ãããã®å¿ é ã»ãã¥ãªãã£æŠç¥ã§ã¢ãã€ã«ã¢ããªãä¿è·ããŸããè åšã¢ããªã³ã°ãã»ãã¥ã¢ã³ãŒãã£ã³ã°ããã¹ãçãåŠã³ããŠãŒã¶ãŒãšããŒã¿ãå®ãæ¹æ³ã解説ã
ã¢ãã€ã«ã»ãã¥ãªãã£ïŒã¢ããªä¿è·ã®ããã®ç·åã¬ã€ã
仿¥ã®ããžã¿ã«ç°å¢ã«ãããŠãã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã¯è³ãæã«ååšããå人ãšä»äºã®äž¡é¢ã§éèŠãªåœ¹å²ãæãããŠããŸãããã®åºç¯ãªæ®åã«ãããã¢ãã€ã«ã¢ããªã¯ãµã€ããŒæ»æã®äž»èŠãªæšçãšãªã£ãŠããŸãããããã®ã¢ããªã±ãŒã·ã§ã³ãä¿è·ããããšã¯ããŠãŒã¶ãŒããŒã¿ã®ä¿è·ããã©ã³ãã®è©å€ã®ç¶æããããŠäºæ¥ç¶ç¶æ§ã®ç¢ºä¿ã®ããã«æãéèŠã§ãããã®ç·åã¬ã€ãã§ã¯ãã¢ãã€ã«ã¢ããªã»ãã¥ãªãã£ã®å€é¢çãªåŽé¢ãæ¢ããäžçäžã®éçºè ãã»ãã¥ãªãã£å°éå®¶ãçµç¹ã«å®çšçãªæŽå¯ãšãã¹ããã©ã¯ãã£ã¹ãæäŸããŸãã
ã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿããè åšã®å¢å€§
ã¢ãã€ã«ã®è åšã©ã³ãã¹ã±ãŒãã¯çµ¶ããé²åããŠãããæ»æè ã¯ã¢ãã€ã«ã¢ããªã®è匱æ§ãæªçšããããã«ãŸããŸãé«åºŠãªæè¡ãçšããŠããŸããæãäžè¬çãªè åšã«ã¯ä»¥äžã®ãããªãã®ããããŸãïŒ
- ããŒã¿äŸµå®³ïŒå人æ å ±ãè²¡åæ å ±ãèªèšŒæ å ±ãªã©ã®æ©å¯æ§ã®é«ããŠãŒã¶ãŒããŒã¿ãžã®äžæ£ã¢ã¯ã»ã¹ãäŸãã°ãã¢ããªããŒã¿ã®ã¯ã©ãŠãã¹ãã¬ãŒãžã®ã»ãã¥ãªãã£ãäžååãªå ŽåãäœçŸäžãã®ãŠãŒã¶ãŒèšé²ãæŒæŽ©ããå¯èœæ§ããããŸãã
- ãã«ãŠã§ã¢ïŒæ£èŠã®ã¢ããªãè£ ã£ãæªæã®ãããœãããŠã§ã¢ã§ãããŒã¿ã®çªåãæ©èœã®åŠšå®³ããŸãã¯ããã€ã¹ã®å¶åŸ¡ãç®çãšããŠããŸããäŸãšããŠã¯ããã°ã€ã³æ å ±ãçããã³ãã³ã°åããã€ã®æšéЬãããŠãŒã¶ãŒã®æŽ»åãç£èŠããã¹ãã€ãŠã§ã¢ãªã©ããããŸãã
- ãªããŒã¹ãšã³ãžãã¢ãªã³ã°ïŒã¢ããªã®ã³ãŒããéã³ã³ãã€ã«ã»åæããŠãè匱æ§ãããžãã¯ã®æ¬ é¥ãAPIããŒãæå·åããŒãªã©ã®æ©å¯æ å ±ãçºèŠããããšã
- ã³ãŒãã€ã³ãžã§ã¯ã·ã§ã³ïŒã¢ããªã®ã³ãŒãã®è匱æ§ãæªçšããŠãä»»æã®ã³ãã³ããå®è¡ãããã·ã¹ãã ã䟵害ãããã§ããæªæã®ããã³ãŒããæ³šå ¥ããããšã
- ãã£ãã·ã³ã°ïŒæ£èŠã®ã¢ããªéç¥ãæš¡å£ããåœã®ãã°ã€ã³ããŒãžãã¡ãŒã«ãSMSã¡ãã»ãŒãžãéããŠããŠãŒã¶ãŒãéšããŠæ©å¯æ å ±ãæŒæŽ©ãããããšã
- äžéè ïŒMitMïŒæ»æïŒã¢ããªãšãµãŒããŒéã®éä¿¡ãååããŠãããŒã¿ãçãã ãæªæã®ããã³ãŒããæ³šå ¥ãããããããšãããã¯ç¹ã«å®å šã§ãªãWi-Fiãããã¯ãŒã¯ã§å€çºããŸãã
- äžé©åãªæå·åïŒæ»æè ã«ãã£ãŠå®¹æã«åé¿ãããå¯èœæ§ã®ãããè匱ãŸãã¯äžé©åã«å®è£ ãããæå·åã
- äžååãªèªå¯/èªèšŒïŒã¢ããªã®èªèšŒããã³èªå¯ã¡ã«ããºã ã®æ¬ é¥ã«ãããäžæ£ãªãŠãŒã¶ãŒãæ©å¯ããŒã¿ãæ©èœã«ã¢ã¯ã»ã¹ã§ããŠããŸãããšã
ãããã®è åšã¯ããŠãŒã¶ãŒãšçµç¹ã®åæ¹ã«ãééçæå€±ãè©å€ã®æ¯æãæ³ç責任ãä¿¡é Œã®åªå€±ãªã©ãæ·±å»ãªçµæãããããå¯èœæ§ããããŸãã
ããã¢ã¯ãã£ããªã»ãã¥ãªãã£ã¢ãããŒãã®éèŠæ§
ã¢ãã€ã«è åšã®é«åºŠåãé²ãäžãã¢ããªéçºã©ã€ããµã€ã¯ã«ïŒSDLCïŒå šäœãéããŠã»ãã¥ãªãã£äžã®æžå¿µã«å¯ŸåŠãããããã¢ã¯ãã£ããªã»ãã¥ãªãã£ã¢ãããŒããæ¡çšããããšã極ããŠéèŠã§ãããã®ã¢ãããŒãã§ã¯ãåæèšèšããå±éãä¿å®ã«è³ããŸã§ãéçºã®ããããæ®µéã«ã»ãã¥ãªãã£ãçµ±åããŸãã
ããã¢ã¯ãã£ããªã»ãã¥ãªãã£ã¢ãããŒãã«ã¯ä»¥äžãå«ãŸããŸãïŒ
- è åšã¢ããªã³ã°ïŒéçºããã»ã¹ã®æ©ã段éã§æœåšçãªè åšãšè匱æ§ãç¹å®ããããšã
- ã»ãã¥ã¢ã³ãŒãã£ã³ã°ãã©ã¯ãã£ã¹ïŒã€ã³ãžã§ã¯ã·ã§ã³ã®æ¬ é¥ãã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ïŒXSSïŒããããã¡ãªãŒããŒãããŒãªã©ã®äžè¬çãªè匱æ§ãé²ãããã®ã»ãã¥ã¢ãªã³ãŒãã£ã³ã°æè¡ãå®è£ ããããšã
- éçããã³åçè§£æïŒèªååããŒã«ã䜿çšããŠãéçºäžïŒéçè§£æïŒãšå®è¡æïŒåçè§£æïŒã®äž¡æ¹ã§ã¢ããªã®ã³ãŒãã«æœåšçãªè匱æ§ããªããåæããããšã
- ãããã¬ãŒã·ã§ã³ãã¹ãïŒå®éã®æ»æãã·ãã¥ã¬ãŒãããŠãèªååããŒã«ã§ã¯èŠéãããå¯èœæ§ã®ããè匱æ§ãç¹å®ããããšã
- ã»ãã¥ãªãã£æèåäžãã¬ãŒãã³ã°ïŒéçºè ãä»ã®é¢ä¿è ã«ã¢ãã€ã«ã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ã«ã€ããŠæè²ããããšã
- ç¶ç¶çãªç£èŠïŒäžå¯©ãªæ¯ãèãããªããã¢ããªã®ã¢ã¯ãã£ããã£ãç£èŠããã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«è¿ éã«å¯Ÿå¿ããããšã
ã¢ãã€ã«ã¢ããªä¿è·ã®ããã®äž»èŠæŠç¥
ã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ãä¿è·ããããã®äž»èŠãªæŠç¥ãããã€ã玹ä»ããŸãïŒ
1. è åšã¢ããªã³ã°
è åšã¢ããªã³ã°ã¯ãã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ãä¿è·ããããã®éèŠãªæåã®ã¹ãããã§ããéçºããã»ã¹ã®æ©ã段éã§æœåšçãªè åšãè匱æ§ãç¹å®ããéçºè ãããã¢ã¯ãã£ãã«å¯ŸåŠã§ããããã«ããŸããSTRIDEïŒãªãããŸããæ¹ãããåŠèªãæ å ±æŒæŽ©ããµãŒãã¹æåŠãæš©éææ ŒïŒãPASTAïŒProcess for Attack Simulation and Threat AnalysisïŒãªã©ã®ãã¬ãŒã ã¯ãŒã¯ã®äœ¿çšãæ€èšããŠãã ããã
äŸïŒã¢ãã€ã«ãã³ãã³ã°ã¢ããªãéçºããŠãããšããŸããè åšã¢ãã«ã§ã¯ã次ã®ãããªè åšãèæ ®ããŸãïŒ
- ãªãããŸãïŒæ»æè ãåœã®ãã³ãã³ã°ã¢ããªãäœæãããŠãŒã¶ãŒã®èªèšŒæ å ±ãçãã
- æ¹ããïŒæ»æè ãã¢ããªã®ã³ãŒããä¿®æ£ããèªåã®å£åº§ã«è³éãééããã
- æ å ±æŒæŽ©ïŒæ»æè ããŠãŒã¶ãŒã®å£åº§æ®é«ãååŒå±¥æŽã«ã¢ã¯ã»ã¹ããã
ãããã®è åšãç¹å®ããããšã§ãéçºè ã¯ãªã¹ã¯ã軜æžããããã®é©åãªã»ãã¥ãªãã£å¯Ÿçãå®è£ ã§ããŸãã
2. ã»ãã¥ã¢ã³ãŒãã£ã³ã°ãã©ã¯ãã£ã¹
ã»ãã¥ã¢ã³ãŒãã£ã³ã°ãã©ã¯ãã£ã¹ã¯ãã¢ãã€ã«ã¢ããªã®äžè¬çãªè匱æ§ãé²ãããã«äžå¯æ¬ ã§ããããã«ã¯ä»¥äžãå«ãŸããŸãïŒ
- å ¥åæ€èšŒïŒã€ã³ãžã§ã¯ã·ã§ã³æ»æãé²ããããåžžã«ãŠãŒã¶ãŒå ¥åãæ€èšŒãããããã«ã¯ãããŒã¿ã®çš®é¡ã圢åŒãé·ãã®æ€èšŒãå«ãŸããŸãã
- åºåãšã³ã³ãŒãã£ã³ã°ïŒXSSæ»æãé²ãããã«åºåããŒã¿ããšã³ã³ãŒãããã
- ããŒã¿ãµãã¿ã€ãºïŒæœåšçã«æå®³ãªæåãã³ãŒããåé€ããããã«ããŒã¿ããµãã¿ã€ãºããã
- ãšã©ãŒãã³ããªã³ã°ïŒæ å ±æŒæŽ©ããµãŒãã¹æåŠæ»æãé²ãããã«å ç¢ãªãšã©ãŒãã³ããªã³ã°ãå®è£ ããããšã©ãŒã¡ãã»ãŒãžã«æ©å¯æ å ±ã衚瀺ããªãããã«ããã
- ã»ãã¥ã¢ãªããŒã¿ã¹ãã¬ãŒãžïŒæå·åãšé©åãªã¢ã¯ã»ã¹å¶åŸ¡ãçšããŠæ©å¯ããŒã¿ãå®å šã«ä¿ç®¡ãããiOSã®KeychainãAndroidã®Keystoreã®ãããªãã©ãããã©ãŒã åºæã®ã»ãã¥ã¢ãªã¹ãã¬ãŒãžã¡ã«ããºã ã®äœ¿çšãæ€èšããã
- æå°æš©éã®ååïŒãŠãŒã¶ãŒãšã¢ããªã±ãŒã·ã§ã³ã«ã¯ãã¿ã¹ã¯ãå®è¡ããããã«å¿ èŠãªæš©éã®ã¿ãä»äžããã
- 宿çãªã¢ããããŒãïŒæ¢ç¥ã®è匱æ§ã«ããããé©çšãããããã¢ããªãšãã®äŸåé¢ä¿ãææ°ã®ç¶æ ã«ä¿ã€ã
äŸïŒãã¹ã¯ãŒããã£ãŒã«ãã®ãŠãŒã¶ãŒå ¥åãåŠçããéã¯ãåžžã«ãã¹ã¯ãŒãã®è€éããšé·ããæ€èšŒããŸããbcryptãArgon2ã®ãããªåŒ·åãªããã·ã¥ã¢ã«ãŽãªãºã ã䜿çšããŠãã¹ã¯ãŒããå®å šã«ä¿åããŸãã
3. èªèšŒãšèªå¯
å ç¢ãªèªèšŒããã³èªå¯ã¡ã«ããºã ã¯ããŠãŒã¶ãŒã¢ã«ãŠã³ããšæ©å¯ããŒã¿ãä¿è·ããããã«äžå¯æ¬ ã§ãã以äžã®ãã¹ããã©ã¯ãã£ã¹ã®å®è£ ãæ€èšããŠãã ããïŒ
- å€èŠçŽ èªèšŒïŒMFAïŒïŒã»ãã¥ãªãã£ã匷åããããã«ããŠãŒã¶ãŒã«ãã¹ã¯ãŒããšã¯ã³ã¿ã€ã ã³ãŒããªã©ãè€æ°ã®èªèšŒåœ¢åŒã®æäŸãèŠæ±ããã
- 匷åãªãã¹ã¯ãŒãããªã·ãŒïŒãŠãŒã¶ãŒã«è€éãªãã¹ã¯ãŒãã®äœæãšå®æçãªå€æŽãèŠæ±ãã匷åãªãã¹ã¯ãŒãããªã·ãŒãé©çšããã
- ã»ãã¥ã¢ãªã»ãã·ã§ã³ç®¡çïŒã»ãã·ã§ã³ãã€ãžã£ãã¯ãäžæ£ã¢ã¯ã»ã¹ãé²ãããã«ãã»ãã¥ã¢ãªã»ãã·ã§ã³ç®¡çæè¡ãå®è£ ãããçãã»ãã·ã§ã³ã¿ã€ã ã¢ãŠãã䜿çšããèªèšŒåŸã«ã»ãã·ã§ã³IDãåçæããã
- OAuth 2.0 ãš OpenID ConnectïŒèªå¯ãšèªèšŒãå®å šã«å§ä»»ããããã«ãOAuth 2.0ãOpenID Connectã®ãããªæ¥çæšæºã®èªèšŒãããã³ã«ã䜿çšããã
- é©åãªèªå¯ãã§ãã¯ïŒãŠãŒã¶ãŒãèªå¯ããããªãœãŒã¹ãšæ©èœã«ã®ã¿ã¢ã¯ã»ã¹ã§ããããã«ãé©åãªèªå¯ãã§ãã¯ãå®è£ ããã
äŸïŒãœãŒã·ã£ã«ã¡ãã£ã¢ã¢ããªã§ã¯ãOAuth 2.0ã䜿çšããŠããŠãŒã¶ãŒãFacebookãGoogleãªã©ã®ãã©ãããã©ãŒã äžã®æ¢åã®ã¢ã«ãŠã³ãã§ãã°ã€ã³ã§ããããã«ããŸãããã现ããªèªå¯å¶åŸ¡ãå®è£ ããŠããŠãŒã¶ãŒãèªåã®æçš¿ããããã£ãŒã«ã«ã®ã¿ã¢ã¯ã»ã¹ã§ããããã«ããŸãã
4. ããŒã¿ä¿è·
æ©å¯ããŒã¿ã®ä¿è·ã¯ãã¢ãã€ã«ã¢ããªã®ã»ãã¥ãªãã£ã«ãããŠæãéèŠã§ãããŠãŒã¶ãŒããŒã¿ãä¿è·ããããã«ã以äžã®å¯Ÿçãå®è£ ããŠãã ããïŒ
- æå·åïŒåŒ·åãªæå·åã¢ã«ãŽãªãºã ã䜿çšããŠãä¿ç®¡äžããã³è»¢éäžã®æ©å¯ããŒã¿ãæå·åããããã¹ãŠã®ãããã¯ãŒã¯éä¿¡ã«HTTPSã䜿çšããã
- ããŒã¿ãã¹ãã³ã°ïŒã¯ã¬ãžããã«ãŒãçªå·ã瀟äŒä¿éçªå·ãªã©ã®æ©å¯ããŒã¿ããã¹ãã³ã°ããŠãäžæ£ã¢ã¯ã»ã¹ãé²ãã
- ããŒã¿æå°åïŒã¢ããªãæ©èœããããã«å¿ èŠãªããŒã¿ã®ã¿ãåéããã
- ã»ãã¥ã¢ãªããŒã¿ã¹ãã¬ãŒãžïŒiOSã®KeychainãAndroidã®Keystoreã®ãããªãã©ãããã©ãŒã åºæã®ã»ãã¥ã¢ãªã¹ãã¬ãŒãžã¡ã«ããºã ã䜿çšããŠãæ©å¯ããŒã¿ãå®å šã«ä¿ç®¡ããããããã®ã¹ãã¬ãŒãžã¡ã«ããºã ã匷åãªãã¹ã¯ãŒããçäœèªèšŒã§ä¿è·ããã
- ããŒã¿æå€±é²æ¢ïŒDLPïŒïŒæ©å¯ããŒã¿ãèš±å¯ãªãããã€ã¹ããããã¯ãŒã¯ããåºãã®ãé²ãããã«DLP察çãå®è£ ããã
äŸïŒå»çã¢ããªã§ã¯ãAES-256æå·åã䜿çšããŠãä¿ç®¡äžã®æ£è ã®å»çèšé²ãæå·åããŸããã¢ããªãšãµãŒããŒéã®ãã¹ãŠã®éä¿¡ãæå·åããããã«HTTPSã䜿çšããŸããã¢ã¯ã»ã¹æš©ãå¶éãããŠãããŠãŒã¶ãŒã«ããŒã¿ã衚瀺ããéã«æ£è èå¥åãä¿è·ããããã«ãããŒã¿ãã¹ãã³ã°ãå®è£ ããŸãã
5. ãããã¯ãŒã¯ã»ãã¥ãªãã£
ãããã¯ãŒã¯éä¿¡ã®ä¿è·ã¯ãã¢ãã€ã«ã¢ããªãäžéè æ»æãããŒã¿äŸµå®³ããå®ãããã«äžå¯æ¬ ã§ãã以äžã®ãã¹ããã©ã¯ãã£ã¹ãæ€èšããŠãã ããïŒ
- HTTPSïŒè»¢éäžã®ããŒã¿ãæå·åããããã«ããã¹ãŠã®ãããã¯ãŒã¯éä¿¡ã«HTTPSã䜿çšãããä¿¡é Œã§ããèªèšŒå±ããã®æå¹ãªSSL/TLSèšŒææžã䜿çšããŠããããšã確èªããã
- èšŒææžããã³ã°ïŒãµãŒããŒã®SSL/TLSèšŒææžãæ¢ç¥ã®è¯å¥œãªèšŒææžãšç §åããããšã«ãããäžéè æ»æãé²ãããã«èšŒææžããã³ã°ãå®è£ ããã
- ã»ãã¥ã¢ãªAPIïŒèªèšŒããã³èªå¯ã¡ã«ããºã ã«ãã£ãŠä¿è·ãããã»ãã¥ã¢ãªAPIã䜿çšãããã€ã³ãžã§ã¯ã·ã§ã³æ»æãé²ãããã«ããã¹ãŠã®å ¥åããŒã¿ãæ€èšŒããã
- VPNïŒå ¬å ±ã®Wi-Fiãããã¯ãŒã¯ã«æ¥ç¶ããéã¯ãVPNã®äœ¿çšããŠãŒã¶ãŒã«å¥šå±ããã
- ãããã¯ãŒã¯ç£èŠïŒäžå¯©ãªã¢ã¯ãã£ããã£ããªãããããã¯ãŒã¯ãã©ãã£ãã¯ãç£èŠããã
äŸïŒeã³ããŒã¹ã¢ããªã§ã¯ãã¢ããªã𿝿ãã²ãŒããŠã§ã€éã®ãã¹ãŠã®éä¿¡ãæå·åããããã«HTTPSã䜿çšããŸããæ»æè ãæ¯æãæ å ±ãååããã®ãé²ãããã«ãèšŒææžããã³ã°ãå®è£ ããŸãã
6. ãªããŒã¹ãšã³ãžãã¢ãªã³ã°å¯Ÿç
ãªããŒã¹ãšã³ãžãã¢ãªã³ã°ããã¢ããªãä¿è·ããããšã¯ãæ»æè ãè匱æ§ãçºèŠãããæ©å¯æ å ±ãçãã ãããã®ãé²ãããã«äžå¯æ¬ ã§ãã以äžã®æè¡ãæ€èšããŠãã ããïŒ
- ã³ãŒãé£èªåïŒã¢ããªã®ã³ãŒããé£èªåããŠãçè§£ããªããŒã¹ãšã³ãžãã¢ãªã³ã°ãããå°é£ã«ããã
- ã¢ã³ããããã°æè¡ïŒæ»æè ãã¢ããªããããã°ããã®ãé²ãããã«ãã¢ã³ããããã°æè¡ãå®è£ ããã
- ã«ãŒãå/ãžã§ã€ã«ãã¬ã€ã¯æ€åºïŒã¢ããªãã«ãŒãåãŸãã¯ãžã§ã€ã«ãã¬ã€ã¯ãããããã€ã¹ã§å®è¡ãããŠãããã©ãããæ€åºããã¢ããªã®çµäºãç¹å®æ©èœã®ç¡å¹åãªã©ãé©åãªæªçœ®ãè¬ããã
- å®å šæ§ãã§ãã¯ïŒã¢ããªãæ¹ãããããŠããªãããšã確èªããããã«ãå®å šæ§ãã§ãã¯ãå®è£ ããã
äŸïŒã³ãŒãé£èªåã䜿çšããŠãã¯ã©ã¹ãã¡ãœããã倿°ãç¡æå³ãªååã«å€æŽããŸããã«ãŒãå/ãžã§ã€ã«ãã¬ã€ã¯æ€åºãå®è£ ããŠã䟵害ãããããã€ã¹ã§ã¢ããªãå®è¡ãããã®ãé²ããŸãããªããŒã¹ãšã³ãžãã¢ãªã³ã°ããŒã«ã®äžæ©å ãè¡ãããã«ãé£èªåæè¡ã宿çã«æŽæ°ããŸãã
7. ã¢ãã€ã«ã¢ããªãã¹ã
培åºçãªãã¹ãã¯ãã¢ãã€ã«ã¢ããªã®è匱æ§ãç¹å®ãã察åŠããããã«äžå¯æ¬ ã§ãã以äžã®çš®é¡ã®ãã¹ãã宿œããŠãã ããïŒ
- éçè§£æïŒèªååããŒã«ã䜿çšããŠããããã¡ãªãŒããŒãããŒãã€ã³ãžã§ã¯ã·ã§ã³ã®æ¬ é¥ãå®å šã§ãªãããŒã¿ã¹ãã¬ãŒãžãªã©ã®æœåšçãªè匱æ§ã«ã€ããŠã¢ããªã®ã³ãŒããåæããã
- åçè§£æïŒåçè§£æããŒã«ã䜿çšããŠãå®è¡æã®ã¢ããªã®åäœãç£èŠããã¡ã¢ãªãªãŒã¯ãã¯ã©ãã·ã¥ãå®å šã§ãªããããã¯ãŒã¯éä¿¡ãªã©ã®è匱æ§ãç¹å®ããã
- ãããã¬ãŒã·ã§ã³ãã¹ãïŒå®éã®æ»æãã·ãã¥ã¬ãŒãããŠãèªååããŒã«ã§ã¯èŠéãããå¯èœæ§ã®ããè匱æ§ãç¹å®ããã
- ãŠãŒã¶ããªãã£ãã¹ãïŒã¢ããªããŠãŒã¶ãŒãã¬ã³ããªãŒã§å®å šã§ããããšã確èªããããã«ããŠãŒã¶ããªãã£ãã¹ãã宿œããã
- ã»ãã¥ãªãã£ãªã°ã¬ãã·ã§ã³ãã¹ãïŒè匱æ§ãä¿®æ£ããåŸãä¿®æ£ã«ãã£ãŠæ°ããªè匱æ§ãå°å ¥ãããŠããªãããšã確èªããããã«ãã»ãã¥ãªãã£ãªã°ã¬ãã·ã§ã³ãã¹ãã宿œããã
äŸïŒSonarQubeã®ãããªéçè§£æããŒã«ã䜿çšããŠãæœåšçãªã³ãŒãã®è匱æ§ãç¹å®ããŸããSQLã€ã³ãžã§ã¯ã·ã§ã³ãXSSã®ãããªæ»æãã·ãã¥ã¬ãŒãããããã«ãããã¬ãŒã·ã§ã³ãã¹ãã宿œããŸããã¢ããªãã»ãã¥ãªãã£åºæºãæºãããŠããããšã確èªããããã«ã宿çãªã»ãã¥ãªãã£ç£æ»ã宿œããŸãã
8. ç£èŠãšãã®ã³ã°
ç¶ç¶çãªç£èŠãšãã®ã³ã°ã¯ãã»ãã¥ãªãã£ã€ã³ã·ãã³ããæ€åºã察å¿ããããã«äžå¯æ¬ ã§ãã以äžã®å¯Ÿçãå®è£ ããŠãã ããïŒ
- ãã¹ãŠã®ã»ãã¥ãªãã£é¢é£ã€ãã³ãã®ãã°èšé²ïŒèªèšŒè©Šè¡ãèªå¯å€±æãããŒã¿ã¢ã¯ã»ã¹ãªã©ããã¹ãŠã®ã»ãã¥ãªãã£é¢é£ã€ãã³ãããã°ã«èšé²ããã
- äžå¯©ãªæ¯ãèãã«å¯Ÿããã¢ããªæŽ»åã®ç£èŠïŒç°åžžãªãã°ã€ã³è©Šè¡ã倧éã®ããŒã¿è»¢éãäžæ£ã¢ã¯ã»ã¹è©Šè¡ãªã©ãäžå¯©ãªæ¯ãèãããªããã¢ããªã®æŽ»åãç£èŠããã
- ãªã¢ã«ã¿ã€ã ã¢ã©ãŒãã®å®è£ ïŒæœåšçãªã»ãã¥ãªãã£ã€ã³ã·ãã³ããã»ãã¥ãªãã£æ åœè ã«éç¥ããããã«ããªã¢ã«ã¿ã€ã ã¢ã©ãŒããå®è£ ããã
- ãã°ã®å®æçãªã¬ãã¥ãŒïŒã»ãã¥ãªãã£ã®åŸåãšãã¿ãŒã³ãç¹å®ããããã«ã宿çã«ãã°ãã¬ãã¥ãŒããã
äŸïŒãã¹ãŠã®å€±æãããã°ã€ã³è©Šè¡ãããŠãŒã¶ãŒIDãšIPã¢ãã¬ã¹ãå«ããŠãã°ã«èšé²ããŸããç°åžžãªããŒã¿è»¢éããªãããããã¯ãŒã¯ãã©ãã£ãã¯ãç£èŠããŸããæœåšçãªãã«ãŒããã©ãŒã¹æ»æãã»ãã¥ãªãã£æ åœè ã«éç¥ããããã«ããªã¢ã«ã¿ã€ã ã¢ã©ãŒããå®è£ ããŸãã
9. ã€ã³ã·ãã³ã察å¿
æç¢ºã«å®çŸ©ãããã€ã³ã·ãã³ã察å¿èšç»ãæã€ããšã¯ãã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«å¹æçã«å¯Ÿå¿ããããã«äžå¯æ¬ ã§ããã€ã³ã·ãã³ã察å¿èšç»ã«ã¯ã以äžã®ã¹ããããå«ããã¹ãã§ãïŒ
- ç¹å®ïŒã»ãã¥ãªãã£ã€ã³ã·ãã³ããç¹å®ãããã®åœ±é¿ãè©äŸ¡ããã
- å°ã蟌ãïŒãããªãæå®³ãé²ãããã«ãã»ãã¥ãªãã£ã€ã³ã·ãã³ããå°ã蟌ããã
- æ ¹çµ¶ïŒã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®æ ¹æ¬åå ãæ ¹çµ¶ããã
- 埩æ§ïŒã·ã¹ãã ãéåžžã®éçšç¶æ ã«åŸ©æ§ããã
- æèšïŒã»ãã¥ãªãã£ã€ã³ã·ãã³ãããåŸãããæèšãææžåããã»ãã¥ãªãã£å¯Ÿçã®æ¹åã«åœ¹ç«ãŠãã
äŸïŒããŒã¿äŸµå®³ãæ€åºãããå Žåã圱é¿ãåããã·ã¹ãã ãéé¢ããŠçŽã¡ã«äŸµå®³ãå°ã蟌ããŸããè匱ãªãœãããŠã§ã¢ã«ããããé©çšããŠãäŸµå®³ã®æ ¹æ¬åå ãæ ¹çµ¶ããŸããã·ã¹ãã ãéåžžã®éçšç¶æ ã«åŸ©æ§ãã圱é¿ãåãããŠãŒã¶ãŒã«éç¥ããŸãã
10. ã»ãã¥ãªãã£æèåäžãã¬ãŒãã³ã°
ã»ãã¥ãªãã£æèåäžãã¬ãŒãã³ã°ã¯ãéçºè ãä»ã®é¢ä¿è ã«ã¢ãã€ã«ã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ã«ã€ããŠæè²ããããã«äžå¯æ¬ ã§ãããã¬ãŒãã³ã°ã§ã¯ã次ã®ãããªãããã¯ãã«ããŒãã¹ãã§ãïŒ
- äžè¬çãªã¢ãã€ã«ã®è åšïŒãã«ãŠã§ã¢ããã£ãã·ã³ã°ããªããŒã¹ãšã³ãžãã¢ãªã³ã°ãªã©ã®äžè¬çãªã¢ãã€ã«ã®è åšã«ã€ããŠéçºè ãæè²ããã
- ã»ãã¥ã¢ã³ãŒãã£ã³ã°ãã©ã¯ãã£ã¹ïŒäžè¬çãªè匱æ§ãé²ãããã®ã»ãã¥ã¢ã³ãŒãã£ã³ã°ãã©ã¯ãã£ã¹ãéçºè ã«æããã
- ããŒã¿ä¿è·ã®ãã¹ããã©ã¯ãã£ã¹ïŒæå·åãããŒã¿ãã¹ãã³ã°ãããŒã¿æå°åãªã©ã®ããŒã¿ä¿è·ã®ãã¹ããã©ã¯ãã£ã¹ã«ã€ããŠéçºè ãæè²ããã
- ã€ã³ã·ãã³ãå¯Ÿå¿æé ïŒã»ãã¥ãªãã£ã€ã³ã·ãã³ããžã®å¯Ÿå¿æ¹æ³ã確å®ã«çè§£ãããããã«ãéçºè ã«ã€ã³ã·ãã³ãå¯Ÿå¿æé ã®ãã¬ãŒãã³ã°ãè¡ãã
äŸïŒå®è·µçãªæŒç¿ãå®éã®äºäŸãå«ããéçºè åãã®å®æçãªã»ãã¥ãªãã£æèåäžãã¬ãŒãã³ã°ã宿œããŸããéçºè ã«ã»ãã¥ãªãã£ãªãœãŒã¹ãããŒã«ãžã®ã¢ã¯ã»ã¹ãæäŸããŸãã
ã¢ãã€ã«ã»ãã¥ãªãã£ã®æšæºãšã¬ã€ãã©ã€ã³
ããã€ãã®çµç¹ããçµç¹ãã¢ãã€ã«ã»ãã¥ãªãã£äœå¶ãæ¹åããã®ã«åœ¹ç«ã€ã¢ãã€ã«ã»ãã¥ãªãã£ã®æšæºãšã¬ã€ãã©ã€ã³ãæäŸããŠããŸããæãèåãªæšæºãšã¬ã€ãã©ã€ã³ã«ã¯ã以äžã®ãããªãã®ããããŸãïŒ
- OWASPã¢ãã€ã«ã»ãã¥ãªãã£ãããžã§ã¯ãïŒOWASPã¢ãã€ã«ã»ãã¥ãªãã£ãããžã§ã¯ãã¯ãã¢ãã€ã«ã»ãã¥ãªãã£ãã¹ãã¬ã€ãïŒMSTGïŒãã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£æ€èšŒæšæºïŒMASVSïŒãªã©ãã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ãä¿è·ããããã®å æ¬çãªãªãœãŒã¹ã»ãããæäŸããŠããŸãã
- NISTã¬ã€ãã©ã€ã³ïŒç±³åœåœç«æšæºæè¡ç ç©¶æïŒNISTïŒã¯ãNISTç¹å¥åè¡ç©800-124æ¹èš1ãäŒæ¥ã«ãããã¢ãã€ã«ããã€ã¹ã®ã»ãã¥ãªãã£ç®¡çã®ããã®ã¬ã€ãã©ã€ã³ããªã©ãã¢ãã€ã«ããã€ã¹ãšã¢ããªã±ãŒã·ã§ã³ãä¿è·ããããã®ã¬ã€ãã©ã€ã³ãæäŸããŠããŸãã
- PCI DSSã¢ãã€ã«æ±ºæžåä»ã»ãã¥ãªãã£ã¬ã€ãã©ã€ã³ïŒãã€ã¡ã³ãã«ãŒãæ¥çããŒã¿ã»ãã¥ãªãã£åºæºïŒPCI DSSïŒã¯ãã¢ãã€ã«æ±ºæžã¢ããªã±ãŒã·ã§ã³ãä¿è·ããããã®ã¬ã€ãã©ã€ã³ãæäŸããŠããŸãã
çµè«
ã¢ãã€ã«ã¢ããªã®ã»ãã¥ãªãã£ã¯ãè€éã§é²åãç¶ããåéã§ããããã¢ã¯ãã£ããªã»ãã¥ãªãã£ã¢ãããŒããæ¡çšããäž»èŠãªã»ãã¥ãªãã£æŠç¥ãå®è£ ããææ°ã®è åšãšãã¹ããã©ã¯ãã£ã¹ãåžžã«ææ¡ããããšã§ãçµç¹ã¯ã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ãä¿è·ãããŠãŒã¶ãŒããŒã¿ãå®ãããšãã§ããŸããã»ãã¥ãªãã£ã¯äžåºŠããã®ä¿®æ£ã§ã¯ãªããç¶ç¶çãªããã»ã¹ã§ããããšãå¿ããªãã§ãã ãããç¶ç¶çãªç£èŠã宿çãªãã¹ãããããŠç¶ç¶çãªã»ãã¥ãªãã£æèåäžãã¬ãŒãã³ã°ã¯ã匷åºãªã»ãã¥ãªãã£äœå¶ãç¶æããããã«äžå¯æ¬ ã§ããã¢ãã€ã«æè¡ãé²åãç¶ããã«ã€ããŠãæªæ¥ã®èª²é¡ã«å¯Ÿå¿ããããã«ç§ãã¡ã®ã»ãã¥ãªãã£ãã©ã¯ãã£ã¹ãé²åããªããã°ãªããŸããã