ããã«ã¡ã¯ãHabrïŒ ã
äžå°äŒæ¥ïŒSMEïŒåãCIS-Controlså®è£
ã¬ã€ã ãã®èšäºã®ç¿»èš³ãšæ¹ç·šã玹ä»ããŸãã
ã¯ããã«
ã¯ã¬ãžããã«ãŒãã®æŒæŽ©ãå人æ
å ±ã®çé£ãã©ã³ãµã ãŠã§ã¢ïŒWannaCryãªã©ïŒãç¥ç財ç£ã®çé£ããã©ã€ãã·ãŒäŸµå®³ããµãŒãã¹æåŠ-ãããã®æ
å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã¯äžè¬çãªãã¥ãŒã¹ãšãªã£ãŠããŸãã 被害è
ã®äžã«ã¯ãæ¿åºæ©é¢ã倧èŠæš¡ãªå°å£²ãã§ãŒã³ãéèæ©é¢ãããã«ã¯æ
å ±ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã¡ãŒã«ãŒãªã©ãæ倧ãã€æãè£çŠã§æãä¿è·ãããäŒæ¥ããããŸãã
ãã®ãããªäŒæ¥ã¯ãæ°çŸäžãã«ã®äºç®ãæ
å ±ã»ãã¥ãªãã£ã«å²ãåœãŠãŠããŸãããåŸæ¥ã®æ»æã«å¯ŸåŠããããšã¯ã§ããŸããã ãããã®æ»æã®å€ãã¯ãå®æçãªæŽæ°ãã»ãã¥ãªãã£ã§ä¿è·ãããæ§æã®äœ¿çšãªã©ãããç¥ãããŠããæ
å ±ä¿è·æ¹æ³ã«ãã£ãŠé²ãããšãã§ããŸããã
ããã§ã¯ãä»ã®èª°ãäœããã¹ãã§ããããïŒ äºç®ãå°ãªãã¹ã¿ãããéãããŠããçµç¹ã¯ãå¢ãç¶ãããµã€ããŒç¯çœªã«ã©ã®ããã«å¯Ÿå¿ã§ããŸããïŒ ãã®ããã¥ã¡ã³ãã¯ãCISã³ã³ãããŒã«ã«åºã¥ããŠããžãã¹ãä¿è·ããããŒã«ãSMBææè
ã«æäŸããããšãç®çãšããŠããŸãã CIS Controlsã¯ãæãäžè¬çãªè
åšãšè匱æ§ã«å¯Ÿæããå®èšŒæžã¿ã®æ
å ±ä¿è·æ¹æ³ã®å
æ¬çãªã»ããã§ãã ãããã®æ
å ±ä¿è·æ¹æ³ã¯ã察象åéã®å°é家ã«ãã£ãŠéçºãããŠããŸãã
SMBã«å¯Ÿããè
åšã«ã¯æ¬¡ã®ãã®ããããŸãã
æ©å¯æ
å ±ã®çé£ã¯ãå€éšã®äŸµå
¥è
ãäžæºãæ±ããŠããåŸæ¥å¡ãäŒç€Ÿã«ãšã£ãŠéèŠãªæ
å ±ãçãæ»æã®äžçš®ã§ãã
ãµã€ãé害ã¯ãWebãµã€ãã®ããŒãžãå¥ã®ããŒãžã«çœ®ãæããããã¿ã€ãã®æ»æã§ãããã»ãšãã©ã®å Žåãåºåãè
åšããŸãã¯èŠåã¡ãã»ãŒãžãå«ãŸããŸãã
ãã£ãã·ã³ã°ã¯ãä¿¡é Œã§ãããœãŒã¹ããã¡ãã»ãŒãžãåœé ããããšã«ãããæ»æè
ãéèŠãªæ
å ±ïŒãã°ã€ã³ããã¹ã¯ãŒããã¯ã¬ãžããã«ãŒãæ
å ±ãªã©ïŒãåä¿¡ããã¿ã€ãã®æ»æã§ãïŒããšãã°ãæªæã®ãããŠãŒã¶ãŒãç¹å®ããé»åã¡ãŒã«å
ã®ãªã³ã¯ãã¯ãªãã¯ããããã«æ£åœãªããªãã¯ãšããŠæ§æãããé»åã¡ãŒã«ã³ã³ãã¥ãŒã¿ãœãããŠã§ã¢ïŒã
ã©ã³ãµã ãŠã§ã¢ã¯ãã³ã³ãã¥ãŒã¿ãŒäžã®ããŒã¿ãžã®ã¢ã¯ã»ã¹ããããã¯ãããã«ãŠã§ã¢ã®äžçš®ã§ãããã®çµæãç¯çœªè
ã¯èº«ä»£éã匷èŠããŠããã¯ãããããŒã¿ã®ããã¯ã解é€ããŸãã
èªç¶çŸè±¡ãäºæ
ã«ããããŒã¿ã®æ倱ã
ãã®ããã¥ã¡ã³ãã«ã¯ãSMBãä¿è·ããããã«ç¹å¥ã«éžæããããCISã³ã³ãããŒã«ã®æ
å ±ã»ãã¥ãªãã£å¯Ÿçã®å°ããªã»ãããå«ãŸããŠããŸãã æ
å ±ã»ãã¥ãªãã£ããŒã«ã¯çµ¶ããå€å
ããŠããããã
ãµã€ãã§åŒç€Ÿ
ã«é£çµ¡ããŠææ°æ
å ±ãå
¥æã§ããŸãã
埩ç¿
ã»ãã¥ãªãã£ã¯ãITã€ã³ãã©ã¹ãã©ã¯ãã£ç®¡çãšå¯æ¥ã«é¢é£ããŠããŸããé©åã«ç®¡çããããããã¯ãŒã¯ã¯ãé©åã«ç®¡çãããŠããªããããã¯ãŒã¯ãããã¯ã©ããã³ã°ãå°é£ã§ãã çµç¹ãæ
å ±ãã©ã®çšåºŠä¿è·ããŠããããç解ããã«ã¯ã次ã®è³ªåãèªåããŠãã ããã
- åŸæ¥å¡ãã³ã³ãã¥ãŒã¿ãŒã«æ¥ç¶ããŠãããã®ãç¥ã£ãŠããŸããïŒ ããŒã«ã«ãããã¯ãŒã¯å
ã§ã©ã®ããã€ã¹ãæ¥ç¶ãããŠããŸããïŒ
- æ
å ±ã·ã¹ãã ã§äœ¿çšãããŠãããœãããŠã§ã¢ãç¥ã£ãŠããŸããïŒ
- æ
å ±ã»ãã¥ãªãã£èŠä»¶ãæºããããã«ã³ã³ãã¥ãŒã¿ãŒãæ§æããŸãããïŒ
- æ©å¯æ
å ±ãžã®åŸæ¥å¡ã®ã¢ã¯ã»ã¹ã管çããŠããŸããããŸãã¯ã·ã¹ãã ã§ã¢ã¯ã»ã¹æš©ãé«ããããŠãã人ã管çããŠããŸããïŒ
- åŸæ¥å¡ã¯ãæ
å ±ã»ãã¥ãªãã£ã®è
åšããçµç¹ãä¿è·ãã圹å²ãç解ããŠããŸããïŒ
以äžã«ãããŸããŸãªç¡æãŸãã¯äœã³ã¹ãã®ããŒã«ãšããããã®è³ªåã«çããŠçµç¹ã®ã»ãã¥ãªãã£ã¬ãã«ãåäžãããã®ã«åœ¹ç«ã€æé ã瀺ããŸãã ãªã¹ããããŠããããŒã«ã¯ãã¹ãŠã網çŸ
ããŠããããã§ã¯ãããŸããããæ
å ±ã»ãã¥ãªãã£ã®ã¬ãã«ãäžããããã«SMBã䜿çšã§ããå¹
åºãç¡æãŸãã¯äœã³ã¹ãã®ããŒã«ãåæ ããŠããŸãã
ãããã®æšå¥šäºé
ã§ã¯ãæ
å ±ã»ãã¥ãªãã£ã·ã¹ãã ãæ§ç¯ããããã«æ®µéçãªã¢ãããŒãã䜿çšããããšãæšå¥šããŠããŸãã
- ã¹ããŒãž1ã§ã¯ããããã¯ãŒã¯äžã«ãããã®ãç解ããæ
å ±ã»ãã¥ãªãã£ã®åºæ¬èŠä»¶ãå®çŸ©ã§ããŸãã
- ã¹ããŒãž2ã¯ãåºæ¬çãªã»ãã¥ãªãã£èŠä»¶ã®æäŸãšãæ
å ±ã»ãã¥ãªãã£ã®åŸæ¥å¡ã®ãã¬ãŒãã³ã°ã«éç¹ã眮ããŠããŸãã
- ã¹ããŒãž3ã¯ãçµç¹ãæ
å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«åããã®ã«åœ¹ç«ã¡ãŸãã
å段éã§ãåçãå¿
èŠãªè³ªåãšãç®æšã®éæã«åœ¹ç«ã€ã¢ã¯ã·ã§ã³ãšããŒã«ãæ瀺ãããŸãã
ã¹ããŒãž1.ã€ã³ãã©ã¹ãã©ã¯ãã£ãç¥ã
åœåãæ
å ±ã»ãã¥ãªãã£ã®åé¡ãé²ããã«ã¯ãããŒã«ã«ãããã¯ãŒã¯ãæ¥ç¶ãããããã€ã¹ãéèŠãªããŒã¿ããã³ãœãããŠã§ã¢ã«å¯ŸåŠããå¿
èŠããããŸãã ä¿è·ããå¿
èŠããããã®ãæ確ã«ç解ããªããšã蚱容ã§ããã¬ãã«ã®æ
å ±ã»ãã¥ãªãã£ã確å®ã«æäŸããããšãå°é£ã«ãªããŸãã
çæãã¹ãéèŠãªè³ªåïŒ
- ä¿è·ããå¿
èŠãããæ
å ±ãç¥ã£ãŠããŸããïŒ ãããã¯ãŒã¯äžã®æãéèŠãªæ
å ±ã¯ã©ãã«ä¿åãããŠããŸããïŒ
- ãããã¯ãŒã¯ã«æ¥ç¶ãããŠããããã€ã¹ãç¥ã£ãŠããŸããïŒ
- åŸæ¥å¡ã®ã³ã³ãã¥ãŒã¿ãŒã«ã€ã³ã¹ããŒã«ãããŠãããœãããŠã§ã¢ãç¥ã£ãŠããŸããïŒ
- ã·ã¹ãã 管çè
ãšãŠãŒã¶ãŒã¯åŒ·åãªãã¹ã¯ãŒãã䜿çšããŠããŸããïŒ
- åŸæ¥å¡ã䜿çšããŠãããªã³ã©ã€ã³ãªãœãŒã¹ãç¥ã£ãŠããŸããïŒã€ãŸãããœãŒã·ã£ã«ãããã¯ãŒã¯ã§ä»äºãããã座ã£ããããŸãïŒïŒ
ä¿è·ããå¿
èŠãããæ
å ±ã æãéèŠãªæ
å ±ããããã¯ãŒã¯äžã«ä¿åãããŠããå Žæ
äŒç€Ÿã®éèŠãªããŒã¿ã倱ãããããçãŸããããç Žæããããããšãããžãã¹ã倱ãå¯èœæ§ããããŸãã å¶çºçãªåºæ¥äºãèªç¶çœå®³ããæ°žä¹
çãªæ害ãåŒãèµ·ããå¯èœæ§ããããŸãã ããã«ãæœåšçãªæ»æè
ã¯ã䟡å€ã®ããããŒã¿ãæšçã«ããŸãã ãããã®ããã«ãŒã¯ã顧客ãéèæ
å ±ããŸãã¯ç¥ç財ç£ãçãããšããããã«ãŒãŸãã¯äŒç€Ÿã®åŸæ¥å¡ã§ãã 貎éãªæ
å ±ã䜿çšããã«ã¯ããã®æ
å ±ã«ã¢ã¯ã»ã¹ããå¿
èŠããããååãšããŠçµç¹ã®ããŒã«ã«ãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ããå¿
èŠããããŸãã
ããžãã¹ãä¿è·ããã«ã¯ãããŒã¿ã®äŸ¡å€ãšãã®äœ¿çšæ¹æ³ãç解ããå¿
èŠããããŸãã ãŸããæ¯æãæ
å ±ãå人ããŒã¿ãªã©ãæ³åŸã§ä¿è·ããå¿
èŠãããæ
å ±ã決å®ããå¿
èŠããããŸãã 以äžã¯ãèå¥ããã³ã€ã³ãã³ããªããå¿
èŠãããããŒã¿ã®äŸã§ãã
- ã¯ã¬ãžããã«ãŒããéè¡ããã³è²¡åæ
å ±ã
- å人ããŒã¿;
- 顧客ããŒã¿ããŒã¹ã賌å
¥/äŸçµŠäŸ¡æ Œ;
- äŒç€Ÿã®äŒæ¥ç§å¯ãå
¬åŒãæ¹æ³è«ãã¢ãã«ãç¥ç財ç£ã
æ
å ±ã®ä¿è·ã®èŠä»¶ã決å®ããäž»èŠãªé£éŠæ³ãæ瀺ãããŠããŸãïŒSMBã«é©çšãããå ŽåããããŸãïŒ
[翻蚳è
ããïŒãã·ã¢ã®æ³åŸã«åŸã£ãŠææžãæ¿å
¥ãããŸã] ã
- 2006幎7æ27æ¥ã®é£éŠæ³N152-ãå人ããŒã¿ã«ã€ããŠãã
- 2011幎6æ27æ¥ã®é£éŠæ³N161-ãåœæ°æ¯æãã·ã¹ãã ã«ã€ããŠãã
- 2011幎11æ21æ¥ã®é£éŠæ³N323-ããã·ã¢é£éŠã®åžæ°ã®å¥åº·ãå®ãããã®åºç€ã«ã€ããŠãã
- 2010幎11æ29æ¥ã®é£éŠæ³N326-ïŒããã·ã¢é£éŠã®åŒ·å¶å¥åº·ä¿éºã«ã€ããŠã;
- 2006幎7æ27æ¥ã®é£éŠæ³N149-ãæ
å ±ãæ
å ±æè¡ãããã³æ
å ±ä¿è·ãã
- 2004幎7æ29æ¥ã®é£éŠæ³N98-ãåæ¥ç§å¯ã«ã€ããŠãã
ãããã¯ãŒã¯ã«æ¥ç¶ãããŠããããã€ã¹
ãããã¯ãŒã¯ã«æ¥ç¶ãããŠããããã€ã¹ãããã£ãŠããå Žåãã€ã³ãã©ã¹ãã©ã¯ãã£ã®ç®¡çã容æã«ãªããä¿è·ããå¿
èŠãããããã€ã¹ãããããŸãã 以äžã¯ããããã¯ãŒã¯äžã®ããã€ã¹ã«ã€ããŠåŠã¶ããã«å®è¡ã§ããæé ã§ãã
ã¢ã¯ã·ã§ã³ïŒ
- ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ãããå Žåã¯ãã«ãŒã¿ãŒïŒã¯ã€ã€ã¬ã¹ã¢ã¯ã»ã¹ã³ã³ãããŒã©ãŒïŒã§ãæ¥ç¶ãããŠããããã€ã¹ãšã匷åãªæå·åïŒWPA2ïŒã䜿çšãããŠãããã©ããã確èªããŸãã
- 倧èŠæš¡ãªçµç¹ã§ã¯ããããã¯ãŒã¯ã¹ãã£ããŒïŒåçšãŸãã¯ç¡æïŒã䜿çšããŠããããã¯ãŒã¯äžã®ãã¹ãŠã®ããã€ã¹ãèå¥ããããšããå§ãããŸãã
- DHCPãä»ããŠIPã¢ãã¬ã¹ãåä¿¡ãããããã¯ãŒã¯ããã€ã¹ã®æ¥ç¶ã«é¢é£ããã€ãã³ãã®ãã°ãæå¹ã«ããŸãã ãã®ãããªã€ãã³ãã®ãã°ãèšé²ãããšããããã¯ãŒã¯äžã«ãã£ããã¹ãŠã®ããã€ã¹ãç°¡åã«è¿œè·¡ã§ããŸãã ïŒãµããŒããå¿
èŠãªå Žåã¯ãITæ
åœè
ã«ãåãåãããã ãããïŒ
- å°ããªçµç¹ã§ã¯ãæ©åšïŒã³ã³ãã¥ãŒã¿ãŒããµãŒããŒãã©ããããããããªã³ã¿ãŒãé»è©±ãªã©ïŒã®ãªã¹ããšãæ°ããæ©åšãŸãã¯ããŒã¿ã衚瀺ããããšãã«æŽæ°ããå¿
èŠãããã¹ãã¬ããã·ãŒãã®ä¿è·æ
å ±ã®ãªã¹ããä¿æã§ããŸãã
ããŒã«ïŒ
- Nmap ïŒäžçäžã®ã·ã¹ãã 管çè
ãããã«ãŒããããã¯ãŒã¯ã«æ¥ç¶ãããŠããããã€ã¹ãç¹å®ããããã«äœ¿çšãããããç¥ãããå€ç®çãããã¯ãŒã¯ã¹ãã£ããŒã
- ZenMap ïŒNmapã®äœ¿ããããGUI
- Spiceworks ïŒãããã¯ãŒã¯çšã®ç¡æã®ã€ã³ãã³ããªããã³ãªãœãŒã¹ç®¡çãœãããŠã§ã¢ïŒããã€ã¹ããã³ã€ã³ã¹ããŒã«æžã¿ãœãããŠã§ã¢ïŒ
åŸæ¥å¡ã®ã³ã³ãã¥ãŒã¿ãŒã«ã€ã³ã¹ããŒã«ãããŠãããœãããŠã§ã¢
ã€ã³ã¹ããŒã«ããããœãããŠã§ã¢ã®ç£èŠã¯ãåªããIT管çãšå¹æçãªæ
å ±ã»ãã¥ãªãã£ã®äž¡æ¹ã®éèŠãªã³ã³ããŒãã³ãã§ãã ãããã¯ãŒã¯äžã®æªæã®ãããœãããŠã§ã¢ã¯ãªã¹ã¯ãæå°éã«æããå¿
èŠããããã©ã€ã»ã³ã¹ã®ãªããœãããŠã§ã¢ã䜿çšããå Žåã®æ³ç責任ãããã«èµ·å ããŸãã æŽæ°ãããŠããªããœãããŠã§ã¢ã¯ããã«ãŠã§ã¢ã®äŸµå
¥ã®äžè¬çãªåå ã§ãããæ
å ±ã·ã¹ãã ãžã®æ»æã«ã€ãªãããŸãã ãããã¯ãŒã¯ã«ã€ã³ã¹ããŒã«ãããŠãããœãããŠã§ã¢ãç解ããã€ã³ã¹ããŒã«ãããŠãããœãããŠã§ã¢ãå¶åŸ¡ãã管çè
æš©éã§ã¢ã«ãŠã³ããä¿è·ãããšãæ
å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®å¯èœæ§ãšåœ±é¿ã軜æžã§ããŸãã
ã¢ã¯ã·ã§ã³ïŒ
- çµç¹ã䜿çšããã¢ããªã±ãŒã·ã§ã³ãWebãµãŒãã¹ããŸãã¯ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³ã®ãªã¹ããäœæããŸãã
- 管çè
ç¹æš©ãæã€ãŠãŒã¶ãŒã®æ°ãå¯èœãªéãæå°ã®å€ã«å¶éããŸãã äžè¬ãŠãŒã¶ãŒãã·ã¹ãã ã§ç®¡çè
æš©éã§äœæ¥ããããšãèš±å¯ããªãã§ãã ããã
- 管çè
ã¯ã·ã¹ãã ã«å€§ããªå€æŽãå ããããšãã§ããããã管çã¢ã«ãŠã³ãã«ã¯è€éãªãã¹ã¯ãŒãã䜿çšããŠãã ããã åŸæ¥å¡ãè€éãªãã¹ã¯ãŒããäœæããããã®æ瀺ãäœæããŸã[翻蚳è
ããïŒè€éãªãã¹ã¯ãŒãã®äœæäŸã¯ãã¡ã ] ã
- ã·ã¹ãã 管çè
ãå¥ã®ãŠãŒã¶ãŒã¢ã«ãŠã³ãã䜿çšããŠãé»åã¡ãŒã«ã®èªã¿åããã€ã³ã¿ãŒããããžã®ã¢ã¯ã»ã¹ãææžã®äœæãè¡ã£ãŠããããšã確èªããŠãã ããã
- ãããã¯ãŒã¯ã«ãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ããæé ãéçºããApplockerãªã©ã䜿çšããŠæªæ¿èªã®ã¢ããªã±ãŒã·ã§ã³ã®ã€ã³ã¹ããŒã«ãçŠæ¢ããŸãã
ããŒã«ïŒ
- Applocker ïŒå®è¡ãèš±å¯ãããŠãããœãããŠã§ã¢ãèå¥ããã³å¶éããããã®ç¡æã®Microsoft WindowsããŒã«
- Netwrix ïŒã·ã¹ãã äžã®ç®¡çã¢ã¯ã»ã¹æ
å ±ãèå¥ããããã®å€ãã®ç¡æããŒã«
- OpenAudIT ïŒãµãŒããŒãã¯ãŒã¯ã¹ããŒã·ã§ã³ããããã¯ãŒã¯ããã€ã¹äžã®ãœãããŠã§ã¢ã€ã³ãã³ããª
ã¹ããŒãž2.è³ç£ãä¿è·ãã
åŸæ¥å¡ã¯æãéèŠãªè³ç£ã§ããããã®è¡šçŸã¯ããžãã¹ã ãã§ãªãæ
å ±ã»ãã¥ãªãã£ã«ãåœãŠã¯ãŸããŸãã æ
å ±ãä¿è·ããã«ã¯ãæè¡çãªãœãªã¥ãŒã·ã§ã³ã ãã§ãªããã·ã¹ãã ã®å¶çºçãªèª€åäœãé²ãããã®åŸæ¥å¡ã®æèãå¿
èŠã§ãã ãã®ãã§ãŒãºã®äžç°ãšããŠãã³ã³ãã¥ãŒã¿ãŒã®ä¿è·ã ãã§ãªããæ
å ±ã»ãã¥ãªãã£ã®éèŠãªåŽé¢ã«é¢ããåŸæ¥å¡ã®ãã¬ãŒãã³ã°ã«ã€ããŠã説æããŸãã
ããªããçããå¿
èŠãããããã€ãã®è³ªåïŒ
- æ
å ±ã»ãã¥ãªãã£èŠä»¶ãæºããããã«ã³ã³ãã¥ãŒã¿ãŒãæ§æããŸãããïŒ
- ãããã¯ãŒã¯ã«ã¯ãåžžã«æŽæ°ããããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ããããŸããïŒ
- åŸæ¥å¡ã«æ
å ±ã»ãã¥ãªãã£ã®ææ°ã®æ¹æ³ã«ã€ããŠæããŠããŸããïŒ
åºæ¬çãªæ
å ±ã»ãã¥ãªãã£èŠä»¶ãæ§æãã
æ
å ±ã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ãåŸãããã«ãæªæã®ããããã°ã©ã ãæ»æè
ã¯ãã»ãšãã©ã®å Žåãå®å
šã§ãªãæ§æã®ã¢ããªã±ãŒã·ã§ã³ãŸãã¯è匱æ§ã®ããã¢ããªã±ãŒã·ã§ã³ã䜿çšããŸãã ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãšã¢ããªã±ãŒã·ã§ã³ïŒç¹ã«Webãã©ãŠã¶ãŒïŒãææ°ã§ãããé©åã«æ§æãããŠããããšã確èªããå¿
èŠããããŸãã ããã«ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«çµã¿èŸŒãããšãã§ãããã«ãŠã§ã¢å¯Ÿçã¡ã«ããºã ã䜿çšããããšããå§ãããŸãã ããšãã°ãWindows Device GuardãWindows Bitlockerãããã³ä»¥äžã§èª¬æããä»ã®ãŠãŒã¶ãŒã
ã¢ã¯ã·ã§ã³ïŒ
- Microsoft Security Analyzerã»ãã¥ãªãã£ã¹ãã£ããŒãå®æçã«å®è¡ããŠãWindowsãªãã¬ãŒãã£ã³ã°ã·ã¹ãã çšã«ã€ã³ã¹ããŒã«ãããŠããªãããã/æŽæ°ããã°ã©ã ãšãæ§æã®å€æŽãå¿
èŠãªãã®ãå€æããŸãã
- ãã©ãŠã¶ãšãã©ã°ã€ã³ãææ°ã§ããããšã確èªããŠãã ããã Google Chromeãªã©ã®ã³ã³ããŒãã³ããèªåçã«æŽæ°ãããã©ãŠã¶ã䜿çšããŠã¿ãŠãã ãã[翻蚳è
ããïŒYandex.Browserã¯ãã·ã¢ã®é¡äŒŒåãããããŸãã] ã
- ãã«ãŠã§ã¢ããã·ã¹ãã ãä¿è·ããããã«ãææ°ã®ãŠã€ã«ã¹å¯ŸçããŒã¿ããŒã¹ã®æŽæ°ã§ãŠã€ã«ã¹å¯Ÿçã䜿çšããŸãã
- ãªã ãŒããã«ã¡ãã£ã¢ïŒUSBãCDãDVDïŒã®äœ¿çšããå
¬åãè¡ãããã«æ¬åœã«å¿
èŠãªåŸæ¥å¡ã«å¶éããŸãã
- Windowsã³ã³ãã¥ãŒã¿ãŒã«Enhanced Mitigation Experience Toolkit ïŒEMETïŒãã€ã³ã¹ããŒã«ããŠãã³ãŒãã®è匱æ§ããä¿è·ããŸã
- ç¹ã«å
éšãããã¯ãŒã¯ãŸãã¯é»åã¡ãŒã«ãžã®ãªã¢ãŒãã¢ã¯ã»ã¹ã®å Žåã¯ãå¯èœã§ããã°å€èŠçŽ èªèšŒãå¿
èŠã§ãã ããšãã°ããã¹ã¯ãŒãã«å ããŠè¿œå ã®ã»ãã¥ãªãã£ã¬ãã«ãšããŠã³ãŒãä»ãã®ã»ãã¥ã¢ããŒã¯ã³/ã¹ããŒãã«ãŒããŸãã¯SMSã¡ãã»ãŒãžã䜿çšããŸãã
- ãããã¯ãŒã¯ã«è¿œå ãããšãã«ããã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãã«ãŒã¿ãŒããã¡ã€ã¢ãŠã©ãŒã«ãã¯ã€ã€ã¬ã¹ã¢ã¯ã»ã¹ãã€ã³ããããªã³ã¿ãŒ/ã¹ãã£ããŒãããã³ãã®ä»ã®ããã€ã¹ã®ããã©ã«ããã¹ã¯ãŒããå€æŽããŸãã
- æå·åã䜿çšããŠããã€ã¹ããªã¢ãŒãã§å®å
šã«ç®¡çããæ©å¯æ
å ±ãéä¿¡ããŸãã
- æ©å¯æ
å ±ãå«ãã©ããããããŸãã¯ã¢ãã€ã«ããã€ã¹ã®ããŒããã©ã€ããæå·åããŸãã
ããŒã«ïŒ
- Bitlocker ïŒMicrosoft Windowsããã€ã¹ã®çµ±åæå·å
- FireVault ïŒMacããã€ã¹åãã®çµ±åæå·å
- Qualys Browser Check ïŒææ°ã®æŽæ°ããã©ãŠã¶ã§ç¢ºèªããããŒã«
- OpenVAS ïŒã·ã¹ãã ãåºæ¬çãªæ
å ±ã»ãã¥ãªãã£èŠä»¶ã«æºæ ããŠãããã©ããã確èªããããã®ããŒã«
- Microsoft Baseline Security Analyzer ïŒWindowsã³ã³ãã¥ãŒã¿ãŒãå®å
šã«æ§æããæ¹æ³ãç解ããããã®ç¡æã®MicrosoftããŒã«
- CISãã³ãããŒã¯ ïŒ100ãè¶
ãããã¯ãããžã®æ
å ±ã»ãã¥ãªãã£æ§æãæäŸããç¡æã®PDFãã¡ã€ã«ã
ISããã»ã¹éçº
æ
å ±ã»ãã¥ãªãã£ã¯ããã¯ãããžãŒã ãã§ãªããããã»ã¹ãšäººã«é¢ãã話ã§ããããŸãã æ
å ±ã»ãã¥ãªãã£ããŒã«ã ãã§ã¯äžååã§ãã çµç¹ã®ã»ãã¥ãªãã£ã確ä¿ããã«ã¯ãåŸæ¥å¡ãæ
å ±ã»ãã¥ãªãã£èŠä»¶ãå³å¯ã«éµå®ããå¿
èŠããããŸãã åŸæ¥å¡ã«æ
å ±ã»ãã¥ãªãã£ã®åé¡ãæããã«ã¯ã2ã€ã®éèŠãªèŠçŽ ããããŸããæ
å ±ãåŸæ¥å¡ã«äŒããããšãåžžã«ç¥èã¬ãã«ãç¶æããããšã§ãã
åŸæ¥å¡ã«äŒããããæ
å ±ïŒ
- çµç¹å
ã®æ©å¯æ
å ±ã«ã¢ã¯ã»ã¹ãããåŠçãããããåŸæ¥å¡ãç¹å®ãããã®æ
å ±ãä¿è·ãã圹å²ãç解ããŠãã ããã
- æãäžè¬çãª2ã€ã®æ»æã¯ãé»åã¡ãŒã«ãšé»è©±ã®ãã£ãã·ã³ã°æ»æã§ãã ã¹ã¿ãããæ»æã®äž»ãªå
åã説æããã³ç¹å®ã§ããããšã確èªããŠãã ããã ãã®ãããªå
åã«ã¯ã人ã
ãéåžžã«ç·æ¥æ§ã®é«ãããšã話ãããã貎éãªæ
å ±ãæ©å¯æ
å ±ãæ±ãããããããŸããªçšèªãæè¡çšèªã䜿çšããããã»ãã¥ãªãã£æé ãç¡èŠããããã€ãã¹ãããããããã«æ±ããç¶æ³ãå«ãŸããŸã
- åŸæ¥å¡ã¯ãåžžèãæåã®é²åŸ¡ã§ããããšãç解ããå¿
èŠããããŸãã äœãèµ·ãã£ãŠããããå¥åŠãçãããããŸãã¯ããŸãã«ãè¯ããšæãããå Žåããããã¯æ»æã®å
åã§ããå¯èœæ§ãæãé«ãã§ãã
- å¯èœã§ããã°ãåã¢ã«ãŠã³ãã«è€éã§ãŠããŒã¯ãªãã¹ã¯ãŒãã®äœ¿çšããã³/ãŸãã¯äºèŠçŽ èªèšŒã奚å±ããŸãã
- ååãã¢ãã€ã«ããã€ã¹ã§ãç»é¢ããã¯ãã䜿çšããããšã奚å±ããŸãã
- ãã¹ãŠã®åŸæ¥å¡ãããã€ã¹ãšãœãããŠã§ã¢ãåžžã«æŽæ°ããŠããããšã確èªããŠãã ããã
ãµããŒãç¥èã¬ãã«ïŒ
- çµç¹ãä¿è·ããæ¹æ³ãšããããã®æ¹æ³ãå人ã®ç掻ã«ã©ã®ããã«é©çšã§ããããåŸæ¥å¡ã«èª¬æãããããç解ããŠããããšã確èªããŠãã ããã
- æ
å ±ã»ãã¥ãªãã£ãä»äºã®éèŠãªéšåã§ããããšããã¹ãŠã®åŸæ¥å¡ãç解ããŠããããšã確èªããŠãã ããã
- SANS OUCHãã¥ãŒã¹ã¬ã¿ãŒãªã©ã®ç¡æã®æ
å ±ã»ãã¥ãªãã£è³æãåŸæ¥å¡ã«é
åžããŠãã ããïŒ ããã³MS-ISACæåãã¥ãŒã¹ã¬ã¿ãŒã
- National Cyberââsecurity Allianceã®StaySafeOnline.orgãªã©ã®ãªã³ã©ã€ã³ãªãœãŒã¹ã䜿çšããŸãã
ããŒã«ïŒ
ã¹ããŒãž3ïŒçµç¹ãæºåãã
çµç¹ãæ
å ±ã»ãã¥ãªãã£ã®åŒ·åºãªåºç€ãéçºããããã€ã³ã·ãã³ã察å¿ã¡ã«ããºã ãæ§ç¯ããå¿
èŠããããŸãã ãã®ã¢ãããŒãã«ã¯ãæ
å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ããžã®å¯ŸåŠæ¹æ³ãšããã®åŸã®äŒç€Ÿã®åŸ©æ§æ¹æ³ã®ç解ãå«ãŸããŸãã
äž»ãªåé¡ïŒ
- 貎éãªãã¡ã€ã«ãæåŸã«ããã¯ã¢ããããã®ã¯ãã€ã§ããïŒ
- ããã¯ã¢ãããå®æçã«ãã§ãã¯ããŠããŸããïŒ
- ã€ã³ã·ãã³ããçºçããå Žåãã©ã®ååã«é£çµ¡ããã¹ããç¥ã£ãŠããŸããïŒ
ããã¯ã¢ãã管ç
ããã¯ã¢ããã®äœæãšç®¡çã¯æ¥åžžçãªäœæ¥ã§ãããããŸãèå³æ·±ãäœæ¥ã§ã¯ãããŸããããããã¯ããŒã¿ãä¿è·ããé害ããå埩ããããžãã¹ãæ£åžžã«æ»ãããã®æè¯ã®æ¹æ³ã®1ã€ã§ãã ã©ã³ãµã ãŠã§ã¢ã¯ãã¹ãŠã®ããŒã¿ãæå·åãã身代éãŸã§ãããã¯ããããšãã§ãããããããã¯éèŠã§ãã çŸåšããã³ç¶æãããŠããããã¯ã¢ããã«ãã£ãŠè£å®ãããå
ç¢ãªå¯Ÿå¿èšç»ã¯ãæ
å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«å¯ŸåŠããéã®æåã®é²åŸ¡çã§ãã
ã¢ã¯ã·ã§ã³ïŒ
- éèŠãªæ
å ±ãå«ããã¹ãŠã®ã³ã³ãã¥ãŒã¿ãŒã®æ¯é±ã®ããã¯ã¢ãããèªåçã«å®è¡ããŸãã
- ããã¯ã¢ãããå®æçã«ç¢ºèªããããã¯ã¢ããã䜿çšããŠã·ã¹ãã ã埩å
ããŸãã
- å°ãªããšã1ã€ã®ããã¯ã¢ããããããã¯ãŒã¯äžã§å©çšã§ããªãããšã確èªããŠãã ããã ããã¯ããã®ããã¯ã¢ããããã«ãŠã§ã¢ã«ã¢ã¯ã»ã¹ã§ããªããããã©ã³ãµã ãŠã§ã¢æ»æããä¿è·ããã®ã«åœ¹ç«ã¡ãŸãã
ããŒã«ïŒ
ã€ã³ã·ãã³ãã®æºå
æ
å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®çºçã誰ãæãã§ããŸããããæºåãäžå
šã§ããã°ããã»ã©ãã€ã³ã·ãã³ãããè¿
éã«åŸ©æ§ã§ããŸãã æ
å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«ã¯ããµã€ããžã®ã¢ã¯ã»ã¹ã«éåãããµãŒãã¹æåŠæ»æãã·ã¹ãã ãŸãã¯ããŒã¿ããããã¯ããã©ã³ãµã ãŠã§ã¢ã«ããæ»æãã¯ã©ã€ã¢ã³ããŸãã¯åŸæ¥å¡ããã®ããŒã¿ã®æ倱ã«ã€ãªããæªæã®ãããœãããŠã§ã¢ã«ããæ»æãããã³æå·åãããŠããªãããŒã¿ãå«ãã©ããããããçã¿ãŸãã
æºåããã«ã¯ãã€ã³ã·ãã³ãã®å Žåã«èª°ã«é£çµ¡ããããç¥ãå¿
èŠããããŸãã 瀟å
ã®ITã¹ã¿ããã«å©ããæ±ãããããµãŒãããŒãã£ã®ã€ã³ã·ãã³ã管çäŒç€Ÿã«é Œãããšãã§ããŸãã ãããã«ãããã€ãã³ããçºçããåã«ã€ã³ã·ãã³ãã管çãã責任è
ã®åœ¹å²ãç¥ã£ãŠããå¿
èŠããããŸãã
ã¢ã¯ã·ã§ã³ïŒ
- ã€ã³ã·ãã³ããçºçããå Žåã«ææ決å®ãè¡ããã¬ã€ãã³ã¹ãæäŸããçµç¹ã®åŸæ¥å¡ãç¹å®ããŸãã
- ITã¹ã¿ããããµãŒãããŒãã£ã«é£çµ¡å
æ
å ±ãæäŸããŸãã
- æ
å ±ã®å
±æãšæ
å ±ã»ãã¥ãªãã£ã®ä¿é²ã«éç¹ã眮ãåäŒã«åå ããŸãã
- èšç»ã®äžéšãšããŠå€éšé£çµ¡å
ã®ãªã¹ããä¿æããŸãã ãããã«ã¯ãæ³åŸé¡§åãä¿éºä»£çåºãæ
å ±ã»ãã¥ãªãã£ãªã¹ã¯ã«ä¿éºããããŠããå Žåãã»ãã¥ãªãã£ã³ã³ãµã«ã¿ã³ããå«ãŸããŸãã
- ããªãã®åœã®æ
å ±ã»ãã¥ãªãã£äŸµå®³ã«é¢é£ããæ³åŸãèªãã§ãã ããã
ã€ã³ã·ãã³ããçºçããå Žåã®å¯ŸåŠïŒ
- ã€ã³ã·ãã³ãã®æ§è³ªãšç¯å²ãæ確ã§ãªãå Žåã¯ãæ
å ±ã»ãã¥ãªãã£ã³ã³ãµã«ã¿ã³ãã«é£çµ¡ããããšãæ€èšããŠãã ããã
- äºä»¶ã§ç¬¬äžè
ã®æ©å¯æ
å ±ã䟵害ãããããšãå€æããå Žåã¯ãåŒè·å£«ã«é£çµ¡ããããšãæ€èšããŠãã ããã
- éåã®çµæãšããŠæ
å ±ãé瀺ãããã圱é¿ãåãããã¹ãŠã®å人ã«éç¥ããæºåãããŸãã
- å¿
èŠã«å¿ããŠæ³å·è¡æ©é¢ã«éç¥ããŸãã