ãžã¥ãªã¢ã³ã»ã¢ãµã³ãžã¯ ããã©ãªãŒã»ã¯ãªã³ãã³ã圌ã®å人çãªæµãšèããŠãããšèšããŸãã ã ããã§åœŒã¯ããã¡ã³ã·ãŒãã¢ã®ããã«ãŒãç±³åœæ°äž»å
å
šåœå§å¡äŒããçãã ææžãçºè¡ããã®ãæäŒããŸãã西åŽã®åœ¹äººãã»ãã¥ãªãã£ã®å°é家ããã®é°è¬è«è
ã¯æè¿ããã·ã¢æ¿åºããã®åœä»€ãå®è¡ãããšããããã·ã¢ã®ããã«ãŒã®è©±é¡ã«ã€ããŠæŽ»çºã«è°è«ããŠããã ãµã€ããŒè»ã¯æ¬åœã«ãã·ã¢ã«ååšããŸããããããšãåœé ã§ããïŒ ãµã€ããŒã¹ãã€ã«é¢äžããã¢ã¡ãªã«ã®æ¿æ²»å®¶ã«å¯Ÿããç¯çœªã®èšŒæ ã匷èŠããŠããã®ã¯èª°ã§ããïŒ
ãµã€ããŒæŠäºã®å§ãŸãã Stuxnet
ãµã€ããŒã¹ããŒã¹ã«ããã察ç«ãšããŠã®ãµã€ããŒæŠäºã¯ãæ
å ±æŠäºã®çš®é¡ã®1ã€ã§ãã äŒçµ±çã«ãã¢ã¡ãªã«äººã¯ãã®é¢ã§åŒ·ãã§ãã æåãªã³ã³ãã¥ãŒã¿ãŒã¯ãŒã
Stuxnetã西æŽè«žåœã«ãã£ãŠéå§ãããç§å¯ã®ããã«ãŒæäœã®äžéšã§ãã£ãããšã¯ãã»ãŒç¢ºå®ãªäºå®ãšèããããŠããŸãã æé«ã¬ãã«ã§ãã€ãŸãç±³åœå€§çµ±é ã«ãã£ãŠæ¿èªãããŸããã
2012幎6æãDavid Sanger
ã®æ¬
ã察決ãšé èœïŒãªããã®ç§å¯ã®æŠäºãšã¢ã¡ãªã«ã®åã®é©ãã¹ã䜿çšã㯠ãç±³åœãåœå€ã§ãã®åãã©ã®ããã«äœ¿çšããŠãããã®è©³çŽ°ãªèª¬æãšããŠå¿
èªãšããŠåºçãããŸãã ãããããµã³ã¬ãŒã¯æåãªãžã£ãŒããªã¹ãã§ããããã¥ãŒãªããã¡ãŒè³ã2ååè³ãããã¥ãŒãšãŒã¯ã¿ã€ã ãºã¯ã·ã³ãã³æ¯å±ã®ããŒãã§ãããå€äº€åé¡è©è°äŒã®ã¡ã³ããŒã§ãã
æ¬ã®äžã§ãèè
ã¯ãã€ã©ã³ã®æ žèšç»ã«å¯ŸããŠç±³åœãšã€ã¹ã©ãšã«ã«ãã£ãŠè¡ããã
äœæŠããªãªã³ããã¯ç«¶æ倧äŒãã®è©³çŽ°ãæããã«ããŠããŸãã ãã®æäœã®äžéšã¯Stuxnetã¯ãŒã ã§ãããã¯ã€ã©ã³ãæ žå
µåšãäœæããã®ã劚ããã¯ãã§ããã
Stuxnetã¯ãSimatic S7ãã©ã³ãã®ããã°ã©ããã«ããžãã¯ã³ã³ãããŒã©ãŒãšSiemensã®SCADAã·ã¹ãã Simatic WinCCã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ãšã®éã®æ
å ±ã®æµããååããã³å€æŽããæåã®ã³ã³ãã¥ãŒã¿ãŒã¯ãŒã ã§ãã ãã®ããã°ã©ã ã®ç¬èªæ§ã¯ããµã€ããŒæ»æã®æŽå²ã§åããŠããŠã€ã«ã¹ãã€ã³ãã©ã¹ãã©ã¯ãã£ãç©ççã«ç Žå£ããé å¿åé¢æ©ã®åäœã¢ãŒãã«ããããªå€æŽãå ããŠãŠã©ã³ãæ¿çž®ãããšããäºå®ã«ãããŸãã
ãã®ãŠã€ã«ã¹ã¯ãWindowsã·ã¹ãã ã®4ã€ã®è匱æ§ãæªçšããŸããã1ã€ã¯0dayã§ãUSBãã©ã€ããä»ããŠæ¡æ£ããŸããã çã®ããžã¿ã«çœ²åïŒRealtekãšJMicronã«ãã£ãŠçºè¡ããã2ã€ã®æå¹ãªèšŒææžïŒã¯ãèŠéããããã¡ã§ããã
察ç«ãšé èœïŒãªãã倧統é ã®ç§å¯ã®æŠäºãšã¢ã¡ãªã«ã®æš©åã®é©ãã¹ã䜿çšããªãã倧統é ãStuxnetã®å®æœã«é¢ãã詳现ãªäŒè°ãéå¬ããæ¹æ³ã説æããæ¬ã 倧統é ã¯çµ¶ããèæã«æã眮ããé²æ©ã«ã€ããŠç¥ãããããã¹ãŠã®æ°ãã段éãæ¿èªããŸããã èè
ã¯ãäŒè°ã«çŽæ¥é¢äžãã蚌人ã®èšèããããããã
ã³ã³ãããŒã«ã«ãŒã ã§ã®äŒè°ã«ã€ããŠèª¬æããŠããŸãã
æäœããªãªã³ããã¯ç«¶æ倧äŒãã¯ããã¶ãééãã§ã¯ãªãã«ãããããããä»ã®å€ãã®ç±³åœã®ç§å¯ã®ãµã€ããŒäœæŠã®ããã«ãäžè¬å€§è¡ã«æ°žé ã«ç¥ãããŠããªãå¯èœæ§ããããŸãã æã
èµ·ããããã«ããã©ãã«ã¯éçºè
ã®ãšã©ãŒãåå ã§èµ·ãããŸããã 2010幎ã®å€ãããã°ã©ãã³ã°ãšã©ãŒã«ãããããã°ã©ã ã¯ã€ã©ã³ã®ã·ã¹ãã ãè¶
ããŠãã·ãŒã¡ã³ã¹P-1é å¿åé¢æ©ãæ¢ããŠãŠã§ãå
šäœã«åºããå§ãã2010幎6æ17æ¥ã«å ±éæ©é¢ã§æåã«å ±åãããŸããã ããã¯ããã©ã«ãŒã·ã®ãŠã€ã«ã¹å¯ŸçäŒç€ŸVirusBlokAdaã®å°é家ã«ãã£ãŠè¡ãããŸããã å
¥æå¯èœãªæ
å ±ã«ãããšããšã©ãŒã¯ããã°ã©ã ã®2çªç®ã®ããŒãžã§ã³ã«ãããã¢ã¡ãªã«äººãšã¯ç¬ç«ããŠãã€ã¹ã©ãšã«ã®ååã«ãã£ãŠäœæãããŸããã
ãã®æ¬ã®èè
ã¯ãStuxnetã®æåã®ããŒãžã§ã³ã¯ãã€ã¹ã©ãšã«è»ã®å°é家ãšç·å¯ã«ååããŠã¢ã¡ãªã«ã®å°é家ã«ãã£ãŠå
倧統é ãžã§ãŒãžWããã·ã¥ã®äžã§æžããããšæžããŠããŸãã ãã®ããã°ã©ã ã«ã¯ãæ žçæã®æ¿çž®ã«äœ¿çšãããã·ãŒã¡ã³ã¹P-1é å¿åé¢æ©ãæ€çŽ¢ããããããç©ççã«ç¡å¹ã«ãããšããç¹å®ã®ç®æšããããŸããã ããã¯ãé å¿åé¢æ©ã®å転é床ã®äºæããªãæžå°ãŸãã¯å¢å ã«ãããã®ã§ãããæçµçã«ã¯é å¿åé¢æ©ãç ŽæããŸããã äœæŠã¯æåãããšå ±åãããŠããŸãããŠã©ã³æ¿çž®é å¿åé¢æ©ã®æ°ã¯äžæçã«5,000ãã4,000ã«æžå°ããã€ã©ã³ã®æ žèšç»ã¯1幎åãã2幎ã§æžéããŸããã åæã«ãStuxnetã®äœæè
ã¯ãã©ãã¯ãã«ããŒããããšãã§ãããããã€ã©ã³ã®å°é家ã¯ãã®äºä»¶ãæ©æ¢°è£
眮ã®åé¡ã«èµ·å ãããšèããŸããã
Stuxnetãäœæãããšããç®æšã¯ããã®åé¡ã«å¯Ÿããå¹³åçãªè§£æ±ºçã§ãããã¢ã¡ãªã«äººã¯ãã€ã¹ã©ãšã«ãã€ã©ã³ã®æ žæœèšãçæããããšã決å®ããããšãéåžžã«æããŠãããããçŽäºã¯å¶åŸ¡äžèœã«ãªããŸãã
Stuxnetã®çºèŠåŸãã€ã©ã³åœå±ã¯ITã€ã³ãã©ã¹ãã©ã¯ãã£ã®ä¿è·ã倧å¹
ã«åŒ·åããååœãã€ã³ã¿ãŒãããããå®å
šã«å€ç«ããŠããããšã«ã€ããŠè©±ãå§ããŸããã ã¢ã¡ãªã«ã®ãããŒã³ãæãããåŸã圌ãã¯ããããããã³ã°ã§ãããšåè«ããŸãã-ããã¯å°å
ã®ã€ã©ã³ã®ããã«ãŒã®èœåã圌ãã«ç€ºãããã«ã¢ã¡ãªã«äººã«ããå ±åŸ©ã§è¡ãããŸããã
ã©ãããããªãªã³ããã¯äœæŠã¯ãç±³åœããµã€ããŒå
µåšã®å©ããåããŠæå³çã«å¥ã®å·ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãŒã«æ»æãä»æããã®ã¯åããŠã®ããšã§ãã ãã®ã±ãŒã¹ã¯ãå€ãã®å€§åœãå«ãçŸåšã®äžççãªãµã€ããŒæŠäºã®å§ãŸããšå
¬åŒã«èŠãªãããšãã§ããŸãã
äžåœè»
äžåœã¯ãåœå®¶ã®äžã«ãããããã³ã°ãŠãããã®ååšãé ããŠããŸããã 2015幎ã«ã
äžåœã®æ°ããè»äºãã¯ããªã³ãå
¬éãããŸãããããã¯ã次ã®3ã€ã®ã¿ã€ãã®æ¢åã®ãŠããããæ瀺çã«ç¶Žã£ãŠããŸãã
- ãããã¯ãŒã¯æŠéçšã®ç¹æ®ãªè»éïŒé²è¡ããã³æ»æäœæŠãå®æœããããã«èšèšãããŠããŸãã
- ãããã¯ãŒã¯éçšãè¡ãããã«è»äºæå°éšã«ãã£ãŠæ¿èªãããæ°éçµç¹ã®å°é家ã®ã°ã«ãŒãã ãåžæ°çµç¹ãã«ã¯ãåœå®¶å®å
šä¿éçãšå
¬å®çããããŸãã
- ãããã¯ãŒã¯éçšã®ããã«ç·šæããã³åå¡ã§ãããå€éšã¢ã¯ã¿ãŒãã
ãããªãã¯ãã¡ã€ã³ã®ä»¥åãäžåœã®äººæ°è§£æŸè»ã®äžéšã§ãããããããŠããã61398ïŒäžæµ·ïŒã®è©³çŽ°
ãå
¬éãããŸãã ã ããã¯ããµã€ããŒãªãã¬ãŒã·ã§ã³ã«ç¹åãããŠãããã®1ã€ã§ãã äž»ã«è±èªåã®åœã
ã§ãã³ã³ãã¥ãŒã¿ãŒã®ã¹ãã€æŽ»åãšåŠšå®³æŽ»åã«åŸäºããŠããŸãã
ãã®èª¿æ»ã§ã¯ãããã«ãŒã°ã«ãŒãAPT1ãããããæ¿åºã®æ¯æŽãåããŠåäœããAPT1ãç£èŠããªããã141ã®çµç¹ã®äŒæ¥ãµãŒããŒããæ
å ±ãäœç³»çã«çãŸããæ°çŸãã©ãã€ãã®ãã¡ã€ã«ãçãŸããããšã確èªãããŸããã 1905幎ã«å ±åãããæ»æã®97ïŒ
ã§ãããã«ãŒã¯äžæµ·ã®IPã¢ãã¬ã¹ãšç°¡äœåäžåœèªã·ã¹ãã ã¬ã€ã¢ãŠãã®ã³ã³ãã¥ãŒã¿ãŒã䜿çšããŸããã ããã«ãŒçµç¹APT1ã®èŠæš¡ã«ã¯ãæ°åãŸãã¯æ°çŸäººã®åå è
ãé¢äžããŠããŸãã äžé¢ã®å°é家ã¯ããã®ãã¡3人ã®èº«å
ã確èªããããšãã§ããŸããã äžåœã®ããã«ãŒãFacebookããã³Twitterã¢ã«ãŠã³ãã«ãã°ã€ã³ãããšãã«ããã€ãã®ã±ãŒã¹ãæ°ã¥ããŸããããããã¯äžåœã®ãã¡ã€ã¢ãŠã©ãŒã«å
ã§ã¯å®è¡ã§ãããããã«ããäººæ Œã®ç¢ºç«ãä¿é²ãããŸããã
以äžã¯Dodaãšããããã¯ããŒã ã§äžåœã®ããã«ãŒã®ã³ã³ãã¥ãŒã¿ãŒã®ã¹ã¯ãªãŒã³ãã£ã¹ãã§ã圌ã®ã¡ãŒã«ããã¯ã¹ã®å
容ãšäœ¿çšãããŠããããã°ã©ã ãèŠãããšãã§ããŸãã
ããã«ãŒãŠããã61398ã®å¥ã®åŸæ¥å¡ã¯ããã³ãã£ã¢ã³ãã®å°é家ã«ãã£ãŠå¿ååããã2006幎ã«å€§åŠãåæ¥ããçŽåŸã«æ¡çšããããš
圌ã®å人çãªããã°ã§è¿°ã¹ãŠããŸãã æåã®ã¿ã¹ã¯ã®1ã€ã¯ãBack Orifice 2000 RATããã°ã©ã ãã¢ã³ããŠã€ã«ã¹ã«ãã£ãŠæ€åºãããªãããã«é©å¿ãããããšã§ããã 圌ã¯McAfeeãSymantecãTrend Microã®ä¿è·ãç¡äºã«åé¿ã§ããŸããããã«ã¹ãã«ã¹ããŒã«ã¯å¯ŸåŠã§ããŸããã§ããã
Wang Dongã¯å¥ã®ã¿ã¹ã¯ã«ã€ããŠèª¬æããŸãããã³ã³ãã¥ãŒã¿ãŒã«æ¥ç¶ãããUSBããã€ã¹ãèªåçã«æ€åºãããããããã¹ãŠã®ãã¡ã€ã«ãå¯ãã«ã³ããŒãããŠã€ã«ã¹ãäœæããããšã§ãã ç§ãã¡ã¯ãã®ã¿ã¹ã¯ã«ããŸã察åŠããäžåžã¯æºè¶³ããŸããããšãŽã¡ã³ã¯æžããŠããŸãã
ããããã¯ãšãªãŒãã®ã¹ãŒããŒããã«ãŒã§ã¯ãããŸããã
ãš ITã»ãã¥ãªãã£ã®ã¹ãã·ã£ãªã¹ãã§ãããªãã£ãŒãã¢ãŒã°ã«ã¯LAã¿ã€ã ãºã®è§£èª¬ã§è¿°ã¹ãŠããŸãã ã誰ãããããã®ç·ãæªéã«ããããã圌ãã¯åœŒãã®åœã®ããã«åã第äžç·ã®æ»æå
µå£«ã§ããã圌ãã¯æªåœ¹ã§ã¯ãªããã
ãã·ã¢ãããã«ãŒãæè·
ã¢ã¡ãªã«ãšäžåœã®ãµã€ããŒéšéã®ç©æ¥µçãªè¡åã§ããã·ã¢ã®ããã«ãŒãå芳è
ã®ãŸãŸã§ãããšä»®å®ããã®ã¯å¥åŠã§ãã äžéšã®å°é家ã«ãããšãæãå
é²çã§å€æ°ã®ããã®ããã«ãŒã·ãŒã³ã圢æãããã®ã¯æ±ãšãŒãããã§ããã åé¡ã¯ãé·ãéã代衚è
ã
æ¿æ²»ã§ã¯ãªããéã«èå³ãæã£ãŠããããšã§ãã
æ°çŸäžäººã®é«åºŠãªæè²ãåããããã°ã©ããŒãããŠã圌ãã®åãçºæ®ããããšã¯äžè¬çã§ã¯ãªãã£ã90幎代ã«å§ãŸããŸããã ãã®åœã«åœŒãã®è³æ Œã«èŠåã£ãé«çµŠã®ä»äºã¯ãããŸããã§ããã åæã«ã欧米ã®ãªã³ã©ã€ã³ã¹ãã¢ã®ã«ãŒãã匷èŠããããã³ã°ã«ãã£ãŠè¯ããéã皌ãããã«ã¯ãéåžžã«æå©ãªèŠçŽ ããããŸããã ãããã®æ¡ä»¶ã¯æ¬¡ã®ãšããã§ãã
- åœå
èŠå¯ã®ã³ã³ãã¥ãŒã¿ãŒéèåçïŒ90幎代ïŒã
- åæ³ã®é¢é£èšäºã®æ¬ åŠïŒåºçŸåŸ-ã³ã³ãã¥ãŒã¿ç¯çœªã®åã®å¯å€§ãïŒã
- åŒãæž¡ãã«å¯Ÿããä¿è·ã
åŒãæž¡ãã«ã€ããŠã ãã·ã¢ã¯ãæãç®ç«ã£ãç¯çœªã®åŸã§ããããã«ãŒãç±³åœã«æ±ºããŠè£åããŸããã§ããã ãã®ãããã¢ã¡ãªã«äººã¯åœŒããtrickãªæ¹æ³ã§PDFããAdobe PDF圢åŒã®é»åæžç±ã®ä¿è·ã
ç Žã£ãããã«ãŒäŒç€ŸElcomsoftã®
ããã°ã©ããŒDmitry SklyarovãšããŠåãããã«èªããŸããã
ãŸãã¯ã2012幎ã«1å6700äžäººã®ãŠãŒã¶ãŒã¢ã«ãŠã³ãã§LinkedInããããã³ã°ãã
Evgeny Nikulinã
æçäžã®2016幎10æ5æ¥ã«ãã©ãã§è¡ãããããã«ãããã«ãŒãç¡è¬ã«é転ããå奜åœã§æçãè¡ããŸããã
ãã¯ãªã³ã®æçã ãã©ãèŠå¯ã®è¿
éãªéæãã·ã¢ã®ããã«ãŒãæµ·å€ã«æçãããåŸã§ãããã·ã¢ã¯å€äº€çãªæªçœ®ãè¬ããŠããã ãã§ãªããå€äº€çãªæªçœ®ãè¬ããŠããããšã«æ³šæããããšãéèŠã§ãã ããšãã°ããã·ã¢ã§NikulinãæçãããçŽåŸ
ãLinkedInã®ãŠã§ããµã€ãã¯
ãããã¯ãããŸãã -ç®èãªããšã«ã
ãããã¯ã®çç±ã¯å人ããŒã¿ã®æŒæŽ©ã ãã§ãããããã·ã¢ã®ããã«ãŒã®é倱ãåå ã§çºçããŸããã ããããå°ãªããšãã¢ã¡ãªã«äººã¯ãã³ããç解ããå¿
èŠããããŸãã LinkedInåŽã§ã¯ãæ°åäžäººã®ãŠãŒã¶ãŒãããåœã§ãããã¯ãããããããNikulinã«å¯Ÿããè«æ±ãæåŠããæ¹ãç°¡åã§ãã
ãäžè¬ã«ããšãã²ããŒã»ãã¯ãªã³åšèŸºã®ç¶æ³ã¯ãäžçäžã®ãã·ã¢åžæ°ã®ããã®ãç©ãããçµç¹ããä»ã®å·ã«ãã®ç®¡èœæš©ã課ããŠããã¯ã·ã³ãã³ã®è·¯ç·ã確èªããŸãã ç§ãã¡ã¯ããã¯ãªã³ã®ãã·ã¢é£éŠãžã®ç§»è»¢ã䞻匵ããŸãã ãã·ã¢åŽã¯ããã©ããåé¡ã®å
¬å¹³ãªè§£æ±ºã®ããã«ããããå¯èœãªæªçœ®ãè¬ããããšãæãã§ããããšããã§ã³å
±ååœã®ãã·ã¢å€§äœ¿é€šã®ä»£è¡šã§ããã¢ã¬ã¯ã»ã€ã»ã³ã«ãã³ãã¯è¿°ã¹ãã
ãã·ã¢é£éŠã®åŒ·åãªåœå®¶æ©é¢ããã·ã¢ã®ããã«ãŒã®åŒãæž¡ããé²ãããã®éäºã«é¢äžãã以åã®äºäŸã®çµéšã«ãããšãä»åã¯ãã·ã¢ã®å€äº€å®ãæåãããšä»®å®ããããšãã§ããŸãã ããã«ãLinkedInèªäœã¯ãã§ã«åœŒãã®åŽã«ããã¯ãã§ãã
ç¶æ
ã®ãµãŒãã¹ã§
è¿å¹Žããã·ã¢ã®ããã«ãŒã·ãŒã³ã«ã¯ããã€ãã®å€æŽãå ããããŠããŸãã åç±³ãããã¬ã³ãã¯ééããªãæåã§ãã
äžéšã®ã»ãã¥ãªãã£å°é家ã«ãããš
ãç±³åœæ°äž»å
å
šåœå§å¡äŒãžã®
ãµã€ããŒæ»æãªã©ãæè¿ã®å€ãã®äž»èŠãªãããã³ã°ã«é¢äžããŠããã®ã¯ãã·ã¢ã®ãåœå®¶ãããã«ãŒã§ãã
ãã¡ã³ã·ãŒãã¢ãã£ã©ã¯ã¿ãŒç±³åœæ°äž»å
å
šåœå§å¡äŒã«å¯Ÿãããµã€ããŒæ»æã®èª¿æ»ã¯ãCrowdStrikeã®ç¬ç«ããå°é家ã«ãã£ãŠå®æœãããŸããã 圌ãã®æèŠã§ã¯ããã·ã¢ã®ããã«ãŒã®2ã€ã®ã°ã«ãŒã-Cozy BearïŒCozyDukeãŸãã¯APT29ïŒãš
Fancy Bear ïŒSofacy GroupãŸãã¯APT28ïŒããªããšãç Žå£ããŸããã Cozy Bearã°ã«ãŒãã¯ã2015幎å€ã«æ
å ±ã·ã¹ãã ãžã®äžæ£ã¢ã¯ã»ã¹ãååŸãã2016幎4æã«Fancy BearãååŸããŸããã
ãžã¥ãªã¢ã³ã»ã¢ãµã³ãžã¯ãçãŸããããŒã¿ããŠã£ããªãŒã¯ã¹ã®ãŠã§ããµã€ãã«æçš¿ããããšã«åæããŸããã
圌ã«ããã°ããã®ããã«ã
㊠ã
圌ã¯ãã©ãªãŒã»ã¯ãªã³ãã³ã倧統é éžæã«åã€ããšãæ¢ããããšãæ¢ãããã£ãã
ããã«ãŒæ»æã倧統é éžæã®çµæã«äžãã圱é¿ã¯ïŒ ã¢ãµã³ãžã®çºèšã¯é¢šå€ããã ãšèããããŠããŸããã ãã©ãªãŒã»ã¯ãªã³ãã³ã¯äžè«èª¿æ»ã®ãªãŒããŒã§ãããã¡ãŒã«ããã¯ã¹ããããã³ã°ããããšã§ããã«ãã»ãã©ã³ãã®ãããªäººç©ã倧統é ã«éžåºãããã»ã©èªåã®ç«å Žã匱ããããšãæ³åããããšã¯ãŸã£ããäžå¯èœã§ããã
誰ããããä¿¡ããŠããŸãã...