ãããããã¸ã¡ã³ãã®èªååã«ããã¢ããã¤ã¼ã¼ã·ã§ã³ ï½ç¬¬ä¸è©±ï½ èå¼±æ§ç®¡çã®èªåå
ããããããã¸ã¡ã³ãã®èªååã«ããã¢ããã¤ã¼ã¼ã·ã§ã³ãã¨ãããã¼ãã§éå»äºåã話ããã¦ããã ãã¾ããã
第ä¸è©±ã§ã¯ãããããã¸ã¡ã³ãã®æ¦è¦ã¨éè¦æ§ã第äºè©±ã§ã¯åºç¤ã·ã¹ãã æ§ç¯ã¨ãããé©ç¨ã®èªååã«ã¤ãã¦ã説æãã¾ããã
第ä¸è©±ã§ããä»åã¯èå¼±æ§ç®¡çã®èªååã«ã¤ãã¦è§£èª¬ãããã¾ãã
ãããããã¸ã¡ã³ããµã¤ã¯ã«ã«ãããèå¼±æ§ç®¡ç
第ä¸è©±ã§ã説æãããããããã¸ã¡ã³ããµã¤ã¯ã«ã«ã¤ãã¦è¦ãã¦ããã£ãããã¾ããã ãããããã¸ã¡ã³ãã¨ã¯ãã»ãã¥ãªãã£ãªã¹ã¯ãä½æ¸ãã·ã¹ãã ãå¥å ¨ã«éç¨ãããã¨ãç®çã¨ããã·ã¹ãã ãæ§æãããµã¼ãã¼ã®ï¼¯ï¼³ãããã«ã¦ã§ã¢ããã³ãããã¯ã¼ã¯æ©å¨ã®èå¼±æ§ãç¹å®ãããããã®ã»ãã¥ãªãã£ããããé©ç¨ãããã¨ã§èå¼±æ§ãä¿®æ£ããã»ãã¥ãªãã£ãªã¹ã¯ãä½æ¸ããä¸é£ã®ä½æ¥ã管çãããã¨ã§ãã
èå¼±æ§ç®¡çã¯ãã®ãããããã¸ã¡ã³ããµã¤ã¯ã«ã®ä¸ã§ãèå¼±æ§ã®èª¿æ»ãã¨ããããã®ç¹å®ãã®é¨åã«å¯¾å¿ãã¾ãã èå¼±æ§ã®èª¿æ»ã§ã¯èå¼±æ§ã¹ãã£ãã使ã£ãã¹ãã£ã³æ¤æ»ãã»ãã¥ãªãã£å°éä¼ç¤¾ã«ããã»ãã¥ãªãã£è¨ºæã§å¯¾è±¡ãµã¼ãã¼ã®èå¼±æ§ãæ´ãåºãã¾ãã
次ã«æ´ãåºããèå¼±æ§ã«å¯¾ãã¦ãèå¼±æ§ã®æ·±å»åº¦ã¨å¯¾è±¡ãµã¼ãã¼ã®æ å ±è³ç£ã¨ãã¦ã®ä¾¡å¤çéè¦æ§ãæãåããã¦ãããé©ç¨ã®åªå é ä½ã決å®ãã¾ãããããããããã®ç¹å®ãã§ãã
èå¼±æ§ã®èª¿æ»
èå¼±æ§ã¹ãã£ãã§æ¤æ»ããã¨è£½åã«ããè¥å¹²ã®éããããã¾ããããããã以ä¸ã®ãããªé ç®ã®æ å ±ãã¬ãã¼ãã¨ãã¦åºåããã¾ãã
主ãªé ç® | é ç®ã®å 容 |
---|---|
èå¼±æ§ã®åå | èå¼±æ§ã®ä¸è¬å称 |
èå¼±æ§ã®æ¦è¦ | èå¼±æ§ã«ã¤ãã¦ã®è§£èª¬ |
å½±é¿ç¯å² | å½±é¿ãããããã¼ãã¦ã§ã¢ãã½ããã¦ã§ã¢ã®çæ°ç |
CVEçªå· | èå¼±æ§ãã¨ã«æ¯ãããä¸æãªçªå·ï¼å ±éèå¼±æ§èå¥åï¼ |
CVSSå¤ | å ±éèå¼±æ§è©ä¾¡ã·ã¹ãã ã«ããèå¼±æ§ã®æ·±å»åº¦ |
Exploitã®æç¡ | æ»æã³ã¼ãï¼exploitï¼ã®åå¨ |
解決ç | èå¼±æ§è§£æ±ºã®ããã®ãããæ å ±ãè¨å®æ å ± |
åé¿ç | 解決çãåããªãå ´åã解決çããªãï¼ãããããªãï¼å ´åã®åé¿ç |
å ±éèå¼±æ§èå¥åCVE(Common Vulnerabilities and Exposuresï¼ã¯ãåå¥è£½åä¸ã®èå¼±æ§ã対象ã¨ãã¦ãã¢ã¡ãªã«ã®MITRE社ãæ¡çªãã¦ããèå¥åã§ãã
æ¥æ¬ã§ãIPAã¨JPCERT/CCãå ±åã§ç®¡çã»éç¨ãã¦ããJNV(Japan Vulnerability Notesï¼ã¨ããèå¼±æ§ãã¼ã¿ãã¼ã¹ãããã¾ãããæ¥æ¬å½å ã§ãèå¼±æ§ã®ç®¡çã«ã¯CVEçªå·ã使ãã®ãä¸è¬çã§ãã
ãªããMITRE社ã«ã¤ãã¦ã¯å¼ç¤¾ã®ã»ãã¥ãªãã£ã³ã©ã ãMITRE ATT&CK ãã®1 ï½æ¦è¦ï½ãã«è©³ããæ¸ããã¦ãã¾ãã®ã§ãåç §ãã ããã
å ±éèå¼±æ§è©ä¾¡ã·ã¹ãã CVSS(Common Vulnerability Scoring Systemï¼ã¯èå¼±æ§ã®æ·±å»åº¦ã表ãææ¨ã®ä¸ã¤ã§ãããã³ãã¼ã«ä¾åããããªã¼ãã³ã§å æ¬çãæ±ç¨çãªè©ä¾¡æ¹æ³ã¨ãã¦ä½ããã¦ããããã¼ã¸ã§ã³ã¯å½éãã©ã¼ã©ã FIRSTï¼Forum of Incident Response and SecurityãTeamsï¼ã管çãã¦ãã¾ããç¾ç¶v2ã¨v3ã®ï¼ã¤ã®ãã¼ã¸ã§ã³ãããã¾ãã
èå¼±æ§ã®èª¿æ»ã¯æ¤æ»å¯¾è±¡ãã¼ããã¨ã«ãèå¼±æ§ã®åå¨ã¨ãã®æ·±å»åº¦ãã¾ã¨ããä½æ¥ã§ãã CVSSå¤ã¯0ï½10.0ã®å°æ°ç¹ä¸ä½ã®æ°å¤ã§è¡¨ãããv2ã§ã¯ãHigh/Medium/Lowãã®ä¸æ®µéãv3ã§ãCritical/High/Medium/Low/Noneãã®ï¼æ®µéã§æ·±å»åº¦ãã«ãã´ãªåããã¦ãã¾ãã
Score | CVSS v2 | CVSS v3 |
---|---|---|
9.0ï½10.0 | High | Critical |
7.0ï½8.9 | High | |
4.0ï½6.9 | Medium | Medium |
0.1ï½3.9 | Low | Low |
0 | None |
CVSSå¤ã®ãã¼ã¸ã§ã³ã«ããã«ãã´ãªã®éã
ãããã®ç¹å®
ãããã®ç¹å®ã§ã¯èå¼±æ§ã®æ·±å»åº¦ã¨ãµã¼ãã¼ã®æ å ±è³ç£ã¨ãã¦ã®ä¾¡å¤çéè¦åº¦ãæãåããã¦ãããé©ç¨ã®åªå é ä½ã決å®ãã¾ããã¤ã¾ããèå¼±æ§ã®æ·±å»åº¦ï¼å±éºåº¦ã¨ãè¨ããã§ãããï¼ãé«ãããµã¼ãã¼ã®åå¨ãéè¦ã§ä¿æãã¦ããæ å ±è³ç£ã®ä¾¡å¤ãé«ãå ´åã¯ãæåªå ã§ãããé©ç¨ãå¿ è¦ã¨ãããã¨ã§ãã
èå¼±æ§ç®¡çã®èª²é¡
èå¼±æ§ç®¡çã®æ§æè¦ç´ ã§ããèå¼±æ§ã®èª¿æ»ã¨ãããã®ç¹å®ã«ã¤ãã¦èª¬æãã¦ãã¾ãããã ã»ãã¥ãªãã£å°é家ã§ãªãæ å ±ã·ã¹ãã é¨éã®ã¡ã³ãã¼ãèå¼±æ§ç®¡çãé©æ£ã«å®æ½ãããã¨ã¯ç°¡åãªãã¨ã§ã¯ããã¾ããã ä¼æ¥ã®æ å ±ã·ã¹ãã é¨éã§èå¼±æ§ç®¡çãå®æ½ããéã«ã¯ä»¥ä¸ã®ãããªç¹ã課é¡ã¨ãªããã¨ãå¤ãã®ã§ã¯ãªããã¨èãã¾ãã
èå¼±æ§ã¹ãã£ã³æ¤æ»ã¯å·¥æ°ãããã
èå¼±æ§ã¹ãã£ã³æ¤æ»ãå®æ½ããéã«ã¯ãæ¤æ»åã«å¯¾è±¡ãµã¼ãã¼ã管çããç¾å ´ã¨å ¥å¿µãªèª¿æ´ãå¿ è¦ã§ããèå¼±æ§ã¹ãã£ã³æ¤æ»ã¯å¯¾è±¡ãµã¼ãã¼ã®ããã©ã¼ãã³ã¹ã«å½±é¿ãä¸ãããã¨ããããå ãã¦ã¹ãã£ã³ã«é·æéããããã¨ãããã¾ããã§ãã®ã§ãæ¬æ¥æ¥åã®å½±é¿ãã§ããéãæå°åããããã«ãã¹ãã£ã³æ¤æ»ãå®æ½ããæé帯ã®èª¿æ´ã¯éè¦ã§ãã ã¾ããèå¼±æ§ã¹ãã£ã³æ¤æ»ãå®æ½ããå ´åã¯ãç¾å°ã«æ å ±ã·ã¹ãã é¨éã®ã¹ã¿ãããèµ´ãã¹ãã£ããæä½ããå¿ è¦ãããã¾ãã ãã®ããã«äºå調æ´ããã³ã¹ãã£ã³æ¤æ»å®æ½ã«ã¯å·¥æ°ããããªãã«ãããããããããã¤ãã®ã·ã¹ãã ã§å®æ½ããããããæ å ±ã·ã¹ãã é¨éã«ã¯å¤ãã®å·¥æ°ãå¿ è¦ã¨ãªãçç±ã§ãã
ç·æ¥ç¹æ¤æã®æ©åæ§ããªã
èå¼±æ§ç®¡çã¯å®æçãªãããããã¸ã¡ã³ãã®ããã«ã ããããã®ã§ã¯ããã¾ãããä¸éãé¨ããé大ãªæ»æãçºçããå ´åãæ»æ対象ã¨ãªãèå¼±æ§ã®æç¡ãä¸æç·æ¥ç¹æ¤ãããã¨ããã°ãã°ããã¾ãã ãã®ãããªç·æ¥ãè¦ããã±ã¼ã¹ã§ã¯ãç¾å ´ã¨èª¿æ´ãããªããå®æ½ããããæ¹ã§ã¯æ©åæ§ããªããé大ãªèå¼±æ§ãªã¹ã¯ãé·æéæ¾ç½®ããçµæã«ãªãããã¾ããã
èå¼±æ§ã¹ãã£ã³çµæã®ã¨ãã¾ã¨ãã«å´åãããã
èå¼±æ§ã¹ãã£ãããåºåãããæ¤æ»çµæã¯ã·ã¹ãã ãã¨ã«æåã§éè¨ãããå¿ è¦ãããã¾ããã¾ããããããåæãèå¼±æ§ãªã¹ã¯ãè©ä¾¡ããçµå¶é£ã«å ±åããããã®è³æãä½æãããã¨ã«ãããã¸ããªå´åãããããã¨ã§ãããã
èå¼±æ§ç®¡çã®èª²é¡ | èå¼±æ§ç®¡çã½ãªã¥ã¼ã·ã§ã³ã«ããèªåå |
---|---|
èå¼±æ§ã¹ãã£ã³æ¤æ»ã¯å·¥æ°ãããã | ã»ã¹ã±ã¸ã¥ã¼ã«ã«æ²¿ã£ã¦èªåçã«èå¼±æ§ã¹ãã£ããèµ·å ã» ã¹ãã£ã³çµæãèªåçã«ä¸å çéç´ |
ç·æ¥ç¹æ¤æã®æ©åæ§ããªã |
ã»èå¼±æ§ã¹ãã£ãã«ä¸ææ¤æ»ãæ示 ã»ã¹ãã£ã³çµæãèªåçã«ä¸å çéç´ |
èå¼±æ§ã¹ãã£ã³çµæã®ã¨ãã¾ã¨ãã«å´åãããã |
ã»ä¸å
çã«éç´ããçµæãæ§ã
ãªè§åº¦ã§èªåçã«ã¬ãã¼ãã£ã³ã° ã»ããã·ã¥ãã¼ãã§èå¼±æ§ãªã¹ã¯ãèªåçã«è¦ããå |
èå¼±æ§ç®¡çã½ãªã¥ã¼ã·ã§ã³
èå¼±æ§ã½ãªã¥ã¼ã·ã§ã³ã¯å®æçã«èå¼±æ§ã¹ãã£ã³æ¤æ»ãå®æ½ãèå¼±æ§ãªã¹ã¯ã®å®ç¹è¦³æ¸¬ãè¡ãããã®ã½ãªã¥ã¼ã·ã§ã³ã§ãã
èå¼±æ§ç®¡çã½ãªã¥ã¼ã·ã§ã³ã¯ä¸»ã«èå¼±æ§ã¹ãã£ãã¨ãããã管çãããµã¼ãã¼ã¨ã§æ§æããã¦ãã¾ãã
管çãµã¼ãã¼ãä¼æ¥å
ã«è¨ç½®ãããã®ã®ä»ã管çãµã¼ãã¼ãã¯ã©ã¦ãã§æä¾ããSaaSåã½ãªã¥ã¼ã·ã§ã³ããããã¾ãã
èå¼±æ§ç®¡çã½ãªã¥ã¼ã·ã§ã³ã®å¤§ã¾ããªæµãã¯ä¸è¨ã®ã¨ããã§ãã
â èå¼±æ§ã¹ãã£ã³ã®ã¹ã±ã¸ã¥ã¼ãªã³ã°
èå¼±æ§ã¹ãã£ããã¹ãã£ã³ãå®è¡ããã«ãããå¿
è¦ãªæ
å ±ãã¹ãã£ãã«è¨å®ããã¹ãã£ã³ããæ¥æãã¹ã±ã¸ã¥ã¼ãªã³ã°ãã¾ãã
â¡èå¼±æ§ã¹ãã£ã³ã®å®è¡ã¨çµæéç¥
ã¹ã±ã¸ã¥ã¼ãªã³ã°ãããæ¥æã«èªåçã«èå¼±æ§ã¹ãã£ã³ãå®æ½ãããã®çµæã管çãµã¼ãã¼ã«éãã¾ãã
ã¾ããç·æ¥ä¸ææ¤æ»ã®å ´åã¯ã管çãµã¼ãã¼ãæä½ãã¹ãã£ãã«å¯¾ãã¦èª¿ã¹ããèå¼±æ§ã«ãã©ã¼ã«ã¹ãã¦ãªã¢ã«ã¿ã¤ã ã«ã¹ãã£ã³ããããæ示ãåºãã¾ãã
â¢ã¹ãã£ã³çµæã®éè¨ããã³è¦ããå
ã¹ãã£ã³çµæã¯éè¨ããèªåçã«ã¹ãã£ã³ã¬ãã¼ãã¨ãã¦æå½¢ããã¾ãã
ã¾ããããã·ã¥ãã¼ã表示ã«ããä¼æ¥å
¨ä½ã®èå¼±æ§ãªã¹ã¯ã®ç¶æ³ãè¦ããåãã¾ãã
èå¼±æ§ç®¡çã½ãªã¥ã¼ã·ã§ã³ã¯æµ·å¤è£½åãä¸å¿ã«ãã¾ãã¾ãããã¾ãããå½ç¤¾ã§åãæ±ã£ã¦ãããã®ã¯ä¸è¨ã®ï¼è£½åã§ãããã¾ãã
åªå é ä½ä»ãã®èªååã¯ã©ãããã®ã
以ä¸ã®ããã«èå¼±æ§ç®¡çã½ãªã¥ã¼ã·ã§ã³ãå°å ¥ãããã¨ã«ããããããããã¸ã¡ã³ããµã¤ã¯ã«ã®ãã¡ãèå¼±æ§ã®èª¿æ»ãèªååããå¹ççå¹æçãªèå¼±æ§ç®¡çãå®ç¾ãããã¨ãã説æãã¾ããã
ããã§ã¯ãããã®ç¹å®å·¥ç¨ã§ã®èªååã¯ã©ã®ããã«è¡ãã®ã§ããããã
ãããã®ç¹å®å·¥ç¨ã§ã¯ãèå¼±æ§ã®æ·±å»åº¦ã¨æ å ±è³ç£ã®éè¦æ§ããããããã¦ãããé©ç¨ã®åªå é ä½ã決ããå·¥ç¨ã§ããã ãã®å·¥ç¨ãèªååã®ããã«ã¯SOAR(Security Orchestration, Automation and Response)ã®å°å ¥ãæé©ã§ãã
SOARã®æ¦å¿µ
SOARã¨ã¯ä¼æ¥ãå°å ¥ãã¦ãããã¾ãã¾ãªã»ãã¥ãªãã£ã½ãªã¥ã¼ã·ã§ã³ãåºåããæ å ±ï¼ãã°ãã¤ãã³ãçï¼ãSIEM(Security Information and Event Management)ãçºããã¤ã³ã·ãã³ãæ å ±ãèå¼±æ§ç®¡çã½ãªã¥ã¼ã·ã§ã³ã®èå¼±æ§ã¹ãã£ã³çµæãå¤é¨ã®ã¤ã³ããªã¸ã§ã³ã¹ãµã¼ãã¹ã®å¤ç¨®å¤æ§ãªæ å ±ãã¤ã³ãããã¨ãã¦éç´ãããããã®ãªã¢ã¯ã·ã§ã³ï¼ã¢ãããããï¼ãèªåçã«è¡ãããã®ãã©ãããã©ã¼ã ã§ãã ãããé©ç¨ã®åªå é ä½ä»ããèªååããããã«ã¯ãæ å ±è³ç£ã®æ§æ管çãã¼ã¿ãã¼ã¹ã«ãããµã¼ãã¼æ å ±ã¨ãèå¼±æ§ã¹ãã£ã³ã®çµæãæãåããã¦åªå é ä½ã®èªååå¦çãè¡ãSOARã®æ©è½ã使ã£ã¦å®ç¾ãã¾ãã
ãªããSOARãå°å ¥ããã«ã¯ã½ãªã¥ã¼ã·ã§ã³ã®çµã¿åããã«é¢ããç¥è¦ãã»ãã¥ãªãã£éç¨æ¥åã®ç¥è¦ãªã©ãç·åçã«è¨è¨ã«åæ ããå¿ è¦ãããã¾ãã®ã§ããµã¼ãã¹éå§ã¾ã§ããªãæéãããããã¨ãä»ãå ãããã¦ããã ãã¾ãã
çµããã«
ãã¦ãèå¼±æ§ç®¡çã®èªååã«ã¤ãã¦ãåèã«ãªã£ãã§ããããã
çæ§ã®é¢ä¿ãã¦ããæ å ±ã·ã¹ãã ã®èå¼±æ§ãªã¹ã¯ã軽æ¸ãããæ¬æ¥æ¥åãæ»ããªãéè¡ããããã®ä¸å©ã¨ãªãã°å¹¸ãã§ãã ããã§ä¸åã«ãããã話ãã¦ã¾ããã¾ãããããããã¸ã¡ã³ãã®èªååã«ã¤ãã¦çãç½®ãããã¨æãã¾ãã ã³ã©ã ããèªã¿ããã ããããã¨ããããã¾ããã