ե奢֥ : byߥС

ե奢֥

byߥС

ޡȥۡΰݤˡ

IoTInternet of ThingsΤΥ󥿡ͥåȡ˥ǥХϡ֤֤ΩQoLquality of lifeˤ夵롣󤲤ȡѡˤȤ˼¢ˤȤǧꡢ֥򲹤Ϥ᤿Ǥ롣Τ褦ˤƤԳΤӽ²ͼ֤󤬤Ǥ롣ΤȤϤФ餷¿ο͡ǽβäʤ顢ѲǤ褦ˡ󥹤ˤϥꥹȼä˥饤󥻥ƥץ饤ХΥꥹ뤬ꥹΰƱ˸ˤ礹롣Ȥ۴ɹΤɽؤΥå֤ǤȤȤϡʤλ֤ˤϤʤ롣饦ɤΥȤϥå󥰤Сϥåޤؤ򳫤뤷餯ؤΥˡǻԾѤǤȤȤ̣Ƥ롣ơϤʤˤϥå󥰤αޤʤåȤϲǵƤ뤳ȤˤĤƤΥǡ뤿ᡢåȤΤΤץ饤ХФꥹ򶼤

Example of a smart home set up

ޤϰŪʥޡȥۡιȡľ̤Ǥμ򼨤Ƥ롣ޡȥۡƳĴǡߤƤ뤿ᡢǤɸŪȤʤäƤʤΤΡ¸εѤǤɤΥ쥤䡼Ǥ⹶⤷롣

ץ饤Х䥻ƥˤĤơ˿ۤ˻פΤǤСåȤäȤäꤷʤȤˤ뤿ͣˡǤ롣¿οͤˤȤäƤϡIoT䥹ޡȥۡΡ֤ʤȤåȤΤۤץ饤Х䥻ƥˤĤͽȾΤȤο魯ΤޤǤϡIoTǥХϹɸŪˤϤʤäƤʤɸŪˤʤǤ⹶ԤϥǥХη׻ǽϤǡޤǡоݤˤʤäƤʤºݤθߺΥꥹϡǥХ¤ȼԤĿͥǡɤΤ褦˰Ȥˤ롣ɤΤȤŪӹ٤ǤϤʤȤȤꥹ㸺뤿ˤǤ뤳Ȥʲ˵󤲤롣


ѥ֥åIPɥ쥹ȡǥХȤľŪ³ʤǥХΥեȤˡե뤫ǤNATNetwork Address Translation˥롼֤ơ󥿡ͥåȤǥХȯǤʤȤǧ롣ѥ֥åIPɥ쥹ФǥХݡȤФ˥ץǤʤ褦ˤʤ顢롼UPnPUniversal Plug and Playˤ̵ˤ뤳ȡ

ǥХ䥵ӥΥץ饤Хӥƥܤ򤯤ޤʤơפ򤹤٤ƺ롣¿ΥǥХܤˤƾʤΤץ饤Х˱ƶ뤳ȤǥХˤȹͤʤ顢ɬפʵǽߤ褦ȤСޡȥƥӤ䥲ൡǡºݤ˲ޥɤȤޤǻȤäȤʤʤ顢̵ˤȤ塹εǽƤߤʤä顢ĤǤ᤻ͭ롣

IoTǥХΥ饦ɥӥϿݤˤϡϤĸͭΥѥɤѤ˥ѥɤݤġԤɤˤƥѥɤ߽Фꥹȹͤʤ顢ѥɤѹ뤳ȡޤǥХϤ٤ơ᡼륢Ȥ̤ƥѥɤꥻåȤǤ褦ˤƤΤǡ᡼륢Ȥ˶ϤʥѥɤͿơѥɤݤƤ뤳ȤǧȤ褤ޤȤȤǤ2FA2ǧڡˤѤ롣ǤϤƤΰŪʥ᡼륵ӥ󶡤Ƥ롣

PC䥿֥åȡäޥ륦Ƥȡޥ륦ˤ˥ѥɤࡣΤᡢޡȥۡॵӥ䤽˷դƤ᡼륢ȤΥѥɤǽ롣ѥɤȤǥХˤϥƥեȥ򥤥󥹥ȡ뤷ǿΥƥǥեȥ򹹿롣ˡϰѤʥѥ᡼Υ󥯤źեեФ˥åƤϤʤʤ

𸼴ؤ˥⡼Ȥ饢Ǥ륹ޡȥåɤƤѤΤǤСտƤ褦ȤϤإޥåȤ俢ȭβ˸֤Ƥοʹ֤ä顢ޡȥåΤ֤ۤ

ƥ䱣Ƴʤ顢פʤȤϥͥåȥڤΥ𤫤饯饦ɤŪ˲ǥХˤĤƤ⡢ºݤ˻ϻȤΤǤʤСƱͤˤ뤳ȤƤȤ褤ȾIoTǥХη׻ǽϤϤۤɹ⤯ϤʤΤư衦νϥ饦ɾΥФǹԤ뷹ˤ롣ΤȤפФ

Wi-FiǰŹ沽ʤǤWPA2ˤѤ뤳ȡϤWi-Fiѥե졼ȤޤΥѥե졼ݤĤ褦ˤ롣ѥե졼̵ä夫ä硢뤤WEPΤ褦ѻߤ줿ץȥѤƤ硢ƥδϼWi-FiϥץʥͥåȥȤʤ롣

Ź䥷åԥ󥰥⡼ۥƥΥͥåȥʤɡץWi-FiͥåȥѤݤˤդɬפʤΥץꥱʿʸǥѥɤȡ줬ޤּԹﳲԤȤʤ롣ץWi-FiѤݤˤϾVPNץꥱȤȡ֤ˤʤ뤬ʤΥѥɤʤοȸ䤢ʤIoTؤθȤʤ롣

ݥȤꤹ뤳ȡɬפˤʤ뤳ȤʤʬäƤǥХϡƳʤϤɬפʤȤʤǥХϡ٤ƥåȥ󤷤űȤ褤Ǿ̵ȤWi-Fiͳ³ǽʤȤ˵դΤʤ顢³ˤɬΤƤ롣ºݤˤϥ饤ǽޤäȤʤȤ˵դΤʤ顢ǥХͥåȥڤΥ뤳ȡ

ɤΥ᡼ǥХ㤦ꤹݤˡƥץ饤ХˤĤƥ᡼ƤƤ䡢ץ饤Х§ˤĤƳǧ뤳ȡޤʤԾơƥ̤Ǥʤˤȴ򤷤Ƥʤ¤ȼԤʤΥǡưȤƤϲ˥ǡäƤʤǡΰǤǼƤʤơɤ˳ǼΤ

Τ˥ۡ롼ǧ뤳ȡ󥿡ͥåȤˡĤޤWAN󥿡եˤ餵Ƥ륵ӥˤĤƤϡ̵ˤʤäƤɬפ롣ѥѥɤ϶ϤǸͭʤΤѹʤФʤʤ롼DNS꤬ISPDNSФOpenDNSGoogle DNSΤ褦ʥץʥӥ˸Ƥꡢ󤬤ƤʤȤǧ롣

롼Υե०ǿݤġä¤ȼԤϤ䥻ƥԤʤΤǤС롼򿷤Τ֤뤳ȤƤ롣ƥåץǡȤԤʤäꡢ2ǯ˥åץǡȤ褦¤ȼԤϼȤͤ롣ۡͥåȥΥƥϥ롼Ϥޤꡢ롼ϥ󥿡ͥåȤ˻ƤΤ


嵭ιưꥹȤϹϰϤ˵ڤǤꡢмŪ⤷ʤWebʤΥ󥺡ˤϹѤŽפ褦ˡIoTؤ뤲ˡɤäΤȤԤСʬΥƥȥץ饤ХݤƤ뤫ȤǥϤIoTΥƥϤλѤʤƥѥåŬѤפʥӥߤ뤳ȤƱ͡ѥɤIoTǤϤȤƤפǤ롣

ޥ륦ԡե奢˴ƻ뤵ƥۥդǺޤʡ

 δ֡桹ޥ륦ԤåΥꥹΤ餷Ȥ˵ŤåΥꥹ϶ʤΤ桹Ϥξ򿵽Ť˥˥󥰤ΥꥹФ뤢ζ̣뤤Ϸɰդ򼨤ޥ륦򤤤ĤĤ

 桹ϹͤϤ᤿桹Υȥ᡼󤬥åΥꥹФڤõȤǥޥ륦򸡽Ф뤳ȤǤʤ顢桹¾˲򤹤뤳ȤǤƲ桹ϵŤǥӥåɡϥåۥդؤθڤõɬפ롢ȡ褯ͤ

The Hoff t-shirt
Picture (C) F-Secure Corporation

 Τˡ֥ۥաפ˸ڤޥ륦¸ߤ롣

 ⡼ȴTrojanRATˤǡ饤ȤȥХåɥʤBackdoor:W32/IndSocket.A (a7de748dc32a8edda9e81a201e2a83da8f60bd42)פϾ㳲εԥ塼ǡԤΤȤ򤹤Τǽˤ롣ŵŪʤΤϡץμ¹ԡȥΥ󥰡桼Windowsǥȥåפɻѹʤɤ⤢롣ԤϡɤɻȤ٤ʤΤԤ⡼TrojanȥѥͥǡDavid Hasselhoff Atachסʸʸޥޡ˥ܥ򥯥åȡɻ椬ưŪˡάŪ2ɤλҸۤ줿֥ʥȥ饤פͭ̾ʲѤ롣

indsocket options
Picture (C) F-Secure Corporation

 äơʤȤɻ֥ۥաפμ̿ѤƤʤʤ顢ʬե奢Ρ֥󥿡ͥå ƥפˤϡAnti-Hassle Hoff Technology(TM)פܤƤ뤳ȤΤС桹Υޤϰ¿˰㤤ʤ

饦ɥ١Υƥݤ

 饦ɥ١Υ륹塼ͭ륹Ԥȿ⤷褦ȤƤ뤳Ȥ顢줬ʬ롣

 Backdoor:W32/Bohu.AפˤĤƽ񤫤줿[1] [2] 롣ɤε⡢Ф򤱤뤿2εѤƤ뤳ȤŦƤ롣ʤ

  1. եκǸפʥǡɲä

  2. 륹٥ФؤΥɻߤ

 ϿѤǤϤʤƥबBohu˴Ƥ硢ĤΥ륹٥ΥФФ륢֥åȤΤ饦ɥ١Υ塼ΤߤǤϤʤΥ륹ΥåץǡȤɻߤ褦ȤơޤǺƻޤäƱͤι⤬ԤƤ

 桹ϡȤޥ륦Ū˼⤷褦Ȥ⡢饤Ȥؤ³ݤƤƥΥ߽ФȡϤ³Ƥ롣

Screenshot (46k image)
: Backdoor:W32/Bohu.AפǥȤƥ󥹥ȡ뤹ǥץ쥤䡼Υ꡼󥷥å

 եκǸ˥׾񤭹ळȤϡեϥåѹ뤳Ȥˤۤʤ餺椨եϥå˴ŤФ򤵤뤳Ȥˤʤ롣ϡ饦ɥ١ΥƥͭǤϤʤȤ̣ǤϤʤǿΥƥʤϡեϥåΤߤ˴Ť٤ǤϤʤȤȤʤΤ

 ºݡμβᥫ˥ϡޥ륦¦ˤʤ롣ȤСե奢 ǥץ 3פϡץꥱʤɤΥԥơ˴ŤƤ롣֥ǥץɡפˤޤʲ򸡽ФСϡԿפʤΤȤߤʤ롣Τ֥ǥץɤϡ״Ūˡ˥׾ɲä줿ե򸡽Ф뤳ȤǤ롣줬ספʾǤ뤿

 ƥʤȰԤδ֤Τ᤮礤³Ƥ롣.

AMTSOɥ饤

 ե奢Ƥ롢ޥ륦кʤΥƥɸಽΡAnti-Malware Testing Standards OrganizationAMTSOˡפ5˥إ륷󥭤DzԤäƱǡAMTSOС2Ĥοʥɥ饤ȯɽǧ

AMTSO logo

 1οɥ饤ϡWhole Product TestingפWhole Product TestingפƳ˽פŸϴŪˡʤεǽ򤽤줾ƥȤơ餽ʤ󶡤븽¤ΥץƥʡSum-of-Parts TestingסˤΤǤϤʤ¤ζҤФΤƥȤ뤳Ȥ̣Ƥ롣Whole Product TestingפϡƥȤ긽¤˶Ť뤳Ȥǡƥեȥγȯ򡢥桼˿פͿؤƳΤ

 ե奢¿ɸζǤʿԤǤꡢΤ褦ʡWhole Productץץ򴿷ޤƤ롣ƥʤʬΥ桼ϡʬãΥƥȤΤɤεǽʬãݸƤ뤫ȤȤˤĤƤϡƤ¤ϡޤ굤ˤƤʤե奢ʤǤϡؤΥץƥƤ뤷¾ҤƱͤġΥ쥤̤ɾ뤳Ȥϡʤ󶡤ץƥ󡦥٥ɾ뤿ΡˡȤϸʤ

 News from the LabɼԤγʤ餴¸Τ̤ꡢWebϺʥСδ٥ŵŪʴΥʥꥪϡSEOʥ󥸥Ŭ˥ݥ˥󥰤ȺԤGoogle򤢤भ桼ȤСߤνʤɤθԤäݡʬãΥȤ򸡺̤ξ̤ɽΤΤ褦ʥʥꥪǤϡե奢3ؤɸ֤Ƥʲ򻲾ȡˡ

Defense in Depth

 Τ褦ʶҤФץƥƥȤ뤿ΡWhole ProductץץϡʲΤ褦˹Ԥ롧

   1) ɥ饤֥ХɡץȤޤϥޥ륦˥󥯤URLѰդ

   2) ̥桼ϤơURL򥦥֥֡饦DZ

   3) 뤫å롣Υޥ륦ϥƥ˴


 AMTSOμ׸§ΰĤˡ֥ƥȤˤ餷ƤϤʤʤפȤΤ롣äơ嵭Τ褦ʥƥȤԤƥϡɬפͽ֡ʤȤмʬΥͥåȥեʤ볰ƥޥ륦ˤ깶ʤ褦ˤʤɡˤȤͤФʤʤ

 2οɥ饤ϡѥեޥ󥹡ƥȤ˴ؤΤϥ󡦥ԡɤȥ꥽λѤ˴ؤƿƤ롣Whole Product Performance Testingפ˴ؤΤǤϤʤᡢѥեޥ󥹤θġ¦̤ˤեƤ롣ϥƥʤΥѥեޥ̤ɤΤ褦ɾ뤫ˤĤʥɥХ󶡤롣äˡΥѥեޥ󥹡ƥȤλѻФǤ٤Ǥ뤳ȤĴƤ롣ȤСե򥹥󤹤뤳Ȥǡ󡦥ԡɤƥȤΤ̣ʤʤΤʤС̥桼󤹤ۤȤɤΥեϥ꡼ޤۡࡦ桼ƥȤǤϡԥ塼ǥץ졼ǤΥѥեޥ󥹸̤˥ե뤫⤷ʤȤΥե롦Ф˥եƥȤǤϡǥޥɤΥ󡦥ѥեޥ󥹤ˤ꽸椹뤳Ȥˤʤ뤫⤷ʤΤ

ХåʥС
ǥطԤγͤ
ե奢֥С
ե奢֥С
ߥåҥåݥͥ
ե奢 CROʥƥʸˡʥإ륷󥭡
(Twitter)
(Twitter)
硼󡦥Х
ե奢 ƥɥХʥإ륷󥭡
(Twitter)
ŵ
᥿ɽ
(֥)
(Twitter)
߷ ͵
ҥ奢֥쥤 ǹ⵻Ǥ
(֥)
(ʪҲ)
ǥ ȡޥ ꥹӥ (2013ǯ3 ҥå) 󥻥ƥرءҰ
(Twitter)

(ʪҲ)
ʡ
ҥСǥե󥹸 ʬϴ
CDI-CIRTС
(ʪҲ)
͵
FFRI ɽĹ
(ʪҲ)
ʡܡ
ŷ

OWASP Japan
ɥХ꡼ܡ
Rakuten-CERT representative
(ʪҲ)
ե奢 ץȥ롼 Ĺ
ٰ β
ե奢 ץȥ롼
ݥ졼ȥ륹
ե奢
(ե奢֥Twitter)


ҥ᡼ɡ
ե奢᡼ޥ

֥˺ܤʤޥ䡢Ѽԥ󥿥ӥ塼ʾ󡢵ѲǺܤۿޤɥ쥹ΤߤϿǹ̵

ե奢֥ѣҥ
QR