ãµã¤ãã¼è å¨æ å ±ã®å ±æï½NIST SP800-150ã®æ¦è¦ï½
æ¬å·ã§ã¯ãç±³å½å½ç«æ¨æºæè¡ç 究æ(NIST)ãçºè¡ããNIST SP800ã·ãªã¼ãºï¼http://www.intellilink.co.jp/article/column/sec-nist01.htmlï¼ã®ãã¡ããµã¤ãã¼è å¨æ å ±å ±æã®ã¬ã¤ããè¨ããSP800-150ã«ã¤ãã¦æ¦è¦ã解説ããã
1.NIST SP800-150ã®æ¦è¦
NIST SP800-150ã¯ããµã¤ãã¼è å¨æ å ±å ±æé¢ä¿ã®æ§ç¯ãããã³æ å ±ã³ãã¥ããã£ã¸ã®åå ã®ã¬ã¤ãã©ã¤ã³ã§ãããæ¬ã¬ã¤ãã¯ãçµç¹ããµã¤ãã¼è å¨æ å ±ï¼ä»¥ä¸ãè å¨æ å ±ï¼ã®çµç¹å å ±æãå¤é¨æ å ±æºããã®è å¨æ å ±ã®ä½¿ç¨ãå¤é¨å ±æãå«ãè å¨æ å ±ã®çæã«ã¤ãã¦è¦å®ãã¦ãããããã«ãæ å ±å ±æã³ãã¥ããã£ã¸ã®åå ã®èæ ®äºé ã示ããã¦ããã
æ¬ã¬ã¤ãã®æ³å®èªè ã¯CSIRTãã·ã¹ãã ã¨ãããã¯ã¼ã¯ç®¡çè ããµã¤ãã¼ã»ãã¥ãªãã£ã¹ãã·ã£ãªã¹ãããã©ã¤ãã·ã¼ãªãã£ãµã¼ããã¯ãã«ã«ãµãã¼ãã¡ã³ãã¼ãCISOãCIOãæ å ±ã»ãã¥ãªãã£ããã°ã©ã ããã¼ã¸ã£ã¼ããµã¤ãã¼è å¨æ å ±ã«é¢é£ããã¹ãã¼ã¯ãã«ãã¼ã¨ãªãã
2.ãµã¤ãã¼è å¨æ å ±å ±æã®åºæ¬
ãµã¤ãã¼è å¨ãè å¨æ å ±ã¯NIST SP800-30 (Guide for Conducting Risk Assessments)ã«ã¯æ¬¡ã®ããã«å®ç¾©ãã¦ããã
ãµã¤ãã¼è å¨ã¨ã¯ãæ å ±ã·ã¹ãã ãéãã¦ä¸æ£ãªã¢ã¯ã»ã¹ãç ´å£ãæ å ±ã®é示ãå¤æ´ããµã¼ãã¹æå¦ãå®æ½ããçµç¹ã®éå¶ï¼ããã·ã§ã³ãæ©è½ãã¤ã¡ã¼ã¸ãè©å¤ãå«ãï¼ãçµç¹ã®è³ç£ãå人ãä»ã®çµç¹ãã¾ãã¯å½å®¶ã«æªå½±é¿ãä¸ããå¯è½æ§ã®ããã¤ãã³ãã§ããã
ãµã¤ãã¼è å¨æ å ±(ç¥ç§°ï¼è å¨æ å ±)ã¨ã¯ãçµç¹ããµã¤ãã¼è å¨ããèªèº«ãä¿è·ããããæ»æè ã®æ´»åãæ¤åºãããããµã¤ãã¼è å¨ã«å¯¾å¿ãããã¨ãªã©ã«å½¹ç«ã¤å¯è½æ§ã®ããæ å ±ã§ãããè å¨æ å ±ã«ã¯ã侵害ã®ã¤ã³ã¸ã±ã¼ã¿ã¼ãè å¨ã¢ã¯ã¿ã¼ã使ç¨ããæ¦è¡ãææ³ãæé ãæ»æãæ¤åºãå°ãè¾¼ããé²æ¢ããããã®æ¨å¥¨ã¢ã¯ã·ã§ã³ãããã³ã¤ã³ã·ãã³ãåæã®çµæãå«ã¾ãããè å¨æ å ±ãå ±æããçµç¹ã¯ãä»ã®çµç¹ã¨åæ§ã«èªèº«ã®ã»ãã¥ãªãã£ãæ¹åãããã¨ãã§ããã
主ãªè å¨æ å ±ã®ç¨®é¡ã表1ã«ç¤ºãã
é çª | è
å¨æ
å ± ç¨®é¡ |
説æ | ä¾ |
---|---|---|---|
1 | ã¤ã³ã¸ã±ã¼ã¿ã¼ | æ»æãå·®ãè¿«ã£ã¦ãããã¾ãã¯ç¾å¨é²è¡ä¸ã§ãããã¾ãã¯ä¾µå®³ããã§ã«çºçãã¦ããå¯è½æ§ããããã¨ã示ãæè¡çãªã¢ã¼ãã£ãã¡ã¯ãã¾ãã¯è¦³å¯ã§ããã¤ãã³ã | çãããã³ãã³ãã¢ã³ãã³ã³ããã¼ã«ãµã¼ãã¼ã®IPã¢ãã¬ã¹ãçããããã¡ã¤ã³ãã¼ã ã·ã¹ãã ï¼DNSï¼ããã¡ã¤ã³åãæªæã®ããã³ã³ãã³ããåç §ããURLãæªæã®ããå®è¡å¯è½ãã¡ã¤ã«ã®ãã¡ã¤ã«ããã·ã¥ãã¾ãã¯æªæã®ããé»åã¡ã¼ã«ã®ä»¶åãªã© |
2 | TTP | æ¦è¡(Tactics)ããã¯ããã¯(Techniques)ããã³æé (Procedures)ã¯ãã¢ã¯ã¿ã¼ã®æ¯ãèãã説æãããã®ã§ããã æ¦è¡ã¯ã¢ã¯ã¿ã¼ã®æ¯ãèãã«ã¤ãã¦é«ã¬ãã«ã®è¨è¿°ããã¯ããã¯ã¯æ¦è¡ã®ã³ã³ããã¹ãã«ãããæ¯ãèãã®è©³ç´°ãªè¨è¿°ãæé ã¯ãã¯ããã¯ã®ã³ã³ããã¹ãã«ããã詳細ãªè¨è¿° |
ç¹å®ã®ãã«ã¦ã§ã¢äºç¨®ãæä½ã®é åºãæ»æãã¼ã«ããã£ãã·ã³ã°ã水飲ã¿å ´æ»æãªã©ã®é ä¿¡ã¡ã«ããºã ãã¨ã¯ã¹ããã¤ãã使ç¨ããæ»æè ã®å¾åã説æããè¨è¿°ãªã© |
3 | ã»ãã¥ãªãã£ã¢ã©ã¼ã | ã¢ããã¤ã¶ãªãã»ãã¥ãªãã£æ å ±ã¨ãå¼ã°ããç¾å¨ã®èå¼±æ§ãã¨ã¯ã¹ããã¤ãããã®ä»ã®ã»ãã¥ãªãã£åé¡ã«é¢ããç°¡æ½ãªæè¡è åãã®æ å ± | ç±³å½ã³ã³ãã¥ã¼ã¿ã¼ç·æ¥äºæ 対å¿ãã¼ã ï¼US-CERTï¼ãæ å ±å ±æåæã»ã³ã¿ã¼ï¼ISACï¼ãå½å®¶èå¼±æ§ãã¼ã¿ãã¼ã¹ï¼NVDï¼ã製åã»ãã¥ãªãã£ã¤ã³ã·ãã³ãã¬ã¹ãã³ã¹ãã¼ã ï¼PSIRTï¼ãåç¨ã»ãã¥ãªãã£ãµã¼ãã¹ãããã¤ãã¼ãããã³ã»ãã¥ãªãã£ç 究è ãªã©ã®æ å ±æºããçºä¿¡ãããæ å ± |
4 | è å¨ã¤ã³ããªã¸ã§ã³ã¹ã¬ãã¼ã | TTPãæ»æè ã対象ã¨ãªãã·ã¹ãã ã¨æ å ±ã®ç¨®é¡ããã³çµç¹ã®ç¶æ³èªèãé«ããè å¨é¢é£æ å ±ãè¨è¿°ããããã¥ã¡ã³ã | ææ決å®ããã»ã¹ã«å¿ è¦ãªã³ã³ããã¹ããæä¾ããããã®éç´ãå¤æãåæã解éãã¾ãã¯å¼·åãããè å¨æ å ± |
5 | ãã¼ã«ã³ã³ãã£ã°ã¬ã¼ã·ã§ã³ | è å¨æ å ±ã®èªååéã交æãå¦çãåæãããã³ä½¿ç¨ããµãã¼ããããã¼ã«ï¼ã¡ã«ããºã ï¼ã®ã»ããã¢ããããã³ä½¿ç¨ã«é¢ããæ¨å¥¨äºé | ã«ã¼ãããããæ¤åºããã³åé¤ããããã®ã¦ã¼ãã£ãªãã£ã®ã¤ã³ã¹ãã¼ã«æ¹æ³ããã³ä½¿ç¨æ¹æ³ãä¾µå ¥æ¤ç¥ã·ã¹ãã ã®ã·ã°ããã£ãã«ã¼ã¿ã¼ã®ã¢ã¯ã»ã¹å¶å¾¡ãªã¹ãï¼ACLï¼ããã¡ã¤ã¢ã¦ã©ã¼ã«ã®ã«ã¼ã«ãªã© |
ãã®SP800-150ã®ä¸»ãªç®çã¯ãçµç¹éã®å¢çãè¶ãã¦è
å¨æ
å ±ã®å
±æãä¿é²ãããã¨ã§ããã
è
å¨æ
å ±ã®å
±æã«ãããè
å¨æ
å ±ã¸ã®ã¢ã¯ã»ã¹ãæä¾ããããå
±ææ
å ±ã使ç¨ããã¨ããã¼ããã¼ã®ç¥èãçµé¨ãæ©è½ãç©æ¥µçã«æ´»ç¨ãããã¨ã«ãããã»ãã¥ãªãã£æ
å¢ãå¼·åã§ãããã¤ã¾ããããçµç¹ã®è
å¨æ
å ±ã®æ¤åºãå¥ã®çµç¹ã®äºé²ã«ãªããã¨ãããã¨ãå®ç¾ã§ããã
ç¹å®ã®æ¥çãä¸å¿ã«çµç¹ãããã³ãã¥ããã£å ã§äº¤æãããè å¨æ å ±ã¯ãã¡ã³ãã¼çµç¹ãåãã¿ã¤ãã®ã·ã¹ãã ããã³æ å ±ã対象ã¨ããå ±éã®TTPã使ç¨ããæ»æãåãããã¨ãããããæçã¨ãªããçµç¹å士ã®ååã¯ãçµç¹åãããæ»æãé²æ¢ããé²å¾¡ã«å¹æããããåçµç¹ã®ãªã¹ã¯ã軽æ¸ããã»ãã¥ãªãã£ãæ¹åããã®ã«å½¹ç«ã¤ã
æ å ±å ±æã®å©ç¹ã¨èª²é¡ã表2ã«ç¤ºãã
é çª | é ç® | 説æ | |
---|---|---|---|
å©ç¹ | 1 | å ±æã®ç¶æ³èªè | æ å ±å ±æã«ãããçµç¹ã¯ã³ãã¥ããã£å ã§å ±æãã¼ããã¼ã®ç¥èãçµé¨ãããã³åææ©è½ãæ´»ç¨ã§ãããããè¤æ°ã®çµç¹ã®é²å¾¡æ©è½ãå¼·åããã |
2 | ã»ãã¥ãªãã£ã®æ¹å | æ å ±å ±æã«ãããçµç¹ã¯è å¨ç°å¢ã®ç解ãæ·±ã¾ããè å¨æ å ±ã使ç¨ãã¦ãµã¤ãã¼ã»ãã¥ãªãã£ã¨ãªã¹ã¯ç®¡çã®ãã©ã¯ãã£ã¹ãæ¹åãã | |
3 | ç¥èã®æç | ä¸è¦ç¡é¢ä¿ãªè¦³å¯çµæãçµç¹ã«ãã£ã¦å ±æããã³åæããããã¨ã«ãããä»ã®çµç¹ã«ãã£ã¦åéããããã¼ã¿ã¨ç¸é¢ãããã¨ã§æ å ±ã®ä¾¡å¤ãé«ãã | |
4 | é²å¾¡ã®æ©ææ§ | æ å ±ãå ±æããçµç¹ã¯ãè å¨ãè¿ éã«æ¤åºãã¦å¯¾å¿ãããã¨ã«ãããæ»æãæåãã確çãä¸ãããã¨ãã§ãã | |
èª²é¡ | 1 | ä¿¡é ¼ã®ç¢ºç« | ä¿¡é ¼é¢ä¿ã¯æ å ±å ±æã®åºç¤ãå½¢æããããä¿¡é ¼é¢ä¿ã®ç¢ºç«ããã³ç¶æããããã«ã¯åªåãå¿ è¦ã§ãã |
2 | ç¸äºéç¨æ§ã¨èªååã®å®ç¾ | èªååã«ã¯æ¨æºãã©ã¼ãããã¨è»¢éãããã³ã«ãå¿ è¦ã§ããããã ããç¹å®ã®ãã©ã¼ãããã¨ãããã³ã«ãæ¡ç¨ããã«ã¯ãå¤å¤§ãªæéã¨è³æºãå¿ è¦ã«ãªãå¯è½æ§ããã | |
3 | æ©å¯æ å ±ã®ä¿è· | 管çãããéæ ¼ä»ãæ å ±ï¼CUIï¼ãå人ãç¹å®ã§ããæ å ±ï¼PIIï¼ãªã©ã®æ©å¯æ å ±ã®é示ã¯ãæ å ±ã®åãæ±ãèå¥ãå ±ææ å ±ã«æ示ããæ å ±ã®åãæ±ãããªã·ã¼ãæé ãããã³ã¢ã¯ã»ã¹å¶å¾¡ãæ½ãã¦ãæ©å¯æ å ±ã®é示ã®ãªã¹ã¯ã管çããå¿ è¦ããã | |
4 | æ ¼ä»ãæ å ±ã®ä¿è· | æ¿åºã®æ å ±æºããåãåã£ãæ å ±ï¼æ ¼ä»ãæ å ±ï¼ã¯æ©å¯æ±ãã¨ãã¦ããå ´åããããçµç¹ã使ç¨ããããã«ã¯çµç¹å ã§ã®ä¿è·ãããã¨ãéè¦ã§ããã | |
5 | æ å ±ã®ä½¿ç¨ã¨å ¬éã®å¯è½æ§ | è å¨ã®æ å ±ã使ç¨ã¾ãã¯å ¬éãããçµç¹ã¯å¿ è¦ãªã¤ã³ãã©ããã¼ã«ã人æãããã³ãã¬ã¼ãã³ã°ãæºåããå¿ è¦ããããçµç¹ã®åéã«åãããè å¨æ å ±å ±æã®ã¹ã³ã¼ãã決ãããã¨ãéè¦ã§ãã |
3.å ±æé¢ä¿ã®æ§ç¯
ãµã¤ãã¼æ å ±å ±æè½åãæ§ç¯ããéã«ãå³1ã®ããã»ã¹ãæ¨å¥¨ãã¦ããã
å³1ãå ±æé¢ä¿ã®æ§ç¯ããã»ã¹
ãã®ããã»ã¹å ¨ä½ãéãã¦ãçµç¹ã¯ãçµç¹å å¤ã®ãµã¤ãã¼ã»ãã¥ãªãã£å°é家ãæ¥çãã¼ããã¼ãæ³ä»¤ãå é¨ãã¸ãã¹ããã»ã¹ã æé ã«è©³ããè ãªã©ååéã®å°é家ã¨ç¸è«ãããã¨ãå§ãããã¦ãããã¾ããå¤åãç¶ããç¶æ³ã«å¿ãã¦å ±ææ©è½ãè¦ç´ãå¿ è¦ã ãããä¸è¨ã®ããã»ã¹ã®ä¸é¨ã¾ãã¯ãã¹ã¦ãç¹°ãè¿ããã¨ãéè¦ã§ããã
- â ç®æ¨ã¨ç®çã®å®ç¾©
- è å¨æ å ±å ±æã®ç®æ¨ã¨ç®çã®å®ç¾©ã¯ãä¼æ¥ã¯å ±ææ´»åãéãã¦åå¾ãããææãå¼ãåºããã¨ã§ãããä¼æ¥ã®æ å ±å ±æåªåã¹ã³ã¼ ããå ±æã³ãã¥ããã£ã®é¸æãå ±ææ´»åã¸ã®ãµãã¼ããªã©ã®æ¹åæ§ãå°ãã
- â¡å é¨æ å ±æºã®ç¹å®
- è å¨æ å ±ã®å é¨æ å ±æºã®ç¹å®ã¯ã以ä¸ã®ããã«çµç¹ã®æ å ±æºã®æ£å¸ãã«ããå®ç¾ã§ããã
- ã»ã³ãµã¼ããã¼ã«ããã¼ã¿ãã£ã¼ãããªãã¸ããªãªã©è å¨æ å ±ãçæããæ©å¨ã»è£ ç½®ãç¹å®ãããµã¤ãã¼ã»ãã¥ãªãã£ã®ææ決å®ãæ¯æ´ããæ å ±ã®æ£ç¢ºæ§ãçæé »åº¦ã確èªãã
- çµç¹ã®ç¶ç¶çãªç£è¦ã¨ãã¦åéããã³åæãããè å¨æ å ±ãç¹å®ãã
- çµç¹å ã§æ å ±ãåéãã¦ãããã確èªãåæãªã©ãè¡ããã¦ããªãæ å ±ãç¹å®ãããä¼æ¥ã®ãµã¤ãã¼ã»ãã¥ãªãã£ã¨ãªã¹ã¯ããã¸ã¡ã³ãã«ãã®æ å ±ãæ´»ç¨ã§ããããæ¤è¨ãã
- å¤é¨å ±æã«ç¸å¿ããæ å ±ãç¹å®ãã
- â¢å ±ææ´»åã¹ã³ã¼ãã®å®ç¾©
- è å¨æ å ±ã®å ±ææ´»åã¹ã³ã¼ããç¹å®ããã
- å ±æã§ããæ å ±ã®ç¨®é¡
- æ å ±ãå ±æã§ããç¶æ³ã»æ¡ä»¶
- æ å ±å ±æã®ç¸æ å ±ææ´»åãè¡ãããã«å¿ è¦ãªè³æºã¨æ©è½ã確ä¿ããå¿ è¦ããããçµç¹ã®åéã«åããã¦è å¨æ å ±å ±æã®ã¹ã³ã¼ãã決ãããã¨ãéè¦ã§ããã
- â£ å ±æã«ã¼ã«ã®ç¢ºç«
- å
±æã«ã¼ã«ã¯ãè
å¨æ
å ±ã®å
¬éãæµéãã³ã³ããã¼ã«ããä¸é©åã«é示ãããå ´åãçµç¹ããã®é¡§å®¢ã¾ãã¯ãã¸ãã¹ãã¼ããã¼ã«æªå½±é¿ãä¸ããå¯è½æ§ã®ããæ
å ±ã®å
±æãé²ããã¨ãã§ãããããã«å
±æã«ã¼ã«ã«å
±æããæ
å ±ãç·¨éãç¡å®³åãããã ã®è¦ä»¶ãæ
å ±æºã®å¸°å±è¡¨ç¤ºã®æå®ãæ
å ±ãä¿è·ããããã®åä¿¡è
ã®ç¾©åãã«ã¼ã«åããå¿
è¦ããããã¾ããCUIãPIIãç¥ç財ç£ã ä¼æ¥ç§å¯ãªã©ä¿è·ãå¿
è¦ãªæ©å¯æ
å ±ã®åãæ±ããè¦å®ããããªã·ã¼ã¨æé ãç¨æãããã¨ãå¿
è¦ã¨ãªããæ©å¯æ
å ±ã«ç¹å®ãããå ´ åãçµç¹ã¯ãå
±æããåã«è
å¨ã®èª¿æ»ã¾ãã¯å¯¾å¦ã«é¢ä¿ã®ãªãæ©å¯æ
å ±ãå«ãäºé
ãç·¨éããå¿
è¦ãããã
çµç¹ã¯ãå ±æããã¦ããè å¨æ å ±ã«å¯¾ãã¦æ確ãªåãæ±ãã¬ã¤ãã³ã¹ãæä¾ãããã¨ãæ¨å¥¨ããã¦ãããå ±æ種å¥(Sharing Designations)ã¨å¼ã°ãããè å¨æ å ±ã®åä¿¡è ã¯ãæ å ±æºçµç¹ã®å¦çã¬ã¤ãã³ã¹ã«è¨è¼ããã¦ããå¦çãå±æ§ãé å¸ãããã³ä¿åã®è¦ä»¶ ãéµå®ããå¿ è¦ãããã
TLP(Traffic Light Protocol)ã¯ãå ±æ種å¥ã表ç¾ããããã®ãã¬ã¼ã ã¯ã¼ã¯ã§ãããTLPã¯ãç¹å®ã®ã¬ã³ã¼ãã«é©ç¨ãããå¶éã è²åããã¦æå®ãããTLPã®è©³ç´°ã表3ã«ç¤ºãã - â¤å ±æã³ãã¥ããã£ã¸ã®åå
- è
å¨æ
å ±ã¯ããããªãã¯ããã³ãã©ã¤ãã¼ãã®å
±æã³ãã¥ããã£ãæ¿åºã®ãªãã¸ããªãçµç¹æ¨ªæãåç¨è
å¨æ
å ±ããã³ãªã¼ãã³ãªæ
å ±æºããåå¾ã§ããã å
±æã³ãã¥ããã£ã¯ãå¤ãã®å ´åãå
±æã®ç¹æ§ã¾ãã¯é¢å¿ãä¸å¿ã«çµç¹ããããå
±æãã¼ããã¼ã®ä¾ã¨ãã¦ãISACãå½å
å¤ã®ã³ã³ãã¥ã¼ã¿ã¼ç·æ¥äºæ
対å¿ãã¼ã ï¼CERTï¼ã¾ãã¯CSIRTãæ
å ±å
±æããã³åæçµç¹ï¼ISAOï¼ãå½åå®å
¨ä¿éçï¼DHS)ã®AIS(Automated Indicator Sharing)ãè
å¨ã¨èå¼±æ§ãªãã¸ããªãæ³å·è¡æ©é¢ã製åãã³ãã¼ãããã
å ±æã³ãã¥ããã£ãé¸æããã¨ãã¯ãã³ãã¥ããã£å ã§å ±æãããæ å ±ã®ç¨®é¡ãã³ãã¥ããã£ã®æ§é ã¨ãã¤ããã¯ã¹ãããã³ã¡ã³ãã¼ã·ããã®åå ã¨ç¶æè²»ç¨ãªã©ãèæ ®ããå¿ è¦ãããããããã®ã³ãã¥ããã£ãè©ä¾¡ããã¨ãã«ã¯ã次ã®ãããªè¦³ç¹ã«ã¤ãã¦èæ ®ããå¿ è¦ãããã - ã³ãã¥ããã£å ã§å ±æãããè å¨æ å ±ã¯é¢é£æ§ããããçµç¹ã®è å¨ç°å¢ã®ã³ã³ããã¹ãã§ææ義ãªè¦èã«ãããæ¢åã®è å¨æ å ±ãè£å®ãããã¨ãã§ãããï¼
- ã³ãã¥ããã£å ã§äº¤æãããè å¨æ å ±ã¯å®è¡å¯è½ãï¼
- ã³ãã¥ããã£ã«ã¯ã帰å±ã®ãªãè å¨æ å ±ã®æåºæ©è½ã¨æåºè ã®èº«å ãä¿è·ããã¡ã«ããºã ããããï¼
- è å¨æ å ±ã¯ã¿ã¤ã ãªã¼ã§ãä¿¡é ¼æ§ããããå質ãè¯ããï¼
- ã³ãã¥ããã£ã§ä½¿ç¨ãããæ å ±äº¤æå½¢å¼ã¯ãçµç¹ã§ä½¿ç¨ãããã¤ã³ãã©ã¹ãã©ã¯ãã£ããã³ãã¼ã«ã¨äºææ§ããããï¼
- ã³ãã¥ããã£ããéä¿¡ããããã¼ã¿ã®é »åº¦ã¨éãããçµç¹ã¯æ å ±ãåãè¾¼ã¿/åæ/ä¿åããè½åãæã£ã¦ãããï¼
- â¥æ å ±å ±ææ´»åã«å¯¾ããç¶ç¶çãªãµãã¼ãæä¾
- çµç¹ã¯ãæ
å ±å
±æããã®ã¤ã³ãã©ã¹ãã©ã¯ãã£ã®ã¡ã³ããã³ã¹ã¨ã¦ã¼ã¶ã¼ãµãã¼ãã«å¯¾å¿ãããµãã¼ãè¨ç»ãä½æããå¿
è¦ãããã
æ å ±å ±ææ´»åã¸ã®åå ã«ã¯ç¶ç¶çãªè²»ç¨ãå¿ è¦ã«ãªãããè å¨æ å ±ãå¹æçã«ä½¿ç¨ãããã¨ã§ãæ»æãæåããéã®å¤§ããªã³ã¹ããåé¿ãããã¨ãã§ããã
ç¨®å¥ | 使ç¨ããç¶æ³ | å ±ææ¹æ³ |
---|---|---|
TLP: 赤 åå è ã®ã¿ã®é示 |
誤ç¨ãããå ´åã«é¢ä¿è ã®ãã©ã¤ãã·ã¼ãè©å¤ãã¾ãã¯éç¨ã«å½±é¿ãä¸ããå¯è½æ§ãããå ´åãTLPï¼èµ¤ã使ã | åä¿¡è ã¯ãæ å ±ãæåã«é示ãããç¹å®ã®ä¼è°ãã¾ãã¯ä¼è©±ä»¥å¤ã®é¢ä¿è ã¨æ å ±ãå ±æãããã¨ã¯ã§ããªããä¾ãã°ãä¼è°ã®å ´åãæ å ±ã¯ä¼è°ã®åºå¸è ã«éå®ããã |
TLP: é» åå è ã®çµç¹ã«éå®ãããéå®çãªé示 |
é¢ä¿ããçµç¹ã®å¤é¨ã§å ±æãããå ´åããã©ã¤ãã·ã¼ãè©å¤ãã¾ãã¯éç¨ã«ãªã¹ã¯ãããããå ´åãTLPï¼é»ã使ã | åä¿¡è ã¯ãæ å ±ãèªçµç¹ããã³æ害ãé²æ¢ããããã«æ å ±æä¾ããå¿ è¦ãããèªçµç¹ã®é¡§å®¢ã®ã¿ã«å ±æã§ãã |
TLP: ç· ã³ãã¥ããã£ã«éå®ãããé示 |
æ å ±ããã¹ã¦ã®åå çµç¹ããã³ããåºç¯ãªã³ãã¥ããã£ã¾ãã¯æ¥çå ã¡ã³ãã¼ã«å½¹ç«ã¤å ´åãTLPï¼ç·ã使ã | åä¿¡è ã¯ãæ å ±ãæ¥çå ã¾ãã¯ã³ãã¥ããã£å ã®ã¡ã³ãã¼ããã³ãã¼ããã¼çµç¹ã¨å ±æã§ããããä¸è¬ã«ã¢ã¯ã»ã¹å¯è½ãªã¨ããã§ã¯å ±æã§ããªã |
TLP: ç½ é示ã¯å¶éãããªã |
æ å ±ã¯ãå ¬éãªãªã¼ã¹ã«é©ç¨ãããè¦åããã³æé ã«å¾ã£ã¦ãæ å ±ã«èª¤ç¨ã®ãªã¹ã¯ãæå°éã¾ãã¯å ¨ãç¡ãå ´åãTLPï¼ ç½ã使ã | æ å ±ã¯å¶éãªãã«é ä¿¡ã§ãã |
4.å ±æã³ãã¥ããã£ã¸åå ããéã®èæ ®ãã¹ãäºé
æ å ±å ±æã³ãã¥ããã£ã«åå ãã¦ããçµç¹ã®æ´»åã以ä¸ã«ç¤ºããè å¨æ å ±å ±æãéå§ããå½åã®çµç¹ã¯ã1ã¤ã¾ãã¯2ã¤ã®æ´»åã«æ³¨åããæ å ±å ±ææ©è½ãæçããã¨ã¨ãã«æ´»åã追å ãããã¨ãæ¨å¥¨ãããã
- â ç¶ç¶çãªã³ãã¥ãã±ã¼ã·ã§ã³ã«åãçµã
- å ±æã³ãã¥ããã£ã¸ã®ç¶ç¶çãªåå ã¯ãä¿¡é ¼ãè²ã¿ãä»ã®ã¡ã³ãã¼ã¨ã®ããå¼·ãé¢ä¿ã確ç«ããç¶ç¶çãªæ¹åãè¡ãããã«ã¯ä¸å¯æ¬ ã§ããã ã³ãã¥ããã£ã主å¬ããé»è©±ä¼è°ã対é¢ä¼è°ã«ç©æ¥µçã«åå ãã¦ããçµç¹ã¯ãä»ã®ã¡ã³ãã¼ã¨ã®ä¿¡é ¼é¢ä¿ã確ç«ããå¹æçã«ååæ´»åãã§ããã
- â¡ã»ãã¥ãªãã£ã¢ã©ã¼ãã使ç¨ãã対å¿ãã
- ã»ãã¥ãªãã£ã¢ã©ã¼ããåä¿¡ããéã«ã¯ãä¿¡é ¼ã§ããæ å ±æºã確èªãã¦ãããé©åãªå¯¾å¿ãå®æ½ãã¹ãã§ããã
- â¢ã¤ã³ã¸ã±ã¼ã¿ã¼ã®ä½¿ç¨
- å¤é¨ãã£ã¼ãããã®ã¤ã³ã¸ã±ã¼ã¿ã¼ã¯ãä¸è¬çã«ä»¥ä¸ã®åå·¥ç¨ã§ä½¿ç¨ããããçµç¹ã®éç¨ã¾ãã¯ã»ãã¥ãªãã£è¦ä»¶ã«ãããé åºã¯å¤ãããä¿¡é ¼ã§ããæ
å ±æºããã®ã¤ã³ã¸ã±ã¼ã¿ã¼ã¯ãè
å¨ãæ¤åºãã¦å¯¾å¿ããããã«ãã¿ããã«ä½¿ç¨ãããå ´åãããããä¿¡é ¼ã§ããªãæ
å ±æºããã®ã¤ã³ã¸ã±ã¼ã¿ã¼ã¯ã使ç¨åã«æ¤è¨¼ã追å ã®èª¿æ»ãã¾ãã¯ãã¹ããå¿
è¦ã«ãªãå ´åãããã
æ¤è¨¼:ãã¸ã¿ã«ç½²åãæå·åããã·ã¥ãã¾ãã¯ãã®ä»ã®æ段ã«ãããã¤ã³ã¸ã±ã¼ã¿ã¼ã®ã³ã³ãã³ãã¨åºæã®æ´åæ§ãæ¤è¨¼ããã
復å·:æå·åãããã¤ã³ã¸ã±ã¼ã¿ã¼ãã¡ã¤ã«ã¾ãã¯ãã¼ã¿ã¹ããªã¼ã ãå ã®å½¢å¼ã«å¤æããã
解å:å§ç¸®ãããã¤ã³ã¸ã±ã¼ã¿ã¼ãã¡ã¤ã«ãã¢ã¼ã«ã¤ããã¡ã¤ã«ï¼zipãtarãªã©ï¼ãã¾ãã¯ãã¼ã¿ã¹ããªã¼ã ã解åããã
ã³ã³ãã³ãã®æ½åº:ã¤ã³ã¸ã±ã¼ã¿ã¼ãã¡ã¤ã«ã解æããçµç¹ã«ã¨ã£ã¦é¢å¿ã®ããã¤ã³ã¸ã±ã¼ã¿ã¼ãæ½åºããã
åªå é ä½ä»ã:ç¸å¯¾çãªéè¦æ§ãæ å ±æºã®ç¥è¦ä¾¡å¤ããã¼ã¿ã®å ¨ä½çãªä¿¡é ¼åº¦ãªã©ãèæ ®ãã¦ã¤ã³ã¸ã±ã¼ã¿ã¼å¦çã®åªå é ä½ãä»ããã
åé¡:ã¤ã³ã¸ã±ã¼ã¿ã¼ã®ã¡ã¿ãã¼ã¿ã確èªãã¦ãã»ãã¥ãªãã£èå¥ã¨å¦çè¦ä»¶ã決å®ããã
- â£ã¤ã³ã¸ã±ã¼ã¿ã¼ã®æ´çã¨ä¿å
- çµç¹ã¯ããªã¼ãã³ã½ã¼ã¹ãªãã¸ããªãåç¨ã®è å¨æ å ±ãå¤é¨ãã¼ããã¼ãªã©ããã¾ãã¾ãªæ å ±æºããã¤ã³ã¸ã±ã¼ã¿ã¼ãåéãã¦ãæ´çããå¿ è¦ãããå ´åããããã¾ããçµç¹ã¯ãã¤ã³ã¸ã±ã¼ã¿ã¼ããã®ä»ã®è å¨æ å ±ã®å¦åã«å¯¾å¦ããããªã·ã¼ã¨æé ã確ç«ããå¿ è¦ããããããªã·ã¼ããã³æé ã§ã¯ãã¤ã³ã¸ã±ã¼ã¿ã¼æ å ±ã®çæããã³é·æã®å¯ç¨æ§ã«é¢ãããã¼ã¿ä¿æè¦ä»¶ãå®ç¾©ããå¿ è¦ãããã
- â¤ã¤ã³ã¸ã±ã¼ã¿ã¼ã®ä½æã¨å ¬é
- å¤ãã®çµç¹ã¯ã¤ã³ã¸ã±ã¼ã¿ã¼ã使ç¨ãããã¨ã ãã«æ³¨åããã¦ãããããé«åº¦ãªã»ãã¥ãªãã£æ©è½ãåããçµç¹ã¯ãç¬èªã®ã¤ã³ã¸ã±ã¼ã¿ã¼ãä½æãã¦å ¬éãããã¨ãããä»ã®ã³ãã¥ããã£ã¡ã³ãã¼ã¨ã®ä¿¡é ¼ãè²ã¦ããã¨ã§å®è³ªçãªå©çãå¾ããã¨ãã§ããã
5.ã·ããªãªã®ä¾ï¼éèé¢é£ã®ä¼è°åºå¸è ã¸ã®ãã£ãã·ã³ã°æ»æ
ãµã¤ãã¼ç¯ç½ªã°ã«ã¼ãã¯ãå ¬éããã¦ããä¼è°åºå¸è ãªã¹ããå©ç¨ãã¦ãä¸é£ã®ãã£ãã·ã³ã°ã¡ã¼ã«ã§ç¹å®ã®å人ãæ¨çã«ããããã®ã°ã«ã¼ãã¯ã対象çµç¹ã®ä¼è¨ãã¼ã ã®ã¡ã³ãã¼ã§ããåå è ãèå¥ããæ¯æãã¾ãã¯ééãæ¿èªãã権éãæã¤å¯è½æ§ã®ããå人ãç¹å®ã§ãããã°ã«ã¼ãã¯ããã£ãã·ã³ã°æ»æãéãã¦é å¸ããæ¨çåãã«ã¦ã§ã¢ã使ç¨ãã¦ããã·ã³ã¨ã¢ã«ã¦ã³ãã侵害ããä¸æ£ãªé»å決æ¸ã«ãããæµ·å¤ä¼æ¥ã¸ã®è³é移åãè¡ãã
ããä¼æ¥ã¯ãä¼æ¥ä¼è¨ãã¼ã å
ã®äººå¡ã«å¯¾ãããã£ãã·ã³ã°æ»æãæ¤åºããããã®èª¿æ»ä¸ã«ãæ»æä¸ã«æ¨çã¨ãªã£ããã¹ã¦ã®åä¿¡è
ã6ãæåã«åãä¼è°ã«åºå¸ãããã¨ãåãã£ããå社ã®CSIRTã¯ãä¼è°ã®ä¸»å¬è
ããã³ä¼è°ã«åå ããä»ã®çµç¹ã®ä»£è¡¨è
ã«ãé£çµ¡ãããå½±é¿ãåããçµç¹ã¯ãé»è©±ä¼è°ã«ãããæ»æã«é¢ããç¹å®ã®æ
å ±ï¼é»åã¡ã¼ã«ãããã¼ãã³ã³ãã³ããæ·»ä»ãã¡ã¤ã«ãåãè¾¼ã¿URLãªã©ï¼ãå
±æããã
ãã®å
±æã¤ã³ã¸ã±ã¼ã¿ã¼ã使ç¨ãã¦ãä»ã®ä¼è°åå è
ã¯ã¡ã¼ã«ã¨ãããã¯ã¼ã¯ãã©ãã£ãã¯ã®ãã°ã確èªãã侵害ãããå¯è½æ§ã®ãããã¹ããç¹å®ãããã¨ãå¯è½ã¨ãªãã
åèæç®
- 1ï¼NIST Special Publication 800-150, Guide to Cyber Threat Information Sharing, October 2016.
http://dx.doi.org/10.6028/NIST.SP.800-150 - 2ï¼NIST SP 800-30, Guide for Conducting Risk Assessments, September 2012.
http://dx.doi.org/10.6028/NIST.SP.800-30r1
Writer Profile
ã»ãã¥ãªãã£äºæ¥æ¬é¨
äºæ¥æ¨é²é¨
ãµã¤ãã¼ã»ãã¥ãªãã£ã¤ã³ããªã¸ã§ã³ã¹ã»ã³ã¿ã¼
主任ã¨ã³ã¸ãã¢
é³ãæãChen Siï¼CISSPï¼
Tweet