ã«ã€ããŠã®ç 究ã¯äœã§ããç 究ã®ä»ã®éšåãžã®ãªã³ã¯ ãµã€ã¯ã«ã®
以åã®å
¬éã§ãéçŸéæ¯æãã®æ
å ±ã»ãã¥ãªãã£ã·ã¹ãã ã®åºæ¬èŠä»¶ãäœæããä¿è·å¯Ÿçã®å
·äœçãªå
容ã¯è
åšã¢ãã«ã«äŸåãããšè¿°ã¹ãŸããã
è
åšã®å®æ§çã¢ãã«ãäœæããã«ã¯ããã®åé¡ã«é¢ããæ¢åã®éçºãšæ
£è¡ãèæ
®ããå¿
èŠããããŸãã
ãã®èšäºã§ã¯ãè
åšã®ã¢ããªã³ã°ãšæ
å ±ã»ãã¥ãªãã£ãªã¹ã¯ç®¡çã®ããã»ã¹ã説æããçŽ40ã®ãœãŒã¹ã®æ瀺çãªã¬ãã¥ãŒãå®æœããŸãã GOSTãšãã·ã¢ã®èŠå¶åœå±ïŒãã·ã¢ã®FSTECããã·ã¢ã®FSBããã·ã¢é£éŠäžå€®éè¡ïŒã®ææžãããã³åœéæ
£è¡ã®äž¡æ¹ãæ€èšããŠãã ããã
è
åšã¢ããªã³ã°ããã»ã¹ã®ç°¡åãªèª¬æ
è
åšã®ã¢ãã«åããã»ã¹ã®æçµçµæã¯ãããã¥ã¡ã³ãïŒä¿è·ãªããžã§ã¯ãã®æ
å ±ã»ãã¥ãªãã£ã«å¯ŸããéèŠãªïŒé¢é£ããïŒè
åšã®ãªã¹ããå«ã
è
åšã¢ãã« ïŒã«ãªããŸãã
è
åšãã¢ãã«åããå Žåãéåžžã次ã®ãã®ãä¿è·ãªããžã§ã¯ããšèŠãªãããŸãã
- æ
å ±ã·ã¹ãã ;
- èªååã·ã¹ãã ;
- æ
å ±åã®ãªããžã§ã¯ãã
- ããžãã¹ããã»ã¹ã
æŠããŠãè
åšã¢ãã«ã¯ãªã¹ãã®åœ¢ã§æ瀺ããå¿
èŠã¯ãããŸããã ããªãŒïŒã°ã©ãïŒã
ãã€ã³ããããããŸãã¯ã¹ãã·ã£ãªã¹ãã䟿å©ã«äœæ¥ã§ããããã«ãããã®ä»ã®åœ¢åŒã®èšé²ã«ããããšãã§ããŸãã
è
åšã®å
·äœçãªæ§æã¯ãä¿è·ããããªããžã§ã¯ãã®ããããã£ãšããã®æ¯æŽã«ãã£ãŠå®è£
ãããããžãã¹ããã»ã¹ã«äŸåããŸãã ãããã£ãŠãã¢ããªã³ã°ã®åæããŒã¿ã®1ã€ã¯ãä¿è·ããããªããžã§ã¯ãèªäœã®èšè¿°ã«ãªããŸãã
ä»®æ³ãªããžã§ã¯ããèæ
®ãããšã
å
žåçãªïŒåºæ¬çãªïŒè
åšã¢ãã«ã圢æãããŸãã å®éã®ãªããžã§ã¯ããèæ
®ãããå Žåã
ãã©ã€ããŒãè
åšã¢ãã«ã圢æãããŸãã
è
åšãã¢ãã«åããå Žåãä¿è·å¯Ÿè±¡ã®èšè¿°ã«å ããŠãå°é家ã¯è
åšèªäœã«ã€ããŠã®ç¥èãå¿
èŠã§ãã
å®éã«ã¯ããã®ç¥èã¯ä»¥äžããåéã§ããŸãã
- è
åšã®å®è£
ã«äœ¿çšã§ããæ€åºãããè匱æ§ã«é¢ããç 究è
ã®å ±åã
- å®éã®ã³ã³ãã¥ãŒã¿ãŒæ»æã®èª¿æ»ã«é¢ããã³ã³ãã¥ãŒã¿ãŒãã©ã¬ã³ãžãã¯ã¬ããŒãã
- æ
å ±ã»ãã¥ãªãã£ã®åéã«ç¹åããäŒæ¥ã®å ±åæžãã³ã³ãã¥ãŒã¿ã»ãã¥ãªãã£ã®åéã«ãããçŸåšã®ç¶æ³ã®åæã«å°å¿µããŠããŸãã
- ã³ã³ãã¥ãŒã¿ãŒç¯çœªã«é¢ããã¡ãã£ã¢åºçç©ã
- 1ã€ãŸãã¯å¥ã®ååã«ãã£ãŠã°ã«ãŒãåãããè
åšããªã¹ãããããŒã¿ãã³ã¯ãŸãã¯è
åšã«ã¿ãã° ã
ã¢ããªã³ã°ããã»ã¹ã®æåã®æ®µéã¯ã
è
åšã®
èå¥ ãã€ãŸããä¿è·å¯Ÿè±¡ãªããžã§ã¯ãã«çè«çã«åœ±é¿ãäžããå¯èœæ§ã®ããè
åšã®å¯èœãªéãæ倧ã®ãªã¹ãã®éžæã§ãã
ãã®æ®µéã®å®è£
ã«ãããŠãèªç¶ã¯æ
å ±ã»ãã¥ãªãã£ã®å°é家ã欺ããŸãã åé¡ã¯ã人éã®èšæ¶ã¯é£æ³çã§ããããã¹ãŠã®å¯èœæ§ã®ããè
åšãæãåºããªã©ããã¹ãŠã®ã³ã³ãã³ããåãåºããŠæœåºããããšã¯ã§ããªããšããããšã§ãã
èãããããã¹ãŠã®è
åšã®ãªã¹ããäœæããããã«ãå°é家ãç¹å®ã®è³ªåãããããè
åšãã¡ã¢ãªããæœåºããŠèšé²ãããããååã䜿çšã§ããããã«ããããŸããŸãªããªãã¯ã䜿çšãããŸãã ãã®ãããªææ³ã®äŸã«ã¯ã
è
åšåé¡åãè
åš ããªãŒããŸãã¯
å
žåçãªã³ã³ãã¥ãŒã¿ãŒæ»æã®ãã¿ãŒã³ãå«ãŸããŸã ã ãããã®æ¹æ³ã«ã€ããŠä»¥äžã«èª¬æããŸãã
èãããããã¹ãŠã®è
åšã®ãªã¹ããäœæããåŸããã£ã«ã¿ãªã³ã°ãéå§ããæçµçã«çµç¹ã«ãšã£ãŠéèŠãªïŒé¢é£ããïŒè
åšã®ã¿ãæ®ãããã«ããŸãã éåžžããã£ã«ã¿ãªã³ã°ããã»ã¹ã¯è€æ°ã®å埩ã§å®è¡ãããããããã®è
åšã¯1ã€ãŸãã¯å¥ã®å
åã§æåŠãããŸãã
ãããã¯ãéåè
ãè
åšãå®è£
ãã
æ©äŒ ïŒãªãœãŒã¹ïŒã®
å¯çšæ§ã®å
åããå§ãŸããŸãã ããã決å®ããããã«ãæåã«ç¹å¥ãªææžãäœæãããŸã-
éåè
ã®
ã¢ãã«ã§ãéåè
ã®å¯èœæ§ãèå¥ããããã®èœåã決å®ãããŸãã 次ã«ã以åã«åãåã£ãè
åšã¯äŸµå
¥è
ã®ã¢ãã«ãšçžé¢ãããã¹ãŠã®è
åšãç Žæ£ããŸãããã®å®è£
ã¯æœåšçãªéåè
ã®èœåãè¶
ããŠããŸãã
è
åšããã£ã«ã¿ãªã³ã°ããããã®æ¬¡ã®å
åã¯ã
ãªã¹ã¯ã®éèŠæ§ã®å
åã§ã ã æåã«ãçµç¹ã¯éèŠã§ãªããšã¿ãªããªã¹ã¯ã®ã¬ãã«ã決å®ããŸãã 次ã«ãåè
åšã®å®è£
ã«ãããªã¹ã¯ãè©äŸ¡ããæå®ã®ã¬ãã«ä»¥äžã®å Žåãè
åšã¯ç Žæ£ãããŸãã
ãããã£ãŠããã£ã«ã¿ãªã³ã°ãå®äºãããšãæ
å ±ã»ãã¥ãªãã£çµç¹ã«å¯Ÿããé倧ãªïŒé¢é£ããïŒè
åšãå«ãè
åšã¢ãã«ãååŸãããŸãã
è
åšã®ç¹å®æ¹æ³è«-ãè
åšåé¡åã
æ
å ±ã»ãã¥ãªãã£ã«å¯Ÿããã»ãšãã©ã®è
åšã¯ã1ã€ãŸãã¯å¥ã®å±æ§ã«ãã£ãŠã°ã«ãŒãåïŒåé¡ïŒã§ããŸãã çµæãšããŠåŸãããåé¡ã¹ããŒã ã¯ãå°é家ãè
åšãæœåºããã¡ã¢ãªã®ã¢ã³ã±ãŒããšããŠäœ¿çšã§ããŸãã
ããšãã°ãå人ããŒã¿æ
å ±ã·ã¹ãã ïŒISPDïŒã§åŠçãããå人ããŒã¿ïŒPDïŒã®ã»ãã¥ãªãã£ã«å¯Ÿããè
åšãã¢ãã«åããã¿ã¹ã¯ãèããŠã¿ãŸãããã
2008幎ããã·ã¢ã®FSTECã¯ããã®ç®çã®ããã®æ¹æ³è«ææž
-PDè
åšã®åºæ¬ã¢ãã«ãçºè¡ããŸãã
ããã®ææžã«ã¯ãå€ãã®åé¡ã¹ããŒã ãå«ãŸããŠããŸãã

ãã©ã€ããŒããªè
åšã¢ãã«ãæ§ç¯ããå°é家ã¯ããã®ã¹ããŒã ã䜿çšããŠããå人ããŒã¿ã«å¯Ÿããã©ã®ãããªè
åšãå
éšäŸµå
¥è
ã®è¡åã«èµ·å ããã®ãããšèªåãããããã®è
åšãèšé²ã§ããŸãã 次ã«ã次ã®è³ªåãããŸããããããŠãå€éšã®äŸµå
¥è
ã¯ã©ã®ããã«å人ããŒã¿ãæ»æããããšãã§ããŸããïŒããªã©ã
è
åšèå¥ææ³-ãè
åšããªãŒã
ãã®æè¡ã䜿çšããŠãæ
å ±ã»ãã¥ãªãã£ã®å°é家ã¯äŸµå
¥è
ã®ç«å Žã«ç«ã¡ãä¿è·ããããªããžã§ã¯ããã©ã®ããã«æ»æããããèãå§ããŸãã
æåã¯ãå°æ¥ã®ããªãŒã®ã«ãŒããšãªãé«ã¬ãã«ã®è
åšãå®åŒåãããŸãã
ãã®åŸãã¹ãã·ã£ãªã¹ãã¯ãã®è
åšãäœã¬ãã«ã®è
åšã«å解ãå§ãããã®å®è£
ã«ããåé¡ã®è
åšãå®è£
ãããå¯èœæ§ããããŸãã ãããè¡ãããã«ã圌ã¯èª¿æ»äžã®è
åšãã©ã®ããã«ããŸãã¯ã©ãããæå³ã§å®çŸã§ããããå°ããããšããããŸãã
çµæãšããŠçããè
åšã¯ãæ€èšäžã®è
åšãšé¢ä¿ãããããã®åå«ãšããŠããªãŒã«èšé²ãããŸãã 次ã«ãå¿
èŠãªè©³çŽ°ã¬ãã«ãéæããããŸã§ãããããé çªã«å解ãããŸãã
åæ§ã®ã¢ãããŒããåœæè¡åéã§é·ãéç¥ãããŠããã
GOST R 51901.13-2005ïŒIEC 61025ïŒ1990ïŒãªã¹ã¯ç®¡çã§æšæºåããããã©ãŒã«ãããªãŒã®æ§ç¯ã«äœ¿çšãããŠã
ãŸãã ãã©ãŒã«ãããªãŒåæ ã
ãè
åšã®æšãã®äœ¿çšã説æããããã«ãæ
å ±åãªããžã§ã¯ãã®è
åšã¢ãã«ã®åœ¢æãæ€èšããŸããæ
å ±åãªããžã§ã¯ãã¯ãã³ã³ãã¥ãŒã¿ãŒãããã¯ãŒã¯ã«æ¥ç¶ãããŠããªãå€ç«ããã³ã³ãã¥ãŒã¿ãŒã§ãã éèŠãªæ
å ±ããã®æœèšã§åŠçãããŠãããã»ãã¥ãªãã£ã確ä¿ããå¿
èŠããããšããŸãã
é«ã¬ãã«ã®è
åšãšããŠã次ã®ããšãå®çŸ©ããŸããä¿è·ãããæ
å ±ã®ã»ãã¥ãªãã£ããããã£ã®éåã
äžè¬çãªã»ãã¥ãªãã£æ©èœã¯ãæ©å¯æ§ãæŽåæ§ãã¢ã¯ã»ã·ããªãã£ã§ãã ãããã£ãŠãåã©ãã®è
åšã¯æ¬¡ã®ããã«ãªããŸãã
- ä¿è·ãããããŒã¿ã®æ©å¯æ§ã®éåã
- ä¿è·ãããããŒã¿ã®æŽåæ§ã®éåã
- ä¿è·ãããããŒã¿ã®å¯çšæ§ã®éåã
ãä¿è·ãããããŒã¿ã®æ©å¯æ§ã®äŸµå®³ãã®è
åšãå解ããŸãã
ããã®è
åšãã©ã®ããã«å®çŸã§ãããããšãã質åãèªåããŸãããããŠãçããšããŠæ¬¡ã®ãªãã·ã§ã³ãæžãçããŸãã
- åŠçãèš±å¯ããã人ã«ããä¿è·ãããããŒã¿ã®é瀺ã
- æš©éã®ãªã人ã«ããä¿è·ãããããŒã¿ãžã®æš©éã®ãªãã¢ã¯ã»ã¹ã
- æè¡ãã£ãã«ãä»ããä¿è·ãããããŒã¿ã®æŒæŽ©ã
åæ§ã«ãç§ãã¡ã¯ãä¿è·ãããããŒã¿ã®æŽåæ§ã®äŸµå®³ããšããè
åšã«å¯ŸåŠããŸãã 次ã®ããã«å解ã§ããŸãã
- åŠçãèš±å¯ããã人ã®è¡åã«ããä¿è·ãããããŒã¿ã®æå·ã
- æªæã®ããã³ãŒãã«ããä¿è·ãããããŒã¿ã®æå·ã
- ä¿è·ãããããŒã¿ãåŠçãããã³ã³ãã¥ãŒã¿ãŒã®é害ããã³èª€åäœã«ããä¿è·ãããããŒã¿ã®æå·ã
ãä¿è·ãããããŒã¿ã®å¯çšæ§ã®äŸµå®³ããšããè
åšã®å解ã¯ã次ã®è
åšã«ãã£ãŠè¡šãããŸãã
- æªæã®ããã³ãŒãïŒæå·åããã«ãŒïŒãžã®é²åºã«ããä¿è·ãããããŒã¿ã®ç Žå£ã
- ä¿ç®¡ãããŠããã³ã³ãã¥ãŒã¿ãŒã®ããŒããã©ã€ãã®é害ã«ããä¿è·ãããããŒã¿ã®ç Žå£ã
- æ
å ±åã®å¯Ÿè±¡ã®åäœæ¡ä»¶ã«éåããŠãããããæ
åœè
ãæ
å ±åããããšãã§ããŸããã
ãã®çµæã次ã®ããªãŒãåŸãããŸãã

ã芧ã®ããã«ãæ§ç¯ããã°ããã®ãã®ãããªåå§çãªã¢ãã«ã§ãããã°ã©ãã£ã«ã«ã«è¡šç€ºãããšããªãé¢åã§ãã ãããã£ãŠããè
åšããªãŒãã¯äž»ã«éå±€ãªã¹ãã®åœ¢åŒã§ææžåãããŸãã
è
åšèå¥ææ³ãå
žåçãªæ»æãã¿ãŒã³ã
ãã®ææ³ã®åºç€ã¯ãã³ã³ãã¥ãŒã¿ãŒæ»æãå®è¡ãããšãã«ãæ»æè
ãæ¯åç¹å®ã®åæ§ã®äžé£ã®ã¢ã¯ã·ã§ã³ãå®è¡ãããšããèãæ¹ã«ãããŸããããã¯ãå
žåçãªæ»æãã¿ãŒã³ãšåŒã°ããŸãã
çŸæç¹ã§æãããç¥ãããŠããã³ã³ãã¥ãŒã¿ãŒæ»æã®ãã¿ãŒã³ã®1ã€ã¯ãããããŒãããŒãã£ã³ã説æãã
ãã«ãã§ãŒã³ãã³ãã¬ãŒãã§ãã
ã¹ããŒãž1 åµå¯-æ»æããããªããžã§ã¯ãã«é¢ããããŒã¿ã®åéã
ã¹ããŒãž2 ã æŠåšå-æ»æã®ããã®ããŒã«ïŒæªæã®ããã³ãŒãïŒã®éçºã
ã¹ããŒãž3 ã é
ä¿¡-æ»æããããªããžã§ã¯ããžã®æªæã®ããã³ãŒãã®é
ä¿¡ã
ã¹ããŒãž4 ã 䟵å
¥ïŒæªçšïŒ-æªæã®ããã³ãŒããå®è¡ããããã«ãæ»æããããªããžã§ã¯ãã®ããŒãã®è匱æ§ã䜿çšããŸãã
ã¹ããŒãž5 ã ã€ã³ã¹ããŒã«-é ããããªã¢ãŒãã¢ã¯ã»ã¹ã®ã·ã¹ãã ã®äŸµå®³ãããããŒããžã®ã€ã³ã¹ããŒã«ã
ã¹ããŒãž6 ã å¶åŸ¡ã®ç²åŸïŒC2ïŒ-䟵害ãããããŒããžã®æ»æè
ã®ããã®ãªã¢ãŒãã¢ã¯ã»ã¹ãã£ãã«ã®çµç¹ã
ã¹ããŒãž7 ã ã¢ã¯ã·ã§ã³-æ»æãè¡ãããã¢ã¯ã·ã§ã³ã
ç 究çµç¹
MITERã¯ãã¹ããŒãžã®ååããããã«å€æŽãããã®ãã³ãã¬ãŒãã
Cyberââ Attack LifecycleãšåŒã³ãŸããã

ããã«ãMITREã¯ããŸããŸãªæ®µéã®èª¬æãæ¡åŒµããå段éã§ã®æ»æè
ã®å
žåçãªæŠè¡ã®ãããªãã¯ã¹ã圢æããŸããã ãã®ãããªãã¯ã¹ã¯
ATTïŒCKãšåŒã°ããŸãã
ïŒã¯ãªãã¯å¯èœïŒäžèšã®ãããªãã¯ã¹ã¯æ®éçã§ã¯ãããŸããããå€æ°ã®å®éã®æ»æã®å§èšã§æ»æè
ãè¡ã£ãã¢ã¯ã·ã§ã³ãèšè¿°ããããšãã§ããŸãã
è
åšã¢ããªã³ã°ã®èŠ³ç¹ãããå
žåçãªæ»æãã¿ãŒã³ã¯è
åšã®åé¡åãšèŠãªãããšãã§ããå
žåçãªæŠè¡ã®ãããªãã¯ã¹ã¯è
åšã¢ãã«ã®éèŠãªæçãšèŠãªãããšãã§ããŸãã
ãã³ãã¬ãŒãã®æåŸã®ã¹ããŒãžã§ã®ã¿æ確ã«ããå¿
èŠããããŸã-ãã¢ã¯ã·ã§ã³ãããã®åŸãæ»æãå®è¡ãããããã«ãã¹ããŒãžèªäœã¯èæ
®ãããŠããªãæŠè¡ã«ãã£ãŠè£å®ãããŸãã
2008幎ã®å人ããŒã¿ã«å¯Ÿããè
åšã®ã¢ããªã³ã°ã«é¢ãããã·ã¢ã®FSTECã®ææžã
- è
åšã®åºæ¬ã¢ãã«PDN FSTECã2008
- PD 2008ã«å¯Ÿããå®éã®è
åšãå€æããæ¹æ³
äž¡æ¹ã®ææžã¯æ¹æ³è«çã§ããã䜿çšã¯ä»»æã§ããããã·ã¢ã®FSTECã®æèŠã§ã¯ãPDã®ã»ãã¥ãªãã£ãªã¹ã¯ãã¢ãã«åããã¿ã¹ã¯ã解決ããæ¹æ³ãé瀺ããŠããŸãã
FSTEC 2008ã®PDNè
åšã®åºæ¬ã¢ãã«ã«ã¯ãISPDã§åŠçãããPDNã®ã»ãã¥ãªãã£è
åšã«é¢ããçµ±äžãããåæããŒã¿ãå«ãŸããŠããŸãã
- ã³ããŒãŸãã¯éæ³ãªé
åžãç®çãšããæè¡ãã£ãã«ã§ã®PDã®ååïŒåé€ïŒ
- PDãå€æŽãã³ããŒãéæ³ã«é
åžããããã®ISPDnãžã®ç¡èš±å¯ã®ã¢ã¯ã»ã¹ããŸãã¯PDãç Žå£ãŸãã¯ãããã¯ããããã«ãœãããŠã§ã¢ããã³ããŒããŠã§ã¢ãœãããŠã§ã¢ããŒã«ã䜿çšããŠåŠçãããISPDèŠçŽ ããã³PDã«å¯Ÿããç Žå£å¹æ
è
åšã®æ£åŒãªèª¬æãå®çŸ©ããŸãã
- æè¡ãã£ãã«ãä»ããæŒæŽ©ã®è
åšïŒ= <è
åšã®çºçæº>ã<å人ããŒã¿ããã³åœ±é¿ã®é
ä¿¡ç°å¢/æ
å ±ã®åä¿¡æ©/ä¿¡å·ã®éä¿¡æ©>ã<ã¡ãã£ã¢ããŒã¿>
- NSDè
åšïŒ= <è
åšã®ãœãŒã¹>ã<ãœãããŠã§ã¢ãŸãã¯ããŒããŠã§ã¢ã®è匱æ§>ã<è
åšã®å®è£
æ¹æ³>ã<圱é¿ã®ã¿ãŒã²ãã>ã<äžæ£ã¢ã¯ã»ã¹>ã
- ISDNã®ISDè
åšïŒ= <è
åšã®ãœãŒã¹>ã<ISDNã®è匱æ§>ã<è
åšã®å®è£
æ¹æ³>ã<ã¿ãŒã²ããïŒããã°ã©ã ããããã³ã«ãããŒã¿ãªã©ïŒ>ã<ç Žå£ã¢ã¯ã·ã§ã³>ã
- ãµãŒãã¹æåŠã®è
åšïŒ= <è
åšã®ãœãŒã¹>ã<ISPDã®è匱æ§>ã<è
åšã®å®è£
æ¹æ³>ã<ã€ã³ãã¯ããªããžã§ã¯ãïŒPDãã£ãªã¢ïŒ>ã<å³æã®è
åšã®å®è£
çµæïŒãããã¡ãªãŒããŒãããŒãåŠçæé ã®ãããã¯ãåŠçã«ãŒãïŒãªã©ïŒ>;
- ISDNã®PMVè
åšïŒ= <æªæã®ããããã°ã©ã ã®ã¯ã©ã¹ïŒæå®ãããç°å¢ïŒ>ã<è
åšã®ãœãŒã¹ïŒãã«ãŠã§ã¢ãã£ãªã¢ïŒ>ã<æææ¹æ³>ã<æ»æã®ã¿ãŒã²ããïŒããŒãã»ã¯ã¿ãŒããã¡ã€ã«ãªã©ïŒ>ã<èããããç Žå£çãªã¢ã¯ã·ã§ã³ã®èª¬æ>ã<è
åšã«é¢ããè¿œå æ
å ±ïŒå±
äœãäŒæé床ãå€åãªã©ïŒ>ã
è
åšãæ£åŒã«èª¬æããå Žåã次ã®ç¥èªã䜿çšãããŸããã
ISPDn-å人ããŒã¿æ
å ±ã·ã¹ãã ã
äžæ£ã¢ã¯ã»ã¹-äžæ£ã¢ã¯ã»ã¹ã
PMV-ãœãããŠã§ã¢ãšæ°åŠçãªåœ±é¿ïŒãã«ãŠã§ã¢ã®å°å
¥ïŒã
ãã®ææžã¯ãè
åšãšè匱æ§ããã«ãŠã§ã¢ã®åé¡èšå·ã瀺ããŠããŸãã æè¡ãã£ãã«ãä»ãããªãŒã¯ãšäžæ£ã¢ã¯ã»ã¹ã«é¢é£ããå
žåçãªè
åšã®å°ããªã«ã¿ãã°ãæäŸãããŸãã éåè
ã®å
žåçãªã¢ãã«ãäžãããããã®èœåã決å®ãããŸãã
PD 2008ã®çŸåšã®è
åšãå€æããæ¹æ³è«ã¯ ããªã¹ã¯ã®éèŠæ§ã«åºã¥ããŠè
åšããã£ã«ã¿ãªã³ã°ã§ããã¢ã«ãŽãªãºã ãå®çŸ©ããŠããŸãã ãã®ç®çã®ããã«ããã®æ¹æ³è«ã¯ãè
åšãå®çŸããå¯èœæ§ïŒç¢ºçïŒãè
åšã®å±éºæ§ã®ææšïŒæå·ïŒãããã³ã»ãã¥ãªãã£ã®è
åšãç¡é¢ä¿ïŒããããªãªã¹ã¯ïŒãšããŠåé¡ããããã®ã«ãŒã«ã決å®ããæ¹æ³ãæ瀺ããŸãã

åœå®¶æ
å ±ã·ã¹ãã ïŒGISïŒã®è
åšã¢ããªã³ã°ã«é¢ãããã·ã¢ã®FSTECã®ææžãšãã·ã¢ã®FSTECã®è
åšããŒã¿ããŒã¹ã
- ãã·ã¢ã®FSTECã®äœç³»çãªææžã åœå®¶æ
å ±ã·ã¹ãã ã®æ
å ±ã»ãã¥ãªãã£å¯ŸçïŒ2014幎2æ11æ¥ã«ãã·ã¢ã®FSTECã«ããæ¿èªïŒ
- ãã·ã¢ã®FSTECã®æ¹æ³è«ææžã®èæ¡ã æ
å ±ã·ã¹ãã ã®æ
å ±ã»ãã¥ãªãã£ã«å¯Ÿããè
åšãç¹å®ããæ¹æ³
- ãã·ã¢ã®FSTECã®è
åšããŒã¿ããŒã¹ïŒbdu.fstec.ruïŒ ã
ãã·ã¢ã®FSTECã®äœç³»çãªææžã åœå®¶æ
å ±ã·ã¹ãã ã®æ
å ±ã»ãã¥ãªãã£å¯ŸçïŒ2014幎2æ11æ¥ã«ãã·ã¢ã®FSTECã«ããæ¿èªïŒ ã æ
å ±ã»ãã¥ãªãã£ïŒUBIïŒã«å¯Ÿããè
åšã¯ãå€éšããã³å
éšã®éåè
ã®èœåïŒæœåšçãæ©åšãããã³åæ©ïŒãè©äŸ¡ããæ
å ±ã·ã¹ãã ã®æœåšçãªè匱æ§ãæ
å ±ã»ãã¥ãªãã£ã«å¯Ÿããè
åšãå®è£
ããããã®å¯èœãªæ¹æ³ãããã³æ
å ±ã»ãã¥ãªãã£ããããã£ïŒæ©å¯æ§ãæŽåæ§ãã¢ã¯ã»ã·ããªãã£ïŒã®çµæãåæããããšã«ãã£ãŠæ±ºå®ãããŸãã
æ
å ±ã»ãã¥ãªãã£ã®è
åšã®æ£åŒãªèª¬æïŒ
KILLïŒ= [æªçšè
ã®èœåã æ
å ±ã·ã¹ãã ã®è匱æ§ã è
åšãå®è£
ããæ¹æ³ã è
åšã®å®è£
ã®çµæ]ã
éåè
ã®æ©äŒïŒå¯èœæ§ïŒã¯3ã€ã®ã°ã«ãŒãã«åããããŸãã
- åºæ¬çãªå¯èœæ§ãæã€äŸµå
¥è
ã
- ããŒã¹äŸµå
¥è
䟵å
¥è
- æœåšçãªäŸµå
¥è
éåè
ã®èœåã®èª¬æã¯ã
ãã·ã¢ã®FSTECã®æ¹æ³è«ææžã®èæ¡ã«èšèŒãããŠã
ãŸãã æ
å ±ã·ã¹ãã ã®æ
å ±ã»ãã¥ãªãã£ã«å¯Ÿããè
åšãç¹å®ããæ¹æ³ ã
è匱æ§ã®èª¬æãšåé¡ã¯ãåœå®¶æšæºã䜿çšããŠçºçããŸãã
è匱æ§èªäœãè
åšã®å®è£
æ¹æ³ãããã³èããããæ害ã¯
ããã·ã¢ã®FSTECã®ãããã®è
åšã®ããŒã¿ããŒã¹ã«ãªã¹ããããŠã
ãŸã ã
å人ããŒã¿ã®ã»ãã¥ãªãã£ã«å¯Ÿããè
åšã®ã¢ããªã³ã°ã«é¢ãããã·ã¢ã®FSBã®æ¹æ³è«çæšå¥šäºé
- ãé¢é£ãã掻åã®å®æœã®éçšã§éçšãããå人ããŒã¿æ
å ±ã·ã¹ãã ã«ãããå人ããŒã¿ã®åŠçã«é¢é£ããå人ããŒã¿ã®ã»ãã¥ãªãã£ã«å¯Ÿããè
åšãå®çŸ©ããèŠå¶æ³çè¡çºã®éçºã«é¢ããæ¹æ³è«çå§åãïŒ2015幎3æ31æ¥ã«ãã·ã¢é£éŠå®å
šä¿éå±ã«ããæ¿èªN 149/7/2 / 6- 432ïŒ ã
æ¹æ³è«çãªæšå¥šäºé
ã¯ãPDã«å¯Ÿããäž»ãªè
åšã決å®ããŸããããã¯ãæå·æ
å ±ä¿è·ã®å©ããåããŠã®ã¿äžåã§ããŸãã ãããã«ã¯ä»¥äžãå«ãŸããŸãã
- éä¿¡ãããæ
å ±ã®éåè
ã«ããååãŸãã¯ãã®æ
å ±ãžã®äžæ£ãªåœ±é¿ããä¿è·ãããŠããªãéä¿¡ãã£ãã«ãä»ããå人ããŒã¿ã®è»¢éïŒããšãã°ãå人æ
å ±ãå
Œ
±æ
å ±ããã³éä¿¡ãããã¯ãŒã¯ãä»ããŠéä¿¡ããå ŽåïŒã
- æ
å ±ãã£ãªã¢ãžã®å人ããŒã¿ã®ä¿åãéæå·åã®æ¹æ³ãšæ¹æ³ã䜿çšããŠéåè
ã«ããäžæ£ã¢ã¯ã»ã¹ãæé€ããããšã¯ã§ããŸããã
ãã®ããã¥ã¡ã³ãã§ã¯ãéåè
ã®èœåã®åé¡ãå®çŸ©ããŠããŸãã
N | äžè¬åãããæ»æãœãŒã¹æ©èœ |
---|
1 | å¶åŸ¡ããããŸãŒã³ã®å€éšã§ã®ã¿ãæ»ææ¹æ³ã®äœæãæ»æã®æºåããã³å®è¡ãç¬ç«ããŠå®è¡ããæ©èœ
|
2 | CPSããã³ãã®æ©èœç°å¢ãå®è£
ããããŒããŠã§ã¢ïŒä»¥éASãšåŒã³ãŸãïŒãžã®ç©ççã¢ã¯ã»ã¹ãªãã§ãå¶åŸ¡ããããŸãŒã³å
ã§æ»æã®æ¹æ³ãç¬ç«ããŠäœæããæ»æãæºåããã³å®è¡ããæ©èœ |
3 | æå·åæ
å ±ä¿è·ã·ã¹ãã ãšãã®æ©èœç°å¢ãå®è£
ããã¹ããŒã«ãŒãžã®ç©çã¢ã¯ã»ã¹ã䜿çšããŠãå¶åŸ¡ããããŸãŒã³å
ã§æ»ææ¹æ³ãç¬ç«ããŠäœæããæ»æãæºåããã³å®è¡ããæ©èœ |
4 | CIPFã®éçºãšåæã®çµéšãæã€å°é家ãèªèŽããèœåïŒç·åœ¢äŒéä¿¡å·ããã³äºæ¬¡é»ç£æŸå°ãšã¯ãã¹ããŒã¯å¹²æžã®ä¿¡å·ã®åæã®åéã®å°é家ãå«ãïŒ |
5 | æå·åæ
å ±ä¿è·ããŒã«ã®éçºãšåæã®çµéšãæã€å°é家ãåŒãä»ããèœåïŒã¢ããªã±ãŒã·ã§ã³ãœãããŠã§ã¢ã®ææžåãããŠããªãæ©èœã䜿çšããŠæ»æãå®è£
ããåéã®å°é家ãå«ãïŒ |
6 | CIPFã®éçºãšåæã®çµéšãæã€å°é家ãåŒãä»ããèœåïŒCIPFãªãã¬ãŒãã£ã³ã°ç°å¢ã®ããŒããŠã§ã¢ããã³ãœãããŠã§ã¢ã³ã³ããŒãã³ãã®ææžåãããŠããªãæ©èœãæ»æã®å®è£
ã«äœ¿çšããåéã®å°é家ãå«ãïŒ |
ãã·ã¢éè¡ã®æ
å ±ã»ãã¥ãªãã£ãªã¹ã¯ã«é¢ããææž
- 2007幎12æ7æ¥ä»ãã·ã¢é£éŠäžå€®éè¡ããã®æçŽç¬¬197-Tå·ããªã¢ãŒããã³ãã³ã°ã®ãªã¹ã¯ã«ã€ããŠã
- ãã·ã¢éè¡æ¡äŸç¬¬3889-Uã2015幎12æ10æ¥ä»ããå人ããŒã¿æ
å ±ã·ã¹ãã ã§ã®å人ããŒã¿ã®åŠçã«ãããå®éã®å人ããŒã¿ã®ã»ãã¥ãªãã£ã«å¯Ÿããè
åšã®ç¹å®ã«ã€ããŠã
- ãã·ã¢éè¡RS BR IBBS-2.2-2009ã®æšæºååéã«ãããæšå¥šäºé
ã ãæ
å ±ã»ãã¥ãªãã£äŸµå®³ã®ãªã¹ã¯ãè©äŸ¡ããããã®æ¹æ³è«ã
2007幎12æ7æ¥ä»ããã·ã¢é£éŠäžå€®éè¡ã®æçŽ197-Tããªã¢ãŒããã³ãã³ã°ãµãŒãã¹ã®ãªã¹ã¯ã«ã€ããŠãã«ã¯ããªã¢ãŒããã³ãã³ã°ã·ã¹ãã ãšãã®é¡§å®¢ã«å¯Ÿããå
žåçãªè
åšã®ãªã¹ããå«ãŸããŠããŸãã
- RBSãµãŒããŒã«å¯ŸããDoS / DDoSæ»æã
- é»åã¡ãŒã«ã«ãããã£ãã·ã³ã°ã«ããéè¡é¡§å®¢ã®å人æ
å ±ã®çé£ã
- ã¹ããã³ã°æ»æãšåœã®ATMã䜿çšããæ¯æãã«ãŒãã®è©³çŽ°ã®çé£ã
- ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãšé»è©±è©æ¬ºã䜿çšãããªã¢ãŒããã³ãã³ã°ã·ã¹ãã ãžã®é¡§å®¢ã¢ã¯ã»ã¹ã®è©³çŽ°ã®çé£ã
2015幎12æ10æ¥ä»ã®ãã·ã¢éè¡æ¡äŸç¬¬3889-Uå·ããå人ããŒã¿æ
å ±ã·ã¹ãã ã«ãããå人ããŒã¿ã®åŠçã«é¢é£ããå人ããŒã¿ã»ãã¥ãªãã£ã®è
åšã®ç¹å®
ãã«ã¯ã以äžã®è
åšãå«ãæ¥çåºæã®å人ããŒã¿ã»ãã¥ãªãã£ã®è
åšã®ãªã¹ããå«ãŸããŠããŸãã
- å人ããŒã¿æ
å ±ã·ã¹ãã ã®äœæãéçšãä¿å®ãããã³ïŒãŸãã¯ïŒä¿®çãè¿ä»£åãå»çæãå«ããå人ããŒã¿æ
å ±ã·ã¹ãã ã§èš±å¯ããã人ç©ã«ããå人ããŒã¿ãžã®äžæ£ã¢ã¯ã»ã¹ã®è
åšã
- å人ããŒã¿æ
å ±ã·ã¹ãã ã®å€éšã«ããæªæã®ããã³ãŒãã«ãããããè
åšã
- å人ããŒã¿æ
å ±ã·ã¹ãã ã®æš©éãæã€äººã«å¯ŸãããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ææ³ã®äœ¿çšã®è
åšã
- çå€ãããå人ããŒã¿ãã£ãªã¢ãžã®äžæ£ã¢ã¯ã»ã¹ã®è
åšã
- å人ããŒã¿æ
å ±ã·ã¹ãã ã®ãŠãŒã¶ãŒã®ããŒã¿ãã«ããŒãœãã«ã³ã³ãã¥ãŒã¿ãŒãå«ããå人ããŒã¿ã¹ãã¬ãŒãžã¡ãã£ã¢ã®æ倱ïŒæ倱ïŒã®è
åšã
- å人ããŒã¿ä¿è·çµç¹ã®è匱æ§ãå©çšãããå人ããŒã¿æ
å ±ã·ã¹ãã ã«æš©éãæããªã人ã«ããå人ããŒã¿ãžã®äžæ£ã¢ã¯ã»ã¹ã®è
åšã
- å人ããŒã¿æ
å ±ã·ã¹ãã ã®ãœãããŠã§ã¢ã®è匱æ§ã䜿çšããŠãå人ããŒã¿æ
å ±ã·ã¹ãã ã«æš©éãæããªã人ã«ããå人ããŒã¿ãžã®äžæ£ã¢ã¯ã»ã¹ã®è
åšã
- ãããã¯ãŒã¯çžäºäœçšããã³ããŒã¿äŒéãã£ãã«ãä¿è·ããè匱æ§ã䜿çšããŠãå人ããŒã¿æ
å ±ã·ã¹ãã ã«æš©éãæããªã人ã«ããå人ããŒã¿ãžã®äžæ£ã¢ã¯ã»ã¹ã®è
åšã
- å人ããŒã¿æ
å ±ã·ã¹ãã ã®ã³ã³ãã¥ãŒã¿ãŒãããã¯ãŒã¯ãä¿è·ããè匱æ§ã䜿çšããŠãå人ããŒã¿æ
å ±ã·ã¹ãã ã®æš©éãæããªã人ã«ããå人ããŒã¿ãžã®äžæ£ã¢ã¯ã»ã¹ã®è
åšã
- æå·æ
å ±ä¿è·æ段ã®éçšèŠä»¶ãžã®éåã«ããåŒãèµ·ããããè匱æ§ã䜿çšãããå人ããŒã¿æ
å ±ã·ã¹ãã ã®æš©éãæããªã人ã«ããå人ããŒã¿ãžã®äžæ£ã¢ã¯ã»ã¹ã®è
åšã
ãã·ã¢éè¡RS BR IBBS-2.2-2009ã®æšæºååéã«ãããæšå¥šäºé
ã ãæ
å ±ã»ãã¥ãªãã£äŸµå®³ã®ãªã¹ã¯ãè©äŸ¡ããããã®æ¹æ³è«ããã®ããã¥ã¡ã³ãã§ã¯ã次ã®ãªã¹ã¯è©äŸ¡æé ãæäŸããŠããŸãã
æé 1. ISéåã®ãªã¹ã¯ãè©äŸ¡ããããã®æé ãå®è¡ãããæ
å ±è³ç£ã®ã¿ã€ãã®ãªã¹ãã決å®ããŸãïŒä»¥äž-ISéåã®ãªã¹ã¯ãè©äŸ¡ããé åïŒã
æé 2. ISéåãªã¹ã¯è©äŸ¡é åã®æ
å ±è³ç£ã®åã¿ã€ãã«å¯Ÿå¿ããç°å¢ãªããžã§ã¯ãã®ã¿ã€ãã®ãªã¹ãã決å®ããŸãã
æé 3.æé 2ã®äžéšãšããŠå®çŸ©ãããç°å¢ãªããžã§ã¯ãã®çš®é¡ããšã«è
åšã®åå ãç¹å®ããŸãã
æé 4.æé 2.3ã®äžéšãšããŠå®çŸ©ãããŠããçš®é¡ã®ç°å¢ãªããžã§ã¯ãã«é©çšãããISè
åšã®ISSã®æ±ºå®ã
æé 5. ISéåã®ãªã¹ã¯è©äŸ¡ã®é åã®æ
å ±è³ç£ã®çš®é¡ã«å¯ŸããSTF ISéåã®å€å®ã
æé 6.æ
å ±ã»ãã¥ãªãã£äŸµå®³ã®ãªã¹ã¯è©äŸ¡ã
ãªã¹ã¯èš±å®¹åºŠã¯ã確çãšå¯èœæ§ã®ããæ害ãèæ
®ããŠããªã¹ã¯è©äŸ¡ã®ãã¯ã©ã·ãã¯ãããŒãã«ã䜿çšããŠè©äŸ¡ããããšãææ¡ããŸãã

ããã§ãSVRã¯è
åšãå®çŸã§ããçšåºŠã§ãããSTPã¯çµæã®é倧床ã§ã
æšå¥šäºé
ã«ã¯ãã¯ã©ã¹ããšã«åé¡ãããè
åšã®å°ããªã«ã¿ãã°ãå«ãŸããŠããŸãã
ã¯ã©ã¹1.èªç¶ãæè¡çã瀟äŒçæ§è³ªã®æ害äºè±¡ã«é¢é£ããISè
åšã®ãœãŒã¹
ã¯ã©ã¹2ã®ãã掻åã«é¢é£ããæ
å ±ã»ãã¥ãªãã£ã®è
åšã®æºãšç¯çœªãããŠãã人ç¯çœªã¯ã©ã¹3.çŽå
¥æ¥è
/ãããã€ã/ããŒãããŒã®æŽ»åã«é¢é£ããæ
å ±ã»ãã¥ãªãã£ã®è
åšã®æºã¯ã©ã¹4.誀åäœãæ
éãç Žå£/æå·æ¿çã«é¢é£ããæ
å ±ã»ãã¥ãªãã£ã®è
åšã®æºãããŠæ段ã®ã¯ã©ã¹5.ãœãŒã¹ã¯ãé¢é£ããã€ã³ãµã€ããŒIBã®ããè
åšIS6.ã¯ã©ã¹å€éšã®è
åšæŽ»åã®éåIB IBã®ã«é¢é£ããæ
å ±æº7.ã¯ã©ã¹ã®ãœãŒã¹ãäžäžèŽTREBã«é¢é£ããè
åšIS ç£ç£æ©é¢ããã³èŠå¶æ©é¢ã®èŠä»¶ãé©çšæ³ããã·ã¢é£éŠã®åœå®¶åºæºïŒGOSTïŒ
- 51275-2006. . . , .
- / 13569-2007. .
- 56545-2015 . .
- 56546-2015 . .
- 53113.1-2008 (). , . 1.
- 52448-2005 . .
- GOST R ISO / IEC 27005-2010ãæ
å ±æè¡ãã»ãã¥ãªãã£æ¹æ³ãšããŒã«ãæ
å ±ã»ãã¥ãªãã£ãªã¹ã¯ç®¡ç
GOST R 51275-2006ãæ
å ±ä¿è·ãæ
å ±åã®å¯Ÿè±¡ãæ
å ±ã«åœ±é¿ãäžããèŠå ãäžè¬æ¡é
ãã®GOSTã¯ãã€ããªãã®ãŒçã«GOST R 50922-2006æ
å ±ã»ãã¥ãªãã£ã«é¢é£ããŠããŸããäž»ãªçšèªãšå®çŸ©ãæ¹æ³è«ææžãæ©å¯æ
å ±ã®ä¿è·ã«é¢ããç¹å¥ãªèŠä»¶ãšæšå¥šäºé
ïŒSTR-KïŒãïŒCPDïŒãããã³æ
å ±å察象ã®èªèšŒã«é¢ããæ¢åã®ææžããã®ææžã«ã¯ãæ
å ±ã»ãã¥ãªãã£ã«å¯Ÿããè
åšãšè§£éãããå¯èœæ§ã®ããæ
å ±ã«åœ±é¿ãäžããèŠå ã®åé¡ãå«ãŸããŠããŸããGOST R ISO / 13569-2007ãŸã§ãéèãµãŒãã¹ãæ
å ±ã»ãã¥ãªãã£ã«é¢ããæšå¥šäºé
ãã®èŠæ Œã®ä»é²Cã«ã¯ãéèæ©é¢ã®æ
å ±ã»ãã¥ãªãã£ãªã¹ã¯è©äŸ¡ã®äŸãå«ãŸããŠããŸãããã®ç®çã®ããã人å¡ãæ©åšãããžãã¹ã¢ããªã±ãŒã·ã§ã³ãéä¿¡ã·ã¹ãã ããœãããŠã§ã¢ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãªã©ãæ害ãªåœ±é¿ã®äž»ãªãªããžã§ã¯ãéã§åæãè¡ãããšãææ¡ãããŠããŸãããªã¹ã¯ã«ããæ害ã¯ãééçæ倱ãçç£æ§ã®äœäžãè©å€ãžã®æ害ãããã³çµæãšããŠçããæ害ã®åœ¢ã§è©äŸ¡ãããŸãã
GOST R 56545-2015æ
å ±ã»ãã¥ãªãã£ãæ
å ±ã·ã¹ãã ã®è匱æ§ãè匱æ§èšè¿°ã«ãŒã«ãšGOST R 56546-2015æ
å ±ä¿è·ãæ
å ±ã·ã¹ãã ã®è匱æ§ãæ
å ±ã·ã¹ãã ã®è匱æ§ã®åé¡ã¯ãæ
å ±ã·ã¹ãã ã®è匱æ§ãèšè¿°ããã®ã«åœ¹ç«ã¡ãŸããåºæºã¯ãåºæ¬ãšäœµããŠé©çšãããŸãGOST R 50922-2006æ
å ±ã»ãã¥ãªãã£ãäž»èŠãªçšèªãšå®çŸ©ããã®èŠæ Œã¯ã3ã€ã®åé¡å±æ§ãå«ãæ
å ±ã·ã¹ãã ã®è匱æ§ã®åé¡ãæäŸããŸãã- åç£å°å¥
- IPæ¬ é¥ã®çš®é¡å¥ã
- çºçå ŽæïŒçç¶ïŒã
次ã®ã»ã¯ã·ã§ã³ãå«ããã¹ããŒãã®åœ¢åŒã§è匱æ§èªäœãèšè¿°ããããšãææ¡ãããŠããŸãã- è匱æ§ã®ååã
- è匱æ§ID
- ä»ã®è匱æ§èšè¿°ã·ã¹ãã ã®èå¥åã
- è匱æ§ã®ç°¡åãªèª¬æã
- è匱æ§ã¯ã©ã¹ã
- ãœãããŠã§ã¢ã®ååãšãã®ããŒãžã§ã³ã
- ãœãããŠã§ã¢ã®æ©èœã«äœ¿çšããããµãŒãã¹ïŒããŒãïŒã
- ãœãããŠã§ã¢ããã°ã©ãã³ã°èšèªã
- æ¬ é¥ã®ã¿ã€ãã
- è匱æ§ã®çºçå ŽæïŒçç¶ïŒã
- æ¬ é¥ã¿ã€ãèå¥åã
- ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ååãšããŒããŠã§ã¢ãã©ãããã©ãŒã ã®çš®é¡ã
- .
- , .
- () .
è匱æ§ãæ€åºããããã®èŠåã®èšèªãšããŠãæšæºã¯OVALã®äœ¿çšãææ¡ããŠããŸããGOST R 53113.1-2008æ
å ±æè¡ïŒITïŒãç§å¯ãã£ãã«ã䜿çšããŠå®è£
ãããæ
å ±ã»ãã¥ãªãã£ã®è
åšããã®æ
å ±æè¡ããã³èªåã·ã¹ãã ã®ä¿è·ã第1éšäžè¬èŠå®ãã®èŠæ Œã¯ãæ
å ±æè¡ã·ã¹ãã ããã³èªååã·ã¹ãã ã®éçºè
ã«ãã£ãŠæäŸãããŠããªãã»ãã¥ãªãã£ããªã·ãŒã«éåããããã«äœ¿çšã§ããéä¿¡ãã£ãã«ãšããŠå®çŸ©ããããé ããã£ãã«ã«é¢é£ããè
åšã«ã€ããŠèª¬æããŸãã
GOST R 52448-2005æ
å ±ã»ãã¥ãªãã£ãéä¿¡ãããã¯ãŒã¯ã®ä¿è·ãäžè¬èŠå®ãã®ææžã¯ãéä¿¡äºæ¥è
åãã®æ¹æ³è«ææžã§ãããéä¿¡ãããã¯ãŒã¯ãä¿è·ããããã®äžè¬çãªã¢ã¯ã·ã§ã³ã¹ããŒã ãå«ãŸ
ããŠããŸããGOSTR 51275-2006ãè
åšã¢ããªã³ã°ããã»ã¹ã®åºç€ãšããŠäœ¿çšããããšãææ¡ããŸããæ
å ±ä¿è·ãæ
å ±åã®å¯Ÿè±¡ãæ
å ±ã«åœ±é¿ãäžããèŠå ãäžè¬èŠå®ããã®æšæºã¯ãéåè
ã®ã¢ãã«ãæäŸããŸãããã®ããã¥ã¡ã³ãã®ç¹åŸŽã¯ãæ©å¯æ§ãå®å
šæ§ãã¢ã¯ã»ã·ããªãã£ãªã©ã®æ
å ±ã»ãã¥ãªãã£ã®å€å
žçãªç¹æ§ã«å ããŠãèŠæ Œã説æ責任ãèæ
®ããããšã§ãã説æ責任ã®äžã§ãæšæºã¯ããªããžã§ã¯ãã®ãããã¯ãŒã¯å
ã®ã¢ã¯ã·ã§ã³ã®æ確ãªè¿œè·¡ãæäŸããããããã£ãå®çŸ©ããŸãã説æ責任ã®éå-ãããã¯ãŒã¯äžã®ã¢ã¯ã·ã§ã³ã®æåŠïŒå®å
šãªéä¿¡ã»ãã·ã§ã³ãžã®åå ãªã©ïŒãŸãã¯åœé ïŒããšãã°ãå¥ã®ãªããžã§ã¯ãããåä¿¡ãŸãã¯éä¿¡ããããšãããæ
å ±ããã³ã¯ã¬ãŒã ã®äœæïŒãGOST R ISO / IEC 27005-2010ãæ
å ±æè¡ãã»ãã¥ãªãã£æ¹æ³ãšããŒã«ãæ
å ±ã»ãã¥ãªãã£ãªã¹ã¯ç®¡çãã®æšæºã¯ãå€ãã®å ŽåISO 27KãšåŒã°ããæ
å ±ã»ãã¥ãªãã£æšæºã®ã°ã«ãŒãã®äžéšã§ãããã®ããã¥ã¡ã³ãã¯ãæ
å ±ã»ãã¥ãªãã£ãªã¹ã¯ã管çããããã®ç®¡çæé ã«çŠç¹ãåœãŠãŠããŸãã
ä»é²Cã¯å
žåçãªè
åšã®äŸã瀺ããä»é²Dã¯å
žåçãªè匱æ§ã瀺ããŠããŸããNISTç¹å¥åºçç©
- NIST SP 800-30ããªã¹ã¯è©äŸ¡ãå®æœããããã®ã¬ã€ã
- NIST SP 800-39ãæ
å ±ã»ãã¥ãªãã£ãªã¹ã¯ã®ç®¡ç
NIST SP 800-30ããªã¹ã¯è©äŸ¡ãå®æœããããã®ã¬ã€ããã®ããã¥ã¡ã³ãã¯ãçµç¹ã®ç®¡çã¬ãã«ã§ã®ãªã¹ã¯ç®¡çã®åé¡ã«çŠç¹ãåœãŠãŠããŸãã
NIST SP 800-39ãæ
å ±ã»ãã¥ãªãã£ãªã¹ã¯ã®ç®¡çãã®ããã¥ã¡ã³ãã§ã¯ããšã³ã¿ãŒãã©ã€ãºã¬ãã«ã®æ
å ±ã»ãã¥ãªãã£ãªã¹ã¯ç®¡çæ¹æ³ã«ã€ããŠèª¬æããŸããæ¹æ³è«ã®äž»ãªç®æšã¯ãæ
å ±ã»ãã¥ãªãã£ã·ã¹ãã ãçµç¹ã®ããã·ã§ã³ãšç®æšã«çµã³ä»ããããšã§ãã
OCTAVEïŒéçšäžé倧ãªè
åšãè³ç£ãããã³è匱æ§ã®è©äŸ¡ïŒ
OCTAVEã¯æ
å ±ã»ãã¥ãªãã£ãªã¹ã¯ç®¡çæ¹æ³è«ã§ããããã®äž»ãªç®æšã¯ãæ
å ±ä¿è·ããã»ã¹ã®ç®æšãçµç¹ã®ç®æšãšç®æšãšäžèŽããããã«ããããšã§ããæ¹æ³è«ã¯8ã€ã®äž»èŠãªã¹ãããã§æ§æãããŸãã
- ãªã¹ã¯æž¬å®åºæºã®å®çŸ©ïŒãªã¹ã¯æž¬å®åºæºã®ç¢ºç«ïŒã
- æ
å ±è³ç£ã®ãããã¡ã€ã«ã®éçºïŒæ
å ±è³ç£ãããã¡ã€ã«ã®éçºïŒã
- æ
å ±è³ç£ã®ä¿ç®¡/åŠç/転éã®å Žæã®èå¥ïŒæ
å ±è³ç£ã³ã³ããã®èå¥ïŒã
- æ
å ±ã»ãã¥ãªãã£ã«å¯Ÿããé«ã¬ãã«ã®è
åšã®ã°ã«ãŒãã®ç¹å®ïŒæžå¿µé åã®ç¹å®ïŒ
- è
åšã·ããªãªãç¹å®ãã
- æ
å ±ã»ãã¥ãªãã£ãªã¹ã¯ã®ç¹å®ïŒãªã¹ã¯ã®ç¹å®ïŒ
- æ
å ±ã»ãã¥ãªãã£ãªã¹ã¯åæïŒãªã¹ã¯åæïŒ
- 軜æžã¢ãããŒããéžæãã
æé 5ã§è
åšãç¹å®ããã«ã¯ãè
åšããªãŒã®æ¹æ³è«ã䜿çšããŸãããã©ã€ã¯æ¹æ³è«
Trikeã¯ãæ
å ±ã»ãã¥ãªãã£ãæ§ç¯ããããã®ãªã¹ã¯ããŒã¹ã®ã¢ãããŒãã«åºã¥ããŠãããæ
å ±ã»ãã¥ãªãã£ç£æ»ãå®æœããè
åšã¢ãã«ãæ§ç¯ããããã«èšèšãããŠããŸãããã®æ¹æ³ã®ç¹åŸŽã¯æ¬¡ã®ãšããã§ãã- è
åšã¢ãã«ãæ§ç¯ããããã®ç¹å¥ãªãœãããŠã§ã¢ã®äœ¿çšã«æåã«çŠç¹ãåœãŠã
- ã»ãã¥ãªãã£ã®è
åšã説æããããã®ãæ»æããªãŒãã®äœ¿çšã
- å
žåçãªæ»æã©ã€ãã©ãªã®äœ¿çšã
ãã€ã¯ããœããã®è
åšã¢ããªã³ã°æè¡ãšåºçç©
ãã€ã¯ããœããã¯ãã»ãã¥ãªãã£éçºã©ã€ããµã€ã¯ã«ææ³ã䜿çšããŠå®å
šãªãœãããŠã§ã¢ãéçºããŠããŸãããã®æ¹æ³è«ã¯ãã»ãã¥ãªãã£ã«é¢é£ããè¿œå ã®ã¹ããããå°å
¥ãããã¯ã©ã·ãã¯ã- ãœãããŠã§ã¢éçºã®ã«ã¹ã±ãŒãã¢ãã«ïŒããŠã©ãŒã¿ãŒãã©ãŒã«ãïŒã®æ¡åŒµã§ãããèšèšã段éã§ã¯ãè
åšã®ã¢ããªã³ã°ãè¡ãããšãææ¡ãããŠããŸãã
ããã€ãã®ã¢ãããŒãã䜿çšããŠè
åšãèå¥ããããšãææ¡ãããŠããŸãã- STRIDEæ¹æ³è«;
- è
åšåé¡åã®äœ¿çšã
- è
åšããªãŒãšæ»æãã¿ãŒã³ã䜿çšããŸãã
STRIDEæ¹æ³è«ã¯ãæ»æãå®è£
ããããã«äœ¿çšããããšã¯ã¹ããã€ãã®ã¿ã€ããŸãã¯æ»æè
ã®åæ©ã«å¿ããŠãæ»æãèšè¿°ããããã®åé¡ã¹ããŒã ã§ããSTRIDEã¯ãæåã®æåã®é åèªã§ãã- Sã¢ã€ãã³ãã£ãã£poofing - ã«å人æ
å ±ã®çé£ãã䟵å
¥è
ã¯æ£åœãªãŠãŒã¶ãŒã®ãµããããŠïŒããšãã°ããŠãŒã¶ãŒå/ãã¹ã¯ãŒããçãã ïŒã圌ã«ä»£ãã£ãŠæªæã®ããã¢ã¯ã·ã§ã³ãå®è¡ããŸãã
- Tã®ããŒã¿ã䜿çšããampering - «åœã®ããŒã¿ãã䟵å
¥è
ã¯ãWebã¢ããªã±ãŒã·ã§ã³ã®å®è¡æã«ã¢ã¯ã»ã¹å¯èœãªããŒã¿ãæ¹ããããŸãããããã¯ãCookieãHTTPèŠæ±èŠçŽ ãªã©ã§ãã
- Rã® epudiation - «ååŒã®æ絶ãã䟵å
¥è
ã¯ãWebã¢ããªã±ãŒã·ã§ã³åŽã§ãŠãŒã¶ãŒã¢ã¯ã·ã§ã³ã®ååãªç£æ»ãè¡ãããŠããªãå Žåããã©ã³ã¶ã¯ã·ã§ã³ãæåŠã§ããŸãã
- I nformationé瀺- ã«æ©å¯æ
å ±ã®é瀺ãéåè
ã¯ãä»ã®ãŠãŒã¶ãŒã®å人ããŒã¿ãèªèšŒæ
å ±ãªã©ãé瀺ããããšããŸãã
- D enialãµãŒãã¹ã®- «ãµãŒãã¹æåŠãã
- Eã®ç¹æš©ã®levation - «ç¹æš©ã®ææ Œãã
è
åšãç¹å®ããåŸãSDLã¯ããããçæãããªã¹ã¯ã®è©äŸ¡ãææ¡ããŸããããã«ã¯ãDREAD ãã¯ããã¯ã䜿çšã§ããŸããDREADæ¹æ³è«ã®ååã¯ããªã¹ã¯ãè©äŸ¡ããã«ããŽãªã®æåã®æåã®é åèªã§ããããŸãã- Dè
åšãå®çŸãããŠããå Žåãåå ãšãªããŸãã©ã®ãããã®è¢«å®³- Amageã®å¯èœæ§ïŒ
- Rã® eproducibility -ããã¯è
åšãå®çŸããããšãããã«ç°¡åã§ããïŒ
- Eã® xploitability -æ»æãè¡ãå¿
èŠããããŸããïŒ
- ãªãã©ã€ã³ffectedãŠãŒã¶ãŒ-æ»æã®åœ±é¿ãåããããšãã§ããŸãã©ã®ããã«å€ãã®äººã
ïŒ
- Dã® iscoverability -ã¡ããã©ã¢ã¿ãã«ãŒãšããŠã¯è
åšãæ€åºããããšãã§ããŸããïŒ
ãªã¹ã¯èªäœã¯æ¬¡ã®åŒã§è©äŸ¡ãããŸãïŒRisk_DREAD =ïŒDAMAGE + REPRODUCIBILITY + EXPLOITABILITY + AFFECTED USERS + DISCOVERABILITYïŒ/ 5ãæ§æèŠçŽ ã®å€ã¯0ãã10ãŸã§å€åããŸããããšãã°ãæœåšçãªæå·å€ã¯æ¬¡ã®ããã«å®çŸ©ã§ããŸãïŒ- 0 =æå·ãªãã
- 5 =æå·ã¯ã·ã¹ãã ã®äžéšãŸãã¯éãããéã®ããŒã¿ã«ã®ã¿çºçããŸãã
- 10 =ã·ã¹ãã å
šäœã圱é¿ãåãããããã¹ãŠã®ããŒã¿ãç Žå£ãããŸãã
è
åšã«ã¿ãã°
- OWASP Top10
Webã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿããäž»ãªè
åšã«ã€ããŠèª¬æããŸãã
- OWASP Testing project
Web-. - WASC Threat Classification
, Web-.
- Bluetooth Threat Taxonomy
Bluetooth.
- ENISA Threat Landscape
, .
- ENISA Threat Taxonomy
, . - BSI Threat catalogue
, (, , . .).
- Open Threat Taxonomy
, JSON , .
- US DoD Comprehensive Military Unmanned Aerial Vehicle smart device ground control station threat model
, .
- VoIP Security and Privacy Threat Taxonomy
, VoIP.
- Mobile Threat Catalogue
NIST, , . - ATT&CK
, .
- -2.2-2009. « »
, .
. .
- GOST R 51275-2006ãæ
å ±ä¿è·ãæ
å ±åã®å¯Ÿè±¡ãæ
å ±ã«åœ±é¿ãäžããèŠå ã
æ
å ±ã»ãã¥ãªãã£ã«å¯Ÿããå
žåçãªè
åšãèšè¿°ããæšæºã®äžè¬èŠå®ãæè¡ãã£ãã«ãä»ããæ
å ±æŒæŽ©ã«é¢é£ããè
åšã«ã¯ãå€ãã®æ³šæãæãããŠããŸãã
- è
åšã®åºæ¬ã¢ãã«PDN FSTECã2008ã
å人ããŒã¿ã®ã»ãã¥ãªãã£ã«å¯Ÿããå
žåçãªè
åšã®åé¡ã¹ããŒã ãšãæãå¯èœæ§ã®é«ãå°æ°ã®è
åšã®èª¬æãå«ããã·ã¢ã®FSTECã®ããã¥ã¡ã³ãã