SSVCãåèã«ããèå¼±æ§ç®¡çã«ã¤ãã¦æ¬æ°åºãã¦èãã¦ã¿ã¦ããï¼é²è¡ä¸ï¼
ã¯ããã«
ããæè¿èå¼±æ§ç®¡çã«ã¤ãã¦ãã£ã¨èãã¦ããã®ã§ãããSSVCãç¥ã£ã¦ããã¨ãããã®ãããªãã·ã³ãã«ã«èããããããã«ãªãã¾ããã試ã¿èªä½ã¯ã¾ã éä¸ãªã®ã§ããã以ä¸ã®ãããªãã¨ãç®çã¨ãã¦ãSSVCã®æ¦è¦ããç¾æç¹ã§ã®çµéãç§ã®èããæåã«èµ·ããã¦ã¿ã¾ãã
- ã¢ã¤ãã¢ãæ´çããã
- èå¼±æ§ç®¡çã»éç¨ã«æ©ãã§ãã人ã¨å·ãèãåããã
- ããããã°æèè ã®ç®ã«æ¢ã¾ã£ã¦ãæè¦ãè³ãããï¼è¾è¾£ãªã®ã¯ã¤ã¤ï¼
SSVCã¨ã¯ï¼
Stakeholder-Specific Vulnerability Categolizationã®ç¥ãCERT/CCãèæ¡ããèå¼±æ§ç®¡çææ³ã§ããCVSSããèå¼±æ§ã®è©ä¾¡ææ³ãã§ãããã¨ã«å¯¾ãã¦ãSSVCã¯ãèå¼±æ§å¯¾å¿æ¹éã®å¤æææ³ãã§ããã¨è¨ãã¾ãã
ãã¶ãä»ä¸çªåããããã解説ãã¼ã¸ãPWCã ããã ãï¼
å®éã®è³æã¯ãCERT/CCã®GitHubãªãã¸ããªå ã«ãããã¡ã¤ã«åã«æ¥ä»ãéã£ã¦ããPDFã®ãã¡ãä¸çªæ°ããã®ãè¦ãã¨ããã¨æãã¾ãã
ï¼2022-12-24追è¨ï¼ OSSèå¼±æ§ç®¡ç製åã§ãããFutureVulsãã®éçºå ãSSVCã®å訳ãå ¬éãã¦ããã¦ãã¾ãããããããðåæãå²ã¨å¹³æãªè¡¨ç¾ã§æ¸ããã¦ããã¨æãã¾ãããè±èªã«æµæãããæ¹ãæéããªãæ¹ã¯ãã¡ãããããããã¾ãã
FutureVulsã¯ãã¶ãä¸çã§åãã¦ãããã¦ãã¶ãç¾å¨ä¸çã§å¯ä¸ã®SSVCã«ããèå¼±æ§è©ä¾¡ãå®è£ ãã鬼ðãªè£½åãªã®ã§ãèå¼±æ§ã¨ãããã¾ããåãããªã¼ãã¨ããæ¹ã¯ãä¸åº¦ãã©ã¤ã¢ã«ãã¦ã¿ãã¨ãã®ã§ã¯ãªããã¨ã
ããããèå¼±æ§å¯¾å¿æ¹éã®å¤æï¼n=1ï¼
ç§ã®èå¼±æ§æ å ±åéããå¯¾å¿æ¹é夿ã¾ã§ã®ããã¼ã¯ãã ããããããªæãã§ãã
- JPCERT/CCã®æ³¨æåèµ·ãTwitterã§é¨ããã¦ããèå¼±æ§æ
å ±ããã£ãããã
- ãã®æç¹ã§æããã«ã¢ãã¢ããªãã¨ãããâå³å¯¾å¿
- CVSSã®åºæºå¤ã¨AVãè¦ã¦ã大ä½ã®ã¢ããï¼=ç²¾èªãããã©ããï¼ã夿ãã
- AVã¯Nã ã£ããæ¿ã¢ããLãPã ã£ããã²ã¨ã¾ãå®å¿ãã¡ããï¼ãããªãï¼
- ACãCãIãAããããè¦ã¦ãæçµçãªæ¹éãæ±ºãã
- ãcve-xxxx-xxxxx pocãã§ã°ã°ã£ã¦ã¿ã
- ãsite:github.comããä»ããå ´åããã
人åãã¤å¤æåºæºãæããã§ãªãã¨ããããå±äººåãæãç¹ãèª¬ææ§ãä½ãã¨ããç¹ã§ãããªãã¨æã£ã¦ãã¾ããã§ããã£ã¨å¤ãã®æ¹ããããªããã ã¨æããã§ãããâ¦â¦ã¡ããï¼
CVSSãå ¨ã¦ãããªããã
CVSSã¯èå¼±æ§è©ä¾¡ææ³ã¨ãã¦ããæ´çããã¦ãã¦ããæããªã®ã§ãããå¤æåºæºãææ§ã¨ããç¾ç¶è©ä¾¡åºæºã®è©ä¾¡ãããã¾ãããã¦ããªãã¨ããã·ããã¨ããããã£ãããã¾ããç¹ã«ç¾ç¶è©ä¾¡åºæºãéç¨ããã¦ããªãã¨ããã®ã¯ãæ¨ä»ã®è å¨ãã¼ã¹ã¢ããã¼ããã¼ã ã¨çç¾ãã¦ã¾ãããï¼ä½ãªãããä¸ä½ã
â¦â¦ãè å¨ã¤ã³ããªã¸ã§ã³ã¹ã®æç§æ¸ããæèªãã¦ããã¨ãããã®ãã¯ã«è å¨ã¤ã³ããªå¨ãªããã§ã¤ãã£ã¦ãã¾ãã¾ãããããã£ã¨æ¥çã®å éã«ã¨ã£ã¦ãè å¨ãã¼ã¹ã®èãæ¹ã¯æ¨æ¥ä»æ¥å§ã¾ã£ããã®ã§ã¯ããã¾ããããããè å¨ã¤ã³ããªã¸ã§ã³ã¹ã®æç§æ¸ãããã¡ãããæ¬ãªã®ã§èªãã§æ¬²ããã§ãã
SSVCã®ã³ã³ããããï¼
ããã§èå¼±æ§ç®¡ççã®ã¸ã£ã³ãã»ãã«ã¯ãã¨SSVCã®ç»å ´ã§ããSSVCã®æ¨ããã¤ã³ããåæãã¾ãã
ã¢ã¦ãããããå ·ä½çãªã¢ã¯ã·ã§ã³ã§ãã
CVSSã®ã¢ã¦ãããããã¹ã³ã¢ãå屿§ã®è©ä¾¡ã§ãããã¨ã«å¯¾ãã¦ãSSVCã®ã¢ã¦ããããã¯èå¼±æ§ã«å¯¾ããã¢ã¯ã·ã§ã³ã§ããå ·ä½çã«ã¯ä»¥ä¸ã®4éãã
- deferï¼é観ï¼
- scheduledï¼è¨ç»å¯¾å¿ï¼
- out-of-cycleï¼è¨ç»å¤å¯¾å¿ï¼
- Immediateï¼ç·æ¥å¯¾å¿ï¼
ã¢ã¯ã·ã§ã³ã®å¤æåºæºãæç¢ºã«æç¤ºãã¦ãã
SSVCã¯ãã¢ã¯ã·ã§ã³ãå°ãåºãã¾ã§ã«ã©ããã£ã夿ææãããã®ããæç¤ºãã¦ããã¦ãã¾ããæã ã®ãããªããããå½ã¦ãç«å ´ãSSVCã§ããDeployerã®å ´åã¯ã以ä¸ã®4ã¤ã§ããããããã3ã4段éã®åé¡ãæã¡ã¾ãã
- Exploitationï¼èå¼±æ§ã®æªç¨å®ç¸¾ãPoCã®å ¬éç¶æ³ãã©ã®ç¨åº¦ãï¼
- Exposureï¼ã·ã¹ãã ã®å ¬é度åãã¯ã©ã®ç¨åº¦ãï¼
- Utilityï¼èå¼±æ§ã®æç¨æ§=æªç¨ã«ãã£ã¦å¾ããã対価 * æªç¨ï¼èªååï¼ã®ããããï¼
- Well-being and Mission Impactï¼æªç¨ãããæã®ã¤ã³ãã¯ãï¼
Deployerã®å¤ææ¨ãè¦ã¦ã¿ã¾ãããï¼ææ°ã®è³æã§ã¯PDF35ãã¼ã¸ç®ï¼ãè¦ã¦ãããã¨ãããéãã4ã¤ã®è³ªåã«çããçµæã¯äºãããããããã¦ãã¾ããè¦ããã«ããExploitationã¯ï¼ããExposureã¯ï¼ããUtilityã¯ï¼ããHuman-being and misson impactã¯ï¼ãã¨ãã4ã¤ã®åãã«çãããã¨ã§ãããã®èå¼±æ§ã«ã©ã対å¿ãã¹ããï¼ãã¨ããåãã®çããå°ãããããã§ãã
ããæ¶ç©ºã®èå¼±æ§ã®å¯¾å¿æ¹éãSSVCã«æ²¿ã£ã¦ãã£ã¦ã¿ãã¨ããããªæãã§ãã
- 調ã¹ããGitHubã«ã¨ã¯ã¹ããã¤ããå
¬éããã¦ããããã®ã¾ã¾æªç¨ã«è»¢ç¨ã§ããã
- âExploitation = active
- 対象ã·ã¹ãã ã¯ã¤ã³ã¿ã¼ãããããéé¢ããã¦ãã
- âExposure = small
- æªç¨ããããæ©å¯æ
å ±æãããããèªååã容æãã
- âUtility = super effective
- æªç¨ãããããã¸ã§ã¨ã°ã
- âWell-being and Mission Impact = very high
çµæã¯out-of-cycleããåªå 度ãä¸ãã¦è¨ç»å¤å¯¾å¿ããããï¼ãã¨ãããã¨ã«ãªãã¾ãã
ãã®ãã¨ã«ã¯ã以ä¸ã®ãããªã¡ãªãããããã¾ãã
- å¤æåºæºãçµç·¯ã®èª¬æããããã
- æçµçãªå¯¾å¿å¤æãããããæ¸ã¿ã§ãã
- ä¸çªè¿·ãã¨ããï¼æ±ºãã®åé¡ãã¨ããè¨ãããé¨åï¼ãèããªãã¦ãã
- ãã£ã¦ã¿ã¦éããªããããã°ãã
- å®ç¶ã¨ä¹é¢ããçµæãåºãå ´åã«ã調æ´ãããã
ã¤ãã§ã«ããããã®å¤æåºæºã¯ãèå¼±æ§ã«é¢ããè¤æ°ã®ç«å ´ã«å¯¾ãã¦ç°ãªããã®ãæç¤ºããã¦ãã¾ãã
- Supplierï¼ããããä½ã人ãã¡ã¼ã«ã¼ï¼
- Deployerï¼ããããå½ã¦ã人ãå©ç¨è ï¼
- Coodinatorï¼â¦â¦èª°ï¼ï¼
ããã¾ã§ã®ã¾ã¨ã: SSVCã¯é¢æ°ãCVSSã¯å¼æ°
åè¿°ã®éããCVSSã¯ããã¾ã§ãèå¼±æ§ã®è©ä¾¡ææ³ãã§ãã£ã¦ãããããå¯¾å¿æ¹éãå°ãåºãããã®å¤æåºæºã¯ãã»ãã¥ãªãã£æ å½è ãç¨æããªããã°ãªãã¾ããã§ãããSSVCã¯ã¾ãã«ãã®åºæºã«ãªãããã§ããCVSSãã¯ããã¨ããèå¼±æ§æ å ±ã弿°ãSSVCã颿°ã®é¢ä¿ã«ããããããã¨çè§£ããããã§ããããç§ã¯æã£ã¦ãããã§ãããå³ã«ããã¨é端ã«é³è ã«ãªãã®ãªããªã®ï¼
éç¨ããããã«å¿ è¦ãªãã¨
æå¾ã«ãSSVCãéç¨ãã¦ããããã«ãããªããã°ãªããªããããªãã¨ãåæãã¾ãã
actionæ¯ã®å ·ä½çãªå¯¾å¿æéãæ±ºãã
ã¾ãã¯scheduledãã¤ã¾ãèå¼±æ§ã®è¨ç»å¯¾å¿ã¯ã©ããããã®æéæ¯ã«ããã®ããæ±ºã¾ã£ã¦ããªãã¨ãè¨ç»ãè¨ç»å¤ãç·æ¥ããªãã®ã§ããããã°ããã¯æ±ºããããããã¾ãããæ±ºãã¾ãããã
夿ãã¤ã³ãã®å¤æåºæºã決ãã
Exposureã¯ï¼controlledã®å¤æã¯è¿·ãã¨ããã§ããï¼ã»ã¼èªãã¨æ±ºã¾ãã®ã§ç½®ãã¦ããã¨ãã¦ãExploitationãUtilityãWell-being and Mission Impactãä½ã«åºã¥ãã¦æ±ºããããæ±ºããªããã°ãªãã¾ããã
åèã«ã¯ãSSVC using Current Information Sourcesãã¨ããç¯ãããã¾ãã¦ãè¦ããã«ãå夿ãã¤ã³ãã«ããã夿ææã¨ãã¦ãæ¢åã®æ å ±æºãä¸å®æç¨ã§ãããã¨ãã£ããããªãã¨ãæ¸ãã¦ããã¾ããå人çã«ãããªæãã§ããããããªãã¨ããã®ãæ¸ãã¦ããã®ã§åèã¾ã§ã
Exploitation
Exploitationã®è©ä¾¡ã¯active > poc > noneã§ãèå¼±æ§ãã¼ã¿ãã¼ã¹ãä¸»ãªæ å ±æºã§ããå人çã«ã¯ããã§ã®è©ä¾¡ãæãéè¦ã ã¨æã£ã¦ãã¾ãã
- GitHubãExploit-DBãVulnDBãè¦ã¦ã¿ã
- åãªãPoCã«çã¾ããªãpoc
- å³ã»æªã»ç¨ãªæããªãactive
- JPCERT/CCã®æ³¨æåèµ·ã§ãæ¢ã«æªç¨ã観測ããã¦ãããªãactive
- CISAã®Known Exploited Vulnerability Catalogã«è¼ã£ã¦ãããactive
Utility
Utility㯠Automatableï¼èªååã§ãããï¼ã¨Value Densityï¼å¾ããã対価ï¼ã§æ±ºã¾ãã¾ããAutomatableã«ã¤ãã¦ã¯CVSSã®ACãUIãåèã«ãã¦ãããã§ãããã³ã¼ããããã¨ãããã¨ãä¸å®èªååã®ä½å°ãããã¨è§£éãã¦ãExploitationã®å¤æçµæãæµç¨ãã¦ãããã¨æãã¾ããValue Densityã¯ãCVSSã®CIAãåèã«ããã¨ããã®ã§ã¯ãªãã§ããããã
Well-being and Mission Impact
CVSSã®CIAãããããã ã¨æã£ã¦ãã¾ãã
夿ãèªååãã
å ¨èå¼±æ§ããã®ã¯ã½ãã«å¤ææ¨ãè¦ãªããããªã¢ã¼ã¸ããã®ã¯ãã£ã¨ããã©ãã®ã§ãã³ã¼ãã«ã«ã¼ã«ãã¼ã¹ã§å¤æããã¦ãæåã®ãã¡ã¯äººéãç®æ¤ãã¦éå°è©ä¾¡ã»é大è©ä¾¡ãèµ·ãã¦ããªããã確èªããªãã調æ´ãã¦ããå¿ è¦ãããããã§ããèªååããããã«ã¯ãã夿ãã¤ã³ãã®å¤æåºæºã決ãããã§ãããç¨åº¦èªååãè¦è¶ããåºæºãå®ããªãããªããªãã§ããã
ã¾ããPoCã®å ¬éã®ãããªç¶æ³ã®æ´æ°ã«ä¼´ã夿ã®ãç´ãããèæ ®ã«å ¥ããªããã°ãªãã¾ãããããã«ã¤ãã¦ãã宿çãªèå¼±æ§æ å ±ã®æ´æ°ãããã³ç¶æ³ã®å¤åãããªã¬ã¼ã¨ããåè©ä¾¡ã¾ã§ãèªåã§è¡ããã¦ã»ããã§ãã
ãããã«: 調æ´ãã
ã¨ããããæ±ºãã¦ãåãã¦ã¿ã¦ããã¾ããããªããã°èª¿æ´ãã¾ãããã調æ´ããããã¨ããã®ãSSVCã®ããã¨ããã§ãããï¼èªæï¼ã