ããã¢ã«ããããã¯ãŒã¯ã¹ã¯12æ3æ¥ããµã€ããŒè åšãšã»ãã¥ãªãã£ååã®2021幎æ¯ãè¿ããš2022å¹Žäºæž¬ã«é¢ãããªã³ã©ã€ã³èšè 説æäŒãéå¬ããã
2021幎ã®ãµã€ããŒè åšã®åå
åãã«ãæ¥æ¬æ åœæé«ã»ãã¥ãªãã£è²¬ä»»è (Field CSO) ã®æè«æ°ããè åšã€ã³ããªãžã§ã³ã¹ããŒã Unit 42ã®èª¿æ»ã«åºã¥ãããµã€ããŒè åšã®ååãã«ã€ããŠèª¬æãããåæ°ã¯ãã©ã³ãµã ãŠã§ã¢ãããã£ãã·ã³ã°ããè匱æ§ãšã¹ãã£ãã³ã°ãã®3ç¹ããã2021å¹Žãæ¯ãè¿ã£ãã
-

ããã¢ã«ããããã¯ãŒã¯ã¹ æ¥æ¬æ åœæé«ã»ãã¥ãªãã£è²¬ä»»è (Field CSO) æ è«æ°
ææ°ã¯ã2021幎ã®ã©ã³ãµã ãŠã§ã¢ã®ååãšããŠã身代éã®å¹³åèŠæ±é¡ã身代éã®å¹³åæ¯æé¡ã身代éã®æé«æ¯æé¡ã身代éã®æé«èŠæ±é¡ã®ãããã2020幎ããå¢ããŠãããšèª¬æããã
ææ°ã¯ã©ã³ãµã ãŠã§ã¢æ»æãå¢å ããŠããèŠå ãšããŠãRaaSïŒRansomware as a Service) ã®ãµãã©ã€ãã§ãŒã³ãæãããRaaSãšã¯ãã©ã³ãµã ãŠã§ã¢ãçšããæ»ã®ã¯ã©ãŠããµãŒãã¹ã§ãããšã³ã·ã¹ãã ãåºæ¥äžãã£ãŠããŠãããä»åŸããµãŒãã¹ãæŽç·ŽãããŠãããå©çšãããããšãäºæ³ãããããšææ°ã¯èª¬æããã
ããã£ãã·ã³ã°ãã¯ãæ°åã³ãããŠã€ã«ã¹ã®åœ±é¿ã§å°å ¥ãé²ãã åšå® å€åã®å¢å ã«äŒŽããäžççã«æŽ»åãæŽ»çºåããŠãããšããããã ãããã£ãã·ã³ã°ã®ããŒãã¯ææã«åãããŠãããªã¢ãŒãäŒè°ããã¯ã¯ãã³ããå人é²è·å ·ïŒPPEïŒããªã©å€é·ããŠããããšãããŒã¿ããããã£ãŠããã
ãè匱æ§ãšã¹ãã£ãã³ã°ãã«é¢ããŠã¯ãç±³åœCISAãå ¬éãã察å¿ãã¹ãè匱æ§ãªã¹ãã«ã2010幎ãã2018幎ã«çºèŠããã48ã®è匱æ§ãå«ãŸããŠããç¹ã«ã€ããŠããè匱æ§ã®å¯Ÿå¿ãé©åã«è¡ãããšãé£ããããšã衚ããŠããããšææ°ã¯ã³ã¡ã³ããããCISAã¯æ¿åºæ©é¢ã«å¯Ÿãã2021幎11æ17æ¥ãŸã§ã«100ã®è匱æ§ã«ã€ããŠããŸãã2022幎5æ3æ¥ãŸã§176ã®è匱æ§ã«ã€ããŠãå³æå¯Ÿå¿ãæ±ããŠããã
ãŸããæ»æå¯Ÿè±¡ã®å èš³ã¯ãå瀟ã®èª¿æ»ã§ã¯ã©ãŠããµãŒãã¹ã®ãªãœãŒã¹ã79ïŒ ããªã³ãã¬ãã¹ã®ãªãœãŒã¹ã21ïŒ ã§ããããšãããã£ãŠãããæãçãããŠãã察象ã¯ãRDPãµãŒããã ããææ°ã¯ããã«ç®¡çã·ã¹ãã ãçµã¿èŸŒã¿ã·ã¹ãã ãªã©ããå€ã«èŠããŠããã¹ãã§ã¯ãªãããã»ãã¥ã¢ãªç¶æ ã§ãªããã°ãªããªãããã®ãçãããŠããããšã«æ³šæãã¹ããšææããã
äŒæ¥ã®æè³ãšèª²é¡ããèŠã2021幎ãµã€ããŒã»ãã¥ãªãã£ã®åå
ç¶ããŠãããŒããµã€ããŒã»ãã¥ãªãã£ã¹ãã©ããžã¹ãã®æè°·åŸè¯æ°ããäŒæ¥ã®æè³ãšèª²é¡ããèŠã2021幎ã®ãµã€ããŒã»ãã¥ãªãã£ã®ååã«ã€ããŠèª¬æãããåæ°ã¯å šäœçãªã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®åŸåãšããŠã倧ãã2ã€ãããšè¿°ã¹ãã
-

ããã¢ã«ããããã¯ãŒã¯ã¹æ ªåŒäŒç€Ÿ ããŒããµã€ããŒã»ãã¥ãªãã£ã¹ãã©ããžã¹ã æè°·åŸè¯æ°
1ã€ã¯ãã¹ããŒã¯ãã«ããŒã®åœ±é¿ãå¢å ããŠããããšã ãæ ªäž»ãæ¶è²»è ããµãã©ã€ãã§ãŒã³ã瀟äŒå šäœãªã©ãžã®è¢«å®³ãåã¶ç¶æ³ãåžžæ åããŠãããšããããã1ã€ã¯ãæµ·å€æ ç¹ãé¢ä¿äŒæ¥ã»å§èšå ã®ãªã¹ã¯ãé¡åšåããŠããããšã ãæµ·å€æ ç¹ãçµç±ããŠåœå æ ç¹ãæ»æã«ããäºäŸãå¢ããŠãã
ãŸãããŒããã©ã¹ãé¢é£ã®æœçã®ååãšããŠã¯ããé¢å¿ã¯é«ãããçè§£ãè§£éã倿§åããã€ã³ãã©å šäœãåå¥ããŒã«ãšãåãçµã¿ãäºæ¥µåããšãã£ãããšãèŠããããšããããæ°åã³ãããŠã€ã«ã¹ã®åœ±é¿ã§ããã¬ã¯ãŒã¯ã«éå®ããåãçµã¿ãšäºæ¥åºç€å šäœãšããåãçµã¿ã«2極åããŠãããïŒæè°·æ°ïŒ
å ããŠãäŒæ¥ã®ããžã¿ã«ã€ã³ãã©ããµã€ããŒã»ãã¥ãªãã£ã®æè³ã»æœçã®ååã«ãããŠãããå šäœæé©orå奿é©ããããžãã¹ãŽãŒã«orã³ã¹ãåæžã»å¹çåããããžãã¹ãã€ã³ãã©ãã»ãã¥ãªãã£ãäžäœãšãªã£ãŠãããã©ããããšäºæ¥µåã®åŸåã«ãããšããã
ããããäºæ¥µåãçããèæ¯ã«ã€ããŠãæè°·æ°ã¯ãçµå¶å±€ããµã€ããŒã»ãã¥ãªãã£ãçµå¶èª²é¡ãšããŠãšãããŠãããã©ãããã«ã®ãšãªãã以åããã¯ããããçµå¶å±€ãå¢ããŠããããçµç¹çãªèª²é¡ãé¡åšåããŠããããšèª¬æããã
æè°·æ°ã¯ãããŒã¿ã»ãã©ã€ãã·ãŒé¢é£ã®æ³èŠå¶ã«ã€ããŠãè§ŠãããEUäžè¬ããŒã¿ä¿è·èŠåïŒGDPRïŒãæœè¡ãããŠ3幎çµã€ããé«é¡ã®å¶è£éãç§ããããæ¡ä»¶ãå¢ããŠãããåæ°ã¯æžå¿µãã¹ãç¹ãšããŠãæè¡çãªå¯Ÿçãäžååãªç¹ããå¶è£éãç§ããããŠããããšãæããã
ãããŠãæ¥æ¬ã§ãæ¥å¹Ž4æã«ãå人æ å ±ä¿è·æ³ã®æ¹æ£ãäºå®ãããŠãããæ¹æ£ã«ãã眰åã匷åããããããåœå äŒæ¥ã«ãšã£ãŠããŒã¿ã»ãã©ã€ãã·ãŒã¯ãŸããŸãéèŠãªèª²é¡ã«ãªã£ãŠãããæè°·æ°ã¯ãã©ã€ãã·ãŒä¿è·ã®å¯Ÿçã«ã€ããŠãã説æè²¬ä»»ã®åãçµã¿ãéèŠãããŒã¿æŽ»çšãé²ãäžã§ãããŒã¿ã®åãæ±ããæ¹ããŠèããã¹ãããšèª¬æããã
2022幎ã®ãµã€ããŒã»ãã¥ãªãã£ã«é¢ããäºæž¬
2022幎ã®ãµã€ããŒã»ãã¥ãªãã£ã«é¢ããäºæž¬ã«ã€ããŠãææ°ã¯ãã»ãã¥ãªãã£äººæç²åŸãäžå±€å°é£ã«ãªãããšããæããã
ååœæ¿åºããµã€ããŒæ»æã«é¢ããåãç· ãŸãã匷åããåŸåãé«ãŸã£ãŠããããšããããµã€ããŒã»ãã¥ãªãã£äººæã®ç²åŸããããŸã§ä»¥äžã«æ¿ãããªãããšãäºæ³ããããšããã
æè°·æ°ã¯4ã€ã®äºæž¬ã瀺ããã1ã€ç®ã®äºæž¬ã¯ãããžãã¹ããã»ã¹ã«åœ±é¿ããã€ã³ã·ãã³ãã®å¢å ãã ããããŸã§ãªã¹ã¯ã«ãããããŠããªãã£ãããžãã¹ããã»ã¹ãçãããå¯èœæ§ãé«ãŸãããšãèãããããããããžãã¹ããã»ã¹ãæ¢ãŸãããšã«ãã圱é¿ãæ¢ãŸã£ãŠããŸã£ãæã®å¯Ÿçãªã©ãäºæ¥èšç»ãèŠçŽãå¿ èŠããããšããã
2ã€ç®ã®äºæž¬ã¯ããæ¬æ°ã®ãŒããã©ã¹ãããšããŒããã©ã¹ãç²ãããžã®äºæ¥µåãã ãåžå Žãæ··ä¹±ããŠããããšãããããŒã«ãããã®ããªãã¡ãã£ãŠãŒããã©ã¹ããã®åããé²ãããšãæžå¿µããããšãããæè°·æ°ã¯ãŒããã©ã¹ããåŸæ¥ã®æ§é ã«èµ·å ããåé¡ã解決ããããæ©äŒãšæããŠå¯Ÿçãè¬ããã¹ãã ãšèªã£ãã
3ã€ç®ã®äºæž¬ã¯ãBringãYour Own Infrastructure(BYOIïŒã®å¢å ãã ãBYOIã¯æè°·æ°ã®é èªã ããã§ãèŠæ±ã«å¿ããŠãããªãã»ãã¥ãªãã£éšéã«å¯Ÿããããžãã¹ãŠãŒã¶ãŒãçµå¶å±€ã®ãã©ã¹ãã¬ãŒã·ã§ã³ãããŸãããšã§ãç¬èªã«ã¯ã©ãŠãããŒã¹ã®ã€ã³ãã©ãæ§ç¯ããåããèŠãããã®ã§ã¯ãªãããšã®ããšã ã
4ã€ç®ã®äºæž¬ã¯ãæ¥æ¬äŒæ¥ã®æµ·å€åäŒç€Ÿã»é¢é£äŒç€ŸãããŒã¿ã»ãã©ã€ãã·ãŒæ³èŠå¶ã®å¶è£å¯Ÿè±¡ã«ãªããã ãããããäºæ ãåé¿ãããããçµå¶å±€ãã»ãã¥ãªãã£éšéã¯æ³åéšéãšã®é£æºãè¡ãã»ããæ å ±åéãªã©ãéããŠãå人ããŒã¿ã®åãæ±ããªã©ãç¶ç¶ããŠèŠçŽãå¿ èŠããããšããã


