ãœãŒããªãŒããŒ
å¹»èŠå¶åŸ¡: ã»ãã¥ãªã㣠ããã»ã¹ã®äžéšãšã㊠LLM ãå°å ¥ããå©ç¹ãšãªã¹ã¯

å€§èŠæš¡ãªèšèªã¢ãã« èšå€§ãªéã®ããŒã¿ã§ãã¬ãŒãã³ã°ããã LLM ã¯ãã»ãã¥ãªãã£éçšããŒã ãããã¹ããŒãã«ããããšãã§ããŸããLLM ã¯ã察å¿ãç£æ»ãæ å¢ç®¡çãªã©ã«é¢ããã€ã³ã©ã€ã³ã®ææ¡ãšã¬ã€ãã³ã¹ãæäŸããŸããã»ãšãã©ã®ã»ãã¥ãªã㣠ããŒã ã¯ãã¯ãŒã¯ãããŒã®æäœæ¥ã®åŽåã軜æžããããã« LLM ã詊ããã䜿çšãããããŠããŸããããã¯ãæ¥åžžçãªã¿ã¹ã¯ãšè€éãªã¿ã¹ã¯ã®äž¡æ¹ã«åœãŠã¯ãŸããŸãã
ããšãã°ãLLM ã¯ãåŸæ¥å¡ãç¬èªã®ããã¥ã¡ã³ããå ±æããããšããŠãããã©ãããé»åã¡ãŒã«ã§åãåãããã»ãã¥ãªãã£æ åœè ãžã®æšå¥šãšãšãã«å¿çãåŠçããããšãã§ããŸãããŸããLLM ã¯ããªãŒãã³ ãœãŒã¹ ã¢ãžã¥ãŒã«ã«å¯Ÿãããµãã©ã€ ãã§ãŒã³æ»æãæ¢ãããã®ãªã¯ãšã¹ãã翻蚳ããç¹å®ã®æ¡ä»¶ (åºã䜿çšãããŠããã©ã€ãã©ãªãžã®æ°ããè²¢ç®è ãäžé©åãªã³ãŒã ãã¿ãŒã³) ã«éç¹ã眮ãããšãŒãžã§ã³ããèµ·åããã¿ã¹ã¯ãå®è¡ã§ããŸããåãšãŒãžã§ã³ãã¯ããã®ç¹å®ã®æ¡ä»¶ã«åãããŠæºåãããŠããŸãã
ãšã¯ããããããã®åŒ·å㪠AI ã·ã¹ãã ã«ã¯ãã»ãã¥ãªã㣠ããŒã ãçŽé¢ããä»ã®ãªã¹ã¯ãšã¯ç°ãªãé倧ãªãªã¹ã¯ã䌎ããŸããã»ãã¥ãªã㣠LLM ã匷åããã¢ãã«ã¯ãããã³ãã ã€ã³ãžã§ã¯ã·ã§ã³ãããŒã¿ ãã€ãºãã³ã°ã«ãã£ãŠäŸµå®³ãããå¯èœæ§ããããŸãã人éã«ããååãªæå°ããªãç¶ç¶çãªãã£ãŒããã㯠ã«ãŒããšæ©æ¢°åŠç¿ã¢ã«ãŽãªãºã ã«ãããæªæã®ããæ»æè ãå¶åŸ¡ã調æ»ããçãçµã£ã察å¿ãèªå°ããå¯èœæ§ããããŸãã LLM ã¯ãéãããé åã§ãã£ãŠãå¹»èŠãèµ·ãããããã§ããæé«ã® LLM ã§ãã£ãŠããçããããããªãå Žåã¯ããããã§ã£ã¡äžããŸãã
LLM ã®äœ¿çšãšã¯ãŒã¯ãããŒã«é¢ããã»ãã¥ãªã㣠ããã»ã¹ãš AI ããªã·ãŒã¯ããããã®ã·ã¹ãã ããµã€ããŒã»ãã¥ãªãã£ã®éçšãšç ç©¶å šäœã§ããäžè¬çã«ãªãã«ã€ããŠãããéèŠã«ãªããŸãããããã®ããã»ã¹ãéµå®ãããã¬ããã³ã¹ ã·ã¹ãã ã§æž¬å®ããã³èª¬æãããŠããããšã確èªããããšã¯ãCISO ããµã€ããŒã»ãã¥ãªã㣠ãã¬ãŒã ã¯ãŒã¯ 2.0 ãªã©ã®æ°ããèŠä»¶ãæºããããã«åå㪠GRC (ã¬ããã³ã¹ããªã¹ã¯ãã³ã³ãã©ã€ã¢ã³ã¹) ãæäŸã§ããããã«ããããã«äžå¯æ¬ ã§ãã
ãµã€ããŒã»ãã¥ãªãã£ã«ããã LLM ã®å€§ããªçŽæ
CISOãšãã®ããŒã ã¯ãæ°ããªãµã€ããŒæ»æã®å¢å ã«åžžã«å¯Ÿå¿ããããšå¥®éããŠããŸããQualysã«ãããšã2023幎ã«å ±åãããCVEã®æ°ã¯é廿é«ãèšé²ããŸããã 26,447ã®æ°èšé²ããã㯠5 å¹Žãšæ¯ã¹ãŠ 2013 å以äžã«å¢å ããŠããŸãã
å¹³åçãªçµç¹ã®æ»æå¯Ÿè±¡é åãå¹Žã æ¡å€§ããã«ã€ããŠããã®èª²é¡ã¯ããã«è² æ ã倧ãããªãã°ããã§ãã AppSec ããŒã ã¯ãããã«å€ãã®ãœãããŠã§ã¢ ã¢ããªã±ãŒã·ã§ã³ãä¿è·ããç£èŠããå¿ èŠããããŸããã¯ã©ãŠã ã³ã³ãã¥ãŒãã£ã³ã°ãAPIããã«ãã¯ã©ãŠããä»®æ³åãã¯ãããžãŒã«ãããããã«è€éããå¢ããŠããŸããææ°ã® CI/CD ããŒã«ãšããã»ã¹ã䜿çšãããšãã¢ããªã±ãŒã·ã§ã³ ããŒã ã¯ããå€ãã®ã³ãŒããããéããããé »ç¹ã«åºè·ã§ããããã«ãªããŸãããã€ã¯ããµãŒãã¹ã¯ãã¢ããªã·ã㯠ã¢ããªã倿°ã® API ãšæ»æå¯Ÿè±¡é åã«åå²ããå€éšãµãŒãã¹ã顧客ã®ããã€ã¹ãšéä¿¡ããããã«ã°ããŒãã« ãã¡ã€ã¢ãŠã©ãŒã«ã«ããã«å€ãã®ç©ŽãéããŸããã
é«åºŠãª LLM ã¯ããµã€ããŒã»ãã¥ãªã㣠ããŒã ã®äœæ¥è² è·ã軜æžãããã®èœåãåäžããããšãã倧ããªå¯èœæ§ãç§ããŠããŸãã AI ãæŽ»çšããã³ãŒãã£ã³ã° ããŒã«ã¯ããœãããŠã§ã¢éçºã«åºã浞éããŠããŸãã Github ã®èª¿æ»ã«ãããšãéçºè ã® 92% ãã³ãŒãã®ææ¡ãšè£å®ã« AI ããŒã«ã䜿çšããŠããããŸãã¯äœ¿çšããããšãããããšãããããŸããããããã®ãå¯æçžŠãããŒã«ã®ã»ãšãã©ã«ã¯ãäœããã®ã»ãã¥ãªãã£æ©èœãåãã£ãŠããŸããå®éãã³ãŒãã£ã³ã° (ã³ãŒãã¯åäœãã¹ãã«åæ Œããã倱æãããã®ãããã) ãªã©ãæ¯èŒçãã€ããªãªçµæã䌎ãããã°ã©ã åéã¯ãLLM ã«é©ããŠããŸãããœãããŠã§ã¢éçºã CI/CD ãã€ãã©ã€ã³ã«ãããã³ãŒã ã¹ãã£ã³ä»¥å€ã«ããAI ã¯æ¬¡ã®ãããªããŸããŸãªæ¹æ³ã§ãµã€ããŒã»ãã¥ãªã㣠ããŒã ã«ãšã£ãŠäŸ¡å€ããããšèããããŸãã
- 匷åãããåæ: LLM ã¯ã倧éã®ã»ãã¥ãªã㣠ããŒã¿ (ãã°ãã¢ã©ãŒããè åšã€ã³ããªãžã§ã³ã¹) ãåŠçããŠã人éã«ã¯èŠããªããã¿ãŒã³ãçžé¢é¢ä¿ãç¹å®ã§ããŸãã圌ãã¯ãããèšèªãè¶ ããŠã24 æéããããŠå€ãã®æ¬¡å ã«ããã£ãŠåæã«è¡ãããšãã§ããŸããããã«ãããã»ãã¥ãªã㣠ããŒã ã«æ°ããªæ©äŒãéãããŸãã LLM ã¯ãã»ãŒãªã¢ã«ã¿ã€ã ã§å€æ°ã®ã¢ã©ãŒããçŒãæããæãé倧ã§ããå¯èœæ§ãé«ãã¢ã©ãŒãã«ãã©ã°ãç«ãŠãããšãã§ããŸãã匷ååŠç¿ãéããŠãæéã®çµéãšãšãã«åæãæ¹åãããã¯ãã§ãã
- ãªãŒãã¡ãŒã·ã§ã³ïŒ LLM ã¯ãéåžžã¯äŒè©±ã®ããåããå¿ èŠãšãªãã»ãã¥ãªã㣠ããŒã ã®ã¿ã¹ã¯ãèªååã§ããŸããããšãã°ãã»ãã¥ãªã㣠ããŒã ã IoC ãåãåãããšã³ããã€ã³ãã®ææè ã«å®éã«ããã€ã¹ã«ãµã€ã³ã€ã³ãããã©ããããŸãã¯éåžžã®äœæ¥ãŸãŒã³å€ã®å Žæã«ãããã©ãããå°ããå¿ èŠãããå ŽåãLLM ã¯ãããã®åçŽãªæäœãå®è¡ããŠãæ¬¡ã®æäœãå®è¡ã§ããŸããå¿ èŠã«å¿ããŠè³ªåãããªã³ã¯ãæé ãèšèŒããŸããããã¯ä»¥åã¯ãIT ããŒã ãŸãã¯ã»ãã¥ãªã㣠ããŒã ã®ã¡ã³ããŒãèªãè¡ãå¿ èŠã®ããããåãã§ããã LLM ã¯ãããé«åºŠãªæ©èœãæäŸããããšãã§ããŸããããšãã°ãMicrosoft Copilot for Security ã¯ã€ã³ã·ãã³ãåæã¬ããŒããçæããè€éãªãã«ãŠã§ã¢ ã³ãŒããèªç¶èšèªã®èª¬æã«ç¿»èš³ã§ããŸãã
- ç¶ç¶çãªåŠç¿ãšèª¿æŽ: ã»ãã¥ãªã㣠ããªã·ãŒãçè§£ã®ããã®ä»¥åã®æ©æ¢°åŠç¿ã·ã¹ãã ãšã¯ç°ãªããLLM ã¯ãå¿çã«å¯Ÿãã人éã®è©äŸ¡ãåã蟌ã¿ãå éšãã° ãã¡ã€ã«ã«å«ãŸããŠããªãå¯èœæ§ã®ããæ°ããããŒã¿ ããŒã«ãè¿ãããšã«ãã£ãŠããã®å Žã§åŠç¿ã§ããŸããå®éãåãåºç€ãšãªãåºæ¬ã¢ãã«ã䜿çšããŠããµã€ããŒã»ãã¥ãªã㣠LLM ãããŸããŸãªããŒã ãšãã®ããŒãºãã¯ãŒã¯ãããŒããŸãã¯å°åãŸãã¯æ¥çš®åºæã®ã¿ã¹ã¯ã«åãããŠèª¿æŽã§ããŸããããã¯ãã·ã¹ãã å šäœãå³åº§ã«ã¢ãã«ãšåããããã¹ããŒãã«ãªãã倿Žããã¹ãŠã®ã€ã³ã¿ãŒãã§ã€ã¹ã«ããã£ãŠè¿ éã«äŒæãããããšãæå³ããŸãã
ãµã€ããŒã»ãã¥ãªãã£ã®æ³åŠä¿®å£«èª²çšã®ãªã¹ã¯
LLM ã¯å®çžŸãæµ ãæ°ãããã¯ãããžãŒã§ãããããé倧ãªãªã¹ã¯ãæ±ããŠããŸããããã«æªãããšã«ãLLM ã®åºå㯠100% äºæž¬å¯èœãŸãã¯ããã°ã©ã çã§ã¯ãªãããããããã®ãªã¹ã¯ã®å šå®¹ãçè§£ããããšã¯å°é£ã§ããããšãã°ãLLM ã¯ãå¹»èŠããèµ·ãããæ¶ç©ºã®ããŒã¿ã«åºã¥ããŠçããã§ã£ã¡äžãããã質åã«ééã£ãŠçãããããããšããããŸãããµã€ããŒã»ãã¥ãªãã£ã®ãŠãŒã¹ã±ãŒã¹ã« LLM ãæ¡çšããåã«ã次ã®ãããªæœåšçãªãªã¹ã¯ãèæ ®ããå¿ èŠããããŸãã
- å³ææ³šå ¥: æ»æè ã¯ã誀解ãæããããªããŸãã¯æå®³ãªåºåãçæããããã«ãæªæã®ããããã³ãããäœæããå¯èœæ§ããããŸãããã®ã¿ã€ãã®æ»æã¯ãåä¿¡ããããã³ããã«åºã¥ããŠã³ã³ãã³ããçæãã LLM ã®åŸåãæªçšããå¯èœæ§ããããŸãããµã€ããŒã»ãã¥ãªãã£ã®ãŠãŒã¹ã±ãŒã¹ã§ã¯ãããã³ãã ã€ã³ãžã§ã¯ã·ã§ã³ã¯ãã€ã³ãµã€ããŒæ»æãŸãã¯ã¢ãã«ã®åäœãæªããŠã·ã¹ãã åºåãæ°žç¶çã«å€æŽããããã«ããã³ãââãã䜿çšããæš©éã®ãªããŠãŒã¶ãŒã«ããæ»æã®åœ¢æ ãšããŠæãå±éºã§ããå¯èœæ§ããããŸããããã«ãããã·ã¹ãã ã®ä»ã®ãŠãŒã¶ãŒã«å¯ŸããŠäžæ£ç¢ºãŸãã¯ç¡å¹ãªåºåãçæãããå ŽåããããŸãã
- ããŒã¿ãã€ãºãã³ã°: LLM ãäŸåãããã¬ãŒãã³ã° ããŒã¿ã¯æå³çã«ç Žæãããæææ±ºå®ãæãªãããå¯èœæ§ããããŸãããµã€ããŒã»ãã¥ãªãã£èšå®ã§ã¯ãçµç¹ãããŒã«ãããã€ããŒã«ãã£ãŠãã¬ãŒãã³ã°ãããã¢ãã«ã䜿çšããŠããå¯èœæ§ãé«ããç¹å®ã®é¡§å®¢ããŠãŒã¹ã±ãŒã¹ã«åãããŠã¢ãã«ã調æŽããéã«ããŒã¿ãã€ãºãã³ã°ãçºçããå¯èœæ§ããããŸããããã§ã®ãªã¹ã¯ã¯ãæš©éã®ãªããŠãŒã¶ãŒããã¬ãŒãã³ã° ããã»ã¹ã劚害ããããã«äžæ£ãªããŒã¿ (ãã° ãã¡ã€ã«ã®ç Žæãªã©) ã远å ããå¯èœæ§ããããŸããèš±å¯ããããŠãŒã¶ãŒã誀ã£ãŠãããè¡ãå¯èœæ§ããããŸãããã®çµæãäžæ£ãªããŒã¿ã«åºã¥ãã LLM åºåãçæãããŸãã
- å¹»èŠ: åè¿°ã®ããã«ãLLM ã¯ããã³ããã®èª€è§£ãæ ¹æ¬çãªããŒã¿æ¬ é¥ã«ãããäºå®ã«åãããéè«ççããŸãã¯æªæã®ããå¿çãçæããå¯èœæ§ããããŸãããµã€ããŒã»ãã¥ãªãã£ã®ãŠãŒã¹ã±ãŒã¹ã§ã¯ãå¹»èŠã«ããé倧ãªãšã©ãŒãçºçããè åšã€ã³ããªãžã§ã³ã¹ãè匱æ§ã®ããªã¢ãŒãžãšä¿®åŸ©ãªã©ã劚ããããå¯èœæ§ããããŸãããµã€ããŒã»ãã¥ãªãã£ã¯ããã·ã§ã³ã¯ãªãã£ã«ã«ãªæŽ»åã§ãããããLLM ã¯ãããã®ã³ã³ããã¹ãã§å¹»èŠã管çããã³é²æ¢ããããã®ããé«ãåºæºãæºããå¿ èŠããããŸãã
AI ã·ã¹ãã ã®èœåãé«ãŸãã«ã€ããŠãæ å ±ã»ãã¥ãªãã£ã®å°å ¥ãæ¥éã«æ¡å€§ããŠããŸãã誀解ã®ãªãããã«èšããšãå€ãã®ãµã€ããŒã»ãã¥ãªãã£äŒæ¥ã¯ãåçãªãã£ã«ã¿ãªã³ã°ã«ãã¿ãŒã³ ãããã³ã°ã𿩿¢°åŠç¿ãé·ãé䜿çšããŠããŸãããçæ AI æä»£ã®æ°ããç¹ã¯ãæ¢åã®ã¯ãŒã¯ãããŒãšããŒã¿ ããŒã«ã®äžã«ã€ã³ããªãžã§ã³ã¹ã®ã¬ã€ã€ãŒãæäŸããã€ã³ã¿ã©ã¯ãã£ã LLM ã§ããããµã€ããŒã»ãã¥ãªã㣠ããŒã ã®å¹çãæ¹åããæ©èœã匷åããã®ã«æé©ã§ããèšãæããã°ãGenAI ã¯ã»ãã¥ãªã㣠ãšã³ãžãã¢ãããå°ãªãåŽåãšåããªãœãŒã¹ã§ããå€ãã®ããšãå®çŸã§ããããã«æ¯æŽããããã©ãŒãã³ã¹ãåäžãããããã»ã¹ãå éããŸãã