
ãã®æçš¿ã§ã¯ãIEEEã®æ
å ±ã¿ã°äŒç€ŸãšååããŠãã«ãŠã§ã¢ã«é¢ããIEEEã¯ãŒãã³ã°ã°ã«ãŒããéçºããIEEE Software Taggantã·ã¹ãã ã«ã€ããŠã話ããããšæããŸãã
GuardantéçºããŒã ã®èšç»ã¯ãé·ãéãIEEE Software TaggantãµããŒããGuardant Armorãã¬ããã«è¿œå ããããšã§ããã ã·ã¹ãã ã®ç°¡åãªæŠèŠãšç®ã®åã®å®éçãªçµè«ã
ãŠã€ã«ã¹å¯Ÿçããããã¯ã«ãªãã®ã¯ãªãã§ããïŒ
誀ã£ãã¢ã³ããŠã€ã«ã¹ããªã¬ãŒã®åé¡ã«ééããªããŠãŒã¶ãŒã¯ããŸããã æ®éã®äººã®åå¿ã¯ãå€ãã®å Žåããçãããããã¡ã€ã«ã®åé€ã«åž°çããŸããããã¯ãå€ãã®å Žåãæ害ã§ã¯ãªãã ãã§ãªããéã«æçšã§ãæã«ã¯äŸ¡å€ããããŸãã åæ§ã«ããã®ãããªãžã§ãŒã¯ãç¥ã£ãŠããããã°ã©ããŒã¯ãã¹ãã¬ã¹ã«è¿ãåºæ¿ã«é¥ãããšããããŸãã ã©ã¡ããå¹æçãªäœæ¥ã«å¯äžããŸããã
å€ãã®å Žåããã®ãããªããªã¬ãŒã¯ãããŸããŸãªãããã¯ã¿ãŒã«ãã£ãŠä¿è·ãããŠãããã¡ã€ã«ã§çºçããŸãã åé¡ã¯ãææ°ã®ãããã¯ã¿ãŒãã³ãŒãã®é£èªåãå€çšããŠããããšã§ãã é£èªåãšã¯ãçªç¶å€ç°ãšã³ãŒãä»®æ³åãã¯ãããžãŒãããã³ãããã®çµã¿åãããæå³ããŸãã é£èªåã¯ãç¹å®ã®æ°ã®ã¡ãœãããšããŒã«ã®ãœãŒã¹ã³ãŒãã®åæãå°é£ã«ããããã«äœ¿çšãããŸãã ãã¥ãŒãªã¹ãã£ãã¯ãªãŠã€ã«ã¹å¯Ÿçã¢ãã©ã€ã¶ãŒããããã¯ç¶æ
ã«ããã®ã¯ãã³ãŒãã®é£èªåãããã»ã¯ã·ã§ã³ã§ãã
æ°å¹ŽåããŠã€ã«ã¹å¯ŸçäŒç€Ÿãšä¿è·è
ã®éã§çã®æŠããå§ãŸããŸããã çŽå€±ãããŠã€ã«ã¹å¯Ÿçãœããã¯ãåçšãœãããŠã§ã¢ãæ®åããŠãããœãããŠã§ã¢ã§äœ¿çšãããŠããªããã¹ãŠã®ããã«ãŒãçŠæ¢ããããšã«ããŸããã ãã®åŸãããã€ãã®æåãªããã«ãŒã§ãããçŠæ¢ãããŸããã æéãçµã€ã«ã€ããŠãç¶æ³ã¯éåžžã«æ»ããŸããããåé¡ã®å®å
šãªè§£æ±ºçã¯ãŸã ãããŸããã
ã³ãŒãé£èªåæè¡ã®çµ¶ãéãªãéçºãå
ã®ã³ãŒãã®æ¬äŒŒã³ãŒããžã®çœ®æãä¿è·ãããã¢ããªã±ãŒã·ã§ã³ã®åäœäžã«å®è¡ãããåæãèããè€éã«ããä¿è·ããããã¡ã€ã«ãã¢ã³ããŠã€ã«ã¹ã§ã¹ãã£ã³ãããšãã®ããã©ãŒãã³ã¹ã«åœ±é¿ãäžããŸããã æ£åœãªç®çãšæªæã®ããç®çã®äž¡æ¹ã«äœ¿çšãããå€çš®å€æ§ãªãããã¯ã¿ãŒã¯ããŠã€ã«ã¹å¯Ÿçæ¥çã«åé¡ãåŒãèµ·ãããŸãã æ·±å»ãªã»ãã¥ãªãã£ãªã¹ã¯ã¯ãäœæè
ãä¿è·è
ã®æªæã®ããã³ãŒãïŒããã€ã®æšéŠ¬ããŠã€ã«ã¹ãªã©ïŒã䜿çšããŠãã³ãŒããæ€åºããé ãããšã§ãã ãã®ææ³ã¯ãµãŒããŒåŽã«ãé©çšãããŠããïŒãµãŒããŒããªã¢ãŒãã£ãºã ïŒããã®çµæãæªæã®ããã³ãŒãããã®è
åšãæ€åºããŠå¯ŸåŠããããšãã¯ããã«å°é£ã«ãªã£ãŠããŸãã ã¢ã³ããŠã€ã«ã¹ã¯ãä¿è·ããããã¡ã€ã«ã®å®éã®å
容ãå€å¥ããããšãã§ãããä¿¡é Œæ§ãšç¡å®³ãªããã°ã©ã ã®èª€æ€ç¥ã®å®å
šãªæ¬ åŠãšã®ãã©ã³ã¹ãèŠã€ããããšãäœåãªããããŸãã
ä¿è·ããããã¡ã€ã«ã®é
åžãå¶åŸ¡ãã
ãã¥ãŒãªã¹ãã£ãã¯åæã¯ãæ°ããè
åšãæ€åºããããã«ãŠã€ã«ã¹å¯ŸçäŒç€Ÿã«ãã£ãŠèæ¡ããããã®ã§ãäžå¯©ãªãã¡ã€ã«ãåéããããã«éšåçã«å¿
èŠã§ãã ãã®å Žåã®èª€æ€ç¥ã®å¯èœæ§ã¯ã¯ããã«é«ããããã¢ã³ããŠã€ã«ã¹ã¯åçšããã«ãŒã®çœ²åã®ããã¯ã€ãããªã¹ããç¶æããŸãã ããã¯ç¶æ³ãæ¹åããã®ã«ããçšåºŠåœ¹ç«ã¡ãŸãããããã§ãã¢ã³ããŠã€ã«ã¹ããå
責ããæããæ©äŒãæ®ããŸãã ãµã€ã³ãããã¬ã€ãããç¥ãã®ããã«ã圌ãã¯ãŠã€ã«ã¹ã«ç¡å®³ãªãã¡ã€ã«ãé
åžããããšãã§ããŸãã ååšãæ£åœåããããã«ãã¢ã³ããŠã€ã«ã¹ã¯åæãè€éã«ããè¿œå ã®å¶åŸ¡ã¹ããŒã ãèãåºãããšãäœåãªããããŠããŸãã ãããã¯ã¿ãŒã«ã€ããŠã¯ãä¿è·ããããã¡ã€ã«ã®é
åžãå®å
šã«å¶åŸ¡ããã·ã¹ãã ãå®è£
ããããšã«ããŸããã ãã®ã·ã¹ãã ã§ã¯ãä¿è·ããããœãããŠã§ã¢ã®ä¿¡é Œã§ããªãçºè¡å
ããã®ãã¡ã€ã«ã®ã¿ããããã¯ããä¿¡é Œã§ãããœãŒã¹ããã®ãã¡ã€ã«ãžã®å¿ èª ã瀺ãããšãã§ããŸãã
ãŠã€ã«ã¹å¯Ÿçã§ã¯ãããžã¿ã«çœ²åãéäžçã«äœ¿çšããŠãã¡ã€ã«ãèªèšŒããŸãã ä¿¡é Œã§ããçµç¹ã«ãã£ãŠæ€èšŒãããããžã¿ã«çœ²åã¯ããã¡ã€ã«ã®ãœãŒã¹ã远跡ããä¿¡é Œã§ããæ¹æ³ãæäŸããŸãã ãã®ãããªçµç¹ã¯ã蚌ææžã§ãã«ãŠã§ã¢ã«çœ²åããããšã¯ã»ãšãã©ãããŸããã ããããå¿
ãããããžã¿ã«çœ²åã§ååã§ã¯ãããŸããã ãã¡ã€ã«ã«æå¹ãªããžã¿ã«çœ²åãå«ãŸããŠããå Žåãæ¢ç¥ã®ææäºäŸããããŸãã ãŠã€ã«ã¹ã¯ããã°ã©ã ã®ã³ã³ãã€ã«æ®µéã§å°å
¥ãããŸããã ãã ããããžã¿ã«çœ²åãé©çšãã責任ã¯ãã¬ãããŠãŒã¶ãŒã«ããã蚌ææžã®çºè¡è
ã«ã¯é«ãã¬ãã«ã®ä¿¡é Œãå¿
èŠã§ãã
2010幎ã«ãIEEEãã«ãŠã§ã¢ã¿ã¹ã¯ãã©ãŒã¹ã¯ãç¹å®ã®ãã¬ãããŠãŒã¶ãŒãèå¥ããã®ã«åœ¹ç«ã€ã·ã¹ãã ïŒçŸåšã¯IEEE Software TaggantãšåŒã°ããïŒã®éçºæ¹æ³ã«ã€ããŠè°è«ãå§ããŸããã ãã¿ã¬ã³ãããšããçšèªã¯ãççºç©ã«äœ¿çšãããã·ã¹ãã ããåçšãããŠããŸãããã®ã·ã¹ãã ã§ã¯ãååŠããŒã«ãŒãè¿œå ãããççºãŸã§ããŸãã¯ççºåŸã«è¿œè·¡ããããšãã§ããŸãã IEEE Software Taggant Systemã¯ããããã¯ã¿ãŒã®ã€ã³ã¹ããŒã«ã«ãã£ãŠäœæãããåºåå®è¡å¯èœãã¡ã€ã«ã«æå·åããŒã¯ã³ãåã蟌ã¿ãŸãã ããã«ããããã¡ã€ã«ã®ä¿è·ã«äœ¿çšãããäžæã®ãã¬ããã©ã€ã»ã³ã¹ãèå¥ã§ããŸãã
IEEEãœãããŠã§ã¢Taggantã®åã«ã¯ãéããã䜿çšããæ¹æ³ããããŸããã éããã«ã¯æå·åãããã©ã€ã»ã³ã¹æ
å ±ãå«ãŸããŠããŸãã æã責任ã®ãããã¬ããéçºè
ã¯ãå®è¡å¯èœãã¡ã€ã«ã«2ã»ããã®éãããå«ããŸãã 1ã€ã¯ãã¬ãããèå¥ãããã1ã€ã¯ã©ã€ã»ã³ã¹ãäžæã«èå¥ããŸãã ããã«ããããããããéãããã®äœ¿çšã«é¢ããåäžã®æšæºã¯ãªãããã¬ããã®åéçºè
ã¯ã¢ã¯ã·ã§ã³ã§èªç±ã§ãã
ã·ã¹ãã ã®éçºè
ã«ãããšããã¿ã¬ã³ãããšããæ°ããçšèªã®å°å
¥ã¯ãããŸãã§ãã äžæ¹ã§ãããŠã©ãŒã¿ãŒããŒã¯ããšããçšèªãšèšŒææžã®äœ¿çšãäžèŠã«ãªããä»æ¹ã§ãIEEE Software Taggantã·ã¹ãã ã«ã¯ãããã®ããŒã«ã®äž¡æ¹ã®ç¹æ§ãå«ãŸããŸãããã¹ã³ãŒããšããã©ãŒãã³ã¹ã¯å€§ããç°ãªããŸãã
ã€ã³ãã©
IEEE Software Taggantã¯ããã¬ããããã³ãŠã€ã«ã¹å¯Ÿçãšåæã«äœ¿çšãããå Žåã«ã®ã¿æå¹ã§ãã ã·ã¹ãã ã¯å
¬éããŒåºç€ïŒPKIïŒã䜿çšããŸãããã«ãŒãã»ã³ã¿ãŒãšãã©ã¹ãããã»ã³ã¿ãŒã¯IEEEãå¶åŸ¡ããŸãã ãã¬ãããã³ããŒã®å Žåã¯ãIEEEã«ç»é²ããŠSoftware Taggantã©ã€ã»ã³ã¹ãçæããå¿
èŠããããŸãã ã©ã€ã»ã³ã¹ã¯ããã¬ãããŠãŒã¶ãŒã«å¯ŸããŠééçã§ããã販売ããåã«ã€ã³ã¹ããŒã©ãŒã«çµ±åãããŠããå¿
èŠããããŸãã
æ°ãããã¬ããããªãªãŒã¹ããåã«ããã³ããŒã¯ãããŸããŸãªä¿è·ãã©ã¡ãŒã¿ã䜿çšããŠ10ã20åã®ãã¡ã€ã«ã®ä»£è¡šçãªãµã³ãã«ãä¿è·ããå
¬éããããšããå§ãããŸãã ã¢ã³ããŠã€ã«ã¹ã¯ããã¥ãŒãªã¹ãã£ãã¯ã¢ãã©ã€ã¶ãŒããã®èª€æ€åºããªãããšã確èªããå¿
èŠããããŸãã Software TaggantããŒã«ãŒã®ãããã¡ã€ã«ã®è©å€ã¯ãããããªããã¡ã€ã«ã®è©å€ãããé«ããªããã°ãªããŸããã
Software TaggantããŒã«ãŒã§ä¿è·ããããã«ãŠã§ã¢ãæ€åºããããšããã«ãŠã§ã¢ãä¿è·ãããã©ã€ã»ã³ã¹ããã©ãã¯ãªã¹ãã®åè£ã«ãªããŸãã ã³ãã¥ããã£ã§ã¯ããããã¯ãããã©ã€ã»ã³ã¹ã®å®å
šãªãªã¹ããäœæããããã«ããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ãæ
å ±ããã°ããå
±æããããšãæšå¥šããŠããŸãã
æå·åããŒã«ãŒ
Software Taggantã¯ãMicrosoft Windowsã®éåžžã®Authenticodeããžã¿ã«çœ²åãšã©ã®ããã«éããŸããïŒ
IEEE Software Taggantã·ã¹ãã ã§ã¯ãããã°ã©ã ã®å°ããªã¯ãªãã£ã«ã«ã»ã¯ã·ã§ã³ã®ããã·ã¥åèšãèšç®ããŠããœãããŠã§ã¢ã®æŽåæ§ããã§ãã¯ããæéãæå°éã«æããããšãã§ããŸãïŒAuthenticodeã¯åžžã«ãã¡ã€ã«å
šäœãã«ããŒãããããæ€èšŒæéã¯ãã¡ã€ã«ãµã€ãºã«äŸåããŸãïŒã ããã¯ããŠã€ã«ã¹å¯Ÿçããã°ã©ã ãã¯ã€ãã¯ã¹ãã£ã³ã¢ãŒãã§åäœã§ããããã«ããããããŠã€ã«ã¹å¯Ÿçããã°ã©ã ã«ãšã£ãŠéèŠã§ãã ãã1ã€ã®èå³æ·±ãç¹ã¯ãã€ã³ã¿ãŒãããã«æ¥ç¶ããŠããå ŽåãããŒã«ãŒãäœæããããã®ä¿¡é Œã§ããã¿ã€ã ããŒã«ãŒïŒRFC 3161ã«æºæ ïŒãè¿œå ãããããšã§ããããã«ããããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã¯ãã©ãã¯ãªã¹ããéžæçã«è£å®ã§ããŸãïŒç¹å®ã®äŸµå®³ã®ç¬éã«ã®ã¿ãœãããŠã§ã¢ããããã¯ããŸãïŒã
ããã¥ã¡ã³ãã«ãããšãTaggantã¯PE圢åŒã®ãã¡ã€ã«ã ãã§ãªãè¿œå ã§ããŸãã 圢åŒã®ãªã¹ãã«ã¯ãELFãšJavaScriptãå«ãŸããŸãã Taggantãä»»æã®éæ§é å圢åŒã«è¿œå ããããšãã§ããŸãã
PE圢åŒã®å ŽåãWindowsã®ããžã¿ã«çœ²åãšé¡äŒŒããŠããŸãã Taggantæ§é ã¯ãPEãã¡ã€ã«ã®æåŸã«ãªãŒããŒã¬ã€ãšããŠæžã蟌ãŸããŸãã å
ã®ãªãŒããŒã¬ã€ããã¡ã€ã«ã«ååšããå Žåãæ§é ã¯ãã®åŸã«æžã蟌ãŸããŸãã ããã·ã¥ã®åèšãèšç®ããããã«ãSHA2-256ã¢ã«ãŽãªãºã ã䜿çšãããŸãã TaggantãPEãã¡ã€ã«ã«è¿œå ããæãç°¡åãªæ¹æ³ã¯ãSignToolãšããããªãã¿ã®ååã®ãŠãŒãã£ãªãã£ã䜿çšããããšã§ãã
äŸïŒ
> SignTool.exe SimpleTest-x86.exe license.pem
SignToolã¢ããªã±ãŒã·ã§ã³ïŒTaggant v2ããã¡ã€ã«ã«è¿œå ïŒ
SPV Taggant LibraryããŒãžã§ã³2
ã©ã€ã»ã³ã¹ãã¡ã€ã«ã¯æå¹ã§ãæå¹æéã¯åææ¥4æ03æ¥23:59:59 2027ã§ã
æ£åžžã«èšç®ããããã¡ã€ã«ããã·ã¥
ã¿ã€ã ã¹ã¿ã³ããå
¥ãã
ã¿ã€ã ã¹ã¿ã³ããæ£åžžã«é
眮ãããŸãã
ã¿ã¬ã³ããæºåãã
ã¿ã¬ã³ããæ£åžžã«äœæãããŸãã
Taggantã¯ãã¡ã€ã«ã«æžã蟌ãŸããŸã
Microsoftã®ããžã¿ã«çœ²åã¯ãTaggantãšç«¶åããŸããã ã¿ã¬ã³ãæ§é ã®åŸã«è¿œå ãããã¿ã¬ã³ããå«ããã¡ã€ã«å
šäœãã«ããŒããŸãã
ã¡ãªãã
IEEE Software Taggantã·ã¹ãã ã¯ããŠã€ã«ã¹å¯Ÿçããã³ãããã¯ã¿ãŒçšã®å°éçãã€æ±çšçãªãœãªã¥ãŒã·ã§ã³ãšããŠéçºãããŸãããããã¯ãä»ã®ãã¡ã€ã«èªèšŒæ¹æ³ãããééããªãæå©ãªå©ç¹ã§ãã ã¢ã³ããŠã€ã«ã¹ã¯ä»¥äžãåãåããŸãïŒ
- ãã«ãŠã§ã¢ã®çæã«äœ¿çšãããç¹å®ã®ã©ã€ã»ã³ã¹ãèå¥ããæ©èœã ããã«ããããã¬ããå
šäœããããã¯ããããšãªããåã
ã®ã©ã€ã»ã³ã¹ããã©ãã¯ãªã¹ãã«ç»é²ã§ããŸãã
- ãã¡ã€ã«ã解åããå¿
èŠãªããæ確ã«å®çŸ©ãããã»ãŒãã¢ãŒãã§äœ¿çšãããããã«ãŒã®ããŒãžã§ã³ãšã©ã€ã»ã³ã¹ãè¿
éã«èå¥ããæ©èœã ããã«ããããã¡ã€ã«ãã¹ãã£ã³ãããšãã®ããã©ãŒãã³ã¹ãåäžããã¯ãã§ãã
- ãã¡ã€ã«ã®å€æŽãããããŒãžã§ã³ãèå¥ããæ©èœã ãã®ãããªãã¡ã€ã«ã¯ãã©ãã¯ãªã¹ãã«ç»é²ã§ããŸãã
- ã©ã€ã»ã³ã¹å±¥æŽã远跡ããŠãç¹å®ã®ãã¬ãããŠãŒã¶ãŒã®è©å€ãé«ããæ©èœã
ãããã®æ©èœã¯ãã¹ãŠãä¿è·ããããã¡ã€ã«ãã¹ãã£ã³ããéã®èª€æ€ç¥ã®ãªã¹ã¯ãæžãããçç£æ§ãåäžãããã¯ãã§ãã
ãã¹ãäž
ã·ã¹ãã ã¯ããªãåã«ç»å ŽããããããŠã€ã«ã¹å¯Ÿçã®èª€æ€ç¥ãæžãããããšèããŸããã ããããæ²ããããªãå¥è·¡ã¯èµ·ãããŸããã§ããã ãŸããVirusTotalã®çµæãèŠãŠãã ããã
ã¯ãªãŒã³ãã¡ã€ã«ïŒ
Taggantã䜿çšããªãä¿è·ããããã¡ã€ã«ïŒ
Taggantã§ä¿è·ããããã¡ã€ã«ïŒ
Microsoft眲åä»ãã®Taggantä¿è·ãã¡ã€ã«ïŒ
ããŸãç¥ãããŠããªããŠã€ã«ã¹å¯Ÿçãœããã¯ãTaggantã·ã°ããã£ã®ååšã«ãŸã£ããåå¿ããããããåå¿ããŸããããã®éãåæ§ã§ãã 圌ãã«ãšã£ãŠãMicrosoftã®çœ²åã¯äŸç¶ãšããŠéèŠãªè°è«ã§ãã
Kaspersky Endpoint Securityãç§ãã¡ãæãããŸããã Taggant眲åãšMicrosoft眲åãååšãããã©ããã«é¢ä¿ãªãããã¡ã€ã«ãæ€ç«ããŸãã åãšåæ§ã«ããã¥ãŒãªã¹ãã£ãã¯ã¢ãã©ã€ã¶ãŒãç¡å¹ã«ããã ãã§åœ¹ç«ã¡ãŸãã ãã®å ŽåãKaspersky Anti-Virusã«ããVirusTotalã®ã¹ãã£ã³ã¯ããã¡ã€ã«ãã¯ãªãŒã³ã§ãããšèšããŸãã

ãããã«
ã©ãããããã¹ãŠã®ãŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ãTaggantãµããŒãããšã³ãžã³ã«çµ±åããã®ã«æ¥ãã§ããããã§ã¯ãããŸããã IEEEã®å®åå¶åºŠãæžå¿µäºé
ã§ãã ãã®çµç¹ãšã®éä¿¡ã«ã¯ãèšå€§ãªæéãããããŸããã åçŽãªéçºè
ã«ãšã£ãŠãåæ³çãªãœãããŠã§ã¢ãã£ã¹ããªãã¥ãŒã¿ãŒã®ãã¯ã€ããªã¹ãã«ç»é²ããããšã¯ãMicrosoftã®ããžã¿ã«çœ²åã¡ã«ããºã ã䜿çšãããããé£ããå ŽåããããŸãã ããã§ããTaggantã¯éããã®äŸ¡å€ãã代æ¿æ段ã§ãããã·ã¹ãã ãåŸã
ã«å®è£
ãããããšãæãã§ããŸãã ãããŸã§ã®éãMicrosoftã®çœ²åã¯ãŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã«ãšã£ãŠãã匷åãªè°è«ã§ãã
åç
§ïŒ
- ICSGïŒIndustry Connections Security Group
- IEEEãã«ãŠã§ã¢å¯ŸçãµããŒããµãŒãã¹ïŒAMSSïŒ
- GitHubïŒIEEE_Taggant_System
- ããã«ãŒã®äœ¿çšã«é¢ããåºæºãšããªã·ãŒ