æ¥åžžã®ãã¥ãŒã¹ã®äžã§ããµã€ããŒæ»æããããµã€ããŒç¯çœªããšãã£ãèšèãèŠèãããã®ãããã¯ãçããããšã§ã¯ãªããªã£ãã
è¿å¹Žã®æ¿åºé¢é£æ©é¢ãæ¥æ¬äŒæ¥ã«å¯Ÿãããæšçåæ»æãã®å¢å ããã€ã³ã¿ãŒãããã«ãããå€§èŠæš¡ãªDDoSæ»æããã£ãã·ã³ã°è©æ¬ºã®æšªè¡ã¯ãäž»èŠãªæ å ±ã€ã³ãã©ãšãªã£ãã€ã³ã¿ãŒãããã®ã»ãã¥ãªãã£åäžã«åããŠãããŸããŸãªäŒæ¥ãçµç¹ãåºã飿ºããŠåãçµãã§ããããšã®å¿ èŠæ§ãæµ®ã圫ãã«ãããåŸæ¥ã®ãããªãå人ãäžéšã®çµç¹ãã»ãã¥ãªãã£äŒæ¥ã«ããåå¥ã®åªåã§ã¯ãäºé²ã察åŠãé£ããã¬ãã«ãžãšãæ»æã®æè¡ãæå£ãé«åºŠåããŠããŠããããã ã
ãã®ç¶æ³ã«å¯Ÿå¿ãããããæ¥æ¬ã«ãããŠãããµã€ããŒæ»æãžã®çµç¹çãªå¯ŸåŠãè¡ã£ããã瀟äŒçãªæ å ±ã»ãã¥ãªãã£ã®ã¬ãã«ãåäžãããããšãç®çã«ãæ¿åºæ©é¢ãITé¢é£äºæ¥è ã«ãã飿ºã®åããæŽ»çºã«ãªã£ãŠããã
ãã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ãé¢é£ã®ãµãŒãã¹ãæäŸããäºæ¥è ã«ãã£ãŠçµç¹ãããæ¥æ¬ã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³äºæ¥è åè°äŒ(ISOG-J)ããããããåãçµã¿ã«ç©æ¥µçã«åç»ããŠããå£äœã®ã²ãšã€ã ã
åå£äœã§ã¯ãç·åçãèŠå¯åºãšå ±åã§ããããäžã§ã®ããžãã¹å±éãæ å ±æäŸãè¡ã£ãŠããäŒæ¥ã«åããè匱æ§èšºæãªã©ã®ã»ãã¥ãªãã£èšºæãµãŒãã¹ãåºãçè§£ããæå¹ã«æŽ»çšããŠããããã¬ã€ãã©ã€ã³ãçå®ããã®å 容ãããµã€ããŒæ»æããããžãã¹ãå®ã ïœã»ãã¥ãªãã£èšºæãµãŒãã¹ã¬ã€ãïœã(NTTåºç)ãšããæžç±ã«ãŸãšããã
ããããã¬ã€ãã©ã€ã³ãäœæããæå³ããåå£äœã«ãããããŸããŸãªæ å ±å ±æã飿ºã®åãçµã¿ã«ã€ããŠãISOG-Jä»£è¡šã®æŠæºæŽæ°ããã³ãã®å çäŒæ¥ã§ããSCSKã§ãITãããžã¡ã³ã第äžäºæ¥æ¬éšã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³éšWebã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³èª²ãããŒãžã£ãŒãåããé·å°Ÿäº®æ°ã«è©±ã䌺ã£ããé·å°Ÿæ°ã¯ãWebã¢ããªã±ãŒã·ã§ã³è匱æ§èšºæã®ã¬ã€ãã©ã€ã³äœæã«ãåå ããŠããã
é¢é£èšäº : ã»ãã¥ãªã㣠ããŒããŒãœã³ (1) OWASP å²¡ç°æ°
é¢é£èšäº : ã»ãã¥ãªã㣠ããŒããŒãœã³ (2) æ¥æ¬CSIRTåè°äŒ æäžææ°
ãããã£ãŒã«æŠæº æŽ(TAKECHI Hiroshi)
ââCISSPãã©ã㯠ã»ãã¥ãªãã£äºæ¥æ¬éš æ åœéšé·ãæ¥æ¬ã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³äºæ¥è åè°äŒ(ISOG-J)代衚ãèŠèŠåº ã³ã³ãã¥ãŒã¿ãŠã£ã«ã¹é¢é£ç¯çœªåè°äŒ å§å¡ãWASForum Hardening Projectå®è¡å§å¡
![]()
2008幎3æããã©ãã¯ã«å€åãITã»ãã¥ãªãã£ããã³ãµã€ããŒã»ãã¥ãªãã£é¢é£ã®ã·ã¹ãã éçºãšç£èŠãµãŒãã¹éšéãçµãåŸãçŸåšã¯ãäž»ã«å®å ¬åºåã察å¿ã«åŸäºã以åã¯ãçŽ22幎éã«æž¡ãããã©ã³ãå¶åŸ¡ã¡ãŒã«ã«ãããŠç ç©¶éçºãšã»ãã¥ãªãã£ããžãã¹ã®ç«ã¡äžãã«åŸäºããçµéšãæã€ãé·å°Ÿ 亮(Nagao Ryo)
ââSCSK ITãããžã¡ã³ã第äžäºæ¥æ¬éš ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³éš Webã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³èª² ãããŒãžã£ãŒ
![]()
Webã¢ããªã±ãŒã·ã§ã³ãšã³ãžãã¢ãçµãŠ2007幎ããã»ãã¥ãªãã£é¢é£ã®æ¥åã«æºãã£ãŠããã幎é40ãµã€ã以äžã®è匱æ§èšºæã«åŸäºããäžæ¹ãæ°å€ãã®äŒæ¥ã«ãããŠãã¬ãŒãã³ã°ã宿œããã»ãã¥ãªãã£èšºæã®å è£œåæ¯æŽãææããŠããã ãŸãæµ·å€ã®ã»ãã¥ãªãã£è£œåãåãæ±ã£ãŠãããã¯ãŒã«ãã¯ã€ãã§ã®ã»ãã¥ãªãã£äºæ ã«ã粟éã
ã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ã®éèŠæ§ãåçºãããISOG-Jã
ââæåã«ãISOG-Jãã©ããã£ãç®çãæã€å£äœãªã®ãã«ã€ããŠèãããŠäžããã
æŠæº : ISOG-Jã¯ãInformation Security Operation providers Group Japanãã®ç¥ã«ãªããŸããã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³äºæ¥è ã®æ¥çå£äœãšããŠ2008幎6æã«èšç«ãããçŸåšã¯NPOã§ããæ¥æ¬ãããã¯ãŒã¯ã»ãã¥ãªãã£åäŒ(JNSA)æå±ã®çµç¹ãšããŠæŽ»åããŠããŸãã
ISOG-Jã¯ããŠãŒã¶ãŒããã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ãã®å°å ¥ã«ããã£ãŠãRFPãæžããªãããšããç¶æ³ãå€ããããã«äœãã§ããªãã ããããšããå顿èããã¹ã¿ãŒãããŠããŸãã
|
|
ISOG-Jä»£è¡šã®æŠæºæŽæ° |
ã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ãšããã®ã¯ãäŒæ¥ã®æ å ±ã·ã¹ãã ã«å¯ŸããŠãç¹ã«ã»ãã¥ãªãã£é¢ã«é¢é£ããéçšãè«ãè² ããµãŒãã¹ãªã®ã§ããããã®ãã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ããšããæ¥åã«ã€ããŠãåœæã¯ããŸããŸãªäºæãäŒæ¥ã«ãã£ãŠãŸã¡ãŸã¡ã§ããŸãããã®åé¡ã«ã€ããŠè°è«ããå Žããªããšãã£ãç¶æ³ã§ããã
ã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ãšããŠæäŸãããŠãããµãŒãã¹ã«ã¯ãéçšç£èŠãã¯ãããšããŠãè匱æ§èšºæããã©ã¬ã³ãžãã¯ãç·æ¥å¯Ÿå¿ãªã©ãå¹ åºãåéãå«ãŸããŸããITã·ã¹ãã ã®ã©ã€ããµã€ã¯ã«ã§èããã°ããªãã¬ãŒã·ã§ã³ã«çžåœãããéçšãã®éšåãæãé·æã«ãããéèŠãªèŠçŽ ã§ããã«ãããããããããã«é¢ãã課é¡ãæ€èšããããæ å ±äº€æãã§ããå Žããªãã£ãã®ã§ããã
ããããèæ¯ã®ããšãISOG-Jã¯ããªãã¬ãŒã¿ãŒã®äººæè²æãããã³é¢ä¿ããçµç¹ã»å£äœéã®é£æºãæšé²ããããšã«ãã£ãŠãã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ãµãŒãã¹ã®æ®åãšãµãŒãã¹ã¬ãã«ã®åäžãä¿ããå®å šã§å®å¿ããŠå©çšã§ããITç°å¢å®çŸã«å¯äžãããããšãç®çãšããŠèšç«ãããŸãããèšç«åœåã¯10å£äœã§ã2013幎çŸåšã¯22瀟ãå çããŠããŸããSCSKãããããã®äžã®1瀟ã§ãã
ââå ·äœçãªæŽ»åå 容ã¯ã©ã®ãããªãã®ã§ãã?
æŠæº : ã²ãšã€ã¯ããŠãŒã¶ãŒã«å¯ŸããŠãã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ãšã¯äœããã«ã€ããŠåçºããæŽ»åã§ããäŸãã°ããè匱æ§èšºæã¯ã©ã調éããã°ãããããã»ãã¥ãªãã£ã«é æ ®ããéçšãã©ãè¡ãã°ãããããSOC(Security Operation Center)äºæ¥è ãã©ãéžã¹ã°ãããããšãã£ãçåã«å¯ŸããŠãäœããã®ã¬ã€ãã©ã€ã³ãæäŸããŠããããšãããã®ã§ãã
ããã²ãšã€ã¯ãã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ã®çŸç¶ã«ã€ããŠã®æ å ±æäŸãè¡ãããšãå ããŠãã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³äºæ¥è éã®æšªã®é£æºãäœããæ å ±äº€æã®å Žãèšããããšã§ãã
ISOG-Jã®ãªãã¶ãŒããŒãšããŠã¯ãçµæžç£æ¥çãç·åçãã¢ããã€ã¶ãŒãšããŠåéžå 端ç§åŠæè¡å€§åŠé¢å€§åŠã®ç¯ ç°éœäžææã«å°±ä»»ããŠããã ããŠããŸããé¢é£å£äœãšããŠã¯ãJPCERT/CCãIPAãè²¡å£æ³äººã€ã³ã¿ãŒãããåäŒãWASãã©ãŒã©ã ãããããããå šäœãéãã飿ºã®ãªãŒã¬ãã€ãºãªã©ãè¡ã£ãŠããŸãã
ââã¯ãŒãã³ã°ã°ã«ãŒã(WG)ã«ããæŽ»åãæŽ»çºã«è¡ãããŠããããã§ããã
æŠæº : ISOG-Jã«ã¯ãçŸåš5ã€ã®WGããããŸãã
ã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³äºæ¥è ã®æäŸãããµãŒãã¹ãéžå¥ããéã«åèã«ããã¬ã€ãã©ã€ã³ãäœæãããã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ã¬ã€ãã©ã€ã³WGããææ°ã®ã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³æè¡ã®æ¢æ±ãšæè¡è ã®äº€æµãç®çãšãããã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³æè¡WGããã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³äºæ¥è ããµãŒãã¹ã®å©çšçµç¹ãç¹ã«èªèããŠããã¹ãé¢é£æ³èŠã«ã€ããŠæŽçãããã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³é¢é£æ³èª¿æ»WGããã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ã®å¿ èŠæ§ã«ã€ããŠç€ŸäŒçã«åºå ±ããŠãããã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³èªç¥åäžã»æ®ååçºWGããšãã£ããã®ãèšç«åœåããååšããWGã§ãã
2011幎7æããã¯ããããã«å ãã5ã€ãã®ãæšçåæ»æå¯Ÿçæ€èšWGããæŽ»åãéå§ããŠããŸããæšçåæ»æãçãã«ãªãã¯ããããããããæ»æã«é¢é£ããæ å ±ãéããæœåºããŠãããã«ã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ã«çãããã«ã€ããŠã¯éèŠãªããŒãã«ãªã£ãŠããã®ã§ããããããåäœã®äŒæ¥ã§è¡ãããšã¯é£ãããããWGãšããŠã¹ã¿ãŒããããŸãããããã§ã¯ã宿 調æ»ãé²åŸ¡çã«ã€ããŠã®æ€èšãè¡ã£ãŠããŸãã
ããªã±ãŒããªæ å ±ã®å ±æã¯åœäºè å士ã®ãã§ã€ã¹ã»ãã¥ã»ãã§ã€ã¹ã§ã®ä¿¡é Œé¢ä¿ãåºæ¬ã«ãªããŸããããã¯ãæ¥æ¬ã§ãæµ·å€ã§ãäžç·ã§ãããããããæ å ±å ±æã¯ã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³äºæ¥è ã«ãšã£ãŠããã¿ãããªåéã§ã¯ãããŸããããã®WGã§ã¯ãããããã£ãŠããããšåãçµãã§ããŸãã
ââSCSKãããISOG-Jã«åå ããçµç·¯ã¯ãã©ããã£ããã®ã ã£ãã®ã§ããããã
|
|
SCSK ITãããžã¡ã³ã第äžäºæ¥æ¬éšã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³éšWebã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³èª²ãããŒãžã£ãŒã®é·å°Ÿäº®æ° |
é·å°Ÿ : SCSKã§ã¯ã2003幎以éãããã»ãã¥ãªãã£ã®åéã§ããŸããŸãªããžãã¹ãå±éããŠããŸããããã®äžã«ã¯ãSOCã®æ§ç¯æ¯æŽãWebã¢ããªã±ãŒã·ã§ã³è匱蚺æãµãŒãã¹ãå«ãŸããŠããŸããä»åãISOG-Jã§ãè匱æ§èšºæã®ã¬ã€ãã©ã€ã³ããäœæãããšããããšã§ãOWASP Japanã®å²¡ç°æ§ãéããŠã声ãããããã ãããããŸã§ã®ããžãã¹ã®äžããè²¢ç®ã§ããããšãããã®ã§ã¯ãšæããåå ãããŠããã ããŸããã
æŠæº : å ã»ã©ç޹ä»ãããã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ã¬ã€ãã©ã€ã³WGãã§ã¯ãããã§ãéçšç£èŠã«é¢ããã¬ã€ãã©ã€ã³ãåºããŠããŸãããä»åæ°ãã«ãçµæžç£æ¥çãç·ååºãèŠå¯åºã®é¢ä¿åçåºã®çè ã®æ¹ãšäžç·ã«è匱æ§èšºæã«å¯Ÿããã¬ã€ãã©ã€ã³ãäœãããããæžç±åããããšããæŽ»åãè¡ããŸããã
ãã®ææç©ãããµã€ããŒæ»æããããžãã¹ãå®ã ïœã»ãã¥ãªãã£èšºæãµãŒãã¹ã¬ã€ãïœã(NTTåºç)ãšããŠã2æ25æ¥ã«çºå£²ãããŠããŸãã



