ã¬ãã¡ã³ãã¯ã©ãŠãå©çšã·ã¹ãã ã«ãããã»ãã¥ãªãã£å¯Ÿç(å ±é)
2023/03/27 å ¬é
æ¬æžã¯ã¬ãã¡ã³ãã¯ã©ãŠãã«ããããå©çšã·ã¹ãã åŽã®å¯Ÿå¿ãã¹ãã»ãã¥ãªãã£ãçè§£ããããã®ææžã§ãããæ¬æžã¯åCSPã«å ±éããå 容ã§ãããCSPã«ç¹åããå 容ã¯å¥æžãšãªã£ãŠãããæ¬æžã芪ãšãªãæ§æã®ããã奿žã¯æ¬æžãèªäºåŸã«é²èЧããããšããŸããæ¬æžã§ã¯ã¯ã©ãŠãã«ç±æ¥ããªãäžè¬çãªã»ãã¥ãªãã£å¯Ÿçå šè¬ãç¶²çŸ çã«èšèŒããŠããããã§ã¯ãªãã®ã§æ³šæããããã
ã»ãã¥ãªãã£å šäœå
ã¯ããã«ããªã³ãã¬ãã¹ãšã¯ã©ãŠãã§ã®ã»ãã¥ãªãã£ã®éãã«ã€ããŠçè§£ããå¿
èŠãããã
ãªã³ãã¬ãã¹ã§ã¯å¢çåã»ãã¥ãªãã£ã®èãæ¹ã«åºã¥ããå±éºãªå€éšããå
éšãããã¯ãŒã¯ãžã®äŸµå
¥ãé²åŸ¡ããããšãåæãšããèšèšãäž»æµã§ããã
ããããã¯ã©ãŠãã§ã¯å€éšãšå
éšã®å¢çããããŸãã§ããããªã³ãã¬ãã¹ãšåæ§ã®èãæ¹ã ãã§ã¯äžååã§ããã
ã¯ã©ãŠãã§ã¯ãŒããã©ã¹ãã®èãæ¹ã«åºã¥ããå
šãŠã®ã¢ã¯ã»ã¹ãä¿¡çšããªãããšã§è
åšã鲿¢ããããšãåæãšããã»ãã¥ãªãã£ãšãªããã€ã³ã¿ãŒããããšVPCã®å¢çãªã©ãéèŠãªãã€ã³ãã«é¢ããŠã¯ããªã³ãã¬ãã¹ãšåæ§ã®å¢çåã»ãã¥ãªãã£ã«åºã¥ããã»ãã¥ãªãã£å¯Ÿçã宿œããã
以äžã«ã¬ãã¡ã³ãã¯ã©ãŠãã®ã»ãã¥ãªãã£å šäœåã瀺ãã
å³001ãã¬ãã¡ã³ãã¯ã©ãŠãã®ã»ãã¥ãªãã£å
šäœå
å³ã§ç€ºããããã«ãã¬ãã¡ã³ãã¯ã©ãŠãã«ãããã»ãã¥ãªãã£ã¯ãè²¬ä»»å ±æã¢ãã«ã«ããå©çšã·ã¹ãã ãã¬ãã¡ã³ãã¯ã©ãŠã管ççµç¹ãCSPã®äžçš®é¡ã«è²¬ä»»ç¯å²ãåå²ããããæ¬æžã§ã¯ãã®ãã¡ããåå©çšã·ã¹ãã ãã«ãããã»ãã¥ãªãã£ã«ã€ããŠèšè¿°ãããåå©çšã·ã¹ãã ã®ã»ãã¥ãªãã£ã¯ãäž»ã«ä»¥äžã®äžç¹ã§æ§æãããã
- ã¬ã€ãã«åºã¥ãã·ã¹ãã æ§æãšéçšã§å®çŸããã»ãã¥ãªãã£
- ãã³ãã¬ãŒã/IaCãã¡ã€ã«ã䜿ã£ãŠæ§ç¯ããããšã§å®çŸãããã»ãã¥ãªãã£
- æãåºãæã«èªåçã«èšå®ãããäºé²çã»çºèŠççµ±å¶
ã
è²¬ä»»å ±æã¢ãã«
責任å
±æã¢ãã«ãšã¯ãã¯ã©ãŠããµãŒãã¹ãå©çšããäžã§ãCSPãšå©çšè
ãã»ãã¥ãªãã£ãšã³ã³ãã©ã€ã¢ã³ã¹ã®è²¬ä»»ãè² ãç¯å²ãå®ãããã®ã§ãããäžè¬çã«ã¯ç©çãµãŒããç©çã¹ãã¬ãŒãžããããã¯ãŒã¯ããããŒãžããµãŒãã¹ãªã©ãCSPã®è²¬ä»»ç¯å²ãšãªããOSãããã«ãŠã§ã¢ãCSPãæäŸãããµãŒãã¹ã®èšå®ãã¢ã³ãããŒãžããµãŒãã¹äžã®ããŒã¿ãªã©ãå©çšè
ã®è²¬ä»»ç¯å²ãšãªãããã ããå
Œ
±åéã®ã·ã¹ãã ã«ãããŠã¯å®éã®è²¬ä»»ã®æç¡ã«é¢ãããã説æè²¬ä»»ãåãããå Žåãããããšãæ³å®ããŠãããããã
以äžã«è²¬ä»»ç¯å²ã®äŸãšãªãå³ã瀺ãã
å³002ã責任ç¯å²äŸ
å³äžã®çªå·ãã€ããããéšåãå©çšè
ã®è²¬ä»»ç¯å²ã§ããã
â å€éšããèš±å¯ããéä¿¡ãšãããåããããã°ã©ã
â¡ãµãŒãã¹ããèªäœã§ã¯ãªããã®èšå®
â¢ç°å¢ãžã¢ã¯ã»ã¹ããããã€ã¹ãéä¿¡
ã¬ãã¡ã³ãã¯ã©ãŠãã§ã®è²¬ä»»å ±æã¢ãã«
ã¬ãã¡ã³ãã¯ã©ãŠãã«ããã責任ç¯å²ã¯ã以äžã®äžã€ã®ç¯å²ã«åå²ãããã
- å©çšçµç¹
ã¯ã©ãŠããµãŒãã¹ãå«ããã€ã³ãã©æ§æãã¯ã©ãŠããµãŒãã¹ã®èšå®ãOSãããã«ãŠã§ã¢ãã¢ããªã±ãŒã·ã§ã³ãããŒã¿ã®ç®¡çãªã© - ã¬ãã¡ã³ãã¯ã©ãŠã
ã¬ãŒãã¬ãŒã«èšå®ããã³ãã¬ãŒã/IaCãã¡ã€ã«ãç°å¢æãåºããªã© - CSP
ã¯ã©ãŠãåºç€ïŒããŒããŠã§ã¢ããœãããŠã§ã¢ããããã¯ãŒã¯ïŒããããŒãžããµãŒãã¹ãªã©
ãã®ãã¡ãå©çšçµç¹ã®è²¬ä»»ç¯å²ã¯ãããŒãžããµãŒãã¹ãå©çšããããšã§çããããšãã§ããã»ãã¥ãªãã£ãªã¹ã¯ã軜æžããããšãã§ããã詳现ã«ã€ããŠã¯è²¬ä»»å ±æã¢ãã«ã«ãããç¯å²ã®éå®ãåç §ã
å³003ãã¬ãã¡ã³ãã¯ã©ãŠãã§ã®è²¬ä»»å
±æã¢ãã«
ã¬ã€ãã«åºã¥ãã·ã¹ãã æ§æãšéçšã§å®çŸããã»ãã¥ãªãã£
ã¬ãã¡ã³ãã¯ã©ãŠããæ¬æ Œçãªæåã®ã¯ã©ãŠããµãŒãã¹å©çšã§ããã·ã¹ãã ã®å Žåãçµéšåã«ãã察å¿ãå°é£ã§ãã£ãããã¯ã©ãŠãæè¡ã®ååãªæè²ãéçšæé ã®æšæºåãå³ãããŠããªãããšãã£ã課é¡ãæã£ãŠããå Žåããããæ¬é ã§ã¯ããããã£ãã·ã¹ãã ã®æ åœè åãã«ãé©åãªã»ãã¥ãªãã£ã¬ãã«ãåããã·ã¹ãã æ§ç¯ãšéçšã®åèãšãªãå 容ãèšè¿°ããã
èšèšæ¹é
ã
è²¬ä»»å ±æã¢ãã«ã«ãããç¯å²ã®éå®
ã·ã¹ãã æ§ç¯ã«ä»®æ³ãµãŒããŒãµãŒãã¹ãå©çšããå Žåããå³003ãã¬ãã¡ã³ãã¯ã©ãŠãã§ã®è²¬ä»»å
±æã¢ãã«ãã§ç€ºããããã«ãOSãããã«ãŠã§ã¢ããããã¯ãŒã¯æ§æãªã©ã¯å©çšè
åŽã®è²¬ä»»ç¯å²ãšãªããä»®æ³ãµãŒããŒãµãŒãã¹ã®ä»£ããã«ãããŒãžããµãŒãã¹ãå©çšããå Žåãåè¿°ã®è²¬ä»»ç¯å²ã®å€§éšåããããã¯å
šãŠãCSPã®è²¬ä»»ç¯å²ãšãªãããã®éšåã®ã»ãã¥ãªãã£å¯ŸçãäžèŠãšãªãã
ãã ãããããŒãžããµãŒãã¹ã§ãã£ãŠãããµãŒãã¹ã®èšå®å
容ã¯å©çšè
åŽã®è²¬ä»»ãšãªãããšã«ã¯çæããã
ã»ãã¥ãªãã£å¯Ÿå¿ç
ã¬ãã¡ã³ãã¯ã©ãŠãäžã®ã·ã¹ãã ã§èããã¹ãèªèšŒã®äŸç€º
ã¬ãã¡ã³ãã¯ã©ãŠãäžã§çšŒåããã·ã¹ãã ã®èªèšŒã«ã€ããŠã¯ãåçµç¹ã®æºæ ãã¹ãããªã·ãŒã«åŸã£ãŠãã®å®çŸæ¹åŒãå®çŸ©ãå®è£
ãè¡ããèªèšŒæ¹åŒã®å®çŸ©ã®éã«ã¯ãç±³åœç«æšæºæè¡ç ç©¶æïŒNISTïŒãå®çŸ©ãããããžã¿ã«ã¢ã€ãã³ãã£ãã£ã¬ã€ãã©ã€ã³ NIST SP
800-63ã®ææ°çããå
é£ãµã€ããŒã»ãã¥ãªãã£ã»ã³ã¿ãŒïŒNISCïŒãå®çŸ©ããã¬ã€ããåç
§ã§ãããããã§ã¯ãã¬ãã¡ã³ãã¯ã©ãŠãããŒã ã«ããéçšç®¡çã«ãããŠå®çŸ©ããŠããèªèšŒã®åºæ¬ååããå©çšã·ã¹ãã ã§ãåç
§ã§ããæ
å ±ãšããŠã人ã«å¯ŸããèªèšŒãšã·ã¹ãã ã«å¯ŸããèªèšŒã®äž¡æ¹ã§4ãã¿ãŒã³ãã€ç޹ä»ãããä»åŸã®ã¯ã©ãŠãæ©èœã®æ¡å
ãç°å¢ã®å€åã«å¿ããŠãéæåç
§ã§ãããã¿ãŒã³ãå¢ãããŠããã
ã¬ãã¡ã³ãã¯ã©ãŠããšããŠã®èªèšŒã®åºæ¬ååã®äŸç€º
ã¬ãã¡ã³ãã¯ã©ãŠãã®éçšç®¡çã¯ãã®ååã«åŸã£ãŠèªèšŒãå®è£ ããŠããã
- 1ã€ã®å®äœã«ã€ã1ã€ã®ID
- 1ã€ã®å®äœïŒäººãããã¯ã·ã¹ãã ããµãŒãã¹ïŒã«ã€ã1ã€ã®IDãå²ãåœãŠã
- ååãIDã®å ±æã¯çŠæ¢ãã - 人ã®èªèšŒã§ã¯ããã¹ã¯ãŒãïŒå€èŠçŽ èªèšŒãå©çš
- 人ã®èªèšŒã§ã¯ããã¹ã¯ãŒãæ¡æ°ãªã©ã®ããªã·ãŒã«åŸã£ããã¹ã¯ãŒããšãååãšããŠç°ãªã屿§ãæã€æ å ±ãèªèšŒã®ã·ãŒã¯ã¬ãããšããŠå€èŠçŽ èªèšŒãè¡ã - ã·ã¹ãã éã®èªèšŒã§ã¯ãäžæããŒã¯ã³ãå©çš
- ã·ã¹ãã éïŒãµãŒãã¹éïŒã§ã®èªèšŒã§ã¯ãæ¯èŒççãæå¹æéãã€ããŠäžæçã«çºè¡ãããäžæããŒã¯ã³ãã·ãŒã¯ã¬ãããšããŠèªèšŒãè¡ã - IDã«ä»äžããæš©éã¯æå°ãšãã
- IDã¯ã¢ã¯ã»ã¹å¯èœãªãµãŒãã¹ãæ©èœãå¿ èŠæå°éã«éå®ãã
- çšéïŒã·ã¹ãã ãããã°ã©ã ãã¹ãã¬ãŒãžé åçïŒããšã«IDãšæš©éãåãã - èªèšŒæ
å ±ã¯å¹³æã§æžããªã
- ãã¹ã¯ãŒããããŒã¯ã³çã®ã·ãŒã¯ã¬ãããããã°ã©ã ã³ãŒãããã¡ã€ã«ã«çŽæ¥å¹³æã§æžããªãïŒæå·åãããä¿¡é Œã§ããã·ãŒã¯ã¬ãã管çã®ä»çµã¿ã䜿ãïŒ - IDã®ãã°ãèšé²ã確èªãã
- ã©ã®IDãã©ãã«ã¢ã¯ã»ã¹ãäœããããããã°ãšããŠèšé²ãã
- ãã°ã«å¯ŸããŠå®æçã«äžæ£ããªãã確èªããïŒç¹ã«æš©éã®åŒ·ãIDçã«å¯ŸããŠè¡ãïŒ - IDã®æ£åžãè¡ã
- IDãã©ããããçºè¡ãããŠãããã©ã®ããã䜿ãããŠããã®ãææ¡ã管çãã
- 䜿ãããŠããªãIDãé·æéå©çšäŒæ¢äžã®IDã¯ç¡å¹åãŸãã¯åé€ãã - ã¯ã©ãŠãå©çšã®ãã¹ããã©ã¯ãã£ã¹ã«åŸã
- ã¯ã©ãŠãäºæ¥è å瀟ãåºããŠããID管çãèªèšŒã®ãã¹ããã©ã¯ãã£ã¹ã«åŸã£ãŠéçšãè¡ã
èªèšŒãã¿ãŒã³
1. 人ã®èªèšŒ
å©çšã·ã¹ãã åŽã®ã¢ããªã±ãŒã·ã§ã³ã«ããããŠãŒã¶èªèšŒã¯ãæºæ ãã¹ãããªã·ãŒãååã«åŸãã€ã€ãå®è£
æ¹åŒã«ãã£ãŠå®çŸã§ãã
æ¹åŒãå©çšã·ã¹ãã åŽã§å®çŸ©ãããå
žåçã«ã¯ãå³ã®1-1.ã®ããã«ãªããšèããã
å©çšã·ã¹ãã ã§ã¯ã©ãŠãäºæ¥è
ã®ã¯ã©ãŠããµãŒãã¹ããã®ãŸãŸã¢ããªã±ãŒã·ã§ã³ãšããŠãŠãŒã¶ããã¢ã¯ã»ã¹ããããå Žåã¯ãèªèšŒ
ã®å®è£
æ¹åŒã«ã€ããŠçæç¹ãããã3ã€ã®ã±ãŒã¹ïŒå³1-2.ãå³1-4.ïŒã«åé¡ããŠå®çŸ©ããã
å³1-2. ã¯ã©ãŠã管çç»é¢å©çšæã®èªèšŒ
ã¢ããªã±ãŒã·ã§ã³ã®äžéšãšããŠã¯ã©ãŠã管çç»é¢ã䜿ãããšã¯ååé¿ããïŒ*1ïŒãäžæ¹ã§ãã¯ã©ãŠãã€ã³ãã©éçšã®ããã«ã¯ã©ãŠ
ã管çç»é¢ã䜿ãå Žåã¯ãã¬ãã¡ã³ãã¯ã©ãŠãã®GCASèªèšŒã«åŸãã
*1 æš©éã®èšå®æ¬¡ç¬¬ã§ã¯ãããã®ã®ãã¯ã©ãŠãã€ã³ãã©ãæäœã§ããç»é¢ã䜿ã£ãŠæ¥åã¢ããªã±ãŒã·ã§ã³ãåäœããããšãè·ååé¢ïŒæš©éã®åé¢ïŒãæ¥ã ã®æ¥åã®äžã§ã€ã³ãã©æ§æããªã¹ã¯ã«ããããããšãã芳ç¹ã§é¿ããæ¹ãæãŸããã
å³1-3. å€éšIdPãšé£æºå¯èœãªã¯ã©ãŠããµãŒãã¹ã§ã®èªèšŒ
ã¯ã©ãŠããµãŒãã¹ã«ãã£ãŠã¯ãŠãŒã¶ãŒåãæ©èœãç¬èªç»é¢ãã€ã³ã¿ãã§ãŒã¹ã§çšæããå€éšã®IdP(Identity Provider)ãšèªèšŒé£æºå¯
èœã§ããããã®ãããªã¯ã©ãŠããµãŒãã¹ã䜿ãå Žåã¯ãå
žåãã¿ãŒã³ïŒ1-1.ïŒãšåããçµç¹ã®èªèšŒã·ã¹ãã ãå€éšIdPãšããŠèªèšŒã
ä»»ããè€æ°ã®ã¢ããªã±ãŒã·ã§ã³ãžã®ã·ã³ã°ã«ãµã€ã³ãªã³ãå®çŸã§ããã
å³1-4. äžæããŒã¯ã³ãå©çšããã¯ã©ãŠããµãŒãã¹ã§ã®èªèšŒ
ã¯ã©ãŠããµãŒãã¹ã§ã¯ããã®ã¯ã©ãŠããçæããäžæããŒã¯ã³ã䜿ã£ãèªèšŒæ©èœãæäŸããŠããå Žåãããããã®å ŽåãGCASã«
ããã·ã³ã°ã«ãµã€ã³ãªã³åŸã®ã¯ã©ãŠã管çç»é¢ãããã¯æ©èœããäžæããŒã¯ã³ååŸããŠã¯ã©ãŠããµãŒãã¹ã«å¯ŸããèªèšŒãè¡ãã
å³004-1:ã¬ãã¡ã³ãã¯ã©ãŠãã§ã®èªèšŒãã¿ãŒã³ïŒ1. 人ã®èªèšŒïŒ
2. ã·ã¹ãã ã®èªèšŒ
ã·ã¹ãã å ã§ã®èªèšŒã®å žåçãªã±ãŒã¹ãšããŠãã¢ããªã±ãŒã·ã§ã³ãµãŒãããã®ããŒã¿ããŒã¹ïŒãã¹ãã¬ãŒãžïŒã®èªèšŒãããïŒå³2-1.ïŒãããŒã¿ããŒã¹ïŒãã¹ãã¬ãŒãžïŒãžã®èªèšŒæ å ±ã¯ç§å¿æ å ±ãšããŠå³éã«åãæ±ãå¿ èŠããããããã¯ã©ãŠããµãŒãã¹ã®ã·ãŒã¯ã¬ãã管çãµãŒãã¹ã«ä¿ç®¡ããçããŠãããã°ã©ã ã³ãŒãã«çŽæ¥æžãããOSãã¡ã€ã«ã«å¹³æã§æžãããããªãããã«ããïŒå³2-1.ã®æ¡1ïŒããããã¯ãããŒã¿ãä¿ç®¡ããããŒã¿ããŒã¹ãã¹ãã¬ãŒãžã察å¿ããŠããå Žåã¯ãã¯ã©ãŠããæäŸããããµãŒãã¹ã«çŽã¥ããäžæããŒã¯ã³çºè¡æ©èœãå©çšããŠã¢ã¯ã»ã¹ããã
ã·ã¹ãã éã®èªèšŒã§ã¯ãåäžã¯ã©ãŠãå ïŒå³2-2.ïŒãç°ãªãã¯ã©ãŠãéïŒå³2-3.ïŒããªã³ãã¬ãã¹ãšã¯ã©ãŠãéïŒå³2-4.ïŒã®ã±ãŒã¹ã§å®è£ æ¹åŒãå®çŸ©ããããã¹ãŠã®ã±ãŒã¹ã§äžæããŒã¯ã³ã䜿ã£ãã¯ã©ãŠããµãŒãã¹ã®èªèšŒãå®çŸããã
å³2-2. åäžã¯ã©ãŠãå ã§ã¯ãã¯ã©ãŠãã®æ©èœãšããŠçšæãããŠããããµãŒãã¹ã«çŽã¥ããäžæããŒã¯ã³ã䜿ãããããããã䜿ã£ãŠèªèšŒãè¡ããããã«ãããã·ãŒã¯ã¬ããããŒã¿ãã©ãã«ãä¿ç®¡ããããŠãŒã¶ã®æã«ãæž¡ããªãããã¡ã§å®å šã«èªèšŒãè¡ããã
å³2-3. ç°ãªãã¯ã©ãŠãéã§ã¯ãOIDCã«ããIDãã§ãã¬ãŒã·ã§ã³ãšäžæããŒã¯ã³ãçµã¿åãããŠã®ã¯ã©ãŠããµãŒãã¹é£æºãè¡ãïŒ*2ïŒãããã«ãããïŒåïŒæ°žç¶çãªã·ãŒã¯ã¬ããããŒã¿ãçºçãããããšãªãã¯ã©ãŠããµãŒãã¹éã§ã®èªèšŒãå¯èœãšãªããäžéšã®ã¯ã©ãŠããµãŒãã¹ã§ã¯å©çšã§ããªãããšããããããäºåã®ã¯ã©ãŠããµãŒãã¹éã®çµã¿åããã§ã¯å®çŸå¯åŠã®ç¢ºèªãè¡ãå¿ èŠãããããã®å Žåã¯ãå³2-4.ã®æ§æã«è¿ã¥ããèªèšŒã·ã¹ãã ïŒIdPïŒãæ§ç¯ããæ¹åŒãçšæããå¿ èŠãããã
*2 ããšãã°ãAWSã®AssumeRoleWithWebIdentityæ©èœãGoogle Cloudã®Workload Identity FederationãAzureã®Federated identity credentialsãOCIã®OCI IAM Workload Identity Federationãããã«å¯Ÿå¿ãã
å³2-4. ãªã³ãã¬ãã¹ãšã¯ã©ãŠãã®éïŒå³2-4.ïŒã§ã¯ãã¯ã©ãŠãã®äžæããŒã¯ã³ãçºè¡ããããã®èªèšŒãµãŒãïŒèªèšŒã¢ããªïŒãOAuth M2MèªèšŒãªã©ã®ä»çµã¿ã䜿ã£ãŠéçºããŠçšæããããã¯ã©ãŠããµãŒãã¹ã®äžæããŒã¯ã³ã䜿ã£ããªã³ãã¬ãã¹ãµãŒããšã®ãã¡ã€ã«é£æºæ©èœãå©çšããïŒ*3ïŒã
*3 AWSã®ssm agentæ©èœãIAM Roles AnywhereãOCIã®OIC agentãããã«å¯Ÿå¿ãã
ã¬ãã¡ã³ãã¯ã©ãŠãã§ã®èªèšŒãã¿ãŒã³ïŒ2. ã·ã¹ãã ã®èªèšŒïŒ
3. ã·ã¹ãã éããŒã¿é£æº
ã·ã¹ãã éã§ããŒã¿é£æºãè¡ãå Žåã¯ããŸãã¯APIã«ããããŒã¿é£æºãæ€èšãããããã§ã®APIã¯ãRESTful APIãGraphQLãgRPCçã®HTTP(S)ããŒã¹ã®çŸä»£çãªAPIãæãã
ã¯ã©ãŠããµãŒãã¹ã®APIãçŽæ¥äœ¿ã£ãŠããŒã¿é£æºããå Žåãããããã¯ãAPI Gatewayãç«ãŠãŠãã®APIçµç±ã§ããŒã¿é£æºããå Žåããäžèšã®èªèšŒãã¿ãŒã³ãå©çšã§ãããä»ã·ã¹ãã ãžã®ããŒã¿é£æºãå¿ èŠãªå Žåã¯ãå€åãã®APIãçšæããã
ãããã¡ã€ã«ã§ã®é£æºãå¿ èŠãªå Žåã¯ããªããžã§ã¯ãã¹ãã¬ãŒãžã®ãµãŒãã¹ã䜿ã£ãŠAPIã§ãã¡ã€ã«é£æºããããã®å Žåãäžèšã®èªèšŒãã¿ãŒã³ãå©çšã§ããã
GCASèªèšŒã«ããCSPç°å¢ãžã®ã·ã³ã°ã«ãµã€ã³ãªã³
什å6幎床ããGCASã§ã¯GCASèªèšŒã«ããCSPç°å¢ãžã®ã·ã³ã°ã«ãµã€ã³ãªã³æ©èœïŒGCAS-SSOïŒãå±éãããããã«ãããGCASèªèšŒïŒå®æ ã¯Google Workspaceã®èªèšŒïŒåŸãGCASã¢ã«ãŠã³ãã®ID(ã¡ãŒã«ã¢ãã¬ã¹)ãçšããŠã¬ãã¡ã³ãã¯ã©ãŠãã§æäŸããåçš®ãµãŒãã¹(CSPç°å¢ããã«ããã¹ã¯ãªã©ïŒãžèªèšŒã®æäœäžèŠã§ãã°ã€ã³å¯èœã«ãªãã
å³003-aãGCASã·ã³ã°ã«ãµã€ã³ãªã³æŠèŠ
- GCASã§å®çŸããã·ã³ã°ã«ãµã€ã³ãªã³ã®ç®ç
ã¬ãã¡ã³ãã¯ã©ãŠãã§æäŸããåçš®ãµãŒãã¹ãžã®ã·ã³ã°ã«ãµã€ã³ãªã³ã®ç®çã¯ä»¥äžã®éãã- GCASèªèšŒãžã®çµ±åã«ããGCASæäŸã¢ããªãCSPãžã®èªèšŒæäœçç¥ã«ãããŠãŒã¶ããªãã£åäž
- GCASã¢ã«ãŠã³ããžã®çµ±åã«ããGCASæäŸã¢ããªãCSPæ¯ã®ã¢ã«ãŠã³ã管çè² è·ã®è»œæž
- GCAS IDã«å¯Ÿããäžå åãããèªèšŒåŒ·åèšå®(MFA)ãšã¢ã¯ã»ã¹å å¶åŸ¡ã«ããã»ãã¥ãªãã£åäž
- GCAS-SSOãå®çŸããä»çµã¿
GCASã«ããããŠãŒã¶ãŒèªèšŒã§ã¯ãGoogle瀟Cloud Identityãå©çšããŠãããCloud Identity 㯠IDaaSïŒIdentity as a ServiceïŒãœãªã¥ãŒã·ã§ã³ãšããŠæäŸãããŠãããã¬ãã¡ã³ãã¯ã©ãŠãã§ã¯GCASã§å©çšããŠããã¢ããªã±ãŒã·ã§ã³ãSaaSãåCSPç°å¢ãšCloud IdentityãSAMLèŠæ Œã«åºã¥ããŠã·ã³ã°ã«ãµã€ã³ãªã³é£æºãå®è£ äžã§ãããCloud Identityã¯SAMLèŠæ Œã«ãããŠå€éšIdentity Provider(IdP)ãšããŠæ©èœãããAWSç°å¢ã§ã¯èªèšŒã»ã¢ã¯ã»ã¹æš©ç®¡çãµãŒãã¹ã®AWS IAM Identity CenterãšSAML飿ºãããŠãŒã¶ãŒæ å ±ãåæããã
å³003-bãAWSç°å¢ãäŸãšããã·ã³ã°ã«ãµã€ã³ãªã³ã€ã¡ãŒãž
[Googleããã¥ã¡ã³ã: Cloud Identity ãšã¯]
https://support.google.com/cloudidentity/answer/7319251?hl=jaOpens in new tab
- GCAS-SSOãžã®ç§»è¡ã«äŒŽã察å¿
什å5幎床æç¹ã§ã¬ãã¡ã³ãã¯ã©ãŠãã®CSPç°å¢ã®å©çšçµç¹ã¯ãã·ã³ã°ã«ãµã€ã³ãªã³æ©èœã®å®è£ ã«ããå€éšIdPã®å©çšã«ãããæ¢åãŠãŒã¶ãŒã¢ã«ãŠã³ãã¢ã«ãŠã³ãããã®åãæ¿ããå¿ èŠã«ãªãã詳现ã¯åCSPã®ãGCAS-SSOãžã®ç§»è¡ã«äŒŽã察å¿ãã確èªããããšã - GCAS-SSOé害æã®å¯Ÿå¿
GCASã«ããããŠãŒã¶ãŒèªèšŒã§ã¯ãGoogle瀟Cloud Identityã®èªèšŒæ©èœãå©çšãããCloud Identityãé害çã§å©çšäžå¯ãªå Žåã¯GCASã®ã·ã³ã°ã«ãµã€ã³ãªã³ãä»ããCSPç°å¢ãžã®ãã°ã€ã³ãäžå¯ãšãªããéå»å®çžŸããé害ãçºçããçã¯æ¥µããŠäœãããšãããã£ãŠãããæ¬çªãªãªãŒã¹äœæ¥çã§ç®¡çã€ã³ã¿ãã§ãŒã¹ã®å©çšãäºå®ããŠããŠãé害ããã®åŸ©æ§ãåŸ ãŠããé害ã«åããŠç·æ¥ã¢ã¯ã»ã¹çšã®ãŠãŒã¶ãŒãå¿ èŠã ãšå©çšçµç¹ã倿ããå Žåã¯ãGCASç·æ¥ãŠãŒã¶ãŒç®¡çïŒGCAS BreakGlassïŒã·ã¹ãã ãçšããŠç·æ¥ã¢ã¯ã»ã¹ãŠãŒã¶ãŒãçºè¡ããçºè¡ãããèªèšŒæ å ±ãçšããŠåCSPãžãã°ã€ã³ããããšãå¯èœãšãªãããã ããæ¬æ©èœãå©çšã§ããªãCSPã«ã€ããŠã¯ãäºåã«ã¬ãã¡ã³ãã¯ã©ãŠã管ççµç¹ã«è©²åœãŠãŒã¶ãŒã®äœæãäŸé ŒãããåCSPãžã®å¯Ÿå¿ã¯ã以äžã®éããšãªããAWSãAzureãOCIã«ã€ããŠã®è©³çްã¯GCASã¢ã«ãŠã³ããååŸã®äžãGCASã¬ã€ã(ã¡ã³ããŒå°çšããŒãž)ã§å ¬éãããŠããããã¥ã¡ã³ããåç §ããããšã
ãªããGoogle Cloudã«ã€ããŠã¯ãã®å©çšãCloud Identityã«ããèªèšŒãåæãšãªããããSSOã¢ã¯ã»ã¹äžå¯æ(Cloud Identityã¢ã¯ã»ã¹äžå¯æ)ã«ã¯Google瀟ã«ãã埩æ§ãåŸ ã€ããšã
â»CSPå¥ GCAS-SSOé害æã®å¯Ÿå¿æ¹é
| CSP | GCASç·æ¥ãŠãŒã¶ãŒç®¡çïŒGCAS BreakGlassïŒ | äºåã«ã¬ãã¡ã³ãã¯ã©ãŠã管ççµç¹ã«ãŠãŒã¶äœæäŸé Œ |
|---|---|---|
| AWS | å©çšå¯èœ ïŒ2025幎4æããæäŸïŒ | å©çšäžå¯ ïŒGCAS BreakGlassã®æäŸã«äŒŽã廿¢ïŒ |
| Azure | å©çšå¯èœ ïŒ2025幎7æããæäŸïŒ | å©çšäžå¯ ïŒGCAS BreakGlassã®æäŸã«äŒŽã廿¢ïŒ |
| OCI | å©çšäžå¯ ïŒCSP仿§ã«ããåæ§ã®å®è£ ãäžå¯ãªããïŒ | å©çšäžå¯ ïŒå©çšçµç¹åŽã®æ¿èªã»çºè¡ãåæãšããŠããããïŒ |
| Google Cloud | å©çšäžå¯ ïŒCSP仿§ã«ããCloud Identityã«ããèªèšŒãåæãšãªãããïŒ |
å€èŠçŽ èªèšŒã®äœ¿çš
IDããã¹ã¯ãŒãã®ã¿ã®èªèšŒã§ã¯ãæ»æè ã«ãããã¹ã¯ãŒããªã¹ãæ»æããã«ãŒããã©ãŒã¹æ»æçã§èªèšŒãçªç Žãããå¯èœæ§ãé«ããèªèšŒåŒ·åºŠãšããŠäžååã§ãããã¬ãã¡ã³ãã¯ã©ãŠãã®å©çšã§ã¯å šå©çšè ã®å€èŠçŽ èªèšŒãå¿ é ãšãããå€èŠçŽ èªèšŒãšã¯è€æ°ã®ç°ãªãèªèšŒèŠçŽ ãçµã¿åãããæ¹åŒãæå³ããèªèšŒèŠçŽ ã«ã¯ID/ãã¹ã¯ãŒãã«ä»£è¡šãããç¥è屿§ãããŒã¯ã³ãªã©ã®ææã«ããææç©å±æ§ãæçŽãªã©ã®çäœå±æ§ãæãããããã¬ãã¡ã³ãã¯ã©ãŠãã§ã¯å屿§ã®çµã¿åãããååãšãããå€èŠçŽ èªèšŒã®èšå®å¯Ÿè±¡ãšæ¹åŒã¯æ¬¡ã®ãšããã
- å€èŠçŽ èªèšŒã®èšå®å¯Ÿè±¡ã®ãŠãŒã¶ãŒ
ã¬ãã¡ã³ãã¯ã©ãŠãã®å©çšã«ãããå€èŠçŽ èªèšŒã®èšå®å¯Ÿè±¡ãŠãŒã¶ãŒã¯æ¬¡ã®ãšããã§ãããCSPäžã«å©çšã·ã¹ãã åŽã§æ§ç¯ããã¢ããªã±ãŒã·ã§ã³ã®èªèšŒã¯å©çšã·ã¹ãã åŽã§æ€èšããã- GCAS
- GCASå©çšãŠãŒã¶ãŒ
- CSP
- AWSç°å¢
- ããžã¿ã«åºãæãåºããGCASã¢ã«ãŠã³ãã«ãã£ãŠã®ã¿ãåCSPç°å¢ãžã®ã¢ã¯ã»ã¹ãå¯èœã§ãããã¬ãã¡ã³ãã¯ã©ãŠãã«ãããŠã¯GCASã¢ã«ãŠã³ãã®å©çšã«ãããŠå€èŠçŽ èªèšŒãè¡ãã
- Microsoft Azure
- ããžã¿ã«åºãæãåºããGCASã¢ã«ãŠã³ãã«ãã£ãŠã®ã¿ãåãµãã¹ã¯ãªãã·ã§ã³ãžã®ã¢ã¯ã»ã¹ãå¯èœã§ãããã¬ãã¡ã³ãã¯ã©ãŠãã«ãããŠã¯GCASã¢ã«ãŠã³ãã®å©çšã«ãããŠå€èŠçŽ èªèšŒãè¡ãã
- Oracle Cloud Infrastructure
- ããã³ã·ãŒã®åæããã³ã管çè ãŠãŒã¶ãŒïŒããã©ã«ãã®Identity Domainå ã«äœæãããïŒã
- åIdentity Domainå ã®IAMãŠãŒã¶ãŒãGCASããCSPç°å¢ãžã®ã·ã³ã°ã«ãµã€ã³ãªã³èªèšŒç§»è¡åã¯Identity Domainã«ãŠå©çšã·ã¹ãã åŽã§èšå®ãããç§»è¡åŸã¯GCASèªèšŒã®èšå®ãåªå ãããã
- Google Cloud
- Google Cloudç°å¢ã¯GCASå©çšãŠãŒã¶ãŒãšåäžã§ããã
- AWSç°å¢
- GCAS
- å€èŠçŽ èªèšŒã®èšå®ãšæ¹åŒ
ã¬ãã¡ã³ãã¯ã©ãŠãã®å©çšã«ããããŠãŒã¶ãŒã®æš©éçš®å¥ã«åºã¥ãå€èŠçŽ èªèšŒã®æ¹åŒã¯æ¬¡ã®ãšãããšãããGCASã«ãããã·ã³ã°ã«ãµã€ã³ãªã³æ©èœã®å©çšéå§åŸã¯ãGCASã®èªèšŒã§å©çšããGoogle Workspaceã«ãããŠèšå®ãããGCASã®Google Workspaceã§ã¯Google Cloud IdentityãèªèšŒæ©èœãšããŠå©çšããŠããããGoogleã¢ã«ãŠã³ãã®ç®¡çãã¡ãã¥ãŒãã2段éèªèšŒOpens in new tabãèšå®ããïŒè©³çްã¯ãã¬ãã¡ã³ãã¯ã©ãŠãæŠèŠè§£èª¬_8 å©çšã®å šäœã®æµãOpens in new tabããåç §ïŒã
ã
| No. | ãŠãŒã¶ãŒæš©éçš®å¥ | èªèšŒæ¹åŒ |
|---|---|---|
| â | GCASå©çšã«ãããŠä»¥äžã®ç®¡çè
æš©éãæããïŒâ»ïŒããŸãã¯åCSPã®æ¬çªçžåœç°å¢ ïŒæ¬çªç°å¢/å ±ééçšç®¡çç°å¢/CI/CDç°å¢ïŒã«ã¢ã¯ã»ã¹ãããŠãŒã¶ãŒ â»GCASå©çšã«ããã管çè æš©é該åœè ã»å©çšæ©é¢GCAS責任è ã»å©çšæ©é¢GCASæ åœè ïŒç®¡çè ïŒ ã»ãããžã§ã¯ãããŒã GCAS責任è ã»ãããžã§ã¯ãããŒã GCASæ åœè ïŒç®¡çè ïŒ ã»éçºéçšå§èšæ¥è 管çã°ã«ãŒãGCAS責任è ã»éçºéçšå§èšæ¥è 管çã°ã«ãŒãGCASæ åœè ïŒç®¡çè ïŒ ã»éçºéçšå§èšæ¥è GCAS責任è ã»éçºéçšå§èšæ¥è GCASæ åœè ïŒç®¡çè ïŒ | IDããã¹ã¯ãŒã + FIDOèŠæ Œæºæ (FIDO U2F/FIDO2)ã®ããŒããŠã§ã¢MFAããŒã¯ã³ |
| â¡ | â 以å€ã®ãŠãŒã¶ãŒ | IDããã¹ã¯ãŒãã«å ããŠä»¥äž3ã€ã®ãããããéžæ A: ã»ãã¥ãªãã£ã㌠B: èªèšŒã·ã¹ãã ã¢ã㪠C: Googleããã®ã¡ãã»ãŒãž |
衚001 ãŠãŒã¶ãŒã®æš©éçš®å¥ã«åºã¥ãå€èŠçŽ èªèšŒæ¹åŒ
è£è¶³äºé
â ïŒIDããã¹ã¯ãŒãã«ããèªèšŒã«å ããŠãFIDOèŠæ Œæºæ ã®ããŒããŠã§ã¢ããŒã¯ã³æ¹åŒã®æ¡çšãååãšãã(Google瀟ã§ã¯ã»ãã¥ãªãã£ããŒãšè¡šçŸãããŠãã)ãããŒããŠã§ã¢ããŒã¯ã³ã«é¢ãã詳现ã¯åŸè¿°ããããªããGCASã®èªèšŒã§ã¯ããŒããŠã§ã¢ããŒã¯ã³ã®å©çšã匷å¶ããå¶åŸ¡ããªã·ãŒã®é©çšã什å6幎床7æä»¥éã«äºå®ããŠããã
â¡ïŒã»ãã¥ãªãã£ããŒã¯GCASã§çšããŠããGoogle WorkspaceããµããŒãããèªèšŒæ¹åŒã§ãããâ ã§æå®ããFIDOèŠæ Œã®ããŒããŠã§ã¢ããŒã¯ã³ä»¥å€ã«ã¹ããŒããã©ã³ã®çµã¿èŸŒã¿ã®ããŒçããããèªèšŒã·ã¹ãã ã¢ããªã«ã¯ã¹ããŒããã©ã³ã§åäœããGoogle AuthenticatorçããããGoogleããã®ã¡ãã»ãŒãžã¯Google瀟ãæäŸããã¹ããã¢ããªãžã®éç¥ãžã®ã¢ã¯ã·ã§ã³ã«ãã£ãŠèªèšŒããæ¹åŒã§ããããªããã¬ãã¡ã³ãã¯ã©ãŠãã§ã¯ãã¹ããŒã®å©çšã¯èš±å¯ããŠããªããé³å£°ãŸãã¯ããã¹ãã¡ãã»ãŒãžãå©çšããSMSèªèšŒã«ã€ããŠã什å7幎床以éã«çŠæ¢äºå®ã§ããã詳现ã¯Googleãã«ããåç
§ããã
https://support.google.com/accounts/topic/2954345?hl=ja&ref_topic=7667090&sjid=4492682044056046115-APOpens in new tab
什å7幎床以éãã»ãã¥ãªãã£åŒ·åã®ãããã°ã€ã³æã®SMSã«ããã¯ã³ã¿ã€ã ãã¹ã¯ãŒãèªèšŒãå©çšçŠæ¢äºå®ã§æ€èšããŠãããçŸç¶ãSMSã®å©çšã«ãããŠã¯ãSIMã¹ã¯ããã³ã°ãªã©ã®è¢«å®³ãå ±éãããŠããããšãã該åœã®é»è©±ã«ã€ããŠé話ãŸãã¯éä¿¡ã確å®ã«è¡ããããšã確èªããåœè©²é»è©±ãæ¬äººãå©çšå¯èœã§ããããšãæ
ä¿ããã
- å€èŠçŽ èªèšŒã§çšããããŒããŠã§ã¢ããŒã¯ã³ã®è£è¶³
GCASã«ãããŠå©çšå¯èœãªããŒããŠã§ã¢ããŒã¯ã³ã¯FIDOïŒFast Identity OnlineïŒèŠæ ŒããµããŒããFIDOã¢ã©ã€ã¢ã³ã¹ãèªå®ããããŒããŠã§ã¢ããŒã¯ã³ãšãªããFIDOèŠæ Œã«ã¯FIDO1.0(U2F)ã什å5幎çŸåšã«ãããææ°ã®FIDO2ããããGCASã®èªèšŒã§ã¯ã©ã¡ãã察å¿å¯èœã§ããã調éæã«éžæå¯èœã§ããã°å°æ¥çãªäºææ§ã®ããã«ææ°ã®ä»æ§ã§ããFIDO2ããµããŒãããããŒã¯ã³ãéžæããããã®éãFIDOã®èŠæ ŒãšããŠããŒã¯ã³å ã«æå·éµãä¿æããããšãããèã¿ã³ãæ§ã確ä¿ãããããŒã¯ã³ã»èªèšŒæ å ±ã®è€è£œã«å¯Ÿã匷ãèæ§ãæããããšã確èªããã
å©çšããPCã«åãããŠã³ãã¯ã¿ãŒã®åœ¢ç¶ã確èªããŠéžæããããŸããFIDO ã¢ã©ã€ã¢ã³ã¹ã¯ãFIDO èŠæ Œã«é©åãããã¹ãŠã® FIDO èªå®è£œåOpens in new tabã®ãªã¹ããå ¬éããŠããã®ã§å¿ èŠã«å¿ããŠåç §ããããªããAWSã¢ã«ãŠã³ãã®ã«ãŒããŠãŒã¶ãŒãªã©ã®ç¹æš©ç®¡çè ã®èªèšŒã«çšããããããŒããŠã§ã¢ããŒã¯ã³ã¯é庫ãªã©ã®æœé 管çã§ããç®æã«ä¿ç®¡ããããã以å€ã®ãŠãŒã¶ãŒã®ããŒããŠã§ã¢ããŒã¯ã³ã¯ç¬¬äžè ãå ¥æã»æªçšã§ããªããããé©åã«ç®¡çããããšã
GCASãå©çšããGoogleã«ãããèšå®ã¯ä»¥äžã®ãªã³ã¯å ãåèã«å®æœããã
[Googleããã¥ã¡ã³ãïŒ2 段éèªèšŒããã»ã¹ã«ã»ãã¥ãªã㣠ããŒã䜿çšãã]
https://support.google.com/accounts/answer/6103523?sjid=5245628036608199608-APOpens in new tab)
[Googleã»ãã¥ãªãã£ããŒèšå®ç»é¢]
https://myaccount.google.com/signinoptions/two-step-verification?flow=sk&opendialog=addskOpens in new tab
ãªããããŒããŠã§ã¢ã¯ã³ã¿ã€ã ãã¹ã¯ãŒãããŒã¯ã³ã¯GCASã®èªèšŒã§ã¯ãµããŒããããŠããªãããå©çšäžå¯ã§ãããäžæ¹ã§AWSç°å¢ã«ãããã«ãŒããŠãŒã¶ãŒãIAMãŠãŒã¶ãŒã®èªèšŒã¯GCASèªèšŒãšã¯çŽæ¥é£æºããªããããå©çšå¯èœã§ãããAWSç°å¢ã§ããŒããŠã§ã¢ TOTPããŒã¯ã³ãèšå®ããå Žåã¯ãAWSãšã®äºææ§ç¢ºä¿ã®ããããã®ãªã³ã¯å ïŒOTPããŒã¯ã³Opens in new tabãŸã㯠OTPãã£ã¹ãã¬ã€ã«ãŒãOpens in new tabïŒããè³Œå ¥ããå¿ èŠãããã
ãã ããã¯ã³ã¿ã€ã ãã¹ã¯ãŒãããŒã¯ã³ã¯ããããªãŒã§åäœããããã宿çãªäº€æãå é»ã®éçšã®èæ ®ãå¿ èŠã«ãªãã
CSP管çGUIãžã®æ¥ç¶å ã¢ã¯ã»ã¹å¶åŸ¡
ã¬ãã¡ã³ãã¯ã©ãŠãã§ã¯ãGCASã®èªèšŒæ©èœãšããŠå©çšããŠããGoogle瀟ã®Cloud IdentityããåCSPãžã·ã³ã°ã«ãµã€ã³ãªã³ãè¡ãéãã¢ã¯ã»ã¹å ã®å©çšç«¯æ«ã®ã·ãªã¢ã«çªå·ãŸãã¯æ¥ç¶å ãããã¯ãŒã¯ç°å¢ã瀺ãã°ããŒãã«IPã¢ãã¬ã¹ã«åºã¥ããã¢ã¯ã»ã¹å¶åŸ¡ãå¯èœã§ããã
ãã®ã¢ã¯ã»ã¹å å¶åŸ¡ã¯ãGoogle瀟ãæäŸããChrome Enterprise PremiumïŒCEPïŒïŒæ§ BeyondCorp EnterpriseïŒBCEïŒïŒãšåŒã°ããããŒã«ãçšããŠå®çŸãããCEPã§æäŸãããChromeãã©ãŠã¶ã®æ¡åŒµãã©ã°ã€ã³Endpoint Verification(EV)ãå©çšããããšã§ç«¯æ«ã®ã·ãªã¢ã«çªå·ãCEPã«é£æºãããã¢ã¯ã»ã¹å¶åŸ¡ã«çšããããã
å³003-CãCEPãå©çšããã¢ã¯ã»ã¹å
ã®å¶åŸ¡ã€ã¡ãŒãž
åŸè¿°ã®éããCSPç°å¢ã§ã¯GCASã¢ã«ãŠã³ãããã®ã·ã³ã°ã«ãµã€ã³ãªã³å®è£ ã«äŒŽããå©çšã·ã¹ãã åŽã«ããCSPç°å¢ã®ã¢ã¯ã»ã¹å¶åŸ¡èšå®æäœã«å¶çŽãçããå ŽåããããããCSPç°å¢ãžã®ã¢ã¯ã»ã¹å å¶éãæ€èšã宿œäžã®å©çšçµç¹ã¯æ¬ã¢ã¯ã»ã¹å¶åŸ¡æ¹æ³ã®å©çšãæ€èšããã
CEPã®å©çšã¯åœã®è¡æ¿æ©é¢/å°æ¹å ¬å ±å£äœã«ãã£ãŠæ¬¡ã®æ¹éãšãªãã
å³003-Dãåœã®è¡æ¿æ©é¢ããã³å°æ¹å ¬å ±å£äœã®ã¬ãã¡ã³ãã¯ã©ãŠãã«ãããã¢ã¯ã»ã¹å å¶éæ¹é
CEPã®å©çšãå¿ èŠãªçµç¹ã¯åŸè¿°ã®æé ã«åŸã£ãŠã©ã€ã»ã³ã¹å©çšç³ã蟌ã¿ãè¡ããã¢ã¯ã»ã¹å å¶åŸ¡æ å ±ãã¬ãã¡ã³ãã¯ã©ãŠãããŒã ã«é£æºããããŒã«ã®å°å ¥ãè¡ãã
- CEPã®å©ç𿹿³
CEPã¯ãåè¿°ã®Chromeãã©ãŠã¶ã®æ¡åŒµãã©ã°ã€ã³EVãå°å ¥åŸãå©çšè ã®æäœã¯äžèŠã§ããã - CEPã«ããã¢ã¯ã»ã¹å¶åŸ¡ã®ä»æ§
- CEPã«ããã¢ã¯ã»ã¹å¶åŸ¡ã¯ãGCASã¢ã«ãŠã³ããçšããŠåCSPç°å¢ãžã·ã³ã°ã«ãµã€ã³ãªã³ããéã«äžåŸã§é©çšãããã
- CSPã«ã¢ã¯ã»ã¹ãã端æ«ã·ãªã¢ã«çªå·ãŸãã¯(ã°ããŒãã«)IPã¢ãã¬ã¹ã«åºã¥ããŠã¢ã¯ã»ã¹ãå¶åŸ¡ããããã ããIPã¢ãã¬ã¹(CIDR衚èš)ãç³è«ããå Žåã端æ«ã·ãªã¢ã«çªå·ã§ç³è«ãã端æ«ã«å ããŠããã®IPã¢ãã¬ã¹ãã¢ã¯ã»ã¹å ãšãã端æ«ããã®ã¢ã¯ã»ã¹ãèš±å¯ãããã
- CEPã©ã€ã»ã³ã¹æç¡ã®éãã«ããåœã®è¡æ¿æ©é¢ãšå°æ¹å
Œ
±å£äœã®ã¢ã¯ã»ã¹å¶åŸ¡é©çšæç¡ã¯ä»¥äžã®éãã
- ååºçåºã¯CEPã®ã©ã€ã»ã³ã¹ãå²ãåœãŠããããŠãŒã¶ãŒã«å¯ŸããŠã¢ã¯ã»ã¹å¶åŸ¡ãæå¹åããããã©ã€ã»ã³ã¹ãå²ãåœãŠãããŠããªããŠãŒã¶ãŒã¯ã¢ã¯ã»ã¹å¶åŸ¡ãè¡ããããCSPç°å¢ãžæ¥ç¶å ã«ãããã¢ã¯ã»ã¹ã§ããããšã«æ³šæããããšã
- å°æ¹å ¬å ±å£äœã¯CEPã®ã©ã€ã»ã³ã¹ãå²ãåœãŠããããŠãŒã¶ãŒã«å¯ŸããŠã¢ã¯ã»ã¹å¶åŸ¡ãæå¹åããããã©ã€ã»ã³ã¹ãå²ãåœãŠãããŠããªããŠãŒã¶ãŒã¯ãCSPç°å¢ãžã¢ã¯ã»ã¹ãã§ããªãããšã«æ³šæããããšã
- ã¢ã¯ã»ã¹å ã«å¯Ÿããã¢ã¯ã»ã¹å¶åŸ¡ã¯ãåœã®è¡æ¿æ©é¢ãŸãã¯å°æ¹å ¬å ±å£äœã®ã¬ãã¡ã³ãã¯ã©ãŠãå©çšçµç¹å šäœã§å šCSPç°å¢ã«å¯ŸããŠäžåŸã§é©çšããããçµç¹ãCSPãæ¬çªç°å¢ãæ€èšŒç°å¢ãªã©ã®çš®å¥ããšã®å¶åŸ¡ã§ã¯ãªãããšã«æ³šæããããããã£ãŠãéçºç°å¢ã«ã¢ã¯ã»ã¹ãããŠãŒã¶ãŒã®ãã¡ããã¬ã¯ãŒã¯ãè¡ãéçºæ¥è ã®ã¿éçºç°å¢ã«å¯ŸããŠã®ã¿ã¢ã¯ã»ã¹èš±å¯ããããšãã察å¿ã¯äžå¯ãšãªãããŠãŒã¶ãŒèªèšŒã§å¶åŸ¡ããã
- 端æ«ã®ã·ãªã¢ã«çªå·ååŸã¯ä»¥äžã®å
容ã確èªããŠå®æœããã
- WindowsOS
- Microsoftã¢ã«ãŠã³ãã§ãµã€ã³ã€ã³ãŸãã¯çŽä»ããããŠããå ŽåããMicrosoftã¢ã«ãŠã³ããã§Windows OSã®ã·ãªã¢ã«çªå·ã確èªå¯èœã§ããããMicrosoftã¢ã«ãŠã³ããã«ãµã€ã³ã€ã³åŸãããã€ã¹ã®é ç®ã«ãŠç¢ºèªãããPCã«ããã詳现ã衚瀺ããéžæãããããã€ã¹ã®æ å ±ãããã·ãªã¢ã«çªå·ãã確èªããã
- ã³ãã³ãããã³ãããŸãã¯PowerShellã«ãŠä»¥äžã®ã³ãã³ãã§Windows11ã®ã·ãªã¢ã«çªå·ã確èªããã
wmic bios get serialnumber
- macOS
Apple瀟ã®ãMac ã®ã¢ãã«åãšã·ãªã¢ã«çªå·ã調ã¹ãããåç §ããã
https://support.apple.com/ja-jp/HT201581Opens in new tab
- WindowsOS
- CEPå©çšã®ç«¯æ«åææ¡ä»¶
- CEPå©çšã«ãããŠEVã®å°å
¥ã«é¢ãã端æ«ã®åææ¡ä»¶ã¯æ¬¡ã®éãããªããæ¥ç¶å
ã®ã°ããŒãã«IPã¢ãã¬ã¹ã«ããã¢ã¯ã»ã¹å¶åŸ¡ã®ã¿ãåžæããå ŽåãEVã®å°å
¥ã¯äžèŠã§ããããŸããååºçã§ã®äžéšã§å©çšãããŠããGSS端æ«ã«ãããEVã®å°å
¥ã¯äžå¯ã§ããã
- Chromeãã©ãŠã¶ããã³æ¡åŒµãã©ã°ã€ã³ã€ã³ã¹ããŒã«æš©éä¿æ
- GoogleãµãŒãã¹ã®åå解決
- CEPå©çšã«ãããŠEVã®å°å
¥ã«é¢ãã端æ«ã®åææ¡ä»¶ã¯æ¬¡ã®éãããªããæ¥ç¶å
ã®ã°ããŒãã«IPã¢ãã¬ã¹ã«ããã¢ã¯ã»ã¹å¶åŸ¡ã®ã¿ãåžæããå ŽåãEVã®å°å
¥ã¯äžèŠã§ããããŸããååºçã§ã®äžéšã§å©çšãããŠããGSS端æ«ã«ãããEVã®å°å
¥ã¯äžå¯ã§ããã
- GCASã·ã³ã°ã«ãµã€ã³ãªã³å©çšäžã®å¶çŽãšCEPã®å©çš
AWSãAzureãGoogleã§ã¯GCASã¢ã«ãŠã³ãããã®ã·ã³ã°ã«ãµã€ã³ãªã³å®è£ ã«äŒŽããå©çšã·ã¹ãã åŽäž»äœã®CSPç°å¢ã«ãããæ¥ç¶å IPã¢ãã¬ã¹çã®ã¢ã¯ã»ã¹å¶åŸ¡æäœã«å¶çŽãçããå ŽåããããããåCSPã®ã¬ã€ãïŒãã»ãã¥ãªã㣠- CSP管çGUIãžã®æ¥ç¶å ã¢ã¯ã»ã¹å¶åŸ¡ãé ïŒãåç §ãããå¿ èŠã«å¿ããŠCEPã®å©çšãç³è«ããã - CEPã®å©çšæç¶ã
CEPã®å©çšåã³ã©ã€ã»ã³ã¹ã®åžæçµç¹ã¯ã¡ã³ããŒéå®ããŒãžã«ãããã¬ãã¡ã³ãã¯ã©ãŠãæç¶ãæŠèŠããåç §ãå¿ èŠãªæç¶ããè¡ãããšã
ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹å¶åŸ¡
ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹å¶åŸ¡ã¯äž»ã«æäœæš©éãéä¿¡ã®å¶åŸ¡ãæå³ãããæäœæš©éã®ã·ã¹ãã çãªå¶åŸ¡ã¯åŸæ¥ãOS ãã¢ããªã±ãŒã·ã§ã³ã§å®è£ ãããŠããããã¯ã©ãŠãç°å¢ã§ã¯ãããã«å ããŠCSPãæäŸãããªãœãŒã¹ïŒãµãŒãã¹å«ãïŒã®æäœã«é¢ããå¶åŸ¡ã®èæ ®ãå¿ èŠã«ãªãããŸããéä¿¡ã®ã¢ã¯ã»ã¹å¶åŸ¡ã¯ãCSPç¹æã®æ©èœãå©çšãããŸãŒãã³ã°ããã¡ã€ã¢ãŠã©ãŒã«ãªã©ã®å©çšãå¿ èŠã§ããã
ã¢ã¯ã»ã¹å¶åŸ¡ã«ãããŠã¯ãäºæãã¬ãã©ãã«ãã€ã³ã·ãã³ããé¿ãããããã¢ã¯ã»ã¹äž»äœãžã®å¿ èŠæå°éã®æš©éä»äžãéèŠã§ãããããã¯æå°æš©éã®ååãšåŒã°ãããCSPã§ã¯APIã«ããæäœãå¯èœã«ãªãããªãœãŒã¹ãžã®ãã现ããªã¢ã¯ã»ã¹å¶åŸ¡èšèšãå¯èœã§ããã现ããç²åºŠã§æå°æš©éãå®çŸã§ããäžæ¹ã§ãã¢ã¯ã»ã¹æš©ã®èšèšãéçšäžã®è² è·ãèããé«ãŸãå Žåãããããã®ãããCSPç°å¢ã®å©çšåœ¢æ ã«åãããŠæå°æš©éã®ç²åºŠãå€åãããããšãæšå¥šããã
äŸãã°ãéçºç°å¢ãšæ¬çªçžåœç°å¢ã§åããããªã¢ãããŒããæ¡çšããå¿ èŠã¯ãªããéçºç°å¢ã¯ä¿è·ãã¹ãããŒã¿ãååšããªãããã«æ§æããããŸããéçºäœæ¥ãé å»¶ãªãã¹ã ãŒãºã«ããšãã«ã¯è©Šè¡é¯èª€ããªããé²ããããããã«æ§æãããŠããå¿ èŠãããããã®ãããªã±ãŒã¹ã§ã¯çްããç²åºŠã®ã¢ã¯ã»ã¹å¶åŸ¡ã¯ç Žç¶»ããã
ããããå Žåã¯ãå€èŠçŽ èªèšŒã®èšå®ããã°ã®ååŸãªã©ã®ã»ãã¥ãªãã£æ©æ§ã倿Žãããªããããªå¿ èŠæäœéã®å¶éã宿œããã
äžæ¹ã§ãæ¬çªçžåœç°å¢ã«ã€ããŠã¯èæ ®ããäœå°ããããæ¬çªçžåœç°å¢ãšããŠéçšãããŠããå Žåããã®éçšæ¥åã¯å€§ãããå®åçãªå 容ããšãéå®åçãªå 容ãã«åé¡ãããã
- å®åçãªå 容ïŒãµãŒãã¹ã®ç£èŠãªã©ãã·ã¹ãã ã®å®å®çãªç¶æãç®çãšããäœæ¥å 容ãæç¢ºãªéçšæ¥å
- éå®åçãªå 容ïŒãã©ãã«ã·ã¥ãŒãã£ã³ã°ãªã©ãäœæ¥å 容ãèŠå®ã§ããªãéçšæ¥å
ãå®åçãªå 容ãã«ã€ããŠã¯äœæ¥å 容ãæç¢ºã§ããããã现ããç²åºŠã®ã¢ã¯ã»ã¹å¶åŸ¡èšèšãå¯èœãšèããããããéå®åçãªå 容ãã«ã€ããŠã¯äœæ¥å 容ãäºåã«äºæž¬äžå¯èœãªãããæéçãªåŒ·ãæš©éã®ä»äžãèãããããå³å¯ãªã¢ã¯ã·ã§ã³åäœã®èšèšãè¡ããªãåé¢ãå¿ èŠã«å¿ããŠçºèŠççµ±å¶ã®èгç¹ããäœæ¥ãæ£ããè¡ãããŠããã®ããç¹æ€ããã
ãã®ããã«ç°å¢ããŠãŒã¹ã±ãŒã¹ãæ³å®ããªããã¡ãªããªãã€ããŠæå°æš©éã®ç²åºŠã䜿ãåããããšãæšå¥šããã
å³003-Eãç°å¢å¥ã®æå°æš©éã¢ãããŒããšçºèŠççµ±å¶ã«ããè£å®äŸ
éä¿¡ã®éå®ãšæå·å
HTTPãFTPãªã©ã®æå·åãããŠããªãéä¿¡ã§ã¯çèŽãæ¹ããã®ãªã¹ã¯ãããããã䜿çšããªããVPCå€éšãšã®éä¿¡ã¯éåç¶²ã§ãã£ãŠãHTTPSãSFTPãªã©ã®æå·åãããéä¿¡ã«éå®ãããVPCå
éšã®éä¿¡ãæå·åãæšå¥šããã
ã¹ãã¬ãŒãžã«ä¿åãããããŒã¿ã®ãã¡ãæ©å¯æ§ã®é«ããã®ã«é¢ããŠã¯ãæå·åãè¡ãããŸããèªèšŒæ
å ±ãAPIããŒãªã©ã®ã·ãŒã¯ã¬ããã¯ã³ãŒãå
ãç°å¢å€æ°ã«ä¿åãããCSPãæäŸããã·ãŒã¯ã¬ãã管çãµãŒãã¹ã«ä¿åããã
HTTPSã䜿çšããéã«ãµãŒãèšŒææžãå¿
èŠã«ãªãããCSPãæäŸãããµãŒãèšŒææžã®èªåæŽæ°ãµãŒãã¹ãæ£ããåäœãããèšŒææžã®æå¹æéåãã§ã¢ã¯ã»ã¹äžèœãšãªãã±ãŒã¹ããããèªåæŽæ°ãµãŒãã¹ã䜿çšããå Žåã¯æ£ããåäœããããšã確èªããäžã§éçšããããšã
ä¿ç®¡ããŒã¿ã®æå·å
ã¬ãã¡ã³ãã¯ã©ãŠãã«ãããããŒã¿ã®æå·åã§ã¯ååãšããŠå©çšã·ã¹ãã ã®ç®¡çè ãäž»äœçã«ç®¡çã§ããæå·éµïŒäŸïŒã«ã¹ã¿ããŒãããŒãžãããŒïŒã®å©çšãåŒ·ãæšå¥šãããããã«ãã以äžãå®çŸã§ããããã«ãªãã
- æå·éµãžã®ã¢ã¯ã»ã¹ãã°ã®ååŸ
- æå·éµãžã®çްããªã¢ã¯ã»ã¹å¶åŸ¡
- æç€ºçãªæå·éµã®äœæâ§åé€ãšãã®ãã°ã®ååŸ
æå·å察象ãšããŠã¯ãããŒã¿ããŒã¹ãã¹ãã¬ãŒãžã®ãµãŒãã¹ãOSã«ããŠã³ãããã¹ãã¬ãŒãžçãæ¥åããŒã¿ãä¿ç®¡ãããé åãã¹ãŠãšãªããå©çšçµäºæã®ããŒã¿æ¶å»ã«ã€ããŠã¯ãã¯ã©ãŠãäºæ¥è èªèº«ãNIST SP 800-88 ãªã©ã®åœéçãªããŒã¿æ¶å»åºæºã«æºæ ããæ¹åŒã§å®æœããŠããããšãç£æ»å ±åããŠããå Žåããããã®ã®ãããšãã°ãNISCãæ¿åºæ©é¢çã®ãµã€ããŒã»ãã¥ãªãã£å¯Ÿçã®ããã®çµ± åºæºçŸ€ãã§èšäžåãããŠããã¯ã©ãŠãç°å¢ã«ããããæå·åæ¶å»ãã«ããå©çšçµäºããŒã¿ã®åé€ãè¡ãããå Žåã¯ããã®æå·éµç®¡çæ¹åŒãå¿ èŠãšãªãã
ãªããæå·éµã®äœæãéµãžã®ã¢ã¯ã»ã¹æš©ä»äžãªã©ã®ç®¡çã¯ãååãšããŠå©çšçµç¹åäœã§è¡ãããã ããè€æ°ã®å©çšçµç¹ã«ããã¯ã©ãŠãç°å¢ã®å ±åå©çšã«ãããŠã¯ãå ±åå©çšåäœã«ããæå·éµã®ç®¡çãšãããå ±åå©çšæã«ãããŠããã¢ã¯ã»ã¹å¶åŸ¡çã®æžå¿µãããå Žåã¯ãå©çšçµç¹æ¯ã«æå·éµã管çããããšã劚ãããã®ã§ã¯ãªãã
WAF/ãã¡ã€ã¢ãŠã©ãŒã«
- WAF
Webã¢ããªã±ãŒã·ã§ã³ãéçšããã«ãããããµã€ããŒæ»æãžã®å¯Ÿçãå¿ èŠãšãªããæ»æã®çš®é¡ã¯å€æ§åããŠãããã¢ããªã±ãŒã·ã§ã³ã®å®è£ ãããã«ãŠã§ã¢ã®èšå®ã§ã¯ã»ãã¥ãªãã£å¯Ÿçã«éçãããããã®ãããWebã¢ããªã±ãŒã·ã§ã³ã®åé¢éšã«WAFãé 眮ããããšãéèŠã§ããã - ãã¡ã€ã¢ãŠã©ãŒã«
ãªã³ãã¬ãã¹ã®å Žåããã¡ã€ã¢ãŠã©ãŒã«ã¯å€éšãšå éšã®ãããã¯ãŒã¯ã®å¢çã«é 眮ãããã¯ã©ãŠãã§ã¯ãŒããã©ã¹ãã®èãæ¹ã«åºã¥ããå éšããã®ã¢ã¯ã»ã¹ã§ãã£ãŠãä¿¡çšãããå¿ èŠãªIPãšããŒãã®ã¿èš±å¯ããã
ã
DDoS察ç
DDoSæ»æãžã®å¯Ÿçã¯ã以äžã®ãããªãã®ãããã
- æ»æå¯Ÿè±¡é åã®åæž
å€éšã«å ¬éããç®æãæå°éã«ãã1ãæã§ã®ä¿è·ã§æžãããã«ã·ã¹ãã ãæ§ç¯ããããŸããå ¬éããç®æãã³ã³ãã³ãé ä¿¡ãããã¯ãŒã¯(CDN)ãããŒããã©ã³ãµãŒã«ããããšã§ãã¢ããªã±ãŒã·ã§ã³ãžã®ãã©ãã£ãã¯ãå¶éããããšãã§ããã - ã¹ã±ãŒã©ããªãã£ã®ç¢ºä¿
å€§èŠæš¡ãªããªã¥ãŒã DDoSæ»æã«èããããã垯åãšãµãŒã容éã«æ¡åŒµæ§ãæãããã
ãããŒãžããµãŒãã¹ã®CDNã¯ãã©ãã£ãã¯éã«å¿ããŠã¹ã±ãŒã«ããããã垯åã®ç¢ºä¿ã«åœ¹ç«ã€ã
ãµãŒããŒå®¹éã¯è² è·ã«å¿ããŠèªåçã«æ¡å€§ãšçž®å°ããæ§æã«ããããšã§ãæ¡åŒµæ§ã確ä¿ããã - CSPãæäŸããDDoS察ççšãµãŒãã¹ãå©çšãã
CSPãDDoS察ççšã®ãµãŒãã¹ãæäŸããŠããå Žåããããå©çšããããšã§DDoSæ»æã軜æžã§ããã
ã
ãã«ãŠã§ã¢å¯Ÿç
ãã«ãŠã§ã¢å¯ŸçãšããŠããã«ãŠã§ã¢å¯Ÿç補åã®å°å ¥ã宿œããããã以ãŠå¯Ÿçå®äºãšããå Žåãããããããã ãã§ã¯äžååã§ãããæ¥åžžçã«è匱æ§å¯Ÿçã宿œããŠãã«ãŠã§ã¢ææãªã¹ã¯ã軜æžããããšãäžå¯©ãªåãããã£ãå Žåã¯éããã«æ€ç¥ããå¯åçéããã«å¯ŸåŠããããšãéèŠã§ããããã«ãŠã§ã¢å¯Ÿç補åã®å°å ¥ã¯ããããã£ã察çã®è£å®ãšããŠäœçœ®ä»ããå¿ èŠãããã
è匱æ§å¯Ÿçã宿œããäžã§ã®ãã«ãŠã§ã¢å¯ŸçãšããŠã¯ããŠã€ã«ã¹ããã«ãŠã§ã¢ãæ··å
¥ããããã¡ã€ã«ïŒTextãCSVã§ã¯ãªããã€ããªãŒãã¡ã€ã«çïŒãéãããŠããçµè·¯ãååšããå Žåã¯ããã®ãã¡ã€ã«ãå®è¡ãããªãããã«åãæ±ããããªã¢ããªã±ãŒã·ã§ã³æ§æã«ããããããããããã¡ã€ã«ãå®è¡ã§ããOSäžã«ä¿åããå¿
èŠãããå Žåã¯ããã®OSã«ã€ããŠãµãŒãããŒãã£ã®ãŠã€ã«ã¹å¯Ÿçãœããã®å©çšãæ€èšãããäŸãã°ããã¡ã€ã«ã¢ããããŒããåãä»ããã¢ããªã±ãŒã·ã§ã³ã§ãããã¡ã€ã«ãçŽæ¥ãããŒãžãã¹ãã¬ãŒãžãµãŒãã¹ã«ä¿ç®¡ããããšã§ããã¡ã€ã«ãå®è¡ãããã¿ã€ãã³ã°ã¯ãªããªãã
ãŸããCSPã®ãµãŒãã¹ã§ãã«ãŠã§ã¢å¯ŸçãšããŠå©çšã§ãããã®ããããããããæŽ»çšããã
ä»®æ³ãµãŒããŒãå©çšããããã«ãŠã§ã¢ã掻åããŠå®å®³ãçºçããé åãååšããªãå Žåã¯ããã«ãŠã§ã¢å¯Ÿçã¯äžèŠãã³ã³ãããå©çšããŠããå Žåã¯read onlyã«ããããšã§å¯ŸåŠããããŸããæ¬æ¥ãããŒãžãã§ããã¹ãã¬ãŒãžãµãŒãã¹ãOSã®ãã¡ã€ã«ã·ã¹ãã ã«ããŠã³ããããµãŒãããŒãã£ãŒè£œåããããããã«ãŠã§ã¢å¯Ÿçãå¿ èŠãªãã€ã³ããå¢å ãããããéæšå¥šãšããã
è匱æ§å¯Ÿç
ä»®æ³ãµãŒããŒãã³ã³ãããå©çšããŠããã·ã¹ãã ã®å ŽåãOSãããã«ãŠã§ã¢ã®è匱æ§ã®æ
å ±ãåéããé©åãªã»ãã¥ãªãã£ããããé©çšããå¿
èŠãããã
ãŸããCSPãçšæããã»ãã¥ãªãã£è©äŸ¡ãµãŒãã¹ã䜿çšããè匱æ§ã®ãã§ãã¯ãè¡ãã
ä»®æ³ãµãŒããŒãã³ã³ãããå©çšããªããªã©ãè匱æ§å¯Ÿçã®å¯Ÿè±¡ãååšããªãå Žåã¯ãè匱æ§å¯Ÿçã¯äžèŠã
CI/CD
CI/CDãã€ãã©ã€ã³ããªããžããªããããã€å ã®ã³ã³ãããªã©ãã¢ããªã±ãŒã·ã§ã³ã®éçºãšãªãªãŒã¹ã«ãããããŠãŒã¶ãŒãå¶åŸ¡ããã»ãã¥ã¢åããããšã§ã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã確ä¿ããããŠãŒã¶ãŒå¶åŸ¡ã®å ·äœçãªæ¹æ³ã¯ãå€èŠçŽ èªèšŒã®äœ¿çšãã¢ã¯ã»ã¹å¶åŸ¡ãåç §ã
ãŸãããªãªãŒã¹æã®æ¿èªãããŒã«ã責任è ã®æ¿èªãå¿ èŠãšããããã»ã¹ãèšããããšã§ãã¬ãã¥ãŒãªãã§ãªãªãŒã¹ãè¡ãããããšã鲿¢ã§ããã
ã³ãŒãã«å«ãŸããè匱æ§å¯ŸçãšããŠããªãªãŒã¹åã«è匱æ§ã¹ãã£ã³ãè¡ãCSPãµãŒãã¹ãŸãã¯ãµãŒãã¹è£œåããã€ãã©ã€ã³ã«çµã¿èŸŒããæåã§è匱æ§ã¹ãã£ã³ãè¡ãå Žåã宿œæŒããçºçããããšããããããã€ãã©ã€ã³ã«çµã¿èŸŒãã å Žåã¯ãå¿ ã宿œãè¡ãããã
ãã°ã®ååŸãšåæ
ã·ã¹ãã éçšã®äžã§ãCSPãµãŒãã¹ãã¢ããªã±ãŒã·ã§ã³ãªã©ã®ãã°ã®ååŸã¯éèŠã§ãããé©åãªãã°ã®ååŸãšç®¡çãè¡ãããšã§ãã·ã¹ãã ã®å®å šæ§ãšä¿¡é Œæ§ã確ä¿ã§ããããã°ã¯ä»¥äžã®ãããªèгç¹ã§äœ¿çšãããã
- ã»ãã¥ãªãã£å¯Ÿç
ãŠãŒã¶ãŒã®ã¢ã¯ã»ã¹æ å ±ãæäœå±¥æŽãªã©ãã·ã¹ãã ã®ã»ãã¥ãªãã£ã«é¢ããæ å ±ãèšé²ããããäžæ£ã¢ã¯ã»ã¹ãæ å ±æŒæŽ©ãªã©ã®ã€ã³ã·ãã³ããçºçããå Žåã«ããã°ããåå ã®åæãå¯èœã§ããã - ãã©ãã«ã·ã¥ãŒãã£ã³ã°
ã·ã¹ãã ã«é害ãçºçããå Žåã«ããã°ãåæããããšã§åé¡ã®åå ãç¹å®ã§ããã - ããã©ãŒãã³ã¹ã®æ¹å
ãã°ããã·ã¹ãã ã®ããã©ãŒãã³ã¹ã«é¢ããæ å ±ãæœåºããããšã§ãããã«ããã¯ãè² è·ãéäžããŠããç®æãç¹å®ã§ããã該åœã®ç®æãæ¹åããããšã§ãã·ã¹ãã ã®æ¹åãæé©åãè¡ããã - ã»ãã¥ãªãã£èŠä»¶ã®éµå®
PCI DSSã®æºæ ãªã©ããã°ã®é©åãªä¿ç®¡ãèŠä»¶ãšãªãå Žåãããã
æ§æå€æŽã®èšé²ãšèªåæ€ç¥
ã·ã¹ãã ã®æ§ææ å ±ã«å€æŽããã£ãå Žåã倿Žããã£ãããšã®èªåæ€ç¥ããããããªã·ãŒã«é©åããå 容ã§ããããèªåãã§ãã¯ããçµæã管çè ã«éç¥ããã·ã¹ãã ãæ§ç¯ããããŸããæ§ææ å ±ã®å±¥æŽãæ®ããéå»ã®æ§æã«æ»ããç¶æ ã«ããŠããã
ãã³ãããŒã¯/ãã¹ããã©ã¯ãã£ã¹èªåãã§ãã¯
ã·ã¹ãã ãã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ã«é©åããŠãããã確èªããããã®ããŒã«ããµãŒãã¹ãå©çšããå¿ èŠã«å¿ããŠä¿®æ£ãè¡ãã代衚çãªãã³ãããŒã¯ã«ã¯CIS BenchmarksããããåCSPçšã®ãã³ãããŒã¯ãçšæãããŠãããCSPãç¬èªã®ãã¹ããã©ã¯ãã£ã¹ã«é©åããŠããã確èªããããã®ãµãŒãã¹ãæäŸããŠããå Žåã¯ã䜵ããŠå®æœãè¡ãã
AIã«ããäžæ£èªåæ€åº
äžæ£è¡çºã®æ¹æ³ã¯åžžã«å€åããŠãããäžå®ã®ã«ãŒã«ããã¿ãŒã³ãããã³ã°ã«ããæ€åºã§ã¯æ€åºçãäœãããŸãã誀æ€ç¥ãå€ããªãããã察å¿ãšããŠäžååã§ãããAIãçšããããšã§ææ°ã®äžæ£è¡çºã«ãèªåãã€è¿ éã«å¯Ÿå¿å¯èœã«ãªãã
éçš
宿çãªæ¹å掻å
ã»ãã¥ãªãã£æ°Žæºãä¿ã€ããã«ã¯ãæ¥ã ã®éçšã®äžã§åé¡ç¹ã®æ€åºãšå¯Ÿå¿ãè¡ããæ¹åããŠããããšãéèŠãšãªããå ·äœçãªå 容ã«ã€ããŠã¯æè¡ããã¥ã¢ã«ãçºèŠççµ±å¶å 容説æãã®ãçºèŠæã®ã¢ã¯ã·ã§ã³ããåç §ã
ãã³ãã¬ãŒã/IaCãã¡ã€ã«ã䜿ã£ãŠæ§ç¯ããããšã§å®çŸãããã»ãã¥ãªãã£
æåã«ããæ§ç¯ãè¡ãå Žåãšæ¯èŒãããã³ãã¬ãŒã/IaCãã¡ã€ã«ã䜿ã£ãèªåæ§ç¯ã§ã¯äºåãã§ãã¯ã«ããèšå®ãã¹ã®è»œæžãäœæ¥äººå¡ãæžããããšã«ããæ¬çªçžåœç°å¢ã®ã»ãã¥ãªãã£ãªã¹ã¯ã®è»œæžãªã©ã®ãã»ãã¥ãªãã£äžã®ã¡ãªããããããæ¬é ã§ã¯ããããã®ã¡ãªããã«ã€ããŠèšè¿°ããã
ãã¹ããã©ã¯ãã£ã¹ãå«ããµã³ãã«IaCãã¡ã€ã«ã®å©çš
ã¬ãã¡ã³ãã¯ã©ãŠãããæäŸãããµã³ãã«IaCãã¡ã€ã«ã¯ãã¹ããã©ã¯ãã£ã¹ãçµã¿èŸŒãã§äœæããŠããããããããŒã¹ãšããŠå©çšããã°ã»ãã¥ãªãã£ã®æ¬ é¥ãå°ãªãã·ã¹ãã ã®æ§ç¯ãå¯èœã§ããã
äºåãã§ãã¯ã«ããæ¬ é¥ã®æ©æçºèŠ
ã·ã¹ãã æ§ç¯åã«ãã³ãã¬ãŒãå 容ãã¬ãã¥ãŒããããšã«ãããèšå®ãã¹ãèæ ®æŒããªã©ã®æ¬ é¥ãäºåã«çºèŠã§ããæ©æå¯ŸåŠãå¯èœã«ãªãã
èªåæ§ç¯ã«ãããã¹ã®è»œæž
æåã§ã·ã¹ãã æ§ç¯ãè¡ãå Žåãèšå®ã®å ãšãªããã©ã¡ãŒã¿ã·ãŒãã«èª€ãããªãã£ããšããŠãããã¥ãŒãã³ãšã©ãŒã«ãããã¹ãçºçããå¯èœæ§ããããèªåæ§ç¯ã®å Žåã¯ããã³ãã¬ãŒãå 容éãã«æ§ç¯ãè¡ããããããèšå®ãã¹ãçºçããªãã
æ¬çªçžåœç°å¢ã®äººå¡åæžã«ããã»ãã¥ãªãã£ãªã¹ã¯ã®è»œæž
æåã§ã·ã¹ãã æ§ç¯ãè¡ãå Žåãããã«ãã§ãã¯ãªã©ã®ããã«äœæ¥æ åœè 以å€ã®äººå¡ãæ¬çªçžåœç°å¢ã«å ¥ãããšã«ãªãããã®åã®ã»ãã¥ãªãã£ã«ãŒããIDãçºè¡ããå¿ èŠãããããããã®ç®¡çãçŽå€±ãªã¹ã¯ãåæžã§ãããããã»ãã¥ãªãã£ãªã¹ã¯ã®è»œæžã«ãªãã
æãåºãæã«èªåçã«èšå®ãããäºé²çã»çºèŠççµ±å¶
ã¯ã©ãŠãã§ã¯èª€ã£ãèšå®ã«ããæå³ããªãæ
å ±ã®å€éšå
¬éãé¿ããã·ã¹ãã ãã»ãã¥ã¢ã«ä¿ã€ãããæ§ã
ãªèšå®ãæ£ããè¡ããç¶æããããšãéèŠãšãªãã
äºé²ççµ±å¶ãšã¯äžæ£ãªæäœãäºåã«é²æ¢ããããšã§ãããçºèŠççµ±å¶ãšã¯ãªãœãŒã¹ãäžæ£ãªç¶æ³ã«ãªã£ãŠããªãããç¶ç¶çã«ç£èŠãä¿®æ£ããæ©èœã§ããã
ã¬ãã¡ã³ãã¯ã©ãŠãã§ã¯ãäžèšã®äºé²ççµ±å¶ããã³çºèŠççµ±å¶ã®ä»çµã¿ãCSPãµãŒãã¹ããã³ãã³ãã¬ãŒãã«ãã£ãŠå®æœããã
詳现ã«ã€ããŠã¯æè¡ããã¥ã¢ã«ãäºé²ççµ±å¶å 容説æãããçºèŠççµ±å¶å 容説æããåç §ã
æ¹èšå±¥æŽ
| æ¹èšå¹Žææ¥ | æ¹èšçç± |
|---|---|
| 2023幎03æ27æ¥ | æ°èŠäœæ |
| 2023幎06æ12æ¥ | ããã°ã®ååŸãšåæããæ°èŠäœæ |
| ãè²¬ä»»å ±æã¢ãã«ããéä¿¡ã®éå®ãšæå·åããå€èŠçŽ èªèšŒã®äœ¿çšããä¿®æ£ | |
| 2024幎03æ01æ¥ | ãGCASèªèšŒã«ããCSPç°å¢ãžã®ã·ã³ã°ã«ãµã€ã³ãªã³ããCSP管çGUIãžã®æ¥ç¶å ã¢ã¯ã»ã¹å å¶åŸ¡ããæ°èŠäœæ |
| ãå€èŠçŽ èªèšŒã®äœ¿çšããä¿®æ£ | |
| ãã¢ã¯ã»ã¹å¶åŸ¡ãã®åç§°ãããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹å¶åŸ¡ãã«ä¿®æ£ãå 容远å | |
| ãéä¿¡ã®éå®ãšæå·åãã®äœçœ®ãä¿®æ£ | |
| 2024幎03æ29æ¥ | GCAS-SSOé害æã®å¯Ÿå¿ã«é¢ããåç §å ã®ä¿®æ£ |
| 2024幎04æ04æ¥ | ãå³003-aãGCASã·ã³ã°ã«ãµã€ã³ãªã³æŠèŠãä¿®æ£ |
| 2024幎05æ10æ¥ | æèšä¿®æ£ |
| 2024幎09æ02æ¥ | BCEãCEPã«åç§°å€æŽ |
| å€èŠçŽ èªèšŒã®è¡šãä¿®æ£ | |
| 2024幎10æ01æ¥ | æèšä¿®æ£ |
| 2025幎03æ07æ¥ | ãä¿ç®¡ããŒã¿ã®æå·åããæ°èŠäœæ |
| 2025幎04æ23æ¥ | ãGCAS-SSOé害æã®å¯Ÿå¿ãä¿®æ£ |
| 2025幎04æ30æ¥ | ãã¬ãã¡ã³ãã¯ã©ãŠãäžã®ã·ã¹ãã ã§èããã¹ãèªèšŒã®äŸç€ºã远å |
| ãCSPå¥ GCAS-SSOé害æã®å¯Ÿå¿æ¹éãã®è¡šã®ä¿®æ£ | |
| ãå³003-CãCEPãå©çšããã¢ã¯ã»ã¹å ã®å¶åŸ¡ã€ã¡ãŒãžãã®ä¿®æ£ | |
| 2025幎05æ21æ¥ | ãä¿ç®¡ããŒã¿ã®æå·åãä¿®æ£ |
| 2025幎07æ25æ¥ | ãã³ãã¬ãŒãã®åç§°å€æŽã«äŒŽãä¿®æ£ |
| 2025幎07æ28æ¥ | ãâ»CSPå¥ GCAS-SSOé害æã®å¯Ÿå¿æ¹éãä¿®æ£ |
| 2025幎10æ17æ¥ | GCASç§»è¡åã®èšèŒã®åé€ |
| 2026幎02æ12æ¥ | ã·ã¹ãã èªèšŒã®OCIã®ãµãŒãã¹åã®ä¿®æ£ |