ãŒããã©ã¹ããåé¡ãã3ã€ã®èгç¹
ååã¯ãåŸæ¥ã®å¢çé²åŸ¡ã¢ãã«ãã»ãã¥ãªãã£å¯ŸçãšããŠé£ããããšãšããŒããã©ã¹ããæ³šç®ãããçç±ã«ã€ããŠèª¬æããŸãããããã§ãä»åã¯ãŒããã©ã¹ãã®æŠèŠãšãã®ç¹åŸŽã«ã€ããŠè§£èª¬ããŸãã
æ¬é£èŒã§ã¯ããããŸã§ã«ããã©ã¹ããæå±ãããŠããèæ¯ãããŒããã©ã¹ãã®æŠèŠã«ã€ããŠç޹ä»ããŠããŸãããä»åã¯ããŒããã©ã¹ãã«ããããœãªã¥ãŒã·ã§ã³ã«ã€ããŠèª¬æããããšæããŸãã
ãŸããããã§ã¯å€§ãŸããªåé¡ãšããŠããªãœãŒã¹(æ å ±è³ç£ãã·ã¹ãã )ããããã¯ãŒã¯ããããŠããšã³ããã€ã³ã(PCãã¹ããŒããã©ã³çã®ç«¯æ«ãæããŸã)ã®3ã€ã®èгç¹ã§åãããã€ã³ããçµã£ãŠèããŠãããããšæããŸãã
åé¡1:ãªãœãŒã¹(æ å ±è³ç£ãã·ã¹ãã )
ãŒããã©ã¹ãã®ååã§ã¯ã誰ããçµç¹ã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ãããã³ã«ãèªèšŒã»èªå¯ãæ±ããããããšã¯ã第2åã«èšè¿°ããŸããããã®ããããªãœãŒã¹ãžã®èªèšŒã»èªå¯ã¯ããŒããã©ã¹ãã§ã®åºç€ã«ãªãéšåãšãããŸãã
ãããã£ãæ©èœã¯ãåŸæ¥ã¯ç€Ÿå ã«èšçœ®ãããID管çãµãŒãã䜿ã£ãŠå®è£ ããŠããŸãããããã第1åã§èšè¿°ãããšããã瀟å€ããäŒæ¥ã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããšãæ±ããããããã«ãªã£ãŠããããšãããID管çãèªèšŒã·ã¹ãã èªäœãã¯ã©ãŠãã§æäŸãããIDaaS(Identity as a Service)ããšãããµãŒãã¹ãç»å ŽããŠããŠããŸãã
ãããŠãIDaaSãšé£æºãããŒããã©ã¹ãã«åºã¥ããã¢ã¯ã»ã¹å¶åŸ¡ãè¡ããœãªã¥ãŒã·ã§ã³ãšããŠãSDP(Software Defined Perimeter)ãæããããŸãã
ãŒããã©ã¹ãã¢ãã«ã«åºã¥ããã»ãã¥ãªãã£å¯Ÿç:SDP
ãŒããã©ã¹ãã«ããããããã¯ãŒã¯ã»ãã¥ãªãã£ã®ä»£è¡šãšããŠãSDP(Software Defined Perimeter)ãç¥ãããŠããŸãã
SDPãšã¯ããã®ä»æ§ããŸãšããå£äœã§ãããCSA(Cloud Security Alliance)ãã«ããã°ãå¢çç·(Perimeter)ããœãããŠã§ã¢äžã§æ§ç¯ãéäžçã«å¶åŸ¡ããã¢ã¯ã»ã¹å¶åŸ¡ã«é¢ããèšå®ãæè»ã«åçã«å€æŽããŠå®å šã«ããŒã¿ã転éãããæè¡ãšãããŠããŸããâŠããŒããã¡ãã£ãšåããã¥ããã§ããã
VPNãšã®æ¯èŒ
ããã§ããã¬ã¯ãŒã¯ã§ãã䜿ãããæè¡ã§ããVPN(Virtual Private Network)ãšæ¯èŒããŠã¿ãŸããããVPNã¯ããŠãŒã¶ãã©ã®å Žæããã§ãã¢ã¯ã»ã¹åºæ¥ããããå€éšããæ¥ç¶ã§ããIPã¢ãã¬ã¹ãæã£ãŠããŸãããããŠãæ¥ç¶åŸã«ãID ãšãã¹ã¯ãŒãã§ã·ã¹ãã ã«ãã°ã€ã³ããããšãå€ãã§ãã
å®ã¯ãããã«åé¡ããããŸããäŸãããªããåºå®é»è©±ã®çªå·ãå ¬éããŠãããããªãã®ã§ããæªã人ãé»è©±çªå·ãèŠã€ããå Žåããã®å®¶ã®äž»ã®ååãç¥ããªããŠãããŸãé»è©±ãããããšã§ã(é»è©±ã«åºã人)ãã¯ããäœè€ã§ããã©ãâ(æªã人)ãããããã®å®¶ã¯ãäœè€ãšããååãªãã ãªããã®ãããã§äœè€ã¯2äžç®ã«ããããªããªãããããâŠãããšãã£ãå ·åã§ã次ã®ã¢ã¯ã·ã§ã³ãèšç»ããããã®æ å ±ãäžããŠããŸããŸãã
ã€ã³ã¿ãŒãããã«æ¥ããŠããVPNè£ çœ®ã®è匱æ§ãçã£ãæ»æãå€ããå®éã«æ»æãåããããšã«ãã被害ãå€ãå ±åãããŠããŸãã2020幎1æã«ã倧æå€è²šäž¡æ¿ãµãŒãã¹ãæäŸããTravelex瀟ãã©ã³ãµã ãŠã§ã¢ã«å€§èп𡿿ãã600äžãã«ãã®èŠæ±ããããããšã¯ãèšæ¶ã«æ°ãããšããã§ãã
äžæ¹ã§ãSDPã§ã¯ãã¢ããªã±ãŒã·ã§ã³ãµãŒãåŽã®æ¥ç¶å (Accepting-SDPãã¹ã)ã¯ãå€éšããèŠããªãããŸããã§ã¯ãæ¥ç¶ããã«ã¯ã©ãããã®ãããŸãããSDPã³ã³ãããŒã©ãŒãããæåã®åä»ã«ãªããŸããäžæŠã仲仿¥è ãæãããšã§ã¢ããªã±ãŒã·ã§ã³åŽã®å®å šæ§ãæ ä¿ããŠããŸãã
æµããšããŠã¯ãSDPã³ã³ãããŒã©ãŒããã¢ã¯ã»ã¹ããŠãããŠãŒã¶ãããã€ã¹(Initiating SDPãã¹ããšèšããŸã)ããæ¥ç¶å ããããã«æ¥ç¶ããŠãããã©ãããã確èªããŸãã
ãã®ããã«ããŠãæ¥ç¶å ãæ¥ç¶ããŠãOK!ãšç¢ºèªã§ããå Žåã®ã¿ãAccepting-SDPãã¹ããžã®æ¥ç¶å ã®æ å ±ãInitiating SDPãã¹ã(ãŠãŒã¶åŽ)ã«äŒããŸãããã®æ å ±ããªãéããã¢ããªã±ãŒã·ã§ã³ãžæ¥ç¶ã§ããŸããã
ãã®ããã«ãSDP ã§ã¯ãèªèšŒã»èªå¯ããããŸã§ã¯ããããªãæ¥ç¶ãè¡ãããªããããç©ççãªå¢çã«é Œãããšãªããé«ãã»ãã¥ãªãã£ã確ä¿ã§ããããã«æ§æããŠããŸããSDPã¯ããŒããã©ã¹ãã¢ãã«ã«åºã¥ããããšããããŒã¯ãŒããšäžç·ã«èªãããããšãå€ãã®ã§ããããããã£ãä»çµã¿ãããããã§ãã
ãªããèªèšŒã»èªå¯ã®éšåã«é¢ããŠã¯ãSDPããIDaaSãšé£æºããããšã§è¡ããŸããå ·äœäŸãšããŠã¯ãPCããæ¥ç¶ããŠããå Žåã«ããã®ãŠãŒã¶ãæã£ãŠããã¹ããŒããã©ã³ã«éç¥ãããŠãæ¬äººãã©ããã確èªããããšãã£ãæ¹æ³ãå©çšããããšãå€ãã§ããã
SDP以å€ã®ãããã¯ãŒã¯ã»ãã¥ãªãã£ã§ã®äž»ãªãœãªã¥ãŒã·ã§ã³ã§ã¯ãSWG(Secure Web Gateway)ããCASB(ãã£ã¹ããŒãCloud Access Security Broker)ãªã©ãæããããŸããSWGãšCASBããé©æé©æã§æŽ»çšããã°ãå€ãã®ã¯ã©ãŠãå©çšæã®ã»ãã¥ãªãã£å¯Ÿçã«å¿ãããããšèããããŸãã
次åã¯ãSWGãCASBãšããããã¯ãŒã¯ããšã³ããã€ã³ãã§å©çšããããœãªã¥ãŒã·ã§ã³ã«ã€ããŠèª¬æããããšæããŸãã


