Security Hubã«ãªãããå±±æ¬ææµ·ã§ãã
稼åãã¦ããç°å¢ã§Inspectorãæå¹åããã¨ã大éã®èå¼±æ§ãæ¤åºããã¦é©ããããã¨ããããã¨æãã¾ãã ãã®éã«ãã¾ãã¯ã©ã®èå¼±æ§ã«å¯¾å¿ãå¿ è¦ããèå¼±æ§ã®å¯¾å¿åªå é ãè©ä¾¡ããææ³ãæµç¨ãã¦åªå é ãæ¤è¨ãããã¨æãã¾ãã
å ã«çµè«
SSVCã®è©ä¾¡é ç®ãæµç¨ããç·æ¥æ§ã®é«ãèå¼±æ§å¯¾å¿ãã£ã«ã¿ã¼ã¯ä»¥ä¸ã®éãã§ãã
- ã¯ã¼ã¯ããã¼ã®ã¹ãã¼ã¿ã¹ = NEW or NOTIFIED
- ã¬ã³ã¼ãã®ç¶æ = ACTIVE
- 製åå = Inspector
- ã½ããã¦ã§ã¢ã®èå¼±æ§ã¨ã¯ã¹ããã¤ããå©ç¨å¯è½ = YES
- éè¦åº¦ã©ãã« = CRITICAL or HIGH
ããã«ãAWSã¢ã«ã¦ã³ãIDãVPC IDãã¤ã³ã¹ã¿ã³ã¹IDããªã©ã§éè¦ãªç°å¢ããªã½ã¼ã¹ã®ãã£ã«ã¿ã¼ã追å ãã¦ãã ããã
åææ¡ä»¶
Inspectorã¨Security Hubãé£æºãã¦ãããã¨ãåæã¨ãã¦ãã¾ã
CVSSã®ã¹ã³ã¢ã¨Inspectorã®éè¦åº¦ã¬ãã«
Inspectorã®æ¤åºçµæã®éè¦åº¦ã¬ãã«ã¯ãåºæ¬ã¬ãã«ã¨ãã¦CVSSã®ã¹ã³ã¢ã使ç¨ããã¾ãã ãã®ä»ã«EPSSã¹ã³ã¢ãInspectorãç¬èªã«æ¡ç¹ããInspectorã¹ã³ã¢ãªã©è¤æ°ã®è©ä¾¡è»¸ã§èå¼±æ§ãè©ä¾¡ããæçµçãªã¹ã³ã¢ã«å¿ãã¦éè¦åº¦ã®ã©ãã«ãã¤ãã¾ãã
ã¹ã³ã¢ã¨éè¦åº¦ã®ã©ãã«ãæç²ãã¾ãã
ã¹ã³ã¢ | ã©ãã« |
---|---|
9.0ï½10.0 | CRITICAL |
7.0ï½8.9 | HIGH |
4.0ï½6.9 | MEDIUM |
0.1ï½3.9 | LOW |
0 | INFORMATIONAL |
ãã®éè¦åº¦ã¯ãå½±é¿ãåãããªã½ã¼ã¹ãçµç¹ã«å¯¾ãã¦ç·æ¥æ§ã¾ãã¯éè¦æ§ãæå³ãããã®ã§ã¯ããã¾ããã
ãã®ãããèå¼±æ§ã¸ã®å¯¾å¿ã®åªå
度ã¯å¥ã®è©ä¾¡ææ³ã§ã®æ¤è¨ãå¿
è¦ã§ãã
SSVCã§èå¼±æ§å¯¾çã¸ã®åªå é ä½ãã¤ãã
èå¼±æ§å¯¾å¿ã®åªå 度ã¨ãã¦ç¨ããè©ä¾¡ææ³ã¨ãã¦SSVCï¼Stakeholder-Specific Vulnerability Categorizationï¼ã¨ããè©ä¾¡ææ³ãããã ãæ¿åºæ©é¢çã®å¯¾çåºæºçå®ã®ããã®ã¬ã¤ãã©ã¤ã³ãã®è³æã§ãç´¹ä»ããã¦ããã¾ãã ãã®è©ä¾¡ææ³ãSecurity Hubä¸ã§æ¤åºçµæããã£ã«ã¿ã¼ããæ¡ä»¶ã«å¤æã§ããªããèãã¦ã¿ã¾ããã
â» æ¿åºæ©é¢çã®å¯¾çåºæºçå®ã®ããã®ã¬ã¤ãã©ã¤ã³ï¼ä»¤åï¼å¹´åº¦çï¼ https://www.nisc.go.jp/pdf/policy/general/guider5.pdf
â» CISA Stakeholder-Specific Vulnerability Categorization Guide https://www.cisa.gov/sites/default/files/publications/cisa-ssvc-guide%20508c.pdf
SSVCã¨ã¯ã©ããããã®ã
èå¼±æ§ãèå¼±æ§ã®ç¶æ
ã¨èå¼±æ§ãã¯ããç°å¢ã«é¢ãã4ã¤ã®è©ä¾¡åºæºã§æ¡ç¹ããèå¼±æ§å¯¾å¿ã®ç·æ¥æ§ãæ¡ç¹ããã·ã¹ãã ã§ãã¢ã¡ãªã«æ¿åºãå·ã®èå¼±æ§å¯¾å¿ã®åªå
é ä½ä»ããæ¯æ´ããããã®ãææ決å®ããªã¼ã§ãã
SSVCã®è©ä¾¡ã¯æ·»ä»ããç»åã®ãããªããªã¼æ§é ã§è¡¨ç¾ã§ãã¾ãããã®ãã¨ããèå¼±æ§ã®åªå
度åããã©ã®ç¨åº¦ãææ¡ããããã¼ãã£ã¼ãã®ããã«ä½¿ããã¨èãã¦ããã ãã¦ãããã¨æãã¾ãã
è©ä¾¡çµæã¯4種é¡ãããç·æ¥æ§ã®é«ããã®ããé ã«ãAct, Attend, Track*, Trackã¨ãªã£ã¦ãã¾ãã
Actã®èå¼±æ§ã¯ã§ããã ãæ©ãèå¼±æ§ãä¿®æ£ãããã¨ãæ±ãããã¦ãããTrackã¯é常ã®ã¹ã±ã¸ã¥ã¼ã«ã§ã®å¯¾å¿ãæ±ãããã¦ã¾ãã説æã«ããã¨ãããèå¼±æ§å¯¾å¿ã«é常ã®ã¹ã±ã¸ã¥ã¼ã«ãã¤ã¾ãèå¼±æ§å¯¾å¿ã®å®æçãªãµã¤ã¯ã«ãããåæã§ãã
ä»åã®æ¤è¨å 容
Inspectorã§æ¤åºããèå¼±æ§ã®æ°ã¯ãã£ãããªéã«ãªãå ´åããããããã¾ãä½ããå§ãããæ¤è¨ãå¿
è¦ã«ãªãã¾ãã
æ¤è¨ã®ããã«SSVCã®è©ä¾¡é
ç®ãSecurity Hubã®è©ä¾¡çµæã®ãã£ã«ã¿ã¼ã«å¤æãã¦ãSSVCã®Actã«ç¸å½ãããã§ããã ãæ©ãä¿®æ£ãããã¨ãæ±ãããã¦ããèå¼±æ§ããã£ã«ã¿ã¼ã§ããªããæ¤è¨ãã¾ãã
SSVCã®è©ä¾¡é ç®
åè¿°ããããã«ãèå¼±æ§ã¨ç°å¢ã以ä¸ã®4ã¤ã®è©ä¾¡ãè¡ãèå¼±æ§å¯¾å¿ã®åªå 度ã決å®ãã¾ãã
â ã¨ã¯ã¹ããã¤ãã³ã¼ãã®ç¶æ
SSVCã¬ã¤ãã«ã¯3ã¤ã®ç¶æ ãããã¾ãã
- None
- ã¨ã¯ã¹ããã¤ãã³ã¼ããå ¬éããã¦ããªã
- Public PoC
- å ¸åçãªå ¬éPoCãåå¨ãã
- Active
- å®éã«ã¨ã¯ã¹ããã¤ãã³ã¼ãã使ç¨ããã¦ãã
Security Hubã®ãã£ã«ã¿ã¼ã«å¤æããéã¯ãè©ä¾¡é
ç®ãåç´åããã½ããã¦ã§ã¢ã®èå¼±æ§ã¨ã¯ã¹ããã¤ããå©ç¨å¯è½ããYESã®ãã®ã«ãã¾ããï¼ç»ååç
§ï¼
ã¬ã¤ãã®Noneããã以å¤ãã®ç¶æ
ã«ããã¤ã¡ã¼ã¸ã§ãã
ãã ããLog4Jã®ããã«çæéã§ççºçã«æµè¡ããå
ãããããã®ã¯ãSSVCã¬ã¤ãä¸ã®Activeã®ç¶æ
ã¨æããããç·æ¥æ§ãé«ãã¨å¤æããã»ããç¡é£ã¨èãã¾ãããã®å ´åã¯å¥éç·æ¥ãªå¯¾å¿ãå¿
è¦ã¨ãªãæ³å®ã§ãã
â¡ èªååå¯è½ãã©ãã
ã¬ã¤ãã«ã¯2ã¤ã®ç¶æ ãããã¾ãã
- No
- ãµã¤ãã¼ãã«ãã§ã¼ã³ã®1ã4ã®ãã§ã¼ãºï¼åµå¯ãæ¦å¨åãé éãã¨ã¯ã¹ããã¤ãï¼ã®ããããã§èªååã§ããªãç¶æ
- Yes
- ãµã¤ãã¼ãã«ãã§ã¼ã³ã®1ã4ã®ãã§ã¼ãºã®ãã¹ã¦ã§èªååã§ããç¶æ
è
å¨ã¢ã¯ã¿ã¼ãèå¼±æ§ãæªç¨ããã¤ãã³ããçºçããããã¨ã®å®¹æãã¨é度ã表ãã¾ãã
åµå¯ããæªæã®ããã³ã¼ããå®è¡ããã¾ã§ã®æé ã確å®ã«å
¨ã¦èªååå¯è½ãªèå¼±æ§ãç°å¢ã®å ´åãYesã«ãªãã¾ãã
å¤æã«è¿·ããã¤ã³ãã§ãããSSVCã®ã¬ã¤ãã®ã³ã¡ã³ãã«ã¯ãå¹æçãªããªã¢ãããï¼ä¾ãã°èå¼±ãªã³ã³ãã¼ãã³ããã¤ã³ã¿ã¼ãããã«ãªã¼ãã³ã«æ¥ç¶ããã¦ããªãï¼ãªãNoã¨è¨ããã¨ããè¨è¼ãããã¾ããã¾ããèå¼±æ§ãã¤ãæ»æãèªååã§ããªãå ´åãNoã¨ãªããããèå¼±æ§ã®æ§è³ªãå½±é¿ãã¾ãã
ãã®å¤æã¯åã
ã®ç°å¢ã®ç¶æ
ã«ä¾ãã®ã§ãã¢ã«ã¦ã³ãIDãVPC IDãªã©ã§æ¸å¿µãããç°å¢ã»ãªã½ã¼ã¹ã®ãã£ã«ã¿ã¼ã追å ããã®ãããã¨èãã¾ããæ¡ä»¶ãåç´åãããããèå¼±æ§ã®æ§è³ªã¯ä¸æ¦èæ
®ããå¤ãã¾ãã
⢠æè¡çãªã¤ã³ãã¯ã
ã¬ã¤ãã«ã¯2ã¤ã®ç¶æ ãããã¾ãã
- Partial
- èå¼±æ§ã¯èå¼±æ§ãå«ãã½ããã¦ã¨ã¢ã®åä½ãéå®çã«å¶å¾¡ã§ããããã«ãªããããããã¯æ å ±ãæ´é²ã§ããããã«ãªã
- Total
- èå¼±æ§ã¯ã½ããã¦ã§ã¢ã®åä½ãå®å ¨ã«å¶å¾¡ãããããèå¼±æ§ãå«ãã·ã¹ãã ä¸ã®ãã¹ã¦ã®æ å ±ãå®å ¨ã«é示ããã
SSVCã®è³æã§ã¯æè¡çãªã¤ã³ãã¯ãã¯CVSSã®æ·±å»åº¦ã¨ä¼¼ã¦ãããã®ã¨ããè¨è¼ãããã¾ãã åCVEã®èª¬æã®ç®æã§ã©ããã£ãå½±é¿ããããã®è¨è¼ãããã®ã§ããã®å 容ãåèã«ããã ã¾ãã¯åã«CVSSã®æ·±å»åº¦ãHIGH以ä¸ã®ãã®ã対象ã«ãããªã©ã§åæ§ã®è©ä¾¡ãå¯è½ã¨ããèªèã§ãã
⣠ããã·ã§ã³
ã¬ã¤ãã«ã¯2ã¤ã®ç¶æ ãããã¾ãã
- Minimal
- 以ä¸ã®Supportã§ãEssentialã§ããªã
- Support
- èå¼±ãªã³ã³ãã¼ãã³ãã2ã¤ä»¥ä¸ã®çµç¹ã®ä¸æ¢ã®æ©è½ã§ãµãã¼ãããã¦ãã
- Essential
- èå¼±ãªã³ã³ãã¼ãã³ãã¯ãå°ãªãã¨ã1ã¤ã®çµç¹ã®ã1ã¤ä»¥ä¸ã®ä¸æ¢ã®æ©è½ãæ§æããè½åãç´æ¥æä¾ãã¦ãããã³ã³ãã¼ãã³ãã®æ éã¯ãä¸æ¢æ©è½å ¨ä½ã®é害ã«ã¤ãªããå¯è½æ§ãããï¼ãã ããå¿ ãããããã§ã¯ãªãï¼
ã©ã®ãããèå¼±ãªã³ã³ãã¼ãã³ããçµç¹ã®ä¸å¿çãªæ¥åãæ¯ãã¦ãããã¾ãã¯ãµãã¼ããã¦ãããã¨ãã観ç¹ã«ãªãã¾ãã ç°å¢ãã¢ã«ã¦ã³ãã®ã¹ãã¼ã¸ã¾ãã¯ãæ©è½ã®ããã·ã§ã³ã¯ãªãã£ã«ã«æ§ãªã©ã§è©ä¾¡ã§ãããã¨èãã¦ãã¾ãã
ãã®å¤æãâ¡ã¨åæ§ã«ãåã ã®ç°å¢ã®ç¶æ ã«ä¾ãã®ã§ãã¢ã«ã¦ã³ãIDãVPC IDãªã©ã§æ¸å¿µãããç°å¢ã»ãªã½ã¼ã¹ã®ãã£ã«ã¿ã¼ã追å ããã®ãããã¨èãã¾ãã SSVCã§ã¯å ¬å ±ç¦ç¥ = ã©ã®ãããå¸æ°ã«å¯¾ããå½±é¿ããããã¨ãã観ç¹ãããã¾ãããä»åã¯çãã¾ãã
Security Hubã®ãã£ã«ã¿ã¼
ããã©ã«ãã®ãã£ã«ã¿ã¼ï¼ã¯ã¼ã¯ããã¼ã®ã¹ãã¼ã¿ã¹ãNEW, ã¾ãã¯NOTIFIEDã§ã¬ã³ã¼ãã®ç¶æ ãACTIVEï¼ã« 製ååãInspectorã®ãã£ã«ã¿ã¼ã追å ãã¾ãã
ããã«ãSSVCã®è©ä¾¡é ç®â ã¨â¢ãSecurity Hubã®ãã£ã«ã¿ã¼ã«è¿½å ãã以ä¸ã®ãã£ã«ã¿ã¼ã«ãªãã¾ã
- ã¯ã¼ã¯ããã¼ã®ã¹ãã¼ã¿ã¹ = NEW or NOTIFIED
- ã¬ã³ã¼ãã®ç¶æ = ACTIVE
- 製åå = Inspector
- ã½ããã¦ã§ã¢ã®èå¼±æ§ã¨ã¯ã¹ããã¤ããå©ç¨å¯è½ = YES
- éè¦åº¦ã©ãã« = CRITICAL or HIGH
ããã«AWSã¢ã«ã¦ã³ãIDãVPC IDãã¤ã³ã¹ã¿ã³ã¹IDããªã©ã§éè¦ãªç°å¢ããªã½ã¼ã¹ã®ãã£ã«ã¿ã¼ã追å ãã㨠SSVCã®è©ä¾¡é ç®ãæµç¨ãããã£ã«ã¿ã¼ãå®æãã¾ãã
Inspectorã®æ¤åºçµæã®å¯¾å¿ãæ¤è¨ãããå ´åãä¸è¨ã®ãã£ã«ã¿ã¼ã§æ¤åºãããçµæãããæ¤è¨ãããã®ãè¯ããã¨èãã¦ããã¾ãã
CLIã§ã®æ¸ãæ¹
以ä¸ã®ã³ãã³ãã¯ä¸è¨ãã£ã«ã¿ã¼ãå®è£ ããæ¤åºçµæãªã¹ãããã³ãã³ãã§ããã½ã¼ãã¯éè¦åº¦ã©ãã«é ã§ãã å¿ è¦ãªå ´åãéè¦ãªç°å¢ããªã½ã¼ã¹ã®ãã£ã«ã¿ã¼ã追å ãã¦ãå©ç¨ãã ããã
aws securityhub get-findings --filters \ '{ "WorkflowStatus":[{"Value":"NEW","Comparison":"EQUALS"},{"Value":"NOTIFIED","Comparison":"EQUALS"}], "SeverityLabel": [{"Value": "CRITICAL","Comparison":"EQUALS"},{"Value": "HIGH","Comparison":"EQUALS"}], "RecordState":[{"Value":"ACTIVE","Comparison":"EQUALS"}], "ProductName": [{"Value": "Inspector","Comparison":"EQUALS"}], "VulnerabilitiesExploitAvailable": [{"Value": "YES","Comparison":"EQUALS"}]}' \ --sort-criteria '{ "Field": "SeverityLabel", "SortOrder": "desc"}'
ãããã«
SSVCã®è©ä¾¡é
ç®ãç¨ãã¦Inspectorã®æ¤åºçµæããç·æ¥æ§ã®é«ãèå¼±æ§ãæ½åºããæ¹æ³ãèãã¦ã¿ã¾ããã
ã¨ã¯ã¹ããã¤ãã³ã¼ããç°å¢ã®ç¶æ
ã¯å¸¸ã«å¤ããç¶ããã®ã§ãä¸åº¦ã ãã§ã¯ãªãå®æçã«ç¶æ
ã確èªããå¿
è¦ãªå¯¾å¿ãå¿
è¦ãªã¿ã¤ãã³ã°ã§ã§ããã¨ãããã¨èãã¾ãã
ãã®è¨äºãåèã«ãªãã°å¹¸ãã§ãã
å±±æ¬ ææµ·(å·çè¨äºã®ä¸è¦§)
ã¨ã³ã¿ã¼ãã©ã¤ãºã¯ã©ã¦ãé¨ ã¯ã©ã¦ããªã©ã¤ã¢ããªãã£èª²
Security Hubã«ãªããã
åçã¯é»ç«ã®ãã¾ã
è¨äºã«é¢ãããåãåãããä¿®æ£ä¾é ¼â [email protected]