è¿å¹Žã倧æäŒæ¥ãæ¿åºæ©é¢ãªã©ãéå¶ãããŠã§ããµã€ãã®æ¹ãããããµã€ããçµç±ããæ å ±æŒããäºä»¶ãªã©ã®å ±éãç®ã«ããããšãæ¥åžžçã«ãªã£ãŠããã
人ã ã®ç掻ãããžãã¹ã®äžã§ãããã®æãã圹å²ãæ¡å€§ããã«ã€ããäžçèŠæš¡ã§æç¢ºã«ç¯çœªãæ å ±è©åãç®çãšãããµã€ããžã®æ»æãå¢ãç¶ããŠãããWebãµã€ããéå¶ããäŒæ¥ãçµç¹ã¯ããã®çŸç¶ãèžãŸããæ¥ã 鲿©ããæ»æææ³ã«å¯ŸããŠé©åã«é²è¡ã®ææ®µãè¬ããããšãæ±ããããŠãããäžæ¹ã§ãå ·äœçãªå¯Ÿçãé²ãããã«ããã©ããã£ãæé ã§ãã©ãããæãä»ããŠããããåããããæãããŸãããŠããæ åœè ãå€ããšããã®ãçŸå®ã§ã¯ãªãã ãããã
|
|
OWASP Japan 代衚ã®å²¡ç°è¯å€ªéæ° |
ãSECURE YOUR SITEãã®ãã©ã³ãåã§äžé£ã®äŒæ¥åãã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãæäŸããSCSKã¯ã6æ6æ¥ã«æ±äº¬éœå代ç°åºã§ããµã€ããŒæ»æã®åŸåãšå¯Ÿçã»ãããŒããéå¬ããã
æ¥æ¬IBMãšã®å ±å¬ã§å®æœããããã®ã»ãããŒã«ã¯ãåºèª¿è¬æŒã®ã¹ããŒã«ãŒãšããŠOWASP Japanã®ä»£è¡šãåãã岡ç°è¯å€ªéæ°ãæãããããå®å šãªWebãµã€ãã®æ§ç¯ãšéå¶ãç®æãã«ããããäŒæ¥ãçµç¹ã®æ åœè ã念é ã«çœ®ãã¹ãäºæããè¿å¹Žã®ãµã€ããŒã»ãã¥ãªãã£ã®ååãæ«é²ãããããŸããåãããŠãå²¡ç°æ°ã代衚ãåããOWASP Japanã®æŽ»åã«ã€ããŠã玹ä»ãè¡ãããã
SCSKããã¯ãå¹ åºãæ¥çã«åããŠãµã€ããŒã»ãã¥ãªãã£å¯Ÿçãœãªã¥ãŒã·ã§ã³ã®æäŸãè¡ã£ãŠããæ åœè 2åãç»å£ããäŒæ¥ã察çãé²ããéã®å ·äœçãªæ¹æ³è«ããå®éã®äºäŸã«ã€ããŠç޹ä»ãè¡ã£ãã
æ±æ¥æ¬å€§éçœããèŠããWebã»ãã¥ãªãã£ã®ã課é¡ã
ãå®å šã»ç¢ºå®ã«çšŒåããWebãµã€ãã®æ°ããæçŸ©ãšäœ¿åœããšé¡ãããåºèª¿è¬æŒã®åé ãå²¡ç°æ°ã¯2011幎3æ11æ¥ã®æ±æ¥æ¬å€§éçœä»¥éã«çšŒåãããããã€ãã®Webãµã€ãã®ç»é¢ãèŽè¡ã«ç€ºããã
å²¡ç°æ°ã¯IPA OSSã»ã³ã¿ãŒã®çºè¶³æããéåžžå€ç ç©¶å¡ãåããŠããããã®ç ç©¶ã®äžç°ãšããŠãéçœçºçåŸã«åæå€çºçã«æ§ç¯ãããã被çœå°æ¯æŽãé¢ä¿è éã®æ å ±å ±æãç®çãšããWebãµã€ãã®èª¿æ»ãè¡ã£ãã瀺ãããã®ã¯ããããããµã€ãã®äžéšã®ã¹ãããã·ã§ããã§ããã
調æ»ã«ããã°ãéçœçºçåŸ3ã«æä»¥å ã«ãçŽ300ã«ã®ãŒãæ¯æŽãµã€ããäœããããã®ãã¡å€ãã®ãã®ã3æ¥ä»¥å ã«ç«ã¡äžãã£ãŠãããšãããåŸ©èæ¯æŽãšããããŒãã«ãããŠãçæéã§ãããã ãã®æ°ã®ãµã€ããæ§ç¯ãããã®ã¯ããã€ãŠäŸãèŠãªãäºäŸã§ãããšåæã«ãã¯ã©ãŠãã®æ®åã«ãã£ãŠãµãŒãã®èª¿éãæ§ç¯ã容æã«ãªã£ãããšãããªãŒãã³ãœãŒã¹ãäžå¿ãšãããœãããŠã§ã¢æ§ç¯æè¡ãäžè¬åããŠããããšãããã®èæ¯ã«ãããšããã
ãµã€ãäžã§å ¬éãããå ±æãããæ å ±ã®äžã«ã¯ãéèŠãªãã®ãå«ãŸããŠããã埩æ§ã«äœããã®åœ¢ã§å®éã«åœ¹ã ã£ããã®ã¯å€ãããšããäžæ¹ã§ãå²¡ç°æ°ã¯ããããã®ãµã€ãã®äžã§ãæ§ç¯ã«ããã£ãŠãåœåããã»ãã¥ãªãã£ãéèŠããŠããã®ã¯ãå šäœã®1å²çšåºŠãã§ãã£ããšææããã
ãã»ãã¥ãªãã£ãéèŠããŠãããšåçããªãã£ããµã€ãã«å¿ ãããè匱æ§ããã£ãããã§ã¯ãªãããŸãããã®éåžžäºæ ã«ãããŠã¯ãè¿ éã«ãµã€ãã皌åãããããšãæåªå ãããäºæ ãçè§£ã§ãããããããªãããå人æ å ±ããã©ã€ãã·ãŒã«é¢ããæ å ±ã¯ãã¡ããã®ããšããéã䟡å€ã®é«ãç©è³ã«é¢ããæ å ±ãæ±ããã®ãå€ãããããã®ãµã€ãã§ããæ§ç¯ã®å¢ãããšãã»ãã¥ãªãã£æèã®å¢ãããå šãéã£ããã®ã§ãã£ãããšã¯ãä»åŸã®å€§ããªèª²é¡ãšèãããããåæã«ãã£ãŠäœããããµã€ãããããã«ã€ã蟌ãã æ»æã§è¢«å®³ãåããŠããŸã£ãŠã¯å°ç¡ãã«ãªããç§ãšããŠã¯ããããªãWebã»ãã¥ãªãã£ã®åèãããã®å ·äœçãªæ§ç¯ææ®µãåºããçè§£ãé«ããŠããããšã®å¿ èŠæ§ã匷ãæããã(å²¡ç°æ°)
å²¡ç°æ°ã¯ãäžè¬çãªåŸåãšããŠãããŒããŠã§ã¢é¢ã«ãããã匷é±ããã«ã€ããŠã¯äºåã«ååã«èæ ®ããããã®ã®ããœãããŠã§ã¢é¢ã§ã¯ãåããŠããããšãæ£çŸ©ãã§ããããã®å ç¢æ§ã匷é±ãã®ç¢ºä¿ã«ã€ããŠã¯ãããŒãã«å¯ŸããŠç«ã¡åŸããŠãããšææãããä»åŸã¯ãœãããŠã§ã¢é¢ã«ã€ããŠããå¹³æããæäºã®ç¶æ³ãæ³å®ãããã®éã®ãã¡ãŒãžã®è»œæžããæ©æ¥ãªå埩ãæã蟌ãã èšç»ãéèŠã«ãªã£ãŠããã ãããšããã
ITã·ã¹ãã ãå«ãBCP(äºæ¥ç¶ç¶èšç»)ã«ãããŠããå¹³æããã®åãã§ããåé·æ§ãå ç¢æ§ã®ã¿ãªãããäœããã®åé¡ãèµ·ããå Žåã«è¿ éã«å¯ŸåŠã§ãããä¿ææ§ãããèšæ©æ§ããæ±ããããããã«ãªã£ãŠãããšããã
è¿å¹Žã®æè¡ç°å¢ãå©çšç°å¢ã®å€åã¯æ¥éã§ããã€è€éããå¢ããŠããããã®ãããªç¶æ³ãèžãŸãããããã§ãŠãŒã¶ãŒã«ãµãŒãã¹ãæäŸããåŽã«æ±ããããã®ã¯ãæ¥ã ãµã€ããéå¶ããäžã§ãã©ã®ãããªãªã¹ã¯ãååšããŠããã®ããç¥ãããšãšãå€åããæè¡ç°å¢ããŠãŒã¶ãŒã®å©çšç°å¢ã«å¿ããŠãã»ãã¥ãªãã£ã®èгç¹ãå å³ããéçšãé²åãããŠããããšã§ãããšããã
ç¹ã«ãæ»æã«å¯Ÿãããããã¯ãŒã¯ã¬ã€ã€ã§ã®é²åŸ¡ãšã¢ããªã±ãŒã·ã§ã³ã¬ã€ã€ã§ã®é²åŸ¡ãå šã質ã®ç°ãªããã®ã§ãããã©ã¡ããäžæ¹ã®å¯Ÿå¿ãçãã«ãªãã°æ·±å»ãªè¢«å®³ãžãšã€ãªããå¯èœæ§ãããç¹ããã¹ããŒããã©ã³ã®æ®åã«ãã£ãŠãéçºåŽãæèãã¹ããã»ãã¥ã¢ããã°ã©ãã³ã°ã®èŠç¹ããå¢ããŠããç¹ãªã©ã«èšåãçŸåšã®ãããç°å¢ã«ãããŠã¯ãåäœã®ãŠã§ããµã€ããã¯ã©ãã¯ãããªãããã«ãããšãã£ãçšåºŠã®ã»ãã¥ãªãã£æèã§ã¯äžååã«ãªã£ãŠããããšææããã
ãããããèæ¯ã®ããšãWebãµã€ãã®ã©ã€ããµã€ã¯ã«ã®äžã§ãã»ãã¥ãªãã£ç¢ºä¿ã®ããã«ã©ã®ãããªããšã«çæããå®è¡ããã°ããã®ããå®å šãªWebãµã€ããå®çŸããããã®ã³ã³ã»ãããšå ·äœçãªæ¹æ³è«ãã©ã®ããã«èŠãåºããã«ã€ããŠãé¢å¿ãé«ãŸã£ãŠããã(å²¡ç°æ°)
Webãã»ãã¥ã¢ã«ããããã®ããŠããŠãéçµãããOWASPã
ãã®èª²é¡ã«åãçµãã§ããäžçèŠæš¡ã®ãã©ã³ãã£ã¢ãããžã§ã¯ãã®ã²ãšã€ãOWASP(The Open Web Application Security Project)ã§ãããå²¡ç°æ°ã¯ããã®æ¥æ¬ãã£ãã¿ãŒã®ä»£è¡šãåããŠãããå ·äœçãªæŽ»åå 容ã«ã€ããŠç޹ä»ããã
OWASPã§ã¯ãWebã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã®åäžãç®æããšãã¹ããŒããããªãŒãã³ãœãŒã¹ãããžã§ã¯ãçãªã³ã©ãã¬ãŒã·ã§ã³ã«ãã£ãŠãã³ãŒããããŒã«ãããã¥ã¡ã³ããªã©ã®ããŸããŸãªææç©ãçã¿ã ããŠãããåå£äœãæ°å¹Žããšã«çºè¡šãããOWASP Top 10ãã¯ããŠã§ãã¢ããªã±ãŒã·ã§ã³ã«ãšã£ãŠãæã泚æãã¹ãè匱æ§ãšããã®å¯ŸåŠæ³ãç¥ãããã®æçšãªãªãã¡ã¬ã³ã¹ãšããŠç¥ãããŠããã
ãŸãOWASPã§ã¯ãã»ãã¥ãªãã£ã«é¢ãããããäžäœã®ãITã¬ããã³ã¹ãã«é¢ããæŽ»åãè¡ã£ãŠãããããã¯ãåå¥ã®ã¢ããªã±ãŒã·ã§ã³ã®å®å šæ§ãããããããéçºããçµç¹å šäœãšããŠããœãããŠã§ã¢ã®å®å šæ§ã確ä¿ããŠããããã®ãæŠç¥ãæè²ãã»ãã¥ãªãã£èŠä»¶ãã¬ãã¥ãŒãç°å¢ãªã©ãããã«ç¢ºä¿ãã¹ããã«ã€ããŠäœç³»åãè¡ã£ãŠãããã®ã ã
æŽ»åææã¯ããœãããŠã§ã¢ã»ãã¥ãªãã£ä¿èšŒæç床ã¢ãã«(SAMM)ããšããŠå ¬éãããŠãããäŒæ¥ã®CISOãã¬ãŒãã³ã°ãªã©ã«ã掻çšãããŠãããšãããå²¡ç°æ°ã¯ããœãããŠã§ã¢çºæ³šåŽã«ãšã£ãŠãå¿ æºã®åºæºããã²åèã«ããŠã»ããããšè¿°ã¹ãã
ãã®ã»ãã«ããOWASPã§ã¯éçºè ã®ããã®ã»ãã¥ãªãã£ã¬ã€ãã©ã€ã³ãã³ãŒãã¬ãã¥ãŒåºæºããã¹ãã£ã³ã°ã¬ã€ããããã«æ¥æ¬ã§ã¯ç¹ã«èª²é¡ãšãªããœãããŠã§ã¢éçºå¥çŽã«é¢ããã¬ã€ãã©ã€ã³ãšãã£ããæçšãªãªãœãŒã¹ã®äœæãšå ±æãè¡ãããŠããã
ãããããææç©ãããªãŒãã³ãœãŒã¹çã«äœãäžããå ±æãããšãã詊ã¿ã«ãããããããã®äŒæ¥ã®äžã ãã§åãçµãããããããå¹ççã§æç¶æ§ã®é«ãç¥èã®èç©ãæåŸ ã§ããã(å²¡ç°æ°)
ãŸããè¿å¹ŽéèŠæ§ãå¢ããŠããã¢ãã€ã«ã»ãã¥ãªãã£ã«é¢ããŠã¯ãOWASPã®ãããŒãã·ãŒããããžã§ã¯ãããšããŠå€æ°ã®ææç©ãçãŸããŠããã»ããæ¥æ¬ã«ãããŠãäžè¬ç€Ÿå£æ³äººæ¥æ¬ã¹ããŒããã©ã³ã»ãã¥ãªãã£åäŒã«ãããã¹ããŒããã©ã³ãããã¯ãŒã¯ã»ãã¥ãªãã£å®è£ ã¬ã€ããã®ãããªåœ¢ã§ãæçšãªããŠããŠãèç©ããã€ã€ãããšããã
ãçŸåšã®ç€ŸäŒæ å¢ã®äžã§ãWebãã»ãã¥ã¢ã§å®å šã«äœ¿ããããã®ã§ããããšãç®æããŠåªåãããšããã®ã¯ãäžèŠå°é£ãªåœé¡ã ãããããããã解決ããããã®ããŠããŠãå ·äœçãªæ¹æ³è«ã¯ãOWASPãªã©ã«ãã誰ã§ãã¢ã¯ã»ã¹ã§ãããéçºè ã ãã§ãªãã顧客ããœãããŠã§ã¢éçºäŒæ¥ãçµç¹ãæè²è ããããžã§ã¯ããããŒãžã£ãŒãšãã£ãããããã¹ããŒã¯ãã«ããŒããå šå¡å šåã§ãã®åœé¡ã«åãçµãããšãå¯èœã ã(å²¡ç°æ°)
ã€ãã³ããéããŠæŽç·Žããããæè¡ããšãç¥èã
ããããåãçµã¿ãåºãæ®åãããããã®åãçµã¿ãšããŠãå²¡ç°æ°ã¯ãOWASPããŒãã£ã³ã°ãããã¯ã¹ãã©ãŒã©ã ã»ããŒããã³ã°ãããžã§ã¯ã(WASForum Hardening Project)ãã玹ä»ããã
OWASPããŒãã£ã³ã°ã¯ãæ¥æ¬ã§ã¯2012幎ããäžã¶æã«äžåºŠã®ããŒã¹ã§éå¬ãããŠãããã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã«é¢å¿ãæã€ãšãã¹ããŒããå®éã«é¡ãåãããŠãããŠããŠã®å ±æããè°è«ãè¡ãã€ãã³ãã§ãããæ¯åã倿°ã®æ¥å Žè ããããä»åŸã¯ããå šåœçãªåãçµã¿ã«ããŠãããããšããã
ãåãéããããšã«åå åžæè ãå¢ããŠãããé¢å¿ã®é«ãŸããæããŠãããWebã»ãã¥ãªãã£ãçŸå Žã§å®è£ ãã人ãã¡ã«ãåœäºè æèãçãŸããŠããŠãã蚌ã ãšæãã(å²¡ç°æ°)
ãŸãããããŒããã³ã°ãããžã§ã¯ããã¯ãITã·ã¹ãã ã®ãç·åéçšåããšãå ç¢åæè¡ããå Œãåãããšã³ãžãã¢ã®çºæãšé¡åœ°ãç®çãšããŠãããŒã ã«ããç«¶æåœ¢åŒã§è¡ãããã€ãã³ãã§ããã
ãããŒããã³ã°ããšã¯ãã»ãã¥ãªãã£ãæœãããŠããªãç¶æ³ã§ææž¡ãããè匱ãªWebãµã€ãããå ·äœçãªç®æšãæ¹éãæ±ºããªãããã»ãã¥ã¢ããªãã®ãžãšå ç¢åããŠããäœæ¥ãæããç«¶æã§ã¯ããã®ãµã€ããã³ããŒã¹ãµã€ããšä»®å®ããå Žåã®ã売äžãããã€ã³ããšããŠå ç®ãããµã€ãã®åæ¢ããæ»æã«ãã被害ãçºçããå Žåã«ã¯æžç¹ããããªã©ã®ã«ãŒã«ã§ç·åãã€ã³ããé«ããããšãç®æãã
å ç¢åã®ã¢ãããŒããå®äœæ¥ã®æ¹æ³ãç°ãªããããããŒã ã«ãã£ãŠçŽ8æéã®ç«¶æã®äžã§çŽ3åãã®ãã€ã³ãå·®ãåºãããšãããããã»ãã¥ãªãã£ç¢ºä¿ã®ããã®ç®æšã®ç«ãŠæ¹ã宿œæ¹æ³ã«ãã£ãŠææãç°ãªããã€ãŸããæè¡è ããã»ãã¥ãªãã£æè¡ã«ããããžãã¹ç¶ç¶ææ®µã«ãåªå£ããåºãããšãã¢ãã«ãšããŠèªèã§ããæå³ã§ãè峿·±ãã€ãã³ãã«ãªã£ãŠããã(å²¡ç°æ°)ãšããã
å²¡ç°æ°ã¯ãOWASPããŒãã£ã³ã°ãããŒããã³ã°ãããžã§ã¯ãã«ã€ããŠã¯ãåãçµã¿ã®äžäŸãšããŠç޹ä»ãããèŠããŠãããŠããã ãããã®ã¯ãã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã確ä¿ãããããžãã¹ãå®ãæè¡ããšããã®ããæ¢ã«ååšããŠãããšããããšã ãä»åŸã¯ããã®éšåã«ã€ããŠããããžãã¹ãªãŒããŒãç©æ¥µçã«é¢ãããããžãã¹ã®äŸ¡å€ãæå€§åããŠãããšããæèãæã£ãŠã»ããããšè¿°ã¹ãåºèª¿è¬æŒãç· ãããã£ãã