人éã®åäœãæš¡å£ãããããã¢ã¯ã»ã¹ãšã¯
æšä»ããªã¹ãåæ»æïŒã¯ã¬ãã³ã·ã£ã«ã¹ã¿ããã£ã³ã°æ»æïŒãšåŒã°ãããæ»æãé »çºããŠããããŸãé«åºŠåããŠããŸãã
ãªã¹ãåæ»æãšã¯ãæªæãæã€ç¬¬äžè
ããäœããã®ææ³ã«ãããããããå
¥æãããªã¹ãåããIDã»ãã¹ã¯ãŒããå©çšããŠãWebãµã€ãã«ã¢ã¯ã»ã¹ã詊ã¿ãçµæãšããŠå©çšè
ã®ã¢ã«ãŠã³ãã«å¯ŸããŠäžæ£ã«ãã°ã€ã³ã宿œããæ»æã§ãã
é«åºŠãªãªã¹ãåæ»æã¯ãæ»æè
ã«ãããã©ãã£ãã¯ãšæ£åžžãªãã©ãã£ãã¯ãé
·äŒŒããŠããã芳枬ããããšãéåžžã«é£ããã§ãããã®ããå€ãã®å Žåããªã¹ãåæ»æãåããŠããããšã«æ°ã¥ãããšãã§ããããªã¹ãåæ»æãåããŠããããšã課é¡ãšããŠèªèã§ããŠããªãããšããããŸãã
WebãµãŒãã¹ãAPIã«å¯Ÿãã人éã®åäœãæš¡å£ãããããã«ããæ»æã¯ãã·ã¹ãã ãæäŸããŠãããµãŒãã¹ãæ©èœãæªçšããæ»æã宿œããŸããã€ãŸããã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã®èгç¹ããããããããã¡ã€ã¢ãŠã©ãŒã«ãWAFãªã©ãé©çšã察çããŠããå Žåã§ããæ»æã«æåããŠããŸãæãããããŸãã
äžèšã«å ããæ»æè
åŽã以äžã®èгç¹ã§é«åºŠåãé²ãã§ããããããã«ããæ»æã芳枬ãã«ãããªã£ãŠããŸãã
ã»æ©æ¢°åŠç¿ã䜿çšããããšã§ãããŠã¹ã®åããããŒã¹ãããŒã¯ãªã©ã人ã®è¡åãããé«ãç²ŸåºŠã§æš¡å£
ã»ããžã¿ã«ãã£ã³ã¬ãŒããªã³ããçæ/åéããŠããããããå šäœã«é åžãåãããã®ç«¯æ«æ å ±ãããããªã¢ã«ãã«èŠãã
ã»éä¿¡å IPãåœè£ ããæ£åžžãªéä¿¡å ãããã©ãã£ãã¯ã§ããããã«èŠãã
ã»Puppeteerããããã¬ã¹Chromeãªã©ã®èªååããŒã«ã®æªçš
é«åºŠãªãªã¹ãåæ»æãªã©ã®äººéã®åäœãæš¡å£ããæ»æã«ã¯ãå
±éç¹ã1ã€ãããŸãã
ããã¯ãäœçŸäžãã®ãªã¯ãšã¹ããéä¿¡ããã»ãã®äžéšã®å²åãæåããããšã§ãã¢ã«ãŠã³ãã®ä¹ã£åãããæå¹ãªã¯ã¬ãžããã«ãŒãããã€ã³ãæ®é«ã®ããã¢ã«ãŠã³ãçªå·ãåŸãããããšãæåŸ
ããŠããç¹ã§ãã
ãã®æå/倱æã®æ¯çã¯ãã客æ§ãçŸåšä¿æããŠããããŒã¿ã§ç¢ºèªããããšãå¯èœã§ãããŸããShape Securityã®èª¿æ»ã«ãããšãåæ¥çš®ã®äŒæ¥ã§ã¯ãåããããªãã°ã€ã³æåçãæã£ãŠãããšããããšãåãã£ãŠããŸãã
ãã°ã€ã³æåçã確èªããããšã§ãåŸåã確èªããããšãå¯èœã§ãã®ã§ããªã¹ãåæ»æãåããŠãããããããªãå Žåã«ãããŠãããã²ãã°ã€ã³æåçãäžåºŠã確èªãã ããã
èªç€Ÿã®ãã°ã€ã³æåçããèªã¿åããããš
ãµãŒãã¹ã«ããããã°ã€ã³æåçã¯ã©ããããã§ãããã?
ãã°ã€ã³æåçã®å¹³åå€ã¯ããªã¹ãåæ»æãåããŠããæéäžã«åçã«äœäžããŸãã
ãªã¹ãåæ»æã§ã¯ãæŒæŽ©ããæ°çŸäžã®ãŠãŒã¶åãšãã¹ã¯ãŒãæ
å ±ã®ãªã¹ãã䜿çšãããŸãããããã®è³æ Œæ
å ±ã®å€§éšåã¯ãã§ã«å€ãæ
å ±ãã䜿ããŸãããããŠããªãå¯èœæ§ããããæå¹ã§ã¯ãªãããšããããŸãã
Shape Securityã®èª¿æ»ã«ãããšããªã¹ãåæ»æã®æåçã¯ãããã0.2ïœ2%çšåºŠã§ãããšèããããŠããŸããããããªãããæ»æè
ã¯ãæ»æã®å®è¡èªäœãå®äŸ¡ã«ã§ããéããããã»ã©é«ãæåçãå¿
èŠãšããŠããŸãããçµæãšããŠããªã¹ãåæ»æãªã©ã®æ»æã«ãããã°ã€ã³å€±æåæ°ã®å¢å ã«ããããµã€ãã®ãã°ã€ã³æåçã¯å¹³åå€ã倧å¹
ã«äžãããŸããShape Securityãå°å
¥ãã以åã®ã客æ§ã®ç°å¢ãShape Securityã調æ»ãããšããããã°ã€ã³æåçã5%æªæºã ã£ãããšããããŸããããã®ãããªäœãããæåçã¯ç°åžžã§ãããããã«ç¢ºèªããå¿
èŠããããŸãã
以äžã¯ã3ã€ã®äž»èŠãªæ¥çã«ãããç±³åœã§ã®1ãµæã®ãã©ãã£ãã¯ã®å¹³åãã°ã€ã³æåçã§ããâ»1
éèæ©é¢ïŒ79%
æ è¡æ¥ïŒ73%
å°å£²æ¥ïŒ62%
顧客ãããé »ç¹ã«ãã°ã€ã³ãããåŸåããããµã€ãã®å Žåã¯ãäžèšã®å¹³åå€ããããã°ã€ã³æåçãé«ããªãåŸåããããŸããé »ç¹ã«ãã°ã€ã³ãããµã€ãã§ããã°ããŠãŒã¶ã¯èšå®ããŠãããã¹ã¯ãŒããèŠããŠããå¯èœæ§ãé«ãããŸããããã€ã¹ãWebãã©ãŠã¶ã«è³æ Œæ å ±ãä¿åããŠããå¯èœæ§ãããããã§ããéèæ©é¢ã®å Žåã¯ããŠãŒã¶ã®ãã°ã€ã³ã15åéã»ã©ããç¶æããªãããããŠãŒã¶ã®ãã°ã€ã³ãé·æéç¶æããå°å£²æ¥ããœãŒã·ã£ã«ã¡ãã£ã¢ãµã€ãããããã°ã€ã³ã«æåããåæ°ãå€ããçµæãšããŠãéèæ©é¢ã®ãã°ã€ã³æåçã¯å°å£²æ¥ãããé«ããªãåŸåããããŸãã
ãŸããå€ãã®å ŽåããŠãŒã¶ã¯éãããéè¡å£åº§ããå¥çŽããŠããããé »ç¹ã«å€æŽããããšããããŸããããã®çµæããã°ã€ã³è³æ Œæ å ±ãèŠããŠããå¯èœæ§ãé«ãŸããŸããäžæ¹ã§ãå°å£²é¢é£ã®ãµã€ãã§ããã°ããŠãŒã¶ã¯å®æçã«è€æ°ã®ECãµã€ãã§è²·ãç©ããããŸãåECãµã€ãã®ã¢ã«ãŠã³ããç°¡åã«äœæããããšãã§ããŸãããããã£ãèŠçŽ ã圱é¿ããå°å£²æ¥ã®ãµã€ãã®ãã°ã€ã³æåçãäœããªããæ°ãæãŸãã¯æ°å¹Žã§åããŠã¢ã¯ã»ã¹ããå¯èœæ§ã®ãããŠãŒã¶ã®å²åãé«ããªã£ãŠããŸããé »ç¹ã«ãã°ã€ã³ããŠããªããµãŒãã¹ã®å Žåãã¿ãªããŸã«ãçµéšãããããã«ããã¹ã¯ãŒããå¿ããŠããŸãããšãå€ã ããããšæããŸãã
éåžžæã®ãµã€ããžã®ãã°ã€ã³æåçã¯60ïœ85%ã§ãããšèŠèŸŒã¿ãããããé«ããŸãã¯äœãå Žåã¯ãªã¹ãåæ»æãªã©ãçãå¿ èŠããããŸãã
ã©ã®ãããªæ¥çã§ãããã«é¢ä¿ãªãã60ïœ85%ã®ãã°ã€ã³æåçãç®å®ãšãªããŸãã
ããããé«ããŸãã¯äœãæåçã§ããå Žåã¯ãæ»æã«ãã圱é¿ã§ããããšãçãã¹ããããããŸããããã©ãã£ãã¯ã®æ¥å¢ã¯äžæçã«ãã°ã€ã³æåçã«åœ±é¿ãäžããå¯èœæ§ããããŸããããã®åå ãããã¢ãŒã·ã§ã³ããã€ã©ã«ããŒã±ãã£ã³ã°ãªã©ã®ã€ãã³ãã«ãããã®ã§ãããšèª¬æã§ããã°åé¡ã¯ãããŸããã
ã€ãã³ããã£ãã以å€ã§ãã©ãã£ãã¯ã«ã¹ãã€ã¯ãããå Žåã¯ãæªæ§ããããªã©ã«ãããªã¹ãåæ»æã§ããå¯èœæ§ãããããã詳现ã調ã¹ãå¿
èŠããããŸãã
é«ãããæåçã®æ³šæç¹ãšã¯
éèæ©é¢ãªã©ã®äžéšã®æ¥çã§ã¯ãã¢ã°ãªã²ãŒã¿ã®ã¿ãŒã²ããã«ãããŠããŸãã
ã¢ã°ãªã²ãŒã¿ãšã¯ããŠãŒã¶ããåãåã£ãIDãšãã¹ã¯ãŒãæ
å ±ã䜿çšãããŠãŒã¶ã«ä»£ãã£ãŠãŠãŒã¶ã®æ
å ±(éè¡å£åº§ãªã©)ãè€æ°ãµãŒãã¹ããåéãåæããæçãªæ
å ±ãè¿ããµãŒãã¹ã®ããšã§ãã
å®¶èšç°¿ã¢ããªãµãŒãã¹ãªã©ã該åœããŸãããæåãªãµãŒãã¹ãšããŠã¯ãMintãVisaã«ãŒãã«è²·åãããPlaidãªã©ããããŸãã
ã¢ã°ãªã²ãŒã¿ã¯æ£åœãªè³æ Œæ
å ±ã䜿çšãã1æ¥ã«è€æ°åãã°ã€ã³ããããããã°ã€ã³ã®æåçãäžèªç¶ã«é«ããªãå¯èœæ§ããããŸããè€æ°ã®ãŠãŒã¶ã§åãIPã¢ãã¬ã¹ã䜿çšãããŠããå ŽåããšãããIPã¢ãã¬ã¹ãã¯ã©ãŠãããã¹ãã£ã³ã°ãããã€ããŒããã®ãã®ã§ããå Žåã¯ãã¢ã°ãªã²ãŒã¿ã®éä¿¡ã§ããå¯èœæ§ããããŸãã確å®ãªæ€åºæ¹æ³ã§ã¯ãããŸããããå®éã®ãã°ã€ã³æåçãããããçè§£ããããã®è¶³æããã«ãªããŸãã
80%åŸåã90%代ã®ç°æ§ã«é«ããã°ã€ã³æåçãèŠãããå Žåã¯ããªã¹ãåæ»æã®è
åšã¯äœããŠãããã®ãããªã¢ã°ãªã²ãŒã¿ã®ãã©ãã£ãã¯ãå€ãããšã瀺åããŠããŸãã
ã¢ã°ãªã²ãŒã¿ãè
åšãšèŠãªããã©ããã¯ãããžãã¹ããšã«ç°ãªãããšæããŸãããäžåºŠèª¿ã¹ãŠã¿ããšãããããããŸããã
èªç€Ÿã®ãã°ã€ã³æåçãæ°ã«ãªã£ãå Žåã¯ãä»ã®ã»ãã¥ãªãã£è
åšãšåæ§ã察çã®æ€èšãå§ããåã«ããŸãã¯çŸç¶ã®ãã©ãã£ãã¯ç¶æ³ãå¯èŠåããå¿
èŠããããŸãã
ãã¯ãã«ãããã¯ãŒã¯ã¹ã§ã¯ãShape Securityã®ç¡åPoCãšéããŠã人éã«æš¡å£ããŠãããããã«ããã¢ã¯ã»ã¹ãã©ã®çšåºŠããã®ããå¯èŠåããããšãã§ãããŸãã®ã§ãæ°ã«ãªãæ¹ã¯ãåãåããããã ããã°ãšæããŸãã
æªæ§ãããã«ã€ããŠãã詳ããç¥ãããæ¹ã¯ãäžèšã®ãã¯ã€ãããŒããŒããã²ããŠã³ããŒããã ããã
â Shape Securityãã¯ã€ãããŒããŒ
1) æªæ§Botã«ããè
åš ïœå¢å ããBotã®æ€ç¥åé¿ã®å®æ
ãšãã®å¯Ÿçã«ã€ããŠïœ
2) æªæ§BotãæŽ»çšããïŒã€ã®æ»æææ³
3) ECãçãè²·ãå ãBotååãæ¬²ãããŠãè²·ããªã!?転売å±ã掻çšããŠããBot
â Shape Securityãªã³ããã³ãåç»
1) CAPTCHAã®åé¿æ¹æ³ã«ã€ã㊠ïœå®æŒãã¢ãšè§£èª¬ïœ
å€ãã®äŒæ¥ããã¹ã¯ãŒããªã¹ãåæ»æãäžæ£ãã°ã€ã³ãªã©ãé²ãç®çã§ãCAPTCHAãå°å
¥ããŠããããšæããŸããçæ§ã«ãCAPTCHAãäžåºŠã§ã¯è§£æ±ºã§ããªãã£ãçµéšãããããã«ãCAPTCHAãå°å
¥ããããšã«ãã£ãŠã客æ§ã«ãšã£ãŠããªã¯ã·ã§ã³ãšãªãããŠãŒã¶ã®äžéšãé¢è±ããŠããŸããšããããŠããŸããè¿å¹Žã§ã¯CAPTCHAãçªç ŽãããµãŒãã¹ã幎ã
å¢ããŠãããæ»æè
ã«ãšã£ãŠã¯æéãªã解決ã§ãããšããççŸãçãŸããŠããŸã£ãŠããŸãã
æ¬åç»ã§ã¯ãCAPTCHAãã©ã®ããã«æ»æè
ãåé¿ããŠããã®ãããã¢ãçšããŠè§£èª¬ãããŠããã ããŸãã
2) æªæ§ãããã«ãããã¹ã¯ãŒããªã¹ãåæ»æïœå®æŒãã¢ãšè§£èª¬ïœ
ãã¹ã¯ãŒããªã¹ãåæ»æã¯ãæªæ§ããããæŽ»çšããŠããŸããããããã«ãã£ãŠã©ã®ãããªæ»æãå®è¡ãããŠããã®ãããããŠé »ç¹ã«ãã¥ãŒã¹ã«ãªã£ãŠãããã®æ»æã黿¢ããããã®æå¹ãªå¯Ÿçãšã¯äœããå®éã®æ»æã®ãã¢ã亀ããªãã解説ãããŠããã ããŸãã
â»1ãåŒçšå ïŒShape Security Blog
[PR]æäŸïŒãã¯ãã«ãããã¯ãŒã¯ã¹ãF5ãããã¯ãŒã¯ã¹ãžã£ãã³




