ãã¹ã·ãªã·
è匱æ§è©äŸ¡ã¹ãã£ã³ããŒã«ãã¹ã5ïŒ2025幎XNUMXæïŒ
Unite.AI ã¯å³æ Œãªç·šéåºæºãéµå®ããŠããŸãã åœç€Ÿãã¬ãã¥ãŒãã補åãžã®ãªã³ã¯ãã¯ãªãã¯ãããšãåœç€Ÿã¯å ±é ¬ãåãåãå ŽåããããŸãã ãã²ã芧ãã ãã ã¢ãã£ãªãšã€ãé瀺.

ç©æ¥µçã«ç¹å®ããŠå¯ŸåŠãã èåŒ±æ§ çµç¹ã®ããžã¿ã«è³ç£ãä¿è·ããã«ã¯ãã»ãã¥ãªãã£å¯Ÿçãäžå¯æ¬ ã§ããè匱æ§è©äŸ¡ã¹ãã£ã³ããŒã«ã¯ããããã¯ãŒã¯ãã·ã¹ãã ãã¢ããªã±ãŒã·ã§ã³å šäœã«ãããã»ãã¥ãªãã£äžã®åŒ±ç¹ã®æ€åºãšåªå é äœä»ããèªååããããšã§ããã®ããã»ã¹ã«ãããŠéèŠãªåœ¹å²ãæãããŸãããããã®ããŒã«ã¯ãæ»æå¯Ÿè±¡é åãå æ¬çã«å¯èŠåããè匱æ§ãã¿ã€ã ãªãŒã«ä¿®åŸ©ããããšã§ãçµç¹ãæœåšçãªè åšã«å¯ŸããŠäžæ©å ãè¡ãããšãå¯èœã«ããŸãã
ãã®èšäºã§ã¯ãå©çšå¯èœãªæé«ã®è匱æ§è©äŸ¡ã¹ãã£ã³ ããŒã«ã®ããã€ãã«ã€ããŠèª¬æããŸããåããŒã«ã¯ãã»ãã¥ãªãã£ã匷åããããã®ç¬èªã®æ©èœãæäŸããŸãã ãµã€ããŒã»ãã¥ãªãã£ãŒ å§¿å¢ã
1. Tenable Nessus
ãµã€ããŒã»ãã¥ãªã㣠ãœãªã¥ãŒã·ã§ã³ã®å€§æãããã€ããŒã§ãã Tenable ã¯ãæ¥çã§æãåºãå°å ¥ãããŠããè匱æ§è©äŸ¡ã¹ãã£ããŒã® 20 ã€ã§ãã Nessus ãæäŸããŠããŸãã XNUMX 幎以äžã«ãããç¶ç¶çãªéçºãšæ¹åã«ãããNessus ã¯ãã®å æ¬çãªã¹ãã£ã³æ©èœãšæè»æ§ã§ç¥ãããããããèŠæš¡ã®çµç¹ã«ãšã£ãŠä¿¡é Œã§ããããŒã«ã«ãªããŸããã
Nessusã¯ã130,000äžãè¶ ãããã©ã°ã€ã³ãããªãåºç¯ãªããŒã¿ããŒã¹ã掻çšãããœãããŠã§ã¢ã®è匱æ§ãèšå®ãã¹ãã³ã³ãã©ã€ã¢ã³ã¹éåãªã©ãå¹ åºãã»ãã¥ãªãã£åé¡ãç¹å®ããŸãããã®èšå€§ãªãã©ã°ã€ã³ã©ã€ãã©ãªãšNessusã®ã·ãã¯ã¹ã·ã°ã粟床ãçµã¿åãããããšã§ãã¹ãã£ããŒã¯æ¥µããŠäœã誀æ€ç¥çãç¶æããŠããŸããNessusã®æè»ãªå°å ¥ãªãã·ã§ã³ã«ãããITãã¯ã©ãŠããã¢ãã€ã«ãIoTãOTè³ç£ãã¹ãã£ã³ããæ»æå¯Ÿè±¡é åå šäœãå æ¬çã«å¯èŠåã§ããŸãããªã³ãã¬ãã¹ãã¯ã©ãŠãããããã¯ããŒãããœã³ã³ã«å°å ¥ããŠããŒã¿ãã«ã¹ãã£ã³ãè¡ãå Žåã§ããNessusã¯åçµç¹ã®ç¬èªã®ããŒãºã«é©å¿ããŸãã
Tenable Nessus ã®äž»ãªæ©èœã¯æ¬¡ã®ãšããã§ãã
- å¹ åºããªãã¬ãŒãã£ã³ã° ã·ã¹ãã ãããã€ã¹ãã¢ããªã±ãŒã·ã§ã³ãã«ããŒãã 130,000 ãè¶ ãããã©ã°ã€ã³ã«ããå æ¬çãªè匱æ§ã¹ãã£ã³
- ã·ãã¯ã¹ã·ã°ã粟床ã«ãããäœã誀æ€ç¥çãšä¿¡é Œæ§ã®é«ãã¹ãã£ã³çµæãä¿èšŒããŸã
- çµç¹ã®ããŸããŸãªèŠä»¶ã«å¯Ÿå¿ããããã®ããªã³ãã¬ãã¹ãã¯ã©ãŠããã©ããããããªã©ã®æè»ãªå°å ¥ãªãã·ã§ã³
- è匱æ§åªå 床è©äŸ¡ (VPR) ã䜿çšããèªååªå é äœä»ããå³æä¿®åŸ©ãå¿ èŠãªæãéèŠãªåé¡ã匷調衚瀺ããŸãã
- ããã管çãSIEMããã±ããçºè¡ã·ã¹ãã ãšã®ã·ãŒã ã¬ã¹ãªçµ±åã«ãããå¹ççãªè匱æ§ç®¡çã¯ãŒã¯ãããŒãå¯èœã«ãªããŸãã
- è匱æ§ããŒã¿ãé¢ä¿è ã«å¹æçã«äŒéããããã®ã«ã¹ã¿ãã€ãºå¯èœãªã¬ããŒããšããã·ã¥ããŒã
2. ã€ã³ãã¯ãã£
Invicti (以å㯠Netsparker ãšããŠç¥ãããŠããŸãã) ã¯ãçµç¹ã Web ã¢ããªã±ãŒã·ã§ã³ãš API ãç¶ç¶çã«ã¹ãã£ã³ããŠä¿è·ã§ããããã«èšèšãããèªå Web ã¢ããªã±ãŒã·ã§ã³ ã»ãã¥ãªã㣠ã¹ãã£ããŒã§ãã Invicti ã¯ã粟床ãšå¹çã«éç¹ã眮ããã»ãã¥ãªã㣠ããŒã ã誀æ€ç¥ãæå°éã«æããªãããã¹ãäœæ¥ãæ¡å€§ã§ããããã«ããçã®ã»ãã¥ãªã㣠ãªã¹ã¯ãžã®å¯ŸåŠã«ãªãœãŒã¹ã確å®ã«æå ¥ã§ããããã«ããŸãã
Invictiã®éç«ã£ãæ©èœã®äžã€ã¯ãç¹å®ãããè匱æ§ã®æªçšå¯èœæ§ãèªåçã«æ€èšŒããProof-Based Scanningãã¯ãããžãŒã§ããInvictiã¯ãå¶åŸ¡ãããæ¹æ³ã§è匱æ§ãå®å šã«æªçšããããšã§ãSQLã€ã³ãžã§ã¯ã·ã§ã³ã«ããããŒã¿ããŒã¹åã®ååŸãªã©ãè匱æ§ã®ååšãæç¢ºã«èšŒæããŸãããã®ã¢ãããŒãã«ãããæåæ€èšŒãäžèŠã«ãªããã»ãã¥ãªãã£ããŒã ã®è²ŽéãªæéãšåŽåãç¯çŽã§ããŸãã
Invicti ã®äž»ãªæ©èœã¯æ¬¡ã®ãšããã§ãã
- AJAXãRESTful ãµãŒãã¹ãã·ã³ã°ã«ããŒãž ã¢ããªã±ãŒã·ã§ã³ãªã©ã®ææ°ã® Web ãã¯ãããžãŒãå«ããWeb ã¢ã»ããã®å æ¬çãªæ€åºãšã¹ãã£ã³
- Web ã¢ããªã±ãŒã·ã§ã³ãAPI (RESTãSOAPãGraphQL)ãWeb ãµãŒãã¹ã®ã¹ãã£ã³ããµããŒãããæ»æå¯Ÿè±¡é åã培åºçã«ã«ããŒããŸãã
- Proof-Based Scanning ãã¯ãããžãŒã«ããæ£ç¢ºãªèåŒ±æ§æ€åºã«ããã誀æ€ç¥ãæå°éã«æããæªçšå¯èœãªåé¡ã®å ·äœçãªèšŒæ ãæäŸããŸãã
- ãªã¹ã¯ã¬ãã«ã«åºã¥ããè匱æ§ã®èªåæ€èšŒãšåªå é äœä»ãã«ãããæãéèŠãªåé¡ã«éäžã§ããããã«ãªããŸã
- åé¡è¿œè·¡ããŒã«ãCI/CD ãã€ãã©ã€ã³ãã³ã©ãã¬ãŒã·ã§ã³ ããŒã«ãšã®çµ±åã«ãããã»ãã¥ãªã㣠ããŒã ãšéçºããŒã éã®å¹ççãªä¿®åŸ©ãšã³ã©ãã¬ãŒã·ã§ã³ãä¿é²ãããŸãã
- å®çšçãªä¿®åŸ©ã¬ã€ãã³ã¹ãã³ã³ãã©ã€ã¢ã³ã¹ ã¬ããŒã (PCI DSSãHIPAAãOWASP Top 10) ãå«ããæè¡è ãšçµå¶é£ã®äž¡æ¹ã察象ãšãã詳现ãªã¬ããŒã
ã€ã³ãŽã£ã¯ãã£ã蚪å â
3. ã¹ã¿ãã¯ããŒã¯
StackHawk ã¯ããœãããŠã§ã¢éçºã©ã€ããµã€ã¯ã« (SDLC) ã«ã·ãŒã ã¬ã¹ã«çµ±åããããã«èšèšãããææ°ã®åçã¢ããªã±ãŒã·ã§ã³ ã»ãã¥ãªã㣠ãã¹ã (DAST) ããŒã«ã§ãã StackHawk ã¯éçºè ã®æå¹åãšèªååã«éç¹ã眮ããŠããããšã³ãžãã¢ãªã³ã° ããŒã ãéçºããã»ã¹ã®æ©ã段éã§è匱æ§ãç¹å®ããŠä¿®æ£ã§ããããã«ããã¢ããªã±ãŒã·ã§ã³ ã»ãã¥ãªãã£ãžã®ã·ããã¬ãã ã¢ãããŒããä¿é²ããŸãã
StackHawkã®å€§ããªå·®å¥åèŠå ã®äžã€ã¯ãCI/CDãã€ãã©ã€ã³ããã³éçºè ã¯ãŒã¯ãããŒãšã®ç·å¯ãªçµ±åã§ããã·ã³ãã«ãªèšå®ãã¡ã€ã«ãæäŸããGitHub ActionsãGitLabãJenkinsãCircleCIãšãã£ãäž»èŠãªCI/CDãã©ãããã©ãŒã ããµããŒãããããšã§ãStackHawkã¯å®æçãªãã«ãããã³ãããã€ããã»ã¹ã®äžç°ãšããŠãèªåã»ãã¥ãªãã£ã¹ãã£ã³ãå¯èœã«ããŸãããã®çµ±åã«ãããéçºè ã¯ã»ãã¥ãªãã£åé¡ã«é¢ãããã£ãŒãããã¯ãã¿ã€ã ãªãŒã«åãåããè¿ éã«å¯ŸåŠããããšãã§ããŸãã
StackHawk ã®äž»ãªæ©èœã¯æ¬¡ã®ãšããã§ãã
- SQL ã€ã³ãžã§ã¯ã·ã§ã³ãã¯ãã¹ãµã€ã ã¹ã¯ãªããã£ã³ã° (XSS) ãªã©ã® OWASP ããã 10 è匱æ§ãå æ¬çã«ã¹ãã£ã³ããé倧ãªã»ãã¥ãªã㣠ãªã¹ã¯ã確å®ã«ã«ããŒããŸãã
- REST APIãGraphQLãSOAP Web ãµãŒãã¹ã®ã¹ãã£ã³ããµããŒãããææ°ã®ã¢ããªã±ãŒã·ã§ã³ ã¢ãŒããã¯ãã£ã®åŸ¹åºçãªãã¹ããå¯èœã«ããŸã
- ã€ã³ããªãžã§ã³ããªã¯ããŒãªã³ã°ãšã¢ããªã±ãŒã·ã§ã³ ãšã³ããã€ã³ãã®æ€åºã«ãããæ»æå¯Ÿè±¡é åãåºç¯å²ã«ã«ããŒããŸã
- äžè¬ç㪠CI/CD ããŒã«ããã³ãœãŒã¹ç®¡çãã©ãããã©ãŒã ãšã®ã·ãŒã ã¬ã¹ãªçµ±åã«ãããéçºãã€ãã©ã€ã³ã§ã®å®å šã«èªååãããã»ãã¥ãªã㣠ãã¹ããå¯èœã«ãªããŸã
- å¹ççãªè匱æ§ä¿®åŸ©ãä¿é²ãããcURL ã³ãã³ããå«ã詳现ãªåçŸæé ãå«ãéçºè åãã®ã¬ããŒã
- ã·ã³ãã«ãª YAML ãã¡ã€ã«ãéããŠã¹ãã£ã³æ§æãã«ã¹ã¿ãã€ãºã§ãããããã¹ãã£ã³åäœãšãã¹ã ãã©ã¡ãŒã¿ãŒããã现ããå¶åŸ¡ã§ããŸã
ã¹ã¿ãã¯ããŒã¯ã蚪å â
4. ãŠã£ãº
Wiz ã¯ãçµç¹ããã«ãã¯ã©ãŠãç°å¢ãä¿è·ããæ¹æ³ã«é©åœãããããã¯ã©ãŠããã€ãã£ãã®ã»ãã¥ãªã㣠ãã©ãããã©ãŒã ã§ãã Wiz ã¯ããšãŒãžã§ã³ãã¬ã¹ã®å±éãšçµ±åã¢ãããŒãã«ãããIaaSãPaaSãSaaS ãµãŒãã¹ãå«ãã¯ã©ãŠã ã¹ã¿ãã¯å šäœã«ããã£ãŠå æ¬çãªå¯èŠæ§ãšåªå é äœä»ãããããªã¹ã¯ã®æŽå¯ãæäŸããŸãã
Wizã®åªããæ©èœã®äžã€ã¯ãã¯ã©ãŠãã¹ã¿ãã¯å šäœãåæãããã¹ãŠã®ã¯ã©ãŠããªãœãŒã¹ãšãã®é¢ä¿æ§ãã°ã©ãåããæ©èœã§ãããã®Wiz Security GraphãæŽ»çšããããšã§ããã©ãããã©ãŒã ã¯è€éãªæ»æçµè·¯ãç¹å®ããæœåšçãªåœ±é¿åºŠã«åºã¥ããŠæãéèŠãªãªã¹ã¯ãåªå é äœä»ãã§ããŸãããã®ã³ã³ããã¹ãã«åºã¥ããåªå é äœä»ãã«ãããã»ãã¥ãªãã£ããŒã ã¯æãéèŠãªåé¡ã«éäžããããšãã§ããã¢ã©ãŒãç²ãã軜æžãã修埩å¹çãåäžãããããšãã§ããŸãã
Wiz ã®äž»ãªæ©èœã¯æ¬¡ã®ãšããã§ãã
- ãšãŒãžã§ã³ãã¬ã¹å±éãAPI çµç±ã§ã¯ã©ãŠãç°å¢ã«æ¥ç¶ãããšãŒãžã§ã³ãã®ã€ã³ã¹ããŒã«ãå¿ èŠãšããã«è¿ éãªäŸ¡å€å®çŸãå®çŸããŸãã
- ä»®æ³ãã·ã³ãã³ã³ããããµãŒããŒã¬ã¹æ©èœãã¯ã©ãŠã ãµãŒãã¹ãã«ããŒãããAWSãAzureãGCPãKubernetes ã«ãããå æ¬çãªå¯èŠæ§
- ã¯ã©ãŠãè³ç£å šäœã«ãããè匱æ§è©äŸ¡ã«ãããOS ãšãœãããŠã§ã¢ã®æ¬ é¥ãæ§æãã¹ãæŒæŽ©ããç§å¯ãIAM ã®åé¡ãªã©ãæ€åºããŸãã
- éå€§åºŠãæªçšå¯èœæ§ãããžãã¹ãžã®åœ±é¿ãªã©ã®èŠçŽ ãèæ ®ãããè匱æ§åªå 床è©äŸ¡ (VPR) ã«åºã¥ããªã¹ã¯ã®åªå é äœä»ã
- Wiz Security Graph ããåŸãããç¶æ³ã«å¿ãããªã¹ã¯ã®æŽå¯ãæ»æãã¹ãçã¿åºãå±éºãªãªã¹ã¯ã®çµã¿åããã匷調ããŸãã
- CI/CD ããŒã«ããã±ããçºè¡ã·ã¹ãã ãã³ã©ãã¬ãŒã·ã§ã³ ãã©ãããã©ãŒã ãšã®çµ±åã«ãããã·ãŒã ã¬ã¹ãªä¿®åŸ©ã¯ãŒã¯ãããŒãšã»ãã¥ãªã㣠ããŒã ãšéçºããŒã éã®ã³ã©ãã¬ãŒã·ã§ã³ãå¯èœã«ãªããŸãã
5. Nmapã®
Nmap (ãããã¯ãŒã¯ ããããŒ) ã¯ããããã¯ãŒã¯æ€åºãšã»ãã¥ãªãã£ç£æ»ã®æ¥çæšæºãšãªã£ãŠãã匷åãªãªãŒãã³ãœãŒã¹ ããŒã«ã§ãã Nmap ã¯ããã®å€çšéæ§ãšåºç¯ãªæ©èœã»ããã«ãããçµç¹ããããã¯ãŒã¯ ã€ã³ãã©ã¹ãã©ã¯ãã£ã«å¯Ÿããæ·±ãæŽå¯ãååŸããæœåšçãªè匱æ§ãç¹å®ããã·ã¹ãã ã®å šäœçãªã»ãã¥ãªãã£äœå¶ãè©äŸ¡ã§ããããã«ããŸãã
Nmapã®åŒ·ã¿ã®äžã€ã¯ãå æ¬çãªãã¹ãæ€åºãšããŒãã¹ãã£ã³ã®å®è¡èœåã«ãããŸããICMPãšã³ãŒãªã¯ãšã¹ããTCP SYNã¹ãã£ã³ãUDPãããŒãã³ã°ãšãã£ãæ§ã ãªææ³ã掻çšããããšã§ãNmapã¯ã¿ãŒã²ããã·ã¹ãã äžã®ã¢ã¯ãã£ããªãã¹ããšéããŠããããŒããå¹ççã«ç¹å®ã§ããŸãããã®æ å ±ã¯ãæ»æå¯Ÿè±¡é åãææ¡ããæ»æè ãäŸµå ¥ããå¯èœæ§ã®ããäŸµå ¥ãã€ã³ããç¹å®ããäžã§éåžžã«éèŠã§ãã
Nmap ã®äž»ãªæ©èœã¯æ¬¡ã®ãšããã§ãã
- ãããã¯ãŒã¯äžã®ã¢ã¯ãã£ããªãã¹ããèå¥ããããã®ãICMP ãšã³ãŒèŠæ±ãTCP SYN/ACK ã¹ãã£ã³ãARP ã¹ãã£ã³ãªã©ã®æè»ãªãã¹ãæ€åºãªãã·ã§ã³
- å æ¬çãªããŒã ã¹ãã£ã³æ©èœãããŸããŸãªã¹ãã£ã³ ã¿ã€ã (TCP SYNãTCP æ¥ç¶ãUDP ãªã©) ããµããŒãããéããŠããããŒããšé¢é£ãµãŒãã¹ãç¹å®ããŸãã
- ãµãŒãã¹ãšããŒãžã§ã³ã®æ€åºã1,000 ãè¶ ããæåãªãµãŒãã¹ã®èšå€§ãªããŒã¿ããŒã¹ã䜿çšããŠãå®è¡äžã®ã¢ããªã±ãŒã·ã§ã³ãšãã®ããŒãžã§ã³ãèå¥ããŸãã
- é«åºŠãª OS ãã£ã³ã¬ãŒããªã³ãã£ã³ã°ããããã¯ãŒã¯å¿çã®åºæã®ç¹æ§ãåæããŠãã¿ãŒã²ãã ã·ã¹ãã ã®ãªãã¬ãŒãã£ã³ã° ã·ã¹ãã ãšããŒããŠã§ã¢ã®è©³çްãç¹å®ããŸãã
- Nmap Scripting Engine (NSE) ã«ããã¹ã¯ãªããåå¯èœãªèªååã«ãããäºåã«äœæãããå¹ åºãã¹ã¯ãªããã䜿çšããã«ã¹ã¿ãã€ãºãããã¹ãã£ã³ ã¿ã¹ã¯ãšèåŒ±æ§æ€åºãå¯èœã«ãªããŸã
- XMLãgrepable ããã¹ããéåžžã®ããã¹ããªã©ã®è©³çްãªåºå圢åŒã«ãããä»ã®ããŒã«ãšã®çµ±åã容æã«ãªããã¹ãã£ã³çµæã®è§£æã容æã«ãªããŸãã
ãµã€ããŒã»ãã¥ãªãã£æŠç¥ã®éèŠãªèŠçŽ
è匱æ§è©äŸ¡ã¹ãã£ã³ ããŒã«ã¯ãå ç¢ãªãµã€ããŒã»ãã¥ãªãã£æŠç¥ã«äžå¯æ¬ ãªã³ã³ããŒãã³ãã§ãããçµç¹ã IT ã€ã³ãã©ã¹ãã©ã¯ãã£å šäœã®è匱æ§ãç©æ¥µçã«ç¹å®ããŠè»œæžã§ããããã«ããŸãããã®èšäºã§ç޹ä»ããããŒã«ã¯å©çšå¯èœãªæè¯ã®ãœãªã¥ãŒã·ã§ã³ã®äžéšã衚ããŠããããããããç¬èªã®æ©èœãšå©ç¹ãæäŸããŸãã
ãããã®ããŒã«ã掻çšããããšã§ãçµç¹ã¯æ»æå¯Ÿè±¡é åãå æ¬çã«å¯èŠåãããªã¹ã¯ã«åºã¥ããŠè匱æ§ã«åªå é äœãä»ããã»ãã¥ãªãã£ãéçºã¯ãŒã¯ãããŒã«ã·ãŒã ã¬ã¹ã«çµ±åã§ããŸãããµã€ããŒè åšãé²åãç¶ããäžãæœåšçãªäŸµå®³ã«å æãæã£ãŠåŒ·åãªã»ãã¥ãªãã£äœå¶ãç¶æããã«ã¯ã广çãªè匱æ§è©äŸ¡ã¹ãã£ã³ ããŒã«ãã»ãã¥ãªãã£æŠåšã«çµã¿èŸŒãããšãéèŠã§ãã