èšæ¶ã«æ°ããããã€ãã®å€§èŠæš¡ãªããŒã¿äŸµå®³ã¯ãå€èŠçŽ èªèšŒïŒMFAïŒãåé¿ããŸãããMFAã®æ§ææ¹æ³ãæ»æãããããŠãŒã¶ãŒã«å¯ŸããŠããã³ããã倿°è¡šç€ºããããprompt-bombingããè¡ã£ããããµãã³ã³ãã©ã¯ã¿ãŒãæ»æãããããããšã§ãLAPSUS$ãåœå®¶äž»å°ã®ãšãŒãžã§ã³ãã¯ãã¢ã€ãã³ãã£ãã£ã©ã€ããµã€ã¯ã«ã®åŒ±ç¹ãæ»æããããŒã¿ãæã¡åºãããªãMFAãæåã®é²åŸ¡ã©ã€ã³ã§ããã¹ããã瀺ããŸããããæçµã®ææ®µã§ã¯ãªãããšãæããã«ããŸããã
ãããã®æ»æã«ã€ããŠã¯ãæè¿è¡ããããŠã§ãããŒã§ãããã詳ãã説æããŸããã ãªã³ããã³ãã§èŠèŽã§ããŸããæ»æã®æ§é ã詳ãã解説ããäžã§ãè åšè ã䜿çšããææ³ãæ»æã®æå£ã説æããŸããã
ãã®ãŠã§ãããŒã§ã¯ãå€ãã®è³ªåãããã ããŸãããåå è ããç°ãªãèªèšŒèŠçŽ ã®çžå¯ŸçãªåŒ·ã¿ããŒããã©ã¹ãããã¹ã¯ãŒãã¬ã¹ãªã©ã«é¢ããçŽ æŽããã質åãããã ããŸããã以äžã¯ã察å¿ããããªãã£ã質åãšãæéåãã«ãªããªãã£ãå Žåã«å ±æããã§ãããåçãšãªããŸãã
A: ãã®åãã¯ä»åŸãè°è«ãããã§ãããè峿·±ãåé¡ã§ãããã¹ã¯ãŒããšPINã¯ãããããç¥ã£ãŠãããã®ããšããèªèšŒã«ããŽãªãŒã«å±ãããã®ãããã£ãã·ã³ã°æ»æã®å¯Ÿè±¡ã«ãªããŸãããã¹ã¯ãŒãã«æ¯ã¹ãŠãPINã¯äžè¬çã«çãé·ãã§å¶éãããæåã»ããã䜿çšããŸãããããã£ãŠãæ å ±çè«çãªèгç¹ããèŠããšããšã³ããããŒçã«ã¯PINã¯ãã¹ã¯ãŒãããã 匱ã ãšèšããŸããããªãã¡ãéžæè¢ã®æ°ãå€ãã»ã©ããã¹ã¯ãŒããPINããã«ãŒããã©ãŒã¹æ»æããå®ãã®ã¯é£ãããªããŸãã
ããããããã¯ç©èªã®äžéšã«éããŸããããã¹ã¯ãŒããšã¯ç°ãªããPINïŒå°ãªããšãNIST SP800-63ã§å®çŸ©ãããPINïŒã¯ ããŒã«ã«ã§æ€èšŒãããŸããããã¯ãPINãäžåºŠãéä¿¡ããããéäžåã®ãªããžããªã«æ ŒçŽãããªãããšãæå³ããŸããããã«ãããPINã¯ã¹ããã·ã¥ã¢ã³ãã°ã©ãæ»æã§ååãŸãã¯çãŸããå¯èœæ§ãã¯ããã«äœããªããŸãã
ããããããšã§ãããã»ãã¥ãªãã£ã®å šäœçãªå§¿å¢ã«å¯ŸããŠããããã³ã«ãæè¡ãããç°å¢ãèšå®ãããã³ãŠãŒã¶ãŒæè²ã倧ããªåœ±é¿ãäžããããšããããŸãã
A:ããã§ã€ã«ãªãŒãã³ãã·ã¹ãã ãšã¯ãéåžžã®éçšå¶åŸ¡ãæ©èœããªãå Žåã«ããã©ã«ãã§éããç¶æ ã«ãªãã·ã¹ãã ã®ããšãæããŸããããã¯ç©ççãªã»ãã¥ãªãã£ã«ãããéèŠãªå®å šãå®ãããã®ååã§ãïŒäŸïŒç«çœãçºçããå Žåããã¹ãŠã®å€éšãã¢ã¯ããã«è§£é ãããã¹ãã§ãïŒããããéèŠãªè³ç£ãžã®ã¢ã¯ã»ã¹ãä¿è·ããéã«ã¯æãŸãããããŸããã
NGOã®å©çšã±ãŒã¹ã§ã¯ãæ»æè ã¯ããŒã«ã«ã·ã¹ãã ãšã¯ã©ãŠãããŒã¹ã®MFAãããã€ããŒãšã®éä¿¡ã劚ããããšã§è³ç£ãžã®ã¢ã¯ã»ã¹ãã§ããŸãããããã«ãããMFAã®å¶åŸ¡ãè¿åãã广ããããŸããããããå¯èœã ã£ãã®ã¯ãå°å ¥ãããŠããã¢ã€ãã³ãã£ãã£ãœãªã¥ãŒã·ã§ã³ãããã§ã€ã«ãªãŒãã³ãã®ã»ãã¥ãªãã£å§¿å¢ã«ããã©ã«ãã§ãªã£ãŠããããã§ãã
ã·ã¹ãã ãããŠãŒã¶ãŒãæé€ããããšãªãããã®åé¡ãåé¿ããæ¹æ³ãããã€ããããŸãã1ã€ç®ã¯ãã€ã³ã¿ãŒãããã®é害ãçºçããå Žåã«ããŒã«ã«ïŒãªã³ãã¬ãã¹ïŒããŒãã«ãã©ãŒã«ããã¯ã§ãããã€ããªããèªèšŒã·ã¹ãã ãæ¡çšããããšã§ãã2ã€ç®ã¯ããªãã©ã€ã³ã§æ€èšŒã§ããèªèšŒã·ã¹ãã ãæ¡çšããããšã§ããRSA ID Plusã¯äž¡æ¹ã®ãªãã·ã§ã³ããµããŒãããŠããŸãã
A:ããç§ããRSA ID Plusã以å€ã®äœããçããå Žåãå€åä»äºã倱ãããšã«ãªããšæããŸãã
ããããçå£ãªè©±ãšããŠãããã€ãã®ç¹ãèæ ®ããå¿ èŠããããŸãããŸã第äžã«ããã®ãã³ããŒã¯å®çžŸãæã£ãŠããŸããïŒç¬¬äºã«ãã¢ã€ãã³ãã£ãã£ã¯åœŒãã®äž»èŠãªäºæ¥é åãªã®ãããããšã圌ããè¡ãå€ãã®æŽ»åã®äžã€ãªã®ãïŒç¬¬äžã«ããã¶ã€ã³ã®æ±ºå®ã«ãããŠãã³ããŒã¯äŸ¿çãåªå ããã®ããã»ãã¥ãªãã£ãåªå ããã®ãïŒç¬¬åã«ããã®ãœãªã¥ãŒã·ã§ã³ã¯åºç¯ãªãŠãŒã¶ãŒããŠãŒã¹ã±ãŒã¹ããµããŒãããæè»æ§ãæã£ãŠãããããŒã¿ã»ã³ã¿ãŒå éšã«ããè€éãªæ§åŒã¢ããªã±ãŒã·ã§ã³ãå«ããŠå¯Ÿå¿ã§ãããïŒãããŠæåŸã«ãåé¡ãçºçããå ŽåïŒãããŠåé¡ã¯èµ·ããã§ãããïŒããã³ããŒã¯å®å šãªéææ§ãæã£ãŠèªèããã®ãããããšãäºæ ãããŸãããŠè²¬ä»»è»¢å«ãããã®ãïŒ
ã»ãã¥ãªãã£ã¯ç°¡åã§ã¯ãªããè åšè ã¯æ»æå¯Ÿè±¡ã®äžã§ã ã¢ã€ãã³ãã£ã㣠ãä»ã®ã©ã®éšåãããçã£ãŠããŸããçµç¹ã¯ããããçè§£ããIDPïŒã¢ã€ãã³ãã£ãã£ãããã€ããŒïŒãå¿ èŠã§ãã
A:ãŒããã©ã¹ããããã¯ãŒã¯ã¢ã¯ã»ã¹ïŒZTNAïŒã¯ãä¿¡é Œã¯ãŠãŒã¶ãŒã®ããŒã«ã«ã€ã³ãã©ããããžã®æ¥ç¶ã ãã«åºã¥ããŠèªåçã« ä»®å®ããã ã¹ãã§ã¯ãªããšããååã«åºã¥ããã³ã³ã»ããã§ãããŠãŒã¶ãŒã¯ç¶ç¶çã«èªèšŒãããç¹å®ã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããèš±å¯ãæã¡ããã®ããã®æ£åœãªçç±ãå¿ èŠã§ãã
çŸåšåžå Žã«ã¯å€ãã®ããŒããã©ã¹ãã補åããããŸãããéèŠãªã®ã¯ãZTNAã¯æŠå¿µçãªæ çµã¿ãšãã¹ããã©ã¯ãã£ã¹ã®ã»ããã§ãããšããããšã§ãã æè¡ ãã©ã®ããã«æŽ»çšããããªã·ãŒãå®çŸ©ãããšã³ã·ã¹ãã ã管çãããã«ãã£ãŠãZTNAã®å§¿å¢ã決ãŸããŸããæè¡ã¯ç¢ºãã«åœ¹ç«ã€ããšããããŸãããã©ã®ãã³ããŒãèªåãã¡ã®è£œåãZTNAæºæ ã«ãããšèšã£ãŠããå¥ã®éžæè¢ãæ¢ããæ¹ãè¯ãã§ãããã
ãããŒããã©ã¹ãã«ã€ããŠè©³ããåŠã³ããã®ã§ããã°ãç§ã¯NIST SP800-207ã§å®çŸ©ãããŠãããŒããã©ã¹ãã®7ã€ã®ååããå§ããããšãããããããŸãã
A:Apple Face IDã®ãããªéžæè¢ãã¢ãã€ã«ãŠãŒã¶ãŒã«ã»ãŒæ®åããŠããäžã§ããã€ãªã¡ããªã¯ã¹ã¯ç¢ºãã«äººæ°ã®ãããã¹ã¯ãŒãã¬ã¹èªèšŒåœ¢åŒã§ããããã¡ããå¯äžã®ãã®ã§ã¯ãããŸãããFIDO2ã¯ãæ¶è²»è åãããã³äŒæ¥åãã®ãŠãŒã¹ã±ãŒã¹ã®äž¡æ¹ã§ãŸããŸãäžè¬çãªéžæè¢ãšãªã£ãŠããŸããQRã³ãŒããBLEãNFCãªã©ã®éæ¥è§Šåã®æ¹æ³ãäžéšã§äœ¿çšãããŠããŸãããèŠæš¡ã¯å°ããã§ãããŸããŸããã¹ããŒãã«ãŒã«ãæ©æ¢°åŠç¿ãè¡ååæãªã©ã®AIååããèªèšŒã®äžå¯èŠã®èŠçŽ ãšããŠãã»ãšãã©ãŠãŒã¶ãŒããªã¯ã·ã§ã³ãå°å ¥ããªããã»ãšãã©å°å ¥ããªãæ¹æ³ãšããŠã¢ã€ãã³ãã£ãã£ã®ä¿¡é Œæ§ãããã«åäžãããããã«äœ¿çšãããŠããŸããRSA ID Plusã¯ãããã®ãã¹ãŠã®ãªãã·ã§ã³ã仿¥ãµããŒãããŠããŸãã
A: ããã3ã€ã®æ»æã¯ãã¹ãŠããã¢ã€ãã³ãã£ãã£ïŒã¢ã¯ã»ã¹ç®¡çããæä»£é ãã®çšèªã§ã¯ãªãã«ãããäžååãªçšèªã§ããããšã瀺ããŠãããšæãã
ãããã®æ»æã¯ãç§ãã¡ãåã«ã¢ã€ãã³ãã£ãã£ã管çããã ãã§ãªããä¿è·ããå¿ èŠãããããšã匷調ããŠããŸããããšãã°ãã¢ã¯ã»ã¹ãããããžã§ãã³ã°ããã ãã§ã¯äžååã§ããæã ã¯ããŠãŒã¶ãŒãã¢ã¯ã»ã¹ãå¿ èŠãšãããïŒããšããåãããå§ããã¹ãã§ããããå¿ èŠãªããã©ããããã®æéã¢ã¯ã»ã¹ãå¿ èŠãïŒéå°ãªã¢ã¯ã»ã¹ãæäŸããŠããŸã£ãã®ãããããšãã¡ããã©ååãªã¢ã¯ã»ã¹ãæäŸããã®ãïŒã©ã®ããã«ããŠãããç¥ãããšãã§ããã®ã§ããããïŒå€ãã®å Žåã管çè ã¯ã©ã¡ããã®æ¹æ³ãç¥ããªããããŸãã¯ã©ã®ããã«èª¿ã¹ãããåãããªããšæããŸãã
è åšè¡çºè ã¯ãã¢ã€ãã³ãã£ãã£ã管çãã以äžã®åŽé¢ãååšããããšãçè§£ããŠããŸããç§ã調æ»ããæ»æã¯ããµã€ããŒç¯çœªè ãIAMãèæ ®ããŠããªãã®ã£ãããæ»æããæ¹æ³ã瀺ããŠããŸããç§ã¯ãçµç¹ã®ã¢ã€ãã³ãã£ãã£ã«å¯Ÿããçè§£ããå®å šãªã¢ã€ãã³ãã£ãã£ã©ã€ããµã€ã¯ã«ãèæ ®ããä¿è·ããããã«æ¡å€§ããå¿ èŠããããšèããŠããŸãã
ããæè¡çãªèгç¹ããèŠããšãç§ã¯AIãèšå€§ãªèªèšŒãæš©éãäœ¿çš ããŒã¿ãåŠçããéã«å€§ããªåœ¹å²ãæãããšèããŠããŸãã现ããããŒã¿ãçŽ æ©ãå€§èŠæš¡ã«è©äŸ¡ã§ããã€ã³ããªãžã§ã³ããªãã©ãããã©ãŒã ãæã€ããšã¯ãçµç¹ã®ã»ãã¥ãªãã£ãä¿ã€äžã§æ¬åœã®è³ç£ãšãªãã§ãããã
A:SecurIDãšYubiKeyã¯ãããããã®ã«ããŽãªã§ãããã¯ã©ã¹ã®èªèšŒæ©åšã§ãããããŠè¯ããã¥ãŒã¹ã¯ãRSA ID Plusã¯äž¡æ¹ããµããŒãããŠããããšã§ãïŒä»ã«ãå€ãã®èªèšŒãªãã·ã§ã³ããããŸãïŒã
ç¹å®ã®ãã³ããŒã®è©³çްããäžæ©åŒããŠèãããšãOTPãšFIDOèªèšŒåšããããã«ç¬èªã®å©ç¹ããããŸããFIDOã¯ãŠã§ãããŒã¹ã®ãã°ã€ã³ã«ãããŠå®å šã§äŸ¿å©ãªéžæè¢ãšããŠäººæ°ãé«ãŸã£ãŠããŸããããœãããŠã§ã¢ããŒã¹ã®FIDOãªãã·ã§ã³ã¯ãŸã éå®çãªæè»æ§ããæã£ãŠããããããŒããŠã§ã¢ããã€ã¹ã¯ãã°ãã°ç©ççãªæ¥ç¶ãå¿ èŠã§ããããŠã§ããã©ãŠã¶ä»¥å€ã§ã®FIDOã®çã®ãµããŒãã¯ã»ãšãã©ååšããŸãããäžæ¹ãOTPã¯ã»ãŒã©ãã§ãåäœãããšããå©ç¹ããããŸããããŒããŠã§ã¢ãŸãã¯ãœãããŠã§ã¢äžã§ãå°çšã®ã¯ã©ã€ã¢ã³ããœãããŠã§ã¢ãç©ççãªæ¥ç¶ã¯å¿ èŠãããŸããã
ããããOTPãšFIDOãæ¯èŒããéãéåžžã¯ãANDããæåã®çãã§ãã RSA DS100 èªèšŒæ©åšã®ãããªãã€ããªããããã€ã¹ã¯ãäž¡æ¹ã®äžçã®ãã¹ããçµã¿åãããŠãããåäžã®ãã©ãŒã ãã¡ã¯ã¿ã§OTPãšFIDO2ãæäŸããããšã§ãæå€§éã®æè»æ§ãšå¹ åºããµããŒããæäŸããŠããŸãã