ãœãŒããªãŒããŒ
ç§å¯ã®ãªãåœä»€ïŒAIãšãŒãžã§ã³ããã³ãŒãã«è§ŠãããšåŸæ¥ã®ã»ãã¥ãªãã£ã¢ãã«ãç Žç¶»ããçç±

4æã2023ã§ã¯ã ãµã ã¹ã³ã¯èªç€Ÿã®ãšã³ãžãã¢ãChatGPTã«æ©å¯æ å ±ãæŒæŽ©ããŠããããšãçºèŠããããããããã¯å¶ç¶ã§ãããã§ã¯ããããããã®ã³ãŒããªããžããªã«ã人éã«ã¯èŠããªããAIã«ãã£ãŠåŠçãããã³ãŒãã ãã§ãªããAIãã¢ã¯ã»ã¹ã§ãããã¹ãŠã®APIããŒãããŒã¿ããŒã¹èªèšŒæ å ±ããµãŒãã¹ããŒã¯ã³ãæœåºããããã«èšèšããããæå³çã«åã蟌ãŸããåœä»€ãå«ãŸããŠãããšãããã©ãã§ããããããã¯ä»®èª¬ã§ã¯ãããŸããã ã»ãã¥ãªãã£ç ç©¶è ã¯ãã§ã«å®èšŒããŠãã ãããã®ãèŠããªãæç€ºãæ»æã¯æå¹ã§ããåé¡ã¯ããããèµ·ãããã©ããã§ã¯ãªãããã€èµ·ãããã§ãã
ãã¯ãååšããªãå¢ç
ç§ãã¡ã¯äœå幎ãã®éããã³ãŒãã¯ã³ãŒããããŒã¿ã¯ããŒã¿ããšããæ ¹æ¬çãªåæã«åºã¥ããŠã»ãã¥ãªãã£ãæ§ç¯ããŠããŸãããSQLã€ã³ãžã§ã¯ã·ã§ã³ã¯ã¯ãšãªããã©ã¡ãŒã¿åããããšãæããã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ã¯åºåã®ãšã¹ã±ãŒããæããŸããããããŠãããã°ã©ã ã®åäœãšãŠãŒã¶ãŒã®å ¥åã®éã«å£ãç¯ãããšãåŠã³ãŸããã
AI ãšãŒãžã§ã³ãã®ç»å Žã«ããããã®å¢çã¯æ¶æ» ããŸããã
äºæž¬å¯èœãªãã¹ãèŸ¿ãæ±ºå®è«çãªãœãããŠã§ã¢ãšã¯ç°ãªããå€§èŠæš¡èšèªã¢ãã«ã¯ç¢ºççãªãã©ãã¯ããã¯ã¹ã§ãããæ£åœãªéçºè ã®æç€ºãšæªæã®ããå ¥åãåºå¥ã§ããŸãããæ»æè ãAIã³ãŒãã£ã³ã°ã¢ã·ã¹ã¿ã³ãã«ããã³ãââããå ¥åããéãåã«ããŒã¿ãæäŸããŠããã ãã§ã¯ãããŸãããæ¬è³ªçã«ã¯ãã¢ããªã±ãŒã·ã§ã³ããã®å Žã§åããã°ã©ãã³ã°ããŠããã®ã§ããå ¥åãããã°ã©ã ãã®ãã®ã«ãªãã®ã§ãã
ããã¯ãã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã«é¢ãããããŸã§ã®åžžèãæ ¹æ¬çã«èŠããã®ã§ããDROP TABLEã tags, fail completely against natural language attacks. Researchers have demonstrated âsemantic substitutionâ techniques where replacing âAPI keysâ with âapplesâ in prompts allows attackers to bypass filters entirely. How do you firewall intent when itâs disguised as harmless conversation?
誰ãè°è«ããŠããªããŒãã¯ãªãã¯ã®çŸå®
å€ãã®ã»ãã¥ãªãã£ããŒã ãçè§£ããŠããªãã®ã¯ãããã³ããã€ã³ãžã§ã¯ã·ã§ã³ã§ã¯ãŠãŒã¶ãŒãäœãå ¥åããå¿ èŠããªããšããããšã§ããããã¯å€ãã®å ŽåããŒãã¯ãªãã¯ãšã¯ã¹ããã€ãã§ããAIãšãŒãžã§ã³ãããå®åçãªã¿ã¹ã¯ã®ããã«ã³ãŒããªããžããªãã¹ãã£ã³ãããããã«ãªã¯ãšã¹ãã確èªããããAPIããã¥ã¡ã³ããèªãã ãããã ãã§ã人éã®ä»å ¥ãªãã«æ»æãèªçºããå¯èœæ§ããããŸãã
ãã®ã·ããªãªãèããŠã¿ãŸãããã ç ç©¶è ããã§ã«èšŒæããæè¡æªæã®ããæ»æè ãã人æ°ã®ãªãŒãã³ãœãŒã¹ã©ã€ãã©ãªã®ããã¥ã¡ã³ãå ã®HTMLã³ã¡ã³ãã«ãç®ã«èŠããªãåœä»€ãåã蟌ã¿ãŸããGitHub CopilotãAmazon CodeWhispererããããã¯ãšã³ã¿ãŒãã©ã€ãºåãã³ãŒãã£ã³ã°ã¢ã·ã¹ã¿ã³ããªã©ããã®ã³ãŒããåæããããããAIã¢ã·ã¹ã¿ã³ãã¯ãæœåšçãªèªèšŒæ å ±åéããŒã«ãšãªããŸãã1ã€ã®ã©ã€ãã©ãªã䟵害ããããšãæ°åã®éçºç°å¢ãå±éºã«ãããããå¯èœæ§ããããŸãã
å±éºãªã®ã¯LLMãã®ãã®ã§ã¯ãªããç§ãã¡ãLLMã«äžããæš©éã§ãããããã®ã¢ãã«ãããŒã«ãAPIãšçµ±åããããŒã¿ã®ååŸãã³ãŒãã®å®è¡ãç§å¯ãžã®ã¢ã¯ã»ã¹ãå¯èœã«ããç¬éãç§ãã¡ã¯åœ¹ã«ç«ã€ã¢ã·ã¹ã¿ã³ããå®ç§ãªæ»æãã¯ãã«ã«å€ããŠããŸããŸããããªã¹ã¯ã¯ã¢ãã«ã®ç¥èœã§ã¯ãªããæ¥ç¶æ§ã«ãã£ãŠå¢å€§ããã®ã§ãã
çŸåšã®ã¢ãããŒãã倱æããçç±
æ¥çã¯çŸåšãã¢ãã«ã®ãæŽåããšãããåªããè¿ éãªãã¡ã€ã¢ãŠã©ãŒã«ã®æ§ç¯ã«ç±å¿ã«åãçµãã§ããŸããOpenAIã¯ã¬ãŒãã¬ãŒã«ãå¢åŒ·ããAnthropicã¯æ²æ³ã«åºã¥ãAIã«æ³šåããŠããŸãã誰ããéšãããªãã¢ãã«ãäœãããšããŠããŸãã
ããã¯è² ãæŠã ã
AIã圹ã«ç«ã€ã»ã©è³¢ããªããéšãããã»ã©è³¢ããšãèšãããç§ãã¡ã¯ãç§ãããµãã¿ã€ãŒãŒã·ã§ã³ã®çœ ããšåŒã¶ãã®ã«é¥ã£ãŠãããã€ãŸããããåªããå ¥åãã£ã«ã¿ãªã³ã°ãç§ãã¡ãæã£ãŠããããšæã蟌ãã§ããã®ã ãããããæ»æã¯HTMLã³ã¡ã³ãå ã®ç®ã«èŠããªãããã¹ããšããŠé ãããŠããããããã¥ã¡ã³ãã®å¥¥æ·±ãã«åã蟌ãŸããŠãããããããã¯ç§ãã¡ããŸã æ³åãã§ããªãæ¹æ³ã§ãšã³ã³ãŒããããŠããããããæèçã«çè§£ã§ããªããã®ããµãã¿ã€ãºããããšã¯ã§ããªãããããŠãæèãããLLMã®åŒ·åãªç¹ãªã®ã ã
æ¥çã¯å³ããçå®ãåãå ¥ããå¿ èŠããããè¿ éãªæ³šå ¥ã¯æåããã ãããåé¡ã¯ããããæåããæã«äœãèµ·ãããã ã
ç§ãã¡ã«å¿ èŠãªå»ºç¯ã®è»¢æ
çŸåšãç§ãã¡ã¯ããããé©çšãã§ãŒãºãã«ãããå ¥åãã£ã«ã¿ãŒãšæ€èšŒã«ãŒã«ãå¿ æ»ã«è¿œå ããŠããŸããããããSQLã€ã³ãžã§ã¯ã·ã§ã³ãé²ãã«ã¯ãæååãšã¹ã±ãŒãã®æ¹åã§ã¯ãªãããã©ã¡ãŒã¿åãããã¯ãšãªãå¿ èŠã§ããããšãæçµçã«å€æããããã«ãAIã»ãã¥ãªãã£ã«ãã¢ãŒããã¯ãã£çãªãœãªã¥ãŒã·ã§ã³ãå¿ èŠã§ãã
çãã¯ãåçŽã«èããããã®ã®ãã·ã¹ãã ã®æ§ç¯æ¹æ³ãåèããå¿ èŠãããååã«ãããŸããããã¯ãAI ãšãŒãžã§ã³ãã¯ã䜿çšããç§å¯ã決ããŠææããŠã¯ãªããªãããšããããšã§ãã
ããã¯ãèªèšŒæ å ±ç®¡çã®æ¹åãé庫ãœãªã¥ãŒã·ã§ã³ã®æ¹è¯ãšãã£ãããšã§ã¯ãããŸãããAIãšãŒãžã§ã³ããããŠãŒã¶ãŒã«ãã¹ã¯ãŒããèŠæ±ããã®ã§ã¯ãªããäžæãã€æ€èšŒå¯èœãªIDãšããŠèªèããããšã§ããAIãšãŒãžã§ã³ããä¿è·ããããªãœãŒã¹ã«ã¢ã¯ã»ã¹ããå¿ èŠãããå Žåã以äžã®ç¹ã«çæããå¿ èŠããããŸãã
-
æ€èšŒå¯èœãªIDïŒä¿åãããç§å¯ã§ã¯ãªãïŒã䜿çšããŠèªèšŒãã
-
ç¹å®ã®ã¿ã¹ã¯ã«ã®ã¿æå¹ãªãžã£ã¹ãã€ã³ã¿ã€ã ã®è³æ Œæ å ±ãåãåã
-
è³æ Œæ å ±ã¯æ°ç§ãŸãã¯æ°å以å ã«èªåçã«æéåãã«ãªããŸã
-
é·æã«ãããç§å¯ã決ããŠä¿åããããèŠããããšããããªãã§ãã ãã
ããã€ãã®ã¢ãããŒããç»å ŽããŠããŸãã ãµãŒãã¹ã¢ã«ãŠã³ãã®AWS IAMããŒã«, Google ã®ã¯ãŒã¯ããŒã ã¢ã€ãã³ãã£ãã£, HashiCorp Vaultã®ãã€ãããã¯ãªç§å¯ããããŠAkeylessã®ãŒããã©ã¹ãã»ããããžã§ãã³ã°ã®ãããªå°çšãœãªã¥ãŒã·ã§ã³ã¯ãã¹ãŠããã®ç§å¯ã®ãªãæªæ¥ãæã瀺ããŠããŸããå®è£ ã®è©³çŽ°ã¯æ§ã ã§ãããååã¯å€ãããŸãããAIãçãç§å¯ãæã£ãŠããªãå Žåãè¿ éãªã€ã³ãžã§ã¯ã·ã§ã³ã¯è åšãå€§å¹ ã«è»œæžããŸãã
2027幎ã®éçºç°å¢
3幎以å ã«ãAIãæŽ»çšããéçºã«ãããŠ.envãã¡ã€ã«ã¯æ¶æ» ããã§ããããç°å¢å€æ°ã«ä¿æãããé·å¯¿åœã®APIããŒã¯ããã¹ã¯ãŒãããã¬ãŒã³ããã¹ãã§è¡šç€ºããããã«ãªã£ãä»ãç®ã«ããããšã«ãªãã®ã§ããããã¯ããããã€ãŒããªæä»£ã®æ¥ããããéºç©ãšèšããã§ãããã
代ããã«ããã¹ãŠã®AIãšãŒãžã§ã³ãã¯å³æ Œãªæš©éåé¢ã®äžã§åäœããŸããããã©ã«ãã§ã¯èªã¿åãå°çšã¢ã¯ã»ã¹ãæšæºã§ã¢ã¯ã·ã§ã³ã®ãã¯ã€ããªã¹ããã³ã³ãã©ã€ã¢ã³ã¹èŠä»¶ãšããŠãµã³ãããã¯ã¹åãããå®è¡ç°å¢ãåããŠããŸããAIã®æèãå¶åŸ¡ããããšããããAIãäœãã§ããããå¶åŸ¡ããããšã«å®å šã«æ³šåããŸãã
ããã¯åãªãæè¡çãªé²åã§ã¯ãªããä¿¡é Œã¢ãã«ã®æ ¹æ¬çãªè»¢æã§ãããä¿¡é Œãã€ã€ãæ€èšŒããããããæ±ºããŠä¿¡é Œãããåžžã«æ€èšŒãã劥åãåæãšããããžãšç§»è¡ãã€ã€ãããŸããé·å¹Žèª¬ãããªãããå®è·µãããããšã®å°ãªãã£ãæå°æš©éã®ååã¯ããžã¥ãã¢éçºè ãæ¯æ¥äœåãã®æªæã®ããå¯èœæ§ã®ããå ¥åãåŠçããAIã§ããå Žåããã¯ãè²ããªããã®ãšãªããŸãã
ç§ãã¡ãçŽé¢ããéžæ
ãœãããŠã§ã¢éçºãžã® AI ã®çµ±åã¯äžå¯é¿ã§ããã倧ããªã¡ãªããããããããŸãã GitHubã¯ãCopilotã䜿çšããéçºè ã¯ã¿ã¹ã¯ã55%éãå®äºãããšå ±åããŠããŸããçç£æ§ã®åäžã¯çŸå®ã§ãããç«¶äºåãç¶æãããçµç¹ã¯ãããç¡èŠããããšã¯ã§ããŸããã
ããããç§ãã¡ã¯å²è·¯ã«ç«ã£ãŠããŸããã¬ãŒãã¬ãŒã«ã远å ããããåªãããã£ã«ã¿ãŒãæ§ç¯ããéšãããªãAIãšãŒãžã§ã³ãã®éçºãæã¿ãªãããçŸç¶ã®éãæ©ã¿ç¶ãããããããšãè åšã®æ ¹æ¬çãªæ§è³ªãèªèããããã«å¿ããŠã»ãã¥ãªãã£ã¢ãŒããã¯ãã£ãåæ§ç¯ãããã§ãã
ãµã ã¹ã³ã®äºä»¶ã¯èŠåã«éããŸããã§ãããæ¬¡ã®äŸµå®³ã¯å¶çºçãªãã®ã§ã¯ãªããªããäžã€ã®äŒæ¥ã«çãŸãããšããªãã§ããããAIãšãŒãžã§ã³ãã®èœåãåäžããããå€ãã®ã·ã¹ãã ã«ã¢ã¯ã»ã¹ããããã«ãªãã«ã€ããŠãæœåšçãªåœ±é¿ã¯é£èºçã«å¢å€§ããŸãã
ãã¹ãŠã®CISOããã¹ãŠã®ãšã³ãžãã¢ãªã³ã°ãªãŒããŒããããŠãã¹ãŠã®éçºè ã«ãšã£ãŠã®çåã¯ã·ã³ãã«ã§ããããã³ããã€ã³ãžã§ã¯ã·ã§ã³ãããªãã®ç°å¢ã§æåããå ŽåïŒãããŠå¿ ãæåããã§ãããïŒãæ»æè ã¯äœãèŠã€ããã§ããããïŒ é·æã«ããã£ãŠæå¹ãªèªèšŒæ å ±ã®å®åº«ãçºèŠããã®ã§ããããïŒ ãããšãã䟵害ãããŠããã«ãããããããçãã¹ãç§å¯ãæããªãAIãšãŒãžã§ã³ããèŠã€ããã®ã§ããããïŒ
ä»ç§ãã¡ãäžãéžæã«ãã£ãŠãAIããœãããŠã§ã¢éçºã®æå€§ã®å éè£ çœ®ãšãªããããããšããããŸã§ç§ãã¡ãçã¿åºããæå€§ã®è匱æ§ãšãªãããæ±ºãŸããŸããå®å šã§ç§å¯ãå®ããªãAIã·ã¹ãã ãæ§ç¯ããæè¡ã¯æ¢ã«ååšããŸããåé¡ã¯ãæ»æè ã«åŒ·å¶ãããåã«ãããå®è£ ã§ãããã©ããã§ãã
OWASPã¯ãã§ã«è¿ éãªã€ã³ãžã§ã¯ã·ã§ã³ã第äžã®ãªã¹ã¯ãšããŠç¹å®ããŠãã LLM ã¢ããªã±ãŒã·ã§ã³ã®ããã 10 ã«ã©ã³ã¯ã€ã³ããŠããŸãã NISTã¯ã¬ã€ãã³ã¹ãäœæäž ãŒããã©ã¹ãã»ã¢ãŒããã¯ãã£ã«ã€ããŠããã¬ãŒã ã¯ãŒã¯ã¯ååšãããå¯äžã®åé¡ã¯ãå®è£ ã®ã¹ããŒããšæ»æã®é²åã®éãã ã
ç¥æŽïŒRefael Angelã¯ã ããŒã¬ã¹ã§ãå瀟ã®ç¹èš±ååŸæžã¿ãŒããã©ã¹ãæå·åæè¡ãéçºããŸãããæå·æè¡ãšã¯ã©ãŠãã»ãã¥ãªãã£ã«é¢ããæ·±ãå°éç¥èãæã€ããã©ã³ãœãããŠã§ã¢ãšã³ãžãã¢ã§ããRefaelã¯ã以åã¯ã€ã¹ã©ãšã«ã«ããIntuitã®R&Dã»ã³ã¿ãŒã§ã·ãã¢ãœãããŠã§ã¢ãšã³ãžãã¢ãåãããããªãã¯ã¯ã©ãŠãç°å¢ã«ãããæå·éµç®¡çã·ã¹ãã ã®æ§ç¯ããã·ã³èªèšŒãµãŒãã¹ã®èšèšã«æºãããŸããã19æ³ã®æã«ãšã«ãµã¬ã å·¥ç§å€§åŠã§ã³ã³ãã¥ãŒã¿ãµã€ãšã³ã¹ã®çåŠå£«å·ãååŸããŸããã










