æ¥æ¬IBMã¯8æ27æ¥ã«ã2014幎äžåæã®ã»ãã¥ãªãã£è åšååããŸãšããã2014幎äžåæTokyo SOCæ å ±åæã¬ããŒãããçºè¡šãããIBMãã»ãã¥ãªãã£ãŒå¯Ÿçã宿œããŠããåœå äŒæ¥æ°çŸç€Ÿã§ã®ã€ã³ã·ãã³ããåæããæ¥æ¬åœå ã®ååããŸãšããã¬ããŒãã ã
8æ27æ¥ã«è¡ãããçºè¡šäŒã§ãæ¥æ¬IBMã®ããŒãã»ã»ãã¥ãªãã£ã»ã¢ããªã¹ãã®äºäžåææ°ã¯ãä»å¹Ž1æãã6æã®äžåæã§ãç®ç«ã£ããããã¯ã¯3ã€ããããšããŠã以äžã®3ã€ã®é ç®ãåãäžããã
ããã©ã€ãã»ãã€ã»ããŠã³ããŒãæ»æãã®åœ±é¿ã21.9%ã®çµç¹ã§ç¢ºèª
OpenSSLã®è匱æ§ãã€ãHeartbleedæ»æãè匱æ§å ¬éããçŽ1é±éã§100äžä»¶ä»¥äžæ€ç¥
æ°ããªApache Strutsã®è匱æ§(CVE-2014-0094ç)ã«å¯Ÿããæ»æã¯éå®çãªç¯å²ã«çãŸã
äŒæ¥ã§ãå€ãããã©ã€ãã»ãã€ã»ããŠã³ããŒãããIEãAdobe Flash Playerã®è匱æ§ãçªã
ãŠã§ããµã€ããèŠãã ãã§ãã«ãŠã§ã¢ã«ææããããã©ã€ãã»ãã€ã»ããŠã³ããŒããã¯ãå人ã§ã®è¢«å®³ãå€ãããã«æããããå®ã¯äŒæ¥ã§ã被害ããããå·Šã®åã°ã©ãã¯äžåæã«ãã©ã€ããã€ããŠã³ããŒãæ»æã®åœ±é¿ã確èªãããçµç¹ã®å²åã§ã21.9%ã®çµç¹ã§ããã«ãŠã§ã¢ã®ããŠã³ããŒãããçºçããŠããã
ã€ãŸãäŒæ¥ã®2å²ä»¥äžã§ããµã€ãé²èЧâèåŒ±æ§æ»æã®è¢«å®³âãã«ãŠã§ã¢ããŠã³ããŒããèµ·ããŠããããšã«ãªããããã«ã€ããŠäºäžæ°ã¯ã瀟å¡ãæŒäŒã¿ã«ãµã€ããèŠãããååŒå ã»ä»å ¥å ã®ãµã€ããæ¹ãããããŠãããšãããã¿ãŒã³ãå€ãããã ãã¡ãŒã«ã§ã®èªå°ããããæšçåã¡ãŒã«ãšã¹ãã ã¡ãŒã«ã®äžéçãªè©æ¬ºã¡ãŒã«ã§æ¹ãããµã€ãã«èªå°ããŠããããšåæããã
äžåæã®ãã©ã€ããã€ããŠã³ããŒãæ»æã¯ãä»¶æ°èªäœã¯å幎æ¯ã§æžã£ããã®ã®ãæ¥æ¬ã«ç¹åããæ»æãå€ãã£ãããšãç¹åŸŽã ã2æã3æã«ã¯IEã®è匱æ§ãçªããæ»æãçºçããå€ãã®åœå Webãµã€ããæ¹ãã被害ãåããããŸãã5æã«ã¯CDN(ã³ã³ãã³ãã»ããªããªãŒã»ãããã¯ãŒã¯)ã®æ¹ãããèµ·ãã£ãã»ããAdobe Flash Playerã®è匱æ§ãçãããã
ç¹ã«5æã®äºä»¶ã§ã¯ãCDNetworksãæ¹ãããããããšã§ãæ è¡äŒç€Ÿã»ã¬ã³ã¿ã«ããã°ã»åšèŸºæ©åšã¡ãŒã«ãŒã®ããŠã³ããŒããµãŒãã¹ãªã©ã被害ãåãããäºäžæ°ã¯ãIEãFlash Playerã®è匱æ§ãçããããè匱æ§ãã¿ã€ã ãªãŒã«ä¿®æ£ã§ããªãã»åé¿çãåããªãäŒæ¥ã被害ãåããŠããããšããŠããã
ãããã®æ»æã¯ãæ¥æ¬ãã¿ãŒã²ããã«ããŠããããšãç¹åŸŽã ããæããã«æ¥æ¬çããéè¡ã®ãã°ã€ã³æ å ±ãçããã«ãŠã§ã¢ã«ææãããããšãç®çã®ããã ããšäºäžæ°ã¯ãŸãšããŠããã
Heartbleedæ»æã¯ãå ¬éããããã1é±éã§100äžä»¶ä»¥äžã®è¢«å®³
ä»å¹Ž4æã«å€§ããªåé¡ã«ãªã£ãOpenSSLã®è匱æ§ãçªãHeartbleedæ»æã¯ããµãŒããŒèšŒææžã®ç§å¯éµã«ãŸã§ã¢ã¯ã»ã¹ãããå¯èœæ§ããã£ããããå€ãã®ç®¡çè ã察å¿ã«èŠæ ®ããããã ãHeartbleedæ»æã®è¢«å®³ã«ã€ããŠäºäžæ°ã¯ããããããããŠãããã«ããµãŒããŒãæ°æ¥éæ¢ããæ±ºæããã管çè ããããäŒæ¥æŽ»åãã¹ãããããããšãã被害ãåºãŠããããšã®ããšã ã
æ¥æ¬IBM Tokyo SOCã®èŠ³æž¬ã«ããã°ãè匱æ§ã®å ¬éçŽåŸãã1æ¥20äžä»¶ååŸã®æ»æãããã1é±éã§100äžä»¶ãã®æ»æããã£ã(æ¥æ¬IBMãã»ãã¥ãªãã£ãŒå¯Ÿçãè¡ã£ãŠããäŒæ¥ã§ã®èŠ³æž¬ããŒã¿)ã
100äžä»¶ã«ã¯ãç ç©¶è ãã»ãã¥ãªãã£äŒç€Ÿã«ããã¹ãã£ããŒãäžéšå«ãŸããŠãããããã¹ãã£ããŒã§ã¯ãªããæªè³ªãªåããããæ»æãããªããã£ã(äºäžæ°)ããšã®ããšã§ãçæéã§å€§éã®Heartbleedæ»æããã£ãããšã¯ç¢ºãã ã
Heartbleedæ»æã®éä¿¡å IPã¢ãã¬ã¹ã¯ãã¢ã¡ãªã«ã47.4%ãã€ã®ãªã¹31.9%ãäžåœããã10.0%ãšãªã£ãŠãããããããæ»æã®æå£ãç°ãªã£ãŠãããã¢ã¡ãªã«ã¯ã¯ã©ãŠããµãŒãã¹ãå©çšãããã®ãã€ã®ãªã¹ã¯ç¹å®ãããã€ãã®ADSLã¢ãã¬ã¹ããç¹å®äŒæ¥ãçãããŠããã
äºäžæ°ã¯ãäžåœããã®æ»æã§ã¯ãç¹å®ã®ã¿ãŒã²ããã«å¯ŸããŠãè€æ°ã®IPã¢ãã¬ã¹ã«åæ£ãããŠæ»æããŸã1ã¢ãã¬ã¹ããã10ä»¶çšåºŠã®æ»æã«çµã£ãŠãããIPã¢ãã¬ã¹ã§ã®ãããã¯ãé¿ããããã®ãã¯ããã¯ã ãããããšããŠã察çéãã®æå£ã䜿ãããŠãããšåæããŠããã
2014幎äžåæã®3ã€ç®ã®ãããã¯ã¯ãApache Strutsã®è匱æ§ã ãè匱æ§ãçãæ»æã³ãŒããå ¬éãããŠããã4æã«IPAããæ³šæåèµ·ãè¡ããããTokyo SOCã§ã®èŠ³æž¬ã§ã¯ãApache Strutsãžã®æ»æã¯æ°çŸä»¶çšåºŠã®æ»æã2床ãã£ãã ãã§ãæ»æã¯éå®çã ã£ãããã ã
ãã ãäºäžæ°ã¯ãäŒæ¥ã䜿ã£ãŠãããœãããŠã§ã¢è£œåã«ãApache Strutsãçµã¿èŸŒãŸããŠããå Žåãããã察å¿ãé£ãããã¢ã»ãã管ç(ITè³ç£ç®¡ç)ãéèŠã«ãªãããšãããã£ãäºäŸã ã£ãããšããŠããã
ä»åŸã®å¯Ÿç:ã¹ããŒãã»ã¢ã»ãã管çã»äŸµå ¥åæã®å¯Ÿçãäžå¯æ¬
ãã®2014幎äžåæã®ç¶æ³ãããšã«ãäºäžæ°ã¯äŒæ¥ã«æ±ããããããšãšããŠä»¥äžã®3ã€ã®ãã€ã³ãããŸãšããã
ãŸãã¯ãã¹ããŒããã ãè匱æ§å ¬éãšã»ãŒåæã«æ»æã³ãŒããå ¥æå¯èœã«ãªã£ãäºæ¡(Heartbleedæ»æ)ããèŠãŠãä¿®æ£ã»åé¿çé©çšãŸã§ã®ã¹ããŒããéèŠã«ãªã£ãŠããã
2ã€ç®ã¯ãã¢ã»ãã管ç(ITè³ç£ç®¡ç)ããä¿®æ£ã»åé¿çãè¿ éã«è¡ãããã«ãã¢ã»ãã管çãäžå¯æ¬ ã«ãªãã
ãããŠ3ã€ç®ã¯ãäŸµå ¥åæã®éçšäœå¶ããäºäžæ°ã¯ãä¿®æ£ã»åé¿çãé©çšã§ããªãå±é¢ãããã ããããã®å ŽåãäŸµå ¥ãããããšãåæãšããŠãåæã·ã¹ãã ãæå¹ã«æ©èœããŠãããããã®æ å ±ãè¿ éã«åæã§ãããããšããç¹ãéèŠã«ãªãããšããŠãããäŸµå ¥ãããŠãåæã»å¯Ÿå¿ãã§ããã ãã®éçšäœå¶ãéèŠã«ãªã£ãŠããã