpsãHTTPãã©ã³ã¯ã·ã§ã³ãæ¯ç§2ä¸7000ã®æ§è½ãæã¤ãFortiWeb-3000Cã§ã¯æ大ã¹ã«ã¼ãããã1GbpsãHTTPãã©ã³ã¯ã·ã§ã³ãæ¯ç§4ä¸ã¨ãªãã大è¦æ¨¡ãªãã¼ã¿ã»ã³ã¿ã¼ã§ã®éç¨ã«èããä»æ§ã¨ãªã£ã¦ããã æ¬è£½åã¯ãWebã·ã¹ãã ã«åå¨ããã¯ãã¹ãµã¤ãã¹ã¯
ã¤ã³ãã¬ã¹ãã¸ãã¹ã¡ãã£ã¢ã¯2010å¹´5æ24æ¥ãç±³F5 Networksã§ã»ãã¥ãªãã£åéã®ãããã¯ãã»ããã¼ã¸ã£ãåªããIdo Bregeræ°ã«ãWAFã®å¸å ´ååã¨ãBIG-IP ASMã®ææ°æ©è½ã«ã¤ãã¦èããã ---WAFãåãå·»ã2010å¹´ç¾å¨ã®å¸å ´ååã¯ã Ido Bregeræ°: ã¾ããå®ãã¹ãWebã·ã¹ãã ãå¢ãã¦ãããWebãµã¼ãã¼å´ã®å¤åã¨ãã¦ã¯ãããã¸ãã¦ã¬ã¬ã·ã¼ã»ã·ã¹ãã ã®Webåãå éãã¦ãããWebã¯ã©ã¤ã¢ã³ãå´ã®å¤åã¨ãã¦ã¯ãã¿ãã¬ããPCãã¹ãã¼ããã©ã³ã®æµ¸éã«è¦ãããããã«ããã¤ã§ãã©ãã§ã誰ã§ãWebåãããæ¥åã·ã¹ãã ã«ã¢ã¯ã»ã¹ã§ããç¶æ³ã«ãªã£ã¦ãã¦ããã æ»æ対象ã¨ãªãWebã·ã¹ãã ã®ç¨®é¡ãå¢ãã¦ãããç¹å®ã®ä¼æ¥ã対象ã¨ããæ»æã ãã§ãªããä¸ç¹å®å¤æ°ã¸ã®æ»æãèªåçã«å®æ½ããåããããã1å¹´ã»ã©é«ã¾ã£ã¦ãããWebã·ã¹ãã ãã©ã³ãã ã«ã¹ãã£ã³ï¼èµ°æ»ï¼
ãã³ã¿ã»ãã¥ãªãã£ã·ã¹ãã ãºæ ªå¼ä¼ç¤¾ï¼ãã³ã¿ã»ãã¥ãªãã£ï¼ã¯5æ10æ¥ãWebã¢ããªã±ã¼ã·ã§ã³ãã¡ã¤ã¢ã¦ã©ã¼ã«ï¼WAFï¼ã¢ãã©ã¤ã¢ã³ã¹ãWAPPLESãã®ã©ã¤ã³ã¢ããã«ã3ã¢ãã«ã追å ããã¨çºè¡¨ãããæ°ãã«æä¾ãããã®ã¯ãã¨ã³ããªã¼åãã®ãWAPPLES-50ãã¨ããã¤ã¨ã³ãåãã®ãå-2000ããå-5000ãã§ãããããåæ¥ããæä¾ãéå§ãããä¾¡æ ¼ã¯200ä¸åï¼ç¨å¥ï¼ããã WAPPLESã¯ãWebã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ãä¿è·ããããã«å©ç¨ããããWAFã¢ãã©ã¤ã¢ã³ã¹è£½åãã·ã°ããã£ãå©ç¨ãããã¿ã¼ã³ãããã³ã°ã«é ¼ããªããç¬èªã®ãã¸ãã¯åæã¨ã³ã¸ã³ã«ãããæ»æè ãçãèå¼±æ§ãåããææ³ãæ¡ç¨ããé«ãæ¤åºçã¨ä½ã誤æ¤ç¥çãå®ç¾ãã¦ããã®ãç¹å¾´ã ãã¾ããäºåã«è¨å®ãããããªã·ã¼ãé¸æè¢ã26åã®ã«ã¼ã«ãè¨å®ããã ãã§æ¤ç¥è¨å®ãè¡ãããªã©ã管çã«è¦ããæéãåæ¸ããã¦ãããã¨ãããä»ç¤¾è£½å
ã»ãã¥ãªãã£Expert 2010ã«å¤§æ²³å æºç§æ°ããç¾ç¶ã®èª²é¡ã¨âå®ç§ãªWAFâãã¨é¡ãã¦å¯ç¨¿ããã¦ããã大å¤èå³æ·±ãå 容ã§ããã®ã§ããã®å¯ç¨¿ããªãããªãããWAFã®é²å¾¡æ¦ç¥ã«ã¤ãã¦æ¤è¨ãã¦ã¿ããã ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°(XSS)ã«å¯¾ããé²å¾¡ 大河å æ°ã®å¯ç¨¿ã®ååã¯ãç¾ç¶ã®WAFã®èª²é¡ã¨ãã¦ãWebã¢ããªã±ã¼ã·ã§ã³ã«å¯¾ããæ»æã®å¤ãï¼å¤§åï¼ãWAFã®ããã©ã«ãè¨å®ã§ã¯é²å¾¡ã§ããªãã¨ææãããä¾ãã°ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°(XSS)ã«é¢ãã¦ã¯ã以ä¸ã®ãããªææãããã ä»®ã«scriptããã©ãã¯ãªã¹ãã«æå®ããã¨ãã¾ããããããã§ãã¾ã ä¸ååã§ãã<IMG>ã¿ã°ã§XSSãçºåãããã¨ããåãã§ããããï¼ããã°ã©ã ãªã©ã§ã¯<IMG>ã¿ã°ã¯ç»åæ·»ä»ã«å¿ é ã§ãããWAFã§ç¦æ¢ãããã¨ã¯é£ããã®ãå®æ ã§ããã©ãã¯ãªã¹ãæ¹å¼ã®èª²é¡ã¨ãªã£ã¦ãã¾ãã ãç¾ç¶ã®èª²é¡ã¨âå®ç§ãªWAFâãããå¼
2019å¹´3æ28æ¥ã«ããWeb Application Firewall èªæ¬ãã®è£è¶³è³æã¨ãã¦ããWeb Application Firewallã®å°å ¥ã«åããæ¤è¨é ç®ããå ¬éãã¾ããã ãã¡ãã¯ãWAFã®å°å ¥ãæ¤è¨ããã¦ããæ¹ãæ¢ã«å°å ¥æ¸ã¿ã§éç¨ãè¦ç´ãããæ¹åãã«ãWAFã«ã¯ã©ã®ãããªè£½åã»ãµã¼ãã¹ç¨®é¡ãåå¨ããã©ã®ãããªç¹å¾´ãããã éç¨ã®éã«ã©ã®ãããªä½å¶ãå¿ è¦ãã解説ãã¦ããã¾ãã æ¦è¦ ãWeb Application Firewall èªæ¬ã ãWeb Application Firewall èªæ¬ãã¯ãã¦ã§ããµã¤ãéå¶è ãWAFã®å°å ¥ãæ¤è¨ããéã«ãWAFã®ç解ãæå©ãããããã®è³æã§ããæ¬è³æã§ã¯ãKISA(*1)ãOWASP(*2)ãWASC(*3)ãªã©ã®æ©é¢ã«ãããWAFã«é¢ããåãçµã¿ãWAFã®æ¦è¦ãæ©è½ã®è©³ç´°ãå°å ¥ã«ããããã¤ã³ãçãã¾ã¨ãã¾ããã 第1ç« ã§ã¯
EnterpriseZineï¼ã¨ã³ã¿ã¼ãã©ã¤ãºã¸ã³ï¼ç·¨éé¨ã§ã¯ãæ å ±ã·ã¹ãã æ å½ãã»ãã¥ãªãã£æ å½ã®æ¹ã åãã«ãEnterpriseZine DayãSecurity Online DayãDataTechã¨ããã3ã¤ã®ã¤ãã³ããéå¬ãã¦ããã¾ããããããç·¨éé¨ç¬èªã®åãå£ã§ãæ¥çãã¬ã³ããææ°äºä¾ãç¶²ç¾ ãææ°ã®ååãç¥ããã¨ãã§ããå ´ã¨ãã¦ã好è©ãå¾ã¦ãã¾ãã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}