# IoC æ½åºã®ããã®ãã¯ããã¯ã¨ãã¼ã« 5 min read... # åæ IoC(Indicator of Compromise)ã¨ã¯ãã»ãã¥ãªãã£ã¤ã³ã·ãã³ãã«é¢é£ããã¤ã³ãã£ã±ã¼ã¿ã¼ã®ãã¨ã§ããå ·ä½çã«ã¯ããã«ã¦ã§ã¢ã®ããã·ã¥å¤(MD5, SHA256, sssdeep, etc.)ããã®éä¿¡å ã® IP ã¢ãã¬ã¹ãURL çãããã«è©²å½ãã¾ãã ä¸è¬çã«ãIoC ã¯ãã©ãã¯ãªã¹ãã¸ã®é©ç¨ãæ å ±å ±æã®ããã«ç¨ãããã¾ãã # IoC æ½åºãå¿ è¦ã¨ãããèæ¯ ã»ãã¥ãªãã£ãã³ãã¼ããæä¾ãããã¬ãã¼ãã®ä¸ã«ãIoC ãå«ã¾ãã¦ãããã¨ãããã¾ãããæ§é åããããã¼ã¿ã¨ãã¦æä¾ããã¦ããªãå ´åãã»ã¨ãã©ã§ãã(ä¾ãã°ãæä¸ã«ãã¡ã¤ã³åã IP ã¢ãã¬ã¹ãè¨è¼ããã¦ããã ãç) ãããã£ãã¬ãã¼ããããIoC ãæ§é åããããã¼ã¿ã¨ãã¦æ½åºãããã¨ã§ããã©ãã¯ãªã¹ãã¸ã®é©ç¨ãæ å ±å ±æã®
# ã¼ãããã¯ããããã£ãã·ã³ã°å¯¾ç ð£ 2 min read... ãã£ãã·ã³ã°å¯¾çåè°ä¼ (opens new window)ã«ããã°ã2018å¹´ä¸åæã«å ±åããããã£ãã·ã³ã°ã®ä»¶æ°ã¯2017å¹´ä¸åæã®æå¹³åã¨æ¯è¼ãã¦1.6åã«å¢å ãã¦ããããã§ãã (source: https://www.antiphishing.jp/news/pdf/apcseminar2018apc.pdf) ãã®è¨äºã§ã¯ãå¢å ãããã£ãã·ã³ã°ã«å¯¾ãã¦å¹ççã«å¯¾å¿ããããããã¡ã¤ã³åãèµ·ç¹ã«ãã£ãã·ã³ã°ãµã¤ããè¦ã¤ãããããå ±åããã¾ã§ã®æµãã«ã¤ãã¦ç´¹ä»ãã¾ãã # å段 ãã£ãã·ã³ã°ãããããæ»æè ã¯ãç´ãããããã¡ã¤ã³å(ã¿ã¤ãã¹ã¯ã¯ããã£ã³ã° / typosquatting)ãç¨æããããã«ã¿ã¼ã²ãããèªå°ãã¾ãã ä¾ã¨ãã¦ãApple ã¦ã¼ã¶ã¼ãæ¨çã«ãããã£ãã·ã³ã°ãµã¤ãã®ãã¡ã¤ã³åã以ä¸ã«ç¤ºãã¾
|-------------------------|------------------------------------------------------------------------------------------------------| | asn | The Autonomous System Number that identifies the network the device is on. | | before | Only show results that were collected before the given date (dd/mm/yyyy. | | city | Show results that are located in the given city. | | country | Show results that are loca
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}