ã¢ãºãžã§ã³ããæäŸããããã§ãã¯ã»ãã€ã³ãæšçåæ»æå¯Ÿçããã±ãŒãžãã¯ãæšçåæ»æå¯Ÿçã§æ±ããããã3倧æ©èœããã»ããã«ããŠæäŸãããœãªã¥ãŒã·ã§ã³ã ãæšçåæ»æå¯Ÿçã®æ»æã·ããªãªãèžãŸããããšã§ãæ¬åœã«æ±ãããã察çã宿œã§ããããšã倧ããªç¹åŸŽã§ãããåãœãªã¥ãŒã·ã§ã³ã®æ©èœãæ»æã·ããªãªã«æ²¿ã£ãŠè©³ãã玹ä»ããŠããã
é£èŒç¬¬1åã§ã¯ãæšçåæ»æå¯Ÿçã§ã¯ãã¢ã³ããŠã€ã«ã¹ããã¢ã³ãããããããµã³ãããã¯ã¹ãã飿ºããŠåäœã§ããããšãéèŠã ãšææããã第2åã§ã¯ããã®ãã¡ã®ã¢ã³ããŠã€ã«ã¹ãšã¢ã³ããããã®æ©èœãæŽçããããä»åã¯ããµã³ãããã¯ã¹ã䜿ã£ãæªç¥ã®è åšã®æ€ç¥ãšãæ€ç¥ããæ å ±ãã¯ã©ãŠãããŒã¹ã§å ±æããä»çµã¿ã玹ä»ãããã
ãµã³ãããã¯ã¹ã§æ€ç¥ããè åšããŒã¿ãã¯ã©ãŠãã§å ±æ
ããã§ãã¯ã»ãã€ã³ãæšçåæ»æå¯Ÿçããã±ãŒãžãã®ãµã³ãããã¯ã¹ã¯ãæšå¹Žç§ããæäŸãããããã«ãªã£ãæ°æ©èœã ããããŸã§ã«ç޹ä»ããã¢ã³ããŠã€ã«ã¹ãã¢ã³ããããã¯ããã®ãµã³ãããã¯ã¹ãšé£æºããŠåäœããããšã«ãããè åšé²åŸ¡ã®èœåãé£èºçã«åäžãããããšãå¯èœã ã
|
|
ã¢ãºãžã§ã³ã ããŒã±ãã£ã³ã°éš ãããŒãžã£ãŒ ç§å±±è²ŽåœŠæ° |
ã¢ãºãžã§ã³ãã®ããŒã±ãã£ã³ã°éšãããŒãžã£ãŒç§å±±è²ŽåœŠæ°ã¯ããã®3ã€ãã»ããã«ãªã£ãŠæäŸãããããšã§ããããŸã§å¯Ÿå¿ã§ããªãã£ãè åšã«å¯ŸããŠãããŒã¿ã«ã§é²åŸ¡ããããšãã§ããããã«ãªããšèª¬æããã
ããµã³ãããã¯ã¹ã§æ€ç¥ããäžæ£ããã°ã©ã ã®æ å ±ãã¯ã©ãŠãäžã§ããŒã¿ããŒã¹ãšããŠå ±æãããã®ããŒã¿ããŒã¹ãããšã«ãã¢ã³ããŠã€ã«ã¹ãã¢ã³ããããã®ã·ã°ããã£ãã¡ã€ã«ãªã©ãã¢ããããŒãããŠãããŸããããšãã°æªç¥ã®è匱æ§ãçªãæ»æããµã³ãããã¯ã¹ãæ€ç¥ããå Žåãæ°æéåŸã«ã¯æ°ããã·ã°ããã£ãã¡ã€ã«ãäœæãé ä¿¡ã§ããŸãã
ã§ã¯ããããããµã³ãããã¯ã¹ãã¯ã©ãŠãäžã§ã®æ å ±å ±æã¯å®éã«ã©ã®ããã«æ©èœããã®ããæ»æã·ããªãªã«æ²¿ã£ãŠæ·±å ãããŠãããã
ã¢ãã©ã€ã¢ã³ã¹ã«åãããThreatEmulationããšã¯ã©ãŠãããŒã¹ã®ãThreatCloud Emulationã
ãã§ãã¯ã»ãã€ã³ãç€Ÿã®æäŸãããµã³ãããã¯ã¹ã«ã¯ããªã³ãã¬ãã¹ã®ã¢ãã©ã€ã¢ã³ã¹äžã§åäœãããThreatEmulationããšãã¯ã©ãŠãäžã®ãµãŒãã¹ãšããŠæäŸãããThreatCloud Emulationãã®2ã€ããããåºæ¬çã«äž¡è ã¯åããšã³ãžã³ãçšããŠãããçãããããã°ã©ã ããµã³ãããã¯ã¹äžã§å®éã«å®è¡ããã®æ¯ãèããèŠãŠãäžæ£ãªããã°ã©ã ãã©ãããå€å®ããã
ããã§ã¯å žåçãªæ»æã·ããªãªã®1ã€ã§ããããã£ãã·ã³ã°ã¡ãŒã«ã䜿ã£ãæšçåæ»æãèããŠã¿ããã
第1åã§ãå°ãè§Šããããã«ãæšä»ã®æšçåæ»æã¡ãŒã«ã¯æ¬ç©ãšèŠçŽãã»ã©å·§åŠã«äœãããŠãããããšãã°ãæ°æ¥åã«ã»ãããŒãªã©ã«åå ããŠããå Žåã«ãâ¯â¯ã®ã»ãããŒã§ååºäº€æãããŠããã ããâ¯â¯ã§ããæ·»ä»ãã¡ã€ã«ãã芧ãã ããããªã©ãã£ãäž»æšã®ã¡ãŒã«ãå±ãã
ããã§æ·»ä»ãã¡ã€ã«ãéããšãäžæ£ãªããã°ã©ã ãã€ã³ã¿ãŒãããããåæã«ããŠã³ããŒããããŠããŠãPCãææããŠããŸããã¢ã³ããŠã€ã«ã¹ãé©åã«ã¢ããããŒããããŠããªãã£ãããæªç¥ã®è匱æ§ãçªãæ»æããããã¯æ¢ç¥ãŠã€ã«ã¹ã«æ¹è¯ãå ããããããäºçš®ã«ããæ»æãåãããããå Žåãã¢ã³ããŠã€ã«ã¹ãœãããèŠåã衚瀺ããããšããªãããŠãŒã¶ãŒã¯ææããããšã«ããæ°ã¥ããªãã®ã ã
æ·»ä»ãã¡ã€ã«ã§ã¯ãªããã¡ãŒã«ã®æäžã«URLã®ãªã³ã¯ãèšèŒããã±ãŒã¹ãå€ããå€ãã®å Žåããªã³ã¯å ã¯æ¹ç«ãããWebãµã€ãã§ãããããäžæ£ãªããã°ã©ã ãéãããŠããä»çµã¿ã«ãªã£ãŠããããã®éããæªç¥ã®è匱æ§ãäºçš®ãçšããããå Žåãã¢ã³ããŠã€ã«ã¹ã¯æ©èœããªããããã¯ã°ã©ãŠã³ãã§äžæ£ãªããã°ã©ã ãããŠã³ããŒããããŠããŠãŒã¶ãŒã¯ãã®ããšã«ããæ°ã¥ããªãã
ãµã³ãããã¯ã¹ã¯ãããããæ»æã«æå¹ãªå¯Ÿçã ãThreatEmulationãThreatCloud Emulationãæå¹ã«ããŠãããšãã¢ã³ããŠã€ã«ã¹ãªã©ãããã¬ããäžæ£ãªæ·»ä»ãã¡ã€ã«ãæ€ç¥ããèŠå(é衚瀺èšå®ãå¯)ããããšãã§ãããã¡ãŒã«ã«æ·»ä»ãããããããã¯ãããã¯ãŒã¯è¶ãã«ããŠã³ããŒããããã¡ã€ã«ããWindows PCããšãã¥ã¬ãŒãããä»®æ³ãã·ã³äžã§å±éãããã§å®éã«åãããŠãæåããã§ãã¯ããã
ãã§ãã¯ããæåã¯ãäžå¯©ãªãã¡ã€ã«ãäœæããªãããäžèŠãªããã»ã¹ãèµ·åããªãããã¬ãžã¹ããªã«äžæ£ãªå€ãæžã蟌ãã§ããªãããå€éšãšäžæ£ãªéä¿¡ãè¡ã£ãŠããªãããªã©å€å²ã«ããããããããæåãèŠã€ããäžæ£ãªããã°ã©ã ã ãšå€å®ããå Žåãé²èЧãå®è¡ããããã¯ãããŠãŒã¶ãŒãäžæ£ãªããã°ã©ã ã«ææããªãããã«ããã
ãšãã¥ã¬ãŒã·ã§ã³ç°å¢ãšããŠå¯Ÿå¿ããŠãããã©ãããã©ãŒã ã¯ãWindows XP/7/8ãOffice 2003/2007/2010ãAdobe Reader 9ããã¡ã€ã«åœ¢åŒãšããŠã¯ãEXEãZIPãOffice圢åŒãPDFã«å¯Ÿå¿ããSSLéä¿¡äžã§ã®æ€ç¥ãå¯èœã«ãªã£ãŠããã
ææ°è åšæ å ±ãåžžã«é ä¿¡ããThreatCloud
ããã§ãã¯ã»ãã€ã³ãæšçåæ»æå¯Ÿçããã±ãŒãžãã®åŒ·ã¿ã¯ãåã«äžæ£ãªãã¡ã€ã«ãæ€ç¥ããŠæ¢ããã ãã§ã¯ãªããããã§çºèŠããè åšã®æ å ±ããã¿ããã«ã¢ã³ããŠã€ã«ã¹ãã¢ã³ããããã®ãšã³ãžã³ã«ãåæ ã§ããç¹ã倧ããªãã€ã³ãã ã
ãã§ãã¯ã»ãã€ã³ãæšçåæ»æå¯Ÿçããã±ãŒãžãå°å ¥ãããç°å¢ã«ãããŠThreatEmulationããã³ThreatCloud EmulationãçºèŠããããã°ã©ã ã¯ãåºæ¬çã«ã¢ã³ããŠã€ã«ã¹ãããæãããã®ã«ãªãããããã£ãŠããã®è åšæ å ±ã¯ã¢ã³ããŠã€ã«ã¹ãããŒã¿ããŒã¹ã«åã蟌ã¿ã次å以éã¯ãã¡ãã§æ¢ããã¹ãã ãããããããããšã§ãThreatEmulation/ ThreatCloud Emulationã§ã®å®è¡ããã»ã¹ã岿ããå¹ççãªæ€ç¥ãè¡ãããšãã§ããã
ãããå®çŸããããã«ãæ€ç¥ããäžæ£ããã°ã©ã ã®æ å ±ã¯ãThreatCloudããšåŒã°ããã°ããŒãã«ãªè åšããŒã¿ããŒã¹ã«éçŽããããããå šäžçã®ãŠãŒã¶ãŒãå©çšãããã§ãã¯ã»ãã€ã³ã補åã«ããããŸåæ ãããä»çµã¿ã«ãªã£ãŠããããã¡ããããã«ã¯ãThreatEmulationã®ã¿ãªããããã§ãã¯ã»ãã€ã³ã瀟ãåéããæ§ã ãªè åšæ å ±ãå ±æãããã
ãŸããThreatCloudã®æ å ±ã¯ã¢ã³ããããã«ãåæ ããããæ°ããªäžæ£ããã°ã©ã ã®éä¿¡ãã¿ãŒã³ãè§£æããã¢ã³ããããã«é ä¿¡ãããããã«ãããUSBã§ç€Ÿå ãããã¯ãŒã¯ã«æã¡èŸŒãŸãããªã©ã§ãã¢ã³ããŠã€ã«ã¹ãããæããéã«ãC&CãµãŒããžã®éä¿¡ã鮿ã§ããããã«ãªãã
ããã§ãã¯ã»ãã€ã³ã瀟ã¯ãã¢ã³ããŠã€ã«ã¹æ©èœãã¢ã³ããããæ©èœãèªç€Ÿéçºãããããã¯ãŒã¯ã»ãã¥ããªã£ãã³ããŒã§ãããã®ãããããããæªç¥ã®è åšã«å¯Ÿããè¿ éãªå¯Ÿå¿ãã§ããŸããäŒæ¥ã®ã»ãã¥ãªãã£ç®¡çè ã¯ãè åšã¬ããŒããšããã·ã¥ããŒããæŽ»çšããŠããããããŠã€ã«ã¹ã®æ»ææ å ±ãThreatEmulationã§æ€åºãããæ°ããªè åšããã«ãŠã§ã¢ååã®å šäœåãææ¡ã察å¿ããããšãã§ããŸãã(ç§å±±æ°)
ãµã³ãããã¯ã¹è£œåã®ãªãã«ã¯ãè åšãæ€ç¥ããŠçµãããšãããã®ãããããã®å Žåãæªç¥ã®è åšãæ€åºããããšãæ€ç«ãé§é€ãä»ç€Ÿã®ãŠã€ã«ã¹å¯Ÿçãœããã«ãã ããããšã«ãªããè åšã®æ€åºããã·ã°ããã£ã®æŽæ°ãŸã§ãã¹ã ãŒãºã«è¡ãããŠãããšã¯èšãé£ãã
察ããŠããã§ãã¯ã»ãã€ã³ãæšçåæ»æå¯Ÿçããã±ãŒãžã¯ãã¢ã³ããŠã€ã«ã¹ãã¢ã³ããããããµã³ãããã¯ã¹ã飿ºããããŒã¿ã«ãªé²åŸ¡ãå¯èœã«ãªã£ãŠãããããã¯å€§ããªç¹åŸŽãšèšããã ããã
ãªããThreatEmulationãšThreatCloud Emulationã®ããããå©çšãããã¯ãå°å ¥ããèŠæš¡ã圢æ ã§å€ããããšãã§ãããããšãã°ãæ ç¹ãå€ããè€æ°ã®ã¢ãã©ã¢ã³ã¹ãèšçœ®ããããã«æéãããããšãã£ãå Žåã¯ãæ¬éšã§ã¯ãªã³ãã¬ãã¹ã®ThreatEmulationãæ ç¹ã§ã¯ã¯ã©ãŠãã®ThreatCloud Emulationãå©çšãããšãã£ãããšãã§ããã
ãŸããäŒæ¥ã®ã»ãã¥ãªãã£ããªã·ãŒã«ãã£ãŠã¯ãå€éšã®ã¯ã©ãŠãã«ãã¡ã€ã«ã®äžåãéä¿¡ããããªããšããã±ãŒã¹ã§ã¯ãªã³ãã¬ãã¹ç°å¢ã§ã®ã¿å©çšããããšãã§ããããã®å Žåã¯ããããã¯ãŒã¯ã®ãã©ãŒããŒã(TAPã¢ãŒã)ã䜿ã£ãŠãæ¢åç°å¢ã«åœ±é¿ãäžããªããããªæ§æãå¯èœã ã
ãŸããã¢ãºãžã§ã³ãã§ã¯ãæšçåæ»æç¡æèšºæãµãŒãã¹ãšããŠããã§ãã¯ã»ãã€ã³ãæšçåæ»æå¯Ÿçããã±ãŒãžã®è²žåºãµãŒãã¹ãè¡ã£ãŠãããå®éã«è©Šéšå°å ¥ãããã®æ©èœã詊ããŠã¿ãããšãå¯èœã ã
æšçåæ»æå¯Ÿçã§ã¯ãæ¬åœã«äœããã¹ãããããããªãã±ãŒã¹ãå°ãªããªããåŸæ¥åã®ã»ãã¥ãªãã£å¯Ÿçã§ã察å¿ã§ãããšãã誀解ããããµã³ãããã¯ã¹ããå°å ¥ããã°å¯Ÿçãçµãããšãã£ã誀解ããããä»å玹ä»ãããããªã3ã€ã®æ©èœã®é£æºããèªç€Ÿã®å¯Ÿçã®åèã«ããŠããã ãããã