Highlights from RSA Conference: Secure by Design, AI Insights, and Global Collaboration

Highlights from RSA Conference: Secure by Design, AI Insights, and Global Collaboration
é«åº¦ãµã¤ãã¼æ»æã¸ã®å¯¾å¦ã«ããããã°ã®æ´»ç¨ã¨åææ¹æ³ çµç¹ãæ¨çã¨ãããé«åº¦ãµã¤ãã¼æ»æãã¯ãå½å ã«ããã¦ãå¤ãã®çµç¹ã§è¡¨é¢åãã¦ãããæ°ããªã»ãã¥ãªãã£è å¨ã¨ãªã£ã¦ãã¾ããé«åº¦ãµã¤ãã¼æ»æã¯ãå¾æ¥åã®æ»æã«å¯¾ããé²å¾¡ã»æ¤åºã ãã§ã¯å®å ¨ã«é²ããã¨ãã§ãããæ»æãåãã¦ä¾µå ¥ããããã¨ãæ³å®ããä¸ã§ãããã«æ©ãç°å¸¸ã«æ°ã¥ã対å¦ã§ããããæå¦ã®åããç®ã¨ãªãã¾ãã JPCERTã³ã¼ãã£ãã¼ã·ã§ã³ã»ã³ã¿ã¼ã§ã¯ãé«åº¦ãµã¤ãã¼æ»æã«é¢ããæ§ã ãªèª¿æ»ç 究ãè¡ã£ã¦ãã¾ããããã®ææã®ä¸ã¤ã¨ãã¦ãè¤æ°ã®ãµã¼ããæ©å¨çã«è¨é²ãããç¹å¾´çãªãã°ãé©åã«æ¡åãåæãããã¨ã«ãããä¾µå ¥ãæ»æã®å½±é¿ç¯å²ãæããããå¯è½æ§ããããã¨ããããã¾ããã ã¤ã³ã·ãã³ã対å¿ã«ããããã°æ¡åã®éè¦æ§ã¯å¤ãã®çµç¹ã§èªèããã¦ãã¾ããä¸æ¹ã§ãå®éã«å¿ è¦ãªãã°ãè¦å®ãã¦æ¡åããåæ調æ»ããã¦ããçµç¹ã¯å¤ãããã¾ãããããã«ãã¤ã³ã·ãã³
æ ªå¼ä¼ç¤¾ãã¥ã¼ãã©ãªã¢ãæä¾ããã¢ããªã«ã³ã«ã¯ãã¹ã¯ãªããã¤ã³ã¸ã§ã¯ã·ã§ã³ã®èå¼±æ§ãåå¨ãã¾ãã ãªããæ¬èå¼±æ§ã¯ JVN#71088919 ã¨ã¯ç°ãªãåé¡ã§ãã Android ç ã¢ããªã«ã³ 1.12.6 ããã³ãã以åã§ä½æãããã¢ããªã±ã¼ã·ã§ã³ iOS ç ã¢ããªã«ã³ 1.12.3 ããã³ãã以åã§ä½æãããã¢ããªã±ã¼ã·ã§ã³ æ ªå¼ä¼ç¤¾ãã¥ã¼ãã©ãªã¢ãæä¾ããã¢ããªã«ã³ã¯ãAndroid ããã³ iOS åãã¢ããªã±ã¼ã·ã§ã³ã®éçºæ¯æ´ãã©ãããã©ã¼ã ã§ããã¢ããªã«ã³ã«ã¯ãURL ã®å¦çã«èµ·å ããã¹ã¯ãªããã¤ã³ã¸ã§ã¯ã·ã§ã³ã®èå¼±æ§ãåå¨ãã¾ãã
ã¤ã³ã·ãã³ã対å¿ã£ã¦ã ãºã«ã·ã¤ï¼ãNISSAY IT CSIRTã®çµé¨ã«å¦ã¶ãã³ãï¼ä¼æ¥CSIRTã®æåç·ï¼1/3 ãã¼ã¸ï¼ æåããé大ã¤ã³ã·ãã³ãã«å¯¾å¿ã§ããCSIRTãæ§ç¯ããã®ã¯é常ã«é£ããã ãããããã»ã¤æ å ±ãã¯ããã¸ã¼ã®å°æ¾¤æ°ã¯ããåã°ããCSIRTã§ãã¾ãå§ãã¦ã¿ãã¹ããã¨è©±ãã ä¼æ¥ãçµç¹ã§ã»ãã¥ãªãã£ã¤ã³ã·ãã³ãã«å¯¾å¿ãããCSIRTãï¼ã³ã³ãã¥ã¼ã¿ã»ã»ãã¥ãªãã£ã»ã¤ã³ã·ãã³ã対å¿ãã¼ã ï¼ã¸ã®é¢å¿ãé«ã¾ã£ã¦ãããæ¥æ¬ã·ã¼ãµã¼ãåè°ä¼ï¼NCAï¼ã«å çããCSIRTã¯2015å¹´10æã«100ãã¼ã ãè¶ ããæ§ã ãªæ¥ç¨®ã®ä¼æ¥ãåå ãã¦ãããããããCSIRTãæ§ç¯ãããã¨ããå ´åãã©ã®ãããªãã¤ã³ãã«æ°ãä»ããã¹ãã ãããã2014å¹´10æã«NCAã«å çããããã»ã¤æ å ±ãã¯ããã¸ã¼ããå社ã®çµé¨ãªã©ãè¸ã¾ãã¦è§£èª¬ãã¦ãããã ããã»ã¤æ å ±ãã¯ããã¸ã¼ã¯ãæ¥æ¬çå½ã°ã«ã¼ãã®ITä¼æ¥
æ¥å¢ãã«é«ã¾ããµã¤ãã¼æ»æã®è å¨ã¯çµå¶ãè ããã対çãæ¥åã ãã¨ã¯ããã対çç¾å ´ã¯äºç®ã人ããã¦ãã¦ã足ããªãã®ãå®æ ã ãããä»åãããªã¯ã«ã¼ãã°ã«ã¼ãã®ã»ãã¥ãªãã£å¯¾å¿ãã¼ã ããå®è·µçã§å ·ä½çãªã»ãã¥ãªãã£äºæ 対å¿ã®æ¹æ³ã解説ããã äºæ åæ社ä¼ã¨ãããã¼ã¯ã¼ããããã¾ãããã»ãã¥ãªãã£ã«çµ¶å¯¾ã¯ãªããäºæ ã¯èµ·ãããããã®ãã¨ããåæã®ä¸ã§å¯¾çãæ¤è¨ããå¿ è¦ããããã¨ããæå³ã§ãããã®ãã¼ã¯ã¼ãã¯2003å¹´ã«çµæ¸ç£æ¥çãçºè¡¨ãããæ å ±ã»ãã¥ãªãã£ç·åæ¿çãã®ä¸ã«ãåºã¦ãããããã§ãããã¶ãåããå½å ã§ä½¿ããã¦ãã¾ããã ä»å¹´6æãæ¥æ¬å¹´éæ©æ§ãã125ä¸ä»¶ã®å¹´éæ å ±ã®æµåºãæããã«ãªããªã©ãããæ°å¹´ã®ã¤ã³ã·ãã³ãï¼ã»ãã¥ãªãã£äºæ ï¼ã®å¤çºã¶ããè¦èãããã¨ããã®ãã¼ã¯ã¼ããä¸æ°ã«ç¾å®å³ã帯ã³ã¦ããã¨èã§æãã¦ãã¾ããã¡ãã£ã¢ã§ããå種ã¤ã³ã·ãã³ããã»ã³ã»ã¼ã·ã§ãã«ã«å ±éããããã¨ãå°ãªãã
LinuxãçãMySQLãNginxã®ãã£ã¬ã¯ããªãæå·åããã©ã³ãµã ã¦ã¨ã¢ã®è¢«å®³æ¡å¤§ï¼CMSã®ã¢ãããã¼ãã¨ããã¯ã¢ãããæ¨å¥¨ ãã·ã¢ã®ã»ãã¥ãªãã£ä¼æ¥Dr.Webã«ããã¨ãLinuxãµã¼ãã¼ã対象ã¨ããã©ã³ãµã ã¦ã¨ã¢ãLinux.Encoder.1ãã被害ãåºããç´2000ã®Webãµã¤ãã«ææããã¨æ¨æ¸¬ãããã¨ããã PCå ã®ãã¼ã¿ãåæã«æå·åãã¦äººè³ªã«åãããå ã«æ»ãã¦ã»ãããã°ééãæ¯æããã¨è¦æ±ãããã©ã³ãµã ã¦ã¨ã¢ããããã¾ã§å ±åããããã®ã¯Windows PCãå©ç¨ããå人ã¦ã¼ã¶ã¼ã対象ã¨ãããã®ãã»ã¨ãã©ã ã£ãããæ°ãã«ãLinuxãµã¼ãã¼ã対象ã¨ããã©ã³ãµã ã¦ã¨ã¢ãLinux.Encoder.1ããç»å ´ãã被害ãåºãã¦ããããã·ã¢ã®ã»ãã¥ãªãã£ä¼æ¥ãDr.Webã2015å¹´11æ13æ¥ã«å ¬éããæ å ±ã«ããã¨ããã®ã©ã³ãµã ã¦ã¨ã¢ã«ææããWebãµã¤ãã¯ç´2000ã«ä¸ãã¨æ¨
ã©ã³ãã³ã°
é害
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}