(c) Recruit Co., Ltd.

ããã«ã¡ã¯ãCTOã®ã¯ãããã§ãã æ¬æ¥ãAWSããã®ã»ããã¼ã«ã¦ãä¸è¨å 容ã®çºè¡¨ãå¼ç¤¾å®ç°å·ãè¡ãã¾ããã ãã®ã¨ãããå¤ãã®ã客æ§ãããå®éãAWS WAFã£ã¦ã©ããããæ»æãé²ãããã§ãã?ããAWS WAFã®æ§ç¯ãããå°ãç°¡åã«ã§ãã¾ãããï¼ããAWS WAFãå°å ¥ããã®ã¯ããããã©ãã©ãéç¨ããã°ããã®ãããããªãããªã©ã®ãåãåãããããé ãã¾ã¾ãããã®ãããªå£°ã«ãå¿ããããããå¼ç¤¾ã§ã¯å®ç°å·ãä¸å¿ã«AWS WAFã®èª¿æ»ç 究ãé²ãã¦ãããæ¬æ¥ã®ã»ããã¼ãå¥æ©ã«ã調æ»å 容ãç©æ¥µçã«å ¬éãã¦ãããã¨ã¨è´ãã¾ããã ä»å¾ãããWAFã¨ããã°ãã£ã±ãã»ãã¥ã¢ã¹ã«ã¤ã»ãã¯ããã¸ã¼ï¼ãã¨è¨ã£ã¦ãããããããç©æ¥µçã«æ å ±å ¬éãç¶ç¶ãã¦ããã¾ãã®ã§ããã²ãæå¾ ãã ããã
2012å¹´ã®å¾åãããããã¬ã³ã¿ã«ãµã¼ãã¼ã§WAFï¼ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ãã¡ã¤ã¢ã¦ã©ã¼ã«ï¼ãå°å ¥ããã¨ãããå¢ãã¦ãã¾ããã WAFèªä½ã¯è¯ãç©ãªã®ã§ãããCMSã¨ã®ç¸æ§ãæªãï¼CMSã®åä½ã誤æ¤ç¥ããã¦ãã¾ã403ã¨ã©ã¼ãè¿ãããï¼ããããããªãã«ãã¹ããã¨ãã£ãæ å ±ãæ£è¦ããã¾ãã ããããè¯ãç©ããªãã«ãã¦ã»ãã¥ãªãã£ã®ãªã¹ã¯ãä¸ãããã¨ããªããããã£ãããªã®ã§WAFã¨WordPressãå ±åããã¦ã¿ããã¨æãã¾ãã WAFï¼ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ãã¡ã¤ã¢ã¦ã©ã¼ã«ï¼ã¨ã¯ WAFï¼ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ãã¡ã¤ã¢ã¦ã©ã¼ã«ï¼ã¯ãå¾æ¥ã®ãã¡ã¤ã¢ã¦ã©ã¼ã«ãIDSãIPSã§ã¯é²å¾¡ã§ããªãã£ãæ»æãæ¤ç¥ãããããã¯ããæ©è½ã§ãã å¼ç¨ããããã¤ã³ã¿ã¼ããã â WAFï¼ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ãã¡ã¤ã¢ã¦ã©ã¼ã«ï¼ã å°å ¥ãããã¨ã§Webãµã¼ãã¼ã«å¯¾ããä¸æ£ãªã¢ã¯ã»ã¹ãWAFããããã¯ãã¦ããã¾ããé
SiteGuard Liteã¯ã·ã°ããã£æ¤æ»ã«ç¹åãããã¨ã§ä¾¡æ ¼ãä¸ããå»ä¾¡çã¨è¨ããã¨ã«ãªãã¾ãã ã¤ã³ã¹ãã¼ã« SiteGuard Liteã¯åç¨è£½åã§ãã®ã§ãã¤ããªã§ã®æä¾ã¨ãªãã¾ããRed Hat Enterprise Linux 4/5/6ãããã¯CentOS 4/5/6ãåä½å¯è½ãã£ã¹ããªãã¥ã¼ã·ã§ã³ã¨ãªã£ã¦ãã¾ããçè ã¨ãã¦ã¯Ubuntuä¸ã§ãåä½ç¢ºèªãã¦ããããã¨ãããããã¨æãã¾ããã®ã§ãJP-Secure社ã«ã¯ããè¦æãã¦ãã¾ãã rpmã«ããã¤ã³ã¹ãã¼ã«ã¯åºæ¬çã«ã¯ä»¥ä¸ã®3ã³ãã³ãã§ãã # rpm -Uvh siteguardlite-1.00-beta.i386.rpm # cd /opt/jp-secure/siteguardlite/ # ./setup.sh æå¾ã®setup.shã¯Apacheã®å種ãã¹ãªã©ãæå®ãããã®ã§ãããã®ä»ãSE Linuxç¨ã®ã
ã©ã¤ã¶ã ã¼ã³æ»æã«å¯¾ããè¡ãå±ãã解説ãèªã¿ã¾ããã 大è¦æ¨¡ã¤ã³ã¸ã§ã¯ã·ã§ã³ ãLizaMoonãæ»æã«ã¤ãã¦èª¿ã¹ã¦ã¿ãã - piyolog ããã§ç´¹ä»ããã¦ããå 容ã¯ç´ æ´ãããã¨æãã®ã§ãããä¸ç¹ãWAFã«é¢ãã以ä¸ã®è¨è¿°ãå¼ã£ãããã¾ããã SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã§ããã°æ¢ç¥ã®æ»æææ³ã§ããWAFã§é²ããã¨ã¯åºæ¥ãã®ã§ã¯ã¨ããèãæ¹ãããã¾ãããä¾ãã°ãã©ãã¯ãªã¹ãã¿ã¤ãã®WAFã§ãã®æ°å¤ãªãã©ã«åãã¤ãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ãé²ããã¨ãåºæ¥ã¾ãããHTTPãªã¯ã¨ã¹ãã¨ãã¦åããæååã ãã§ãæçµçã«ãã¼ã¿ãã¼ã¹ã«å¯¾ãã¦çºè¡ãããSQLã§ãã®æååãã©ã®ãããªæ±ãã«ãªãã(æ°å¤ãªãã©ã«ã«ãªãã®ãã©ãã)å¤æãããã¨ãåºæ¥ãªãããã§ãã æ¬å½ã«ãã©ãã¯ãªã¹ãã¿ã¤ãã®WAFã§é²ããã¨ãã§ããªãã®ã§ãããããIBMã®ã¬ãã¼ãã«ç´¹ä»ããã¦ãã以ä¸ã®æ»æã§èãã¦ã¿ã¾ãã /target.asp
ã»ãã¥ãªãã£Expert 2010ã«å¤§æ²³å æºç§æ°ããç¾ç¶ã®èª²é¡ã¨âå®ç§ãªWAFâãã¨é¡ãã¦å¯ç¨¿ããã¦ããã大å¤èå³æ·±ãå 容ã§ããã®ã§ããã®å¯ç¨¿ããªãããªãããWAFã®é²å¾¡æ¦ç¥ã«ã¤ãã¦æ¤è¨ãã¦ã¿ããã ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°(XSS)ã«å¯¾ããé²å¾¡ 大河å æ°ã®å¯ç¨¿ã®ååã¯ãç¾ç¶ã®WAFã®èª²é¡ã¨ãã¦ãWebã¢ããªã±ã¼ã·ã§ã³ã«å¯¾ããæ»æã®å¤ãï¼å¤§åï¼ãWAFã®ããã©ã«ãè¨å®ã§ã¯é²å¾¡ã§ããªãã¨ææãããä¾ãã°ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°(XSS)ã«é¢ãã¦ã¯ã以ä¸ã®ãããªææãããã ä»®ã«scriptããã©ãã¯ãªã¹ãã«æå®ããã¨ãã¾ããããããã§ãã¾ã ä¸ååã§ãã<IMG>ã¿ã°ã§XSSãçºåãããã¨ããåãã§ããããï¼ããã°ã©ã ãªã©ã§ã¯<IMG>ã¿ã°ã¯ç»åæ·»ä»ã«å¿ é ã§ãããWAFã§ç¦æ¢ãããã¨ã¯é£ããã®ãå®æ ã§ããã©ãã¯ãªã¹ãæ¹å¼ã®èª²é¡ã¨ãªã£ã¦ãã¾ãã ãç¾ç¶ã®èª²é¡ã¨âå®ç§ãªWAFâãããå¼
ãã©ãã¯ãªã¹ãæ¹å¼ä»¥å¤ ããå¾ãªãã¨æã£ã¦ãã¾ãã Scutumã§æ¡ç¨ãã¦ããWAFã¯ããªã¼ãã³ã½ã¼ã¹ã®Guardian@JUMPERZ.NETï¼ä»¥ä¸ãGuardianï¼ã ãGuardianã®éçºè ã§ããéåºæ°ã¯ãWebé¢é£ã®éçºä¼ç¤¾ã§ããããããã©ã¬ã¹ãã®åç· å½¹ã¨ã¨ãã«SSTã®æè¡é¡§åãåãã¦ããã éåºæ°ãGuardianãéçºãå§ããã®ã¯2002å¹´é ãWebã®éçºãéç¨ã«ããã¦ãApacheãPHPãOpenSSLãªã©ã®èå¼±æ§ãå¡ãããã«æ¸ãå§ããã®ãçºç«¯ã ããã¨ã«ããèå¼±æ§ãçãæ»æã次ã ã¨åºã¦ããã®ã§ãæ»æããã¦ããã®ã§ã¯ï¼ã¨ãã強迫観念ã§ç ããæµ ããªã£ãããããã§ããå½æãWAFã¯300ä¸åã¨ããã¨ã«ããå°ããªWebéçºä¼ç¤¾ã§ã¯å°å ¥ã§ããªãéé¡ã§ãããããã§ãæ©æ¢°èªãæ··ãã£ã¦ãããããªæªããHTTPãªã¯ã¨ã¹ããApacheã«å±ãå段éã§ãã§ãã¯ãããããã·ã¨ãã¦ãJavaã§æ¸ã
ãããã¤ã³ã¿ã¼ãããã¯10æ¥ãå社ãæä¾ãããã¹ãã£ã³ã°ãµã¼ãã¹åãã»ãã¥ãªãã£å¯¾çã«ãã¸ã§ã¤ãã¼ã»ã»ãã¥ã¢ãéçºã»æä¾ããã·ã°ããã£åWebã¢ããªã±ã¼ã·ã§ã³ã»ãã¡ã¤ã¢ã¦ã©ã¼ã«(WAF)ã§ãããSiteGuard(ãµã¤ãã¬ã¼ã)ããæ¡ç¨ããã¨çºè¡¨ãããããµã¤ãã®Webã¢ããªã±ã¼ã·ã§ã³ã«å¯¾ãã容æã«ã»ãã¥ãªãã£å¯¾çãæ½ããã¨ãå¯è½ãã¨ãã¦ããã ãããã¤ã³ã¿ã¼ãããã«ããã¨ãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã¨ãã£ãææ³ãåãã¨ãããWebã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ãæªç¨ããäºä»¶ãæ¥å¢ãWebã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã¥ãªãã£å¯¾çãéè¦è¦ããã¦ãããããµã¼ããã¬ã³ã¿ã«ãããã¹ãã£ã³ã°ãµã¼ãã¹ã«ããã¦ãä¾å¤ã§ã¯ãªãã(å社)ã ã ãå社ã«ããã¨ãå¾æ¥ã®WAFã¯ãWebãµã¼ã(ãã¡ã¤ã³)åå¥ã«ãã¯ã¤ããªã¹ããè¨è¨ã»ä½æããå¿ è¦ããã£ãããããç¹ã«å ±ç¨ãã¹ãã£ã³ã°ãµã¼ãã¹ã§ã®WAFæ©è½ã®æä¾ã¯é£ããã¨èãããã¦ãã
is a totally awesome idea still being worked on. Check back later.
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}