IoTã»ãã¥ãªãã£ã®åå½æ¯è¼ (æ¥ç±³æ¬§ã®ã¬ã¤ãã©ã¤ã³ãã) ï½ç¬¬1å IoTã®å®ç¾©ã¨ç¹å¾´
ããè¿å¹´ãIoTï¼Internet of Thingsï¼ã®å®ç¨ãæ®åã«ä¼´ããä¸çåå½ã§IoTã®æ
å ±ã»ãã¥ãªãã£ã«é¢ããã¬ã¤ãã©ã¤ã³é¡ã®çºè¡ãç¸æ¬¡ãã§ãã¾ãã
ãããããããã®å¯¾è±¡ã¨ããèªè
ã使ãæ¹ãIoTã®ç¨®é¡ãªã©ãå¤ç¨®å¤æ§ã§ããããããããã«ããã®ãå®æ
ã§ãããã®å¤§ããªåå ã¨ãã¦ãIoTã示ãç¯å²ãé常ã«åºãã¨ãããã¨ã¨ãå¾æ¥ã®æ
å ±ã»ãã¥ãªãã£ã¨ã®éããåããã«ãããã¨ãèãããã¾ãã
ããã§ã¯ãæ¥ç±³æ¬§ãããããçºè¡ãã¦ããã¬ã¤ãã©ã¤ã³é¡ã示ãã¦ããIoTã®å®ç¾©ãç¹å¾´ãããã¦IoTã®ã»ãã¥ãªãã£è
å¨ã¨å¯¾çã確èªãããã®éããè¦ã¦ããã¾ãã
åå½ã®IoTã»ãã¥ãªãã£ã«é¢ããææ¸
åå½ã®IoTã»ãã¥ãªãã£ã«é¢ããææ¸ã¯ãå¤æ°å ¬éããã¦ãã¾ããæ¯è¼çæè¿ã®ãã®ã§ã代表çãªææ¸ã¨ãã¦ã¯ä»¥ä¸ã®ãã®ãæãããã¾ããï¼2018å¹´5æç¾å¨ï¼
欧å·(EU) | ãBaseline Security Recommendations for IoT in the context of Critical Information Infrastructuresã(éè¦æ
å ±ã¤ã³ãã©ã«ãããIoTã®ãã¼ã¹ã©ã¤ã³ã»ãã¥ãªãã£ã«é¢ããæè¨ã) 2017å¹´11æ |
ã»ENISAï¼æ¬§å·ãããã¯ã¼ã¯ã»æ
å ±ã»ãã¥ãªãã£æ©é¢ï¼ãå
¬é ã»IoT ã®ã»ãã¥ãªãã£è¦ä»¶ãIoT è³ç£ãè å¨ãæ³å®ãããæ»æãã»ãã¥ãªãã£å¯¾ççã®ç¥è¦ãæä¾ãããã® ã»å½ææ¸ã® æ¥æ¬èªã«ããè¦ç´ ãIPAï¼æ å ±å¦çæ¨é²æ©æ§ï¼ãå ¬éãã¦ãã¾ã |
---|---|---|
ç±³å½ | NISTIR 8200 (DRAFT)ãInteragency Report on Status of International Cybersecurity Standardization for the Internet of Things (IoT)ã(IoTã®ããã®å½éçãªãµã¤ãã¼ã»ãã¥ãªãã£æ¨æºåã®ç¶æ³ã«é¢ããçåºéå ±å(ãã©ããç) ) 2018å¹´2æ |
ã»NISTï¼ç±³å½å½ç«æ¨æºæè¡ç 究æï¼ãå
¬é ã»IoTã»ãã¥ãªãã£ã«é¢ããæ¨æºåã®ç¶æ³ã«é¢ãã調æ»çµæãã¾ã¨ãããã® ã»ãã©ããçã®ãããå¾æ¥æ£å¼çãå ¬éäºå®ï¼2018å¹´5æç¾å¨ï¼ |
æ¥æ¬ | ãIoTéçºã«ãããã»ãã¥ãªãã£è¨è¨ã®æå¼ãã 2017å¹´12ææ´æ° |
ã»IPAãå
¬é ã»IoT ã®ã»ãã¥ãªãã£è¨è¨ã§è¡ãè å¨åæã»å¯¾çæ¤è¨ã»èå¼±æ§ã¸ã®å¯¾å¿æ¹æ³ã解説ãããã® |
ãIoTã»ãã¥ãªãã£ã¬ã¤ãã©ã¤ã³ ver1.0ã 2016å¹´7æ |
ã»ç·åçãå
¬é ã»IoT æ©å¨ãã·ã¹ãã ããµã¼ãã¹ã«å¯¾ãã¦ãªã¹ã¯ã«å¿ããé©åãªãµã¤ãã¼ã»ãã¥ãªãã£å¯¾çãæ¤è¨ããããã®èãæ¹ãã¾ã¨ãããã® |
1. IoTã®å®ç¾©
åå½ã§ã¯ãIoTãã©ã®ããã«å®ç¾©ãã¦ããã§ããããï¼åææ¸ã§ã¯ä»¥ä¸ã®ããã«è¨è¿°ããã¦ãã¾ãã
欧å·ï¼EUï¼
ãææ決å®ãå¯è½ã«ãããç¸äºæ¥ç¶ãããã»ã³ãµãã¢ã¯ãã¥ã¨ã¼ã¿ããæããµã¤ãã¼ãã£ã¸ã«ã«ã»ã¨ã³ã·ã¹ãã ãï¼"a cyber-physical ecosystem of interconnected sensors and actuators, which enable intelligent decision making"ï¼
ç±³å½
NISTã§ã¯ãIoTã¯ããããã¯ã¼ã¯åãããã¨ã³ãã£ãã£ï¼ä¾ãã°ãã»ã³ãµã¼ãã¢ã¯ãã¥ã¨ã¼ã¿ãæ
å ±è³æºã人ã
ï¼ã使ç¨ãã¦ç©ççä¸çã¨å¯¾è©±ããã·ã¹ãã ãä½æãããã¨ã«åºã¥ãã³ã³ã»ãããã¨ãã¦ãIoTã®å®ç¾©ãæ確ã«ã¯å®ãã¦ãã¾ãããææ¸ã®éå±æ¸é¨åã«ããã¤ãã®çµç¹ãå
¬éãã¦ããå®ç¾©ãç´¹ä»ããã«çãã¦ãã¾ãããã ããIoTã®ä¸»è¦ãªæ©è½ã¨ãã¦ãActuatingï¼ä½åï¼ãData Storingï¼ãã¼ã¿ä¿åï¼ãNetworkingï¼ãããã¯ã¼ã¯ï¼ãProcessingï¼å¦çï¼ãSensingï¼æç¥ï¼ã¨ç¤ºãã¦ãã¾ãã
ãªããDHSï¼ç±³å½åå®å
¨ä¿éçï¼ã«ããIoTã®å®ç¾©ã¯ä»¥ä¸ã®éãã§ãã
ã主ã«ç©ççãªç®çï¼ã»ã³ã·ã³ã°ãææ¿ï¼å·æ¿ãç
§æãé»åã¢ã¯ãã¥ã¨ã¼ã·ã§ã³ã輸éãªã©ï¼ãæã¤ã·ã¹ãã ãæ©å¨ããï¼å¤ãã®å ´åï¼çµè¾¼ã¿ã·ã¹ãã ã«çµã¿è¾¼ã¾ããç¸äºéç¨ã®ããã®ãããã³ã«ãä»ãã¦ï¼ã¤ã³ã¿ã¼ããããå«ãï¼æ
å ±ãããã¯ã¼ã¯ã¨ã¤ãªãã£ã¦ãããã¨ãï¼"to the connection of systems and devices with primarily physical purposes (e.g. sensing, heating/cooling, lighting, motor actuation, transportation) to information networks (including the Internet) via interoperable protocols, often built into embedded systems"ï¼
æ¥æ¬
æ¥æ¬ã§ã¯ãITUï¼å½éé»æ°éä¿¡é£åï¼ã®å§åï¼ITU-T Y.2060(Y.4000)ï¼ã«è¨è¼ã®ããIoTã®å®ç¾©ã®ç´¹ä»ã«çãã¦ãã¾ãã
ãæ
å ±ç¤¾ä¼ã®ããã«ãæ¢åãããã¯éçºä¸ã®ç¸äºéç¨å¯è½ãªæ
å ±éä¿¡æè¡ã«ãããç©ççãããã¯ä»®æ³çãªã¢ããæ¥ç¶ããé«åº¦ãªãµã¼ãã¹ãå®ç¾ããã°ãã¼ãã«ã¤ã³ãã©ãï¼"A global infrastructure for the information society, enabling advanced services by interconnecting (physical and virtual) things based on existing and evolving interoperable information and communication technologies"ï¼
EUã§ã¯IoTãæ確ã«å®ç¾©ãã¦ãã¾ããç±³å½ã§ã¯ã³ã³ã»ããã¨ä¸»è¦ãªæ©è½ã説æããæ¥æ¬ã¯å½éæ¨æºã®å®ç¾©ããã®ã¾ã¾ç´¹ä»ãã¦ãã¾ãã
EUã¨ç±³å½ã®ææ¸ã®è¨è¼ãè¦ãã¨ããã»ã³ãµã¼ãã»ãã¢ã¯ãã¥ã¨ã¼ã¿ãã»ãç©ççããå
±éã®ãã¼ã¯ã¼ãã¨ãªã£ã¦ããã¨èãããã¾ãã
2. IoTã®ç¹å¾´
ããã§ã¯ãåå½ã§ã¯IoTã®æã¤ç¹å¾´ã¯ã©ã®ããã«è¨è¿°ããã¦ããã®ã§ããããï¼ææ¸ã®å ·ä½çãªè¨è¿°ããè¦ã¦ããããã¨æãã¾ããï¼â»ç±³å½ã®ææ¸ã«ã¯ãIoTã®ç¹å¾´ã«é¢ããæ確ãªè¨è¼ãªãï¼
表1ï¼IoTã®ç¹å¾´ï¼åå½ã®éãï¼
No. | ç¹å¾´ | EU ãBaseline Security Recommendations for IoT in the context of Critical Information Infrastructuresã 2.2 ã»ãã¥ãªãã£ä¸ã®èæ ®äºé |
æ¥æ¬ ãIoTã»ãã¥ãªãã£ã¬ã¤ãã©ã¤ã³ã 1.1.2 IoT ç¹æã®æ§è³ªã¨ã»ãã¥ãªãã£å¯¾çã®å¿ è¦æ§ï¼æ«å°¾ã«ãã¬ãã¨è¨è¼ï¼ ãIoTéçºã«ãããã»ãã¥ãªãã£è¨è¨ã®æå¼ãã 1.1 IoT ã®ã»ãã¥ãªãã£ã®ç¾ç¶ã¨èª²é¡ï¼æ«å°¾ã«ãæãã¨è¨è¼ï¼ |
---|---|---|---|
1 | 対象ç¯å²ãåºãã㨠| ã»è¨å¤§ãªæ»æ対象ï¼ç¯å²ï¼attack surfaceï¼ | ã»è å¨ã®å½±é¿ç¯å²ã»å½±é¿åº¦åãã大ãããã¨ï¼ã¬ï¼ |
2 | å ¨ä½ãè¤éã§ããã㨠| ã»æ®åã®å¹ åºãï¼å®¶åºããç£æ¥ï¼éè¦ã¤ã³ãã©ï¼ã¾ã§ï¼ | â |
3 | ãã¾ãã¾ãªæ®åå½¢æ ãããã㨠| ã»è¤éãªã¨ã³ã·ã¹ãã ï¼åã ã®IoT æ©å¨ã ãã§ãªããã¤ãªãã£ã¦ããæ©å¨ãã·ã¹ãã ããããã¯ã¼ã¯çãå ¨ä½ã¨ãã¦æããå¿ è¦æ§ï¼ | â |
4 | ã»ã¼ããã£ã®ç¢ºä¿ãå¿ è¦ãªã㨠| ã»å®å ¨ã¸ã®å½±é¿ï¼å®å ¨ãè ããããå±éºæ§ï¼ | ã»çå½ã«é¢ããæ©å¨ãã·ã¹ãã ãç¹ãããã¨ãæ³å®ãããï¼æï¼ |
5 | ã»ãã¥ãªãã£è¦³ç¹ãè¦ä»¶ãç°ãªãã㨠| ã»é¢ä¿è ã«ãã£ã¦ç°ãªãã»ãã¥ãªãã£è¦³ç¹ãè¦ä»¶ | ã»IoT æ©å¨å´ã¨ãããã¯ã¼ã¯å´ã®ç°å¢ãç¹æ§ã®ç¸äºç解ãä¸ååã§ãããã¨ï¼ã¬ï¼ ã»ã¤ãªããä¸çãæ¡ãã¦ããããã«ã¯ããã¢ããå士ã®æè¡çï¼éä¿¡ãããã³ã«ãæå·ãèªè¨¼çï¼ãããã³ãã¸ãã¹çãªç´æäºãä¸å¯æ¬ ã¨ãªã£ã¦ããï¼æï¼ |
6 | å°ç¨ãããã³ã«ãå¿ è¦ãªå ´åãããã㨠| â | ã»IoT æ©å¨å´ã¨ãããã¯ã¼ã¯å´ã®ç°å¢ãç¹æ§ã®ç¸äºç解ãä¸ååã§ãããã¨ï¼ã¬ï¼ ã»ã¤ãªããä¸çãæ¡ãã¦ããããã«ã¯ããã¢ããå士ã®æè¡çï¼éä¿¡ãããã³ã«ãæå·ãèªè¨¼çï¼ãããã³ãã¸ãã¹çãªç´æäºãä¸å¯æ¬ ã¨ãªã£ã¦ããï¼æï¼ |
7 | ãªã½ã¼ã¹ãå¶éããã¦ããã㨠| ã»åã ã®IoT æ©å¨ã«ãããéããããªã½ã¼ã¹ï¼CPUãã¡ã¢ãªçï¼ | ã»IoT æ©å¨ã®æ©è½ã»æ§è½ãéããã¦ãããã¨ï¼ã¬ï¼ |
8 | ä½ã³ã¹ãã§ããã㨠| ã»ä½ã³ã¹ãï¼é©åãªã»ãã¥ãªãã£å¯¾çãå®è£ ããä½è£ã®æ¬ å¦ï¼ | ã»ãã¢ããã®ã³ã¹ãã®è¦³ç¹ãããã»ãã¥ãªãã£å¯¾çãçããããã¨ãæ³å®ãããï¼æï¼ |
9 | ã¹ãã¼ãéè¦ã®éçº | ã»"ã¹ãã¼ãéè¦"ã®ã»ãã¥ã¢ã§ãªãããã°ã©ãã³ã°ã»éçº | â |
10 | ã©ã¤ããµã¤ã¯ã«ãé·ãã㨠| â | ã»IoT æ©å¨ã®ã©ã¤ããµã¤ã¯ã«ãé·ããã¨ï¼ã¬ï¼ |
11 | ã¢ãããã¼ããå°é£ã§ããã㨠| ã»ã»ãã¥ãªãã£ã¢ãããã¼ãã®åé¡ | â |
12 | æ³å®å¤ã®æ¥ç¶ãè¡ãããã㨠| â | ã»ãããã«ç¹ããè
å¨ãããã¾ã§èæ
®ãã¦ãªãã£ãåéã®æ©å¨ã®æ¥ç¶ãæ³å®ãããï¼æï¼ ã»éçºè ãæ³å®ãã¦ããªãã£ãæ¥ç¶ãè¡ãããå¯è½æ§ããããã¨ï¼ã¬ï¼ |
13 | æ©å¨ã¸ã®ã³ã³ããã¼ã«ãè¡ãå±ãã«ããã㨠| â | ã»IoT æ©å¨ã«å¯¾ããç£è¦ãè¡ãå±ãã«ãããã¨ï¼ã¬ï¼ ã»ãã¢ããå士ããç¡ç·çã§èªå¾çã«ç¹ãããã¨ãæ³å®ãããï¼æï¼ |
14 | åéããæ å ±ã®ã³ã³ããã¼ã«ã¯ããã¯ã¨ã³ãå´ç¯å²ã¨ãªã | â | ã»ããããä»ãã¦åéãããæ å ±ã®ç¨éã¯ããã¢ããå´ã§ã¯å¶å¾¡ãå°é£ã§ãããããã¯ã¨ã³ãã«ããã·ã¹ãã ãã¯ã©ã¦ããµã¼ãã¹å´ã§ã®ç®¡çç¯å²ã¨ãªãï¼æï¼ |
15 | 責任åçããããã«ããã㨠| ã»è²¬ä»»åçã®ä¸æ確ã | â |
16 | ãã®ä»ï¼äººæãåºæºï¼ | ã»IoT ã»ãã¥ãªãã£ã«é¢ããç¥èãã¹ãã«ãçµé¨ãæãã人æã®ä¸è¶³ ã»æççãªã»ãã¥ãªãã£åºæºãè¦å¶ | â |
EUã®è¨è¿°ã§ã¯IoTã«é¢ããå¹
åºãã»è¤éæ§ãããã¦äººæãåºæºã®ãããªããã¸ã¡ã³ãå´é¢ã強調ããã¦ããããã«æãã¾ããæ¥æ¬ã®è¨è¿°ã§ã¯æ©å¨ããã¼ã¿ã®ç®¡çã®é£ãããæãããã¦ããããã«è¦ãã¾ãã
両å½ã®è¨è¿°ãè¦ãã¨ããåºãã¦è¤éãããä½ã³ã¹ãã§ãªã½ã¼ã¹ã«å¶ç´ãããã»ã¼ããã£ãããå°ç¨ãããã³ã«ããå
±éã®ãã¼ã¯ã¼ãã¨ãªã£ã¦ããã¨èãããã¾ãã
åè
IoTã¨é¡ä¼¼ã®ãã®ã¨ãã¦è«ãããããã¨ã®å¤ãã·ã¹ãã ã¨ãã¦ãå¶å¾¡ã·ã¹ãã ãããã¾ããIoTã®å®ç¾©ã«ãã£ã¦ã¯å¶å¾¡ã·ã¹ãã ããã®ç¯å²ã«å«ã¾ããã±ã¼ã¹ãããããããã®ç¹å¾´ãææ¡ãã¦ãããã¨ã¯æç¨ã¨èãããã¾ãã
å¶å¾¡ã·ã¹ãã ã¨é常ã®ITã·ã¹ãã ã¨ã®éãã«ã¤ãã¦ãç±³å½ã®NIST SP800-82 Revision2ãç£æ¥ç¨å¶å¾¡ã·ã¹ãã ï¼ICSï¼ã»ãã¥ãªãã£ã¬ã¤ããã§ç´¹ä»ãã¦ãã¾ãã®ã§ã覧ãã ãããï¼åã¬ã¤ã表2-1ï¼
表2ï¼ITã·ã¹ãã ã¨ICSã®ç¸éç¹ï¼ç°¡ç¥åã»ä¸é¨çç¥ï¼
ã«ãã´ãª | ITã·ã¹ãã | ç£æ¥ç¨å¶å¾¡ã·ã¹ãã ï¼ICSï¼ |
---|---|---|
æ§è½è¦ä»¶ | ãªã¢ã«ã¿ã¤ã ä¸è¦ãç | ãªã¢ã«ã¿ã¤ã ãç |
å¯ç¨æ§è¦ä»¶ | ãªãã¼ãçã®å¿çã¯å¯ãç | è¦ä»¶ã«ãããªãã¼ãçã®å¿çã¯ä¸å¯ãç |
ãªã¹ã¯ç®¡çè¦ä»¶ | ãã¼ã¿ã®æ©å¯æ§ã¨ä¿å ¨ãæéè¦ãç | 人ã®å®å ¨ãæéè¦ãç |
ã·ã¹ãã éç¨ | èªåå±éãã¼ã«ãå©ç¨ãç | ã½ããã¦ã§ã¢ã®å¤æ´ã¯æ éãè¦ãããç |
ãªã½ã¼ã¹ã®å¶ç´ | ååãªãªã½ã¼ã¹ãç | ã»ãã¥ãªãã£è¿½å ã«å¿ è¦ãªãªã½ã¼ã¹ã¯ç¡ããç |
éä¿¡ | æ¨æºéä¿¡ãããã³ã«ãç | å¤æ°ã®å°ç¨ã»æ¨æºéä¿¡ãããã³ã«ãç |
å¤æ´ç®¡ç | è¯å¥½ãªã»ãã¥ãªãã£ããªã·ã¼ã»æé ã«å¾ãã¿ã¤ã ãªã¼ã«å®æ½ãç | ã½ããã¦ã§ã¢å¤æ´ã¯ã·ã¹ãã å ¨ä½ãéãã¦å¾¹åºçã«è©¦é¨ã»å±éãç |
管çãµãã¼ã | å¤æ§ãªãµãã¼ãã¹ã¿ã¤ã«ãã | ãµã¼ãã¹ãµãã¼ãã¯é常1æ¥è ã®ã¿ |
ã³ã³ãã¼ãã³ãã®å¯¿å½ | 3å¹´ï½5å¹´ | 10å¹´ï½15å¹´ |
ã³ã³ãã¼ãã³ãã®æå¨å ´æ | é常ãã¼ã«ã«ã«æå¨ | é絶ãããé éå° |
â»å¶å¾¡ã·ã¹ãã ã®è©³ç´°ã«ã¤ãã¦ã¯ãéå»ã®ã³ã©ã ãå¶å¾¡ã·ã¹ãã ã®ã»ãã¥ãªãã£ã ãã覧ãã ããã
次åã¯ãIoTã®ã»ãã¥ãªãã£è å¨ã¨å¯¾çã«é¢ããåå½ã®éããè¦ã¦ããããã¨æãã¾ãã
åèææ¸
- Baseline Security Recommendations for IoT in the context of Critical Information Infrastructuresï¼ENISAï¼æ¬§å·ãããã¯ã¼ã¯ã»æ å ±ã»ãã¥ãªãã£æ©é¢ï¼ï¼
- Interagency Report on Status of International Cybersecurity Standardization for the Internet of Thingsï¼NISTï¼ç±³å½å½ç«æ¨æºæè¡ç 究æï¼ï¼
- Guide to Industrial Control Systems (ICS) Securityï¼NISTï¼ç±³å½å½ç«æ¨æºæè¡ç 究æï¼ï¼
- NIST SP 800-30 Revision 1ï¼NISTï¼ç±³å½å½ç«æ¨æºæè¡ç 究æï¼ï¼
- Strategic Principles For Securing The Internet Of Thingsï¼DHSï¼ç±³å½åå®å ¨ä¿éçï¼ï¼
- IoTéçºã«ãããã»ãã¥ãªãã£è¨è¨ã®æå¼ãï¼IPAï¼æ å ±å¦çæ¨é²æ©æ§ï¼ï¼
- IoTã»ãã¥ãªãã£ã¬ã¤ãã©ã¤ã³ ver1.0ï¼ç·åçï¼
- ITU-T Y.2060(Y.4000)ï¼ITUï¼å½éé»æ°éä¿¡é£åï¼ï¼
Writer Profile
ã»ãã¥ãªãã£äºæ¥é¨
ã»ãã¥ãªãã£ã³ã³ãµã«ãã£ã³ã°æ
å½ ãã¼ãã³ã³ãµã«ã¿ã³ã
æ¸ç° åä¹
Tweet