ã2026幎çããµã€ããŒã»ãã¥ãªãã£ã®å§ãæ¹ â ITé²åŸ¡ã¹ãã«ã®ç¬¬äžæ©ãå®å šã¬ã€ã
ãµã€ããŒã»ãã¥ãªãã£ã£ãŠããèããã©ããªãã§ãããªã«å€§äºã£ãŠèšãããŠãã®ïŒ
ããŸãäŒæ¥ãå人ãããããªãã§ã¯ç掻ã§ããªãæä»£ã ããããã®è£ã§ããµã€ããŒæ»æã¯å¹Žã å¢ããŠããŠãäžçäžã§ã»ãã¥ãªãã£äººæãå§åçã«äžè¶³ããŠãããã ãæ¥æ¬ã ãã§ãæ°äžäººèŠæš¡ã§è¶³ããªããšèšãããŠããŠãéèŠããã®ãããé«ãåéãªãã ãã
ãããªã«è¶³ããŠãªããã ïŒã§ãã»ãã¥ãªãã£ã£ãŠé£ãããâŠããŸãäœããç¥ãã°ããã®ïŒ
ãŸãã¯ãCIA triadïŒCIAã®äžèŠçŽ ïŒããæŒãããããConfidentialityïŒæ©å¯æ§ïŒã¯æ å ±ãèš±å¯ããã人ã ããèŠãããããšãIntegrityïŒå®å šæ§ïŒã¯æ å ±ãæ¹ãããããŠããªãããšãAvailabilityïŒå¯çšæ§ïŒã¯å¿ èŠãªãšãã«æ å ±ã«ã¢ã¯ã»ã¹ã§ããããšããã®3ã€ãã»ãã¥ãªãã£ã®åºæ¬äžã®åºæ¬ã ãã
CIAã£ãŠèããšã¹ãã€æ ç»ã¿ããïŒããããå®éã«ã©ããªæ»æãããã®ïŒ
代衚çãªãã®ã ãšããŸããã£ãã·ã³ã°ãæ¬ç©ãã£ããã®åœã¡ãŒã«ãåœãµã€ãã§ãã¹ã¯ãŒããçãæå£ã ããæ¬¡ã«ãã«ãŠã§ã¢ããŠã€ã«ã¹ãã©ã³ãµã ãŠã§ã¢ãªã©ãæªæã®ãããœãããŠã§ã¢ã®ç·ç§°ã ããããšã¯SQLã€ã³ãžã§ã¯ã·ã§ã³ãWebãµã€ãã®å ¥åæ¬ã«äžæ£ãªSQLæãéã蟌ãã§ãããŒã¿ããŒã¹ã®æ å ±ãæãåãæ»æããããã¯ä»ã§ã被害件æ°ããããã¯ã©ã¹ãªãã ã
æãâŠïŒããããæ»æããã©ããã£ãŠå®ãã®ïŒ
é²åŸ¡ã®åºæ¬ã¯3ã€ãããã1ã€ç®ã¯ãã¡ã€ã¢ãŠã©ãŒã«ããããã¯ãŒã¯ã®åºå ¥ãå£ã§äžå¯©ãªéä¿¡ããããã¯ãããéçªãã®ãããªååšã ãã2ã€ç®ã¯æå·åãããŒã¿ãèªããªã圢ã«å€æããŠãçãŸããŠãäžèº«ãåãããªãããã«ããæè¡ã3ã€ç®ã¯å€èŠçŽ èªèšŒïŒMFAïŒããã¹ã¯ãŒãã ããããªããã¹ããã®èªèšŒã¢ããªãSMSã³ãŒããªã©è€æ°ã®æ¹æ³ã§æ¬äººç¢ºèªããä»çµã¿ã ãã
ãªãã»ã©ïŒãããã»ãã¥ãªãã£ãå匷ããããšæã£ãããã©ãããé çªã§åŠã¹ã°ããã®ïŒ
ããããã®åŠç¿ããŒããããã¯ããã ãããŸããããã¯ãŒã¯ã®åºç€ïŒTCP/IPãDNSãHTTPãªã©ïŒãçè§£ãããæ¬¡ã«OSã®ä»çµã¿ïŒLinuxãWindowsã®åºæ¬æäœãã³ãã³ãã©ã€ã³ïŒãåŠã¶ããã®äžã§ã»ãã¥ãªãã£ããŒã«ïŒWiresharkãNmapãBurp Suiteãªã©ïŒã®äœ¿ãæ¹ãèŠããããããã¯ãŒã¯ãšOSãåãã£ãŠããªããšãæ»æãé²åŸ¡ãçè§£ã§ããªãããããã®é çªã倧äºãªãã ã
è³æ Œãšããåã£ãã»ããããã®ïŒããããã£ãŠããïŒ
è³æ Œã¯ã¹ãã«ã®èšŒæã«ãªãããåã£ãŠãããšæå©ã ããåœéçã«æåãªã®ã¯CompTIA Security+ã§ãã»ãã¥ãªãã£ã®åºç€ãç¶²çŸ çã«åŠã¹ãå ¥éè³æ Œã ããæ¥æ¬ã ãšæ å ±åŠçå®å šç¢ºä¿æ¯æŽå£«ïŒç»é²ã»ãã¹ãïŒãåœå®¶è³æ ŒãšããŠè©äŸ¡ãé«ããããŸãã¯Security+ããå§ããŠãå®åçµéšãç©ã¿ãªããç»é²ã»ãã¹ããç®æãã®ãããã«ãŒãã ãã
座åŠã ããããªããŠãå®éã«æãåãããŠç·Žç¿ã§ããå Žæã£ãŠããã®ïŒ
ãããïŒTryHackMeã¯åå¿è åãã®ã¬ã€ãä»ãã§ããã©ãŠã¶äžã§ãããã³ã°ã®æŒç¿ãã§ãããã©ãããã©ãŒã ãããå°ãå®åãã€ãããHack The Boxã«ãææŠããŠã¿ããšãããå®éã®è匱æ§ããããã·ã³ãæ»ç¥ããCTFïŒCapture The FlagïŒåœ¢åŒã§ãå®è·µåãããªãéãããããã
ã»ãã¥ãªãã£ã®ä»äºã£ãŠãå ·äœçã«ã¯ã©ããªãã£ãªã¢ãããã®ïŒ
äž»ãªãã£ãªã¢ãã¹ã¯3ã€ããããSOCã¢ããªã¹ãã¯ã»ãã¥ãªãã£ç£èŠã»ã³ã¿ãŒã§24æéäœå¶ã§è åšãæ€ç¥ã»å¯Ÿå¿ãã圹å²ããããã¬ãŒã·ã§ã³ãã¹ã¿ãŒïŒãã³ãã¹ã¿ãŒïŒã¯äŒæ¥ã«äŸé ŒãããŠã·ã¹ãã ã«æ¬äŒŒæ»æã仿ããè匱æ§ãèŠã€ããä»äºãã»ãã¥ãªãã£ãšã³ãžãã¢ã¯ã·ã¹ãã å šäœã®ã»ãã¥ãªãã£èšèšã»æ§ç¯ã»éçšãæ åœãããæªçµéšãããªãSOCã¢ããªã¹ããå ¥ãããããã
ãã¥ãŒã¹ã§ããŒããã€æ»æããšãããµãã©ã€ãã§ãŒã³æ»æãã£ãŠèããã©ãããã£ãŠäœãªã®ïŒ
ãŒããã€æ»æã¯ããœãããŠã§ã¢ã®è匱æ§ãçºèŠãããŠããä¿®æ£ããããåºããŸã§ã®ã0æ¥ç®ããçãæ»æã®ããšã察çãååšããªãç¶æ ã§æ»æãããããéåžžã«åä»ãªãã ããµãã©ã€ãã§ãŒã³æ»æã¯ãã¿ãŒã²ããäŒæ¥ãçŽæ¥æ»æããã®ã§ã¯ãªããååŒå ã䜿ã£ãŠãããœãããŠã§ã¢ã®éçºå ãçµç±ããŠäŸµå ¥ããæå£ã ãã2020幎ã®SolarWindsäºä»¶ãæåã§ãæ£èŠã®ã¢ããããŒãã«ãã«ãŠã§ã¢ãä»èŸŒãŸããŠãããã ã
ãã£ãæ£èŠã®ã¢ããããŒããå±éºã£ãŠããšãâŠïŒïŒããããè匱æ§ãèŠã€ããããéãããããã£ãŠèãããã ãã©æ¬åœïŒ
ããã¯ãã°ããŠã³ãã£ïŒè匱æ§å ±å¥šéïŒããã°ã©ã ã®ããšã ããGoogleãMicrosoftãAppleãªã©å€§æäŒæ¥ããèªç€ŸãµãŒãã¹ã®è匱æ§ãèŠã€ããŠå ±åããŠããããå ±å¥šéãæããŸãããšããå¶åºŠãèšããŠãããã ãå ±å1ä»¶ã§æ°åäžåãé倧ãªè匱æ§ãªãæ°åäžåã«ãªãããšãããããHackerOneãBugcrowdãšãã£ããã©ãããã©ãŒã ã§åå ã§ãããè ã磚ãã°å¯æ¥ã«ããªãããã»ãã¥ãªãã£ãã£ãªã¢ã®å®çžŸãšããŠãéåžžã«åŒ·åã ãã