ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã«ã¯ãããŸããŸãªèŠçŽ ããããŸãããæ¥ã æ°ããã¢ããªã±ãŒã·ã§ã³ãéçºãããç¶æ³ãšã¢ããªæ°ãèããã°ãã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã«ã€ããŠæ€èšããããšãå¿ èŠã ãšåãããšæããŸãã
1. åªå é äœã¯é«ããªããéèŠãªãã®
IoTããã³ã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã«ã€ããŠArxanãšIBMãè¡ã£ã調æ»ã§ã¯ãæ»æé²æ¢çãäœãè¬ããŠããªãããšãèªããåçè ã44ïŒ ãšããé«ãå²åã«éããŸããã
人ã«ãã£ãŠã¯ããã®ãããªåçãã¢ããªã±ãŒã·ã§ã³ããŒããã©ãªãªã®ãã¡ã®äžéšã«é¢ãããã®ã«ãããªããšæããããããŸãããããããWebã»ãã¥ãªãã£ã«é¢ããWhiteHat Securityã®å幎ããšã®ã¬ããŒãã§ã¯ããä¿éºæ¥çã§ã¯çŽ3åã®1ãéè¡ããã³éèãµãŒãã¹æ¥çã§ã¯çŽ40ïŒ ããã«ã¹ã±ã¢æ¥çãšå°å£²æ¥çã§ã¯çŽåæ°ãè£œé æ¥çãé£åã»é£²ææ¥çãããã³ITæ¥çã§ã¯åæ°ä»¥äžã®ã¢ããªã±ãŒã·ã§ã³ã¯ãåžžã«è匱ã§ããããšå ±åãããŠããŸãã
WhiteHat Securityã®ãåžžã«è匱ããšããèªå¥ã¯ãã幎éãéããŠãã¹ãŠã®æ¥ã«ãããŠè匱ã§ãããããšãšå®çŸ©ãããŠããŸããã€ãŸããå€ãã®ã¢ããªã±ãŒã·ã§ã³ã¯è åšã«ãããããŠãããšèšããã§ãããã
ããã«ãåã¬ããŒãã§ã¯ãæ¥çã«ãã£ãŠç°ãªããä¿®æ£ãŸã§ã®å¹³åæéã¯ãçŽ100æ¥éãã245æ¥éã«åã¶ãããšãåãããŸãããæ¥çå¥ã§ã¿ããšãå°å£²æ¥çãšãã«ã¹ã±ã¢æ¥çã§ã¯çŽ200æ¥ããã¯ãããžãŒããã³ITæ¥çã§ã¯ãããäžåãçŽ250æ¥éãè匱æ§ã®ä¿®æ£ã«èŠããŠããããã§ãã
ãã®ãããªç¶æ³ãçã¿åºããŠããã®ã¯ãæåã«è¿°ã¹ãæŸä»»äž»çŸ©çãªå§¿å¢ã§ããã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ããåªå 床ãªã¹ãã®äžäœã«ãªãå Žåãã¢ããªã±ãŒã·ã§ã³(ãŸãã¯ã¢ããªã±ãŒã·ã§ã³ã«ããŒã¿ãäŸçµŠããAPI)ã®çžåœã«å²åã®è匱æ§ãååšãããšèããŠã誀ãã§ã¯ãããŸããã
2. ã¢ããªã±ãŒã·ã§ã³ã ãã«æ³šæãæããªã
ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã¯ãã¢ããªã±ãŒã·ã§ã³ã®ã¿ã«é¢ä¿ãããã®ã ãšãã誀解ããããããããŸããã
ã¢ããªã±ãŒã·ã§ã³ãç¬ç«ããååšã§ããã°ãããã¯æ£ãããããããŸãããããããã¢ããªã±ãŒã·ã§ã³ã¯ãã©ãããã©ãŒã äžã§å±éããããµãŒãããŒãã£ã«ããã¹ã¯ãªãããAPIã«äŸåãããŸãããŒã¿ç®¡çãæ ãã·ã¹ãã ãšäžäœåãããŸããããã¯ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãã¹ã¿ãã¯ã§ãããã¢ããªã±ãŒã·ã§ã³ãã®ãã®ã ãã§ã¯ãªãããã¹ãŠã®ã³ã³ããŒãã³ãã«ã€ããŠæ³šæãæãå¿ èŠãããããšãæå³ããŸãã
OWASP Top Tenã¯ãã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã«ã€ããŠæ€èšããè¯ãåºçºç¹ã§ããããããã³ã«(TCPãHTTPãããã³TLS)ã¬ãã«ã®è匱æ§ããéå»10幎éã«ãã©ãã«ã®å€§ããªåå ãšãªã£ãŠããããšãå¿ããªãã§ãã ããã
ãŸããããªã¥ã¡ããªãã¯(å¢å¹ å)DDoSæ»æãšãããç¡çŸãªã·ã¹ãã ãã¢ããªã±ãŒã·ã§ã³ã¬ã€ã€ãŒãžã®æ»æãšã®é¢ä¿ãç¡èŠã§ããŸãããDark Readingã®èšäºã§ããã®é¢ä¿ã次ã®ããã«ç€ºãããŠããŸãã
æ»æãåããäŒæ¥ãšçµç¹ã®åæ°è¿ãã¯ããã®DDoSæ»æãšåæã«ãããŒã¿çé£ãã©ã³ãµã ãŠã§ã¢ãªã©èªãã®ãããã¯ãŒã¯äžã§ã®éåãäžæ£ãªæŽ»åãè¡ããããšå ±åããŠãããããšãã°47ïŒ ã¯DDoSæ»æã®åŸã«èªçµç¹ã®ãããã¯ãŒã¯äžã§ã®ãŠã£ã«ã¹ã®æŽ»åã43ïŒ ã¯ãã«ãŠã§ã¢ã®èµ·åãããã³32ïŒ ã¯é¡§å®¢ããŒã¿ã®çé£ãå ±åããŠãããã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã«ãããŠã¯ããããã¯ãŒã¯ãããŒã¿ãããã³ãµãŒãã¹ãå«ãããã¢ããªã±ãŒã·ã§ã³ã«å¿ããŠèŠæš¡ãæ¡å€§çž®å°ãããšãšãã«ããã®ã»ãã¥ãªãã£ãæ ãã¢ããªã±ãŒã·ã§ã³ã¢ãŒããã¯ãã£å šäœã«æ³šæãæãå¿ èŠããããŸãã
- Dark ReadingãDDoS Attacks Surge, Organizations Struggle to Respondã
3. ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã¯ä»äººããšã§ã¯ãªã
F5ã®ã2017幎ç ã¢ããªã±ãŒã·ã§ã³ããªããªã®ç¶æ³ãã®èª¿æ»ã«ãããšããã§ã«äŒæ¥ãçµç¹ã®5åã®1ãã¢ããªã±ãŒã·ã§ã³ã®åæ°ä»¥äžãã¯ã©ãŠãå ã«ãã¹ãããŠããç¶æ³ã§ããã€ãŸããã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã®ç¢ºä¿ã¯ãåŸæ¥ãããããã«å°é£ãšãªã£ãŠããŸãã ãŸããã¢ããªã±ãŒã·ã§ã³ã®ã¯ã©ãŠããžã®ç§»è¡ã«äŒŽããç¹ã«ãããã¯ãŒã¯ãšã·ã¹ãã ã¬ãã«ã®ã³ã³ããŒãã³ãã«é¢ããã»ãã¥ãªãã£ã®è²¬ä»»ãç§»è¡ããå¯èœæ§ããããŸãã ããããã¢ããªã±ãŒã·ã§ã³ãšãã®ãã©ãããã©ãŒã ãããã³ã¢ããªã±ãŒã·ã§ã³ãäŸåããå€éšã®ã¹ã¯ãªãããšãªãœãŒã¹ã¯ãäŸç¶ãšããŠãã®ã¢ããªã±ãŒã·ã§ã³ãå©çšããåŽã®è²¬ä»»ã§ãããªã³ãã¬ãã¹ãšåçã®ã»ãã¥ãªãã£ãã¯ã©ãŠãå ã§å®çŸããããšã¯ãããªã·ãŒã¬ãã«ã§ãªã³ãã¬ãã¹ã®ãã®ãšäºææ§ããªããã€ãã£ããªã¯ã©ãŠããµãŒãã¹ãšçµã¿åãããå Žåãç¹ã«å°é£ãšãªãåŸãŸããã€ãŸãããããã®ããªã·ãŒããªã³ãã¬ãã¹ãšã¯ã©ãŠãã®äž¡æ¹ã§ããµãŒãã¹ã®äžè²«æ§ãä¿èšŒãããã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã«é¢ããäžè²«æ§ãåææäŸã§ãããµãŒãã¹ããŒã¹ã®è£œåã«ç§»ãããããã¯ã¯ã©ãŠããã€ãã£ãã®ãµãŒãã¹ã«ã€ããŠåçã®ããªã·ãŒãæ éã«äœæããããšãã£ãæ¹æ³ã§å¯ŸåŠããªããã°ãªããŸããã ãããã«ãããã©ã®ãããªæ¹æ³ãåããã«ãããããã責任ã¯ã¢ããªã±ãŒã·ã§ã³ã䜿ãåŽã«ãããŸãããã©ã³ãã®è©å€ãæ¶è²»è ããã®ä¿¡é Œãããã³(èªèšŒæ å ±ãçé£ãããå Žåã¯)å°æ¥çãªæªçšã«é¢ãããªã¹ã¯ã®ãããã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã¯ãããŸã§ä»¥äžã«éèŠãšãªã£ãŠããŸãã 察çãæåŸãŸã§å éãããããããã¯èª°ãã察å¿ããŠãããã ãããšèããããšã¯ã倧æšäºãåŒãèµ·ããåå ãšãªããŸãããã¹ããšæ¯æ£ã®éèŠæ§ãèªèããé«ãåªå 床ãèšå®ãããšãšãã«ãã¯ã©ãŠããšã¯ã©ãŠããæ¯ãããµãŒãã¹ãå®çŸããã¢ãŒããã¯ãã£äžã®éžæè¢ã掻çšããããšããªã¹ã¯è»œæžã«å€§ãã«åœ¹ç«ã¡ãŸãã ã©ã®ãããªç¶æ³ã§ãã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã¯å¿ é ãšãªããŸããä»åè¿°ã¹ãããšãèžãŸããŠãååãªå¯Ÿçãè¡ããŸãããã
èè ãããã£ãŒã«
äŒè€ æ çŽå€«(ããšã ããã)
UNIXãµãŒããã¹ãã¬ãŒãžãã·ã³ã»ã¯ã©ã€ã¢ã³ããšãã£ãã€ã³ãã©ãšã³ãžãã¢ãçµãŠãF5ãããã¯ãŒã¯ã¹ãžã£ãã³ãž2012幎ã«å ¥ç€Ÿã
F5ãããã¯ãŒã¯ã¹ãžã£ãã³
ã»ãŒã«ã¹ãšã³ãžãã¢ãªã³ã°æ¬éš
ããªã»ãŒã«ã¹ã³ã³ãµã«ã¿ã³ã
çŸåšã¯ã»ãã¥ãªãã£ã»ã¯ã©ãŠããããŒã¯ãŒãã«ã€ãã³ãè¬æŒããã³ãºãªã³ã©ããè¡ããF5ãœãªã¥ãŒã·ã§ã³ã®åèæŽ»åã«å¥®éäžã
æè¿ã¯OpenStackãIoTãšãã£ãããŒã¯ãŒããäžå¿ã«é£æºãœãªã¥ãŒã·ã§ã³ã暡玢ããŠããã

