
ã©ã³ãµã ãŠã§ã¢ã¯PCãŠãŒã¶ãŒã«ãšã£ãŠå€§ããªè
åšã§ããããã®æŽ»åã¯æéã®çµéãšãšãã«
å¢å ããŠããŸãã ã·ã¹ã³ã®æè¿ã®å幎ããšã®
ã¬ããŒãã«ãããš ãã©ã³ãµã ãŠã§ã¢ã¯ãã«ãŠã§ã¢åžå Žãæ¯é
ããŠãããéå»ã®æ»æè
ã«ãšã£ãŠæãåçæ§ã®é«ãã¿ã€ãã®ãã«ãŠã§ã¢ã§ãã ã©ã³ãµã ãŠã§ã¢ã«ã€ããŠã¯ãã§ã«å€ãã®ããšãæžãããŠãããã»ãšãã©ã®äººã¯èªåãäœã§ããããçè§£ããŠããŸãã ã©ã³ãµã ãŠã§ã¢ã¯ããŸããŸãªããªãã¯ã䜿çšããŠã被害è
ã®ã³ã³ãã¥ãŒã¿ãŒãŸãã¯ãã¡ã€ã«ãžã®ã¢ã¯ã»ã¹ããããã¯ãããã®åŸã身代éãèŠæ±ããŠããããžã®ã¢ã¯ã»ã¹ã埩å
ããŸãã æè¿ããŠãŒã¶ãŒãã¡ã€ã«ã®æå·åãå°éãšããã©ã³ãµã ãŠã§ã¢ãšã©ã³ãµã ãŠã§ã¢ã®æŽ»åã倧å¹
ã«å¢å ããŠããŸãã 䜿çšããæå·åæ¹æ³ãæ€èšããŠãã ããã
äžè¬çãªæ
å ±
ãã®ãããªãããžãã¹ãã®æåã¯ããŠãŒã¶ãŒãã¡ã€ã«ãžã®ã¢ã¯ã»ã¹ããããã¯ããããã«ã©ã®çšåºŠæåãããã«ãã£ãŠæ±ºãŸããããæå·åã¯æå·åã®éèŠãªèŠçŽ ã§ãã æå·åèªäœã¯ãæªæã®ããæ¹æ³ãæäœã§ã¯ãããŸããã äžæ£ã¢ã¯ã»ã¹ããããŒã¿ãä¿è·ããããã«ãäžè¬ãŠãŒã¶ãŒãäŒæ¥ãæ¿åºã䜿çšãã匷åã§åæ³çãªããŒã«ã§ãã
æå·äœæè
ã¯ããŠãŒã¶ãŒããŒã¿ããçããããã«èšèšãããŠããŸãã 圌ãã¯ãã®ç®çã®ããã«æå·åã䜿çšããŸããæå·åããŒãç¥ããªããããæ£åœãªææè
ãžã®ããŒã¿ãžã®ã¢ã¯ã»ã¹ãé²ãæ©äŒãäžããŸãã ãã®ããŒãç¥ã£ãŠããæ»æè
ã®ã¿ãããŒã¿ã«ã¢ã¯ã»ã¹ã§ããŸãã
ã·ã¹ãã ã§ã®èµ·ååŸãæå·åããã°ã©ã ã¯ããã¡ã€ã«ã·ã¹ãã ã®ãã¡ã€ã«ãŸãã¯éèŠãªãµãŒãã¹ããŒã¿ããå
ã®ç¶æ
ã«åŸ©å
ããããšã«ãã£ãŠã®ã¿èªã¿åããããã«å€æŽãå§ããŸãã æ¬¡ã«ããã®æäœã§ã¯ããã¡ã€ã«åŸ©å·åããŒã䜿çšããå¿
èŠããããŸãããããã¯æ»æè
ã®ã¿ãç¥ã£ãŠããŸãã æããã«ããã®å Žåãæå·åããã³é埩å·åæäœã¯æªæã®ããç®çã«äœ¿çšãããŸãã
ããã«ããã«ãŠã§ã¢äœæè
ã¯ããã«ãŠã§ã¢ãšãã®ç®¡çCïŒCãµãŒããŒãšã®å®å
šãªçžäºäœçšã®ããã«æå·åã䜿çšããŸããããã«ãããããŒã¿ãè§£èªããããã«å¿
èŠãªããŒãæ ŒçŽãããŸãã ãã®ããŒã䜿çšããŠããã¡ã€ã«ã·ã¹ãã ããŒã¿ãŸãã¯ãã¡ã€ã«èªäœãå
ã®ç¶æ
ã«åŸ©å
ã§ããŸãã
æå·åã®äœæè
ã¯ã察称æå·åãšé察称æå·åã®äž¡æ¹ã®ã¿ã€ãã®æå·åãå©çšããŸãã ããã«ãããããŒã¿ãæå·åãããšãã«æé©ãªããã©ãŒãã³ã¹ãšå©äŸ¿æ§ãåŸãããŸãã 察称æå·åã¹ããŒã ã®å ŽåãããŒã¿ã®æå·åãšåŸ©å·åã®äž¡æ¹ã«åãç§å¯éµã䜿çšãããŸãã é察称æå·åã§ã¯ããã©ã€ããŒããšãããªãã¯ã®2ã€ã®ããŒã䜿çšãããŸãã 1ã€ç®ã¯ãµã€ããŒç¯çœªè
ã«ã®ã¿ç¥ãããŠãããããŒã¿ã®è§£èªã«äœ¿çšããã2ã€ç®ã¯å
¬éãããŠããŒã¿ã®æå·åã«äœ¿çšãããŸãã
察称æå·åã¯ãå©äŸ¿æ§ãšããã©ãŒãã³ã¹ã®ç¹ã§æå·åã«åœ¹ç«ã¡ãæªæã®ããããã°ã©ã ã劥åœãªæéå
ã«ããŒã¿ãæå·åã§ããããã«ããŸãã äžæ¹ãé察称æå·åã¯å¯Ÿç§°ããŒã®æå·åã«äœ¿çšãããŸãããããã¯ç°ãªãå ŽåããããŸãã ãããã£ãŠãæ»æè
ã¯ç¹å®ã®ææäºäŸããšã«ããŒãä¿åãã代ããã«ããã¹ãŠã®è¢«å®³è
ã«å¯ŸããŠ1ã€ã®åŸ©å·åããŒããµããŒãã§ããŸãã
å³ 1.æå·åã§äœ¿çšããã察称ããã³é察称æå·åã®äœæ¥ã¹ããŒã ã察称ããŒä¿è·ã¡ã«ããºã ã¯å€æŽã§ããŸãããååãšããŠãæªæã®ããããã°ã©ã ã®æ¬äœã«ããå
¬éããŒã䜿çšãããããå¶åŸ¡ããCïŒCãµãŒããŒããæœåºãããæå·åã«äœ¿çšãããŸãã æå·åããã»ã¹ãå®äºãããšãå€ãã®å Žåã察称ããŒããµãŒããŒã«éä¿¡ããããã被害è
ã®ã·ã¹ãã ã«ä¿åãããŸãã
管çCïŒCãµãŒããŒãšã®çžäºäœçš
æå·äœæè
ã¯ãCïŒCãµãŒããŒãæäœãããšãã«æå·åã䜿çšããŠãéä¿¡ããŒã¿ã®æ©å¯æ§ãä¿æããæªæã®ããæŽ»åãé ããŸãã CïŒCã䜿çšããå Žåãæå·äœæè
ã®ä»¥åã®ãã¡ããªãŒããã³ããŒãžã§ã³ã¯ãæ©å¯æ§ã«ç¹ã«æ³šæãæããŸããã æ°ãããã¡ããªãšå€æŽã¯ã
TLSãªã©ã®ãããã³ã«ã«å®çžŸã®ããæå·åæšæºã䜿çšã
ãŸã ã
䟵害ãããã·ã¹ãã ãšãµãŒããŒéã®ãã©ãã£ãã¯ã®æå·åã¯ããªã³ã©ã€ã³ãã³ãã³ã°ãªã©ã®æ£åœãªæäœã§äœ¿çšãããæå·åãããã³ã«ãšåºå¥ããããšãé£ãããããæªæã®ããã¢ã¯ãã£ããã£ãæ€åºããã¿ã¹ã¯ãããå°é£ã«ããŸãã
æå·åããããã©ãã£ãã¯ãæ€æ»ããã«ã¯ããããã¯ãŒã¯ã»ãã¥ãªãã£æ©èœã«ã¯ã被害è
ã®ãããã¯ãŒã¯ã®è¿œå æ©èœãå¿
èŠã§ãã ããšãã°ãTLSã§æå·åããããã©ãã£ãã¯ããã§ãã¯ããã«ã¯ãå
éšãããã¯ãŒã¯äžã®ã³ã³ãã¥ãŒã¿ãŒãšãªã¢ãŒããµãŒããŒéã®ããŒã¿è»¢éãã¹ã«ããIDS / IPSãœãªã¥ãŒã·ã§ã³ã䜿çšã§ããŸãã TLSãã©ãã£ãã¯ã®ãã§ãã¯ã¯ã䜿çšãããŠãããŠã€ã«ã¹å¯ŸçããŒã«ã®æ©èœã«å¿ããŠãã³ã³ãã¥ãŒã¿ãŒèªäœã®ã¬ãã«ã§ãå¯èœã§ãã
å
éšãããã¯ãŒã¯ã«ãã©ãã£ãã¯ã远跡ããæ©èœããªãå Žåããã«ãŠã§ã¢ã¯æå·åã䜿çšããŠCïŒCã«æ¥ç¶ããŸããCïŒCã¯ãCïŒCã¢ãã¬ã¹ãæ€åºãããæªæã®ããIPã¢ãã¬ã¹ãšãã¡ã€ã³ã®ãã©ãã¯ãªã¹ãã«è¿œå ããããŸã§æ€åºãããŸããã ãããã£ãŠããã®ä¿è·æ¹æ³ã¯ããåå¿çã§ãã
æå·åã®å®è£
ã®ãšã©ãŒ
ESETã®å°éå®¶ã¯ãã©ã³ãµã ãŠã§ã¢ã®é²åã«é¢ããã¬ããŒãããã§ã«
å
¬éããŠãããã©ã³ãµã ãŠã§ã¢ã®æ®åçãæããã«ãªã£ãŠããŸãã æå·åè£
眮ã®ãã¡ããªãšå€æŽã®æ°ã¯2011幎以é倧å¹
ã«å¢å ããŠããŸããããã«ãã©ã³ãµã ãŠã§ã¢ãåäœããããã«èšèšãããŠãããã©ââãããã©ãŒã ã®æ°ãå¢å ããŠããŸãã
å³ 2. 2011幎ãã2015幎ãŸã§ã®æéã«ãããæå·åã®æ®åæ®ãã®åæã¯ãé²åã®ããŸããŸãªæ®µéã§ã®æå·åã®4ã€ã®ãã¡ããªãŒã§ã®æå·åã®å®è£
æ¹æ³ã«åœãŠãããŸãïŒCryptoDefenseïŒ2014ïŒãTorrentLockerïŒ2014ïŒãããã³äººæ°ã®ããTeslaCryptïŒ2015ïŒããã³PetyaïŒ2016ïŒã

ç§ãã¡ã®ç ç©¶ã®ç®çã¯ãæå·äœæè
ãæéã®çµéãšãšãã«ã©ã®ããã«é²åãããã瀺ããèè
ã®ééããæããªãã®ããããè€éãªãã®ãŸã§åæããããšã§ãã
CryptoDefenseã©ã³ãµã ãŠã§ã¢ããµã€ããŒç¯çœªè
ã«ãã£ãŠäœ¿çšãããŠãããšæåã«èŠããããšãããã®èª¿æ»ã¯CryptoLockerã«éåžžã«é¡äŒŒããŠããããšã瀺ããŸããã åŸè
ã¯ããã®çš®ã®æå·åè£
眮ãšããŠã¯åããŠã®ãã®ã§ãã CryptoDefenseãããã¡ã€ã«ãæå·åããããã»ã¹ã ãã§ãªãã管çããCïŒCãµãŒããŒãšå¯Ÿè©±ããã¡ã«ããºã ã®å®è£
ã«éå€§ãªæ¬ é¥ãããããšã¯æ³šç®ã«å€ããŸãã
CïŒCã䜿çšããããã®ãããã³ã«ã¯ãææãããã¹ãããæªæã®ããããã°ã©ã ã«ãã£ãŠéä¿¡ãããHTTPãããã³ã«ã®POSTèŠæ±ã®äœ¿çšã«åºã¥ããŠããŸãã CïŒCã§ã®äœæ¥æã«ã»ãã¥ãªãã£ã確ä¿ããããã«ãCryptoDefenseã¯HTTPãããã³ã«ã®POSTãªã¯ãšã¹ãã§URLé£èªåã䜿çšããŸããã ãããã£ãŠãã¡ãã»ãŒãžã®æå·åã«äœ¿çšãããæå·åããŒã¯é ãããŠããŸããã POSTèŠæ±ã®æ¬æã«ã¯ãRC4ã¢ã«ãŽãªãºã ãšPOST URLã®ç§å¯ããŒã䜿çšããŠæå·åãããCïŒCãããã³ã«ã¡ãã»ãŒãžãå«ãŸããŠããŸããã
å³ 3. CryptoDefenseã©ã³ãµã ãŠã§ã¢ã®CïŒCãããã³ã«ã®è§£èªãæå·åãããCryptoDefenseã¡ãã»ãŒãžãååããå Žåãç°¡åã«è§£èªã§ããŸãã POSTèŠæ±èªäœã«ã¯ãæå·åããŒã埩å
ããCïŒCãšã®çžäºäœçšã®ãããã³ã«ã®ã¡ã«ããºã ãé瀺ããããã«å¿
èŠãªãã¹ãŠã®æ
å ±ãå«ãŸããŠããŸãã ããã«ããããããã¯ãŒã¯çœ²åãäœæããŠãã©ã³ãµã ãŠã§ã¢ã®ã¢ã¯ãã£ããã£ãæ€åºãããã®æªæã®ããã¢ã¯ã·ã§ã³ãç¹ã«ãã€ããŒãã®æ£ããåäœããããã¯ããããšãã§ããŸãã
ãã¡ã€ã«æå·åã®å Žåãã¢ã«ãŽãªãºã ã®å®è£
ã«ããããšã©ãŒã¯é©ãã»ã©ä»¥åã®ãã®ãšé¡äŒŒããŠããŸãã ãããçè§£ããããã«ãCryptoLockerã©ã³ãµã ãŠã§ã¢ã®ã¢ã¯ã·ã§ã³
ãå®è¡ãã
ã¢ã«ãŽãªãºã ãæ€èšããŠãã ããã
- 被害è
ã䟵害ãããåŸãã©ã³ãµã ãŠã§ã¢ã¯ããã«ã€ããŠCïŒCãµãŒããŒã«éç¥ãããã£ã³ããŒã³èå¥åïŒIDïŒãšäžæã®ã·ã¹ãã IDã瀺ããŸãã
- 管çCïŒCãµãŒããŒã¯ã確èªã®OKã¡ãã»ãŒãžã§å¿çããŸãã
- ã¯ã©ã€ã¢ã³ãã¯ããã£ã³ããŒã³èå¥åãšäžæã®ã·ã¹ãã èå¥åãæå®ããŠããµãŒããŒã«å床ã¢ã¯ã»ã¹ããŸãã
- ãµãŒããŒã¯ãã©ã³ãµã ãŠã§ã¢ã«ã©ã³ãµã ãªã¯ãšã¹ãã¡ãã»ãŒãžãšããã£ã³ããŒã³IDãšè¢«å®³è
ã·ã¹ãã IDã®ãã®çµã¿åããã«å¯ŸããŠçæãããããŒãã¢ããã®RSA-2048å
¬éããŒãæäŸããŸãã ãã®ãã¢ããã®ç§å¯éµã¯ãCïŒCãµãŒããŒããé¢ããããšã¯ãããŸããã
- ã©ã³ãµã ãŠã§ã¢ã¯ãCïŒCãµãŒããŒã«å¯ŸããŠã身代éã¡ãã»ãŒãžãšå
¬éããŒãæ£åžžã«åãå
¥ããããããšã確èªããŸãã ãŸãããã¡ã€ã«æå·åããã»ã¹ã®çµäºã確èªããŸãã
CryptoLockerã®ã¡ã«ããºã ã®è匱æ§ã¯ãã¹ããã3ãš4ãååšããããšã§ãããã®å ŽåããŠãŒã¶ãŒã¯ã©ã³ãµã ãŠã§ã¢ãCïŒCãµãŒããŒãšæ£åžžã«éä¿¡ããå Žåã«ã®ã¿ãã¡ã€ã«ãæå·åã§ããããã§ãã ãããã®ã¹ãããã¯CryptoDefenseã¢ã«ãŽãªãºã ã§åé€ããã被害è
ã®ã·ã¹ãã èªäœã«ããŒãã¢ãçæãããŸãã
ããããCryptoDefenseã®äœæè
ã¯ãã©ã³ãµã ãŠã§ã¢ãã·ã¹ãã ããRSAç§å¯éµãåé€ããããšãå¿ããŠãããšããã现éšã®èŠèœãšãã
倱ããŸãã ã ãã®ããŒã¯ãæå·åããããã¡ã€ã«ãè§£èªããããã«
䜿çšã§ããã·ã¹ãã ã§èŠã€ããããšãã§ããŸãã ãã®åŸãWindows API颿°ã®1ã€ã䜿çšããŠããã¡ã€ã«ãè§£èªããŸãã
ãããã£ãŠãCryptoDefenseã®äœæè
ã¯ã©ã³ãµã ãŠã§ã¢ã®1ã€ã®ãšã©ãŒãä¿®æ£ããŸããããããã«2ã€ç®ã®ãšã©ãŒãäœæããŸããã
ãã¬ã³ãããã«ãŒ
TorrentLockerã®ä»¥åã®ããŒãžã§ã³ã«ãæå·åã®å®è£
ã«
ãšã©ãŒãå«ãŸããŠããŸããããCTRã¢ãŒãã®éåžžã«å®å
šãªAESãã¡ã€ã«æå·åã¢ã«ãŽãªãºã ã«äŸåããŠããŸããã ãã ãããã®ã¢ã«ãŽãªãºã ã®å®è£
æ¹æ³ã«ãããäžè¬çãªæå·åã¹ããŒã ã«è匱æ§ãååšããããšã«ãªããŸããã
AESã¢ã«ãŽãªãºã ã¯
ãããã¯æå·ã§ã ãã€ãŸããåºå®ãµã€ãºïŒ16ãã€ãïŒã®ãããã¯ã«ããããŒã¿ã®æå·åãæå³ããŸãã
CTRã¢ãŒãã®AESã¯ãåæåãã¯ãã«ãŸãã¯åæåãã¯ãã«ïŒIVïŒãšåŒã°ããåæå€ãå
¥åãšããŠåãå
¥ããããŒå€ïŒ128ã192ããŸãã¯256ãããã®ããã容éãæã€ïŒãæå·åãããããŒã¿ã®ãµã€ãºïŒããŒãšåŒã°ããïŒã«æ¡åŒµããŸãã¹ããªãŒã ïŒããŒã¹ããªãŒã ïŒã ãã®åŸãå
ã®ã¡ãã»ãŒãžã®ããŒã¿ã«å¯ŸããXORæŒç®ãããŒã¹ããªãŒã ã«é©çšãããã¹ããªãŒã æå·ã®æŠå¿µãæš¡å£ããŸãã
TorrentLockerã®æå·åå®è£
ã®åŒ±ç¹ãå©çšããããšã¯éåžžã«ç°¡åã§ããã䟵害ãããã·ã¹ãã ã§ã¯ãã©ã³ãµã ãŠã§ã¢ã¯2MBã®ããŒã¹ããªãŒã ãçæããåãã¡ã€ã«ã®æåã®2MBãæå·åããŸãã ãã¡ã€ã«ãµã€ãºã2MBæªæºã®å Žåããã®æ¹æ³ã䜿çšããŠå®å
šã«æå·åãããŸãã
ãã ããAES-CTRã䜿çšããããšã¯ãåæåãã¯ãã«ãšã¹ããªãŒã æå·ããŒãåå©çšããããšãšãŸã£ããåãã§ãããããã¯ãæå·åŠã®åå¿è
ã«ããããééãã§ãã å°ãªããšã1ã€ã®æå·åããããã¡ã€ã«ãšãã®å
ã®ãœãŒã¹ã³ã³ãã³ãããããããããŒã¹ããªãŒã ã埩å
ããæ®ãã®ãã¡ã€ã«ãè§£èªããã®ã¯éåžžã«ç°¡åã§ãã TorrentLockerã®ä»¥éã®ããŒãžã§ã³ã§ã¯ãäœæè
ã¯ãAES CTRæäœã¢ãŒããCBCã«çœ®ãæããããšã§ãã®ãšã©ãŒãä¿®æ£ããŸãããããã«ã€ããŠã¯ãTeslaCryptã®æ¬¡ã®ã»ã¯ã·ã§ã³ã§èª¬æããŸãã
å³ 4. CTRæå·åã¢ãŒãã¹ããŒã ãããã£ã¢
Petyaã©ã³ãµã ãŠã§ã¢ã¯ãä»ã®ã©ã³ãµã ãŠã§ã¢ãšã¯ç°ãªãã¢ãããŒãã䜿çšããŠãæªæã®ããæ©èœãå®è¡ããŸãã åãã¡ã€ã«ãåå¥ã«æå·åãã代ããã«ããã£ã¹ã¯ãŸãã¯ãã¡ã€ã«ã·ã¹ãã ã®ããŒã¿æ§é ã䟵害ããããšããŸãã Petyaã®ç®æšã¯ãOSã®èµ·åã«äœ¿çšããã被害è
ã®ãã¹ã¿ãŒããŒãã¬ã³ãŒãïŒMBRïŒã»ã¯ã¿ãŒã§ãã
Petyaã®èè
ã¯ãæ°ããã¹ããªãŒã æå·ã§ããeSTREAMãèå¥ãããããžã§ã¯ãã«å±ããSalsa20æå·åã¢ã«ãŽãªãºã ãéžæããŸããã ãã®ã€ãã·ã¢ããã¯ãåŸæ¥ã®RC4ã¿ã€ãã眮ãæããæ°ããã¹ããªãŒãã³ã°ãã©ã³ãã®éçºãä¿é²ãããããžã§ã¯ãã§ãã Petyaã«ããSalsa20æå·ã®äœ¿çšã¯ãæå·äœæè
ã®é²åãæå³ããŸããæå·äœæè
ã¯çŸåšãããä¿¡é Œæ§ã®é«ãæ°ããæå·ã䜿çšããŠããŸãã
Petyaãå®è¡ã®ããã«èµ·åããããšãã·ã¹ãã ææããã»ã¹ãéå§ããŸãããã®ããã»ã¹ã¯
2ã€ã®æ®µéã§æ§æãããŸãã MBRæå·åããã»ã¹ã¯ããªãããŸãå®è£
ãããŠããŸãã MBRã倿Žããããšããéå§ããBSODãåŒã³åºããŠããŠãŒã¶ãŒã«ã·ã¹ãã ã®åèµ·åã匷å¶ããŸãã åèµ·ååŸããŠãŒã¶ãŒã«ã¯æåãªCHKDSKããŒã«ã®åœã®ç»é¢ã衚瀺ãããPetyaã¯è¿œå ã®MBRæå·åæäœãå®è¡ããŸãã ãã®åŸã圌ã¯åã³ã·ã¹ãã ãåèµ·åãã身代éèŠæ±ã®ããã¹ããšãšãã«åšå§çãªç»åããŠãŒã¶ãŒã«è¡šç€ºããŸãã
å³ 5.身代éãèŠæ±ããæå·äœæè
Petyaã®æããããŠãŒã¶ãŒç»åãæããã身代éèŠæ±ã¡ãã»ãŒãžã«ãããããããäœè
ãã©ã³ãµã ãŠã§ã¢ã³ãŒãã«
è¿·æãªãšã©ãŒãç¯ãããããMBRãè§£èªããæ¹æ³ããããŸãã ãµã€ããŒç¯çœªè
ã«é Œããã«MBRã埩å·åã§ããæãéèŠãªæ¬ ç¹ã¯ãæå·åããã°ã©ã ãMBRã䜿çšããŠå埩ããŒãååŸããæ¹æ³ã§ãã
ãã®æ¬ ç¹ã®æ¬è³ªãçè§£ããããã«ãäžæ¹ã§æå·åã®ç¶æ³ãèæ
®ããŸãã ãŸããæ»æè
ã被害è
ã«æäŸããå埩ããŒã䜿çšããŠãã¡ã€ã«ã埩å·åããããã»ã¹ã調æ»ããŸãã ãã®åŸãããŒå
šäœãç¥ããªããŠããå®è£
ã®ãã®ãã°ã䜿çšããŠMBRã埩å·åããæ¹æ³ã説æããŸãã
埩å·åããŒã®æåã»ããã®ãã£ãŒã«ãã¯54æåã«å¶éãããŠããããã®é·ãã¯åºå®ã§16æåã§ãã ãŠãŒã¶ãŒã身代éèŠæ±ã§ã¡ãã»ãŒãžãã£ãŒã«ãã«ããŒãå
¥åãããšããã«ãããŒããã§ãã¯ãããŸãã æ€èšŒããã»ã¹äžã«ãå
¥åãããå埩ããŒã¯ãç¹å¥ãªã¢ã«ãŽãªãºã ã䜿çšããŠæå·åããŒã®32ãã€ãã«æ¡åŒµãããã·ãŒã±ã³ã¹å
ã®æ€èšŒãããã¡ãŒãšæ¯èŒãããŸãã ãšã³ã³ãŒããããããŒãæ€èšŒãããã¡ãŒãšäžèŽããå ŽåãSalsa20æå·åã¢ã«ãŽãªãºã å®è£
颿°ïŒå®éã¯
Salsa10 ïŒã®å
¥åã«å
¥ãããã®åŸãã£ã¹ã¯ã»ã¯ã¿ãŒã®ããŒã¿ã埩å·åãããŸãã
ããŒã®æ¡åŒµæ¹æ³ã¯å埩ããŒã«å¯ŸããŠå®è¡ããããµã€ãºã2å
ã«ãªããŸãããæ¡åŒµã¢ã«ãŽãªãºã ã¯æ±ºå®è«çã§ãããããããŒã®
ãšã³ããããŒã¯è¿œå ãããŸããã ãããã£ãŠããã®å Žåã®ã»ãã¥ãªãã£ã¯54 ^ 16ã®ç°ãªãããŒã®æ°ã«ãã£ãŠå¶éãããŸããããã¯ã92ãããã®ã»ãã¥ãªãã£ã¬ãã«ïŒã€ãŸããlog2ïŒ54 ^ 16ïŒ= 92.07ïŒã«å¯Ÿå¿ââããç²éãªã¡ãœããã®äœ¿çšæåã®ç¯å²ãè¶
ããŠããŸãããšãã°ãNSAã«ã¯æå€§80ãããé·ã®ããŒ
ãå埩åŠçãã
æ©èœããããŸãã
Petyaã®äœè
ã¯ãæå·åããã»ã¹ã§äœ¿çšãããããããã¡ã€ã³ããŒãã«ãã宿°ãšããŒãå«ã16ã¯ãŒãã®é
åãäœæããã¡ã€ã³é¢æ°Salsa20ã®å®è£
ã«
誀ããç¯ããŸããã æå·ã®äœæè
ã¯ã16ãããã¢ãŒããã¯ãã£ããµããŒãããããã«æ¢åã®
Salsa20å®è£
ãä¿®æ£ããŸããããéèŠãªéšåãèŠéããŠããŸããã Salsa20ã®å®è£
ã«çްå¿ã®æ³šæãæãçç±ã¯ãã©ã³ãµã ãŠã§ã¢ã³ãŒãã®
å®è¡ã¢ãŒãã§ãã Petyaã¯ããŒãããŒããŒãšããŠåäœããããã«èšèšãããŠãããããx86ãã€ã¯ãããã»ããµã®16ããããªã¢ã«ã¢ãŒãã§åäœããŸãã
äžèšã®é
åãäœæããã«ã¯ãã¡ã€ã³ããŒãã«ã®2ã€ã®ã³ããŒãçŽæ¥ãã€ãé ïŒãªãã«ãšã³ãã£ã¢ã³ïŒã®åœ¢åŒã§äœæããŸãã æå·äœæè
ã®äœæè
ã¯ãuint32_tåã®å€æ°ãuint16_tã«å€æŽããŠãã³ãŒãã16ãããã¢ãŒããã¯ãã£ã«é©åãããŸããã ãã ããSalsa20ã®ã¡ã€ã³æ©èœã§ã¡ã€ã³ããŒãã«ãæäœããå Žåãæ°ãããããæ·±åºŠãé©çšããŠãµã€ã¯ã«ãå®è¡ããããšãæ ã£ãŠããŸããã ãã®ãšã©ãŒã«ããã2ãã€ããèªã¿åã£ãåŸã次ã®ããŒã¿èªã¿åãæäœã®ãªãã»ããã2ãã€ãã§ã¯ãªãã4ãã€ãå¢å ããŸãã
å³ 6. 16ãããã¢ãŒããã¯ãã£ã®Salsa20ã®å®è£
ãšã©ãŒããã®ãããå®éã«ã¯ãSalsa20æå·åæäœã«é¢äžããã®ã¯ããŒã®ååã®ã¿ã§ãã ããã«ãããPetyaæå·åã¹ããŒã å
šäœã®ã»ãã¥ãªãã£ã¬ãã«ã92ããããã46ãããã«äœäžããŸãã ãã®å ŽåãããŒã¯ãã«ãŒããã©ãŒã¹æ¹åŒã䜿çšããŠãéåžžã®ã³ã³ãã¥ãŒã¿ãŒã§ãæ°ç§ä»¥å
ã«ååŸã§ããŸãã
ãã¹ã©ã¯ãªãã
TeslaCryptã©ã³ãµã ãŠã§ã¢ãæãæåããã©ã³ãµã ãŠã§ã¢ãã¡ããªã®1ã€ãšèŠãªãããããšã¯å¶ç¶ã§ã¯ãããŸããã TeslaCryptã®æå·åã¡ã«ããºã ã¯éåžžã«æ
éã«å®è£
ãããŠããããã®ç®çã®ããã®ã¢ã«ãŽãªãºã ã®éžæã¯ãèè
ãæå·åã®åéã§äœããã®ãã¬ãŒãã³ã°ãåããŠããããšã瀺ããŠããŸãã
TeslaCryptã¯ãAES-256ã¢ã«ãŽãªãºã ã䜿çšããŠãã¡ã€ã«ãæå·åããŸãã ãã ããè匱ãªããŒãžã§ã³ã®TorrentLockerãšã¯ç°ãªããCBCãæäœã®æå·ã¢ãŒããšããŠ
䜿çšããŸãã ãã®ã¢ãŒãã§ã¯ãæå·åãããããŒã¿ã®åãããã¯ïŒåºå®ãµã€ãºã®æå·åãããã¡ãã»ãŒãžã®äžéšïŒã¯ã次ã®ãããã¯ãæå·åãããšãã«IVåæåãã¯ãã«ãšããŠæ©èœãããã¹ãŠã®ãããã¯ã¯åãããŒã§æå·åãããŸãã ãã®äºå®ã¯ããããã¹ã¬ããåãããæå·ãä»ã®åæ§ã®æå·ã§ã¯ãªãããšã瀺ããŠããããã®å ŽåãTorrentLockerã«å¯ŸããŠäœ¿çšãããããŒæ€çŽ¢æé ã¯åœ¹ã«ç«ããªããªããŸãã
å³ 7. CBCæå·åã¢ãŒãã¹ããŒã ãAESããŒèªäœã¯ãTeslaCryptã®å Žå
ãEl-Gamalã¹ããŒã ã«é¡äŒŒããã¢ã«ãŽãªãºã ã䜿çšããŠæå·åãããCïŒCãµãŒããŒã«éä¿¡ãããŸãã äœæè
ã¯RSAã®ä»£ããã«RSAã®ä»£ããã«æ¥åæ²ç·æå·åïŒECCïŒãéžæããŸãããããã¯ãECCãæå·åãããããã¹ãã®éãæžãããå®è¡ã«ãããæéãçããããæ€åºãé¿ããããã®å©äŸ¿æ§ã®ããã§ãã
ãã ããTeslaCrypt v2.2.0ïŒå¥åTeslaCrypt v8ïŒã®äœæè
ã¯1ã€ã®ãã¹ãç¯ããŸãããããã¯ã以åã®ãã¹ãšã¯å¯Ÿç
§çã§ãã
BleepingComputerã® Webãµã€ãããã³
Talosã®èª¿æ»ã§è¿°ã¹ãããŠããããã«ãæå·åããŒãä¿è·ããããã«èšèšãããå埩ããŒïŒRKïŒã¯ãCïŒCãµãŒããŒã§æå®ãããå
±æç§å¯ããŒïŒC2KïŒãšäœ¿çšããç§å¯ããŒãæãåãããçµæãšããŠçæãããŸããã¡ã€ã«æå·åïŒFKïŒã
RK = C2K * FK
埩æ§ããŒã¯äŸµå®³ãããã·ã¹ãã ã«ä¿åãããC2Kãæ¢ç¥ã®å Žåã«FK埩æ§ããã»ã¹ãå®è¡ã§ããŸãã ãã ããTeslaCrypt v2.2.0ã®äœæè
ã¯ãRSAã®åºç€ãšãªã
å ååè§£ã¡ã«ããºã ã䜿çšã§ãããšèª€ã£ãŠæ³å®ããŠããŸããã
æ°å幎åŸã§ããç ç©¶è
ã¯äžããããæ°ã®çŽ å æ°ãèšç®ããããã®å¹æçãªã¢ã«ãŽãªãºã ãèŠã€ããããšãã§ããŸããã§ããïŒRSAã§äœ¿çšããããã®ãšåãããã倧ããïŒã ãã ããããã¯ãå æ°åè§£ã®åé¡ãå°æ¥è§£æ±ºã§ããªããšããæå³ã§ã¯ãããŸããã
ããŒã¿å埩ããŒã®é·ãã¯ãåè§£ã¿ã¹ã¯ãäžå¯èœã«ããã»ã©é·ãã¯ãããŸããã ãããã£ãŠããã«ãŒããã©ãŒã¹æ»æã¯ãæå·åããŒãèŠã€ããŠãã¡ã€ã«ã埩å·åããããã«äœ¿çšã§ããæ¹æ³ã§ãã
æå·åã«å¯ŸããŠæå·åã䜿çšã§ããŸããïŒ
åé¡ã¯ãæ¢ã«æå·åããããã¡ã€ã«ã®æå·åãæå·åããå°éå®¶ã§ã¯ãªãã®ã§ããïŒ çãã¯ã€ãšã¹ãšããŒã®äž¡æ¹ã§ãã
æããã«ãæå·åãããããŒã¿ãããäžåºŠæå·åã§ããŸãã å®éããã®äºå®ã¯ãªããªã³ã«ãŒãã£ã³ã°ã®ã¢ã€ãã¢ã®æ ¹åºã«ãããŸãã ã€ãŸãããªããªã³ã«ãŒãã£ã³ã°ã¯ãããŒã¿ã®æ©å¯æ§ãšãããŒããŸãã¯ã«ãŒãã£ã³ã°ããŒããä»ããããŒã¿ã®éä¿¡ãä¿èšŒããããã«èšèšãããŠããŸãã ãŠãŒã¶ãŒãWebãµã€ãã«ã¢ã¯ã»ã¹ããããšãã«ããªã¯ãšã¹ãã3åæå·åãããããã«ã3ããŒãã®ã¹ããŒã ãæ³åããŠãã ããã åããŠãããŒã3ã§ã次ã«ããŒã2ã§ããã®åŸããŒã1ã§ããªã¯ãšã¹ããåããŒããééãããšãçŸåšã®ããŒãã®ããŒã§æå·åããããããã«ãŒããééããåã§ãããŒã3ã®ã¿ãå
¥åã«å
ã®ããŒã¿ãæã¡ãŸãã ããŒã3ã¯ããŠãŒã¶ãŒã«ä»£ãã£ãŠèŠæ±ãå®è¡ããèŠæ±ã«é©çšãããã®ãšåãæå·åã¹ããŒã ã䜿çšããŠå¿çãéãè¿ããŸãã
ãã¡ã€ã«æå·åã®å¹çãšç²ŸåºŠã確ä¿ããããã«ãæå·åè
ã¯éåžžãæ¡åŒµåã§ãã¡ã€ã«ããã£ã«ã¿ãªã³ã°ããŸãã ããšãã°ã2014幎ã®TorrentLockerãã¡ã€ã«ã®ãªã¹ãã¯
次ã®ãšããã§ããã ãã¡ã€ã«æ¡åŒµåããªã¹ãã«å«ãŸããŠããå Žåã¯æå·åãããå«ãŸããŠããªãå Žåã¯ç Žæ£ãããŸãã
äžæ¹ãæå·åããŒã«ã¯ãå€ãã®å Žåãæå·åããããã¡ã€ã«ã®ååã«å®çŸ©æžã¿ã®æ¡åŒµåã远å ããŸãã ããã¯è峿·±ãäºå®ã§ãããã¡ã€ã«æå·åããŒã«ã察象ãšããæå·åããã°ã©ã ã®äŸã¯èŠãŠããªãã£ãããã§ãã ãããã£ãŠããããã®ããŒã«ã®ããããããæå·åæ©èœã«ãã£ãŠäŸµå®³ãããã³ã³ãã¥ãŒã¿ãŒã§äœ¿çšãããå Žåããã®ããŒã¿ã¯ã©ã³ãµã ãŠã§ã¢ã«ãã£ãŠæå·åãããŸããã
äºé²ç
ã©ã³ãµã ãŠã§ã¢ããä¿è·ããããã®äºé²çã¯ããã§ã«ããŸããŸãªãœãŒã¹ã§å
¬éãããŠããŸãã äžè¬çã«ãæ¬¡ã®æšå¥šäºé
ã¯ãŠãŒã¶ãŒã«åœ¹ç«ã¡ãŸãã
- HIPSã®äºé²çãªä¿è·ãšãã£ãã·ã³ã°ä¿è·ãåããåªãããŠã€ã«ã¹å¯Ÿç補åã䜿çšããå¿
èŠããããŸãã
- é ããã¡ã€ã«æ¡åŒµåã«æ³šæããæªç¥ã®ãœãŒã¹ããåä¿¡ããã¡ãã»ãŒãžã®ãªã³ã¯ããã©ããªãã§ãã ããã
- ãã¡ã€ã«ããã¯ã¢ããã䜿çšããã§ããã ãé »ç¹ã«å®è¡ããŸãã
- ããã¯ã¢ãããã¡ã€ã«ã®ãããã£ã¬ã¯ããªãã³ã³ãã¥ãŒã¿ã«ããŠã³ãããªãã§ãã ããã ã©ã³ãµã ãŠã§ã¢ã¯ããªã ãŒããã«ã¡ãã£ã¢ãã¯ã©ãŠããããã³OSãã¡ã€ã«ã·ã¹ãã ããå°éå¯èœãªä»ã®å Žæã«ãããã¡ã€ã«ãæå·åã§ããŸãã
ã·ã¹ãã ãæ¢ã«ã©ã³ãµã ãŠã§ã¢ã«ãã£ãŠäŸµå®³ãããŠããå Žåãã»ãã¥ãªãã£ç ç©¶è
ãéçºãã
埩å·åããŒã«ã䜿çšããŠãã¡ã€ã«ã®åŸ©å·åã詊ã¿ãããšãã§ããŸãã ESETã«
ã¯ãããã€ãã®ã©ã³ãµã ãŠã§ã¢ãã¡ããªãšãã®ä¿®æ£ãè§£èªããããã®ããŒã«
ãããã€ããããããã«ãããŠãŒã¶ãŒã¯èº«ä»£éãæ¯æãããšãªããã¡ã€ã«ã«ã¢ã¯ã»ã¹ã§ããŸãã
ããã«ããªã©ã³ãèŠå¯ã®åœç«ãã€ãã¯ç¯çœªãŠããããšãŠãŒãããŒã«æ¬§å·ãµã€ããŒç¯çœªã»ã³ã¿ãŒã¯ãã»ãã¥ãªãã£äŒæ¥ãšååããŠãæå·åã®è¢«å®³è
ãæ¯æŽ
ããããŒã«ã
æäŸããŠããŸãã