OSINTã®ãã¦ããªä¹±ã
- 2023/06/18 é¨åã®å å¶ã¨ãªã£ãTweetã«ã¤ãã¦ã¯æ¬äººããæ²è¼è¨±å¯ãããã ãã¦ããã¾ããããã¾ã§æ¬è¨äºã®ç®çã¯ç¥èã»ç¨èªã®æ´çããã³ä»¥å¾ã®æ··ä¹±ãé¿ããããã®ä¸ææ¡ã§ãããããæ¬äººã¸ã®çªæãªã©ã¯ãé æ ®ãã ããã
- 2023/05/08 AIãArtifact Intelligenceã¨èª¤è¡¨è¨ãã¦ããã®ã§ä¿®æ£
tl;dl
- çè ã"OSINT"ã«ã¤ãã¦è¨åããçµæãçä¸ã«ã¬ã½ãªã³ãæãã¦ãã¾ã£ãæããããããç¨èªã®æ´çã¨çè ãªãã®èããã¾ã¨ãã
- OSINTã¨ããåèªã¯ãã¤ã³ã¿ã¼ãããã使ã£ã¦ã»ã«ãã»ã«ããããã¨ããé常ã«æ¼ ç¶ã¨ããã³ã³ããã¹ãã®å ã§ä½¿ç¨ãããå ´é¢ãæ£è¦ãããèãæã«ãã®ã³ã³ããã¹ããå ±æããã¦ããªãå ´åã¯è§£éã«ä¸ä¸è´ãçãã
- å°ãªãã¨ãåçºã®ã¢ã¯ãã£ããã£ãå ¬éæ å ±ããã®æ å ±åéã¨ããè¡çºã«ããã¦ã¯ãOSINTã¨ããå°éç¨èªãæã¡åºããã¨ãé©åãªæ¥æ¬èªã使ç¨ããã»ããèãæãç解ãããã
ã¯ããã«
æ¬è¨äºã®æ稿ããç´äºãæã»ã©åãOSINT (Open-Source Intelligence) ãé¡æã¨ããã¤ã¶ããã§çéãçãä¸ãã£ã¦ããã
ããOSINTãä½ãæãã¦ãã®ãããããªã...ãä¸æ£ã¢ã¯ã»ã¹ç¦æ¢æ³çã«æµè§¦ããOSINTãªãã¦ããã®...ï¼ https://t.co/FLmMadyWwl
— defenceability (@defenceability) 2023å¹´3æ9æ¥
æãåãããã¦ãä½ã®å¶ç¶ãããããªããçè ãOSINTé¢é£ã®è©±é¡ãã¤ã¶ããã¦ãããé¨åã«ã¬ã½ãªã³ãæããããªããã¡ã§è©±é¡ãåºããäºæ ã¨ãªã£ã¦ãã¾ã£ãã
æè¿ã¨ã»ã³ã³ãµã«ã£ã½ããããªæ¥åããã¦ãããã©ãããããã®çµç¹ãããã«ã¦ã§ã¢è§£æ x OSINT ãä½ã³ã¹ãã§ãããã¨ãã¦ãããã©ãã¾ãåããªããã¨ãã課é¡ãæãã¦ããã®ããªã¨æã£ãã(話ãããã®ãç¾å ´ã®äººã§ã¯ç¡ããããå®æ ã¯å¤å°ç°ãªãã®ãããããªããã©)
— MigawariIV (@strinsert1Na) 2023å¹´3æ8æ¥
ãã®çµæã¯çè ã¨ãã¦ãæ¬æã§ã¯ãªãããäºæ ã«å æ ãã¦ããã¦ãçµæ¯ããããã¼ãã¾ããã¨ããã®ãä¸èª å®ãªæ°ããã¦ãªããªããçè ãæ¬ä»¶ãæ©ä¼ã«æ¹ãã¦OSINTã«ã¤ãã¦ãã®è¨èã®å®ç¾©ãå確èªãããOSINTã¨ã¯ä½ããã¨ããåãã«å¯¾ããèªåãªãã®åçãæ»ãã ãã¦ã¿ãã®ã§ãåå¿é²ã¨ãã¦ãã®å 容ãæ¸ãæ®ãã
ãªããæ¬è¨äºã¯çè ãªãã®æè¦ãå¤åã«å«ã¿ãä¸é¨ã®å 容ã«ã¤ãã¦ã¯ééã£ã¦ããããããããããçããã«æããããåãä¼ããããã¨ãã£ãæå³ã¯å ¨ããªãã®ã§ã誤ãã®ããå 容ã«ã¤ãã¦ã¯ãã²ææãã¦ããã ãããã
SNS ä¸ã§è¦ãããè«ç¹ã¨çè ãªãã®è¦è§£
çä¸ã¨ããã®ã¯ãçºä¿¡å
ãç·å©ãã«ãã£ã¦ãããã¨ããå ´åã«éããããæ§ã
ãªæè¦ãæã£ã¦ããå人ãåã
ã«çºè¨ããçµæããã¯ããªè¦ç¹ã§è¦ãã¨ãã«ä¸ã¤ã®å¤§ããªçã«è¦ãããã¨ããæ§é ãã¨ã£ã¦ããå ´åããããçè
ã®è¦ç«ã¦ã§ã¯æ¬ä»¶ããã®ã±ã¼ã¹ã«è©²å½ããã®ã§ã¯ãªããã¨èå¯ãã¦ãããSNS(Twitter) ã§è¦ãããè¨åãæ´çãã¦ã¿ãã¨ãã¯ãããã¤ãã®éã£ãè«ç¹ã§ã®ææãè¦ãããããããç¬æã¨åè¦ã§3ã¤ã®ã«ãã´ãªã«åããã®ã§ãããããã®å½é¡ã«å¯¾ãã¦çè
ãªãã®è¦è§£ãè¿°ã¹ã¦ããã
Intelligence â Collection
Open Source Intelligence (OSINT) â Open Source Collection
— Neutral8â9eR @[email protected] (@0x009AD6_810) 2023å¹´3æ9æ¥
ãã¦ãããããOSINTã«ã¤ãã¦èããã¨ãããã¨ã¯ãã¾ããã®è¨èã®å®ç¾©ã«ã¤ãã¦ç¢ºèªããªããã°ãªããªãã
æ¬è¨äºãè¦ã¦ããã ãã¦ãã人ã®å¤ãã¯ãOSINTã¨ããåèªãè¦èããããã¨ãããã ããããæ¬æ¥ã®OSINTã¾ã¨ãã§ãããã¨ãã£ã¦Webè¨äºã®ã¾ã¨ããæåºãã人éãããOSINTã§SNSã¢ã«ã¦ã³ãç¹å®ãã¾ãã!ãã¨è¨ã£ã¦ãã身å
ã¨ééããçµé¨ã¯å°ãªãããããã®ã§ã¯ãªããã¨æã£ã¦ãããã§ã¯ããã®æèã§èªããã¦ããOSINTã¨ããã¯ã¼ãã¯ãæããã¦OSINTã®å®ç¾©ã«æ²¿ã£ããã®ãªã®ã ãããã
OSINTã¨ã¯ "Open-Source INTelligence" ã®ç¥ã§ããããã®åã®éãWebãµã¤ããSNSã¨ãã£ãå ¬éæ å ±ããçæããã "ã¤ã³ããªã¸ã§ã³ã¹" ãªããã®ã§ãããOSINTã¯ã¤ã³ããªã¸ã§ã³ã¹ã"æ å ±ã®åéæº"ã¨ãã観ç¹ã§æ´çããä¸ã¤ã®åé¡ä¸ã®å¼ã³åã«ãããããã®ä»ã«ã HUMINT (Human INTelligence) ã SIGINT (Signal INTelligence) ã¨ãã£ãå¥ã®æ å ±æºããåéããã¤ã³ããªã¸ã§ã³ã¹ã®å¼ã³åãåå¨ããããæ¬è¨äºã®æ¬è³ªããå 容ãåããããä»åã¯å²æããã
ããã§çåã¨ãªãã®ããå ã»ã©ããå¤ç¨ããã¦ãã"ã¤ã³ããªã¸ã§ã³ã¹"ã¨ã¯ãã£ããä½è ãªã®ãã¨ãããã¨ã§ãããè¿å¹´ã§ã¯ AI (Artificial Intelligence) ã¨ããè¨èãä¸è¬äººã«ãç¥ã渡ã使ç¨ãããããã«ãªã£ããããããã"ã¤ã³ããªã¸ã§ã³ã¹"ã¨ããè¨èãåä½ã§ä½¿ç¨ãã人ã¯ãã¾ã ã«å°ãªããæå³ããã£ãã調ã¹ããã¨ãããã¨ãã人ã¯ãã£ã¨å°ãªãã®ã§ã¯ãªãã ããããããããã®ã¯ãã§ãã¤ã³ããªã¸ã§ã³ã¹ (Intelligence)ã¨ã¯å æ¥è»äºã§ç¨ããããå°éç¨èªã§ãããæ¥å¸¸ã§ä½¿ããããã¨ã¯ã»ã¨ãã©ãªããã¾ãã¯ç±³è»çµ±åæ å ±æ¬é¨ãå ¬éãã¦ãããJoint Publication 2-0: Joint Intelligenceã*1ããããã®æå³ã確èªãã¦ã¿ãã¨ããããPDFã®åé ã«ã¯ãããæ¸ããã¦ããã
Information on its own may be of utility to the commander, but when related to other information about the operational environment and considered in the light of past experience, it gives rise to a new understanding of the information, which may be termed âintelligence.â
æ å ±ã¯ããèªä½ã§ãå¸ä»¤ã«ã¨ã£ã¦æç¨ãããããªããããããä½æ¦ç°å¢ã§é¢é£ããä»ã®æ å ±ãéå»ã®çµé¨ã¨ç §ããåãããã¨ãããã®æ å ±ã«å¯¾ããæ°ããç解ãçã¾ãããããã "ã¤ã³ããªã¸ã§ã³ã¹" ã¨è¨ãã®ãããããªãã
æ¥æ¬èªè¨³ã¯çè
ãæ¸ãããã®ãªã®ã§ãå¤å°èª¤è¨³ããããããããªãããããåæã確èªããæ¹ã¯ããããåããããªææ³ãæ±ãã®ã§ã¯ãªãã ãããããç¨èªè§£èª¬ã®ã¯ããªã®ã«èª¬æãæ½è±¡çã§ã¯ãªãã? æ
å ±ãããæãã«ä½¿ã£ã¦ãã£ã¨ä¾¡å¤ã®ããä½ãã«ããã°ããã®ã!?ãã¨ãã§ã¯ãå
容ãããæçã«ãªã Introduction ã¾ã§èªã¿é²ãã¦ã¿ãããIntroduction ã ãã§ãé·ãå
¨æãè¼ãããã¨ãã§ããªãã®ã§ãçè
ãã¤ã³ããªã¸ã§ã³ã¹ãç解ããããã§éè¦ã ã¨æãç®æã ãæç²ãããããåæãæ°ã«ãªãæ¹ã¯ãPDFã® Introduction ãè¦ã¦ããã ãããã
a. æ å ±ã¯å°æ¥ã®ç¶æ³ãæ¡ä»¶ã«ã¤ãã¦åççãªæ´å¯ãæä¾ãããã¨ã§ãå¸ä»¤ã®ææ決å®ããã»ã¹ã«è²¢ç®ãæ大ã®ä¾¡å¤ãçºæ®ããã
(ä¸ç¥)
çã®ãã¼ã¿(Raw Data)ã¯ããèªä½ã¯æ¯è¼çéå®çãªæç¨æ§ãããããªãããããããã¼ã¿ãç解ããããå½¢ã«å¦çãããã¨ããã¯æ å ±(Information)ã¨ãªãããã大ããªæç¨æ§ãå¾ããæ å ±ã®æ®µéã§ãå¸ä»¤ã«ã¨ã£ã¦æç¨ãããããªãããä½æ¦ç°å¢ã«é¢ããä»ã®ç¶æ³ãéå»ã®çµé¨ã¨ç §ããåãããã¨ãããã®æ å ±ã«å¯¾ããæ°ããç解ãçã¾ãããããã "ã¤ã³ããªã¸ã§ã³ã¹ (Intelligence)" ã¨è¨ãã®ãããããªãã
(ä¸ç¥)
ã¤ã³ããªã¸ã§ã³ã¹ã¯ãæçµçã«æ å ±ã¨ã¯2ã¤ã®ç°ãªãç¹å¾´ããããã¤ã³ããªã¸ã§ã³ã¹ã¯å°æ¥ã®ç¶æ³ãæ å¢ãäºæ¸¬ãããã¨ãã§ããè¡åæé(Courses of Action)ãã¨ããã¨ã§ã©ã®ãããªéããçã¾ãããæããã«ãããã¨ã«ãã£ã¦ææ決å®ã«è²¢ç®ãããã¨ãã§ããã
b. ã¤ã³ããªã¸ã§ã³ã¹ã¯ãä½æ¦ç°å¢ãç解ãããããããããã®è©ä¾¡ããã³æ¨å®ãå¸ä»¤ã«æä¾ããã
(ä¸ç¥)
c. ã¤ã³ããªã¸ã§ã³ã¹ã¯ç§å¦ã§ã¯ãªããã¤ã³ããªã¸ã§ã³ã¹ã¢ããªã¹ã(åæè )ã¯ä½æ¦ç°å¢ãè©ä¾¡ããéã«ä¸ç¢ºå®æ§ãæã£ã¦ããã
(ä¸ç¥)
ãããã£ã¦ãã¢ããªã¹ãã¯èªãã®åæã«ã©ã®ç¨åº¦ä¿¡é ¼ãæã£ã¦ããã(degree of confidence)ãä¼ãããã¨ãéè¦ã§ããã
(ä¸ç¥)
d. ã¤ã³ããªã¸ã§ã³ã¹ã«ã¯ãè½åã»ããã»ã¹ã»çµç¹ãå«ã¾ããã
ããã»ã¹ã«ã¯ãåé, å å·¥, æ½åº, åæ, é å¸ã®å·¥ç¨ãå«ã¾ãã¦ããã
(ä¸ç¥)
ã¤ã³ããªã¸ã§ã³ã¹ã¯ããèªä½ãç®çã§ã¯ãªããä½æ¦ã«ãããã¤ã³ããªã¸ã§ã³ã¹ã®é¢é£æ§ãåä¸ãããããã«ãããã¼ã¸ã£ã¼ã¯æ¶è²»è ã®ãã¼ãºãäºæ¸¬ããã¤ã³ããªã¸ã§ã³ã¹ãå¹æçããå½±é¿åãããããæ¤è¨ããªããã°ãªããªãã
(ä¸ç¥)
ä½æ¦ç°å¢ã¯çµ¶ããå¤åãããããã¤ã³ããªã¸ã§ã³ã¹ã¯ç¶ç¶çãªæ´»åã§ãããã¨ãçæããå¿ è¦ãããã
ããã¾ã§èªã¿é²ããã¨é常ã«è©³ç´°ã«æ¸ããã¦ãããããå¤ãã®æ¹ãããé®®æã«"ã¤ã³ããªã¸ã§ã³ã¹"ãã¤ã¡ã¼ã¸ã§ããããã«ãªã£ãã®ã§ã¯ãªãã ããããçè ãªãã«ã¾ã¨ãã"ã¤ã³ããªã¸ã§ã³ã¹ã¨ã¯ä½ã"ãã¾ã¨ãããã®ã以ä¸ã§ããã
- ã¤ã³ããªã¸ã§ã³ã¹ã¨ã¯: 以ä¸ã®3ã¤ãå«ããã®ã§ããã
- è½å: ææ決å®è ã«å¯¾ãã¦æå¹ãª"ã¢ã¦ãããã(ææç©)"ãæ示ã§ãããã¨ãæããå ·ä½çã«ã¯ããã¼ã¿ãåéããæ å ±ã¸ã¨å å·¥ããåæãã¦ã¤ã³ããªã¸ã§ã³ã¹ã¸ã¨æè¯ã§ããã¨ã¨ãã«ããããææ決å®è ã«å¯¾ããå ·ä½çãªè¡åæéã¨ãã¦è²¢ç®ã§ãã¦ãããã¨ã§ããããµã¤ãã¼ã»ãã¥ãªãã£ã®æèã§ã¯ãCISOã«å¯¾ãã¦ã»ãã¥ãªãã£æ½çãäºç®ã¸ã®æè¨ãSOCã«IoC(Indicator of Compromise)ãã·ã°ããã£ã®æä¾ã¨ãã£ãã¢ã¦ããããã該å½ãã
- ããã»ã¹*2: 顧客ã»çµç¹ã®ã¤ã³ããªã¸ã§ã³ã¹è¦æ±(Intelligence requirements)ãç解ã»æ¤è¨ããããè¦æ±ã«æ²¿ã£ãã¤ã³ããªã¸ã§ã³ã¹ãæä¾ã§ããããç¶ç¶çã«æ¹åãè¡ããã¦ããã
- çµç¹: ä¸è¨ãçµç¹çã«å¾äºããã¦ããã
- ãªãã¤ã³ããªã¸ã§ã³ã¹ãããã®ã
- å»ä¸å»ã¨å¤åã大éã®æ å ±ã溢ãã¦ããç¾å ´ã«ããã¦ãææ決å®è ã¯å¿ è¦ãªæ å ±ã ããåæ¨é¸æã次ã®è¡åã決ããå¿ è¦ããããã¤ã³ããªã¸ã§ã³ã¹ã¯ææ決å®è ãå©ããçµç¹ãããæé©ãªè¡åãã¨ããã¨ãç¶ç¶çã«ãµãã¼ãã§ãã
- ã¤ã³ããªã¸ã§ã³ã¹ã¯ã©ã®ããã«çã¾ããã©ã®ãããªç¹æ§ãæã¤ã®ã
- çµç¹ã«æå±ããè½åãæã£ãã¢ããªã¹ãããææ決å®è ã®ãã¼ãºããã¨ã«æ¹åãç¹°ãè¿ããªããè¡åæéã«å¯ä¸ããåæããããã¨ã§çæãããããããã¤ã³ããªã¸ã§ã³ã¹ã¯ç§å¦ã§ã¯ãªãä¸ç¢ºå®æ§ãä¼´ã£ã¦ãããããåæã«ã¯ã¢ããªã¹ãã®è©ä¾¡ã»æ¨å®ãå«ã¾ãããã¢ããªã¹ãã«ããä¸ç¢ºå®æ§ã®è©ä¾¡ã¯ãä¿¡é ¼åº¦ã¨ãã¦è¡¨ç¾ãããã
å°ã
é åãã¨ãªã£ã¦ãã¾ã£ããããã®ã¾ã¨ããè¸ã¾ãã¤ã¤ããJoint Intelligenceãã®å®ç¾©ã«åºã¥ããªããããOSINTã¨ã¯?ãã«å¯¾ããçè
ãªãã®èª¬æä¸è¨ã§è¡¨ç¾ãã¦ã¿ãã¨ã以ä¸ã®ããã«ãªã£ãã
ãçµç¹ã»é¡§å®¢ã®ã¤ã³ããªã¸ã§ã³ã¹è¦æ±ãéæãããã¨ç®çã¨ãã¦å ¬éæ å ±ãåéã»åæãã çµç¹ã®æ å ±æ¦ã«é¢ããææ決å®ã«ç¶ç¶çã«è²¢ç®ãããã¨ã
ãã¦ãããã§ã¯åé ã®åãã«æ»ãããWebè¨äºã®ã¾ã¨ããSNSã¢ã«ã¦ã³ãç¹å®ã¯æããã¦OSINTãªã®ã ããããçè
ã®è¦è§£ã¨ãã¦ã¯ããOSINTãçæããããã®æ
å ±åéåã³åæçµæã®ä¸é¨ã§ã¯ãããããã¤ã³ããªã¸ã§ã³ã¹ã®å®ç¾©ã«ã¯æ²¿ã£ã¦ããªãã®ã§OSINTã¨è¡¨ç¾ãã¹ãã§ã¯ãªãããã«ãªããã¤ã¾ããå
æ¥ã®ãã£ã¡ãã¨ããå®ç¾©ã«åºã¥ãã¦"ã¤ã³ããªã¸ã§ã³ã¹(ã¾ãã¯ãOSINT)"ã¨ããåèªã使ç¨ãã¦ãã人ã«ã¨ã£ã¦ã¯ãæ¨ä»æ§ã
ãªã³ã³ããã¹ãã§ä½¿ç¨ããã¦ããOSINTã¯æ¬æ¥ã®æå³ãããããå¥ã®ä½ãã¨ãã¦æ ãã®ã§ããã
æ¬é¨åã«ããã¦ããOSINTãçæããããã®æ´»åãæãã¦"OSINT"ã¨è¡¨ç¾ãã¦ãã人ãæ£è¦ãããããããæ
å ±åé(Open-Source Collection)ã¨ããã®ã¯OSINTãçæããããã§ã®æ´»åã®ä¸é¨ã§ã¯ããããããèªä½ã¯OSINTã§ã¯ãªãããã¨ããæå³ãè¾¼ãã¦ããã®ãããªæ¬è³ªçãªäºè±¡ã«ã¤ãã¦è¿°ã¹ãã¢ããªã¹ãããããã®ã¨æãããã
ããã¾ã§é·ã
ã¨è¶çªããç¶ãã¦ããããç´è¿ã§SANSããåºãããOSINTã«é¢ããè¨äºã§ãåæ§ã®å
容ãæ¸ããã¦ãããã¨ã確èªã§ãããä½åãããæ¹ã¯ãæ¯éä¸èªãã¦ãããããã
www.sans.org
åé ãæç²ããã¨ã以ä¸ã®ããã«è¿°ã¹ããã¦ããã®ã確èªã§ããã ããã
Open-Source Intelligence (OSINT) is defined as intelligence produced by collecting, evaluating and analyzing publicly available information with the purpose of answering a specific intelligence question.
OSINT ã¯ãç¹å®ã®ã¤ã³ããªã¸ã§ã³ã¹è¦æ±ã«ãããããã¨ãç®çã¨ãã¦ãå ¬éããã¦ããæ å ±ãåéã»è©ä¾¡ã»åæãããã¨ã«ãã£ã¦çæãããã¤ã³ããªã¸ã§ã³ã¹ã¨å®ç¾©ãããã
OSINT ã®ã¹ã³ã¼ãå®ç¾©ãããã¯å«çã¨ã®å¢ç
ä»å¹´ã OSINT ããããã¯ã¨ãã¦æ±ãè¬ç¾©ãããã®ã§ãæ¹ãã¦å®ç¾©ã宣è¨ããã®ã大åã ãªãã¨ããããæ£è§£ã ï¼ã§ã¯ãªãã諸説ããã¾ããã«ã¯ãªãã ãããã©ð¤èªåã¯ãããªã¤ã¡ã¼ã¸ã§æãã¦ãã¦ãããã¦ãããâ»è«¸èª¬ãã pic.twitter.com/bxS3ZBxj8J
— _roku_ (@00001B1A) 2023å¹´3æ9æ¥
æ¬é¨åã¯ãOSINT ãããéç¨ã§å³ãããã¦æ»æã¨ãªã£ã¦ãã¾ã£ãããæ³å¾ã«æµè§¦ãããããªãã¨ããããããããªãã®ã§æ³¨æãã¦ãã ããããã¨ããçºè¨å 容ããã¨ã ã£ããããæ³ã¨å«çã«é¢ããè¨åãæãå¤ãã£ãããã«æãã¦ããã
OSINTã®å®ç¾©ã¯å ã«è¿°ã¹ãéãã§ããããçè ã調ã¹ãéãã§ã¯ããã«å«çãæ³ã¨ãã£ãæ¦å¿µã¯ä»å¨ãã¦ããªãããã®ãããOSINTã¨å«çã«é¢ããè«ç¹ã¯ãã"OSINT"ãçæããã«ããããå«çã«èãã»æ³ãç¯ãã¢ã¯ãã£ããã£ã¨ããã®ã¯ããã«å«ã¾ããã¹ãã§ã¯ãªãã®ã§ã¯ãªãããã¨ããå½é¡ã«è¨ãæãããã¨ãã§ããã®ã§ã¯ãªããã¨æãã(ããçè ã趣æ¨ãééã£ã¦ç解ãã¦ãããªãã°ãç³ã訳ãªãã)
ãã®è«ç¹ã«é¢ãã¦ããOSINTã¯å«çã»æ³ã«èãã¢ã¯ãã£ããã£ãå«ã¾ãªããã¨ããæè¦ãæ£è¦ãããããããçè ã®ç§è¦ãè¿°ã¹ããªãã°ããOSINTãçæããããã®ã¢ã¯ãã£ããã£ã«ã¯å«çã»æ³ã«èããã®ãå«ã¾ãããã¨ããã®ãOSINTã¨å«çåé¡ã«å¯¾ããåçã«ãªããçè ã®è¨èã§è¨ãæãããªãã°ããå·±ãã¤ã³ã¿ã¼ãããããã¾ãã£ã¦èª¿æ»ã»åæããçµæçæãããã¤ã³ããªã¸ã§ã³ã¹ã§ããã°ãããã¯ãã¹ã¦ãOSINTã«åé¡ããããã¨ãããããªèªèã§ãããããã¯ãä¸ã§å¼ç¨ããã¦ããã ãã _roku_ ããã®å³ãé常ã«åèã«ãªãã¨èãã¦ãããçè ã®OSINTã«é¢ããç解ãã¾ããããã®éãã§ãããOSINTãçæããããã®ã¢ã¯ãã£ããã£ã大å¥ããã¨ãã¿ã¼ã²ããã«å¯¾ãã¦èªããç´æ¥é¢ä¸ããçè·¡ãæ®ãActiveã¨ããã§ãªãPassiveã®2ã¤ã®ã¿ã¤ãããããActiveã®æ´»åããããããã¨å«çãæ³å¾ã®åé¡ã絡ãã§ããã¨ããèªèã§ãããããã¤ãé åãããããã¦ãã¦ããããã«å«ã¾ãããã¹ã¦ã®ã¹ã³ã¼ããOSINTãçæããããã«å¿ è¦ãªã¢ã¯ãã£ããã£ã§ããã
ãªããããã¯ããã¾ã§ãOSINTã®å®ç¾©çã«å«çã»æ³ã«èãæ´»åããã®çæéç¨ã§è¡ããã¦ãããã®ããããã¨ãããã¥ã¢ã³ã¹ã§è¿°ã¹ããã®ã§ãã£ã¦ã決ãã¦ç¯ç½ªãæåãããããªå 容ã§ã¯ãªããã¨ã«çæãã¦ã»ãããããããªãããããã¾ã§ãµã¤ãã¼ç©ºéã«ãããæ å ±æ¦æåã®ãããªåå¨ã§ããOSINTã«æ±ããããã®ã¯æ å ±ã®æ£ç¢ºæ§ãèç¶æ§ã証æ ã®ç¢ºå®æ§(åç¾æ§)ã§ãããã¤ã³ããªã¸ã§ã³ã¹ã¨ãã¦ã®ä¾¡å¤ãé«ããããã®è¡åã¯å«çã»æ³çã«çåãæ®ã£ãã¨ãã¦ããæçµçã«çæãããã¤ã³ããªã¸ã§ã³ã¹ã«å«ççãªåé¡ã絡ã¾ãªãã®ã§ããã°ãããã¯é常ã«ä¾¡å¤ã®ããã¤ã³ããªã¸ã§ã³ã¹ã¨ãã¦äº«åãã¦ããçµç¹ãå¤ãã®ã§ã¯ãªãã ããããå°ãªãã¨ããçè ã¯å«ççã«çåãããææ³ã¯ç¨ãããã¦ããã©ãããããé人éçãªè¨åãããã¤ã³ããªã¸ã§ã³ã¹ãçæããã¦ããã¬ãã¼ãã¯è¦ããã¨ã¯ãªããç¾å®ã«ãã«ã³ãã¡ã¬ã³ã¹ã§ã®çºè¡¨ãæåã¤ã³ããªã¸ã§ã³ã¹ãµã¼ãã¹ã®ã¬ãã¼ããè¦ã¦ãã¦ããããããæ³çã«åé¡ããæ¹æ³ã§IoCãåå¾ãã¦ãããªãã¨ããã¢ãã¯ã¡ãã»ãåå¨ãããã ããããã«å¯¾ãã¦çã¯çæãããã¤ã³ããªã¸ã§ã³ã¹ã«æè¬ãããªããèªçµç¹ã®ã·ã°ããã£ã«çµã¿è¾¼ãã§ããã®ã§ã¯ãªãããããã ã¨ããã¨ãå¤ãã®çµç¹ã¯å«çã»æ³çã«åé¡ã®ããæ´»åãæé»çã«äºæ¿ãã¦ããã¨ãããã¨ã«ä»ãªããªãã
å ã»ã©ã¾ã§ã¯ãã¤ã³ããªã¸ã§ã³ã¹ã¨å«çãã¨ãã観ç¹ã§è«ããããã§ã¯è¦ç¹ãããå°ããã¯ãã«è½ã¨ããOSINTãçæããã¾ã§ã®ã¢ã¯ãã£ããã£ã¨å«çãã¨ãã観ç¹ãããèãã¦ã¿ãããæ³ãå«çã«æµè§¦ããããªã¢ã¯ãã£ããã£ã«å¯¾ããè¨åã«ã¯ã©ã®ãããªãã®ããã£ãã ãããã
Aãä¸æ£ã¢ã¯ã»ã¹ã¯ãããª!ã
Bã許å¯ãªãèå¼±æ§æ¤æ»ããããª!ã
ãªãã»ã©ããããã«ã¢ã¯ãã£ããã£ã«å¯¾ãã¦ã¯å«çã»æ³çã«åé¡ããããã¨ã¯ããã¾ããããã¨èª¬ããã¨ãã§ãããã§ããã(ããããããã¯OSINTã¨ããæèã§ã¯ãªã"調æ»æ´»å"ã®ãããªãã¥ã¢ã³ã¹ã§èªãã»ããæ£ç¢ºãªæ°ããã¦ãªããªãã)
ã§ã¯ããããã®è¡çºãã©ã®ãããªæ³å¾ã«å¼ã£ãããæããããã®ã ããããããããããä¸æ£ã¢ã¯ã»ã¹è¡çºã®ç¦æ¢çã«é¢ããæ³å¾ããé称ãä¸æ£ã¢ã¯ã»ã¹ç¦æ¢æ³ãã該å½ãããæ³å¾ã®è©²å½é¨å*3ãæç²ããã¨ã以ä¸ã®æé¢ã«ãªãã¨æãããã
ä¸æ£ã¢ã¯ã»ã¹è¡çºã®ç¦æ¢çã«é¢ããæ³å¾
(ä¸ç¥)
第äºæ¡
ï¼ããã®æ³å¾ã«ããã¦ãä¸æ£ã¢ã¯ã»ã¹è¡çºãã¨ã¯ã次ã®åå·ã®ããããã«è©²å½ããè¡çºãããã
ä¸ãã¢ã¯ã»ã¹å¶å¾¡æ©è½ãæããç¹å®é»åè¨ç®æ©ã«é»æ°éä¿¡åç·ãéãã¦å½è©²ã¢ã¯ã»ã¹å¶å¾¡æ©è½ã«ä¿ãä»äººã®èå¥ç¬¦å·ãå ¥åãã¦å½è©²ç¹å®é»åè¨ç®æ©ãä½åãããå½è©²ã¢ã¯ã»ã¹å¶å¾¡æ©è½ã«ããå¶éããã¦ããç¹å®å©ç¨ããå¾ãç¶æ ã«ãããè¡çºï¼å½è©²ã¢ã¯ã»ã¹å¶å¾¡æ©è½ãä»å ããã¢ã¯ã»ã¹ç®¡çè ããããã®åã³å½è©²ã¢ã¯ã»ã¹ç®¡çè åã¯å½è©²èå¥ç¬¦å·ã«ä¿ãå©ç¨æ¨©è ã®æ¿è«¾ãå¾ã¦ãããã®ãé¤ããï¼
(ä¸ç¥)
ä¸ãé»æ°éä¿¡åç·ãä»ãã¦æ¥ç¶ãããä»ã®ç¹å®é»åè¨ç®æ©ãæããã¢ã¯ã»ã¹å¶å¾¡æ©è½ã«ãããã®ç¹å®å©ç¨ãå¶éããã¦ããç¹å®é»åè¨ç®æ©ã«é»æ°éä¿¡åç·ãéãã¦ãã®å¶éãå ãããã¨ãã§ããæ å ±åã¯æ令ãå ¥åãã¦å½è©²ç¹å®é»åè¨ç®æ©ãä½åããããã®å¶éããã¦ããç¹å®å©ç¨ããå¾ãç¶æ ã«ãããè¡çº
è¦ç´ããã¨ãæ¬äººã®è¨±å¯ãªãã«èªè¨¼æ å ±/èå¼±æ§ã使ã£ã¦æä½ããã¦ã¯ãããªããã¨ããå 容ã ãããããããã«ããã¯å«ççã«ãåé¡ãããè¡çºã ããå 容ã¨ãã¦ã¯å¦¥å½ãªæ³å¾ã§ãããããããªãã
ã§ã¯ãã¡ãã£ã¨å¥ã®äºä¾ãèãã¦ã¿ãããããªãã®æå±ããã¤ã³ããªã¸ã§ã³ã¹ãã¼ã ã§ã¯ãèªçµç¹ã«é¢é£ãããµã¤ãã¼è å¨ã®IoCãåéããä¿¡é ¼æ§ã®é«ããã®ãSOCã«æä¾ãã¦ã»ãããã¨ããã¤ã³ããªã¸ã§ã³ã¹è¦æ±ãéæããå¿ è¦ããã£ãã¨ãããã¢ããªã¹ãã¯èªçµç¹ã®ãããã¯ã¼ã¯å¢çãã¤ã³ã¿ã¼ãããããæ¥æ¬ã«é¢é£ããã§ããããµã¤ãã¼æ»æé¢é£ã®IoCãåéããè©ä¾¡ã»åæããã¦ç¶ç¶çã«SOCã«ã¤ã³ããªã¸ã§ã³ã¹ãé å¸ãããã¨ã«ãªãã ããã
æ¥æ¬ã«ã°ãã¾ããããã«ã¦ã§ã¢ã«ã¯æ§ã
ãªç¨®é¡ã®ãã®ãããããããã§ã¯Agent Teslaã¨ããæ
å ±æååã®ãã«ã¦ã§ã¢ã«ã¤ãã¦ã¨ãããã¦ã¿ããã
ãã®ãã«ã¦ã§ã¢ã¯ææãã端æ«ã®ã¯ã¬ãã³ã·ã£ã«æ
å ±ãåéããå¾ãä»ã®ææè
(æ»æè
ãç¬èªã§ä½æãããã®ã®å ´åããã)ããèªè¨¼æ
å ±ãçãã§ã³ã³ããã¼ã«é
ä¸ã¨ãªã£ãã¡ã¼ã«ãFTPãµã¼ãã«å¯¾ãã¦èªè¨¼ãè¡ããçãã æ
å ±ã転éããã¨ãã£ãåä½ãããã
news.sophos.com
ä¾ãã°ã以ä¸ã®æ¤ä½ã¯æ¥æ¬ã®IPã¢ãã¬ã¹ããANY.RUN ã¨ãããªã³ã©ã¤ã³ãµã³ãããã¯ã¹ã«æ稿ããããFTPãµã¼ãã«å¯¾ãã¦æ
å ±ã転éããã¿ã¤ãã®ä¾ã§ããã
app.any.run
ããã§ä¸ã¤ã®çåãçã¾ããããæå³çã«ãªã³ã©ã¤ã³ãµã³ãããã¯ã¹ã«ãã«ã¦ã§ã¢ãã¢ãããã¼ãããçµæãä»äººã®èªè¨¼æ å ±ãåæã«ä½¿ç¨ãã¦ã¢ã¯ã»ã¹ãã¦ãã¾ã£ãå ´åã¯ä¸æ£ã¢ã¯ã»ã¹ç¦æ¢æ³ã«è©²å½ããã®ã ããã?ãã¨ã
ãããçè ãæé¢ãèªãéãã§ã¯ããã®ãããªã±ã¼ã¹ããä¸æ£ã¢ã¯ã»ã¹ç¦æ¢æ³ã«è©²å½ãããã®ã§ã¯ãªããã¨æãããããããªããé®æï¼ï¼ãã¨ããäºæ ã«ã¯ãã¡ãããªããªãã¨ã¯æãããä¸æ£ã¢ã¯ã»ã¹ç¦æ¢æ³ã¯é親å罪ã§ãã以ä¸ãå½äººãå½äººãå«ãã æå±çµç¹ã«æ¨ã¿ã®ãã第ä¸è ã«ãã£ã¦ããã®äººããã®ãµã¼ãã¹ã使ã£ã¦ä»äººã®è¨±å¯ãªãèªè¨¼æ å ±ãå ¥åãã¦ä¸æ£å©ç¨ãã¾ãããï¼ï¼ãã¨åçºããã¦ãã¾ã£ãããå½äººã貶ãããããªãã¦ãã¨ã¯ååèããããã ããã(çè ã¯æ³å¾ã®å°é家ã§ã¯ãªããããããããããè¦å½éãã®ãã¨ã話ãã¦ãããããããªããããã§ãã£ããç³ã訳ãªãã)
ã§ã¯æ¤ä½ãã¢ãããã¼ãã¾ã§ã¯ããªãã¨ããã¤ã³ããªã¸ã§ã³ã¹ã§éè¦ãªåç¾æ§ãã¨ãããã«ãANY.RUN ã«ãã "Restart" ãã¿ã³ãæ¼ãã¦ããä¸åº¦è§£æãè¡ãæåã確èªãã¦IoCãæ´çããã¨ããããããã¯ãã©ãã ããã? åãããVirusTotal ã«ãã Reanalyze ãã¿ã³ãæ¼ããå ´åã¯? ãããã©ã¡ããå度éä¿¡ã¯é£ãã§ãããããã¢ã¦ããªæ°ããã¦ãªããªãã
ããããç´°ããæä½ã¯ä¸åããã«çµæã ã確èªããã°ããã§ã¯ãªãããã¨ãã話ã§ãããããããªã(ããããè«ã¨ãã¦ãçµæãåéããã®ã¿ã§ç¬èªã§åæãããªãã¨ããè¡çºã¯ãã§ã«ã¤ã³ããªã¸ã§ã³ã¹ã§ã¯ãªãã®ã ããä¸æ¦èã«ç½®ãã¦ããã)ãã§ã¯ä»ã®èª°ããã¤ã³ã¿ã¼ãããä¸ã«æ å ±ãå ¬éããã®ãå¾ ã¡ããã®çµæã ããåãåãã¨ããã®ã¯æããã¦èª å®ãªè¡ããªã®ã ããããããã¯è¨ãæããã°ããåãããã¨ç¯ç½ªã«ãªããããããªããã©ãä»ã®èª°ãããã£ããã®ã®çµæã ããé²è¦§ããåã«ã¯ç¯ç½ªãããªãããã誰ããããã®ãå¾ ã¡ãªãããã¨ããããã ãã å®è¡ç¯ãèªå以å¤ã®èª°ãã«ãªããã¤ããã ãã®è¨èãªæ°ããã¦ãçè ã¯å«ççãªåé¡ãæ±ãã¦ãããããªæ°ããã¦ãªããªã (çè ã®å«ç観ãçã£ã¦ããã¨ãããã¨ãããã®ãããããªãã)ãããã¾ã§çå¿æ鬼ã«ãªãã¨ãã¹ã¦ããã¼ã«ã«ç°å¢ã§åæãããããªããªã£ã¦ãã¾ãã®ã ããããããå¤é¨ã®ã¤ã³ããªã¸ã§ã³ã¹è¦æ±ã«ããããããã®æ´»åã®ã¯ããªã®ã«ãã®ã¤ã³ããªã¸ã§ã³ã¹ã®è©³ç´°ãå¤ã«åºãã«ãããã¨ãããªãã¨ãä¸åçãªç¾å®ãçã¿åºãã®ã§ããã
ããã¯ããã¾ã§ä¸ä¾ã§ãããããã®ã»ãã«ã権éè¨å®ããã¾ãAPI keyãæ»æè
ãè¨ç½®ããWebshellãªã©ã調æ»ãæ·±ã¼ããã¦ããããã§ãããã£ã¦ã©ãã¾ã§ãã£ããæ³ã§è£ããããã§ãã?ãã¨ããå ´é¢ã«ã¯ãã³ãã³ééãããç¾å®åé¡ãçè
ãä½åº¦ãç´é¢ããçµé¨ãããããããã¼ã ã«ãããããã£ã¦ãããã¨æãã¾ãã?ãã¨è°é¡ãæãããããã¨ããã³ãã³ããããã®ã»ãã«ãããIPã¢ãã¬ã¹ãå
¥ããã¨ãµã¼ãã¹ã調æ»ãã¾ããèå¼±æ§æ¤æ»ã¾ã§ã¯ãã¾ããããã¨è¬¡ã£ã¦ãããªãããæªæ§ãã±ãããéãä»ãã¦ãããµã¼ãã¹ãåå¨ãããããããªãããhogehoge ã¯ãã¦ã¯ãªããªããã¨è«ããã®ã¯å®¹æãããå®éã®ã¢ã¯ãã£ããã£ãæ¬å½ã«ãhogehogeããå«ãã§ããªããã¨ãä¿è¨¼ã§ãããã¨ããã®ã¯æè¡ã«å¯¾ãã¦æ·±ãé è©£ããªããã°ãªããããåï½ä¸ç´è
ã«ã¨ã£ã¦ã¯æ³¨æåèµ·ãããã¦ããã®å¢çã¯ä¸æçã®ã¾ã¾ã§ããããæ®æ´"å«ç"ã«é¢ãã¦ã¯ãå人ã«ããäºè±¡ã®åãæ¢ãæ¹ã®å·®ãæ¿ãããããä¸è¬è«çã«èªããã¨ãå°é£ã§ããã
å®ç ´é¢
ä»åè¬æ¼ãã¦ããªããã©ãOSINTã§å¾ãããã¡ã¼ã«ã¢ãã¬ã¹ã¨ãã¹ã¯ã¼ããå ¥ãã¦ãã°ã¤ã³æåããå ´åãMITERã®åµå¯ã«ããNessusãªã©ã§ã®èå¼±æ§ã¹ãã£ã³ã¯ä¸é¨èå¼±æ§ã使ã£ãæ»æã³ã¼ããå«ã¾ãã¦ããã®ã§æåããå ´åã®2ã±ã¼ã¹ã¯ä¸æ£ã¢ã¯ã»ã¹ç¦æ¢æ³ã«ãããã¾ãã
— lumin (@lumin) 2023å¹´3æ9æ¥
ããã¾ã§æ£ã å«çã»æ³ã«ã¤ãã¦è¿°ã¹ã¦ããããçè ã¯åæªåçããããããã§ãå«çã«é¢ããå²å¦ããããããã§ããªããå ã§è¿°ã¹ããã£ããã¨ã¯ããOSINTãçæãã以ä¸ããã®çæéç¨ã«ããã¦ãããå«çã»æ³çãªåé¡ã«ç´é¢ãããã¨ãããã¨ã§ãããããã«çåãåããæ¹ã¯ããããããã®ã¤ã³ããªã¸ã§ã³ã¹ãã©ã®ããã«ãã¦çæããã¦ãããã«ã¤ãã¦ç¡ç¥ã§ãããã人éã ãã§ããã(å°ã ã表ç¾æ¹æ³ããããªãæ°ãããã)ã
ãããã ããã¨è¨ã£ã¦ãOSINTã«ã¤ãã¦ç´¹ä»ãç ä¿®ããã人éã»çµç¹ããOSINTã¯å«çãæ³ã®åé¡ãä»ãç©ã ãããã©ã¤ã³è¦æ¥µããªããã©ãã©ã調æ»ããã¦ããããããªãã¦ãã¨ãç¡è²¬ä»»ã«å±ãããã¨ã¯ã¾ãã§ããªããç¹ã«ä¸æ£ã¢ã¯ã»ã¹ç¦æ¢æ³ãã¢ã¦ãã®å¢çç·ãæçã§ãªã以ä¸ãæ¥æ¬ã§ã¯ä¸æ©éãå¤ãããéæ³ã«ãªããããªOSINTã¨ããåå¨ã¯ãä¸è¬è«çã«ã¯å¶ç´ããããç¶æ ã§ç´¹ä»ããããå¾ãªãã ãããçè ãOSINTã«é¢ããç ä¿®ãä½æãããã¨ãããããå¤é¨ã®äººéã«ã話ã以ä¸ä¸å¹¸ããã£ã¦ã¯ãããªãã¨æãããã¼ã«ããµã¼ãã¹ã®ç´¹ä»ã§ã¯æ³¨æäºé ãå·æã«è¨è¿°ãã¦ããããã®ãããªèæ¯ãããOSINTã¯å«çã»æ³ã«èãã¢ã¯ãã£ããã£ãå«ãã§ã¯ãªããªããã¨èãã¦ãã人ã®å¤ãã«ããã®ãããããªããããæå³ãæ¥æ¬ã«ããã"å®"çãªOSINTã®èãæ¹ã§ããã
ããããªãããçµç¹ã»æ¶è²»è ã®ã¤ã³ããªã¸ã§ã³ã¹è¦æ±ã«å¯¾ãã¦å°ãã§ã価å¤ã®é«ãçããè¿ããã¨ããã¨ã"å®"ã®ã¿ã®èãæ¹ã¯åä»ãª"éç"ã¨ãã¦ç«ã¡ã¯ã ãã£ã¦ããããã®ãããã®èª²é¡æããã¡ãã»ãè¦ããããå«çã»æ³ã®éµå®ã¯ç¡çããããã¨ãã"ç ´", "é¢"å´ã«ããã¢ããªã¹ãã®èããªã®ã§ã¯ãªããã¨æãããããã®èª²é¡ã«ééããå ´åãå人ã®å¤æã§èª¿æ»ãç¶ç¶ããã«ã¯ãªã¹ã¯ã大ããããã®ã§ãããã¾ã§ã¯èª¿æ»ãã¾ãããããããå ã¯æ³çã«ã°ã¬ã¼ã¾ã¼ã³ã«ãªãã¾ããããããæ·±ã¼ãããã°ãã価å¤ã®é«ãã¤ã³ããªã¸ã§ã³ã¹ã«ãªãã¨æãã®ã§ãã調æ»ãç¶ç¶ãã¾ãã?ãã¨ãã£ãå ·åã§çµç¹å´ã®ææ決å®ã«å§ãã¦ãããã®ãæåæã«ãªãã®ã§ã¯ãªãã ããããæ å ±å¦çå®å ¨ç¢ºä¿æ¯æ´å£«ãªã©ã®è³æ ¼ããã®ãããã®å«çãç¸ã£ã¦ããä¸æ¹ã§ãæ´»åã®å¹ ãåºãã¦ããããããªç¹æ¨©ã¯ä½ä¸ã¤ä¸ãã¦ãããªããä¿å®çãªçµç¹ã§ã¯æ´»åãé常ã«å¶éããã¦ãã¾ã£ã¦ãããããçé¢ç®ã«åãçµãã§ããã¢ããªã¹ãã»ã©å®çãªOSINTã«å¯¾ããéçã«åãã¦ããã®ã§ã¯ãªããã¨æãããã
ãªããæ¬è¨äºãããããOSINTãªãã !!ãã¨ãã£ã"å®"å¯ãã®å 容ã§ã¯ãªãã"ç ´"ã«åãã£ã¦ããæ»ããã人éãæ¸ãã¦ãããã®ã§ãããä¸è¬è«ã§ã¯ãªãã話ååã§è¦ã¦ãããã»ããããã ããã
ããããã®OSINTã®è©±ãããã
ãã¦ã話ãå°ããããã®ã§ã¾ãæ¬é¡ã«æ»ããããIntelligence â Collectionãã®ç¯ã«ããã¦ãçè
ãªãã®OSINTã®å®ç¾©ã¨ã¯ãçµç¹ã»é¡§å®¢ã®ã¤ã³ããªã¸ã§ã³ã¹è¦æ±ãéæãããã¨ç®çã¨ãã¦å
¬éæ
å ±ãåéã»åæãã çµç¹ã®æ
å ±æ¦ã«é¢ããææ決å®ã«ç¶ç¶çã«è²¢ç®ãããã¨ãã§ãããã¨ã¨è¿°ã¹ãã
ããããªãããçéã§ããã¾ã§æ§ã
ãªæè¦ãé£ã³äº¤ããã¨ãè¸ã¾ãã¦ããOSINT ã¨ããåèªã®è§£éã¯åã
人ã«ãã£ã¦è§£éã«å¤§ããªéãããããããã§ã¯ä¸æ¦ããªãããã¾ã§è§£éã®å¹
ãåºããªã£ã¦ãã¾ã£ãã®ããã¨ããçç±ãæ´çããããããã¨ã«ãã®OSINTã¨ããåèªãã©ãæ±ã£ã¦ããã¹ããåæ¤è¨ã試ã¿ãã
ãªãOSINTã®è§£éãããã¾ã§åºãã®ããã«å¯¾ããä¸èå¯
ãããèç¡ãªãã°èç¡èªèº«ããã®ã¨ã»ãã§
ããç¨åº¦ã¾ã§ã¯ã¿ããªã«å ±éãããã¾ã
ï¼ãã¹ã¦ãããããã®ä¸ã®ã¿ããªã§ããããã«
ãã¿ããªã®ãã®ãã®ã®ãªãã®ãã¹ã¦ã§ãããï¼
- ãæ¥ã¨ä¿®ç¾ ã: åº (宮沢 賢治)
ã¾ããã©ããã¦OSINTã¨ããè¨èã«ã¯ãããªã«ã解éã«éããããã®ããçè ãªãã«ããã¤ã仮説ãç«ã¦ã¦ã¿ãã
- ãããã "Intelligence" ã¨ããè¨èã®èªèãå¤ãã®äººã«èª¤è§£ããã¦ããã
- ãå ¬éæ å ±ããã調æ»ãããã¨ããåºç¾©çãªæå³ã§"OSINT"ã¨ç´¹ä»ãã¦ãã人ã»è¨äºããã
- ãã¿çãªã³ã³ããã¹ãã§ä½¿ããã"OSINT"ããã®ã¾ã¾å ¬çãªå ´é¢ã§ä½¿ããã
ã©ããå½ãããã¨ãé ããããªä»®èª¬ã ããçè ã®èãã§ã¯"OSINT"ã¨ããè¨èã使ã人ãå¢ãããã¨ãå½±é¿ã¨ãã¦å¤§ããã®ã§ã¯ãªããã¨èãã¦ãããå°ã ä¹±æ´ãªè¡¨ç¾ããããªãã°ããå°éç¨èªã®èªç¥åº¦ããããããã¦éå°é家ããã®ã¯ã¼ããå¤ç¨ãããã¨ã«ãªã£ãããã¨ãç¾å¨ã®äºæ ã«æè»ãããã¦ããã®ãããããªããOSINTã¨ããè¨èãå°ã ãã£ããã¼ãªè¨èãªã®ã§ã使ç¨ãããã¨ã«ãã£ã¦æ¤ç´¢ã«å¼ã£ããããããã£ãããããã¨ãããã®ã ããããJoint Publication 2-0: Joint Intelligenceãã®åé ã ããåãåã£ã¦è§£èª¬ãããããªWebè¨äºãè¦ã¦ããå ¬éæ å ±ãããæãã«ä½¿ã£ã¦ãã£ã¨ä¾¡å¤ã®ããä½ãã«ããã°ãããã¤ã³ããªã¸ã§ã³ã¹ãªã®ã!ãã¨ãã£ãå°ã ç°ãªãç解ããã¦ãã¾ã£ãæ¹ãããã®ãããããªãã
ããã¨ã¯å¥ã«ããOSINTã§ç¹å®ãã¾ããwãã®ãããªã¡ãã£ã¨ããããããã¼ã ããã¯ãªè¡¨ç¾ãè¦ã¦ãããããOSINTã£ã¦è¨ããããªãã¨è§£éããã人ãããã®ã ãããæ§ã ãªçç±ãèããããããOSINT ã¨ããè¨èãæ§ã ãªã³ã³ããã¹ãã§ä½¿ãããããã«ãªã£ãçé«ã«ã¯ããã®æ±ç¨æ§ã®é«ããèæ¯ã«ããã®ã§ã¯ãªããã¨çè ã¯èãã¦ããããå ¬éæ å ±ã使ã£ã¦ããæãã«ä½ããã¾ãããã¨ãããµãã£ã¨ãããã¥ã¢ã³ã¹ã§ãæè¡çã«è©³ãããªãç¸æã«å¯¾ãã¦ããã®ã¤ã¡ã¼ã¸ãä¼ããè¨èã¨ãã¦åªç§ãªã®ã ããããã¨ããWebãµã¤ãã§â³â³ã«ã¤ãã¦èª¿ã¹ã¦ãçºè¦ããÃÃãã¾ãå¥ã®ãã¼ã«ã§...ããªãã¦ãã¨ãããããè¨ããªãã¦ãããOSINTãããã¨ããã ãã§ããã¼ãªããããæãã«èª¿ã¹ããè¦ã¤ãã£ããã ãããªã¼ãã¨ç¸æã解éãã¦ãããã°ãããã§ã³ãã¥ãã±ã¼ã·ã§ã³èªä½ã¯æç«ããã®ã§ãããæ¬æ¥ã®"OSINT"ã®æå³ããã¯ä¹±ããçãã¦ãã¦ãã"ããç¨åº¦ã¾ã§ã¯ã¿ããªã«å ±é"ããã¤ã¡ã¼ã¸ã«ãã£ã¦ç¸æãé½åã®ããããã«è§£éãã¦ãããããã®ãããªéåãããã®OSINTã¨ããè¨èã«åãã£ã¦ããã®ãããããªãã
ãã®ä¸æ¹ã§ãããä¸å®æ°ã®äººéã«ã¨ã£ã¦OSINTã¨ããè¨è㯠"ã¿ããªã«å ±é" ããã¤ã¡ã¼ã¸ããé¸è±ãã¦ãã¾ã£ã¦ãããã¨ããã®ãä»åã®é¨åã«ãã£ã¦æãã¿ã«ãªã£ããã¨ã ãããç¾ã«ãå æ¥ã®è¨èã®æå³ãã大ããå¤ãããã®ããOSINTãã®æ´¾çã¨ãã¦è§£éããã¦ãããããå°é家ã«ã¨ã£ã¦ã¯ã³ã³ããã¹ãããã¡ãã¨ææ¡ããªããã°ãããèªåãæ®æ®µæ±ã£ã¦ããOSINTãªã®ããå¤æã§ããªãç¶æ³ã«é¥ã£ã¦ãããåããããªé¨åãç¹°ãè¿ããªãããã«ãããæã ã¯OSINTã¨ããåèªãã©ãæ±ã£ã¦ããã¹ãããã¨ãããã¨ãä»ä¸åº¦èãç´ãå¿ è¦ãããã®ãããããªãã
æã ã¯OSINTãã©ãæ±ãã¹ãã
å®ç¾©ãææ§ã§å ±éèªèãå½¢æããã¦ããªãè¨èãªãã ã£ãããã£ãã®ãã¨ä½¿ããªãã»ããããã¨æããã§ãããããOSINTãã£ã¦è¨èãã¾ãã«ããã
— è¾» ä¼¸å¼ (nobuhiro tsuji) (@ntsuji) 2023å¹´3æ9æ¥
çè ãèãã "OSINT" ã¨ããåèªã使ç¨ããä¸ã§çæãã¹ãäºé ã¯æ¬¡ã®äºç¹ã§ããã
- åèªã®å ±éèªèã確ç«ããã¦ããçµç¹å ã§ã®ã¿ä½¿ç¨ãããã¨
- ããããã®ä½¿ç¨ãé¿ãããã¨
ããããªãããã©ã¡ãã®äºé ã«ã¤ãã¦ããã®è¨äºãèªãã§ãã人ãããOSINTã¨ããåèªãé°å²æ°ã§ä½¿ãç¶ãã¦ãã人ã«å®ã¦ã¦ããã®ã§ãæããã¦æ¬è¨äºã§è¨åãããã¨ã§ç¾ç¶ãæ¹åããããã¨ããã¨ããã¯å®ãã§ã¯ãªããããä¸è¨ãé¸è±ãã¦ãããããªä½¿ãæ¹ã確èªããå ´åããã²ããªããè¦å¯ã¨ãã¦åãã¦ããã ãããã
ã¾ãä¸ã¤ã¯ãOSINTã¨ããã¯ã¼ãã£ã³ã°ã®ä½¿ç¨ã«éãã¦ãããå«ãå°éç¨èªã®å
±éèªèã確ç«ããã¦ããçµç¹ã§ã®ã¿æã¡åºãã¹ãã¨ããç¹ã§ããããã£ã¨ãã¤ã³ããªã¸ã§ã³ã¹ã«æºããæ¥åããã¦ããã°ãOSINTã«éããããã«ããããå°éç¨èªã¯å±±ã®ããã«åºã¦ããããã§ãããã解éããã¬ãæããä¾ãæ¨å®ç¢ºçè¨èªã¨ãã£ãä¿¡é ¼æ°´æºã表ç¾ããã¯ã¼ãã£ã³ã°ã ãããæ¨å®ç¢ºçè¨èªã¯ã¤ã³ããªã¸ã§ã³ã¹ã®ä¿¡é ¼æ§ã表ç¾ããããã§å¿
è¦ä¸å¯æ¬ ã§ããããããã«ä¸çæ¨æºçãªãã®ã¯åå¨ãããã©ã®ãããªã¯ã¼ãã§ä¿¡é ¼æ§ã表ç¾ãã¦ãééãã§ã¯ãªãããããã使ç¨ããã¯ã¼ãã®èªèãçµ±ä¸ããã¦ããªããã°ãã®ä¿¡é ¼æ§ã®è©ä¾¡ã¯ç価ãçºæ®ããªãã®ã¯æããã§ããã
en.wikipedia.org
ãã®ãããã¤ã³ããªã¸ã§ã³ã¹ãã¼ã ã«æå±ããã¢ããªã¹ãã¯ãèç¶æ§ã極ãã¦é«ããããèç¶æ§ãé常ã«é«ããã¨ãã£ãè¨èãé°å²æ°ã§ä½¿ãåãã¦ããããã§ã¯ãªãããä¿¡é ¼æ§ã99.9%ãªã"極ãã¦é«ã"ãã80%以ä¸ç¨åº¦ãªãã°"é常ã«é«ã"ã使ç¨ãã¾ããã¨ããåã決ããçµç¹ã«èªèãããããã§ããã¼ã ã®ã¢ããªã¹ãã«ããã®æå³ã§ã®ä½¿ç¨ãçµ±ä¸ããã¦ããã®ã§ããã
çè
ãæå±ããã¤ã³ããªã¸ã§ã³ã¹ãã¼ã ã®å ´åãå
é¨ã§ä½¿ç¨ãããå°éç¨èªã¯ãè
å¨ã¤ã³ããªã¸ã§ã³ã¹ã®æç§æ¸ãã«ã»ã¼çµ±ä¸ããã¦ãããææ決å®è
ã«èªå½ã®è©³ç´°ãªæå³ãåãããå ´åã¯ãæç§æ¸ã®P.ãã«ãããã®å®ç¾©ã«æ²¿ã£ã¦ãã¾ããã¨è¿ããã¨ãã§ããããã«ãã¦ãããã¤ã³ããªã¸ã§ã³ã¹ãµã¼ãã¹ã«ãã£ã¦ã¯ãå¼ãµã¼ãã¹ã¯ä»¥ä¸ã®ãããªç¢ºè¨¼åº¦ã«åºã¥ãã¦æ¨å®ç¢ºçåèªã使ç¨ãã¦ãã¾ããã¨ãã£ãå
±éèªèãããåãããããã®ãã¼ã¸ãç¨æãã¦ããã¦ãããã®ãåå¨ããã ããã
gihyo.jp
ããã¯æ¥µç«¯ãªä¾ã§ããããããã§ãã¤ã³ããªã¸ã§ã³ã¹ã¨ãããã®ã¯ç¨èªéã®æºåãææ決å®è
ã¨ã®ã³ãã¥ãã±ã¼ã·ã§ã³ãªã©ãçµç¹çã«åã決ãã¦æ¨é²ãã¦ãããªããã°ããã®å
±éèªèãããåããããã¨èªä½ãå°é£ãªã®ã§ãããããããããçµç¹å
é¨ã§ã®ã³ãã¥ãã±ã¼ã·ã§ã³ãåæ»ã«ããããã«ãããçµç¹ã§ã¯ä¸è¬ã¨ã¯å°ãç°ãªãæå³åãã§è§£éãçµ±ä¸ãã¦ããåèªã¨ããã®ãåå¨ãããããããªãããã®ããã第ä¸è
å士ããããªã対é¢ãã¦ãOSINTã~ããªãã¦è©±ããã¦ããææªã®å ´åãå
¨ãå¦ç¿ããã¦ããªãããã©ãå°éç¨èªãé°å²æ°ã§ä½¿ã£ã¦ãããã¨ããã±ã¼ã¹ãåå¨ãã以ä¸ãæ¬äººã®æå³éãã«ç¸æã«å
容ãä¼ãããã¯ããªãæªããã
ã¡ãªã¿ã«ãçè
ã¯ãã¤ã³ããªã¸ã§ã³ã¹æ¥åãã£ã¦ã¾ããã¨è¨ã£ãæµãã§ãæ¥åã®ä¸ç°ã§"OSINT"ããã£ã¦ã¾ãããã¨è¨ã£ãçµæã対話ç¸æã«ããã¼ã¯ã¦ã§ããç£è¦ãã¦ãã人ãã¨ãã¦èªèããããã¨ããããé¢åãªã®ã§è¨æ£ã¯ããªãã£ããããããããã®çµç¹ã«ãããOSINTæ¥åã¨ããã®ã¯ããã¼ã¯ã¦ã§ããã¢ãã¿ãªã³ã°ã»åæãã¦å¾ãããã¤ã³ããªã¸ã§ã³ã¹ã主ã¨ãªã£ã¦åã£ã¦ããã®ã ããããã®çµç¹ã«ããã¦ããã"OSINT"ã ã¨å®ç¾©ããã¦ããã¨ãã¦ããçè
ã¯ãããééã£ã¦ããã¨ã¯æããªããããããªããã"OSINT"ã¨ããè¨èã«å¯¾ããç解ã¨èªèã¯ãã®äººã®çæ´»åã«ãã£ã¦å¤§ããç°ã£ã¦ãããããããããä¾ãèªåãæ£ããè¨èã使ç¨ãã¦ããã¨ãã¦ããç°æåå士ã®ã³ãã¥ãã±ã¼ã·ã§ã³ã«ãªãããã¨ãããã¨ã¯å¿µé ã«ç½®ãå¿
è¦ã¯ãã£ããçãçè
ã®ãããªèª¤è§£ãçã¾ãªãããã«ããå
±éèªèã確ç«ãããåãæååã§ã®ã¿ãã¤ã³ããªã¸ã§ã³ã¹ã«ããããç¨èªã使ã£ã¦ããã ããã»ããè³¢æã§ããã
ããã¦ããä¸ã¤ããããè¨ãã¨å ãåããªãã®ãããããªãããOSINTã¨ããåèªããããã使ç¨ããªãããã«å¿ãããã¨ãããã¨ã ãããããæãè¿ãã¦ã¿ãã¨ãçè ã¯ã¤ã³ããªã¸ã§ã³ã¹ãã¼ã ã«æå±ãã¦ãããããã1å¹´åã«ãªãããæ¥åä¸ã«"OSINT"ã¨ããåèªãé£ã³äº¤ã£ã¦ãããã¨ã¯ãããã1度ã2度ããããããªããã¢ããªã¹ãã¯ãããã«ã¤ãã¦â³â³ã§åæããçµæã¨ãããã«å¯¾ããèå¯ã§ããã¨ãã£ãå ·åã§é常ã«æ£ç¢ºãªè¨èã使ç¨ããããåæãçµããã¢ããªã¹ããããããã»ãã¨ãã«ã¤ã³ããªã¸ã§ã³ã¹ã ã£ããããªï½ãã¨ããææ³ãæ¼ãããã¨ãããããæçµçã«ææ決å®è ã«ã¬ãã¼ãã£ã³ã°ããéã¯ãOSINTãã¨ãã£ãä½è£ãæ´ããæé¢ã使ç¨ãããããã£ã¼ãããã¯ãçµãã¦ããªã段éã§"ã¤ã³ããªã¸ã§ã³ã¹"ã¨ããåèªãå俵ã«åºãã®ã¯ãã¢ããªã¹ãå´ã«ã¨ã£ã¦ãåæ°ã®ããè¡åã§ã¯ãªããã¨æãããããã£ãèæ¯ããã£ã¦ããçè ã"OSINT"ã¨ããåèªãæã¡åºããã¨ã¯æ» å¤ã«ãªããæ¬å¹´çè ãJSACã«æã¡åºããè¬æ¼ã®ã¿ã¤ãã«ã¯ãInvestigation for Continuous Cyberespionage Based on Open Source (å ¬éæ å ±ãåºã«ããæ¨çåæ»æã®èª¿æ»)ãã§ãã£ã¦ãæ å ±åéã¨ãã®åæææ³ã«ã¤ãã¦è¿°ã¹ããã¦ã¯ããããæããã¦ã¤ã³ããªã¸ã§ã³ã¹ã®å®ç¾©ãæºããã¦ãããã¨ããã¨ããã¯è¦è°è«ã§ãã£ããããããã« "OSINT" ã¨ããæé¢ã¯åå¨ãã¦ããªãã®ã§ããã*4(å é¨è³æã§ã使ç¨ãã¦ããªã)
å¿ãã¦ã¯ãããªããã¨ã ããOSINTã¯ãã£ãã¨ããå°éç¨èªã§ããããã®éã«è©³ãããªã人ã«å¯¾ãã¦ãããããããã¨æ¿«ç¨ãã¹ãè¨èã§ã¯ãªãããIf all you have is a hammer, Everything looks like a nail (ãã³ãã¼ããæã£ã¦ããªããã°ããã¹ã¦ãéã«è¦ãã)ã ãªãã¦ãã諺ã«ããã¨ããã人éã¯éå ·ãæã«ããã°ãªãã¹ãããã使ã£ã¦ã¿ãããªãããæ°ããè¨èãè¦ããæ¥ã«ã¯ãªãã¹ããã®è¨èã«å½ã¦ã¯ãã¦ã¿ãããªããã®ã§ãããããªããOSINTã¨ããè¨èã®ãã³ãã¼ãæã«ãã¦ããã¨ãããæã¨ãã¨ãã¦ããã¢ãã¯æããã¦æ¬å½ã«éãªã®ã ããããã¨ããæèã¯é ã®çé ã«ããã¦ããã¹ãã ãããç¹ã«ãã¤ã³ããªã¸ã§ã³ã¹ãçæããããã®åçºã®ã¢ã¯ãã£ããã£ãOSINTã¨è¡¨ç¾ãã¦ãããã®ã«ã¤ãã¦ã¯ããã£ãããã®ã¾ã¾çãæ¥æ¬èªã§è¡¨ç¾ã§ãããã®ãé常ã«å¤ãã®ã¯äºå®ã§ããããGoogleã§ããã¨ç»åæ¤ç´¢ãã¦è¦ã¤ããã, ãShodanã§ããã¨ããã¯ã¨ãªã§æ¤ç´¢ããã, ãURLhaus ããããã«ããããIoCã®ä¸è¦§ãåå¾ããããªã©ã§ããããã¡ãã®ã»ããç解ããããããOSINTè¦å¯ã«çªã£è¾¼ã¾ãããã¨ããªããªãã ãããç¹ã«å ¬çãªå ´ã§ã¯ãããªãä¹±ããçã¾ãªãããã«ããæ£ç¢ºãªåèªããã§ã¤ã¹ãããã¨ãæ¨å¥¨ãããã
æå¾ã«ãçè
ã¯æ±ºãã¦ãOSINTã¨ããåèªã俺ã®åã§ä½¿ããªãã¨ä¸»å¼µãããããã§ã¯ãªããã¨ãè£è¶³ãã¦ãããçè
ãä¼ãããã®ã¯ãOSINTã¨ããã®ã¯ããã¾ã§ä¸è¬äººãç´æçã«ç解ãããã¨ãé£ãã"å°éç¨èª"ã§ãããã¨ãå¿ãã¦ã¯ãããªããã¨ãããã¨ã§ãããã¤ã³ããªã¸ã§ã³ã¹ã¢ããªã¹ãããã³ãã¼ãåããæå³ã¯å
¨ããªãã
çè
ãããç´è¿1ãæåã®ãå
¬éæ
å ±ããã¨ã«èª¿æ»ããæµå¯¾å½ã«é¢ããå½éæ
å¢ã¨ãµã¤ãã¼ç©ºéä¸ã§ã®åååæãããã³èªç¤¾ã®å¯¾å¿ã«ããããæè¨æ¸ã§ããã¨è¨ããããããªãã®ãã¨??ãã¨é ã«ã¯ã¨ã¹ãã§ã³ãã¼ã¯ãæµ®ãã¶ãããMonthly OSINT Reportãã¨è¨ãããã°ããã¼ããã¨ãã£ãå¿æã¡ã§ææ¸ã«ç®ãéããã¨ãã§ããã話ãæã¨èãæã«ç¨èªã¸ã®å
±éç解ãããã°ãã¾ã©ãã£ãããè¨ãåããããæãã«è¡¨ç¾ã§ãã便å©ãªåèªã§ãããã¨ã¯æºãããªãäºå®ã§ããã
ãããã«
ããã¾ã§OSINTã«ã¤ãã¦è«ãã¦ãã¦æå¾ã®æå¾ã«ã¯ãããå¤ãã®ãç³ã訳ãªãããçè ã¯"OSINT"ã¨ããåèªãåç主義çãªã¾ã§ã«æ£ãã使ãã¹ãã ã¨ã¯æã£ã¦ããªããã究極çãªã¨ããé°å²æ°ã§ä½¿ã£ã¦ãã人ããã¦ãå¥ã«ããã¨ãæã£ã¦ããã è¦ã¯"OSINT"ã¨ããåèªã®åå¨ã«ãã£ã¦è¨èªã³ãã¥ãã±ã¼ã·ã§ã³ãåæ»ã«ãªãããªããã¤ä½¿ç¨è ãæå±ãã¦ããã¤ã³ããªã¸ã§ã³ã¹ãã¼ã ãçµç¹ã«å¯¾ãã¦ä¾¡å¤ã®ããã¢ã¦ãããããåºãç¶ãããããããã°ããã§ããã®ã ãShodanã§ã®èª¿æ»çµæããç´ æ´ãããOSINTã§ãã!ãã¨CIOãCISOãã³ã¡ã³ããããã¨ã«å¯¾ãã¦ãããããããªã³ã©ã¤ã³ãµã¼ãã¹ãå©ç¨ãã調æ»èªä½ã¯OSINTã¨ã¯è¨ããã®ã§ãã!ãã¨è§ãç«ã¤ãã¨ãè¨ããªãã¦ãã"ããç¨åº¦ã¾ã§ã¯ã¿ããªã«å ±é"ãããã®ãä¼ãã£ã¦ããã°ããã§ããã¨ããæãã
ãããããã¯ãã¼ã«ã«ã«éããç°å¢ã§ã®è©±ã§ãã£ã¦ããã®ããªãä¸éä¸è¬ã«å¯¾ãã¦æã¡åºãã¨é端ã«ã³ãã¥ãã±ã¼ã·ã§ã³ã®ãã¹ãçè
ã®ãããªOSINTè¦å¯ã®çºç¾ã«ã¤ãªãããã¨ã ããããªããªããããªãã®æ³åãã¦ãã"OSINT"ã¨ãå¥ã®èª°ããç¥ã£ã¦ãã"OSINT"ã¯ä¼¼ã¦éãªãã¢ããããããªãããã ããA Nice Derangement of Epitaphs (å¢ç¢éã®ãã¦ããªä¹±ã)ãã"ç°åã®ãã¦ããªè¨ãåã"ã¨ãèãæããã¦ããªä¹±ãã«ãã£ã¦è§£éãã¦ãããä¿è¨¼ã¯ã©ãã«ããªãã®ã§ããã
ãµã¤ãã¼ã»ãã¥ãªãã£ã®æèã§"ã¤ã³ããªã¸ã§ã³ã¹"ã¨ããå°éç¨èªãæã¡åºãå ´åãæããã¦ãããæãé©ãã表ç¾ã§ãããã¨ããã®ã¯ä½¿ç¨è
å´ãä»ä¸åº¦èããã»ãããããããããªãã
ããããã°ãçè
ãã©ããªãã¨ããã¦ãã人éãªã®ã話ãã®ã失念ãã¦ãã¾ããããèªçµç¹ã«å¯¾ããè
å¨ã®èª¿æ»ãããã«é¢é£ããã·ã°ããã£ä½æããã³èå¼±æ§ã®PoCæ¤è¨¼ã¨ãã£ãã»ãã¥ãªãã£æè¡ã»éç¨æ¯æ´ãã¨è¡¨ç¾ããã«ã¯è¦ç¹ããã¯ãããããããå¤è§çè¦ç¹ããã®åæã«ãããä¸é·æçãªã»ãã¥ãªãã£æ½çããã³ææ決å®æ¯æ´ãã¨èªã£ã¦ãã¾ãã¨æ½è±¡çããã¦ä½ãä¼ããã¾ãããããããã ããè
å¨ã¤ã³ããªã¸ã§ã³ã¹ããã£ã¦ã¾ãã¨è¡¨ç¾ããã®ãä¸çªãã£ãããã¾ãããã
......ããã¾ã§ã®é§æã«ä»ãåã£ã¦ããã ããããã¨ããããã¾ããã
*1:ãJoint Publication 2-0: Joint Intelligenceã, https://irp.fas.org/doddir/dod/jp2_0.pdf
*2:ããããã»ã¹ãè½åé¨åã®å 容ããã¸ã¥ã¢ã«ã«ç¢ºèªãããæ¹ãããã£ãããã°ããThe Sliding Scale of Cyber Securityãã¨ããWhitepaperãåèã«ãã¦ããã ãããã
*3:https://elaws.e-gov.go.jp/document?lawid=411AC0000000128
*4:ã¡ãªã¿ã«ãåãããã«JSACã«ã¦è¬æ¼ãè¡ã£ãç¬æ²»å±±ããã«ã¤ãã¦ããã¿ã¤ãã«ã¯「公開情報により攻撃動向の予測を行う新たな試みと調査手法の共有」ã§ãããOSINT ã¨ããåèªã¯abstractä¸ã«ãç¨ãããã¦ããªãã£ãã