ããç¥ããããµãŒãã¹ãè£ ã£ãã¡ãŒã«ãSMSãéãããŠãŒã¶ãŒIDïŒãã¹ã¯ãŒããªã©ã®è³æ Œæ å ±ãã¯ã¬ãžããã«ãŒããªã©ã®éèæ å ±ãå ¥åããããã£ãã·ã³ã°æ»æãäŒæ¥çµç¹ãçããã£ãã·ã³ã°ã§ã¯ããã®ãããªçš®é¡ã®ã»ãã«ããååŒå ãèªç€Ÿã®çµå¶è å±€ãªã©ã«ãªãããŸãããããžãã¹ã¡ãŒã«è©æ¬º(BECïŒBusiness Email Compromise)ãã®è¢«å®³ãå ±åãããŠããŸããããžãã¹ã¡ãŒã«è©æ¬ºã§ã¯ã被害è ã®ããžãã¹ã®ç¶æ³ãããå©çšããŠããæé¢ãããã£ãã·ã³ã°ã¡ãŒã«ã®æé¢ã«å©çšãããŠããããšãªã©ããããã£ãã·ã³ã°ã§ããããšã«æ°ãä»ãã«ããããšããç¹åŸŽããããŸãã
å žåçãªããžãã¹ã¡ãŒã«è©æ¬ºã®æµã
å žåçãªããžãã¹ã¡ãŒã«è©æ¬ºã®äŸã§ã¯ãæ»æè ã¯ãŸãããã£ãã·ã³ã°æ»æãªã©ã«ãã£ãŠæåã®ã¿ãŒã²ãããšãªããŠãŒã¶ãŒã®ã¡ãŒã«ãµãŒãã¹ã«ãã°ãªã³ããããã®è³æ Œæ å ±ïŒãŠãŒã¶ãŒIDããã¹ã¯ãŒããªã©ïŒãå ¥æããŸããè³æ Œæ å ±ãå ¥æãããããã®ã¿ãŒã²ããã®ã¡ãŒã«ãµãŒãã¹ã«ãã°ã€ã³ããŠæ å ±ãåéãããã©ã®ãããªçžæãšã©ã®ãããªããåããããŠããã®ããããã䜿ãèšèãèšãåãããããžãã¹ã®äºå®ãåºåŒµã®äºå®ããããžãã¹äžã®ééã®ãããšãããªã©ãåæããŸãã
æ å ±ã®åéïŒåæãçµãããšããã®ãŠãŒã¶ãŒã«ãªãããŸãããŠãŒã¶ãŒãã¡ãŒã«ã®ããåããããŠããçžæã«ããã£ãã·ã³ã°ã¡ãŒã«ãéããŸãããã®éã®ã¡ãŒã«ã¯ãäºåã«åæããå 容ãèžãŸããŠãããããã¡ãŒã«ãåä¿¡ããçžæã¯äžä¿¡æãæ±ãã«ããããã£ãã·ã³ã°ã¡ãŒã«ã ãšæ°ãä»ãããšã¯é£ããå 容ã«ãªã£ãŠããŸããäŸãã°ãã宿çãªãããšããè¡ã£ãŠããçµçæ åœè ããã以åã®ãããšããšåãæé¢ã§ãå£åº§å€æŽã®ãç¥ãããæ¯æãè«æ±ãèªç¶ãªã¿ã€ãã³ã°ã§éãããŠãããããæ°ã¥ããã«æ»æè ã®å£åº§ã«ééããŠããŸã£ãããšããã±ãŒã¹ãå ±åãããŠããŸãã
ãã®ããã«ãæ»æè ã¯ãããžãã¹ã¡ãŒã«è©æ¬ºã®æåçãé«ããããã«ãæåã®ã¿ãŒã²ãããšãªããŠãŒã¶ãŒã®ã¡ãŒã«ãµãŒãã¹ã«ãã°ãªã³ããåŸãäžå®æéã¡ãŒã«ã®å 容ãã¢ãã¿ãªã³ã°ããŠæ å ±ãåéããŸãããã®ãšããã¡ãŒã«ãã¢ãã¿ãªã³ã°ããããã«ãã¿ãŒã²ããã®ãŠãŒã¶ãŒã«å±ãã¡ãŒã«ãæ»æè èªèº«ã®ã¡ãŒã«ã¢ãã¬ã¹ãžè»¢éããŠããã±ãŒã¹ãå€ãå ±åãããŠããŸãã
æ»æè ã«ãšã£ãŠã¯ãäžåºŠã¿ãŒã²ããã®ã¡ãŒã«ãµãŒãã¹ã«ãã°ã€ã³ããŠèšå®ããã°ã以éã¯ãµãŒãã¹ã«ãã°ãªã³ããªããŠã転éããã¡ãŒã«ã§æ»æã®æºåãã§ãããããçºèŠã®æ©äŒãæžããšããã¡ãªããããããŸãã転éèšå®ããããŠããŸããŠãŒã¶ãŒåŽã¯ãã¡ãŒã«ã®è»¢éãèšå®ãããŠãæ°ãä»ãã«ããããã被害ãå¯ç¥ãã¥ããã®ã§ãã
ãšã¯ãããã¡ãŒã«ã®è»¢éèšå®ã¯æ¥åäžã®å¿ èŠããã£ãŠå©çšããŠããããšãããã§ããããã»ãã¥ãªãã£äŸµå®³ã®çºçãæããŠäžæŠã«å šãŠçŠæ¢ããã®ã§ã¯ãªããã転éèšå®ã¯ã誰ãã©ã®é ç®ã§èšå®ã§ããã®ããã転éèšå®ã«é¢ããŠã©ã®ãããªã³ã³ãããŒã«ãã§ããã®ãããçè§£ããèªçµç¹ã«ãããèšå®ã®ç¶æ³ãææ¡ããŠã³ã³ãããŒã«ããããšãéèŠã§ããããã«ãããæ¥åå¹çãé»å®³ããããšãªããªã¹ã¯ãäœæžãããŸããäžãäžããŠãŒã¶ãŒã®ã¡ãŒã«ã¢ã«ãŠã³ãã«äžæ£ãã°ãªã³ããã£ãå Žåãªã©ã¯ãçŽ æ©ã転éã®èšå®ã確èªïŒå¯ŸåŠããããšã§ã被害ãæå°éã«æããããšãã§ããŸãã
ã¡ãŒã«ã®è»¢éèšå®ç®æã¯è€æ°ã¢ãª
ã¡ãŒã«ã®è»¢éã¯ããŠãŒã¶ãŒã®ã¡ãŒã«ã¯ã©ã€ã¢ã³ãåŽã管çè åŽãªã©ããã€ãã®å Žæã§èšå®ã§ããŸãããŸããã¡ãŒã«ã®è»¢éã®èšå®ã¯ã©ãã§ã§ããã®ãæŽçããŠã¿ãŸãããããMicrosoft 365 Exchange OnlineãããOutlookãããOutlook Web Access (OWA)ããå©çšããŠããå Žåã¯ã次ã®å Žæã§èšå®å¯èœã§ãã
- ãŠãŒã¶ãŒã®èšå®ïŒã¡ãŒã«ããã¯ã¹ã®ã«ãŒã«(Outlook/OWA)
ãŠãŒã¶ãŒã¯ãåä¿¡ããã¡ãŒã«ãåŠçããã«ãŒã«ãäœæããããšãã§ãããã®ã«ãŒã«ã§åä¿¡ããã¡ãŒã«ã¯å¥ã®ã¡ãŒã«ã¢ãã¬ã¹ã«è»¢éã§ããŸã(ããã¡ã€ã«ãâãèªåå¿çãâãã«ãŒã«ãã«ããã転éã)ã - ãŠãŒã¶ãŒã®èšå®ïŒãèªåå¿çãæ©èœ
ãŠãŒã¶ãŒã¯ãäžåšæãªã©ã«ãåä¿¡ããã¡ãŒã«ã«èªåã§è¿çããããã¡ãŒã«ã転éãããããããšãã§ããŸãã - ãŠãŒã¶ãŒã®èšå®ïŒãPower Automate(æ§ç§°ïŒMicrosoft Flow)ããå©çšããã¡ãŒã«ã®è»¢é
ãŠãŒã¶ãŒãPower Automateãšèªèº«ã®ã¡ãŒã«ã飿ºããèªåçãªåŠçãè¡ãããšãã§ããŸãã - Exchange管çããŒã¿ã«ïŒã¡ãŒã«ãããŒèšå® (ForwardingAddress)
Exchange管çã»ã³ã¿ãŒã®ããã¡ãŒã«ãããŒèšå®ããããããããã®ãŠãŒã¶ãŒã®è»¢éãèšå®ã§ããŸãããã®èšå®ã¯ãForwardingAddressãã®ããããã£å€ã«åæ ãããŸãã - M365 管çããŒã¿ã«ïŒã¡ãŒã«ãããŒèšå®(ForwardingSmtpAddress)
M365管çããŒã¿ã«ã®ããã¡ãŒã«ãããŒèšå®ããããããããã®ãŠãŒã¶ãŒã®è»¢éãèšå®ã§ããŸãããã®èšå®ã¯ãForwardingSmtpAddressãã®ããããã£å€ã«åæ ãããŸãããã ãããForwardingAddressããèšå®ãããŠããå Žåã¯ããã®å€ã衚瀺ãããŸãã
ã¡ãŒã«ã®è»¢éã管çè ãå¶åŸ¡ããæ¹æ³
äžæ¹ãçµç¹ã®ç®¡çè ã«ã¯ãçµç¹ã®ãŠãŒã¶ãŒã®ã¡ãŒã«è»¢éãçŠæ¢ãããªã©ãã¡ãŒã«ã®è»¢éãå¶åŸ¡ããæ¹æ³ãããã€ãçšæãããŠããŸãã
âOffice 365 ã»ãã¥ãªãã£/ã³ã³ãã©ã€ã¢ã³ã¹ã»ã³ã¿ãŒïŒã¡ãŒã«ã®ãã£ã«ã¿ãŒåŠç
ãOffice 365 ã»ãã¥ãªãã£/ã³ã³ãã©ã€ã¢ã³ã¹ã»ã³ã¿ãŒãã®ãã¡ãŒã«ã®ãã£ã«ã¿ãŒåŠçãã«é¢ããããªã·ãŒã«ãã£ãŠãèªçµç¹ããçµç¹å€ã«éä¿¡ãããã¡ãŒã«ã®åŠçãå¶åŸ¡ã§ããŸããæ¢å®ã§èšå®ãããŠãããéä¿¡è¿·æã¡ãŒã« ãã£ã«ã¿ãŒ ããªã·ãŒãã§ã¯ã転éã¯ãèªå - ã·ã¹ãã å¶åŸ¡ããšãªã£ãŠããŸãããã®å Žåã¯ãOffice 365ãèšå®ããã·ã¹ãã æ¢å®å€ã«åŸãããšã«ãªããŸãã
ãªããçŸåšã¯ãã·ã¹ãã æ¢å®å€ã¯ã転éããæå¹ã§ãããä»åŸãããå®å šãªæ¢å®å€ãæšå¥šããããã«ãèªå転éãç¡å¹ã«ããããæ¢å®å€ã倿Žããäºå®ã§ããåçµç¹ã§ããã®èªå転éã®å¿ èŠæ§ã®ãããŠãŒã¶ãŒã確èªããå¿ èŠãªãŠãŒã¶ãŒã®ã¿ãèš±å¯ããããªã·ãŒãèšå®ããããšãæšå¥šããŠããŸãã
âExchange管çã»ã³ã¿ãŒïŒã¡ãŒã«ãããŒã®èšå®(ãªã¢ãŒããã¡ã€ã³)
ãã®èšå®ã§ã¯ããForwardingSmtpAddress parameterãã«è©²åœããå€ãèšå®ããããšã§ãOutlookãå©çšããã¡ãŒã«è»¢éã«ãŒã«ãšãäžåšéç¥ãå¶åŸ¡ã§ããŸãããã ããã»ãã®èšå®ã§å®æœãããèšå®(ForwardingAddress parameter)ã¯å¶åŸ¡ã§ããŸããããŸãã転éãæåŠãããå Žåãåã«ã¡ãŒã«è»¢éãè¡ãããªãã ããšãªãããŠãŒã¶ãŒãžã®NDRãªã©ã¯è¿ããªãããããŠãŒã¶ãŒãç¥ãããšãã§ããŸããã
âExchange管çã»ã³ã¿ãŒïŒã¡ãŒã«ãããŒã®èšå®(ãã©ã³ã¹ããŒã ã«ãŒã«)
Exchange管çã»ã³ã¿ãŒã®ã¡ãŒã«ãããŒã§ã¯ããã©ã³ã¹ããŒãã«ãŒã«ãèšå®ããããšã§ãã¡ãŒã«ã®è»¢éãå¶åŸ¡ããããšãã§ããŸãããã®èšå®ã§ã¯ãæ¡ä»¶ãæå®ããŠè»¢éã®å¯åŠãèšå®ã§ãããŠãŒã¶ãŒãžã®NDRéç¥ãè¡ãããšãå¯èœã§ãã
ããããªãããããã§æå®ããæ¡ä»¶ã¯ãOWAãExchange管çè ãèšå®ãã転éã§çšããããŠããã¡ãã»ãŒãžã¯ã©ã¹(IPM.note.forward)ãããŒã¹ã«ããå¶åŸ¡ã§ãããOWAãExchange管çè ãèšå®ãã転éã§å©çšãããéåžžã®ã¡ãã»ãŒãžã¯ã©ã¹(IPM.Note)ã§ã¯ãããŸããããã®ãããOWAãExchange管çè ãèšå®ãã転éã®å¶åŸ¡ãè¡ãããšã¯ã§ããŸããã
âOWAïŒè»¢éèšå®é
ç®ã衚瀺ããªã
OWAã§ã®è»¢éã®èšå®ã¯ããRole Based Access Control(RBAC)ãã§ã転éã®èšå®ããããã衚瀺ãããªãããã«èšå®ã§ããŸãããã®ããããŠãŒã¶ãŒãOWAã§è»¢éãèšå®ããããšããŠãèšå®ã§ããªãããšããç¶æ
ã«ããããšãå¯èœã§ãããã ãããã¯ãããŸã§ãOWAã§ã®èšå®é
ç®ã®å¶åŸ¡ãªã®ã§ããã¹ã¯ãããçã®Outlookã§ã®è»¢éèšå®ã¯å¶åŸ¡ã§ããŸããããŸãããã§ã«çµç¹å
ã§èšå®ãè¡ãããŠããå Žåã¯ããã®èšå®ãããŠã転éãç¡å¹ã«ããããšã¯ã§ããŸããã
転éã®èšå®ç®æãšå¶åŸ¡ãŸãšã
ããããã®èšå®ïŒå¶åŸ¡æ©èœã«ã¯ãå©ç¹ãšåæã«èæ ®ãã¹ãç¹ããããŸããåçµç¹ã§å¿ èŠãªèŠä»¶ãç°ãªãã®ã§ããããããã¹ãã ããšããæ¹æ³ã¯ãããŸãããèªçµç¹ã®èŠä»¶ã確èªããé©åãªã³ã³ãããŒã«ãçµã¿åãããŠç®¡çããããšãæšå¥šããŸããäŸãã°ãåæã«è»¢éèš±å¯ãšæåŠã®èšå®ããããŠãããããªå Žåã¯ãæåŠããããã«ããã»ããããã§ãããã
|
|
|
ã¡ãŒã«ã®èªå転éã®èšå®ç®æãšã転éå¯åŠã®ã³ã³ãããŒã«èšå®ïŒâ¯ïŒè»¢éå¶åŸ¡å¯èœïŒâ³ïŒäžéšå¯èœïŒâïŒäžå¯èœïŒ |
ã¢ã©ãŒãã§äžå¯©ãªæåã®ç¢ºèªã
çµç¹ã§ã¡ãŒã«ã®è»¢éãèš±å¯ããŠããå Žåã¯ã転éç¶æ³ãç£èŠããäžå¯©ãªæåããªãããã¢ãã¿ãªã³ã°ããããšã§ãäžãäžè¢«å®³ã«ãã£ãéã«æ©ãæ°ãä»ãããšãã§ããŸãã
Office 365 ã»ãã¥ãªãã£/ã³ã³ãã©ã€ã¢ã³ã¹ã®ãã¡ãŒã« ãã㌠ããã·ã¥ããŒããã§ã¯ãçµç¹ã®ãŠãŒã¶ãŒã«ãã£ãŠè»¢éãããã¡ãŒã«ã®ç¶æ³ã確èªã§ããŸãã転éãããã¡ãŒã«ã®ç·æ°ã転éå ãã¡ã€ã³ãªã©ã転éãããã¡ãŒã«ã®ç¶æ³ãåæããçµæã衚瀺ãããçµç¹ã®å šäœçãªç¶æ³ã®ææ¡ã«åœ¹ç«ã¡ãŸãã
ãŸããOffice 365 ã»ãã¥ãªãã£/ã³ã³ãã©ã€ã¢ã³ã¹ã®ãã¢ã©ãŒãããªã·ãŒãã§ã¯ãäžå¯©ãªã¡ãŒã«ã®è»¢éã«é¢ããã¢ã¯ãã£ããã£ãéç¥ããã¢ã©ãŒãèšå®ãçšæãããŠããŸãããã®ã¢ã©ãŒãã§ã¯ããŠãŒã¶ãŒãçµç¹å€ã®å®å ãžã¡ãŒã«ã®è»¢éãèšå®ããããšãæ€åºãã管çè ã«ã¡ãŒã«ã§éç¥ããŸãããã®éç¥ãåãåã£ã管çè ã¯ã転éãèšå®ãããŠãŒã¶ãŒèªèº«ãèšå®ãããã®ããäžæ£ãã°ãªã³ã®è¢«å®³ãåããŠããªããã確èªããããšã§ãçµç¹ãžã®äŸµå®³ãæ©æã«çºèŠã察åŠããããšãã§ããŸãã
|
|
|
|
ãSuspicious Email Forwarding Activityãããªã·ãŒ |
転éèšå®ãè¡ãããããšã瀺ãã¢ã©ãŒãéç¥ |
ã¡ãŒã«è»¢é以å€ã®ããããå å
æ»æè ã¯ã¿ãŒã²ãããšãªããŠãŒã¶ãŒã®ã¡ãŒã«ã調æ»ããŠãããšããããªãããŸãã¡ãŒã«ãéä¿¡ããéãã§ããã ããŠãŒã¶ãŒã«æ°ã¥ãããªãããã«æ éã«é²ããŠããŸããããããªããããŠãŒã¶ãŒèªèº«ããäŸãã°ä»¥äžã®ãããªäžå¯©ãªæ§åã«æ°ä»ãå ŽåããããŸãã
- æ¶ããèŠãã®ãªãã¡ãŒã«ãæ¶ããŠããããã©ã«ãç§»åããŠãã
- åä¿¡ããã¡ãŒã«ãããããŸã§ãããšãããèŠãã®ãªãå 容ã«åºã¥ããå 容ãæé¢ã«ãªã£ãŠãã
- äœæããèŠãã®ãªãåä¿¡ã¡ãŒã«ã«å¯ŸããåŠçã«ãŒã«ãèšå®ãããŠããïŒã¡ãŒã«ã®è»¢éããã©ã«ãã®ç§»åãªã©ïŒ
- éä¿¡ããèŠãã®ãªãã¡ãŒã«ãéä¿¡æžã¿ãã¬ã€ã«ãã
- ååãé»è©±çªå·ãéµäŸ¿çªå·ãªã©ã®ãã£ãã«å€æŽãããªããããã£ãŒã«ãæŽæ°ããã
ãã®ãããªå åãèŠãããå Žåã®å ±åå ããŠãŒã¶ãŒã«åšç¥ããŠããã®ããè¢«å®³ã®æ©æçºèŠã«åœ¹ç«ã¡ãŸãããŸããããããŠãŒã¶ãŒã®ã¡ãŒã«ã¢ã«ãŠã³ãã䟵害ãããŠããå Žåã¯ãå©çšã¢ã«ãŠã³ãããªã»ãããããã転éãã¡ãŒã«æ¯ãåãã®ã«ãŒã«ãªã©ãåé€ããããšãã£ããè¢«å®³ã®æ¡å€§ã鲿¢ããæªçœ®ããšãå¿ èŠããããŸãã
*ã*ã*
ä»åã¯ãããžãã¹ã¡ãŒã«è©æ¬ºã«ãããŠæ»æè ãå€çšããæå£ã®äžã€ã§ããã¡ãŒã«ã®è»¢éã«çç®ããèŠçŽãã¹ããã€ã³ããªã©ã«ã€ããŠè§£èª¬ããŸãããçµç¹å ã§ã¡ãŒã«è»¢éã®èšå®ãææ¡ïŒç®¡çããŠããããã»ãã¥ãªãã£ç®¡çããã£ãã·ã³ã°å¯Ÿçã®ãç²ç¹ããšãªã£ãŠããã±ãŒã¹ãæ£èŠãããŸãã
æ¬é£èŒã®ç¬¬24åã§è§£èª¬ãããã£ãã·ã³ã°å¯ŸçãšåãããŠãã¡ãŒã«ç°å¢ã®å¥å šåã®äžç°ãšããŠãä»äžåºŠç¢ºèªããŠã¿ãŠãã ããã






