ãç·æ¥ã¬ãã¼ããKRACKsï¼key reinstallation attacksï¼éµåã¤ã³ã¹ãã¼ã«æ»æï¼ã«ã¤ãã¦
2017/10/19 åç
IL-CSIRT
ã¯ããã«
2017å¹´10æ16æ¥ããã«ã®ã¼ã®ç 究è
ã§ããMathy Vanhoefæ°ããç¡ç·LAN(以ä¸ãWi-Fi)ã®èªè¨¼ãããã³ã«ã«è¤æ°ã®èå¼±æ§ããããã¨ãWebãµã¤ã(https://www.krackattacks.com/)ã§å
¬è¡¨ãã¾ããã
Vanhoefæ°ã¯ããããä¸é£ã®èå¼±æ§ããã³æ»æææ³ã®è©³ç´°ãã2017å¹´12æã«ã¤ã®ãªã¹ã§éå¬ãããBlack Hat Europe 2017ã§æããã«ããã¨ãã¦ãã¾ãã
æ¬ã¬ãã¼ãã¯ã2017å¹´10æ18æ¥æç¹ã§æããã«ãªã£ã¦ããæ
å ±ã«åºã¥ããæ³å®ãããè
å¨ã¨ç¾å¨èãããã対çã«ã¤ãã¦ãIL-CSIRTã®è¦è§£ã示ããã®ã§ãã
1. KRACKs
Mathy Vanhoefæ°ãå ¬è¡¨ããä¸é£ã®èå¼±æ§ã¯ãWi-Fiã®èªè¨¼ãããã³ã«ã§ããWPA/WPA2ã®ã4-way handshakeããªã©ã®ä»æ§ã«èµ·å ãããã®ã§ãã Mathy Vanhoefæ°ã¯ããããã®èå¼±æ§ãã¤ãæ»æææ³ãKRACKsï¼Key Reinstallation AttaCKsï¼ã¨åä»ãã¾ããã
çµç·¯
å¹´ææ¥ | 詳細 |
---|---|
2017.5.19 | Vanhoefæ°ããç 究è«æãæåºããã |
2017.7é | Vanhoefæ°ããç±³CERT/CCã«èå¼±æ§ã®æ å ±ãé示ããã |
2017.8.28 | ç±³CERT/CCããè¤æ°ã®éçºãã³ãã¼ã«éç¥ãåºããã éçºãã³ãã¼ã«ããã»ãã¥ãªãã£ãããã®éçºãã¹ã¿ã¼ã |
2017.10.6 | Blackhatã®ãµã¤ãã«ã¦WPA2ã®èå¼±æ§ã«é¢ããçºè¡¨ãããæ¨å ¬éããã |
2017.10.16 | WPA2ã®èå¼±æ§(KRACKs)ã«é¢ãã¦æ å ±ãå ¬éããã |
2017.12.4ï½7 | Black Hat Europe 2017ã§KRACKsã®è©³ç´°æ å ±ãå ¬éãããäºå® |
KRACKsãããããè å¨
æ»æè ããèå¼±æ§ã®ããWi-Fiãããã¯ã¼ã¯ã®é»æ³¢ãåä¿¡ã§ããå ´åãKRACKsã®æ»æææ³ã使ã£ã¦WPA/WPA2ãããã³ã«ã®æå·åã解èªãã¦Wi-Fiã®éä¿¡å 容ã復å·ã»çè´ãããã¨ãå¯è½ã¨ãªãã¾ãã
æ»æã®ã¤ã¡ã¼ã¸
â» æ»æè ã復å·ã»çè´ã§ããéä¿¡ã¯ããã¾ã§ãæå·åãããWi-Fiã®éä¿¡ãã§ããå©ç¨è ãããµã¼ãã¼ã¾ã§ã®çµè·¯ãSSLãVPNãªã©ã§æå·åããã¦ããã°ãWebãµã¤ãé²è¦§ãªã©ã®ãã¼ã¿ãKRACKsã«ãã£ã¦ç´æ¥çã¿è¦ããããã¨ã¯ããã¾ããã
ãåèãWPA2ãWPAã¨WEP
WPA2ã¯ãIEEEãçå®ããWi-Fiã®èªè¨¼ãããã³ã«ã®å®è£
ã®ä¸ã¤ã§ãWi-Fiãããã¯ã¼ã¯ãè¨ç½®ããéã«åºãæ¡ç¨ããã¦ãã¾ããWPA2ã¯WPAãWEPã¨ãã£ãä»ã®èªè¨¼ãããã³ã«ãããå
åºãªãããä¸è¬çã«WPA2ãæ¡ç¨ãããã¨ãæ¨å¥¨ããã¦ãã¾ãã
WEPã¯KRACKsã®æ»æ対象å¤ã§ãããWEPã¯æ¢ã«ç ´ãã解èªå¯è½ãªèªè¨¼ãããã³ã«ã§ãããããKRACKs対çã¨ãã¦WEPãæ¡ç¨ãã¹ãã§ã¯ããã¾ããã
â» æ¬ã¬ãã¼ãã§ã¯ãä¸è¬å®¶åºãå°è¦æ¨¡ãªä¼æ¥ãªã©ã®Wi-Fiãããã¯ã¼ã¯ã§ä½¿ç¨ãããWPA2-Personalï¼WPA2-PSKï¼ãæ³å®ãã¦è¨è¿°ãã¦ãã¾ãã
2. èå¼±æ§æ¦è¦
対象æ©å¨
- WPA/WPA2ããµãã¼ããããã¹ã¦ã®Wi-Fiæ©å¨
- ã»WPA/WPA2ã®ä»æ§ã«é¢ããèå¼±æ§ã¨ãªããç¹å®ã®æ©å¨ãOSã»ã½ããã¦ã§ã¢ã«éããåºç¯å²ã«å½±é¿ãåã³ã¾ãã
- ã»ä¸»ã«å½±é¿ãåãã対象ã¯ã¯ã©ã¤ã¢ã³ãå´ã¨ããã¦ãã¾ãããAPå´ãå½±é¿ãåããå¯è½æ§ãããã¾ãã
çã¿è¦ãããæ å ±
- ã¯ã©ã¤ã¢ã³ã⇔APã§é»æ³¢ã使ã£ã¦éä¿¡ããéã®å¹³ææ å ±
- ã»ã¯ã©ã¤ã¢ã³ã⇔APéã§é»æ³¢ã使ã£ã¦éä¿¡ããéã®æå·ã解èªããããã¨ã«ãããHTTPéä¿¡ãªã©å¹³æã§æ å ±ãåã渡ãã¦ããå ´åãæ»æè ã«éä¿¡ã®å 容ãçã¿è¦ãããå¯è½æ§ãããã¾ãã
- ã»SSLéä¿¡ãVPNã使ç¨ãã¦ããå ´åãæ¬èå¼±æ§ã®ã¿ã§éä¿¡ã®å 容ãçã¿è¦ããããã¨ã¯ããã¾ããã
æªç¨ã®ããã®æ¡ä»¶
- æ»æè ãé»æ³¢ã®å±ãç¯å²ã«ã¢ã¯ã»ã¹å¯è½
- ã»é»æ³¢ã®å±ãç¯å²ã§ã®ã¿å©ç¨å¯è½ãªèå¼±æ§ã¨ãªãã¾ãã
-
- â» ç¡ç·ä»¥å¤ã®ãããã¯ã¼ã¯çµç±ã§æ»æããããã¨ã¯ããã¾ããã
- â» ç¾ç¶æããã«ãªã£ã¦ãã¾ããããä¸éè æ»æãè¡ãå ´åã¯ã¯ã©ã¤ã¢ã³ããAP両æ¹ã®é»æ³¢ã®å±ãç¯å²ã«ããå¿ è¦ãããã¨æ¨æ¸¬ããã¾ãã
èå¼±æ§æªç¨ããã¼ (4-Way HandShakeã®å ´åã®æªç¨)
3. 対象CVE
KRACKsé¢é£ã®èå¼±æ§ä¸è¦§
CVEçªå· | CVSS(Ver3.0) | æ¦è¦ | |
---|---|---|---|
Base | Temp | ||
CVE-2017-13077 | 6.8 | - | 4way Handshakeã«ããããã¢æå·éµ(PTK-TK)ã®åã¤ã³ã¹ãã¼ã« |
CVE-2017-13078 | - | - | 4way Handshakeã§ã®ã°ã«ã¼ãéµ(GTK)ã®åã¤ã³ã¹ãã¼ã« |
CVE-2017-13079 | - | - | 4way Handshakeã«ãããæ´åæ§ã°ã«ã¼ãéµ(IGTK)ã®åã¤ã³ã¹ãã¼ã« |
CVE-2017-13080 | - | - | Group Key Handshakeã«ãããã°ã«ã¼ãéµ(GTK)ã®åã¤ã³ã¹ãã¼ã« |
CVE-2017-13081 | - | - | Group Key Handshakeã«ãããæ´åæ§ã°ã«ã¼ãéµ(IGTK)ã®åã¤ã³ã¹ãã¼ã« |
CVE-2017-13082 | - | - | åéãããFast BSS Transition Reassociation Requestã®åãå ¥ãã¨ããã®å¦çã«ããããã¢æå·éµ(PTK-TK)ã®åã¤ã³ã¹ãã¼ã« |
CVE-2017-13084 | - | - | PeerKey Handshakeã«ãããSTKéµã®åã¤ã³ã¹ãã¼ã« |
CVE-2017-13086 | - | - | TDLS Handshakeã«ãããTunneled Direct-Link Setup(TDLS)PeerKey(TPK)ã®åã¤ã³ã¹ãã¼ã« |
CVE-2017-13087 | - | - | ã¯ã¤ã¤ã¬ã¹ãããã¯ã¼ã¯ç®¡ç(WNM)ã¹ãªã¼ãã¢ã¼ãã¬ã¹ãã³ã¹ãã¬ã¼ã ãå¦çããéã®ã°ã«ã¼ãéµ(GTK)ã®åã¤ã³ã¹ãã¼ã« |
CVE-2017-13088 | - | - | ã¯ã¤ã¤ã¬ã¹ãããã¯ã¼ã¯ç®¡ç(WNM)ã¹ãªã¼ãã¢ã¼ãã¬ã¹ãã³ã¹ãã¬ã¼ã ãå¦çããéã®æ´åæ§ã°ã«ã¼ãéµ(IGTK)ã®åã¤ã³ã¹ãã¼ã« |
- â»ã-ã表è¨ã¨ãªã£ã¦ããç®æã¯2017.10.18ç¾å¨éå ¬é
4. ç¾ç¶èãããã対ç
2017å¹´ï¼æé ããæ¬èå¼±æ§ã«é¢ããæ å ±ãé示ãããæ¬ã¬ãã¼ãå ¬éæç¹ã§éçºãã³ãã¼å社ãããããã®ä½æãé ä¿¡ãéå§ããã¦ãã¾ãããã ãæ¬èå¼±æ§ã¯WPA/WPA2ã®ä»æ§ä¸ã®èå¼±æ§ã§ãããWPA/WPA2ããµãã¼ããããã¹ã¦ã®æ©å¨ãå½±é¿ãåããããã対çãè¡ãå±ãã¾ã§ã«ã¯ç¸å½ã®æéãè¦ãããã¨ãäºæ³ããã¾ãã
対çæ¹æ³
- OS/æ©å¨ãã³ãã¼æä¾ã®ãããé©ç¨/ãã¼ã¸ã§ã³ã¢ãããè¡ã
- ã»ä¸»ã«ã¯ã©ã¤ã¢ã³ãå´ã®ãããããªãªã¼ã¹ããã¦ãã¾ãã
- ã»ä¸é¨ã®Wi-Fiä¸ç¶æ©å¨ã®ããã«APã§ãã£ã¦ãã¯ã©ã¤ã¢ã³ãã¨ãã¦ãåä½ãããã®ããã¼ãã³ã°ã®ãããã³ã«ã§ãã802.11rã«å¯¾å¿ãã¦ããæ©å¨ã¯ããã®æ©è½ã®åæ¢ããããé©ç¨ãå¿ è¦ã§ãã
- ã»OSããã©ã¤ãã«ä¾åããããããã»ããã®æ©è½ã ãã§éä¿¡ãã§ããæ©è½ãæã¤è£½åã«ã¤ãã¦ã¯ãã¡ã¼ã ã¦ã§ã¢ã®æ´æ°ãå¿ è¦ãªå ´åãããã¾ãã
- VPNãSSLãªã©éä¿¡ã®æå·åãè¡ãçè´ãé²ã
- ã»é»æ³¢ã使ã£ã¦éä¿¡ãã¦ããéã®æå·ã解èªãããã ãã§ããã®ä¸èº«ã§ããã¯ã©ã¤ã¢ã³ã⇔ãµã¼ãã¼éã®æå·ãããã«è§£èªã§ããããã§ã¯ããã¾ããã
- ã»ä¸è¬çãªå ¬è¡Wi-Fiå©ç¨æã¨åãã¬ãã«ã§æ å ±ã»ãã¥ãªãã£ã«æ°ãé ã£ã¦ãããã¨ã§ãå¤ãã®å±éºãåé¿ã§ãã¾ãã
- é»æ³¢ã®å±ãç¯å²ãæå°éã¨ãã
- ã»é»æ³¢ã®å±ãç¯å²ã§ã®ã¿å©ç¨å¯è½ãªèå¼±æ§ã®ãããåºå調æ´ãªã©ãå¯è½ãªæ©å¨ã§ã¯é»æ³¢ã®å°éç¯å²ããå¿ è¦æå°éã«ããããç©ççã«ã¢ã¯ã»ã¹ãå¶éã§ããç¯å²ã«éãããªã©ã®ææ³ãä½µç¨ãã¦ãªã¹ã¯ãä½æ¸ãã¦ãã ããã
注æ
- èå¼±æ§å¯¾çãè¡ããªãç¶æ ã§ãã£ã¦ãWEPããã¯ã»ãã¥ã¢ã§ãããããWPA/WPA2ã®ä½¿ç¨ãç¶ç¶ãããã¨ãæ¨å¥¨ãã¾ãã
- 詳細ãå ¬éãããçµæãä¸éè æ»æãæ³å®ãããèå¼±æ§ã§ããã¨å¤æããå ´åãæ¥ç¶å ã®APãæ£ãããã¨ããµã¼ãã¼é¡ã®è¨¼ææ¸ãæ£è¦ã®ãã®ã§ãã確èªããã£ããè¡ããã¨ãéè¦ã¨ãªãã¾ãã
主ãªãã³ãã¼ãããé å¸ç¶æ³(2017.10.18ç¾å¨)
ãã³ãã¼ | ç¶æ³ |
---|---|
Windows | 2017.10ãããé å¸æ¸ã¿(CVE-2017-13080) |
Linux(RHEL) | 2017.10.18 ãããé å¸æ¸ã¿(RHSA-2017:2907 - Security Advisory) |
Apple(macOS, iOS) | macOS,iOS,tvOS,watchOSã®ãã¼ã¿çã§ã¯æ¢ã«èå¼±æ§ãä¿®æ£ããã¦ãããæ°é±é以å ã§ã®ãªãªã¼ã¹å¾ ã¡ |
Google(Android)â» | åé¡ãèªèãã¦ãããå½±é¿ãåããããã¤ã¹ã«å¯¾ããããããæ°é±éã®ãã¡ã«çºè¡ããäºå® |
- â» Googleã®ãããçºè¡ãããåã¡ã¼ã«ã®ç«¯æ«ã«é©åãããããé å¸éå§ã¾ã§ã¯é·æéæããå¯è½æ§ãããã¾ããæä¾å ã®éä¿¡ãã£ãªã¢ãã¡ã¼ã«ã®æ å ±ãã確èªãã ããã
æ å ±ã½ã¼ã¹
ä¸æ¬¡æ å ±
- Key Reinstallation Attacks
https://www.krackattacks.com/ - KEY REINSTALLATION ATTACKS: BREAKING THE WPA2 PROTOCOL
https://www.blackhat.com/eu-17/briefings/schedule/#key-reinstallation-attacks-breaking-the-wpa2-protocol-8861
注æåèµ·
- Vulnerability Note VU#228519 Wi-Fi Protected Access II (WPA2) handshake traffic can be manipulated to induce nonce and session key reuse
https://www.kb.cert.org/vuls/id/228519/ - JVNVU#90609033ãWi-Fi Protected Access II (WPA2) ãã³ãã·ã§ã¤ã¯ã«ãã㦠Nonce ããã³ã»ãã·ã§ã³éµãåå©ç¨ãããåé¡
https://jvn.jp/vu/JVNVU90609033/ - WPA2 ã«ãããè¤æ°ã®èå¼±æ§ã«ã¤ãã¦
https://www.ipa.go.jp/security/ciadr/vul/20171017_WPA2.html - ç¡ç·LANï¼Wi-Fiï¼æå·åã«ãããèå¼±æ§ã«ã¤ãã¦(注æåèµ·)
http://www.soumu.go.jp/menu_kyotsuu/important/kinkyu02_000274.html - Wi-Fi Alliance® security update
https://www.wi-fi.org/news-events/newsroom/wi-fi-alliance-security-update
æ¬ä»¶ã«é¢ãããåãåããå
NTTãã¼ã¿å
端æè¡æ ªå¼ä¼ç¤¾
ãåãåãããã©ã¼ã
- â» åè¦æ ¼åãä¼ç¤¾åãå£ä½åã製ååã¯ãå社ã®åæ¨ã¾ãã¯ç»é²åæ¨ã§ãã
Tweet