Catoã¯ã©ãŠãã§ã¯ãçŸåšã®ãµãŒãã¹ç¶æ
ã宿ã¡ã³ããã³ã¹ãªã©ã®æ
å ±ã確èªã§ããã¹ããŒã¿ã¹ãµã€ãã®ããŒãžããããŸãã ä»åã¯ã¹ããŒã¿ã¹ããŒãžã«ã€ããŠãèŠæ¹ãäœ¿çšæ¹æ³ã確èªããŠãããããšæããŸãã Loading... status.catonetworks.com Catoã¹ããŒã¿ã¹ããŒãžãšã¯ Catoã¹ããŒã¿ã¹ ããŒãžã§ã¯ãCatoã¯ã©ãŠã ã®ã¹ããŒã¿ã¹ïŒãµãŒãã¹ã®ç¶æ
ïŒãšãèšç»ãããã¡ã³ããã³ã¹ãã¢ããã°ã¬ãŒãã«é¢ããæ
å ±ã衚瀺ãããŠããŸãã Catoã¯ã©ãŠãå
ã®PoPã«é¢ãããªã¢ã«ã¿ã€ã æ
å ±ãšãCato管çã¢ããªã±ãŒã·ã§ã³ã皌åãããµãŒããŒã«é¢ããæ
å ±ãªã©ã衚瀺ãããŸãã Catoã«æ¥ç¶ã§ããªãçãšãã£ãéã®é害ã®äžæ¬¡åãåããšããŠã掻çšã§ããŸãã®ã§ããã²ãåç
§ãã ããã ã¡ã³ããã³ã¹ã«ã€ããŠã§ãããPoPã¡ã³ããã³ã¹æéäžã¯ããŠãŒã¶ãŒåŽã§äœãç¹å¥ãªããšãããå¿
èŠã¯ãããŸããããã¡ã³ããã³ã¹ãè¡ã£ãŠããéã¯ãçŽ30ç§éãµãŒãã¹ã䜿ããªããªãããšããããŸãã 宿ã¡ã³ããã³ã¹ã«ã€ããŠã¯ãäºåã«ã¹ããŒã¿ã¹ããŒãžãéããŠã¢ããŠã³ã¹ãããŸãã ã©ã®ãµãŒãã¹ãã¡ã³ããã³ã¹ã§åœ±é¿ãåããã®ãã®ç¯å²ã詳现ãäºæ³ããããµãŒãã¹åæ¢æéãªã©ã®æ
å ±ãå«ãŸããŠãããŸãã®ã§ãäºåã«ç¢ºèªã§ãããšããã§ããã ãµã€ãå
容 ãŸããã¹ããŒã¿ã¹ããŒãžã«ã©ã®ãããªé
ç®ãèšèŒãããŠããããå
šäœçãªå
容ã«ã€ããŠã¿ãŠãããŸãããã æ²èŒãããŠããå
容ã¯ä»¥äžãšãªããŸãã PoP皌åç¶æ³ ã¡ã³ããã³ã¹ã«ã¬ã³ã㌠ãµãŒãã¹çšŒåç¶æ³ Uptime PoP皌åç¶æ³ ãµã€ããéããšããã®ãããªç»é¢ã衚瀺ãããŸãã PoPã®UP/DOWNãªã©ã®çŸåšã®çšŒåç¶æ³ãã¡ã³ããã³ã¹æ
å ±ãé害çºçæã«ã©ã®PoPã§ãªã«ãèµ·ãã£ãŠãããçã®ç¢ºèªãã§ããŸãã ã¡ã³ããã³ã¹ã«ã¬ã³ã㌠皌åç¶æ³ã®äžã«ã¯ããNotificationsããšãMaintenanceãã®é
ç®ããããŸãã ãNotificationsãã§ã¯ãPoPã¹ããŒã¿ã¹ã AFFECTEDç¶æ
ã®ãã® ã«é¢ããæ
å ±ïŒçºçæ¥æãçŸåšå¯ŸåŠããŠããå
容ïŒã衚瀺ãããŠããŸãã ãMaintenanceãã§ã¯ãã«ã¬ã³ããŒã«ä»åŸäºå®ãããŠããã¡ã³ããã³ã¹ãããã§ã«å®æœãããã¡ã³ããã³ã¹å±¥æŽãèšèŒãããŠããŸããå¯Ÿè±¡ã®æ¥ä»ãéžæãããšã¡ã³ããã³ã¹å
容ã®ç¢ºèªãã§ããŸãã 詊ãã«ã2024/1/24ã®ç®æãéžæããŠã¿ãŸããšã以äžã®ããã«ã¡ã³ããã³ã¹å®æœæéã察象ã®ãµãŒãã¹ç¯å²ãããŠã³ã¿ã€ã ã®æšå®æéãªã©ãèšèŒãããŠãããä»åŸäºå®ãããŠããã¡ã³ããã³ã¹æ
å ±ã«ã€ããŠç¢ºèªããããšãã§ããŸãã ãµãŒãã¹çšŒåç¶æ³ Service Historyã®Listã®è¡šç€ºã§ã¯Events Cato APIãCMAãªã©ã®Managementæ©èœãPoPæ¥ç¶ã®ãããã¯ãŒã¯ãµãŒãã¹å
šäœã«ã€ããŠã®GlobalãåPoPã®ãµãŒãã¹çšŒåç¶æ³ã«ã€ããŠã®è¡šç€ºããããŸãã æ£åžžã«çšŒåããŠããããã¡ã³ããã³ã¹ãéå®³ã®æç¡ã«ã€ããŠã®å±¥æŽã確èªã§ããŸãã ç·è² æ£åžžã«çšŒåããŠãã é»è² ããã©ãŒãã³ã¹ã«åœ±é¿ãã èµ€è² ãµãŒãã¹ããŠã³ãã é害ããã£ãéã¯èµ€äžžã«ãŠè¡šç€ºãããé害å
容ã察象æéã察åŠå
容ã®èšèŒããããŸãã ãŸããCarendarãéžæãããšã1ãæã®å±¥æŽã確èªã§ããŸãã 確èªãããå
容ãããã°ãè©²åœæ¥ä»ã®èšèŒãã¯ãªãã¯ããŸããšã詳现å
容ã説æãããããŒãžãžç§»åãããŸãã 詊ãã«ã1æ4æ¥ã®é
ç®ãã¯ãªãã¯ããŠã¿ãŸããšã以äžã®ããã«èª²é¡ããã€çºèŠãããããçŸåšå¯ŸåŠäžã§ããæšã課é¡ããã€è§£æ±ºããããã«ã€ããŠã®å
容ã確èªã§ããŸããã Uptime Managementæ©èœã®åãµãŒãã¹ãåPoPã®Uptimeãã1æ¥ã»1é±éã»1ãæã»1幎åäœã§ç¢ºèªããããšãå¯èœã§ãã CMAã«ãã°ã€ã³ã§ããªããããã°ãåæ ãããªããšãã£ãéã¯ãã¡ãã®é
ç®ã«ãŠDOWNããŠããå¯èœæ§ãããã確èªããŠã¿ãŸãããã ãµã€ãã«èšèŒãããŠããå
容ã«ã€ããŠã¯ä»¥äžãšãªããŸãã æ©èœçŽ¹ä» ã¹ããŒã¿ã¹ãµã€ãã§äœ¿çšã§ããæ©èœã«ã€ããŠã確èªããŠãããŸãã SUBSCRIBE äŸãã°ãæ ç¹ã®Catoã¯ã©ãŠãæ¥ç¶ãåããŠããŸããé害圱é¿ã§ããã確èªãããããæ±äº¬ã»å€§éªPoPã®ä»åŸã®ã¡ã³ããã³ã¹äºå®ã®éç¥ãåé ãããããªã©ãšãã£ãéã«äœ¿çšã§ããæ©èœãããããŸãã ããã以äžã®ãSUBSCRIBEãã§ãã ãã¡ããã¯ãªãã¯ãããšä»¥äžã®è¡šç€ºããããéç¥ãåé ãããé
ç®ãéžæããããšãã§ããŸãã éç¥èšå®ã«ã€ããŠã詊ãã«Emailã«ãŠèšå®ãè¡ã£ãŠã¿ãããšæããŸãã ãEmailããéžæãããšãã¡ãŒã«ã¢ãã¬ã¹ã®èšå®ã«ç§»ããŸãã ã¢ãã¬ã¹ãå
¥åããåæã«ãã§ãã¯ãå
¥ããŸãããéç¥ããŠã»ããå
容ã®ã«ã¹ã¿ãã€ãºãè¡ããŸãã â»All serviceãéžæããå Žåããã¹ãŠã®PoPé害ã»ã¡ã³ããã³ã¹çã®éç¥ãæ¥ãããšã«ãªããŸãã éžæã§ããå
容ãšããŠã¯ãManagementæ©èœã®ãµãŒãã¹ãšãåå°åã®PoPãéžæããããšãã§ããŸãã æ±äº¬ã倧éªã®PoPæ
å ±ã®ã¿éç¥ã欲ãããšãã£ãéã«ã¯ããTokyo,JapanããTokyo_DC2,JapanããOsaka,JapanããOsaka_DC2,Japanãã«ãã§ãã¯ãããSaveãã¿ã³ãæŒããŸããšãå®äºãšãªããŸãã å®éã®éç¥ã¡ãŒã«ã¯ä»¥äžã®ãããªãã®ãéä»ãããŠããŸãã 察象PoPã»ãµãŒãã¹ã®éžæ ç¹å®ã®PoPããµãŒãã¹ãäŸãã°æ±äº¬PoPã ãã®ã¡ã³ããã³ã¹å±¥æŽãä»åŸã®ã¡ã³ããã³ã¹äºå®ãç¥ããããªã©ã®éã¯ãService History ïŒLISTãäžä»è¿ã«ããæ€çŽ¢æ¬ã®ç®æã§å¯Ÿè±¡ã®PoPåã»ãµãŒãã¹åãå
¥åããã ããšè©²åœã®ãã®ã®ã¿è¡šç€ºãããããã«ãªããŸãã ä»ã«ãPoPåã ãã§ãªãããJAPANããªã©åœåãå
¥åããããšã§å¯Ÿè±¡åœã®PoPæ
å ±ã確èªããããšãã§ããŸãã ãŸããããŒãžå³äžã®ã¿ã€ã ãŸãŒã³ããUTCãâãJSTãã«å€æŽããããšã§ãã¡ã³ããã³ã¹ã«ã¬ã³ããŒã®è¡šèšæéãæ¥æ¬æéã®è¡šèšã«å€æŽãããããèŠããããªããŸãã æ©èœç޹ä»ã¯ä»¥äžãšãªããŸãã ä»ãµãŒãã¹ãšã®æ¯èŒ AWS AWSã§ã¯ AWSãµãŒãã¹ãã«ã¹ããã·ã¥ããŒã ãšããæ©èœã«ãŠåçš®ãµãŒãã¹ãæ£åžžçšŒåããŠãããã©ãããå
¬éããŠãããµã€ãããããŸãã ãã¡ãã®ãµã€ãã«ãŠAWSã¹ããŒã¿ã¹ã確èªããåãªãŒãžã§ã³ã®ãµãŒãã¹çšŒåç¶æ³ã確èªã§ãããããAWSã«ãŠå©çšããŠããµãŒãã¹ã«äœãåé¡ãèµ·ããå Žåã¯ããã§ãã¯ããããšãå¯èœã§ããéå»ã«èµ·ããåé¡çãæç³»åã§é²èЧããããšãå¯èœãšãªã£ãŠããŸãã AWSãµãŒãã¹ã§ãéç¥æ©èœãåãã£ãŠãããããå€éšããŒã«ãªã©ã§æå®ãã察象ãªãŒãžã§ã³ã®ãµãŒãã¹ã®éç¥ãåãåãããšãå¯èœã§ãã Catoã®ã¹ããŒã¿ã¹ããŒãžãšã®æ¯èŒããŠã¿ããšãAWSã§ã¯ä»ã®AWSãµãŒãã¹ãšçµ±åã»çµã¿åãããããããšãå¯èœã«ãªã£ãŠããŸããäŸãã°ãAWS CloudWatchãAWS Lambda颿°ãšçµã¿åãããŠãåé¡çºçæã®æ¹åæªçœ®ãèªååããéçšã®è² æ
æžãããªã©ã®ããšãå¯èœãšãªã£ãŠãããŸããAWSã®ãµãŒãã¹ã®è±å¯ããæŽ»çšããŠãããšæããŸãã Azure Azure ã§ã¯ã Azure ã®ç¶æ
ãããŒãžã«ãŠãAzure ã®å
šãµãŒãã¹ããã³å
šãªãŒãžã§ã³ã®çšŒåç¶æ³ãé害æ
å ±ã®ç¢ºèªãå¯èœãšãªããŸãã ãŸããããããŒãœãã«ãªæ
å ±ã確èªã§ãããAzure Service HealthããšããããŒãžãããããŸãã ã客æ§ããšã«å©çšããŠãããµãŒãã¹ãšãªãŒãžã§ã³ããšã«ç¢ºèªãã§ããããŒãžãšãªããService Health å
ã§ã¯ã顧客ã圱é¿ãåãã軜埮ãªãµãŒãã¹åæ¢ãããèšç»ã¡ã³ããã³ã¹ã®å®æœãå§ããšããæ£åžžæ§ã«é¢ããéç¥ãŸã§ãããŸããŸãªæ
å ±ãåç
§ã§ããŸãã Catoãšã®éãã§ã¯ãããã·ã¥ããŒãã®æ
å ±ãããŒãœãã©ã€ãºãããŠãããããã客æ§ãå©çšäžã®ãµãŒãã¹ããªãŒãžã§ã³ãåæ ãããããã«ãªã£ãŠãããŸãããå®¢æ§æ¯ã®ããŒãžãããããã©ãã«ã·ã¥ãŒãã£ã³ã°ã«åœ¹ç«ã€ãããåã€ãã³ãã«ãã£ãŠåœ±é¿ãåããå¯èœæ§ã®ãããªãœãŒã¹ã®ãªã¹ããæç€ºããŠãããŠãããŸãã ä»ã®ã¹ããŒã¿ã¹ããŒãžãšæ¯èŒããCatoã¯ã©ãŠãã®ã¹ããŒã¿ã¹ããŒãžã®ç¹åŸŽãšããŠã¯ã詳现ãªç¢ºèªä»¥å€ã¯1ããŒãžã§å®çµããŠããèŠããããç¹åŸŽã§ãããšæããŸããã ãŸãšã ä»åã¯Catoã¯ã©ãŠãã®ãµãŒãã¹ç¶æ³ã®ç¢ºèªãã§ãããµã€ãã¹ããŒã¿ã¹ããŒãžã®ã玹ä»ãããŸããã Catoã¯ã©ãŠãã«æ¥ç¶ã§ããªããšãã£ãäºè±¡ãçºçããŸããããé害ãçºçããŠããªãããã¡ã³ããã³ã¹ã«è©²åœããŠããªããã®ã確èªãããŠããã ããåãåã察å¿ã®åãåãã«ã掻çšããã ããã°å¹žãã§ãã ã芧ããã ãããããšãããããŸããã
æ¬èšäºã®å
容ã¯ãCato Networks瀟㮠Avishay Zawoznikæ°ãæçš¿ãã以äžã®ããã°ãå
ã«æ¥æ¬èªãžç¿»èš³ïŒæèš³ïŒããåæ§æãããã®ãšãªããŸãã Busting the App Count Myth ïŒã¢ããªæ°ç¥è©±ãæã¡ç ŽãïŒ Busting the App Count Myth Many security vendors offer automated detection of cloud applications and services, classifying them into categories and exposing attributes such as security ri... www.catonetworks.com ã¯ããã« SSEãç¹ã«CASBãäžå¿ãšããã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã§ãçŽ50,000以äžã®ã¯ã©ãŠãã¢ããªã±ãŒã·ã§ã³ã®æ€åºãå¯èœã§ãããšè¬³ãããŠããäºããããããŸãããæ¬èšäºã§ã¯ãã¯ã©ãŠãã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã«ããã”ã¢ããªã±ãŒã·ã§ã³æ°”ã®éèŠæ§ã«å¯Ÿããçåãåããã¢ããªã±ãŒã·ã§ã³ã®å®éã®ãã©ãã£ãã¯ã«çŠç¹ãåœãŠãå
æ¬çãªã¢ãããŒããæèšãããã®ãšãªããŸãã ã€ãŸãã ã¢ããªã±ãŒã·ã§ã³æ°ã ãã§ãªãããã©ãã£ãã¯ããèŠãã¢ããªã±ãŒã·ã§ã³ã®ã«ãã¬ããžïŒCoverageïŒç¶²çŸ
çïŒã«æ³šç®ãã¹ã ã§ãããæ°ãå¢ããŠãå¿
ãããã»ãã¥ãªãã£åäžã«ã€ãªãããªãããšã瀺åããŠããŸãã Catoã¯ã©ãŠãã®CASBã«ã€ããŠã¯ã以äžã®èšäºãåç
§ãã ããã Catoã¯ã©ãŠãã®CASBã«ã€ã㊠Catoã¯ã©ãŠãã®ã»ãã¥ãªãã£ãªãã·ã§ã³ CASB ã«ã€ããŠè§£èª¬ããŸãã blog.usize-tech.com 2023.09.12 åã»ãã¥ãªãã£ãã³ããŒã¯ãã¯ã©ãŠãã¢ããªã±ãŒã·ã§ã³ããµãŒãã¹ãèªåæ€åºããã«ããŽãªåé¡ããŠãã»ãã¥ãªãã£ãªã¹ã¯ãã³ã³ãã©ã€ã¢ã³ã¹ããµãŒãã¹æäŸäŒæ¥ã®ã¹ããŒã¿ã¹ãªã©ã®å±æ§ãå
¬éããŠããŸãã ãŠãŒã¶ãŒã¯ãã¢ããªã±ãŒã·ã§ã³ã®ã«ããŽãªãšå±æ§ã«åºã¥ããŠããã¡ã€ã¢ãŠã©ãŒã«ãCASBãDLPããªã·ãŒã®èšå®ãªã©ãããŸããŸãªã»ãã¥ãªãã£å¯Ÿçãé©çšããããšãã§ããŸãã ãã®ãããã¢ããªã±ãŒã·ã§ã³ã®å顿°ãç»é²ãããŠããã¢ããªã±ãŒã·ã§ã³æ°ãå€ããã°å€ãã»ã©è¯ããšããçµè«ã¯ãšãŠãçã«ããªã£ãŠããããã«æããŸãã ã¡ãªã¿ã«ãCatoã¯ã©ãŠãã§ã¯ãç¬èªã®ACEïŒApplication Credibility EngineïŒãçšããŠã¢ããªã±ãŒã·ã§ã³åé¡ãè¡ãããŠããŸãã ACEã®ã¢ããªã±ãŒã·ã§ã³ã«ã¿ãã°ïŒApp CatalogïŒã«ã¯ã 2024幎2æ5æ¥æç¹ã§10,352ã®ã¢ããªã±ãŒã·ã§ã³ãç»é² ãããŠããŸãã ã¢ããªã±ãŒã·ã§ã³ãæ°ããã®ããããŠã«ãã¬ããžãèããã¹ã ãŸããã¢ããªã±ãŒã·ã§ã³ã®æ°ãæ°ããã®ããããŠãã¢ããªã±ãŒã·ã§ã³ã®ã«ãã¬ããžãèããã¹ãã§ãããšããããšã§ãã ã»ãã¥ãªãã£ãã³ããŒãåé¡ããã¢ããªã±ãŒã·ã§ã³æ°ãè°è«ããŠããå®éã®ãã©ãã£ãã¯ãèæ
®ããªããã°æå³ããããŸããã 10äžã®ã¢ããªã±ãŒã·ã§ã³ã«ã¿ãã°ãæäŸãããã³ããŒãšãäžæ¹ã§2åã®ã¢ããªã±ãŒã·ã§ã³ã«ã¿ãã°ãæäŸãããã³ããŒã«ãããŠãäž¡æ¹ã®ãã³ããŒãã«ããŒããã®ããšãã«åã1åã®ã¢ããªã±ãŒã·ã§ã³ã§ããã°ãæäŸããŠããæ©èœãšããŠã¯å
šãåãããšã§ãã äžã®å³ã§ãå·Šã®åã¯ã»ãã¥ãªãã£ãã³ããŒã«ãã£ãŠçœ²åãããåé¡ãããã¢ããªã±ãŒã·ã§ã³ã衚ããå³ã®åã¯ã顧客ã®ãããã¯ãŒã¯äžã®å®éã®ã¢ããªã±ãŒã·ã§ã³ãã©ãã£ãã¯ã衚ããŠããŸãã äž¡æ¹ã®äº€ãã£ãéšåãããŠãŒã¶ã®ã¢ããªã±ãŒã·ã§ã³é©çšïŒæ€åºïŒæ°ã衚ããŠããŸãã ã€ãŸãã顧客ã®ãã©ãã£ãã¯ã«é©çšãããã¢ããªã±ãŒã·ã§ã³ã«ã¿ãã°ã§ãã Catoã¯ãäžéšã®ãã³ããŒã®ããã«ã«ã¿ãã°ã®ã¢ããªã±ãŒã·ã§ã³æ°ã«éç¹ã眮ãã®ã§ã¯ãªãã«ãã¬ããžãæå€§åããããšã«éç¹ã眮ããŠããŸãã ã¯ã©ãŠããã³ããŒãšããŠã®ããŒã¿å¯èŠæ§ã«ãããCatoã®èª¿æ»ããŒã ã¯é¡§å®¢ããŒã¹å
šäœããŸãã¯èŠæ±ã«å¿ããŠç¹å®ã®é¡§å®¢ã«ããŽãªãŒïŒå°åãæ¥çš®ãªã©ïŒã«å¯ŸããŠã¢ããªã±ãŒã·ã§ã³ã®ã«ãã¬ããžãæé©åããããšã«åãå
¥ããŠããŸãã ã¢ããªã±ãŒã·ã§ã³æ°ãšã«ãã¬ããžã®èå¯ ã¢ããªã±ãŒã·ã§ã³ã®ã«ãã¬ããžã«æ³šç®ãããšããã¯ãã ããå€ãã®ã¢ããªã±ãŒã·ã§ã³ãç»é²ããã°ãã«ãã¬ããžã¯ã©ãã©ãåäžããã®ã¯ïŒ ããšããçåãçããŸãã ã¢ããªã±ãŒã·ã§ã³æ°ãšã«ãã¬ããžã®é¢ä¿ãçè§£ããããã«ãCatoã¯ã©ãŠãå
šäœã®ãã©ãã£ãã¯ã1é±éååéããåé¡ããããã©ãã£ãã¯ãšåé¡ãããŠããªããã©ãã£ãã¯ãåæããŸããã â»ã¢ããªã±ãŒã·ã§ã³ã«ã¿ãã°ã®èгç¹ããäž»ãªé¢å¿äºã§ããã¯ã©ãŠãã¢ããªã±ãŒã·ã§ã³ä¿è·ã®ã·ããªãªã«çŠç¹ãåœãŠããããCatoã®ããŒã¿ã¬ã€ã¯ããåéããHTTPã®ã¢ãŠãããŠã³ãã»ãããŒã®ãã©ãã£ãã¯ã«åºã¥ããŠããŸãã ãã®çµæã 10 ã®ã¢ããªã±ãŒã·ã§ã³ãããã©ãã£ãã¯ã® 45.42%ãã«ã㌠100 ã®ã¢ããªã±ãŒã·ã§ã³ãããã©ãã£ãã¯ã® 81.6%ãã«ã㌠1000 ã®ã¢ããªã±ãŒã·ã§ã³ãããã©ãã£ãã¯ã® 95.58%ãã«ã㌠2000 ã®ã¢ããªã±ãŒã·ã§ã³ãããã©ãã£ãã¯ã® 96.41%ãã«ã㌠4000 ã®ã¢ããªã±ãŒã·ã§ã³ãããã©ãã£ãã¯ã® 96.72%ãã«ã㌠9000 ã®ã¢ããªã±ãŒã·ã§ã³ãããã©ãã£ãã¯ã® 96.78%ãã«ã㌠Catoã®ã¢ããªã±ãŒã·ã§ã³ã«ã¿ãã°ã«æåŸïŒ4000â9000ïŒã«è¿œå ããã5000ã®ã¢ããªã±ãŒã·ã§ã³ã¯ãç·ã«ãã¬ããžã®+0.06%ããè²¢ç®ããŠããªãããšã倿ããŸããã ã€ãŸããã¢ããªã±ãŒã·ã§ã³æ°ã®å¢å ã¯ãã«ãã¬ããžãšããç¹ã§ã¯åç©«éå¢ïŒãã
ããããŠãããïŒâ»ãšãªã£ãŠããŸãã â»ã¢ããªã±ãŒã·ã§ã³ã远å ããŠãããšã«ãã¬ããžã¯å¢ããããã«ãã¬ããžã®äŒžã³çã¯æ¬¡ç¬¬ã«äœäžããŠããããšã Catoã¯ã©ãŠããã9000 ã®ã¢ããªã±ãŒã·ã§ã³ã ãã§ 96.78%ãšããé«ãã«ãã¬ããžãšãªã£ãŠã ãã®ã¯ãå®éã®é¡§å®¢ãã©ãã£ãã¯ã§èŠãããã¢ããªã±ãŒã·ã§ã³ããã«ãã¬ããžãžã®è²¢ç®åºŠã«å¿ããŠåªå
çã«åé¡ããäœç³»çãªã¢ãããŒããè¡ã£ãŠããçµæã§ãã â»2024幎2æ5æ¥æç¹ã§ã¯10,352ã®ã¢ããªã±ãŒã·ã§ã³ãç»é²ãããŠããŸãã æ¬¡ã«ãCatoã¯ã©ãŠãã®ç·ã«ãã¬ããžãããããã«èžã¿èŸŒãã§ãåæ§ã®ææ³ã§ã¢ã«ãŠã³ãããšã®ã«ãã¬ããžã調æ»ããŠããŸãã Catoã®é¡§å®¢ã¢ã«ãŠã³ãã«ãããŠã 91%ã®ã¢ã«ãŠã³ããã90%ïŒãŸãã¯ãã以äžïŒã®ã«ãã¬ããž 82%ã®ã¢ã«ãŠã³ããã95%ïŒãŸãã¯ãã以äžïŒã®ã«ãã¬ããž 77%ã®ã¢ã«ãŠã³ããã96ïŒ
ïŒãŸãã¯ãã以äžïŒã®ã«ãã¬ããž ã«ãã¬ããžã¯ãCatoã¯ã©ãŠãã®ã«ãã¬ããžã«éããŸãããã顧客èšå®ãšã¯ç¡é¢ä¿ã§ãã Catoã®æ°èŠé¡§å®¢ã§ããã°ããã©ãã£ãã¯ã®90ïŒ
ãåé¡ããã確çã¯91ïŒ
ãšããçµè«ã«ãªããŸããå³ã«è¡šããšã次ã®ããã«ãªããŸãã ã¢ããªã±ãŒã·ã§ã³æ°ã¯ãããŒã±ããã«ãšã£ãŠéåžžã«åããããç°¡åãªææšã§ãããã¢ããªã±ãŒã·ã§ã³ã®ã«ãã¬ããžãããçã®äŸ¡å€ã§ãã ãã«ãã«ã®ã¢ããªã±ãŒã·ã§ã³ã«ã¿ãã°ãèŠãã³ããããŠããã£ãåŸãå®éã«ãã®ãã³ãã«ã¢ããªã±ãŒã·ã§ã³ã®ãã©ãã£ãã¯ã®äœããŒã»ã³ããåé¡ã§ããŠãããèããŠã¿ãŠã¯ã©ãã§ããããïŒïŒ96.78%以äžã§ããããïŒïŒ ã¡ãªã¿ã«ãCatoã¯ã©ãŠãã§ã¯ãCASBããå¥çŽã®ã客æ§ã®ã«ãã¬ããžã93%以äžïŒæªåé¡7%æªæºïŒã«ãªãããã«ç®¡çãããŠããŸãã ã«ãã¬ããž100ïŒ
ã¯ããåŸãã æ¬¡ã®çåã¯ã100%ã®ã¢ããªã±ãŒã·ã§ã³ã®ã«ãã¬ããžã¯å¯èœãïŒãã§ãã Catoã¯ã©ãŠãäžã®1é±éã®ãã©ãã£ãã¯ãæ³šææ·±ã調æ»ããçŸåšCatoã®ã¢ããªãã«ããŽãªãŒã«åé¡ãããŠããªããã©ãã£ãã¯ã«çŠç¹ãåœãŠãŸãããã¢ããªã±ãŒã·ã§ã³ãåé¡ããããã«äœãå¿
èŠããç¥ãããã«ããã®ãã©ãã£ãã¯ãïŒå®å
šãªãµããã¡ã€ã³ã§ã¯ãªãïŒã»ã«ã³ãã¬ãã«ãã¡ã€ã³ã§åé¡ããŸããã ã€ãŸããCatoã¯ã©ãŠãã®96.78%ã«ããŒçã®æ®ã3.22%ã«ã€ããŠãããã«è©³çްãªåæãè¡ã£ãçµæã ãã©ãã£ãã¯ã®0.88%ã¯ãã¡ã€ã³åã瀺ããŠããªãã ãšãããããŸãããããã¯IPã¢ãã¬ã¹ããã®çŽæ¥ã¢ã¯ã»ã¹ãåå ã§ãã 3.22%ã® æ®ãã®2.34%ã«ã€ããŠã¯ã318äžåã®ç°ãªãã»ã«ã³ãã¬ãã«ãã¡ã€ã³ã«ãŸããã£ãŠããããã®ãã¡312äžåã¯ã5åæªæºã®ã¯ã©ã€ã¢ã³ãIPããŸãã¯åäžã®Catoã¢ã«ãŠã³ãã§çºèŠ ãããŸããã ãã®ããšãããæªåé¡ã®ãã©ãã£ãã¯ã«ã¯ãåžžã«ãã³ã°ããŒã«ãååšããããšãããããŸããã ã»ãã¥ãªãã£ãã³ããŒãšããŠããã®ããšãã100%ã®ã«ãã¬ããžçããéæããããšãäžå¯èœã«ããŠããããšãåãããŸããã ã€ãŸããã«ãã¬ããžã100%ã«ããããšã¯äžå¯èœãšããããšã«ãªããŸãã æªåé¡ïŒUnclassifiedïŒãžã®å¯Ÿå¿ã«ã€ã㊠ããããããªã«ãã¬ããžãåŸãããã«ãããå€ãã®ã¢ããªã±ãŒã·ã§ã³ãåé¡ããããšã¯ãã»ãã¥ãªãã£ã®èгç¹ã§ãæå³ããããŸããã ãã³ããŒãšé¡§å®¢ã®äž¡æ¹ã«å¯ŸããŠãæªåé¡ã®ãã©ãã£ãã¯ã远ããããã®ã§ã¯ãªããæªçœ²åã®ã¢ããªã®ãã³ã°ããŒã«ãé©åãªã»ãã¥ãªãã£ç·©åçã§åŠçããå¿
èŠãããããšãCatoã¯ã©ãŠãã§ã¯ææ¡ããŸãã æªæã®ãããã©ãã£ãã¯ïŒMalicious trafficïŒããã®ä¿è· C&CãµãŒããŒãšã®éä¿¡ããã£ãã·ã³ã°ãµã€ããžã®ã¢ã¯ã»ã¹ããã«ãŠã§ã¢é
ä¿¡ãµã€ããªã©ã®æªæã®ãããã©ãã£ãã¯ã®ä¿è·ã¯ãã¢ããªã±ãŒã·ã§ã³ã®åé¡ããªããŠãä¿è·ãè¡ãå¿
èŠããããŸãã Catoã§ã¯ããã«ãŠã§ã¢ä¿è·ãšIPSã¯ãã¢ããªã±ãŒã·ã§ã³åé¡ããå®å
šã«ç¬ç«ããŠãããããã¿ãŒã²ãããµã€ããæ¢ç¥ã®ã¢ããªãšããŠåé¡ãããŠããªããŠãä¿è·ãããŸãã ã·ã£ããŒITã¢ããªïŒèªå¯ãããŠããªãã¢ããªã±ãŒã·ã§ã³ïŒãžã®äžæ£ã¢ã¯ã»ã¹ã«ã¯ã以äžã®ãããªå¯Ÿçãå¿
èŠã§ãã å®å
šãªå¯èŠæ§ã®ç¢ºä¿ ã¢ããªã±ãŒã·ã§ã³åé¡ã®æç¡ã«ãããããããã¹ãŠã®ãã©ãã£ãã¯ãå¯èŠåããããšãã§ããŸãã Catoã®ãŠãŒã¶ãŒã¯ããã©ãã£ãã¯ãã¢ããª/ã«ããŽãªã«åé¡ãããŠãããã©ããã«ããããããããããã¢ã¯ãã£ããã£ãç£èŠããããã«éžæã§ããŸãã ããŒã¿æå€±é²æ¢ïŒDLPïŒ æªèªå¯ã®ã¯ã©ãŠãã¹ãã¬ãŒãžããã¡ã€ã«å
±æãµãŒãã¹ã䜿çšãããšãæ©å¯ããŒã¿ã瀟å€ã«æµåºããå¯èœæ§ããããŸãã Catoã¯ãã¢ããªã®åé¡ã«é¢ä¿ãªãããã¹ãŠã®HTTPãã©ãã£ãã¯ãDLPã¹ãã£ã³ããæ©èœãå°å
¥ããŸããã äžè¬çã«ã¯ãæªç¥ã®ã¯ã©ãŠããµãŒãã¹ã«å¯ŸããŠããå¶éçãªããªã·ãŒãèšå®ããããã«ãã®æ©èœã䜿çšããããšããå§ãããŸãã ã«ã¹ã¿ã ã¢ããªæ€åº ãã®æ©èœã¯ãCatoã«ãã£ãŠåé¡ãããŠããªãã¢ããªã±ãŒã·ã§ã³ã®è¿œè·¡ãæ¹åããããã«ããã©ãã£ãã¯ã远跡ãã顧客ããšã«ã¢ããªã±ãŒã·ã§ã³åé¡ããæ©èœãå°å
¥ããŠããŸãã ãªã¢ãŒããã©ãŠã¶åé¢ïŒRBIïŒ ã¢ããª/ã«ããŽãªã«åé¡ãããŠããªããUncategorized(æªåé¡)ãããã³ãUnknown(äžæ)ããšãªããµã€ãã¯ããšã³ããŠãŒã¶ã®ããã€ã¹ã§çŽæ¥ã¢ã¯ã»ã¹ãããã®ã§ã¯ãªããCatoã¯ã©ãŠãäžã®ä»®æ³ãã·ã³ããã¢ã¯ã»ã¹ãè¡ãããã®ç»é¢æ
å ±ããšã³ããŠãŒã¶ãžã¹ããªãŒãã³ã°ããRBIæ©èœããããŸãã ãŸãšã ã¯ã©ãŠãã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£åŒ·åºŠã®ææšãšããŠãã¢ããªã»ã«ã¿ãã°ã®ã¢ããªã±ãŒã·ã§ã³æ°ã«åºå·ããããšãç¡æå³ã§ããããšã解説ããŸããã ã¢ããªã±ãŒã·ã§ã³æ°ã®å¢å ã«ãããªã¿ãŒã³ã®æžå°ã¯ãå€ããã°å€ãã»ã©è¯ããšããäžè¬çãªèãæ¹ã«çåãæãããããã®ã§ãã ã¯ã©ãŠãã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãè©äŸ¡ããæé©åããããã®éèŠãªè»žãšããŠãããæå³ã®ããææšã§ããã«ãã¬ããžã®æ¡çšããã¬ã³ãã«ãªã£ãŠããŸãã 广çãªã»ãã¥ãªãã£æŠç¥ã¯ãã¢ããªã®åé¡ã«ãšã©ãŸãããå®å
šãª100%ã®ã«ãã¬ããžã¯å®çŸäžå¯èœã§ããããšãèªèããå¿
èŠããããŸãã ã€ãŸããã¢ããªã±ãŒã·ã§ã³åé¡ã ãã§ã¯ãªããIPSãDLPãRBIãªã©ã®ä»ã®ãœãªã¥ãŒã·ã§ã³ãé©åã«çµã¿åãããããšã§ã»ãã¥ãªãã£ãªã¹ã¯ã軜æžããã¢ããªã±ãŒã·ã§ã³ã®ãã³ã°ããŒã«ãã«ããŒããã®ã£ããã«å¯ŸåŠããå¿
èŠããããŸãã ã¯ã©ãŠãã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã®è€éãªç¶æ³ãããã²ãŒãããã«ã¯ãé©åãªã¡ããªã¯ã¹ãšé©åãªã»ãã¥ãªãã£ã³ã³ãããŒã«ãçµã¿åããã埮åŠãªã¢ãããŒãããå
æ¬çã§é©å¿æ§ã®ããä¿è·ã確ä¿ããããã«æãéèŠã«ãªããŸãã
ããã«ã¡ã¯ãSCSKã®ãµãã¡ãŒã¬ã§ãã ã¿ãªããã¯ãã³ã³ããé¢é£ã®ãµãŒãã¹ãå©çšããããšãããŸãã§ããããã æ¬èšäºã§ã¯ãECSã¿ã¹ã¯å®çŸ©ãCloudFormationã§ç®¡çã»ãããã€ãããšãã®ã¡ãã£ãšãããã¯ããã¯ãã玹ä»ããŸãã ECSã¿ã¹ã¯å®çŸ©ãCFNã§ç®¡çãããšãªããžã§ã³ä¿æããããšãã§ããªãïŒ ECSã¿ã¹ã¯å®çŸ©ãCloudFormationã§ç®¡çãããšã以åã®ãªããžã§ã³(ããŒãžã§ã³)ãä¿æããããšãã§ããªãåé¡ããããŸããã€ãŸããCloudFomrationã§ãããã€ãããšã以åã®ãªããžã§ã³(ããŒãžã§ã³)ãåé€ãããŠãææ°ã®ãªããžã§ã³(ããŒãžã§ã³)ã®ã¿ä¿æãã仿§ã«ãªã£ãŠããŸãã ECSã¿ã¹ã¯å®çŸ©ã®CloudFormationããã¥ã¡ã³ãã確èªãããšãåããããã£ãæŽæ°ãã㚔眮æ”ãçºçããŠããŸãããšãèšèŒãããŠããŸããããããªããžã§ã³ä¿æããããšã劚ããåå ãšãªããŸãã AWS::ECS::TaskDefinition - AWS CloudFormation Use the AWS CloudFormation AWS::ECS::TaskDefinition resource for ECS. docs.aws.amazon.com 解決çïŒUpdateReplacePolicyãå©çšãã “UpdateReplacePolicy”屿§ãå©çšããŠã”Retain”ãæå®ããŸãããã UpdateReplacePolicy 属性 - AWS CloudFormation UpdateReplacePolicy 屿§ã䜿çšããŠãAWS CloudFormation ã«ããã¹ã¿ãã¯æŽæ°ãªãã¬ãŒã·ã§ã³æã«ãªãœãŒã¹ã®çœ®ãæããåŠçããæ¹æ³ãæå®ããŸãã docs.aws.amazon.com è§£æ±ºæ¹æ³ã¯ããã£ãããã ãã§ããæã£ãããç°¡åã§ããã 宿ããCloudFromationãã³ãã¬ãŒã 以äžã®ãã³ãã¬ãŒãã䜿çšããŠããããã€ããŸãã AWSTemplateFormatVersion: 2010-09-09 Parameters: Env: Type: String AllowedValues: - TEST - STG - PROD Resources: # ================================ # ECS (Task Difinition) # ================================ ECSTaskDefinition: Type: "AWS::ECS::TaskDefinition" UpdateReplacePolicy: Retain #ãã®èšè¿°ã远å Properties: Cpu: 256 ExecutionRoleArn: !Sub "arn:aws:iam::${AWS::AccountId}:role/ecsTaskExecutionRole" Family: !Sub "ECS-${Env}-helloworld-taskdef" Memory: 512 NetworkMode: awsvpc RequiresCompatibilities: - FARGATE ContainerDefinitions: - Name: helloworld Image: !Sub "${AWS::AccountId}.dkr.ecr.${AWS::Region}.amazonaws.com/helloworld-appliction:v1.0" LogConfiguration: LogDriver: awslogs Options: awslogs-group: !Sub "/ecs/ECS-${Env}-helloworld-service" awslogs-region: !Ref AWS::Region awslogs-stream-prefix: v1.0 PortMappings: - AppProtocol: http HostPort: 80 Protocol: tcp ContainerPort: 80 Name: helloworld-80-tcp ReadonlyRootFilesystem: false RuntimePlatform: CpuArchitecture: X86_64 OperatingSystemFamily: LINUX Tags: - Key: Name Value: !Sub "ECS-${Env}-helloworld-taskdef" ECSã¿ã¹ã¯å®çŸ©ã®æŽæ° äžèšã§ãããã€ããã¿ã¹ã¯å®çŸ©ãæŽæ°ããŠããªããžã§ã³2ãäœæããããšã«ããŸãã 以äžã®ãã³ãã¬ãŒãã䜿çšããŠãã¹ã¿ãã¯ãæŽæ°ããŸãã AWSTemplateFormatVersion: 2010-09-09 Parameters: Env: Type: String AllowedValues: - TEST - STG - PROD Resources: # ================================ # ECS (Task Difinition) # ================================ ECSTaskDefinition: Type: "AWS::ECS::TaskDefinition" UpdateReplacePolicy: Retain Properties: Cpu: 256 ExecutionRoleArn: !Sub "arn:aws:iam::${AWS::AccountId}:role/ecsTaskExecutionRole" Family: !Sub "ECS-${Env}-helloworld-taskdef" Memory: 512 NetworkMode: awsvpc RequiresCompatibilities: - FARGATE ContainerDefinitions: - Name: helloworld Image: !Sub "${AWS::AccountId}.dkr.ecr.${AWS::Region}.amazonaws.com/helloworld-appliction:v1.1" #ã³ã³ããã€ã¡ãŒãžã®æŽæ° LogConfiguration: LogDriver: awslogs Options: awslogs-group: !Sub "/ecs/ECS-${Env}-helloworld-service" awslogs-region: !Ref AWS::Region awslogs-stream-prefix: v1.1 #ãã°ã°ã«ãŒãã®æŽæ° PortMappings: - AppProtocol: http HostPort: 80 Protocol: tcp ContainerPort: 80 Name: helloworld-80-tcp ReadonlyRootFilesystem: false RuntimePlatform: CpuArchitecture: X86_64 OperatingSystemFamily: LINUX Tags: - Key: Name Value: !Sub "ECS-${Env}-helloworld-taskdef" ã¿ã¹ã¯å®çŸ©ã®ãªããžã§ã³2ãäœæããã以åã®ããŒãžã§ã³ãä¿æãããŠããããšãåãããŸãã æ³šæäºé
ã»ã¿ã¹ã¯å®çŸ©ã®ãã¡ããªãŒåã¯ãæ
éã«ååä»ããæ±ºå®ããåŸã«ãããã€ããããš ã¿ã¹ã¯å®çŸ©ã®ãªããžã§ã³ã¯ããã¡ããªãŒåã«åºã¥ããŠããŸããã¿ã¹ã¯å®çŸ©ãåé€ãããšããŠããå
éšã§ãã¡ããªãŒåãèšé²ãããŠããããããªããžã§ã³ã以åã®ãã®ããåŒãç¶ããŸãããªããžã§ã³ã”1″ããæ¡çªãããå Žåã¯ãç°ãªããã¡ããªãŒåã§åäœæããããšãå¿
èŠã§ãã ãŸãšã ãããã ã£ãã§ããããã以åã®ãªããžã§ã³ã®ã¿ã¹ã¯å®çŸ©ãCloudFromationã§ãä¿æããããšãã§ããŸããããããšããæã«ã以åã®ãªããžã§ã³ã®ã¿ã¹ã¯å®çŸ©ããã³ã³ãããèµ·åããããšããèŠä»¶ãæºããããšãã§ããŸãã æ¬èšäºãçæ§ã®ã圹ã«ããŠã°å¹žãã§ãã ã§ã¯ãµãŠãã©ïœð¥
Catoã¯ã©ãŠãã«ãå®¢æ§æ ç¹ãæ¥ç¶ããéãéåžžã¯å°çšæ©åšã§ããCato Socketã®ãå©çšãããããããŠãããŸãããå¥ã®æ¹æ³ãšããŠããææã¡ã®ç©çã«ãŒã¿ããã¡ã€ã¢ãŠã©ãŒã«æ©åšããIPsecã§æ¥ç¶ããããšãå¯èœã§ãã IPsecã§ã®æ¥ç¶ã¯ãSocketã«æ¯ã¹ããšæ©èœãå£ãã®ã§ãããæ¢åã®æ©åšã§æ¥ç¶ã§ããããšããäžæçãªå©çšã«ã¯æçšã§ããIPsecæ¥ç¶æã®æ©èœå¶éã«ã€ããŠã¯ã以äžã®èšäºã®ãSocket/vSocketãšIPsecã®æ¯èŒãã«ãŠç޹ä»ããŠãããŸãã®ã§ãåç
§ãã ããã Cato SSE 360 ã«ã€ã㊠Catoã¯ã©ãŠãã®ãCato SSE 360ããSSEã©ã€ã»ã³ã¹ãã«ã€ããŠèª¬æããŸãã blog.usize-tech.com 2023.09.05 ä»åããã¹ããšããŠYAMAHAã«ãŒã¿ã§ã®IPsecæ¥ç¶ãè¡ããŸããã®ã§ãèšå®å
å®¹ãæ³šæç¹ãã玹ä»ããŸãã æ¥ç¶åã®äºåç¢ºèª èšå®ãè¡ãåã«ã以äžã®æ
å ±ã確èªããŠãããŸãã æ©åšã§äœ¿ããIPsecã®ãã©ã¡ãŒã¿ã確èªãã Catoã«éãããç°ãªãæ©åšéã§ã®IPsecã®æ¥ç¶ã¯é£ããã§ãããã®çç±ã¯ãIPsecã§ã¯æå·åæ¹åŒãã¯ãã倿°ã®èšå®é
ç®ãããããã©ã¡ãŒã¿ãäž¡æ©åšã§å®å
šã«äžèŽããŠããªããšæ¥ç¶ã«å€±æããããã§ããæ©åšã«ãã£ãŠé
ç®ã®ååãå®è£
ã埮åŠã«éã£ããããããšãåå ã®ã²ãšã€ã§ãã ãã®ãããCatoã®IPsecæ¥ç¶æã«ãããŸãã¯å©çšããæ©åšã®ä»æ§ãææ¡ããŠããå¿
èŠããããŸãã Catoã¯IPsec IKEv1/v2ã®äž¡æ¹ã«å¯Ÿå¿ããŠãããä»åã¯äžè¬çãªv2ã®æ¥ç¶ä»æ§ãã玹ä»ããŸãããå©çšã®æ©åšããããã®ãã©ã¡ãŒã¿ã«å¯Ÿå¿ããŠãããã©ãããšãåé
ç®ã®èšå®ã³ãã³ããäºåã«ã確èªãã ããã èšå®é
ç® Catoã®å¯Ÿå¿ãã©ã¡ãŒã¿ èªèšŒæ¹åŒ äºåå
±æéµ (Pre-shared key, PSK) ã®ã¿ æå·ã¢ã«ãŽãªãºã (Encryption Algorithm) AES-CBC 128 / AES-CBC 256 / AES 128 GCM-16 / AES 256 GCM-16 â»AES-CBC 128ããã³256ã¯100Mbpsæªæºã®æ¥ç¶ã«ã®ã¿å¯Ÿå¿ããŸãã100M以äžã®å Žåã¯AES 128 GCM-16 ãŸã㯠AES 256 GCM-16ã䜿çšããŠãã ããã ããã·ã¥ã¢ã«ãŽãªãºã (PRF Algorithm, Integrity Algorithm) SHA1 / SHA2 256 / SHA2 384 / SHA2 512 DHã°ã«ãŒã (Diffie-Hellman Group) 2(1024bit) / 5(1536bit) / 14(2048bit) / 15(3072bit) / 16(4096bit) / 21(521bit ECP) èªèšŒID (Authentication Identifier) ååIPv4ãä»ã«FQDN, Email, KEY_ID ã«ã察å¿ã IKE SA(Phase1)ã®ã©ã€ãã¿ã€ã 19,800 ç§ Child SA(Phase2)ã®ã©ã€ãã¿ã€ã 3,600 ç§ â»2024幎1æçŸåšã®ä»æ§ã§ããææ°ã®æ
å ±ã¯Cato Knowledge Baseãã確èªãã ããã â»ã©ã€ãã¿ã€ã ã¯2024幎1æçŸåšã¯å€æŽäžå¯ã§ãããè¿æ¥äžã«CMAããå€ã®æå®ãã§ããããã«ãªãäºå®ã§ãã IPsecã®åé·åæ§æãèãã IPsecæ¥ç¶ã§ã¯ãç¹å®ã®PoPã«å¯ŸããŠæ¥ç¶ããããããã®PoPã§é害ãçºçãããšæ¥ç¶äžå¯ãšãªã£ãŠããŸããŸãããã®ããã ãã±ãŒã·ã§ã³ã®ç°ãªãPoPã«Secondaryã®IPsecã匵ã£ãŠããããšãæšå¥š ãšãªã£ãŠããŸãã ä»åã¯ä»¥äžã®æ§æã§ãã¹ãããŸãããPPPoEæ¥ç¶ã®åç·1æ¬ã䜿ããæ±äº¬ãšãã³ãã³ã«IPsecã匵ããŸãã ããã§ã¯ãå®éã«èšå®ãè¡ã£ãŠãããŸãã ãŸãã¯PoP IPã¢ãã¬ã¹ã®ååŸ IPsecã®æ¥ç¶å
ã¯Catoã®PoPãšãªããŸããããã®PoPã«ãŠæ¥ç¶çšã®åºå®IPã¢ãã¬ã¹ãååŸããå¿
èŠããããŸããPrimaryã®PoPãšSecondaryã®PoPã§ããããååŸããŸãã ãªããCatoã®æšå¥šã¯ã1ã€ã®Siteã«å¯Ÿãã«1ã€ã®åºå®IPãååŸããããšã§ãããèšå®äžã¯1ã€ã®IPã¢ãã¬ã¹ã«è€æ°ã®SiteããIPsecã匵ãããšãå¯èœã§ãã IPã¢ãã¬ã¹ã®ååŸã¯ãCMA(Cato管çç»é¢)ã® Network > IP Allocation ããè¡ããŸããæšæºã§3ã€ãŸã§ååŸå¯èœã§ã4ã€ã以éã¯å¥éè²»çšãšãªããŸãã Siteã®äœæ ç¶ããŠãIPsecçšã®SiteãäœæããŸããNetwork > Site ã®ãNewãããäœæããŸãã IPsec Siteã®å Žåã¯ãConnection Typeã®éžæã§ããIPsec IKEv1ããŸãã¯ãIPsec IKEv2ããéžæããŸããã©ã¡ããå©çšãããã¯ãå©çšã®æ©åšã«ãããŸãããä»åå©çšããYAMAHA RTXã·ãªãŒãºã¯v1/v2äž¡æ¹å¯Ÿå¿ã®ãããäžè¬çãªIKEv2ãšããŸãã Siteãäœæãããšã以äžã®ããã«ãIPsecããšããèšå®é
ç®ããããŸãã®ã§ãããã§IPsecã®èšå®ãè¡ã£ãŠãããŸãã General äžèšã¹ã¯ãªãŒã³ã·ã§ãããGeneralã®ã»ã¯ã·ã§ã³ã§ã¯ãæ¥ç¶ã®åºæ¬èšå®ãè¡ããŸãã Connection Mode ã¯ãCatoåŽããIPsecã匵ãã«è¡ããã©ããã®èšå®ã§ã éåžžã¯é«éã«æ¥ç¶ããããã«ãBidirectionalããšããŸã ããResponder Onlyãã«ããå Žåã«ã¯ãCatoã¯æ¥ç¶ãåãä»ããã®ã¿ã§ãèªåããã¯æ¥ç¶ã«è¡ããŸããã ãŸãã Authentication Identifier ã¯ãæ¥ç¶çžæãã©ã®æ
å ±ã§èå¥ãããã®èšå®ã§ãã éåžžã¯IPv4 ã§ããConnection ModeãResponder Onlyã«ããå Žåã«ã¯ãä»ã®éžæè¢ãéžã¹ãŸãã Primary / Secondary ç¶ããŠãIPã¢ãã¬ã¹çã®èšå®ã§ããPrimary/Secondaryãšãã«èšå®é
ç®ã¯åãã§ãã Public IPã® Cato IPã«ãPoPã®ã¢ãã¬ã¹ ããã«ããŠã³éžæããŸããä»åã¯TokyoãšLondonã§ãã Site IPã¯ãæ ç¹åŽã®ã°ããŒãã«IPã¢ãã¬ã¹ ã§ããä»åã¯åç·ã1æ¬ãªã®ã§ãPrimary/Secondaryãšãåãã¢ãã¬ã¹ã«ãªããŸãã Private IPsã¯ãBGPã«ããDynamic Routingãè¡ãå Žåã«Peer IPãšããŠäœ¿çšããŸããä»åã¯äœ¿çšããŸããã®ã§ç©ºæ¬ã§ãã Last-mile Bandwidthã¯ãSiteã®å¥çŽåž¯å ãæå®ããŸãã æåŸã«ã Primary PSK, Secondary PSK ãèšå®ããŸããIPsecæ¥ç¶ã®ãã¹ã¯ãŒããšãªããã®ã§ãã8ïœ64æåã§ãã¢ã«ãã¡ãããã®å€§æåå°æåãåºå¥ããŸããæ©åšã«ãã£ãŠã¯èšå·ã«å¯Ÿå¿ããŠããªãããšããããããã¢ã«ãã¡ããããšæ°åã§ã®æå®ãç¡é£ã§ãã Init Message Parameters / Auth Message Parameters æå·ã¢ã«ãŽãªãºã çã®èšå®ã§ãã ãã£ãšãåä»ãªç®æã§ããã ãŸãã¯ãã¹ãŠAutoèšå®ãšããããšãæšå¥š ãšãªã£ãŠããŸããã«ãŒã¿åŽã§æ¹åŒãåºå®ããCatoåŽã¯Autoãšããããšã§ãèšå®ãã«ãŒã¿åŽã«åãããæå³ã§ããAutoã§ããŸãè¡ããªãå Žåã«ã¯ããšã©ãŒã¡ãã»ãŒãžãèŠãªãã調æŽããŠãããŸãããšã©ãŒã«ã€ããŠã¯åŸè¿°ããŸãã ãªãã Init Messageã®Diffie-Hellman Groupã ãã¯ãAutoãNoneãèšå®ã§ããªããããå©çšããæ©åšã察å¿ããŠããæ¹åŒãéžæããèšå®ããŸãã Routing æåŸãRoutingã®ã»ã¯ã·ã§ã³ã§ãã Initiate connection by Cato ã¯ãCatoåŽããæ¥ç¶ãéå§ãããã©ããã§ãã éåžžã¯ONãæšå¥š ã§ãã Network Ranges ã¯ãå©çšæ©åšåŽã®èšå®ãããªã·ãŒããŒã¹ã®IPsecã§ãSAã«Network Rangeãå®çŸ©ãããŠããå Žåã«ããã®ã¬ã³ãžãæå®ããŸãã空æ¬ã®å Žåã«ã¯ãæé»çã«ã«ãŒãããŒã¹ãšããŠèªèãããŸãã ä»åã¯ç©ºæ¬ãšããŠããŸãã 以äžã§ãCatoåŽã®èšå®ã¯äžæŠå®äºã§ãã YAMAHAã«ãŒã¿ã®èšå® ä»åã¯ä»¥äžã®æ©åšã§åäœã確èªããŠããŸããå
æ¥EoLãšãªã£ãæ©åšã§ãããConfigã¯ä»ã®RTXã·ãªãŒãºãã»ãŒåãã§ãã ããŒããŠã§ã¢ YAMAHA RTX810 ãã¡ãŒã ãŠã§ã¢ Rev.11.01.34 å€ãæ©åšã®ããã以äžã®å€ããªãã©ã¡ãŒã¿ã䜿çšããŸãããæè¿ã®æ©çš®ã¯ããå€ãã®ã¢ã«ãŽãªãºã ã«å¯Ÿå¿ããŠããŸãã®ã§ãCatoã®å¯Ÿå¿ç¯å²å
ã§ã§ããã ãã»ãã¥ãªãã£ã®é«ã(æ°å€ã®å€§ãã)ãã®ãéžãã§ãã ããã èšå®é
ç® ãã©ã¡ãŒã¿ æå·ã¢ã«ãŽãªãºã (Encryption Algorithm) AES-CBC 256 ããã·ã¥ã¢ã«ãŽãªãºã (PRF Algorithm, Integrity Algorithm) SHA2 256 DHã°ã«ãŒã (Diffie-Hellman Group) 2(1024bit) IPsecãµã³ãã«Config PPPoEçã®èšå®ãè¡ããInternetãžéä¿¡ã§ããããšã確èªã®äžãIPsecé¢é£ã®èšå®ãå
¥ããŠãããŸãã tunnel select 1 tunnel name <ã«ãŒã¿äžã§ã®è¡šç€ºå> ipsec tunnel 1 ipsec ike version 1 2 # IKEv2ãå©çšãããšæç€ºçã«æå®ããèšå® ipsec ike group 1 modp1024 # DHã°ã«ãŒã ipsec ike encryption 1 aes256-cbc # Phase1ã®æå·ã¢ã«ãŽãªãºã ipsec ike hash 1 sha256 # Phase1ã®ããã·ã¥ã¢ã«ãŽãªãºã ipsec sa policy 1 1 esp aes256-cbc sha256-hmac # Phase2ã®æå·ã»ããã·ã¥ã¢ã«ãŽãªãºã ipsec ike duration ike-sa 1 19800 # Phase1ã®ã©ã€ãã¿ã€ã ipsec ike duration child-sa 1 3600 # Phase2ã®ã©ã€ãã¿ã€ã ipsec ike keepalive use 1 on # Keepaliveãè¡ãèšå® ipsec ike keepalive log 1 off # Keepaliveã®ãã°ã衚瀺ããªãèšå®(倧éã«åºããã) ipsec ike local address 1 <ã«ãŒã¿ã®Global IPã¢ãã¬ã¹> ipsec ike local name 1 <ã«ãŒã¿ã®Global IPã¢ãã¬ã¹> ipv4-addr ipsec ike remote address 1 <CatoPoPã®åºå®ã°ããŒãã«IPã¢ãã¬ã¹> ipsec ike remote name 1 <CatoPoPã®åºå®ã°ããŒãã«IPã¢ãã¬ã¹> ipv4-addr ipsec ike pre-shared-key 1 text <Pre-Shaerd Keyæåå> ipsec ike proposal-limitation 1 on # æå®ããã¢ã«ãŽãªãºã 以å€ã§ã¯ããŽã·ãšãŒã·ã§ã³ããªãèšå® ip tunnel tcp mss limit auto tunnel enable 1 ipsec auto refresh on äžèšã§Primaryåã®èšå®ã§ããåæ§ã«tunnel2ãšããŠSecondaryã®èšå®ãæå
¥ããŸãã èšå®ãå¿ããããã®ã¯ã ipsec ike proposal-limitation <tunnelçªå·> on ãã§ãã YAMAHAã«ãŒã¿ã®ä»æ§ãšããŠãããã©ã«ãã§ã¯IPsecã®èšå®äžäžèŽãè§£æ¶ããããã«ã宣èšããã¢ã«ãŽãªãºã 以å€ãå«ã䜿ããã¢ã«ãŽãªãºã ãã¹ãŠãçžæã«ææ¡ããŸãããã®çµæãCatoåŽããæ³å®ãšéãã¢ã«ãŽãªãºã ãæ¥ãããšãšã©ãŒãè¿ããŠããŸããSAã確ç«ããŸããããã®ã³ãã³ãã on ã«æç€ºããããšã§åé¡ãè§£æ¶ããŸãã ãŸããWANã€ã³ã¿ãŒãã§ã€ã¹(ä»åã¯PPPoEæ¥ç¶ãè¡ãPPã€ã³ã¿ãŒãã§ã€ã¹ã§ã)ã«ãŠä»¥äžã®ãã£ã«ã¿ãèšå®ããŠãã ãããIPsecã®éä¿¡ã«ãŠå©çšãããããã³ã«(ESP, UDP/500)ã®èš±å¯ã§ãã ip filter <ãã£ã«ã¿çªå·> pass <CatoPoPã®åºå®ã°ããŒãã«IPã¢ãã¬ã¹> <ã«ãŒã¿ã®Global IPã¢ãã¬ã¹> esp * * ip filter <ãã£ã«ã¿çªå·> pass <CatoPoPã®åºå®ã°ããŒãã«IPã¢ãã¬ã¹> <ã«ãŒã¿ã®Global IPã¢ãã¬ã¹> udp * 500 ã«ãŒãã£ã³ã°ã®èšå®ã«ã泚æç¹ããããŸãã ãŸãã以äžã®IPã¢ãã¬ã¹ã¯å¿
ãtunnelã«åãã(Catoç¶²ãžã«ãŒãã£ã³ã°ããã)å¿
èŠããããŸãã Catoã®èšåIPã¢ãã¬ã¹ 10.254.254.1 / .5 / .253 Catoç¶²å
ã®ä»æ ç¹ã®IPã¢ãã¬ã¹ã¬ã³ãžãã¢ãã€ã«ãŠãŒã¶ã®IPã¢ãã¬ã¹ã¬ã³ãž æ ç¹ã®ã«ãŒãã£ã³ã°èŠä»¶ã«ããããŸãããéåžžã¯æ ç¹å
ã®ãã¹ãŠã®éä¿¡ã«ã€ããŠCatoç¶²ãéãã®ãæšå¥šã§ãã®ã§ã以äžã®ãããªã«ãŒãã£ã³ã°ã«ãªãããšæããŸãã Primaryã®PoPã«é害ãçºçããå Žåã«åããtunnel1ãdownããŠãtunnel2ã§éä¿¡ç¶ç¶ã§ããããã«èšå®ããŠãããŸãããã ip route default gateway tunnel 1 hide gateway tunnel 2 weight 0 # åºæ¬çã«ãã¹ãŠã®éä¿¡ã¯tunnel1ã«åããtunnel1ã®downæã¯tunnel2ã䜿ã ip route <Primaryã®CatoPoPã®åºå®ã°ããŒãã«IPã¢ãã¬ã¹> gateway pp 1 # CatoPoPãšã®IPsec確ç«ã«ã¯pp1(PPPoEã€ã³ã¿ãŒãã§ã€ã¹)ã䜿ã ip route <Secondaryã®CatoPoPã®åºå®ã°ããŒãã«IPã¢ãã¬ã¹> gateway pp 1 以äžãèšå®ããããYAMAHAã«ãŒã¿ãInternetã«æ¥ç¶ããæ¥ç¶ã§ãããã確èªããŸãã æ¥ç¶ç¢ºèª IPsecãæ£åžžã«åŒµããŠãããã©ããã¯ã以äžã®æ¹æ³ã§ç¢ºèªããŸãã YAMAHAã«ãŒã¿ã§ã®ç¶æ
ç¢ºèª # show status tunnel <ãã³ãã«çªå·> ããã³ãã«ã€ã³ã¿ãŒãã§ãŒã¹ã¯æ¥ç¶ãããŠããŸãããšåºãŠããã°ãæ£åžžã«UPããŠããŸãã # show status tunnel 1 TUNNEL[1]: 説æ: ã€ã³ã¿ãã§ãŒã¹ã®çš®é¡: IPsec ãã³ãã«ã€ã³ã¿ãã§ãŒã¹ã¯æ¥ç¶ãããŠããŸã éå§: 2024/01/29 18:38:23 éä¿¡æé: 21å6ç§ åä¿¡: (IPv4) 105 ãã±ãã [9660 ãªã¯ããã] (IPv6) 0 ãã±ãã [0 ãªã¯ããã] éä¿¡: (IPv4) 134 ãã±ãã [10872 ãªã¯ããã] (IPv6) 0 ãã±ãã [0 ãªã¯ããã] IKEããŒãã¢ã©ã€ã: [ã¿ã€ã]: rfc4306 [ç¶æ
]: OK [次ã®éä¿¡]: 5 ç§åŸ ç°åžžãªå Žåã«ã¯ãããã³ãã«ã€ã³ã¿ãã§ãŒã¹ã¯äžåºŠãæ¥ç¶ãããŠããŸããããšåºãããäœã衚瀺ãããªãã£ããããŸãã CMAã§ã®ç¶æ
ç¢ºèª Monitoringã®Topologyã«ãŠãSite Statusã Connected ãšãªã£ãŠããããšã確èªããŸãã ãŸããIPSEC DETAILS ã«ãŠãPrimaryãšSecondaryããããã®æ¥ç¶ç¶æ³ã確èªã§ããŸãã æ¥ç¶ã§ããŠããªãå Žåã¯ãæ ç¹ãèµ€ã衚瀺ãšãªããSite Statusã¯DisconnectedãšãªããŸãã ãŸããIPsecã®èšå®ç»é¢ã«ãŠãConnection Statusããã¿ã³ãæŒããšãæ°ç§ããåŸãçŸåšã®æ¥ç¶æ
å ±ã衚瀺ãããŸããåŸ
ã£ãŠãäœã衚瀺ãããªãå Žåã¯ãæ¥ç¶ã§ããŠããŸããã æ£åžžã«æ¥ç¶ã§ããããã«ãŒã¿ã®LANåŽã®ç«¯æ«ãããä»Siteãã€ã³ã¿ãŒããããžã®éä¿¡ãã確èªãã ããã ç¹ãããªãå Žåã®ãã©ãã«ã·ã¥ãŒã ç¶ããŠãIPsecãç¹ãããªããšãã®åãåãæ¹æ³ãã玹ä»ããŸãã åãåãã¯æéãããããå¿ãæããããšããããŸãããåçŽã«éµäº€æã«äžæçã«å€±æããŠããã ããšããããšãå€ãã®ã§ããŸãã¯ãã³ãã«ã®ãªã»ãããããããããŸãã ãã³ãã«ã®ãªã»ãã YAMAHAã«ãŒã¿åŽããã®ãã³ãã«ãªã»ãã # ipsec sa delete all ã³ãã³ãå
¥ååŸäœãåºãŸããããããã«SAãäœãçŽããããŸããallã§ã¯ãªãç¹å®ã®SAã®ã¿äœãçŽããããšãã¯ãshow ipsec sa ã§ SAçªå·ãç¹å®ããallã®ä»£ããã«çªå·ãæå®ããŸãã CatoåŽããã®ãã³ãã«ãªã»ãã Primary/SecondaryãããããIPsecã®èšå®ç»é¢ã«ãããReset Tunnelããã¿ã³ããResetãå¯èœã§ãã ãªã»ããããæ°ååŸ
ã£ãŠãæ¥ç¶ãããªãå Žåãäžæçãªåé¡ã§ã¯ãªããšèããããããããã©ãã«ã·ã¥ãŒãã«é²ã¿ãŸãã CatoåŽãã°ã®ç¢ºèª ãŸãã¯CatoåŽã®ãã°ã確èªããŠã¿ãŸããæ¥ç¶ã§ããªãæ¹ã®tunnelã§ãTimelineããã¯ãªãã¯ãããšãCatoåŽã®ãã°ãcsv圢åŒã§ããŠã³ããŒããããŸãã ããããã§ ãFile not foundããšãšã©ãŒãåºãŠãã¡ã€ã«ãããŠã³ããŒããããªãå Žåããã°ãååšããŸããã æ¥ç¶ãå
šãå°éããŠããªããšããããšã«ãªããŸãã®ã§ã以äžã®ç¹ã確èªããŸãã ã«ãŒã¿ãInternetã«æ¥ç¶ã§ããŠããã ã«ãŒã¿ã®ipsec ike remote address ã§æå®ããCato PoPã®ã°ããŒãã«ã¢ãã¬ã¹ãééã£ãŠããªãã ã«ãŒã¿ã®ãã£ã«ã¿ã§ãPoPãšã®esp, udp500ã®éä¿¡ãç Žæ£ãããŠããªãã ã«ãŒã¿ããCato PoPã®ã°ããŒãã«IPã¢ãã¬ã¹ã«å¯ŸããŠPingãéãã CMAã«èšå®ãããã«ãŒã¿ã®ã°ããŒãã«IPã¢ãã¬ã¹ãééã£ãŠããªãã ãã°ãããŠã³ããŒãã§ããå Žåã¯ãçŽè¿ã®ãšã©ãŒå
容ã確èªããŸãã åºæ¬çã«ã¯ã«ãŒã¿ãšCatoã®ãã©ã¡ãŒã¿äžäžèŽãåå ãšãªããããäœãäžäžèŽãªã®ãã調ã¹ãä¿®æ£ããŠããäœæ¥ãšãªããŸãã äžäŸãšããŠãåœç€Ÿã®æ€èšŒã«ãŠç¢ºèªããCatoåŽã®ãšã©ãŒã¡ãã»ãŒãžãã玹ä»ããŸãã èªèšŒæ
å ±ã®äžäžèŽ Auth payload doesn't match the calculated one - wrong psk? Auth payload doesn't match dropping this sa èªèšŒæ
å ±ãäžèŽããªããšãããšã©ãŒã§ããPSKãnameã®èšå®ãåæ¹ã§ç°ãªã£ãŠããå Žåã«çºçããŸãã®ã§ã以äžã確èªããŸãã PSK(ãã¹ã¯ãŒã)ãCatoãšã«ãŒã¿ãšã§äžèŽããŠããããåèšå®ããŠã¿ãŠæ¹åããã ã«ãŒã¿åŽã®ipsec ike local name, ipsec ike remote name ã«çžæãšèªåã®ã°ããŒãã«IPã¢ãã¬ã¹ãæ£ããèšå®ãããŠããããã³ãã³ãæ«å°Ÿã®ãipv4-addrããæããŠããªãã DHã°ã«ãŒãã®äžäžèŽ DH group number in the KE property doesn't match the selected proposal [selected: 14, in KE payload: 5] ã«ãŒã¿ãæåã«å®£èšããDHã°ã«ãŒããšãå®éã«éä¿¡ããŠããDHã°ã«ãŒããéããšãããšã©ãŒã§ãã DH group GROUP_5_MODP1536 (5) in our proposal does not match DH group GROUP_14_MODP2048 (14) in peer's proposal 1 Catoãææ¡ããDHã°ã«ãŒããšãã«ãŒã¿ãææ¡ããŠããDHã°ã«ãŒããéããšãããšã©ãŒã§ãã ãããã®å Žåã以äžã確èªããŸãã CatoåŽãšã«ãŒã¿åŽã®DHã°ã«ãŒãèšå®(ipsec ike group)ãäžèŽããŠããã YAMAHAã«ãŒã¿ã« ipsec ike proposal-limitation <tunnelçªå·> on ãèšå®ãããŠããã â»ãã®èšå®ãæããŠãããšãæå®ããŠããªãDHã°ã«ãŒãã§éä¿¡ããŠããŸããŸã ãã®ä»åçš®ã¢ã«ãŽãªãºã ã®äžäžèŽ Encryption algorithm length AES_256 (256) in our proposal does not match encryption algorithm length AES_128 (128) in peer's proposal 1 PRF algorithm HMAC_SHA2_256 (5) in our proposal does not match PRF algorithm HMAC_SHA1 (2) in peer's proposal 1 Integrity algorithm HMAC_SHA2_256_128 (12) in our proposal does not match integrity algorithm HMAC_SHA1_96 (2) in peer's proposal 1 Catoãææ¡ããåçš®éä¿¡æ¹åŒãšãã«ãŒã¿ãææ¡ããŠããã¢ã«ãŽãªãºã ãéããšãããšã©ãŒã§ãããããã®å Žåãã以äžã確èªããŸãã YAMAHAã«ãŒã¿ã« ipsec ike proposal-limitation <tunnelçªå·> on ãèšå®ãããŠããã â»ãã®èšå®ãæããŠãããšãæå®ããŠããªãã¢ã«ãŽãªãºã ã§éä¿¡ããŠããŸããŸã ãšã©ãŒãåºãŠããèšå®é
ç®ã«ã€ããŠãCatoã®ã¢ã«ãŽãªãºã èšå®ãAutoã«ããŠæ¹åããã ãšã©ãŒãåºãŠããèšå®é
ç®ã«ã€ããŠãCatoã®ã¢ã«ãŽãªãºã èšå®ãã«ãŒã¿ãšåãå€ã§åºå®æå®ã«ããŠæ¹åããã ãšã©ãŒãåºãŠããèšå®é
ç®ã«ã€ããŠãCatoã»ã«ãŒã¿åæ¹ã®ã¢ã«ãŽãªãºã æ¹åŒãä»ã®æ¹åŒã«å€ããŠæ¹åããã ãã¹ãŠç¢ºèªããŠããšã©ãŒãè§£æ¶ãããªãå ŽåãCato PoPåŽã®åé¡ã§ãããã©ããã®åãåããšããŠãä»ã®ãã±ãŒã·ã§ã³ã®Cato PoPã®IPã¢ãã¬ã¹ãååŸãããã¡ããštunnelã匵ãããã確èªãã ããã (ãåè)YAMAHAã«ãŒã¿åŽç¢ºèªæ¹æ³ åé¡åãåãã®éã¯ãCatoåŽã®ãã°ãšããããŠãYAMAHAã«ãŒã¿åŽã§ãç¶æ³ãã確èªãã ããã 確èªã³ãã³ãã®äŸ show ipsec sa SAã確ç«ã§ããŠãããã©ããã確èªã§ããŸãã以äžã¯tunnelã2æ¬åŒµã£ãå Žåã®æ£åžžäŸã§ãã1ã€ã®tunnelã«å¯Ÿããphase1ã§1ã€ãphase2ã§2ã€ã®SAã確ç«ãããŸãã ãã®ã³ãã³ããèŠãããšã§ãphase1ã®ç¢ºç«ã§å€±æããŠããã®ãããŸãã¯phase2ã§å€±æããŠããã®ãã®åãåããã§ããŸãã # show ipsec sa Total: isakmp:2 send:2 recv:2 sa sgw isakmp connection dir life[s] remote-id ----------------------------------------------------------------------------- 1 1 - ike - 17106 <æ±äº¬PoPã®ã°ããŒãã«IPã¢ãã¬ã¹> 2 2 - ike - 18598 <ãã³ãã³PoPã®ã°ããŒãã«IPã¢ãã¬ã¹> 3 2 2 tun[002]esp send 2398 <ãã³ãã³PoPã®ã°ããŒãã«IPã¢ãã¬ã¹> 4 2 2 tun[002]esp recv 2398 <ãã³ãã³PoPã®ã°ããŒãã«IPã¢ãã¬ã¹> 5 1 1 tun[001]esp send 906 <æ±äº¬PoPã®ã°ããŒãã«IPã¢ãã¬ã¹> 6 1 1 tun[001]esp recv 906 <æ±äº¬PoPã®ã°ããŒãã«IPã¢ãã¬ã¹> show ipsec sa gateway <tunnelçªå·> detail ããã«SAã®è©³çްæ
å ±ãèŠãã³ãã³ãã§ãã以äžã¯æ£åžžäŸã§ãã æ£åžžã«è¡šç€ºãããŠããªãç®æããæå³ããªãèšå®ã«ãªã£ãŠããç®æããªãã確èªããŸãã # show ipsec sa gateway 1 detail SA[1] ç¶æ
: ç¢ºç«æž 寿åœ: 15014ç§ ãããã³ã«: IKEv2 ããŒã«ã«ãã¹ã: <ã«ãŒã¿ã®ã°ããŒãã«IPã¢ãã¬ã¹>:<ããŒã> ãªã¢ãŒããã¹ã: <æ±äº¬PoPã®ã°ããŒãã«IPã¢ãã¬ã¹>:<ããŒã> æå·ã¢ã«ãŽãªãºã : AES256_CBC PRF : HMAC_SHA2_256 èªèšŒã¢ã«ãŽãªãºã : HMAC_SHA2_256_128 DHã°ã«ãŒã: MODP_1024 SPI: <SPIæåå> éµ : <鵿åå> ---------------------------------------------------- SA[5] ç¶æ
: ç¢ºç«æž 寿åœ: 1522ç§ éåä¿¡æ¹å: éä¿¡ ãããã³ã«: ESP (ã¢ãŒã: tunnel) ããŒã«ã«ID: <ã«ãŒã¿ã®ã°ããŒãã«IPã¢ãã¬ã¹> (IPv4_ADDR) ãªã¢ãŒãID: <æ±äº¬PoPã®ã°ããŒãã«IPã¢ãã¬ã¹> (IPv4_ADDR) æå·ã¢ã«ãŽãªãºã : AES256_CBC èªèšŒã¢ã«ãŽãªãºã : HMAC_SHA2_256_128 ESN: DISABLE å§ç¹ãã©ãã£ã㯠ã»ã¬ã¯ã¿ (ã¿ã€ã / ãããã³ã« / ããŒã / ã¢ãã¬ã¹) IPv4-range / any / 0-65535 / 0.0.0.0-255.255.255.255 çµç¹ãã©ãã£ã㯠ã»ã¬ã¯ã¿ (ã¿ã€ã / ãããã³ã« / ããŒã / ã¢ãã¬ã¹) IPv4-range / any / 0-65535 / 0.0.0.0-255.255.255.255 SPI: <SPIæåå> éµ : <鵿åå> ---------------------------------------------------- SA[6] ç¶æ
: ç¢ºç«æž 寿åœ: 1522ç§ éåä¿¡æ¹å: åä¿¡ ãããã³ã«: ESP (ã¢ãŒã: tunnel) ããŒã«ã«ID: <ã«ãŒã¿ã®ã°ããŒãã«IPã¢ãã¬ã¹> (IPv4_ADDR) ãªã¢ãŒãID: <æ±äº¬PoPã®ã°ããŒãã«IPã¢ãã¬ã¹> (IPv4_ADDR) æå·ã¢ã«ãŽãªãºã : AES256_CBC èªèšŒã¢ã«ãŽãªãºã : HMAC_SHA2_256_128 ESN: DISABLE SPI: <SPIæåå> éµ : <鵿åå> ---------------------------------------------------- show log éåžžã®ãã°ã«ãSAç¢ºç«æåã»å€±æçã®ãã°ãåºãŸãã®ã§ããšã©ãŒå
容ããã©ãã§å€±æããŠããã®ãã確èªããŸãã ãªãã以äžã®èšå®ãããŠããããšã§ããã詳现ãªãã°ã»ãããã°æ
å ±ã衚瀺ãããããã«ãªããŸãã ipsec ike log 1 key-info message-info payload-info syslog debug on â»ãã°ã倧éã«ãªããããæ£åžžã«æ¥ç¶ã§ããåŸã¯OFFãæšå¥šã§ã ãŸãšã 以äžãé·ããªããŸããããYAMAHAã«ãŒã¿ã§ã®IPsecæ¥ç¶ã®ã玹ä»ã§ããã æ€èšŒæããã©ã¡ãŒã¿ãæ£ããäžèŽãããŠããã€ãããªã®ã«äžäžèŽã®ãšã©ãŒã§ç¹ããããããªãæ©ãŸãããŸããããã»ãšãã©ãYAMAHAåŽã®èšå®ã®äžè¶³ãçžéãåå ã§ãããä»åã玹ä»ãããµã³ãã«Configã¯æ£åžžã«æ¥ç¶ã§ããåŸã®ãã®ã§ãã®ã§ãã©ãªããã®åèã«ãªããŸããã幞ãã§ãã ææ³ãšããŠãPoPãšã®æ¥ç¶ãã«ãŒãã£ã³ã°ãé害åãæ¿ããããã¹ãŠèªåã§è¡ã£ãŠããã Cato Socketã®æ¥œãã身ã«ãã¿ãŸããâŠã äœããã®äºæ
ã§Socketãå©çšã§ããIPsecæ¥ç¶ãè¡ãããéã«ã¯ããªããªãèŠåŽããŸãã®ã§ãæºåã»æ€èšŒã«ååãªæéãåãããšãããããããŸãã
æè¿å¥åº·èšºæãã人éããã¯ã«ã©ã³ã¯ã¢ãããããæœ®ã§ãã æ®æ®µAWSã®ããŒã¿ããŒã¹ç³»ãµãŒãã¹ãç¹ã«Amazon RDSãAmazon Auroraçã®RDBç³»ã®ãµãŒãã¹ãäžå¿ã«æ€èšŒãæ§ç¯ããã¥ãŒãã³ã°çã
ããŠããŸãã ä»åã¯ã¡ãã£ãšå€ãã£ãDBãšããŠãOracle瀟ãAWSäžã§åããDBãšããŠæäŸããŠãããMySQL HeatWave on AWSããã玹ä»ããŸãã MySQL HeatWave on AWSãšã¯ïŒ MySQL HeatWave on AWSã¯ãOLTPç³»ã®åŠçã¯MySQLã§æããOLAPç³»ã®åŠçã¯åæçšã«ãã¶ã€ã³ãããHeatWaveããŒãã«ãªãããŒãããŠæãããšãããOLTPãšOLAPã®äž¡å©ããç®æããããŒã¿ããŒã¹ã§ããååã®éãAWSäžã§çšŒåãããããäŒç€Ÿå
šäœã§AWSãåºç€ã€ã³ãã©ãšããŠå
šé¢æ¡çšããŠããå Žåããã¢ããªã¯ããããã³ããšã³ããAWSäžã«ããå Žåã«ãã¬ã€ãã³ã·ãéä¿¡ã»ãã¥ãªãã£äžã®ã¡ãªããããããŸãããŸããæè¿ã®ã¢ããããŒãã§ãMySQL HeatWave on AWSå€ããã®ã€ã³ããŠã³ãã¬ããªã±ãŒã·ã§ã³ãã§ããããã«ãªã£ãããšã§ãä»ããMySQLã«æ ŒçŽãããŠããããŒã¿ãåæã«ãããŠã¿ããããšããèŠæã«å¯ŸããŠãåã«ã¹ã¬ãŒãã远å ããæèŠã§åæçšDBã远å ã§ããããã«ãªããŸããã ãã®MySQL HeatWaveã¯ãå
ã
ã¯Oracle Cloud InfrastructureïŒOCIïŒäžã§æäŸãããŠãããµãŒãã¹ã§ãããããããAWSäžã§ã䜿ããããã«ãªããŸããããšããã®ãMySQL HeatWave on AWSã§ãããªããon AzureãååšããŸãã ã¢ãŒããã¯ãã£ã¯ä»¥äžã®éãã§ãOracle瀟管çã®AWSã¢ã«ãŠã³ãäžã§çšŒåããŠããMySQL/HeatWaveããŒãã«å¯ŸããŠãã«ã¹ã¿ããŒAWSã¢ã«ãŠã³ãïŒå¥ã«ãã以å€ã§ãããã§ããïŒããã¢ã«ãŠã³ãè¶ãã«ã¢ã¯ã»ã¹ããããšã«ãªããŸãã MySQLããŒãã¯éåžžã®MySQLåæ§ããŒã¿ãæ°žç¶åãã£ã¹ã¯ã«æã¡ãŸãããHeatWaveããŒãã§ã¯ã€ã³ã¡ã¢ãªã§ããå
šãŠã®ããŒã¿ãHeatWaveããŒãã«æãããå¿
èŠã¯ãªããOLAPç³»åŠçãèŠèŸŒãŸããããŒãã«ã®ã¿HeatWaveããŒãã«ããŒãããããšããããšãã§ããŸãã å
šãŠã®ã¯ãšãªã¯äžåºŠMySQLããŒãã§åããã®ã§ãããããã§ãªããã£ãã€ã¶ãHeatWaveãããMySQLã§å®è¡ããæ¹ãæ©ããšå€æããå Žåã¯ãããšã察象ããŒãã«ãHeatWaveã«ããŒããããŠããŠãMySQLããŒãã§åŠçããŠãããŸãã åæåŠçã®é«éåç¢ºèª MySQL HeatWave on AWSã§åæåŠçãã©ã®çšåºŠæ©ããªããã確èªããŸããä»åã¯ãäŒç¥šåŠçã§ããŒã¿ã倧ããè²ã£ãŠããŸã£ãŠMySQLã§ã¯æéããããããã«ãªã£ãŠããŠããŸã£ãããšããç¶æ³ãæ³å®ããŸããã¯ãšãªã¯å®éã«ãœãããŠã§ã¢äžã§åããŠãããã®ãããŒã¹ã«ããŠãããåŠçã®æŠèŠãšã¬ã³ãŒãã®æŠæ°ã¯ä»¥äžã®éãã§ãã åŠçæŠèŠ å¯Ÿè±¡ããŒãã«å
ã¬ã³ãŒãæ° ç¹å®æ¡ä»¶ããšã®ä»èš³äŒç¥šæ°åºå 30,000,000 ç¹å®æ¡ä»¶ããšã®ä»èš³æçްæ°åºå 200,000,000 ç¹å®æ¡ä»¶ããšã®ä»èš³æçްæ°åºåïŒé€å€æ¡ä»¶ 200,000,000 ç¹å®æ¡ä»¶ããšã®å°åž³æ®é«åºå 90,000,000 ãããã¯ãšãªããMySQLãšHeatWaveããããã§åŠçãããå Žåã®åŠçæéã¯ä»¥äžã§ããã åŠçæŠèŠ MySQLïŒInnoDBïŒ HeatWave ç¹å®æ¡ä»¶ããšã®ä»èš³äŒç¥šæ°åºå 9 s 0.2 s ç¹å®æ¡ä»¶ããšã®ä»èš³æçްæ°åºå 44 s 0.4 s ç¹å®æ¡ä»¶ããšã®ä»èš³æçްæ°åºåïŒé€å€æ¡ä»¶ 55 s 0.4 s ç¹å®æ¡ä»¶ããšã®å°åž³æ®é«åºå 210 s 0.2 s åŠçæéã¯åçã«æ¹åããŠãããã¯ãšãªã«ãã£ãŠã¯1000å以äžã®ã¬ã¹ãã³ã¹ã§ãããããªãã»ãšãã©ã®æ§èœèŠæ±ã¯æºãããŠããããã§ãã ãšã¯ããããã®ãããã®ã¬ã¹ãã³ã¹é床ã¯ãããŒã¿ãŠã§ã¢ããŠã¹ç³»ã®è£œåã§ããã°ããã»ã©ç¹çããŠæ©ããšãããã®ã§ããããŸãããMySQL HeatWave on AWSã®ãããšããã¯ããã®æ§èœãOLTPçšéã§äœ¿ã£ãŠããDBãã®ãã®ã§åºããããšãããã³ãã«MySQLãããããåŸæ¥ã®MySQLçšã«æžãããã¢ããªã§ãã¢ããªã«å€§ããªå€æŽãªã䜿ããããšãAWSäžã§åããŠããããä»ã³ã³ããŒãã³ããAWSäžã«ããã·ã¹ãã ã§ã®æ§èœäžã»ã»ãã¥ãªãã£äžã®ã¡ãªãããããããšããªã©ã§ãã ãŸãšã AWSã§ã¯Amazon Athenaãã¯ãããšããŠãMySQLäžã«ããããŒã¿ãåæããŒã«ããã¯ãšãªã§ããããã«ãããµãŒãã¹ããããŸããããããªãããæ¢æã®MySQLäºæã¢ããªããã£ãŠå€æŽãå°é£ãªå ŽåãAmazon Athenaçã®åæãµãŒãã¹ã§ã¯ååãªæ§èœæ°Žæºã«éããªãå ŽåçããããŸã§åæã諊ããããåŸãªãã£ããŠãŒã¹ã±ãŒã¹ã«å¯ŸããŠãæ°ããªéžæè¢ãšããŠèãããããã§ãã
ååã¯ãCSPMã«ã€ããŠè§£èª¬ããŸããããä»åã¯CWPPã«ã€ããŠè§£èª¬ãè¡ããŸãã CSPMããåç¥ãªãæ¹ã¯ãå
ã«ååã®CSPMã®èšäºãã芧ãã ããã 2024å¹Žææ°ç CSPMïŒCloud Security Posture ManagementïŒãšã¯ïŒ ã¯ã©ãŠãã»ãã¥ãªã㣠CSPMïŒCloud Security Posture ManagementïŒã«ã€ããŠã2024å¹Žã®ææ°æ
å ±ã解説ããŠããŸãã blog.usize-tech.com 2024.01.09 CWPPãšã¯ïŒ CWPPãšã¯ã Cloud Workload Protection Platform ïŒã¯ã©ãŠãã¯ãŒã¯ããŒããããã¯ã·ã§ã³ãã©ãããã©ãŒã ïŒã§ãæ¥æ¬èªèš³ã¯ã ã¯ã©ãŠãã¯ãŒã¯ããŒãä¿è·ãã©ãããã©ãŒã ããšèš³ãããŠããŸãã ã¯ã©ãŠãã¯ãŒã¯ããŒããšã¯ãã¯ã©ãŠããµãŒãã¹äžã§å®è¡ãããæ¥ååŠçãäœæ¥ïŒã¿ã¹ã¯ïŒãæå³ããå
·äœçã«ã¯ãä»®æ³ãã·ã³ïŒIaaSïŒããPaaSãã³ã³ããããµãŒãã¬ã¹ç°å¢ãªã©ã§å®è¡ãããåŠçãã¿ã¹ã¯ã®ããšã§ãã ã€ãŸããCWPPã¯ã ã¯ã©ãŠããµãŒãã¹äžã®ä»®æ³ãã·ã³ïŒVMïŒãªã©ã®IaaSãããŒã¿ããŒã¹ãªã©ã®PaaSãã³ã³ããããµãŒãã¬ã¹ãªã©ã«å¯ŸããŠãã»ãã¥ãªãã£ãããé©çšãè匱æ§å¯Ÿçã«äžåããªããã®ç£èŠãè¡ãããªã¹ã¯ãæ€åºããå Žåã«ãèšå®å€æŽã®ã¢ããã€ã¹ããå®éã®èšå®å€æŽãè¡ããœãªã¥ãŒã·ã§ã³ ãšãªããŸãã CWPPã¯ãCSPMãšã¯ã©ãŠãã»ãã¥ãªãã£ã®ããŒã«ãšããŠã¯åãã§ãããCSPMã¯ã¯ã©ãŠããµãŒãã¹ã®å©çšç°å¢å
šäœã®ä¿è·ãç®çã«ãIaaS/PaaSç°å¢ã«ãããã¢ã«ãŠã³ãããµãŒãã¹ã察象ã«ããŠããŸãããCWPPã¯ãã¯ã©ãŠãã¯ãŒã¯ããŒãä¿è·ãç®çãšããŠãä»®æ³ãã·ã³ïŒVMïŒãã³ã³ããããµãŒãã¬ã¹ãªã©ãIaaS/PaaSã«éå®ããã«ãæ§ã
ãªã¯ãŒã¯ããŒãã察象ã«ããŠããŸãã ãŸããCSPMã¯ã¯ã©ãŠããµãŒãã¹ã®æäŸããAPIãçšããŠèšå®æ
å ±ããã°ãååŸããèšå®ã®ç¢ºèªãããã®ã«å¯ŸããŠãCWPPã¯ãä»®æ³ãã·ã³ãã³ã³ãããªã©ã«ãšãŒãžã§ã³ããå°å
¥ããã»ãã¥ãªãã£ã®ç£èŠãããå Žåãå€ãã§ãã ã»ãã¥ãªãã£èšå®äžåããOSã®ã»ãã¥ãªãã£ãããé©çšç¶æ³ãããã«ãŠã§ã¢ã®èåŒ±æ§æç¡ãã¢ã³ããã«ãŠã§ã¢ãœããã®ãã¿ãŒã³ãã¡ã€ã«æŽæ°ç¶æ³ãã¹ãã£ã³ç¶æ³ããã§ãã¯ããŸãã CWPPã®èæ¯ ãããŸã§ã®ã¢ããªã·ãã¯ïŒäžæå²©ïŒãªãµãŒãã¹éçºã§ã¯ãªããæè¿ã®ãã€ã¯ããµãŒãã¹ã¢ãŒããã¯ãã£ã§ã¯ãè€æ°ã®å°èŠæš¡ãã€è»œéã§ãäºãã«ç¬ç«ãããµãŒãã¹ãçµã¿åãããŠå®è£
ããææ³ãšãªã£ãŠãããã¢ããªã±ãŒã·ã§ã³ã¯ãä»®æ³ãã·ã³ã§ã¯ãªããããå©çšãããªãœãŒã¹ãå°ãªãã³ã³ããäžã§çšŒåããäºäŸãå¢ããŠããŠããŸãã ãã®ããããããŸã§ã®ãªã³ãã¬ãã¹ã®ãµãŒãããä»®æ³ãã·ã³ãšã¯æ¯èŒã«ãªããªãã»ã©å€ãã®ã³ã³ããã皌åããããã«ãªã£ãŠããŸãã ã³ã³ããã¯ãããã±ãŒãžåã容æã§ãå®è¡å Žæãéžã°ãã1å°ã®ä»®æ³ãã·ã³äžã«ãè€æ°ã®ã³ã³ãããå±éã§ããããšãå¯èœãšãªã£ãŠãããä»®æ³ãã·ã³ããæºåããããšãå¯èœã§ããã CaaSïŒContainer as a SericeïŒ ãšããŠã¯ã©ãŠããµãŒãã¹ãšããŠæäŸãããŠããŸãã æ¬¡ã«ããµãŒãã¬ã¹ã¢ãŒããã¯ãã£ãå¢ããŠããŸãããµãŒãã¬ã¹ã¯ã FaaSïŒFunction as a ServiceïŒ ãšãèšãããŸãããAWSã®ãLambdaïŒã©ã ãïŒããAzureã®ãAzure FunctionsããGCPã®ãGoogle Cloud Functionsãã«ä»£è¡šããããããŸã§ã®ä»®æ³ãã·ã³ãå©çšããã«ãã¢ããªã±ãŒã·ã§ã³éçºãè¡ãææ³ãšãªããŸãã éåžžã¯ãããã°ã©ã ãå®è¡ãããµãŒããåžžã«çšŒåãç¶ããŠããå¿
èŠããããŸããããµãŒãã¬ã¹ã§ã¯ããµãŒããå¿
èŠãšããªãããããµãŒãèªäœã®ã³ã¹ããæããããéçšãä¿å®ãå©çšã®ããã®æºåæéã®ççž®ãè¡ããŸãã ãµãŒãã¬ã¹ã¯ãå®éã«ä»®æ³ãã·ã³ã䜿ã£ãŠããªãèš³ã§ã¯ãªããã¯ã©ãŠããµãŒãã¹ãããã€ããŒåŽãæºåããä»®æ³ãã·ã³ãäžæçã«å©çšãã圢æ
ãšãªããŸãã ãã®ãã㪠ãã€ã¯ããµãŒãã¹ã®ãããªéçºææ³ã®å€åããã¯ã©ãŠããµãŒãã¹ã®é²åã«ãããã³ã³ããããµãŒãã¬ã¹ã®å©çšãå¢å ããŠããŸã ã ã³ã³ããããµãŒãã¬ã¹ã¯ãä»®æ³ãã·ã³ãšå€§ããã¢ãŒããã¯ãã£ãç°ãªããã³ã³ããã¯åžžã«çšŒåããŠããèš³ã§ã¯ãªããæ¬¡ã
ãšæ°ãã«äœæãããäžèŠã«ãªããšããã«åé€ãããŸãããŸãããµãŒãã¬ã¹ã¯ã¯ã©ãŠããµãŒãã¹ãããã€ããæºåããä»®æ³ãã·ã³ã®ãããå©çšè
ã管çããããšãã§ããªãããããããŸã§ã®ITéçšæ
åœè
ã®éçšæ¹æ³ã§å¯Ÿå¿ãé£ããå Žåãå€ãã§ãã ITéçšè
ã管çãã§ãããè
åšãèŠããªããªã£ãŠããã»ãã¥ãªãã£ãªã¹ã¯ã¯å€ãããŸãã ã ã³ã³ããããµãŒãã¬ã¹ã«ã€ããŠãã責任ã¯ãååCSPMã§èšèŒããããã«ã責任å
±æã¢ãã«ãæ¹ãã責任åæ
ã¢ãã«ãã«ãŠããã¡ããšè²¬ä»»åçç¹ãèšå®ãããŠãããæ®ã©ã®è²¬ä»»ã«ã€ããŠã¯ãå©çšè
åŽãè² ãããšã«ãªã£ãŠããŸãã æ»æè
ã«ããæªæã®ããã³ã³ããã€ã¡ãŒãžããããªãã¯ãªã¬ããžããªã«ç»é²ãããããã«æ°ã¥ããã«å©çšããæ»æè
ã容æã«äžæ£äŸµå
¥ãèš±ããŠããŸããã³ã³ããã®è匱æ§ãã€ããŠããã¹ãOSãžã¢ã¯ã»ã¹ããäžæ£ããã°ã©ã ãå®è¡ãããããšããããŸãã ã³ã³ããç°å¢ã®Kubernetesã®èšå®ãã¹ãããã¹ãOSãä¹ã£åãããäºäŸããããŸãã ãµãŒãã¬ã¹ã§ã¯ãAWS Lambdaã§æäŸãããŠããè匱æ§ã®ããWebãµã€ãã«ãŠãURLã«ç¹å®æååãå
¥ãAWS Lambdaã®æ
å ±ãååŸãããã«AWS Lambdaã®ç°å¢å€æ°ãèŠãã¹ã¯ãªããã§ã¯ã¬ãã³ã·ã£ã«æ
å ±ïŒèªèšŒID/ãã¹ã¯ãŒããã¢ã¯ã»ã¹ããŒïŒãååŸãããã®ã¯ã¬ãã³ã·ã£ã«æ
å ±ãå©çšããŠç®¡çè
æš©éãä»äžããã°ãAWS S3ã®æ
å ±ãé²èЧããå¯èœãšãªããŸãã AWS Lambdaã¯ããããŸã§ã®ããã«ä»®æ³ãã·ã³ã«ãåŸæ¥ã®ã»ãã¥ãªãã£å¯ŸçãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ããŠä»®æ³ãã·ã³ããšå®ãæ¹æ³ã¯è¡ããŸããããªããªã責任åæ
ã¢ãã«ã«åããå©çšè
ã¯ãã¯ã©ãŠããµãŒãã¹ãããã€ããŒã®AWS Lambdaã®æäŸããä»®æ³ãã·ã³ïŒãµãŒãã¬ã€ã€ïŒã«ãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ã§ããªãããã§ãã CWPPã®5ã€ã®ç¹åŸŽ ã¯ã©ãŠããµãŒãã¹ã®ã»ãã¥ãªãã£äžåã«ãããªã¹ã¯ãäœæžãããCWPPã®äž»ãªæ©èœãšããŠã¯ã以äžã®5ã€ãšãªããŸãã 1. ãã«ãã¯ã©ãŠãå¯Ÿå¿ AWSã ãã§ã¯ãªããAzureãGCPãªã©ã®è€æ°ã®ã¯ã©ãŠããµãŒãã¹ãããã€ããŒããµããŒãããŠããŸãã ãã«ãã¯ã©ãŠãç°å¢ã®ã¯ã©ãŠãã¯ãŒã¯ããŒãïŒä»®æ³ãã·ã³ãã³ã³ããããµãŒãã¬ã¹çïŒããµããŒãããŠããã管çã³ã³ãœãŒã«ãçµ±äžããããªã·ãŒã«ããäžå
çã«ç®¡çããããšãå¯èœã§ãã 2.è匱æ§ç®¡ç ã¯ã©ãŠãã¯ãŒã¯ããŒãã«ååšããè匱æ§ã宿çã«ç£èŠããç¹å®ã®ã»ãã¥ãªãã£ããŒã«ãåé¡ãæ€åºããåæã»ç®¡çãè¡ãã ãœãªã¥ãŒã·ã§ã³ã«ãã£ãŠã¯åé¡ã修埩ããæ©èœãå«ãŸããŸãã 3.䟵å
¥æ€ç¥ãšã©ã³ã¿ã€ã é²åŸ¡ ã¯ã©ãŠãã¯ãŒã¯ããŒãã«å¯Ÿããäžæ£ã¢ã¯ã»ã¹ãæ»æãçãããåäœããæªæã®ããåäœã»ãã©ãã£ãã¯ãæ€åºããé©åãªå¯Ÿçãé²åŸ¡ãè¡ãã 4.ã³ã³ãã©ã€ã¢ã³ã¹ç®¡ç æ§ã
ãªæ³èŠå¶ãäŒæ¥ã®ã»ãã¥ãªãã£ããªã·ãŒã«åŸã£ãŠã¯ãŒã¯ããŒããéçšãããŠããããç£èŠããããªã·ãŒéåããªãããç£èŠã»ç®¡çããŸãããŸããä»åŸæ°ããæœè¡ãããã«ãŒã«ã«ããã¡æ©ã察å¿ãè¡ãããšãå¯èœã«ãªããŸãã 5. èªååãšãªãŒã±ã¹ãã¬ãŒã·ã§ã³ ã»ãã¥ãªãã£ããã»ã¹ã察å¿çã®èªååãçµã¿èŸŒãŸããŠããã人æã®å¯Ÿå¿ãæå°éã«æãã€ã€ãå¹ççãªã»ãã¥ãªãã£ã®å®çŸãå¯èœã§ãã ã€ãã³ãã®èªå察å¿ãã»ãã¥ãªãã£ã¿ã¹ã¯ã®ãªãŒã±ã¹ãã¬ãŒã·ã§ã³ã«ãããè¿
éãªå¯Ÿå¿ãå®çŸãããŸãã åèïŒã¯ã©ãŠãã»ãã¥ãªãã£ã«ãããŠãCSPMãåãããŠããåºçŸããèšè CWPPãšåãããŠãã䜿ãããèšèãšããŠã¯ä»¥äžããããŸããCWPPãCIEMãCNAPPã«ã€ããŠã¯ãå¥éæ¹ããŠèšäºã«ããäºå®ã§ãã ã» CSPM ïŒCloud Security Posture ManabementïŒïŒã¯ã©ãŠããµãŒãã¹ã®æ
å¢ïŒç¶æ
ïŒã®ç®¡ç ã» CIEM (Cloud Infrastructure Entitlement Management) ïŒã¯ã©ãŠããµãŒãã¹ã®ã¢ã¯ã»ã¹æš©éã®ç£èŠ/管ç ã» CNAPP ïŒCloud Native Application Protection PlatformïŒïŒCSPM/CIEM/CWPPãå«ããã©ãããã©ãŒã ãã·ãŒããããšåŒã°ããŸãã ã» CASB ïŒCloud Access Security BrokerïŒïŒã¯ã©ãŠããµãŒãã¹ã®å©çšãå¯èŠå/ç£èŠ/é©åãªã¢ã¯ã»ã¹å¶éã宿œããã£ã¹ããŒãšåŒã°ããŸãã ãŸãšã ååCSPMã«ã€ããŠã¯ãå°å
¥ããããªãæ€èšããã®ã§ã¯ãªããè匱æ§èšºæã®ããã«ãŸãã¯CSPMãå©çšãããµãŒãã¹ãäžåºŠã¹ãããã§ãå©çšãããã®ãè¯ãã®ã§ã¯ãªãããšèããŠãããSCSKã§ã¯ã Palo Alto NetworksïŒããã¢ã«ããããã¯ãŒã¯ã¹ïŒç€Ÿ ã®CSPMã Prisma Cloud ããæ¡çšãããããŒãžããµãŒãã¹ãæäŸããŠãããŸããšãäŒãããŸããã CWPPã«ã€ããŠã¯ããšãŒãžã§ã³ãå°å
¥ãå¿
èŠãªããšããããçŸæç¹ã§ã¯æ®å¿µãªããã¹ãããã§ã®èšºæãµãŒãã¹æäŸã¯ããŠãããŸããããåãããPrisma CloudããCWPPããµããŒãããŠãããŸãã®ã§ããããŒãžããµãŒãã¹ãæäŸããŠãããŸãã ãSmart One Cloud SecurityããšããŠãåžžæç£èŠïŒMonitoringïŒãããããŒãžããµãŒãã¹ããæäŸããŠãããŸãã®ã§ããèå³ãããããæ¹ã¯æ¯éããåãåãããã ããã Smart One Cloud Security® ãããªãã¯ã¯ã©ãŠãã®ã»ãã¥ãªãã£èšå®ã蚺æ/ç£èŠãããããŒãžãCSPMãµãŒãã¹ã§ããPalo Alto Networks瀟Prisma CloudïŒCSPMæ©èœïŒã䜿ãæããç°¡åã«å°å
¥ããã ããŸãã www.scsk.jp ååã®ç¹°ãè¿ãã§ãããCSPMã«ã€ããŠã¯ã ãã«ãã¯ã©ãŠãèšå®èšºæãµãŒãã¹ with CSPM ããšããŠãã¹ãããã§ã®èšºæãµãŒãã¹ïŒ30äžåïœïŒãæäŸããŠãããŸãã®ã§ããŸãã¯èªç€Ÿã®ã¯ã©ãŠããµãŒãã¹ã®è匱æ§èšºæïŒïŒã¯ã©ãŠãèšå®èšºæïŒã宿œãããŠã¿ãã®ãè¯ããšæããŸãã 宿çïŒå幎ãååææ¯ïŒã«ã¹ããã蚺æã宿œããããšãå¯èœã§ããããã¡ããåžžæç£èŠãããµãŒãã¹ããæäŸããŠããã以äžã®ãµãŒãã¹ç޹ä»ããŒãžã«åœç€Ÿãªãªãžãã«ã®æ¥æ¬èªã§ã®èšºæã¬ããŒããµã³ãã«ãããããŸãã®ã§ããèå³ãæãããæ¹ã¯ãæ¯éããŠã³ããŒãããé¡ãããŸãã マルチクラウド設定診断サービス with CSPM| SCSK株式会社 ãã«ãã¯ã©ãŠãç°å¢ã®ã»ãã¥ãªãã£èšå®ãªã¹ã¯ãæè»œã«ç¢ºèªå¯èœãªã¹ããã蚺æãµãŒãã¹ã§ããç¬èªã®èšºæã¬ããŒãããéçšäžã®èšå®ãã¹ãèšèšäžåãã¯ã©ãŠãç°å¢ã®ä»æ§å€æŽãªã©ã§çºçãåŸãåé¡ãå¯èŠåããã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®æ©æçºèŠã«åœ¹ç«ã¡ãŸãã www.scsk.jp ãŸããCSPMãCWPPãªã©ã¯ã©ãŠãã»ãã¥ãªãã£ãã玹ä»ããã»ãããŒãéæéå¬ããŠãããŸãã®ã§ãæ¯éãåç»ãã ããã 以äžã¯ããæ
å ±ã»ãã¥ãªãã£ãããžã¡ã³ããã©ãŒã©ã 2024ãã«ãŠãDXæšé²ã«ããããªãã¯ã©ãŠãå©çšããã®ã»ãã¥ãªãã£å¯Ÿçãšã¯ïŒ ïœäºäŸã§åŠã¶ãã¬ããã³ã¹åŒ·åææ³ãšéçšã®ãã€ã³ãïŒïœãã§è¬æŒãè¡ããŸãã æ
å ±ã»ãã¥ãªãã£ãããžã¡ã³ããã©ãŒã©ã 2024 å®è·µäºäŸãšèããã»ãã¥ãªãã£ãããžã¡ã³ãã®æåç·äŒå¢äž¹ããŒã«ãã£ã³ã°ã¹ãäžè¬è²¡å£æ³äººæä»äŒãæ±äºå»ºèšå·¥æ¥æ ªåŒäŒç€Ÿãæ ªåŒäŒç€Ÿäžè¶äŒå¢äž¹ããŒã«ãã£ã³ã°ã¹ãç»å£ãæ
å ±ã»ãã¥ãªãã£ãããžã¡ã³ããã©ãŒã©ã 2024 r-management.jp
ã©ãããCatoã¯ã©ãŠããæ
åœããŠããäœã
æšã§ãã CatoãŠãŒã¶ããPoPåæ¿ã¿ã€ãã³ã°ãå¶åŸ¡ãããããšããåãåãããå€ãããã ããŸãã®ã§ã ä»å㯠PoPã®åæ¿ã«é¢ããåäœèª¬æïŒä»æ§ïŒãšåæ¿ã¿ã€ãã³ã°ã®å€æŽ ã«ã€ããŠç޹ä»ããŸãã â»ç»âŸ¯ã¯2024幎1âœæç¹ã®ãã®ã§ããæ©èœã¢ããããŒãçã§å€ããå ŽåããããŸãã®ã§ãããããããäºæ¿ãã ããã PoPéžæã«ã€ã㊠éåžžCatoã¯ã©ãŠããžæ¥ç¶ãéå§ãããšãèªåçã«ãŠãŒã¶ã®ãã±ãŒã·ã§ã³ã«æãè¿ãæå¯ãã®PoPã«æ¥ç¶ãããŸãã ãŸããåªå
ããŠæ¥ç¶ãããPoPãå®çŸ©ããŠããå ŽåããŸãåªå
PoPãšã®æ¥ç¶ã詊ã¿ãŸãã 詳现ã¯ãéå»ã®ããã°èšäºïŒã çµè·¯éžæã®ä»çµã¿ ãã Site(æ ç¹)ãæå®ã®PoPã«æ¥ç¶ãã ããããïŒãåç
§ãã ããã Catoã¯ã©ãŠã PoP (Point of Presence)ã«ã€ã㊠Catoã¯ã©ãŠãã®èãšãªããã€ã³ã¿ãŒããããä»ããŠCatoã¯ã©ãŠãã®ãµãŒãã¹ãå©çšããããã®ã¢ã¯ã»ã¹ãã€ã³ããPoP(Point of Presence)ã«ã€ããŠã玹ä»ããŸãïŒ Catoã¯ã©ãŠãã§ã¯äžçäžã«èªåã®PoPãé
åãã°ããŒãã«ã§ãµãŒãã¹ãå±éããŠããŸãã blog.usize-tech.com 2023.11.13 PoPãåãæ¿ãããšãã¯ã©ããªæïŒ SocketãšPoPéã§ã¯ããã±ãããã¹ãé
å»¶ãªã©ãåžžæç£èŠããŠããŸãã åžžæç£èŠããæ©èœãã Connection SLA ããšåŒã³ãŸãã Connection SLAã®ç£èŠé
ç®ã®æ°å€ãéŸå€ãäžåã£ããPoPãšã®ãã³ãã«ãåæããããšãSocketã¯é信埩æ§ãèªåã§è©Šã¿ãŸãã ãã®éä¿¡åŸ©æ§ææ®µã®äžã€ãšããŠã PoPã®åãæ¿ãã ãã詊ã¿ãŸãã ã€ãŸãã ã PoPã®åãæ¿ãã ããçºçããã®ã¯ãSiteãšPoPãšã®éä¿¡ãåæãããæã ãããã¯éä¿¡ãäžå®å®ãªæãšããããšã§ãã PoPãåãæ¿ãããšã©ããªãã®ïŒ PoPåãæ¿ãã®ã¿ã€ãã³ã°ã§ãç¬æïœæ°ç§çšåºŠã®éä¿¡ãçºçããå¯èœæ§ããããŸãã ã PoPã®åãæ¿ãã ãã¯éä¿¡ãäžå®å®ãªã¿ã€ãã³ã°ã§çºçãããããåãæ¿ããããšã§éä¿¡ç¶æ³ãæ¹åãããå¯èœæ§ããããŸãã PoPã®åãæ¿ããã¿ã€ãã³ã°ãå¶åŸ¡ããã ãPoPã®åãæ¿ãããã¯ãSiteãšPoPãšã®éä¿¡ãåæããããšãããŸãã¯éä¿¡ãäžå®å®ãªã¿ã€ãã³ã°ã§çºçããŸãã éä¿¡ãäžå®å®ãªã¿ã€ãã³ã°ãšã¯ãåè¿°ã® Connection SLA(ç£èŠæ©èœ)ã®éŸå€ãäžåã£ãŠããç¶æ
ãæããŸãã éŸå€ã«ãã£ãŠã¯ãPoPã®åãæ¿ãããé »ç¹ã«èµ·ãã£ãããéã«åãæ¿ããã«æéããããããšããããããéŸå€ããã¥ãŒãã³ã°ãããããšããã客æ§ãããã£ããããšæããŸãã ç£èŠé
ç®ïŒConnection SLAïŒã®éŸå€ã倿Žããããšã§ã PoPåãæ¿ãã¿ã€ãã³ã°ã«ã€ã㊠å¶åŸ¡ããæ¹æ³ãã説æããŸãã éŸå€ã®ãã¥ãŒãã³ã°æ¹æ³ïœConnection SLAïœ ã Connection SLA ãã¯ä»¥äžããèšå®å¯èœã§ãã ã Network ãïŒã Connection SLA ããéžæããã SLA Thresholds ããã¯ãªãã¯ããŸãã ããã©ã«ãã®ç¶æ
ã ãšä»¥äžã®éããã Cato Smart SLA ããéžæãããŠããŸãã ããã©ã«ãïŒCato Smart SLAïŒã®éŸå€ã¯ä»¥äžã®éãã§ãã ãã±ãããã¹ïŒ10% é
å»¶ïŒã¬ã€ãã³ã·ãŒïŒïŒ300 ms è©äŸ¡æéïŒ10åé â»ãã±ãããã¹ãšé
å»¶ã¯oræ¡ä»¶ã§ãã ã€ãŸãã ãã±ãããã¹ã10%ããããã¯é
å»¶ã300ms以äžã®ç¶æ
ã10åéçºçãããšåãæ¿ãããçºçããŸãã ä»»æã®èšå®ãããå Žåã¯ãã Use custom SLA thresholds for Packet Loss and Latency ããéžæããã ãã衚瀺ãããé
ç®ã«ä»»æã®å€ãèšå®ãã ããã æ³šæç¹ åç·åé·æ§æã®å Žå ã·ã³ã°ã«æ§æã®å Žåã¯ãPoPãšã®ãã³ãã«ãããŠã³ãããããã±ãããã¹ã100ïŒ
ã«ãªã£ããããConnection SLAãã®éŸå€ãäžåãã°ããã«PoPãåãæ¿ãããŸãããåç·åé·æ§æã®å Žåããã¹ãŠã®ã¢ã¯ãã£ããªã³ã¯ãäžèšç¶æ
ã«ãªããªããšPoPã®åãæ¿ãããçºçããŸããã â»ãåç·åé·æ§æïŒ1å°ã®Socketã«è€æ°ã®ã€ã³ã¿ãŒãããåç·ãæ¥ç¶ãããŠããæ§æ äŸãã°ãActiveããŒãã®ã€ã³ã¿ãŒãããåç·ã®ã¿ã§é害ãçºçããŠããå ŽåãPoPã¯åãæ¿ãããPassiveããŒããå©çšããŸãã â» ActiveããŒããšPassiveããŒãã¯ããããç¬ç«ããŠPoPãšãã³ãã«ãåžžææ¥ç¶ããŠããŸãããActive/Passiveã§å¿
ãåãPoPãå©çšããŸãã éŸå€ãå³ãããããšéã«äžå®å®ã«ãªããã éŸå€ãå³ãããéãããšãé »ç¹ã«ããŒãã®ã¹ããŒã¿ã¹ãæ¥ç¶PoPãå€ãããéã«éä¿¡ãäžå®å®ã«ãªã£ãŠããŸãå¯èœæ§ããããŸãã äŸãã°ãã¬ããåç·ã®ãããªãã¹ããšãã©ãŒãåç·ããå©çšã®å Žåãæ°ïŒ
ã®ãã±ãããã¹ãçºçããããšã¯çãããããŸããã ãå©çšã®ã€ã³ã¿ãŒãããåç·ã®çš®é¡ã«å¿ããŠãé©åãªéŸå€ãæ€èšãã ããã å
šSiteã察象ãšããèšå®ãšãSiteããšã®èšå®ãå¯èœ äžèšã®èšå®æ¹æ³ã¯ãå
šSiteã察象ãšããèšå®ã«ãªããŸãã ç¹å®ã®Siteã®ã¿èšå®ãããå Žåã¯ã以äžã®æ¹æ³ã§å¯èœã§ãã ã Network ãïŒã Sitesããèšå®ããããµã€ã ããéžæããŸãã ã Site Configuration ã>ã Connection SLA ã>ã SLA thresholds ãã§ã Override Account Settings ãããã§ãã¯ãã ä»»æã®éŸå€ãèšå®ãã ããã ãŸãšã ä»åã®ãã€ã³ãã¯ä»¥äžã«ãªããŸãã ã»ãPoPã®åãæ¿ããããçºçããæã¯ããSiteãšPoPãšã®éä¿¡ãåæãããæããšãéä¿¡ãäžå®å®ãªæã ã»éä¿¡ã®äžå®å®ãã¯ç£èŠé
ç®ïŒConnection SLAïŒã®éŸå€ãäžåããã©ããã§å€æ ã»ç£èŠé
ç®ïŒConnection SLAïŒã®éŸå€ã¯æåã§å€æŽå¯èœ æ¬æ©èœå«ããåŒç€Ÿã® ãCatoã«é¢ããFAQãµã€ãã ã«ã¯Catoã«é¢ãã倿°ã®æ
å ±ããããŸãã®ã§ãåèã«ãã ããã ããããã質å | Cato Cloud ã±ã€ãã¯ã©ãŠã - SCSK Cato SASE Cloud Platform. powered by SCSK cato-scsk.dga.jp æåŸã«ãSCSKã§ã¯PoCããå°å
¥ãéçšãŸã§å¹
åºãCatoã«é¢ããæ¯æŽãè¡ã£ãŠãããŸãã æ¬çªæ§æãžã®ç§»è¡ãèŠæ®ããPoCæ§æããPoCã§ã€ãŸã¥ããããç¹ã®ãµããŒããªã©ãè±å¯ãªå°å
¥å®çžŸãåºã«ãæ¯æŽããããŸãã ãã²ã声ãããã ããïŒ
2024幎2æä»¥éã®Catoã¯ã©ãŠãã®æ°ãããµãŒãã¹äœç³»ãåºæ¬ã»ãªãã·ã§ã³æéããããŒãžããµãŒãã¹ã«ã€ããŠè§£èª¬ãè¡ããŸãããããŸã§ïŒ2024幎1ææ«ãŸã§ïŒã®ãµãŒãã¹äœç³»ãããã³æ°æ§ã®å€æŽå
容ã«ã€ããŠã¯ä»¥äžã®èšäºãåç
§ãã ããã Catoã¯ã©ãŠãã®ãµãŒãã¹äœç³»ã«ã€ã㊠Catoã¯ã©ãŠãã®ãµãŒãã¹æéãå«ããµãŒãã¹äœç³»ããªãã·ã§ã³ããããŒãžããµãŒãã¹ã«ã€ããŠç޹ä»ããŸãã blog.usize-tech.com 2023.08.17 Catoã¯ã©ãŠãã®äŸ¡æ Œæ¹å®ïŒPricing UpdateïŒã«ã€ã㊠2023幎11æã«ã¢ããŠã³ã¹ãããCatoã¯ã©ãŠãã®äŸ¡æ Œæ¹å®ïŒPricing UpdateïŒã«ã€ããŠçŸè¡ãµãŒãã¹äœç³»ãšã®å·®ç°ãäžå¿ã«è§£èª¬ããŸããâ»å®éã®äŸ¡æ Œã«ã€ããŠã¯èšèŒããŠããŸããã blog.usize-tech.com 2023.12.25 ãµãŒãã¹åºæ¬æé Catoã¯ã©ãŠãã®ãµãŒãã¹æéã«ã€ããŠã¯ã以äžã®3ã€ã«å¯ŸããŠåºæ¬æéãçºçããŸãã æ ç¹æ¯ã®PoPæ¥ç¶åž¯åããŸãã¯PoPæ¥ç¶ç·åž¯å ã¢ãã€ã«ãŠãŒã¶ Socket æ ç¹æ¯ã®PoPæ¥ç¶åž¯åããŸãã¯PoPæ¥ç¶ç·åž¯å Catoã¯ã©ãŠãã§ã¯ãæ ç¹ã¯” SiteïŒãµã€ãïŒã©ã€ã»ã³ã¹ “ãšãããã®ã«ãªããŸããæ¥ç¶ããæ ç¹æ¯ã®åž¯åãšããŠãæå° 25Mbpsããã50Mã100Mã250Mã500Mã1,000Mã2,000Mã3,000Mãæå€§ 5,000MbpsãŸã§9ã€ã®ã¡ãã¥ãŒãèšå®ãããŠããŸãã æ¬ç€Ÿã»æ¯åºã»å¶æ¥æãããŒã¿ã»ã³ã¿ãŒãªã©ç©ççãªæ ç¹ã ãã§ãªããAWSãAzureãªã©ã®ã¯ã©ãŠãã«ãSiteã©ã€ã»ã³ã¹ãå¿
èŠãšãªããŸãã å¥çŽåž¯å以äžã®é床ã¯åºãŸããããã以äžã®éä¿¡ã¯QoSèšå®ã«åŸããç Žæ£ïŒDiscardïŒãããŸãã Siteã©ã€ã»ã³ã¹ä»¥å€ã«ãæ¥ç¶ããè€æ°æ ç¹ã®ç·åž¯åã賌å
¥ãã” PooledïŒããŒã«ãïŒã©ã€ã»ã³ã¹ “ãšãããã®ããããŸããPooledã©ã€ã»ã³ã¹ã¯ã1,000Mbps以äžïŒè¿œå åäœ100MbpsïŒã§ã®è³Œå
¥ãšãªããŸããSiteã©ã€ã»ã³ã¹ãšã¯ç°ãªãã10Mbpsåäœã§æ ç¹ãžã®åå²ã§ããæ ç¹åž¯åã®å¢é/æžéãè¡ãããšãå¯èœã§ãã æéã«ã€ããŠã¯ãæäŸå°åã«ããç°ãªããŸããCatoã¯ã©ãŠãã§ã¯ãäžçååœã倧ãã3ã€ã®ã°ã«ãŒãïŒ Group1 ã Group2 ã Stand-alone Countries ïŒã«åå²ããŠããŸããæ¥æ¬ã¯ãGroup2 ã«æå±ããŸãã Stand-alone CountriesïŒåç¬åœïŒã«ã¯3ãµåœïŒäžåœããããã ãã¢ããã³ïŒãå«ãŸããããããã®åœæ¯ã«äŸ¡æ Œèšå®ããããŠãããããå
šéšã§5ã€ã®æéäœç³»ãšãªããŸãã Group1 ïŒåã¢ã¡ãªã«ããšãŒãããïŒ Group2 ïŒæ¥æ¬ãå«ãã¢ãžã¢ããªãŒã¹ãã©ãªã¢ãã¢ããªã«ãã¡ãã·ã³ïŒ Stand-alone CountriesïŒäžåœïŒ Stand-alone CountriesïŒãããã ïŒ Stand-alone CountriesïŒã¢ããã³ïŒ Group1ãGroup2ãStand-alone Countriesã¯ä»¥äžïŒäžçå°å³ïŒã®éãã§ãã Stand-alone Countriesã«ã€ããŠã¯ãå
ã»ã©ã®25Mã50Mãã5,000Mã®9ã€ã®ã¡ãã¥ãŒã§ã¯ãªããåœå
ïŒRegionalïŒ/åœå€ïŒGlobalïŒåãã®éä¿¡ããããã1Mbpsåäœã§å¥çŽãè¡ããŸãïŒæå°2Mbps以äžïŒ äŸ¡æ ŒïŒæéïŒãšããŠã¯ãïŒå®ãïŒGroup1 ïŒ Group2 ïŒ Stand-alone Countries ïŒé«ãïŒãšãªããŸãã Pooledã©ã€ã»ã³ã¹ã¯ãåãã°ã«ãŒãå
ã§ã®åé
ãå¯èœãšãªã£ãŠãããŸãã Stand-alone CountriesïŒäžåœããããã ãã¢ããã³ïŒã«ã¯ãPooledã©ã€ã»ã³ã¹ã¯ããããŸããã éåžžã¯ãSASEã©ã€ã»ã³ã¹ãšããåŸè¿°ã®Socketã®å©çšãåæãšããã©ã€ã»ã³ã¹ã«ãªããŸãããSocketãå©çšããªãïŒIPsecæ¥ç¶ïŒå Žåã«ã¯ãããå®äŸ¡ãªSSEã©ã€ã»ã³ã¹ãšãããã®ãé©çšããããšãå¯èœã§ãã ã¢ãã€ã«ãŠãŒã¶ ã¢ãã€ã«ãŠãŒã¶ïŒïŒSDPâ»ãŠãŒã¶ïŒã¯ãã¢ã«ãŠã³ãæ°ã«ãã課éãšãªããŸãã â»SDPSoftware Defined PerimeterïŒãœãããŠã§ã¢å®çŸ©å¢çïŒã¯ãZTNAã®å¥åã§ãåŸæ¥åã®ãªã¢ãŒãã¢ã¯ã»ã¹ãšã¯ç°ãªãããŒããã©ã¹ãã®ååã«åã£ãã»ãã¥ã¢ãªãªã¢ãŒãã¢ã¯ã»ã¹ã§ããCatoã¯ã©ãŠãã®ãªã¢ãŒãïŒã¢ãã€ã«ïŒã¢ã¯ã»ã¹ãæå³ããŸãã Group1ãGropup2ã«ã€ããŠã¯ãå
±éã®” Generalã©ã€ã»ã³ã¹ “ãšãªããŸãã Stand-alone CountriesïŒäžåœããããã ãã¢ããã³ïŒã¯ããããå¥ã®ã¡ãã¥ãŒäœç³»ãšãªããŸãã 賌å
¥ããã¢ã«ãŠã³ãæ°ä»¥äžã¯ç»é²ãè¡ããŸããïŒãšã©ãŒã«ãªããŸãïŒ ãŸããäºåã§Generalã©ã€ã»ã³ã¹ã5ã€ä»äžãããŠããŸãã SDPãŠãŒã¶ã¯ã10ãŠãŒã¶ã©ã€ã»ã³ã¹ãã賌å
¥ãå¯èœãšãªããŸãã Generalã©ã€ã»ã³ã¹ã«ã€ããŠã¯ã10ïœ500ã501ïœ1,000ã1,001ïœ5,000ã5,001ïœ10,000ã10,001ããšå¥çŽãŠãŒã¶æ°æ¯ã«ããªã¥ãŒã ãã£ã¹ã«ãŠã³ãæéãé©å¿ãããŸãã ã¢ãã€ã«ãŠãŒã¶ã¯ã端æ«ã«Catoã¯ã©ã€ã¢ã³ããã€ã³ã¹ããŒã«ããŸããã1ãŠãŒã¶ïŒã¢ã«ãŠã³ãïŒã§ã3å°ïŒããã€ã¹ïŒãŸã§å©çšããããšãå¯èœã§ãã Socket SocketïŒãœã±ããïŒã¯ãç©çããŒããŠã§ã¢ Socketãäžåå©çšãããä»®æ³ã¢ãã©ã€ã¢ã³ã¹ïŒvSocketïŒããæ¢åã«ãŒã¿ãFirewallçãçšããIPsecæ¥ç¶ã®ã¿ãå©çšãããå Žåã¯äžèŠã§ãã Socketã¯ã倧ãã X1500 ã X1600 ã X1700 ã®3æ©çš®ããããX1500ãæå€§ã¹ã«ãŒãããã500MbpsãŸã§ãX1600ã1,000MbpsãŸã§ãX1700ã5,000MbpsãŸã§ãšãªã£ãŠãããŸãã X1600ã«ã€ããŠã¯ãããŒã·ãã¯ã¢ãã«ãããªãªãŒã¹ãããŠãããä»åŸãSIMãæèŒå¯èœãªãLTEã¢ãã«ãããWi-Fiã¢ãã«ããã5Gã¢ãã«ãããWi-Fi+LTEã¢ãã«ããªã©ããªãªãŒã¹ãããäºå®ã§ãã Socketã¯ãåé·ïŒHAïŒæ§æãè¡ãããšãå¯èœã§ããã³ãŒã«ãã¹ã¿ã³ãã€ã®äºåæ©ãšããŠæé
ããããšãå¯èœã§ãã Socketã¯ãäžæ¬è³Œå
¥ããã®ã§ã¯ãªãããµãã¹ã¯ãªãã·ã§ã³ïŒãµãŒãã¹èª²éïŒãšãªããŸãã®ã§ãæé
ããSocketãã¹ãŠã«è²»çšãçºçããŸãã ã©ãã¯ããŠã³ããããããŠã©ãŒã«ããŠã³ãããããæããåãããµãã¹ã¯ãªãã·ã§ã³ã§æäŸãããŠããŸãã ãµãã¹ã¯ãªãã·ã§ã³ã®ãããCatoã¯ã©ãŠãã®ãµãŒãã¹çµäºæã«ã¯ããã¹ãŠè¿åŽããã ãå¿
èŠããããŸãã ãªãã·ã§ã³æéïŒã»ãã¥ãªãã£ãªãã·ã§ã³ïŒ çŸåšãä»¥äž 5ã€ã®ã»ãã¥ãªãã£ãªãã·ã§ã³ããããŸãïŒ2024幎2ææç¹ïŒ No. ã»ãã¥ãªãã£ãªãã·ã§ã³ ãªãã·ã§ã³ãµãŒãã¹å
容 1 Threat Prevention ã¢ã³ããã«ãŠã§ã¢ïŒAMïŒã次äžä»£åã¢ã³ããã«ãŠã§ã¢ïŒNGAMïŒãIPSïŒIntrusion Prevention SystemïŒãDNS SecurityãThreat Intelligenceãã€ã³ã©ã€ã³AI/MLãã¢ã³ããã£ãã·ã³ã° 2 CASB Cloud Access Security Broker SaaSã»ã¢ããªã±ãŒã·ã§ã³å©çšã®å¯èŠå/è©äŸ¡/å¶åŸ¡ 3 DLP Data Loss Prevention æ©å¯æ
å ±ãéèŠããŒã¿ã®æŒæŽ©å¯Ÿç 4 RBI Remote Browser Isolation Webãã©ãŠã¶åé¢ 5 SaaS Security API å€éšã¯ã©ãŠããµãŒãã¹ã®APIã«ããã»ãã¥ãªãã£æ€æ»ïŒã¢ã³ããã«ãŠã§ã¢ãDLPïŒ ã»ãã¥ãªãã£ãªãã·ã§ã³ã¯ããµãŒãã¹åºæ¬æéïŒSite/Pooledã©ã€ã»ã³ã¹ãSDPãŠãŒã¶ïŒãžã®è¿œå æéãšãªããŸãã Site/Pooledã©ã€ã»ã³ã¹ãšSDPãŠãŒã¶ã¯ãå¿
ãåãã»ãã¥ãªãã£ãªãã·ã§ã³ãéžæããå¿
èŠããããŸã ã ïŒç¹å®æ ç¹ã®ã¿ã»ãã¥ãªãã£ãªãã·ã§ã³ãªããSDPãŠãŒã¶ã®ã¿ã»ãã¥ãªãã£ãªãã·ã§ã³ãªãã¯ã§ããŸããïŒ Threat Prevention  ãã¿ãŒã³ãã¡ã€ã«ãããã³ã°ã®ã¢ã³ããã«ãŠã§ã¢ïŒAnti-MalwareïŒãšãæ©æ¢°åŠç¿ãšã³ãžã³ãçšããæ¯ãèãæ€ç¥ãå«ã次äžä»£åã¢ã³ããã«ãŠã§ã¢ïŒNext Generation Anti-MalwareïŒãCatoã¯ã©ãŠãã§æãã»ãã¥ãªãã£å¹æãé«ã IPSãäžæ£ãªãã¡ã€ã³ãžã®ã¢ã¯ã»ã¹ããããã¯ããâDNS Protectionâããäžå¯©ãªã¢ã¯ã»ã¹ãã¢ãã¿ãªã³ã°ããâSuspicious Activity MonitoringïŒSAMïŒâã”Threat Intelligence”ã”ã€ã³ã©ã€ã³ AI/ML”ã”ã¢ã³ããã£ãã·ã³ã°”ãªã©ããã¹ãŠå«ãŸããŠããŸãã CASB  SaaSã¢ããªã±ãŒã·ã§ã³ãã¯ã©ãŠããµãŒãã¹ã®å©çšç¶æ³ãå¯èŠåïŒïŒã·ã£ããŒITã®å¯èŠåïŒãè¡ããŸããCato瀟ã§åã¢ããªã±ãŒã·ã§ã³ãç¬èªã®ã»ãã¥ãªãã£ã»ã³ã³ãã©ã€ã¢ã³ã¹çã®èŠç¹ã§è©äŸ¡ãã Application Credibility EvaluatorïŒACEïŒãå©çšããŠããããããå
ã«ç®¡çè
ããã¢ããªã±ãŒã·ã§ã³æ¯ã«å©çšèš±å¯ïŒSanctionïŒãè¡ãããšãå¯èœã«ãªããŸããããã«ã¢ããªã±ãŒã·ã§ã³ã®ã¢ã¯ãã£ããã£åäœã§ã®å¶åŸ¡ãè¡ãããšãå¯èœã«ãªããŸããäŸãã°ãDropboxãGmailã§ããŠã³ããŒãã¯èš±å¯ããããã¢ããããŒãã¯èš±å¯ããªããªã©ã§ãããŸããOffice365ã®äŒæ¥ããã³ãã®ã¿ã®å©çšãèš±å¯ãããªã©ããCASBã®ãªãã·ã§ã³ã§å®çŸãå¯èœãšãªããŸãã DLP  ãã©ãã£ãã¯äžã®ãã¹ãŠã®ãã¡ã€ã«ãã¹ãã£ã³ããŠãæ©å¯æ
å ±ã®æ€åºãè¡ããé©åãªæªçœ®ãè¬ããããšãã§ããŸããæ©å¯æ
å ±ã®ç¹å®ã«ã¯ãäºåã«Cato瀟ã§å®çŸ©ãããã«ãŒã«ïŒããŒã¿ã¿ã€ãïŒãå©çšããããšãå¯èœã§ããã¯ã¬ãžããã«ãŒãããã€ãã³ããŒã«ãŒããªã©ã¯äºåã«ã«ãŒã«ãå®çŸ©ãããŠããŸãããåå¥ã«å®çŸ©ããããšãå¯èœã§ãMIPïŒMicrosoft Information ProtectionïŒã©ãã«ãšã®é£æºãå¯èœã«ãªã£ãŠããŸãã RBI  ãŠãŒã¶ãŒã®ãšã³ããã€ã³ãããã€ã¹ã®ä»£ããã«ãCatoã¯ã©ãŠããããŠãŒã¶ãŒã®Webé²èЧã»ãã·ã§ã³ãå®è¡ãããã®ç»é¢æ
å ±ããŠãŒã¶ãžéä¿¡ããããšã«ãã£ãŠããªã³ã©ã€ã³ã®è
åšïŒäžæ£ããã°ã©ã ã®ããŠã³ããŒããå®è¡ïŒãç¡ååãããã®ã§ãã SaaS Security API  Catoã¯ã©ãŠã以å€ãããSaaSã¢ããªã±ãŒã·ã§ã³ãã¯ã©ãŠããµãŒãã¹ãå©çšããå Žåãã€ãŸãå€éšãšã®ã³ã©ãã¬ãŒã·ã§ã³ãè¡ãéã®è
åšãæ€åºããããã«ãSaaSã¢ããªã±ãŒã·ã§ã³ãžAPIãå©çšããŠã»ãã¥ãªãã£æ€æ»ïŒãã«ãŠã§ã¢æ€æ»ãDLPïŒãè¡ãæ©èœãšãªããŸããSaaS Security APIã¯ã1ã€ã®SaaSã ãæ€æ»å¯èœãªã SaaS Security API 1 App connector ãã2ã€ã®SaaSãæ€æ»ããã SaaS Security API 2 Apps connectors ãã3ã€ä»¥äžã®SaaSãæ€æ»ããã SaaS Security API All Apps connectors ãã®3ã©ã€ã»ã³ã¹ã«ãªã£ãŠãããŸãã ã»ãã¥ãªãã£ãªãã·ã§ã³ã«ã¯å¹Ÿã€ãã®åææ¡ä»¶ããããŸãã ã»DLPã¯ãCASBå¥çŽãåæãšãªããŸãã ã»SaaS Security APIã¯ãDLPå¥çŽãåæãšãªããŸãã ã»SaaS Security APIã§ãã«ãŠã§ã¢æ€æ»ãããå Žåã¯ãThreat Preventionã®å¥çŽãåæãšãªããŸãã ã»SaaS Security APIã®ã·ã³ã°ã«ã³ãã¯ã¿ãŒã¯åããã³ããŒã®ã¢ããªã±ãŒã·ã§ã³ã¯ãã¹ãŠã§æ©èœããŸããäŸãã°ãMicrosoft app connectorã¯ãMicrosoft 365ã¢ããªã±ãŒã·ã§ã³ïŒOne DriveãSharepointçïŒãã¹ãŠã§å©çšã§ããŸãã CASBãDLPã¯ã2022幎ã«ãªãªãŒã¹ãããŠãããRBIãSaaS Security APIã¯ã2023幎ã«ãªãªãŒã¹ãããŠããŸãã ä»åŸãæ°ããªã»ãã¥ãªãã£ãªãã·ã§ã³ãé æ¬¡ãªãªãŒã¹ãããŸãããå¥çŽã ãã§ããã«å©çšã§ããã®ããSASEãCatoã¯ã©ãŠãã®æå€§ã®ã¡ãªããã§ãã ãªãã·ã§ã³æéïŒæ°ããã»ãã¥ãªãã£ãµãŒãã¹ãšãããŒãžããµãŒãã¹ïŒ No. ã»ãã¥ãªãã£ãµãŒãã¹ ã»ãã¥ãªãã£ãµãŒãã¹å
容 1 XDR Security Pro Extended Detection and Response æ¡åŒµæ€åºãšå¯Ÿå¿ 2 Endpoint SecurityïŒEPPïŒ Endpoint Protection Platform ãšã³ããã€ã³ããããã¯ã·ã§ã³ãã©ãããã©ãŒã 3 MDR Managed Detection & Response å°ä»»ã®ã»ãã¥ãªãã£ã¢ããªã¹ãã«ããSOCãµãŒãã¹ 4 ILMM Intelligent Last Mile Management ã©ã¹ããã€ã«ã€ã³ã¿ãŒãããåç·ç®¡çãµãŒãã¹ ãŸããCatoã®XDR Securityã¯ãäžçåã®SASEããŒã¹ã®XDRïŒExtended Detection and ResponseïŒã§ãã XDR Securityã«ã¯ãCoreãšProã®2çš®é¡ãããã XDR Security Core ã«ã€ããŠã¯ãCatoã¯ã©ãŠãããå©çšã®ãã¹ãŠã®ã客æ§ãç¡æã§ãå©çšå¯èœã§ãããã ããXDR Security Coreã¯ãã»ãã¥ãªãã£ãªãã·ã§ã³ IPSã®ãã°ãå
ã«ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®åæãããŠããŸãã®ã§ãThreat Preventionã®å¥çŽãåæãšãªããŸãã XDR Security Pro  ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«å¯Ÿãã察å¿ïŒSOCéç¥ã®å¯Ÿå¿ïŒãå¯èœãªã客æ§åãã«æäŸãããæ©èœã§ãAIããŒã¹ã®è
åšãã³ãã£ã³ã°ïŒThreat HuntingïŒããŠãŒã¶ãŒè¡ååæïŒUser Behavioral AnalysisïŒãã€ã³ã·ãã³ãã©ã€ããµã€ã¯ã«ç®¡çã远å ããã»ãã¥ãªãã£ãªãã·ã§ã³ãšãªããŸãã Catoã®ãããŒãžããµãŒãã¹ã§ããMDRã¯ãXDR Security Proã®å¥çŽãåæã«ãªããŸãã Endpoint SecurityïŒEPPïŒ ïœ¥ïœ¥ïœ¥ äžçåã®SASEããŒã¹ã®ãšã³ããã€ã³ãã»ãã¥ãªãã£(EPP)ãšãªããŸãããããŸã§ã®SASEã®ã«ãã¬ããžç¯å²ãããããã¯ãŒã¯å±€ãè¶
ããŠãšã³ããã€ã³ãã«ãŸã§æ¡åŒµãã補åãšãªããCMAã«å®å
šã«çµ±å管çãããã¯ã©ãŠããã€ãã£ããªä»ã®ã»ãã¥ãªãã£ã¹ã¿ãã¯ãšé£æºããŠåäœããŸãã EPPã¯ã端æ«ã«EPPãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ããŸããSDPãŠãŒã¶ã®å©çšããã€ã¹æ°äžéãšåæ§ã«3ããã€ã¹ãäžéãšãªããŸãã MDR  Cato瀟ã®å°ä»»ã®ã»ãã¥ãªãã£å°éå®¶ã«ããã¢ã»ã¹ã¡ã³ãããããŒããããã€ã¡ã³ããå
šãŠã®ãã©ãã£ãã¯åžžæç£èŠããç¶ç¶çãªè
åšãã³ãã£ã³ã°ããµãŒãã¹æäŸããŸãã宿çãªã¬ããŒããšãµãŒãã¹ã¬ãã¥ãŒïŒãªã³ã©ã€ã³äŒè°ïŒãè¡ãããŸãã æ®å¿µãªããã 2024幎2ææç¹ã§ã¯ãMDRã¯è±èªå¯Ÿå¿ã®ã¿ïŒã¬ããŒãããã³ãªã³ã©ã€ã³ã®ã¬ãã¥ãŒäŒè°çïŒãšãªã£ãŠããã æ¥æ¬èªã¯æªå¯Ÿå¿ ãšãªã£ãŠãããŸãã ãã®ããåŸè¿°ããŸãããSCSKã§ã¯åå¥ã«æ¥æ¬èªå¯Ÿå¿ããSOCãµãŒãã¹ãæäŸããŠãããŸãã XDR Security ProãEndpoint SecurityïŒEPPïŒãMDRã«ã€ããŠã¯ã Knowledge UsersïŒãã¬ããžãŠãŒã¶ïŒèª²é ãšãªããŸãã Knowledge Usersãšã¯ãäŒæ¥å
ã®M365ãG-Suiteå¥çŽãŠãŒã¶æ°ã®ããšã§ãåãŠãŒã¶æ°ã§ã®å¥çŽãåæãšãªããŸãã ILMM  Cato瀟ã®NOCïŒNetwork Operations CenterïŒããã©ã¹ããã€ã«ã®ã€ã³ã¿ãŒãããåç·ã®ãã©ãŠã³ã¢ãŠãïŒåç·ã®å質ãã¬ã¹ãã³ã¹ãèŠå®ã«æºããªãç¶æ³ïŒããé¡èãªããã©ãŒãã³ã¹äœäžããã©ãã¯ã¢ãŠãïŒåç·æïŒããªã¢ã«ã¿ã€ã ã«ç£èŠïŒæ€ç¥ïŒããŸããNOCãåé¡ãæ€ç¥ããåç·ãç¹å®ãããšãNOCã¯ãçŽæ¥ISPãžïŒæ¥æ¬åœå
ã®å Žåã¯æ¥æ¬èªã§ïŒé£çµ¡ãè¡ãåé¡ã®è§£æ±ºãå³ããŸããISPãšååãããããã¯ãŒã¯ã®åé¡åå ãç¹å®ããåé¡è§£æ±ºãå³ããã客æ§ãžå¯Ÿå¿å
容ãé©å®ãå ±åããŸãã ISPã«ã¯ãäºåã«ã客æ§ã®å§ä»»ç¶ãããã ãããšã§ãISPãžã®çŽæ¥åãåããã代çã§å®æœããŸãã ILMMã¯ãã»ãã¥ãªãã£ãªãã·ã§ã³ãšåãããµãŒãã¹åºæ¬æéïŒSite/Pooledã©ã€ã»ã³ã¹ãSDPãŠãŒã¶ïŒãžã®è¿œå æéãšãªããŸãã 課éïŒè«æ±ïŒããã³å¥çŽã«ã€ã㊠SCSKã§ã¯ã æé¡èª²éïŒæé¡è«æ±ïŒ ãšãªããŸãïŒäžæ¬è«æ±ããããšãå¯èœã§ãïŒ ãµãŒãã¹åºæ¬æéãšãªãã·ã§ã³æéïŒã»ãã¥ãªãã£ãªãã·ã§ã³ãã»ãã¥ãªãã£ãµãŒãã¹ããããŒãžããµãŒãã¹ïŒã®åèšãæ¯æãè«æ±ããããŸãã Siteã©ã€ã»ã³ã¹ã®å¢éïŒäŸ 25Mbpsâ50MbpsïŒããã¢ãã€ã«ãŠãŒã¶ã®è¿œå ïŒäŸ +10ãŠãŒã¶ïŒãã远å ããæããã®è¿œå 課éïŒè«æ±å¢ïŒãšãªããŸãã Socketã«ã€ããŠããµãã¹ã¯ãªãã·ã§ã³ã§ãã®ã§ã¢ããã°ã¬ãŒããå¯èœã§ããX1500ããX1600ãX1700ãžã®ã¢ããã°ã¬ãŒãã宿œããå Žåã¯ãã¢ããã°ã¬ãŒã宿œæããã®è¿œå 課éïŒè«æ±å¢ïŒãšãªããŸãã ãã®ä»ã«ã¯ããå®¢æ§æ¯ã«åå¥å²ãåœãŠãè¡ãã°ããŒãã«IPã¢ãã¬ã¹ã3ã€ãŸã§ã¯åºæ¬å¥çŽã«å«ãŸããŸããã4ã€ç®ä»¥äžã¯ãªãã·ã§ã³ïŒè¿œå 課éïŒãšãªããŸãã æ¬¡ã«ãCatoã¯ã©ãŠãã®ãå¥çŽæéã¯ã æäœ1幎é ãšãªããŸããè€æ°å¹Žå¥çŽãè¡ãããã客æ§ãå€ãã§ãã Catoã¯ã©ãŠãã®å¢éãã¢ãã€ã«ãŠãŒã¶ã®è¿œå ããããã¯Socketã®ã¢ããã°ã¬ãŒãã¯ãå¥çŽæéäžãã€ã§ã宿œããããšãå¯èœã§ããã æ ç¹ã®è§£çŽãåž¯åæžéãã¢ãã€ã«ãŠãŒã¶åæžãSocketããŠã³ã°ã¬ãŒãã«ã€ããŠã¯ãå¥ç޿޿°æïŒæŽæ°æïŒã«ãã宿œããããšãã§ããŸãã ã®ã§ã泚æãã ããã ãŸããå¥çŽæéäžã®å¢éã»è¿œå ã»ã¢ããã°ã¬ãŒãã¯ãå¥çŽçµäºæãŸã§ã®å¥çŽã«ãªããŸãã äŸãã°ã2024幎2æå¥çŽéå§ã2025幎1æå¥çŽçµäºã®1幎å¥çŽã®å Žåã2024幎4æã«æ ç¹ãå¢éããå Žåã¯ãå¢éåã®å¥çŽã¯2024幎4æãã2025幎1æã®10ãµæå¥çŽãšãªããŸãã Catoã¯ã©ãŠãã®æå°æ§æã¯ã1 Siteã©ã€ã»ã³ã¹ã10 SDPãŠãŒã¶ ãšãªããŸãã äžèšã®æå°æ§æã¯ãã¢ãã€ã«ãŠãŒã¶ 10åãæ ç¹ã¯ã¯ã©ãŠãïŒAWSïŒãšããŠã®Siteã©ã€ã»ã³ã¹ 25MbpsãšããŠããŸãã ã¢ãã€ã«ãŠãŒã¶ïŒæ¥æ¬ïŒã«ã€ããŠã¯ã垯åã®å¶éïŒäžéïŒã¯ãããŸããããäžéšã®å°åïŒäžåœããããã çïŒã«ã€ããŠã¯äžéããããŸãã AWSã®vSocketã«ã¯æéã¯çºçããŸããããã ããAWSã®å©çšéïŒä»®æ³ãã·ã³å©çšãéä¿¡éçïŒã¯å¥éå¿
èŠãšãªããŸãã æå°æ§æã®è²»çšæãšããŠã¯ãå®äŸ¡ããŒã¹ã§å¹Žé65äžä»¥äžïŒæé¡6äžå以äžïŒãšãªããŸãã®ã§ãä»ã®SASEãœãªã¥ãŒã·ã§ã³ãšæ¯èŒãããšãéåžžã«å®äŸ¡ã§ã¹ã¢ãŒã«ã¹ã¿ãŒããå¯èœãªãœãªã¥ãŒã·ã§ã³ã§ãã ã¡ãªã¿ã«ãPooledã©ã€ã»ã³ã¹ã¯1,000Mbps以äžã®è³Œå
¥ãšãªããŸãããSiteã©ã€ã»ã³ã¹ã®100MbpsãããŒã¹ã«äŸ¡æ Œèšå®ãããŠããããã100Mbps以äžã®æ ç¹ã®åèšåž¯åã1,000Mbps以äžã«ãªãå Žåã¯ãPooledã©ã€ã»ã³ã¹ã®è³Œå
¥æ€èšãè¡ãããæ¹ãè³¢æã§ããç¹ã«ã25Mbps以äžã®ç垯åïŒ10M,20MïŒæ ç¹ãå€ãååšããå Žåã¯éåžžã«ã³ã¹ãã¡ãªãããã§ãŸãã SCSKã®ãããŒãžããµãŒãã¹ã«ã€ã㊠SCSKã§ã¯ã2019幎ããCatoã¯ã©ãŠãã®åãæ±ããéå§ããã客æ§ããã®ããŒãºã«å¿ããŠæ§ã
ãªãããŒãžããµãŒãã¹ããæäŸããŠãããŸãã Catoã¯ã©ãŠãããæ€èšäžã®ã客æ§ãžã®PoCã®æ¯æŽãããæ¢åç°å¢ã®çŸç¶èª¿æ»ãèŠä»¶å®çŸ©ãèšèšã»æ§ç¯ã»å°å
¥æ¯æŽãæ¢åWANãã»ãã¥ãªãã£æ©åšããã®ç§»è¡èšèš/ç§»è¡æ¯æŽãæ ç¹ã®ã€ã³ã¿ãŒãããåç·ã®èª¿éãããæ ç¹ã®Socketèšçœ®äœæ¥ãªã©ããèŠæã«å¿ããŠããããããµãŒãã¹ãæäŸããããšãå¯èœã§ãïŒãã¡ãããæ¥æ¬åœå
ã ãã§ãªãæµ·å€ãå«ã¿ãŸãïŒ ãŸããSASEãCatoã¯ã©ãŠãã¯ãæ¢åWANãã»ãã¥ãªãã£æ©åšã®çœ®ãæãã«ãªããããåæã®æ§ç¯ã ãã§ãªããéçšä¿å®ãéåžžã«éèŠãšãªããŸãã ããã§ãSCSKãæäŸããŠãããããŒãžããµãŒãã¹ïŒäžéšïŒãã玹ä»ããŸãã No. SCSKãããŒãžããµãŒãã¹ ãµãŒãã¹æŠèŠ 1 ãµãŒãã¹çªå£ïŒSPOCïŒ 24æé365æ¥ã®é»è©±ã»ã¡ãŒã«ã§ã®ãµãŒãã¹åä»çªå£ããæäŸããŸãã æµ·å€æ ç¹åãã®è±èªã§ã®24æé365æ¥ã®åä»çªå£ããæºåããŠããŸãã 2 ç£èŠã»éå®³äžæ¬¡åãåã æ ç¹ã®é害ç£èŠãè¡ããé害æ€ç¥ïŒãŸãã¯ã客æ§ããã®éå ±ïŒæã«ãéå®³ç®æïŒCatoã¯ã©ãŠã/Socket/ãããã¯ãŒã¯åç·çïŒã®äžæ¬¡åãåããè¡ããŸãã 3 倿Žäœæ¥ä»£è¡ ã客æ§ã«ä»£ãã£ãŠCatoã¯ã©ãŠãã®åçš®èšå®å€æŽäœæ¥ã宿œããŸãã 4 ææ¬¡å ±åäŒ Catoã¯ã©ãŠãããååŸããåçš®ããŒã¿ãåæããŠææ¬¡å ±åæžãäœæããŸãã ãããã¯ãŒã¯ãã©ãã£ãã¯ã®åŸååæãåçš®ã»ãã¥ãªãã£ãã°ã®åæçµæãåºã«ã¬ããŒããäœæããå ±åäŒãéå¬ããŸãã 5 Socketãªã³ãµã€ãä¿å® Socketã®ãªã³ãµã€ã24æé365æ¥ïŒé§ä»ç®æšïŒ4æéïŒä¿å®ãµãŒãã¹ã åœç€Ÿã§Socket代æ¿ãäºåæé
ããç¹å¥ä¿å®ãµãŒãã¹ãæµ·å€æ ç¹åãã®ãªã³ãµã€ãä¿å®ãµãŒãã¹ããæºåããŠããŸãã 6 SOCç£èŠãµãŒãã¹ Catoã¯ã©ãŠãã®ã»ãã¥ãªãã£ãã°ãã»ãã¥ãªãã£ã¢ããªã¹ãããªã¢ã«ã¿ã€ã ã§ç£èŠã»åæãè¡ããå¿
èŠã«å¿ããŠãã客æ§ãžé»è©±ã»ã¡ãŒã«ã§éç¥ãè¡ããŸãã 7 ã»ãã¥ãªã㣠ã¢ããã€ã¶ãªãµãŒãã¹ ã客æ§ããã®äŸé Œã«åºã¥ããã»ãã¥ãªãã£ã¢ããªã¹ããé ããæ
å ±ã調æ»ã»åæãç¥èŠããæäŸããŸãã 8 ãã°ä¿ç®¡ãµãŒãã¹ Catoã¯ã©ãŠãã§ã¯ãã°ä¿ç®¡æéãå®ããããŠããããã3幎éã®é·æä¿ç®¡ãè¡ããŸããã客æ§ã®ãäŸé Œã«å¿ããŠãã°ãæœåºããŠãæäŸããŸãã 9 èšå®èšºæãµãŒãã¹ â»ãã§ã«Catoã¯ã©ãŠãããå©çšã®ã客æ§ã察象 ã»ãã¥ãªãã£ã»ã¢ãŒããã¯ãã»ã³ã¹ãïŒçµæžæ§ïŒã®3ã€ã®èгç¹ããCatoã¯ã©ãŠããæšå¥šèšå®ã«åºã¥ããçŸç¶ã®èšå®å
容ã確èªããå ±åæžãäœæããŸãã ãµãŒãã¹çªå£  24æé365æ¥ã®é»è©±ãããã³ã¡ãŒã«ã®çªå£ãšãªããŸããé害ã®ãåãåãããå§ããCatoã¯ã©ãŠãã®æè¡çãªãåãåããã«ã€ããŠãããµãŒãã¹çªå£ã§åä»ãè¡ããŸãããªããæè¡åãåããã®åçã«ã€ããŠã¯ãå¹³æ¥9:00-17:00察å¿ãšãªããŸãã ãŸãããµãŒãã¹çªå£ã®ãå¥çŽã§ãåœç€Ÿãéå¶ããFAQãµã€ãã®å¥çŽè
IDããç¥ããããŸããFAQãµã€ãã«ã¯ãäžè¬å
¬éæ
å ±ãšã¯å¥ã®è¿œå æ
å ±ããKnowledge Baseãžã®ãªã³ã¯ãåœç€Ÿäœæã®æé æžã»ããã¥ã¢ã«ãªã©ããæäŸããŠãããŸãã ããããã質å | Cato Cloud ã±ã€ãã¯ã©ãŠã - SCSK Cato SASE Cloud Platform. powered by SCSK cato-scsk.dga.jp ææ¬¡å ±åäŒ ïœ¥ïœ¥ïœ¥ Catoã¯ã©ãŠãããååŸã§ãããã©ãã£ãã¯ããŒã¿ãåçš®ãã°ïŒEventsïŒãAPIã§ååŸããéèšã»åæããçµæããææ¬¡å ±åæžãäœæããŸãããããã¯ãŒã¯ãã©ãã£ãã¯ã®åæïŒåœæåºŠãããã³éå»å幎éã®åŸååæïŒãåã»ãã¥ãªãã£ãã°ã®éèšã»åæãããã«ãæ¯é±ãªãªãŒã¹ãããCatoã¯ã©ãŠãã®ææ°æ
å ±ããšããŸãšããŠææ¬¡å ±åæžãšããŠäœæããå ±åäŒïŒãªã³ã©ã€ã³ïŒãéå¬ããŸãã Cato ã¯ã©ãŠãåãææ¬¡ã¬ããŒããµãŒãã¹ã®ç޹ä»ãšæè¡çãªä»çµã¿ã®è§£èª¬ SCSKã§ã¯ Cato ã¯ã©ãŠãã®å°å
¥ããéçšãŸã§äžè²«ããæè¡ãµããŒãããµãŒãã¹ãæäŸããŠãããŸããæ¬èšäºã¯ãµãŒãã¹ã¡ãã¥ãŒã®1ã€ã§ããææ¬¡ã¬ããŒããµãŒãã¹ã®ã玹ä»ãšããã®è£åŽã®æè¡çãªä»çµã¿ã«ã€ããŠè§£èª¬ããããŸãã blog.usize-tech.com 2024.01.22 Socketãªã³ãµã€ãä¿å®  Socketã®ããŒããŠã§ã¢é害æã®æ¥æ¬å
šåœ4æéé§ãä»ãç®æšã®ãªã³ãµã€ãä¿å®ãµãŒãã¹ãšãªããŸãã亀æãè¡ãSocketã®ä»£æ¿æ©ããSCSKã«ãŠäºåã«æºåããŠãããŸãã®ã§ãã客æ§ã§äºåæ©ãæé
ããŠããå¿
èŠããããŸãããïŒäºåæ©è²»çšãåæžã§ããŸãïŒ SOCç£èŠãµãŒãã¹ ã ã»ãã¥ãªãã£ã¢ããã€ã¶ãªãµãŒãã¹ ã¯ã以äžãã芧ãã ããã SASEãCatoã¯ã©ãŠããã®ã»ãã¥ãªãã£ã»ãããŒãžããµãŒãã¹æ©èœã匷å SCSKæ ªåŒäŒç€ŸïŒæ¬ç€ŸïŒæ±äº¬éœæ±æ±åºã代衚åç· åœ¹ å·è¡åœ¹å¡ ç€Ÿé· æé«å·è¡è²¬ä»»è
ïŒè°·å 培ãä»¥äž SCSKïŒã¯ãSASEã®æŠå¿µãå®è£
ãããããã¯ãŒã¯ã»ãã¥ãªãã£ã¯ã©ãŠããµãŒãã¹ãCatoã¯ã©ãŠããã®ã»ãã¥ãªãã£ã«ãããæ€ç¥ã»å¯Ÿå¿ã»åŸ©æ§ã匷åããåãããŒãžããµãŒãã¹ã2022幎1æ28æ¥ããæäŸéå§ããŸãã www.scsk.jp ãã°ä¿ç®¡ãµãŒã㹠 2023幎11æããCatoã¯ã©ãŠãã®ãã°ãå«ãããŒã¿ä¿ç®¡æéïŒæšæºïŒã6ãµæãã3ãµæã«ççž®ãããŸãããäžæ¹ã§3ãµæã6ãµæã12ãµæã«å»¶é·ãè¡ããªãã·ã§ã³ïŒ Data Lake Storage ïŒããªãªãŒã¹ãããŠããŸãããSCSKã«ãŠãã°ã 3幎é ä¿ç®¡ãããµãŒãã¹ãšãªããŸãã èšå®èšºæãµãŒã㹠 Catoã¯ã©ãŠãã®çŸç¶èšå®å
容ã«ã€ããŠç¢ºèªãããŠæ¬²ãããšãããèŠæãå€ããã»ãã¥ãªãã£ã»ã¢ãŒããã¯ãã»ã³ã¹ãïŒçµæžæ§ïŒã®3ã€ã®èгç¹ãããSCSKã®æšå¥šèšå®ã«åºã¥ããçŸç¶ã®èšå®å
容ã確èªããå ±åæžãäœæããå ±åãè¡ããµãŒãã¹ãšãªããŸãããã§ã«Catoã¯ã©ãŠãããå©çšã«ãªãããŠããã客æ§ã察象ãšãªããŸãã ä»åŸã¯ãåœç€Ÿã®æšå¥šèšå®ãããŠããŠãåããŸãšããã Catoã¯ã©ãŠã ãªãã¡ã¬ã³ã¹ã¬ã€ã ããã APIããŒã«ããã ãã®ãµãŒãã¹æäŸãèšç»ããŠãããŸãã ãŸãšã Catoã¯ã©ãŠãã®ãµãŒãã¹äœç³»ãåºæ¬æéããªãã·ã§ã³ããããŒãžããµãŒãã¹ã課éã»å¥çŽã«ã€ããŠè§£èª¬ãããŸããã ããã«ãSCSKã®ãããŒãžããµãŒãã¹ã«ã€ããŠãåãããŠã玹ä»ãããŠããã ããŸããããããèå³ããæã¡ã®æ¹ãããã£ãããã°ããé æ
®ãªããåãåãããã ããã “SASE”èªäœã®ç¥å床ãäœãã”Cato Networks瀟”ã”Catoã¯ã©ãŠãïŒCato Cloud/Cato SASE Cloudã®ç¥å床ãã¯ãŸã ãŸã äœãç¶æ³ã§ãã SCSKã§ã¯ã2021幎ããSASEã®äž»èŠãœãªã¥ãŒã·ã§ã³ãäžåã«ç޹ä»ãè¡ããªã³ã©ã€ã³ã»ãããŒãSCSK SASE Solution SummitïŒéç§° S4 ãšã¹ãã©ãŒïŒãã宿çã«éå¬ããŠãããŸãããããŸã§13åéå¬ãã1,600å以äžã®æ¹ã«ãåå ããã ããŠãããŸãã æ¬¡åã¯ãæ¥æ2024幎2æ15æ¥ã«éå¬ããããŸãã®ã§ãæ¯éãèå³ã®ããæ¹ã¯ãåå ãã ããã ã奜è©ã«ã€ã远å é嬿±ºå®ïŒãSCSK SASE Solution Summit (S4)ãŒäž»èŠ4補åã®éãã匷ã¿ã暪䞊ã³ã§ã玹ä»ïŒãŒ åŒç€Ÿã°ã«ãŒãã«ãŠåãæ±ã£ãŠãã4ã€ã®SASE補åã®æ°ã«ãªããã€ã³ããã®ã¥ããšåçž®ããŠãããè£œåæ¯èŒãéžå®è¡ã£ãŠããããã®æ
å ±ãäžåºŠã«åéã§ããããããSASEã®é¢ããæ
å ±åéäžã®æ¹ãã ãã§ãªãããèªç€Ÿã®èª²é¡è§£æ±ºã«æé©ãªSASEãç¥ãããæ¹ãããä»ç€Ÿã®å°å
¥æåäºäŸãèãããæ¹ãã®ãåå ãå¿ãããåŸ
ã¡ããŠãããŸãïŒ www.scsk.jp Catoã¯ã©ãŠããã¢ã»ãããŒïœCatoã¯ã©ãŠãã®äž»èŠæ©èœã2æéã§ç¶²çŸ
ïœ æ¬ã»ãããŒã§ã¯ãäžçåã®SASEã§ãããCatoã¯ã©ãŠããã®æŠèŠããã£ã·ã2æéããã¢åœ¢åŒã§ã芧ããã ããŸãã ãŸãããåžæã®æ¹ïŒå
ç10åæ§ïŒã¯ããã¢ç°å¢ã«å¯ŸããŠããæå
ã®ç°å¢ãããã³ãºãªã³åœ¢åŒã§Catoã¯ã©ãŠãã«è§ŠããŠé ãããšãå¯èœãªåå åã»ãããŒã§ãã www.scsk.jp SASEã»ãããŒä»¥å€ã«ãCatoã¯ã©ãŠãã®ã客æ§å°å
¥äºäŸã®å¶äœãFAQãµã€ãéå¶ããã® TechHarmonyïŒæè¡ããã°ïŒã§ãçæ§ã®ã圹ã«ç«ãŠãCatoã¯ã©ãŠãã®ç¥å床ã¢ããã«å°ãã§ãè²¢ç®ã§ããã°ãšèããŠãããŸãã
ããã«ã¡ã¯ãSCSKæ©æ¬ãšç³ããŸãã æ©éã§ããããŸãããAzureãµãŒãã¹ã§ãããAzure NAT Gatewayãã«ã€ããŠç޹ä»ããããšæããŸãã Azureä»®æ³ãã·ã³ãäœæããŠããããªãã¯IPã¢ãã¬ã¹ãä»äžããŠããªãã«ãé¢ããã ã€ã³ã¿ãŒãããéä¿¡ãå¿
èŠã§ãã Windows Update ãåºæ¥ãŠããããšã«çåãæã£ãããšã¯ãªãã§ããããã å®ã¯ãAzureä»®æ³ãã·ã³ãäœæããéã«AzureåŽã§ãazure-default-snatããšåŒã°ããã€ã³ã¿ãŒããããšã®éä¿¡çµè·¯ãäœæãããŠãããŸãã ãä»®æ³ãã·ã³âazure-default-snatâã€ã³ã¿ãŒããããã®çµè·¯ãååšããããšã«ãã Windows Update ãå®çŸåºæ¥ãŠããã®ã§ããã azure-default-snatã«ä»»æã®ãããªãã¯IPã¢ãã¬ã¹ãå²ãæ¯ããããŠããŸãã Azureä»®æ³ãã·ã³ãšã€ã³ã¿ãŒãããã®ããåãã Windows Update ãWebé²èЧãªã©ã®ã°ããŒãã«IPã¢ãã¬ã¹å¶éã®ãªãå
容ã§ããã°ããã©ã«ãã§å®è£
ãããazure-default-snatã§ãåé¡ãªãã®ã§ããã azure-default-snatã«å®è£
ãããŠããã°ããŒãã«IPã¢ãã¬ã¹ã¯ãä»®æ³ãã·ã³ã®åèµ·åãããAzureåŽã®ä»»æã®ã¿ã€ãã³ã°ãã§å€æŽãããŠããŸã仿§ããããããIPã¢ãã¬ã¹ã®åºå®ã¯ãããSaaSãšã®é£æºã«ã¯åããŠããªãç¶æ
ãšãªããŸãã ä»åã¯ãSaaSåŽã§ç¹å®ã®ã°ããŒãã«IPã¢ãã¬ã¹ã®ã¿ã«éä¿¡ãèš±å¯ããã±ãŒã¹ããAzure NAT Gatewayããçšããæ¹æ³ã§è§£æ±ºããæ¹æ³ãèšèŒããããŸãã Azure NAT Gatewayãšã¯ Azure NAT Gatewayãšã¯Azureã§æäŸãããŠããNATæ©èœã§ãã å
ã»ã©èšè¿°ãããazure-default-snatããšã¯ç°ãªããå©çšããã°ããŒãã«IPãåºå®ããããšãå¯èœãšãªããŸãã 以äžã«ç°¡æçãªã¢ãŒããã¯ãã£å³ãèšèŒããããŸãã ïŒã¢ãŒããã¯ãã£å³ïŒ ãµãããããšAzure NAT GatewayãçŽã¥ãããããšã«ãã ãµããããå
éšã«äœæããä»®æ³ãã·ã³ã®ã°ããŒãã«IPã¢ãã¬ã¹ãé¢é£ä»ããå¯èœãšãªããŸãã æ³šæç¹ 以äžã®ã±ãŒã¹ã«è©²åœããå Žåã¯ãAzure NAT Gatewayãå©çšã§ããŸããã ã»ãµããããå
ã«ãããªãã¯IPã¢ãã¬ã¹ãä»äžããŠããä»®æ³ãã·ã³ãååšããå Žå ã»ãµããããå
ã«ããŒããã©ã³ãµãå©çšããŠããå Žå æ§ç¯æ¹æ³ â Azure Portal ã«ãŠãNATã²ãŒããŠã§ã€ããšæ€çŽ¢ããŠãµãŒãã¹ç»é¢ãŸã§é·ç§»ããNATã²ãŒããŠã§ã€ã®äœæãæŒäžãã â¡åºæ¬ã¿ãå
ã§ããªãœãŒã¹ã°ã«ãŒããNATã²ãŒããŠã§ã€åãæ±ºå®ããã â¢éä¿¡IPã¿ãå
ã§ãããªãã¯IPã¢ãã¬ã¹ã远å ããã â»æ¢ã«ããã³ãå
ã§ãããªãã¯IPã¢ãã¬ã¹ãçšæããŠããå Žåã¯ãæµçšããŠãåé¡ããããŸãã â£ãµããããã¿ãå
ã§ãAzure NAT Gateway ãšçŽã¥ãå¯èœãªãµãããããåºçŸããã®ã§çŽã¥ãããããµããããã«ãã§ãã¯ãå
¥ãã â€ã¿ã°ã¿ãå
ã§ãä»»æã®ã¿ã°ãäœæãã â¥ç¢ºèª å
ã»ã©çŽã¥ãã宿œããµããããã®ããããã£ãéãããNATã²ãŒããŠã§ã€ãã«äœæãã Azure NAT Gateway ãçŽã¥ããããŠããã確èªããã ãŸããAzure NAT Gateway ã«ãããªãã¯IPã¢ãã¬ã¹ãçŽã¥ããŠããã®ã§ã察象ãµããããå
ã®ãµãŒãããã°ããŒãã«IPã¢ãã¬ã¹ã調æ»ããŠçŽã¥ãããããŠããã確èªã ãŸãšã ãããã§ããã§ãããããææ°ããããªã«å€ããªãã®ã§ç°¡åã«å®çŸã§ãããšæãããæ¹ãããã£ãããã®ã§ã¯ãªãã§ããããã æ³šæç¹ã§èšèŒããæ¡ä»¶ã«åŒã£ããããªããã°æ§ç¯å¯èœãšãªããŸãã®ã§ãæ¯éã°ããŒãã«IPã¢ãã¬ã¹ãåºå®åããããšã®ããšã§ããã°ã詊ãããã ããŸããšå¹žãã§ãã
ã¯ããã« ããã«ã¡ã¯ãæè¿AIç»åçæã«ããã£ãŠããå
çã§ãã 仿¥ã¯ AWS Control Tower ( 以äžControl Tower ) ã«ç®¡çãããŠãã S3 Log ã®ã©ã€ããµã€ã¯ã«ã倿Žããããšããããšã§æ³å®ããŠããªãã£ã課éãçºçãããããããã玹ä»ããŸãã Control Tower ã§ã¯ãLog Archive ã¢ã«ãŠã³ãã« CloudTrail ã®ãã°ãäœæããŠãããŠããŸããããããã ãã¶åã«äœæããã®ã§ãäžäœã©ã®ãããã®æéãã°ãä¿æããŠããããšããã©ã®ãããã®éãã°ãæºãŸã£ãŠããã®ã確èªããŠããŸããã§ããã æ°ã«ãªã£ãŠç¢ºèªããŠã¿ããš… S3 ãããããããªãã§ããïŒ(éé¡ã¯ããããããšãªãã§ãããã¢ã«ãŠã³ããç¶æããŠããã ãã§æ¯ææéãè¿ãåãããã®ãæ°ã«ãªã) ãšããããã§ãå°ãã§ãç¯çŽããããã« å€ããã°ã S3 Glacier Flexible Retrieval (æ§Glacier) ã«ç§»ãããšã«ããŸããã ãã®ãšãã¯æ²åãèµ·ãããšã¯æã£ãŠãèŠãŸããã§ããã S3ãã±ããã®ã©ã€ããµã€ã¯ã«ã倿ŽïŒå€±æïŒ Control Tower ã®ãŠãŒã¶ãŒã¬ã€ããäžéãæ¢ããŠã¿ãã®ã§ãããããã£ãœããŠãŒã¹ã±ãŒã¹ã®èª¬æããããŸããã§ããã仿¹ãªãã®ã§ãèªåã§ææ¢ãããŠã¿ãããšã«ããŸãã Control Tower ã®ãã°ã¯ Log Archive ã¢ã«ãŠã³ãã«ãããŸããLog Archive ã¢ã«ãŠã³ãã«ã¢ã¯ã»ã¹ããŠãS3ãã±ããã確èªããŸããã 180æ¥ã§æéåãã«ãªã£ãŠåé€ãããèšå®ã«ãªã£ãŠããããã§ããã倿ŽããŠã¿ãŸãããã ããïŒãAccess Denied ? ãããããã§ããããControl Tower ã®ç®¡çãããã°ãªã®ã§ãçŽæ¥å€æŽã¯ã§ããªãã§ããããControl Tower ããã§ããŠããŸãããïŒïŒãã£ãšãŒãïŒ ããã§ãããŠããã°ããã£ãã®ã§ãã… Control Tower ã®ã³ã³ãœãŒã«ãããã°èšå®ã®å€æŽ(èŠç¢ºèªïŒ) ãšããããã§ãæ°ãåãçŽã㊠Control Tower ã®æ¹ãã倿ŽããŠãããŸãããã 管çã¢ã«ãŠã³ãã§ãã°ã€ã³ãçŽããŠãControl Tower ã®å·Šã®ã¡ãã¥ãŒãã å
±æã¢ã«ãŠã³ã > ãã°ã¢ãŒã«ã€ã ãã¯ãªã㯠ããŒã¹ã©ã€ã³ã®èšå® ã® CloudFormation StackSet ã衚瀺ãã ãã¯ãªã㯠Log Archive ã¢ã«ãŠã³ãã«Control Tower ããããã€ããéã® StackSet ã®æ
å ±ã衚瀺ãããã®ã§ã ã¹ã¿ãã¯ã€ã³ã¹ã¿ã³ã¹ ã¿ããéžæããŠäžèº«ã確èªããŸããAWS ã¢ã«ãŠã³ãã®ç®æã«Log Archive ã¢ã«ãŠã³ãã衚瀺ãããŠããŸãããšããããšã¯ãããã倿Žãããšããããšã§ãããããïŒ æŽã« ãã©ã¡ãŒã¿ ã®ã¿ããèŠããšã RetentionDays ã 180 RetntionDaysForAccessLogs ã 180 ããã®äžã®TransitionDays ã 90 TransitionToGlacier ã No ã«ãªã£ãŠããŸãããããå€ããã°è¯ãããã§ããã å³äžã® ã¢ã¯ã·ã§ã³ ããã StackSet ã®ãã©ã¡ãŒã¿ãäžæžã ãéžæ RetentionDays ãš RetntionDaysForAccessLogs ãš TransitionToGlacierããéžæã㊠StackSet å€ã®äžæžããéžæ TransitionToGlacier ã Yesã«ããRetentionDays ãš RetentionDaysForAccessLogs 㯠線éã§ããããšããããããããã« 180 -> 200 ãšããŸããã ãããã€ãããã£ãŠ… SUCCEEDED ã«ãªããŸããã LogArchive ã¢ã«ãŠã³ãã«å
¥ãçŽããŠãS3ãã±ããã®ã©ã€ããµã€ã¯ã«èšå®ã確èªãããš90æ¥ã§Gracier Flexible Retrieval ã«ç§»åããŠã200æ¥ã§åé€ãããããã«ãã¡ããšæŽæ°ãããŠããŸããïŒ ããããControl Tower ã® ç»é¢ã® Amazon S3 ãã°ã確èªãããšã 180æ¥ã®ãŸãŸã§ããã ããŒãããªãã ããããšãåœæ¥ã¯èª¿æ»ããããŠäœæ¥ãçµäºããŸããã ç¿æ¥ãç°åžžäºæ
ã®éç¥ãïŒ AWS ãããé£çµ¡çšã®ã¡ãŒã«ã¢ãã¬ã¹ã«ãèŠæ
£ããªãéç¥ãæ¥ãŸããã AWS Cost Management: Cost anomaly(ies) summary for account: <ã¢ã«ãŠã³ãåç§°> (<AWS ã¢ã«ãŠã³ãID>) [2024-01-24] ãŸããïŒããªã«ãä¹ã£åãã§ãçºçããã®ãïŒããšãçã£éã«ãªã£ãŠç¢ºèªããŠã¿ããš… $242.31 !? …調æ»éå§… ã¢ã«ãŠã³ãID äž3æ¡ 911 Log Archive ã¢ã«ãŠã³ãã® S3 … ãŸãã… éããæã§ Anomary Detection Dashboard ã®ãã¿ã³ãæŒããŸã… ããã… $242.31 605775% …. ã¢ã«ãŠã³ãID æ«å°Ÿ 911 ã¯æšæ¥ã® Control Tower ã® Log Archive ã¢ã«ãŠã³ãã§ãããæé㯠S3 ã§çºçããŠããŸãããã®æç¹ã§ã»ãŒã»ãŒæšæ¥ã®èªåã®äœæ¥ãåå ã ãšããããŸãããã§ãããªãïŒ èããããæ ¹æ¬åå ã®ãããã©ã³ãã³ã° ã®ãšãããã¹ã¯ããŒã«ããŠã æ ¹æ¬åå ã®è¡šç€º ã®ãªã³ã¯ãã確èªããŸã æ€èšŒæã«ãã䜿ã£ãŠããªãã¢ã«ãŠã³ããªã®ã§ãéåžžã®å Žåæ¥æ¯ã®ã¢ã¯ã»ã¹æé㯠0 Request ã§ãããšããããæšæ¥ã®ã®ã¿ S3 ã® API ã¢ã¯ã»ã¹ããªããš 7,072,658 Requests ã«ãªã£ãŠããŸãïŒ ããïŒ ã§ãAPIã³ãŒã«ã ãã§ã¯ãããªã«éé¡ããããªããã§ã¯ïŒ S3 æšæº ã® PUTãCOPYãPOSTãLIST ãªã¯ãšã¹ã (1,000 ãªã¯ãšã¹ãããã) 㯠0.0047USD S3 æšæº ã® GETãSELECTãä»ã®ãã¹ãŠã®ãªã¯ãšã¹ã (1,000 ãªã¯ãšã¹ãããã) 㯠0.00037USD 7,072,658(ä»¶) x 0.0047(USD/1000ä»¶) / 1000(ä»¶) =33.2414926 (USD) 7,072,658(ä»¶) x 0.00037USD(USD/1000ä»¶) / 1000(ä»¶) =2.61688346 (USD) åããŸãããã ã¡ãã£ãšèª¿ã¹ãŠã¿ããšã Amazon S3 ライフサイクルを使用したオブジェクトの移行 - Amazon Simple Storage Service S3 ã©ã€ããµã€ã¯ã«èšå®ã䜿çšããŠãªããžã§ã¯ããç§»è¡ããŸãã docs.aws.amazon.com æ³šèš PUTãCOPYããŸã㯠ã©ã€ããµã€ã¯ã«ã«ãŒã«ã䜿çšããŠããŒã¿ãä»»æã® S3 ã¹ãã¬ãŒãžã¯ã©ã¹ã«ç§»åããå Žå ããªã¯ãšã¹ãããšã«åãèŸŒã¿æéãããããŸãããªããžã§ã¯ããã¹ãã¬ãŒãžã¯ã©ã¹ã«ç§»åããåã«ãåã蟌ã¿ãŸãã¯ç§»è¡ã®ã³ã¹ããæ€èšããŠãã ãããã³ã¹ãã«é¢ããèæ
®äºé
ã®è©³çްã«ã€ããŠã¯ã[ Amazon S3 ã®æé ] ãåç
§ããŠãã ããã ããŸã£ãããããã… ã©ã€ããµã€ã¯ã«ç§»è¡ãªã¯ãšã¹ãã®æé ã… S3 Glacier Flexible Retrieval ãžã®ç§»è¡æé㯠0.03USD / 1000 ä»¶(*2024/01/25çŸåš) 7,072,658(ä»¶) x 0.03426USD(USD/1000ä»¶) / 1000(ä»¶) = 242.30926308 (USD) ãŽã£ããã§ãã確å®ã§ããèªåã®ããããã§ãããããããã©ã€ããµã€ã¯ã«ç§»è¡ã®æéã£ãŠããªãå²é«ã ã£ããã§ãã… çµããã« ä»åã¯äžæ°ã«90æ¥åã»ã©ç§»åããã®ã§ 242.31 USD ã®æéãçºçããŸããããããã ãã®ãŸãŸã§ã¯ãæ¯æãã®1/3çšåºŠã®æéãæ¯æçºçããŠããŸãæ¯æ1USDç¯çŽããã©ãããæ¯æçŽ70USDãã€èª²éãããŠããŸããŸããããã¯ããŸããªãã®ã§ã次åã¯ãªã«ã察çãæ€èšããããšæããŸãã
ããã«ã¡ã¯ãMasedatiã§ãã1æãããçµãããŸãããä»å¹Žããããããé¡ãããããŸãã æè¿Amazon Bedrockã®ããã¥ã¡ã³ããçºããŠããã®ã§ããããããã³ãããšã³ãžãã¢ãªã³ã°ã¬ã€ãã©ã€ã³ããªããã®ãããããšã«æ°ãã€ããŸããã プロンプトエンジニアリングガイドライン - Amazon Bedrock Amazon Bedrock ã®ããã³ãããšã³ãžãã¢ãªã³ã°ã«ã€ããŠèª¬æããŸãã docs.aws.amazon.com æ¬èšäºã¯äžèšããã¥ã¡ã³ãã远ã£ãŠããå
容ãšãªã£ãŠããŸãã ãŸãã ã ãã£ãŠã¿ã ãã§ã¯ããã¥ã¡ã³ãã«åºã¥ããããã³ãããšã³ãžãã¢ãªã³ã°ãå®éã«è¡ããŸãã ããã³ãããšã³ãžãã¢ãªã³ã°ãšã¯ çæAIãæåŸ
ããŠãããã®ãšéãå
容ãåºåãããŠãããããããçµéšã¯ãªãã§ããããïŒ äžçæžåœèªåã§èª¿æŽããçµæãã°ã°ã£ãã»ããæ©ãã£ããšããããšãã以åç§ã¯ãããŸããã ãã®ãããªç¡é§ãªæéããªãããäžçºã§æåŸ
ãããã®ãåŸããè¯ãåœä»€ã®ä»æ¹ãã ããã³ãããšã³ãžãã¢ãªã³ã° ã§ãã äžå¿Bedrockããã«ãèããŠã¿ãŸãããã PromptïŒãWhat is prompt engineering?ã ïŒïŒããããã§ãããé·ããŠèªãæ°ã倱ããŠããŸããŸãã⊠åœä»€ãå€ããŠã¿ãŸãã PromptïŒãWhat is prompt engineering? Answer the above question in one sentence.ã ã Prompt engineering is the process of designing and creating prompts that are effective and engaging for a specific task or audience. ã çŽæçã§ããããããåçãè¿ã£ãŠããŸããã ããã§ãšãããããŸãïŒãããããã³ãããšã³ãžãã¢ãªã³ã°ã®äžã€ã§ããããã®äžæ©ãèžã¿åºãããšãã§ããŸããã ã¬ã€ãã©ã€ã³ãŸãšã ããã¥ã¡ã³ãèšèŒã®ã¬ã€ãã©ã€ã³ã以äžã«ãŸãšããŸããã詳现ã¯ããã¥ã¡ã³ããã確èªãã ããã ã·ã³ãã«ãæç¢ºãå®å
šãªæç€ºãè¡ã ããã³ããã® æçµæ ã§ã¿ã¹ã¯ã®æç€ºãè¡ã ç§ã¯ä»ãŸã§ãäžçªæåã«åœä»€ãæžããŠããã®ã§è¡æã§ããã ç°¡æœãªçããæ¬²ããå Žåãªã©åºå圢åŒãæå®ããæç€ºãåœä»€æã«ä»ãå ãã å
ã»ã©ã®äŸã®ãããªãAnswer the above question in one sentence .ãåœä»€æãæå¹ã§ãã æ®µéçã«åŠçããŠã»ããå Žåãåœä»€æã¯ã Think step-by-step to come up with the right answer ããšãã å°åŠçã®ç®æ°åé¡ãæ³åããŠããããã°ãããããããšæããŸãã äŸãã°ããå¥èããã¯ãæ¯ãããã500åããã¥ãããããããŸãããé§èåå±ã§1å100åã®ãèåã3åè²·ããŸãããåž°å®
éäžãžã¥ãŒã¹ãè²·ããæ®é80åãšãªããŸããããžã¥ãŒã¹ã®å€æ®µã¯ãããã§ããããããšãã£ãã¿ã¹ã¯ãè§£ããŠãããéã«æå¹ã§ãã ããã£ãœãæ
å ±ãåºåããããšãé²ããããåœä»€æã«ãIf you don’t know a proof, respond by saying “I don’t know.”ãã®ãããªæç€ºãå ãã ããã³ããã«è§£çäŸãä»ãå ãã åçŽã¿ã¹ã¯ã®å Žåã3~5åã§ååã§ãã çæAIã å±ãŸã ãã¿ããšæã£ãã®ã§ãããããã©ãŒãã³ã¹ãåäžããå Žåãããããã§ãããã¿ãããªãã§ãããâŠïŒ Temperature? Top P? Amazon Bedrock Playgroundã®TextãChatã䜿ã£ãŠããæ¹ã¯ãå³åŽã«ãã©ã¡ãŒã¿èª¿æŽã§ãã”Configurations”æ¬ããããšãæ°ã¥ãã§ããããã ãã¡ãã®èª¿æŽãããã¥ã¡ã³ãã«ãããš “ããã³ãããšã³ãžãã¢ãªã³ã°” ã®äžç°ã®ããã§ãã Amazon Bedrock LLM ユーザー向けの一般的なガイドライン - Amazon Bedrock Amazon Bedrock ã§ããã³ãããšã³ãžãã¢ãªã³ã°ã䜿çšããæ¹æ³ã«é¢ããäžè¬çãªã¬ã€ãã©ã€ã³ã§ãã docs.aws.amazon.com ãªããªã調æŽããæ©äŒããªãããã®ãŸãŸã®æ¹ãå€ãã®ã§ã¯ãªãã§ããããããŸãããã調æŽããŠã¿ããšã©ã®ããã«ããã°ãããããããªããšæããŸãããŸãã¯ãããããã®ãã©ã¡ãŒã¿ã®èª¬æãèŠãŠã¿ãŸãããã åãã©ã¡ãŒã¿ã®èª¬æ Temperature æå®ç¯å²ïŒ0ïœ1 ã0ãã«ãããšããå³å¯ãªåçãšãªããã1ãã«è¿ã¥ãã»ã©ããç°è²ãç¬èªæ§ã®ããåçãšãªãããã§ãã æ°å詊ããã®ã§ãããã0ãã ãšåãåçãåºåãããã1ãã ãšæ¯åç°ãªãåçãåºåãããŸããã Maximum generation length/maximum new tokens æå®ç¯å²ïŒ1ïœã¢ãã«ã«ãã Amazon Titan â ïœ8,000ããŒã¯ã³ Anthropic Claude â ïœ4,096ããŒã¯ã³ AI21 Labs Jurassic-2 â ïœ2,048 or ïœ8,191ããŒã¯ã³ Cohere â ïœ4,096ããŒã¯ã³ Meta Llama 2 Chat 13B â ïœ2,048ããŒã¯ã³ çæãããããŒã¯ã³ã®æå€§æ°ãæå®ããŸããã¯ã©ã¹åé¡ã®ãããªã¿ã¹ã¯ã®å Žåãã©ãã«åºåã®ãããªçãåçãæåŸ
ããããããããŒã¯ã³æ°ãå°ãªãèšå®ããŸãã Top-p æå®ç¯å²ïŒ0.1ïœ1 0.1ïœ1ã®æ°åã¯ç¢ºçã衚ããŠãããã1ãã«èšå®ãããšå¯èœæ§ã®ãããã¹ãŠã®ããŒã¯ã³ããæ¬¡ã®ããŒã¯ã³ãéžã°ããŸããéã«ãã0.1ãã«è¿ã¥ãã«ã€ããŠå¯èœæ§ã®äœãããŒã¯ã³ãé€å€ãããããŒã¯ã³ã®éžæè¢ã¯éå®çãšãªããŸãã Top-k Top-kã®ãã©ã¡ãŒã¿ãããã®ã¯ããAnthropic ClaudeãšCohereãã®ã¿ã§ãã æå®ç¯å²ïŒ0ïœ500 Top-pãšäŒŒãŠããã®ã§ãããTop-kã®å€ã¯æ¬¡ã«åºåãããå¯èœæ§ã®ããããŒã¯ã³ã®äžéã®æ°ã§ãã äŸãã°ãã10ããæå®ãããšæ¬¡ã«åºåãããããŒã¯ã³ã¯ã確çã®é«ãäžäœ10åã®åèªããã©ã³ãã ã§éžã°ããŸãã End token/end sequence æå®ããããŒã¯ã³ã®åã§åºåãæ¢ããããšãã§ããŸãã äŸãã°ãisãã远å ããå ŽåããPrompt: What is AWS?ãã®åºåãšããŠã以äžã®ããã«ãªããŸãã 远å åïŒãAWS (Amazon Web Services) is a comprehensive, evolving…ã 远å åŸïŒãAWS (Amazon Web Services)ã åºæ¬çã«èšå®ããªããŠãããé
ç®ã®ããã§ãã ãã©ã¡ãŒã¿èª¿æŽé£ãããªãã§ããïŒ ãã©ã¡ãŒã¿èª¿æŽé£ãããªãã§ããïŒ lengthãtokenç³»ã¯çŽæçã§ããã”Temperature”ã”Top-p”ã®çµã¿åããã¯ç¡éã«ãããã¿ã¹ã¯ã«é©ãã調æŽã¯ãªããªãé£ãããšæããŠããŸã⊠ãããããããšã«ãAWSå
¬åŒããããã³ããããã©ã¡ãŒã¿ã®èšå®äŸãæäŸãããŠããŸãã Playgroundsäžã§ã¢ãã«ãéžã³ã”Configurations”ã®äžéšã®ã Load examples ããæŒããŠã¿ãŸãããã ããŸããŸãªã¢ãã«ã§èš28ä»¶ã®ããã³ããäŸãæäŸãããŠããŸãã 詊ãã«Claudeã§æäŸãããŠãããCharacter RoleplayããéããŠã¿ãŸããçæAIããã£ãªã¢ã¢ããã€ã¶ãŒã«ãªãããèšå®ã®äŸã§ãã éæ ããã©ã¡ãŒã¿ã§ããããTemperature=1ãTop-p=1ãTop-k=250ããšã©ã³ãã æ§ãé«ããã¢ããã€ã¹ãæ±ããåºåã®éã¯ããåµé çã«èª¿æŽããããã§ãã ããã³ããã¯å€§ããåããŠ3ããŒãã«åãããŠããŸããæåã«ã«ãŒã«ä»ããè¡ããäžéã§è§£çäŸãå¿
èŠãªããŒã¿ããããŠæçµæã«ç°¡æœãªåœä»€ãå
¥åãã圢ãšãªã£ãŠããŸãã ãŸãã«ãŒã«ä»ãã®éãã¬ã€ãã©ã€ã³ãŸãšã5ã«èšèŒãããšããã”ããã£ãœãæ
å ±”ãåºåãããªãããã«ã If you are unsure how to respond, say “Sorry, I didn’t understand that. Could you rephrase your question?” ãã®ã«ãŒã«ã远èšããŠããŸãã ãã£ãŠã¿ã ããã³ãããšã³ãžãã¢ãªã³ã°” ãªã “ãš” ãã “ã§ãåŒç€Ÿã®æ°ãããã£ãããã¬ãŒãºãèããŠãããããšæããŸãã ãã©ã¡ãŒã¿ã¯ãã£ãªã¢ã¢ããã€ã¶ãŒãšåãå€ãšãã” ãªãïŒ ãã “å
±éãšããŸãã TemperatureïŒ1 Top-pïŒ1 Top-kïŒ250 ãŸãã¯ãäœãèããåœä»€ããŠã¿ãŸãã PromptïŒSCSKæ ªåŒäŒç€Ÿã®ãã£ãããã¬ãŒãºãèããŠãã ãã ããã¯ãããžãŒã§æªæ¥ãåµé ããã ãã€ãããŒã·ã§ã³ã®ããŒãããŒã ãããžã¿ã«ãã©ã³ã¹ãã©ãŒã¡ãŒã·ã§ã³ãå
±ã«ã ãå¯èœæ§ã圢ã«ã ãããããããããã§åæ§ããããŸããã⊠ã§ã¯ãä»ãŸã§åŠãã§ããããšãPromptã«è©°ã蟌ãã§ã¿ãŸãããã ãŸãã¯ã«ãŒã«ä»ããšããŠãSCSKæ ªåŒäŒç€Ÿããšã¯ã©ã®ãããªäŒæ¥ãªã®ãæããŠãããŸãã åŒç€ŸããŒã ããŒãž ããåŒçšããŸãããã SCSKã°ã«ãŒãã¯ã50幎以äžã«ããããããžãã¹ã«å¿
èŠãªITãµãŒãã¹ããBPOã«è³ããŸã§ã ãã«ã©ã€ã³ã¢ããã§æäŸãã8,000瀟以äžã®ã客æ§ã®ããŸããŸãªèª²é¡ã解決ããŠããŸããã ãããŠã次ã®é£èºã«åããŠãITã軞ãšããã客æ§ãããŒãããŒã瀟äŒãšã®å
±åµã«ããã ããŸããŸãªæ¥çš®ã»æ¥çã瀟äŒã®èª²é¡è§£æ±ºã«åããæ°ããªææŠã«åãçµãã§ããŸãã ãŸãã远å ã«ãŒã«ãšã㊠åŒç€ŸCMç¹èšãµã€ã èšèŒã®ãMESSAGEããåŒçšããããšæããŸãã SCSKã°ã«ãŒãã«ã¯ã50幎以äžã«ãããããããã課é¡ãITã§è§£æ±ºããŠããç¥èŠãšå®çžŸã«ãããITã®ç¡éã®å¯èœæ§ããããŸãã ããå€ãã®ã¿ãªããã«SCSKãšããäŒç€Ÿãç¥ã£ãŠããããITã®åã§ã倢ããæªæ¥ãå
±ã«åµã£ãŠããããã ä»åŸã®SCSKã°ã«ãŒãã«ããæåŸ
ãã ããã ã«ãŒã«ä»ãã®ããšã¯è€æ°äŸãæããåçŽæå¿«ãªæç€ºãäžããã°å®æã§ãã äžèšãŸãšããPromptã以äžã®ãšããã§ããâ»åŒçšæç« ã®ãã°ã«ãŒãããããæ ªåŒäŒç€Ÿãã«å€æŽããäžéšæç²ããŸãã SCSKæ ªåŒäŒç€Ÿãšã¯æ¥æ¬ã®ã·ã¹ãã ã€ã³ãã°ã¬ãŒã¿äŒç€Ÿã§ãã SCSKæ ªåŒäŒç€Ÿã¯ã50幎以äžã«ããããããžãã¹ã«å¿
èŠãªITãµãŒãã¹ããBPOã«è³ããŸã§ããã«ã©ã€ã³ã¢ããã§æäŸãã8,000瀟以äžã®ã客æ§ã®ããŸããŸãªèª²é¡ã解決ããŠããŸããã ãããŠã次ã®é£èºã«åããŠãITã軞ãšããã客æ§ãããŒãããŒã瀟äŒãšã®å
±åµã«ãããããŸããŸãªæ¥çš®ã»æ¥çã瀟äŒã®èª²é¡è§£æ±ºã«åããæ°ããªææŠã«åãçµãã§ããŸãã SCSKæ ªåŒäŒç€Ÿã«ã¯ä»¥äžã®ç±ãæãããããŸãã ãããå€ãã®ã¿ãªããã«SCSKãšããäŒç€Ÿãç¥ã£ãŠããããITã®åã§ã倢ããæªæ¥ãå
±ã«åµã£ãŠãããããã 以äžãéå»ã®ãã£ãããã¬ãŒãºã®äŸã§ãã <example> 2022幎ïŒãç¡ãããç¥å床ãSCSKãããããITã®å¯èœæ§ãSCSKã 2023幎ïŒãäŒç€Ÿåã ããSCSKãããããITã®å¯èœæ§ãSCSKã </example> 2022幎ã2023幎ã®ãã£ãããã¬ãŒãºããç¹ããããã«ã2024幎ã®SCSKæ ªåŒäŒç€Ÿã®ãã£ãããã¬ãŒãºãèããŠãã ããã ãããåºåïŒ ã ã€ãªããã倢ãšçŸå®ãSCSK ã ãŸãšã ç§ãçæAIãè€ããã䌞ã³ãã¿ã€ãã§ãã
ããã«ã¡ã¯ãSCSKã§AWSã®å
è£œåæ¯æŽã ãã¯ãã«ã«ãšã¹ã³ãŒããµãŒãã¹ ããæ
åœããŠããè²å¡ã§ãã ä»åã¯ãAWS Network Firewallã®è©±é¡ã§ãããããŸã§ã«ãAWS Network Firewallã®èšäºãæžããŠãããŸãã®ã§ããèå³ãããŸããããã¡ããã芧ãã ããã AWS Network Firewallã§ã¢ãŠãããŠã³ããã©ãã£ãã¯ãTLSã€ã³ã¹ãã¯ã·ã§ã³ãã AWS Network Firewallã§ãã¢ãŠãããŠã³ã(egress)ã®TLSã€ã³ã¹ãã¯ã·ã§ã³æ©èœãæ€èšŒããŸãããã¢ãŠãããŠã³ãTLSã€ã³ã¹ãã¯ã·ã§ã³ã«ãããã¯ã©ã€ã¢ã³ãPC(瀟å
)ããå€éšã®ãŠã§ããµãŒããžã®HTTPSéä¿¡ã®å
å®¹ãæ€æ»ããããšãã§ããããã«ãªããŸãã blog.usize-tech.com 2023.12.27 AWS Network Firewallã§ã€ã³ããŠã³ããã©ãã£ãã¯ãTLSã€ã³ã¹ãã¯ã·ã§ã³ãã AWS Network Firewallã§ãã€ã³ããŠã³ã(ingress)ã®TLSã€ã³ã¹ãã¯ã·ã§ã³æ©èœãæ€èšŒããŸãããã€ã³ããŠã³ãTLSã€ã³ã¹ãã¯ã·ã§ã³ã«ãããèªèº«ã§ç®¡çãããŠã§ããµãŒããžã®HTTPSéä¿¡ã®å
å®¹ãæ€æ»ããããšãã§ããããã«ãªããŸãã blog.usize-tech.com 2024.01.09 AWS Network Firewallã®IDSã»IPSæ©èœã«ã€ã㊠AWS Network Firewallã¯IDSã»IPSæ©èœãšãã¡ã€ã¢ãŠã©ãŒã«æ©èœãåããŠããŸãããç°¡æã«å°å
¥ããå ŽåãIDSã»IPSæ©èœã¯AWSãããŒãžãã°ã«ãŒãããã®ãŸãŸé©çšãããšããããšãããã®ã§ã¯ãªãã§ããããã AWS Network Firewallã«ã¯ãAWSãäºãçšæããAWSãããŒãžãã°ã«ãŒããšãããã®ãè€æ°ããããããçµã¿åãããããšã§å©çšè
åŽã¯é£ããèšå®ãããã«IDSã»IPSãšããŠæ©èœãããããšãã§ããã®ã§ãã ãã¡ã€ã³ããã³ IP ã«ãŒã«ã°ã«ãŒãã®äžèЧ è
åšçœ²åã«ãŒã«ã°ã«ãŒãã®äžèЧ AWSãããŒãžãã°ã«ãŒãã¯ã AWSãã«ãŒã«ãèªåçã«ã¢ããããŒãããŠããã ã®ã§ãæ°ããè
åšãçºèŠããããã³ã«èªåãã¡ã§ã«ãŒã«ãæŽæ°ããå¿
èŠããããŸããã AWSãããŒãžãã°ã«ãŒãã®åé¡ç¹ ãã®ããã«äŸ¿å©ãªAWSãããŒãžãã°ã«ãŒãã§ãããå°ã
å°ãããšããããŸãã éçšäžãéåžžã®ãã±ãããã£ã«ã¿ãªã³ã°ã§éä¿¡ããããã¯ãããšãã®ã¢ã©ãŒãã¯éçšæ
åœã«éç¥ããŠã»ãããªãããã©ãIDSã»IPSã§ãããã¯ããå Žåã¯éç¥ãããããšããã±ãŒã¹ã¯ããåŸããã§ãããšãããããã°ãããããã¯AWSãããŒãžãã°ã«ãŒãã®ã«ãŒã«ã«åèŽãããã°ã§ãããšãã倿ãã§ããŸããã 以äžã«CloudWatchã«åºåãããIDSã»IPSã®ã¢ã©ãŒããã°ã2ã€æ²èŒããŸãã 倿ã«äœ¿ããããªãã£ãŒã«ããšããŠã¯ãevent.alert.signatureãševent.alert.signature_idãããããã§ãããsignatureã®æ¹ã¯å
±éããæååããããŸãããäžæ¹ãsignature_idã®æ¹ã¯28ããå§ãŸã7æ¡ã®æ°åãšããå
±éç¹ãããããã§ãããAWSãµããŒãã«åãåããããšããããã®ç¯å²ã®idã䜿ããããšãã確å®ãªæ
å ±ã¯ãªãããã§ããã ç¬èªäœæããã«ãŒã«ã°ã«ãŒãã®ãã°åºåãå¶åŸ¡ãã ããã§ããç¬èªäœæããã«ãŒã«ã°ã«ãŒãããåºåããããã° ä»¥å€ ããéç¥ããèšå®ãèããŠã¿ãŸãã æšæºã¹ããŒããã«ã«ãŒã«åœ¢åŒ [1] ã§èšè¿°ããã«ãŒã«ã«åèŽãããã°ã¯ä»¥äžã®ããã«ãªããŸãã [1] AWS Network Firewallã«ãããã«ãŒã«èšè¿°æ¹æ³ã®ã²ãšã€ããã±ãããã£ã«ã¿ãªã³ã°ã®ã«ãŒã«ãæ¯èŒçç°¡åã«èšè¿°ã§ãããä»ã«Suricataäºæã«ãŒã«æååãšãã圢åŒãããã event.alert.signatureããªã(å³å¯ã«ã¯ã空æå “”ã«ãªã£ãŠãã)ããšãåãããŸãã ãŸããæšæºã¹ããŒããã«ã«ãŒã«åœ¢åŒã®ã«ãŒã«ã«ã¯ãªãã·ã§ã³ã§ä»»æã®signatureæåå(èšå®æã¯msgããŒã¯ãŒãã§æå®)ãä»äžã§ããã®ã§ãæååã®å
é ã«æ±ºãŸã£ãæååãã€ããã®ãããã§ããããæ¬¡ã®äŸã¯å
é ã«”PACKET_FILTER_ALERT:”ãã€ããããã«ããŠã¿ãŸããã ããã«ãç¬èªäœæã«ãŒã«ã°ã«ãŒãã®ã«ãŒã«ã§ã¯ãªãã®ã§ãããTCP 3ãŠã§ã€ãã³ãã·ã§ã€ã¯ãæé»çã«èš±å¯ãããšããªã©ãã©ã®ã«ãŒã«ã«ãåèŽããªãã£ããã±ãããã¢ã©ãŒããã°ã«åºåãããå ŽåããããŸããäžäŸããã¡ãã§ãã signatureã”aws:”ãšããæååã§å§ãŸã£ãŠããããšãåãããŸãã ç¬èªäœæããã«ãŒã«ã°ã«ãŒãã®ãã°ä»¥å€ãéç¥ãããã£ã«ã¿ãŒãäœæãã ããã§ã¯ãã£ã«ã¿ãŒãäœæããŠã¿ãŸããCloudWatch Logsããã¡ãŒã«ãªã©ã®éç¥ã«ã€ãªããæ¹æ³ãšããŠä»£è¡šçãªãã®ã«ã¡ããªã¯ã¹ãã£ã«ã¿ãŒãäœ¿ãæ¹æ³ãšãµãã¹ã¯ãªãã·ã§ã³ãã£ã«ã¿ãŒãäœ¿ãæ¹æ³ããããŸãããæ¬çš¿ã§ã¯ãµãã¹ã¯ãªãã·ã§ã³ãã£ã«ã¿ãŒãèšå®ããŠã¿ãŸãã ãªããã¡ããªã¯ã¹ãã£ã«ã¿ãŒãšãµãã¹ã¯ãªãã·ã§ã³ãã£ã«ã¿ãŒã®ãã£ã«ã¿ãŒãã¿ãŒã³æ§æã¯äžç·ãªã®ã§ã以äžã§èª¬æãããã¿ãŒã³ã¯ã¡ããªã¯ã¹ãã£ã«ã¿ãŒã§ã䜿çšããããšãã§ããŸãã äœæãããã£ã«ã¿ãŒã¯ãsignatureã” PACKET_FILTER_ALERT: “ã” aws: “ã§ã¯ããŸããã® ä»¥å€ ãéç¥ãããã£ã«ã¿ãŒ [2] ãšããŸãã [2] “”ãé€å€æ¡ä»¶ã«å«ããããšããã®ã§ããããµãã¹ã¯ãªãã·ã§ã³ãã£ã«ã¿ãŒã§ã¯æ£èŠè¡šçŸã2ãã¿ãŒã³ãŸã§ããæå®ã§ããããŸãæ£èŠè¡šçŸ”()”ããµããŒãããŠããªããšããããšã§ãç§ã®ç¥èã®ç¯å²ã§ã¯äžã€ãã¹ãŠãé€å€ããèšå®ãæžããŸããã§ãããã«ãŒã«ã«ã¯å¿
ãç¹å®ã®æååããå§ãŸãsignatureãå
¥åãã(msgããŒã¯ãŒããæå®ãã)ãšããéçšã«ããã°ã””ãé€å€æ¡ä»¶ã«å«ããããªããŠãå®çšäžã¯åé¡ãªãããšæããŸãã ãµãã¹ã¯ãªãã·ã§ã³ãã£ã«ã¿ãŒã®äœæ ãµãã¹ã¯ãªãã·ã§ã³ãã£ã«ã¿ãŒã®äœææã«ãæ¢åã®ãã°ãããã£ã«ã¿ãã¿ãŒã³ã®ãã¹ããããããšãã§ããŸãã®ã§ãäžéãå¿
èŠãªãã°ãåºåããŠããäœæã宿œããããšããå§ãããŸãã CloudWatchã®ãã°ã°ã«ãŒããã察象ã®ãã°ã°ã«ãŒããéžæãããã¢ã¯ã·ã§ã³ãâããµãã¹ã¯ãªãã·ã§ã³ãã£ã«ã¿ãŒãâãLambdaãµãã¹ã¯ãªãã·ã§ã³ãã£ã«ã¿ãŒãäœæããã¯ãªã㯠ãLambda ãµãã¹ã¯ãªãã·ã§ã³ãã£ã«ã¿ãŒãäœæãç»é¢ã§å
¥åãããŠãããŸãã ãã°ã®éãå
ãšãªãLambda颿°ãæå®ããå¿
èŠããããŸãããæ¬çš¿ã¯ç¹å®ã®æååãé€å€ãããã£ã«ã¿ãŒã®ãã¹ããŸã§ãæ±ããŸãã®ã§ãæå®ãçç¥ããŸããå®éã«ã¯ãLambda颿°ã®äœæïœSNSéç¥ã®éšåãäœãå¿
èŠããããŸãã®ã§ãã€ã³ã¿ãŒãããäžã®åçš®ããã°èšäºçããåç
§ã®äžãèšå®ããŠãã ããã CloudWatch Logs サブスクリプションフィルターの使用 - Amazon CloudWatch Logs AWS CloudTrail ã€ãã³ããå«ããã°ã°ã«ãŒãã«ãµãã¹ã¯ãªãã·ã§ã³ãã£ã«ã¿ãŒãé¢é£ä»ããŸãã docs.aws.amazon.com ãã°ã®åœ¢åŒã«JSONãæå®ããŸãã ãµãã¹ã¯ãªãã·ã§ã³ãã£ã«ã¿ãŒã®ãã¿ãŒã³ã«ä»¥äžãæå®ããŸãã { $.event.alert.signature != %^PACKET_FILTER_ALERT:.*% && $.event.alert.signature != %^aws:.*% } ãµãã¹ã¯ãªãã·ã§ã³ãã£ã«ã¿ãŒã®ãã¹ã ããã¿ãŒã³ããã¹ããã®ããã¹ããããã°ããŒã¿ãéžæãã®ãšããã§ããã¹ãããããã°ã®ãããã°ã¹ããªãŒã ãéžæããããã¿ãŒã³ããã¹ãããã¯ãªãã¯ããŸãã 衚瀺ããããã¹ãçµæãèŠããšãæå³éããsignatureã”PACKET_FILTER_ALERT:”ãŸã㯔aws:”ã§å§ãŸããã°ãé€å€ã§ããŠããããšã確èªã§ããŸããã ãŸãšã CloudWatch Logsã®ãµãã¹ã¯ãªãã·ã§ã³ãã£ã«ã¿ãŒã䜿ã£ãŠAWS Network Firewallã®AWSãããŒãžãã«ãŒã«ã®ãã°ã®ã¿ãéç¥ããæ¹æ³ã解説ããŠã¿ãŸããã æ¬çš¿ã§ã¯ãAWSãããŒãžãã«ãŒã«ã§äœ¿çšãããsignature_idã¯åãããªããšããåæã«ç«ã¡ãŸããããå
¬åŒããã¥ã¡ã³ãã«å
¬éãããŠããªãã ãã§å®éã«ã¯äœ¿çšãããIDã®ç¯å²ã決ãŸã£ãŠããã®ã§ã¯ãªãããšæãããŸãã®ã§ãAWSã®ãµããŒããåãã€ã€signature_idã§ãã£ã«ã¿ãŒããããæ¹åŒãæ€èšããã®ããããããããŸããã
ã¯ããã« åœç€Ÿã§ã¯ Cato ã¯ã©ãŠãã®å°å
¥ããéçšãŸã§äžè²«ããæè¡ãµããŒãããµãŒãã¹ãæäŸããŠãããŸãã Catoã¯ã©ãŠã å€åããåãæ¹ã«å¿
èŠãªããŒããã©ã¹ãããå®çŸããããããã¯ãŒã¯ãšã»ãã¥ãªãã£ãçµ±åããã¯ã©ãŠããµãŒãã¹(SASE)ãã§ããCatoã¯ã©ãŠããã玹ä»ããŠããŸãã www.scsk.jp ä»åã¯ãµãŒãã¹ã¡ãã¥ãŒã®1ã€ã§ããææ¬¡ã¬ããŒããµãŒãã¹ã®ã玹ä»ãšããã®è£åŽã®æè¡çãªä»çµã¿ã«ã€ããŠè§£èª¬ããããŸãã ææ¬¡ã¬ããŒããµãŒãã¹ã®çŽ¹ä» ææ¬¡ã¬ããŒããµãŒãã¹ã®æŠèŠ ææ¬¡ã¬ããŒããµãŒãã¹ã¯ãã客æ§ã Cato ã¯ã©ãŠããå©çšããäžã§ããããã¯ãŒã¯åç·ããã©ãã£ãã¯ã«åé¡ãçºçããŠããªããã©ãããšãã£ã芳ç¹ããã»ãã¥ãªãã£äžã®åé¡ãæžå¿µãèµ·ããŠããªããã©ãããšãã£ã芳ç¹ãªã©ã§åæããã¬ããŒããæ¯æãæäŸãããµãŒãã¹ã§ãããŸããCato ã¯ã©ãŠãã®æ°æ©èœã®ã玹ä»ãåœç€Ÿã®ãµããŒããµãŒãã¹ã®ãå©çšç¶æ³ã®å®çžŸå ±åãªã©ãææ¬¡ã¬ããŒãã®äžã§è¡ã£ãŠãããŸãã ã¬ããŒãã®äžèº«ã«ã€ããŠããå°ã詳ãã玹ä»ãããšãäŸãã°æ¬¡ã®ãããªåæãè¡ã£ãŠããŸãã åãµã€ãïŒæ ç¹ïŒã®ãã©ãã£ãã¯åæ ã¹ã«ãŒãããããã±ãããã¹ã»ç Žæ£çãã©ã¹ããã€ã«ãªã©ã°ã©ãåã»åŸååæ ã€ãã³ãåæ Socket ã®æ¥ç¶å±¥æŽãã¢ããã°ã¬ãŒãå±¥æŽã®ç¢ºèª ã»ãã¥ãªãã£æ©èœïŒå Firewall æ©èœãSuspicious ActivityãDNS Protection ãªã©ïŒã®éèšã»åæ ãŠãŒã¶åæ é·ææªãã°ã€ã³ãª SDP ãŠãŒã¶ã®æœåº ãæäŸããææ¬¡ã¬ããŒãã«ã¯ãããŒã¿ã®éèšã»åæãã°ã©ãåãããã°ã©ã ã§è¡ã£ãŠèªåçæããå¥çŽãšããã®å
容ãããšã«åœç€Ÿãšã³ãžãã¢ãæçµçãªèå¯ããã®ä»æ
å ±ãèšèŒããæ¬çŽããããŸããå¥çŽã®ãµã³ãã«ã¯ [ãã¡ã] ããã確èªããã ããŸãã ãããã£ãããŒã¿ã¯ Cato ã®ç®¡çç»é¢ (CMA) äžã§åç
§ã§ããŸãã®ã§ã宿çã«ç¢ºèªããŠéçšã«æŽ»çšããŠããã客æ§ãããã£ãããããšæããŸãããã ããµã€ãæ°ãå€ããªã£ãŠãããšãã©ãã£ãã¯ã®ã°ã©ãã確èªããã ãã§æéãããããŸãããåã
ã®ã€ãã³ããã°ã確èªã§ããŠãéèšããããšã¯ã§ããŸããããããŒã¿ã¯äžå®æéïŒ3ãæ or 6ãæ or 12ãæ) ãŸã§ããé¡ã£ãŠç¢ºèªã§ããªããšãã£ã課é¡ããããŸãããããã£ã課é¡ã¯ææ¬¡ã¬ããŒããµãŒãã¹ã§è§£æ¶ããããŸãã ææ¬¡ã¬ããŒããµãŒãã¹ã®ç®ç ææ¬¡ã¬ããŒããµãŒãã¹ã®æ¬è³ªçãªç®çã¯ãã客æ§ã« Cato ã¯ã©ãŠããå¿«é©ã»å®å
šã«ãå©çšããã ãããã«ãã客æ§ã®éçšäœæ¥ãæ¯æŽããããšã«ãããŸããäŸãã°æ¬¡ã®ãããªéçšäœæ¥ãå¿
èŠã«ãªã£ãŠããããšæããŸãã 垯åãäžè¶³ãã€ã€ãããµã€ããããã°ã垯åãå¢éãã ã€ã³ã¿ãŒãããåç·ã®äžèª¿ãããã°ãåç·äºæ¥è
ã»ISPãžã®èª¿æ»äŸé Œãè¡ã äžå¯©ãªéä¿¡ãè¡ãããŠããã°ã調æ»ãéä¿¡ã®é®æãè¡ã éè·ãã瀟å¡ã®ã¢ã«ãŠã³ãã®æ£åžãè¡ã æäŸããææ¬¡ã¬ããŒããéçšäœæ¥ã®ã€ã³ãããæ
å ±ãšããŠãŠåœ¹ç«ãŠãŠããã ããã°ãšèããŠããŸãã èªåçæã®ä»çµã¿ [ãã¡ã] ã®å¥çŽã®ãµã³ãã«ãèªåçæããä»çµã¿ã«ã€ããŠãä»çµã¿ã«ã€ããŠãå°ã解説ããããŸããå
·äœçã«ã¯æ¬¡ã®ãããªããšãããã°ã©ã ã§è¡ã£ãŠããŸãã Cato ã® API ããå¿
èŠãªããŒã¿ãååŸãã ååŸããããŒã¿ãéèšã»åæãã ãã©ãã£ãã¯ã«é¢ããããŒã¿ããæç³»åã°ã©ããäœæãã éèšã»åæçµæãã°ã©ããã1ã€ã®PDFãã¡ã€ã«ãäœæãã Cato API ããããŒã¿ååŸ ææ¬¡ã¬ããŒããçæããã«ããããCato API ã®æ¬¡ã® API ãå©çšããŠããŒã¿ãååŸããŠããŸãã entityLookup : ãµã€ãããŠãŒã¶ã®äžèЧ accountSnapshot : ãµã€ãã®è©³çްæ
å ± accountMetrics : ãã©ãã£ãã¯ã®æç³»åããŒã¿ events : ã€ãã³ãã®éèšçµæ Cato API ã®å©ç𿹿³ã«ã€ããŠã¯å¥èšäºã§ç޹ä»ããŠãããŸãã®ã§ããã¡ããåç
§ãã ããã Cato API ã®å©ç𿹿³ãšå¶éäºé
Cato API ã®å
·äœçãªå©ç𿹿³ã泚æäºé
ã Python ã³ãŒãã亀ããŠè§£èª¬ããŠããŸãã blog.usize-tech.com 2023.08.08 ããŒã¿ã®éèšã»åæãšã°ã©ãäœæ API ããååŸããããŒã¿ã®éèšã»åæã«ã¯ pandas ãå©çšããã°ã©ãäœæã«ã¯ Matplotlib ãå©çšããŠããŸããã©ã¡ãã Python ã®ã©ã€ãã©ãªã§ãããŒã¿åæã®éã«åºãå©çšããããã®ã§ãã PDFãã¡ã€ã«ã®äœæ PDFãã¡ã€ã«ã®äœæã«ã¯ã Asciidoctor ãšããææžåããŒã«ãå©çšããŠããŸããAsciiDoc ãšããããŒã¯ã¢ããèšèªã§ææžãçšæããã°ãé»åæžç±ã®ãããªç¶ºéºãªãã©ãŒãããã®ãã¡ã€ã«ã«å€æã§ãããšããåªããã®ã§ããæ¥æ¬èªãã©ã³ããçšæããã°ããµã³ãã«ã®ãã㪠PDF ãäœæã§ããŸãã AsciiDoc ã§æžãããææžã®äœæã«ã¯ Jinja ãšãããã³ãã¬ãŒããšã³ãžã³ãå©çšãããããããçšæããŠããããã³ãã¬ãŒãã«ããŒã¿ã®éèšã»åæçµæãªã©ãåã蟌ãã§èªåçæããŠããŸãã ä»çµã¿ã®ãŸãšã èªåçæã®ä»çµã¿ããŸãšãããšã次ã®ãããªãããŒã§ææ¬¡ã¬ããŒããèªåçæããŠããŸãã API ã§ããŒã¿ãååŸã§ããã°åŸã¯ããã°ã©ã ã§å€§æµã®ããšã¯å®çŸã§ããŸãããå°æ¥ Cato API ã§ååŸã§ããããŒã¿ãå¢ããŠããã°ææ¬¡ã¬ããŒããå
å®ãããŠããèãã§ãããŸããåœç€Ÿã«ãŠéçºããŠããããã°ã©ã ããæäŸããããšã¯ã§ããŸããããã客æ§èªèº«ã§ Cato API ãå©çšããŠéçšäœæ¥ã«åœ¹ç«ãŠãããšãã§ããããšæããŸãã ãŸãšã Cato ã¯ã©ãŠãã®ã客æ§åãã®ææ¬¡ã¬ããŒããµãŒãã¹ã玹ä»ãããã®è£åŽã®æè¡çãªä»çµã¿ã«ã€ããŠãç°¡åã«èª¬æããŸããã Cato ã¯ã©ãŠãã®å©çšæã«ãããéçšäœæ¥ãšããŠå®æœãã¹ãããšãæŽçããæ
å ±ãããŠããŠïŒâéçšã«é¢ããéæ©èœèŠä»¶ãèšèšæžã®ãµã³ãã«ïŒã¯ãæäŸã§ããŠãããŸããããäžè¬çã«å®æœãå¿
èŠã§ããããšèããéçšäœæ¥ã«åœ¹ç«ã€ããŒã¿ã¯ææ¬¡ã¬ããŒããµãŒãã¹ãšããŠæäŸããŠãããŸãã®ã§ããèå³ãããã°ãã²åœç€Ÿã«ãçžè«ãã ãããã詊ããšããŠææ¬¡ã¬ããŒãã®ãµã³ãã«ã®æäŸãããããŸãã ãŸããææ¬¡ã¬ããŒããµãŒãã¹ãšãã圢ã§ãªããšããã客æ§åºæã®éçšèŠä»¶ã Cato API ãå©çšããŠå®çŸããä»çµã¿ã®éçºæ¯æŽãè¡ããŸãã®ã§ãæ°è»œã«ãçžè«ãã ããã
ããã«ã¡ã¯ãåºéã§ãã AWS AppSync ã䜿çšããã¢ããªã±ãŒã·ã§ã³ãéçºããæ©äŒãããããªãŸã«ãã䞻㫠VTL ã®æžãæ¹ã«é¢ããŠãŸãšãŸã£ãç¥èãåŸãããã®ã§ç޹ä»ããŸããååã®ç¶ããã®ã§ãBatchGetItem ã®æžãæ¹ã玹ä»ããŸãã æ¬èšäºã§ã¯ãVTL ã®æžãæ¹ã«ãã©ãŒã«ã¹ããŠããŸãããäºæ¿ãã ããã AWS AppSyncããªãŸã«ããVTL ã®èª¬æã«ã€ããŠã¯ä»¥äžã®èšäºãã芧äžããã AWS AppSync ãªãŸã«ã (VTL) ã®æžãæ¹ãµã³ãã« No.1 - Amazon DynamoDB GetItem Amazon DynamoDB ã« VTL ã§ GetItem ãããããšãã®åºæ¬çãªæžãæ¹ã玹ä»ããŸãã blog.usize-tech.com 2024.01.09 AWS AppSync ã䜿ã£ãŠ React ã¢ããªããããã¯ããéåæãžã§ãã®çµæãããã·ã¥éç¥ã§åãåã éåæãžã§ããå®è¡ããåŸãçµæãã©ãåãåããïŒãšããã®ã¯éçºè
ãšããŠäœã蟌ã¿ç²æã®ããããŒãã§ããä»å㯠React ã¢ããªãéåæãžã§ããå®è¡ããåŸã«ãAWS AppSync çµç±ã§ãžã§ãå®äºã®ããã·ã¥éç¥ãåãåãä»çµã¿ã玹ä»ããŸãã blog.usize-tech.com 2022.12.01 Amazon DynamoDB ã« BatchGetItem ãã VTL äŸãã°ãAWS AppSync ãã以äžã®ãªã¯ãšã¹ããåãããšããŸããAmazon DynamoDB ã«ã¯é©åãªããŒã¿ãããæ³å®ã§ããããŒãã«åã¯ãªãŸã«ãã®å¥ã®èšå® (Data Source) ã§è¡ããŸãã åŒæ°ãšãªããã©ã¡ãŒã¿ïŒãããŒãã£ã·ã§ã³ã㌠pkeyããœãŒãã㌠skey å¿
èŠãªã¬ã¹ãã³ã¹ïŒãdata1, data2 ãšãã屿§ã®å€ããã ãäºã決ãŸã£ãã«ãŒã«ã§2ã¢ã€ãã åã®ããŒã¿ãå¿
èŠ ä»åã¯åãåã£ã1ã€ã®ãœãŒãããŒãã©ã¡ãŒã¿ãå å·¥ããŠã2çš®é¡ã®ãœãŒãããŒã VTL ã§äœæããŸãã ãã¡ããæåããåŒæ°ãšããŠ2ã€ã®ãœãŒãããŒãæž¡ãããšãã§ããŸãããããŒãã£ã·ã§ã³ããŒãå€ããŠãããã§ãããããã«ããŠããåãããŒãã«ã«å¯ŸããŠè€æ°ã® GetItem ã 1åã®ã¯ãšãªã§ååŸããããšãã«äŸ¿å©ã§ããã€ã¢ããªã«çµæãæ»ããšãã«è€æ°ã®ã¯ãšãªçµæãèåããŠè¿ãããšãå¯èœã§ãã ãããã³ã°ãã³ãã¬ãŒã㯠JSON 圢åŒã§èšè¿°ããŸãããã®äžã« VTL ãæ··åšããæãã§ãã ãªã¯ãšã¹ããããã³ã°ãã³ãã¬ãŒã #set($skey1 = "skey1#"+$context.arguments.skey) #set($skey2 = "skey2#"+$context.arguments.skey) { "version": "2018-05-29", "operation": "BatchGetItem", "tables": { "DynamoDBTableName": { "keys": [ { "pkey": $util.dynamodb.toDynamoDBJson($context.arguments.pkey), "skey": $util.dynamodb.toDynamoDBJson($skey1) }, { "pkey": $util.dynamodb.toDynamoDBJson($context.arguments.pkey), "skey": $util.dynamodb.toDynamoDBJson($skey2) } ] } } } operation ã«ã¯ãBatchGetItem ãæžããŸãããã㯠Amazon DynamoDB ã« BatchGetItem ããããããšããææè¡šç€ºã§ãã DynamDB ããŒãã«åãå
¥ããå¿
èŠããããŸããDynamoDBTableName ã®éšåã¯ãå®éã«ã¯ãšãªããããããŒãã«åã«æžãæããŸãã ã¢ããªããåãåã£ãåŒæ°ã¯ãããã³ã°ãã³ãã¬ãŒãå
ã§ã¯ $context.arguments å
ã«æ ŒçŽãããŸããkeys ã«åãåã£ãåŒæ°ãåã蟌ã¿ããã®ã§ãããããã§ã¯ãpkey ã¯ãã®ãŸãŸãskey ã«å¯ŸããŠãã³ãã¬ãŒãåé ã§ #set() ã§å€ã2çš®é¡ã«å å·¥ããŠããŸãã倿°å㯠$skey1, $skey2 ã«ããŠããŸããå å·¥åŸã®å€æ°ã BatchGetItem ã®ãœãŒãããŒã®åŒæ°ãšããŠæå®ããŠãããšæã£ãŠäžããã ããã§ Amazon DynamoDB ã« GetItem ããããããšãã§ããŸãã ã¬ã¹ãã³ã¹ãããã³ã°ãã³ãã¬ãŒã 2ã€ã® GetItem ãè¡ãããçµæã¯å®è¡é ã«é
åã«æ ŒçŽãããŸããå€ãåãåºããŠãä»»æã® JSON ããŒã¿æ§é ã«ããŠè¿ãããšã«ãªããŸãã $util.toJson({ "skey1data1": $context.result.data.DynamoDBTableName[0].data1 "skey1data2": $context.result.data.DynamoDBTableName[0].data2 "skey2data1": $context.result.data.DynamoDBTableName[1].data1 "skey2data2": $context.result.data.DynamoDBTableName[1].data2 }) VTL ã«é¢ããŠã¯ä»¥äžã® AWS å
¬åŒããã¥ã¡ã³ããå¿
èŠã«å¿ããŠã確èªãã ããã Resolver mapping template reference for DynamoDB - AWS AppSync Resolver Mapping Template Reference for DynamoDB for AWS AppSync. docs.aws.amazon.com ãŸãšã ãããã§ããã§ããããã BatchGetItem ã®äœ¿ãæ¹ã¯ä»ã«ããããšæããŸãããä»åã¯åçŽã«2ã€ã®GetItemããã¿ã«æžãæ¹æ³ã玹ä»ããããŸããã Amazon DynamoDB ãžã® BatchGetItem ãå¿
èŠãšãªãå±é¢ã¯ãããšæããŸããæ¯éãäœãã§ãããæŒãããŠãããŠãå¿
èŠã«ãªã£ããšãã®åŒãåºããšããŠæã£ãŠãããŠé ããããšæããŸãã æ¬èšäºãçæ§ã®ã圹ã«ç«ãŠãã°å¹žãã§ãã
ããã«ã¡ã¯ãèªç§°ãããã¯ãŒã¯æè¡è
ã®è²å¡ã§ããSCSKã§AWSã®å
è£œåæ¯æŽã ãã¯ãã«ã«ãšã¹ã³ãŒããµãŒãã¹ ããæ
åœããŠããŸãã å€ãã®AWSãµãŒãã¹ã䜿ãäžã§ããã°ç®¡çãç£èŠã»éç¥ã¯æ¬ ãããŸããããéåžžãããã®æ©èœãç®çã®ãµãŒãã¹èªèº«ãæã£ãŠããããšã¯ãªããã©ãããŠãä»ãµãŒãã¹(äŸãã°CloudWatch)ãšã®é£æºãåºãŠããŠããŸããŸããããã飿ºãã¿ãŒã³ã1ãã¿ãŒã³ã§ã¯ãªããéçšäžã®èŠä»¶ã»å¶çŽãªã©ã«ãã£ãŠè€æ°ã®é£æºãã¿ãŒã³ãèããããã®ã§ããã®éšåãèšèšããã ãã§ãäžèŠåŽãªã®ã§ã¯ãªãã§ããããã æ¬èšäºå·çã®åæ© ä»åã¯ãAWSã®ãããã¯ãŒã¯ç³»ãµãŒãã¹(ã®äžã§ç§ã«ãªãã¿ã®ãããã®)ãã©ãã«ãã°ãåºåã§ããŠãã©ã®ããã«ç£èŠãéç¥ãã§ããŠããã°ã®åæãã©ãããã°ããã®ããèªåã®äžã§æŽçããããšèããã®ãæ¬èšäºã®å·çåæ©ã§ãã å
è¡ããèšäºãšããŠä»¥äžã®èšäºããããŸããæ¬çš¿ã®å·çã«ããã£ãŠãåèã«ãããŠé ããŸããã AWSã«ããããã°ã®åºåå
ãå¯èŠåãç£èŠã®ãŸãšã - Qiita ã¯ããã«AWSã«ãããäž»èŠãµãŒãã¹ã®ãã°ã®åºåå
ããŸãšããŠãããŸãããã°ã®çš®é¡ãšåºåå
ãã°ãšåºåå
ãS3ã«é¢ããŠã¯å¯Ÿå¿ããæå·åæ¹åŒãèšèŒããŸããS3ã®å Žåããã±ããããªã·ãŒãKMSãå©çšã⊠qiita.com ç§ããã®èšäºãæžãå¿
èŠã¯ãªãã®ã§ã¯âŠâŠãšæãããããããŸãšãŸã£ãŠããã®ã§ããã以äžã®ã¢ãããŒã·ã§ã³ã®ããèªåã§ãèšäºãšããŠãŸãšããããšã«ããŸããã ãããã¯ãŒã¯ç³»ãµãŒãã¹(Transit Gateway, Network Firewall)ã®æ
å ±ãå
å®ããããã£ã éç¥ãŸã§å«ããŠæç€ºãããã£ã ãªãã·ã¹ãã ãç£èŠããã«ããã£ãŠã¯ãåãµãŒãã¹ã®åºåããã¡ããªã¯ã¹(ããã©ãŒãã³ã¹çã«é¢ããå®éçãªæç³»åããŒã¿)ãåãµãŒãã¹ãçºçãããã€ãã³ã(ããšãã°EC2ã®åæ¢)ãéèŠãªæ
å ±ã«ãªããŸãããæ¬çš¿ã§ã¯ãããŠãã°ã®åãæ±ãã®ã¿ãã¿ãŒã²ããã«ããŠããŸãã ãããã¯ãŒã¯ç³»ãµãŒãã¹ã®ãã®ã³ã°ã»ç£èŠã»éç¥ã»åæ ãŸãã¯äžæã®å³ã«ãŸãšããŠã¿ãŸããã®ã§ãã¡ããã芧ãã ããã(æåãå°ããã®ã§æ¡å€§ããŠèŠãããšããå§ãããŸã) å·ŠåŽã«äž»ãªãããã¯ãŒã¯ç³»ãµãŒãã¹ã䞊ã¹ããããã©ã®ãµãŒãã¹ã«ãã°ãåºåã§ããã®ããç¢å°ã§çµãã§ããŸããããã«ãã®ãã°åºåå
ããã©ã®ãµãŒãã¹ã«é£æºãããšç£èŠã»éç¥ã»åæã«ã€ãªããããã®ããç¢å°ã§ç€ºããŸããã GuardDutyã¯éåžžãããã¯ãŒã¯ç³»ãµãŒãã¹ã«åé¡ãããŸãããããããã¯ãŒã¯ç³»ã®ãã°(VPCãããŒãã°ãRoute 53ã¯ãšãªãã°)ãã€ã³ãããã«ããŠè
åšæ€åºãããŠãããããããããŠãã®å³ã«å«ããŠããŸãã ãã°åºåå
åºåå
åè£ã®éžæè¢ã¯åºæ¬çã«3ã€ãCloudWatch LogsãS3ãKinesis Firehoseã§ãããã®3ã€ã®ããããããéžæå¯èœãªãµãŒãã¹ãå€ãã§ãããäžã«ã¯ããã§ã¯ãªããµãŒãã¹ããããŸãã CloudWatch Logs CloudWatch Logsã«åºåããŠããã°ããã®åŸã®ç£èŠã»éç¥ãåæãããããã§ããã ãã°ã®åã蟌ã¿ãåæã§æéãé«é¡ã«ãªãããšããã ããã§ãã ä»å調æ»å¯Ÿè±¡ã«ãããµãŒãã¹ã®å€ãã¯CloudWatch Logsãžã®ãã°åºåã«å¯Ÿå¿ããŠãããRoute 53ã«ã€ããŠã¯CloudWatch Logsã®ã¿ãšãªã£ãŠããŸã S3 S3ã¯ãã°ã®ä¿ç®¡ã ãã«éãã°ããããæé©ã§ãããç£èŠã»éç¥ãåæãããããšãããšã²ãšæéããããŸãã ALBãCloudFrontã¯ãS3ã®ã¿ã®åºåãšãªã£ãŠããŸãã ãŸããä»åãããŠå¯Ÿè±¡ç¯å²ã«ããGuardDutyã§æ€åºããè
åšã¯ãGuardDutyèªäœã決ãŸã£ãä»¶æ°ã®æ€åºçµæãä¿æããŠãããŸãããé·æéä¿ç®¡ããã®ã§ããã°S3ãžã®åºåãšãªããŸãã Kinesis Firehose Kinesis Firehoseã¯ãªã¢ã«ã¿ã€ã ã®åæãETLãå¿
èŠãªå Žåã®åºåå
ã§ããã¹ããªãŒãã³ã°ããŒã¿ããªã¢ã«ã¿ã€ã ã§é
ä¿¡ããããã®ãµãŒãã¹ã§ãããFirehoseèªäœã¯ãã°ã®ã¹ãã¬ãŒãžã§ã¯ãããŸãããå
·äœçãªãã°æŽ»çšã®ãŠãŒã¹ã±ãŒã¹ããã£ãäžã§ã®éžæè¢ãšèšããŸãã ãŸãšã ãã®ã³ã°ã»ç£èŠã»éç¥ã»åæãšéæã¡ãŸãããããã®èšäºã§ã¯èª¬æã¯ãã®ã³ã°ã®éšåãŸã§ã«ãšã©ãã以éã®èª¬æã¯å¥èšäºãšããŠãŸãšããããšã«ããŸãããïŒãã£ã¡ãæžãããšãããšèª¿æ»ãæ€èšŒãããªã倧å€ãšæ°ã¥ããã®ã§âŠâŠ) ãããããã°ç¶ç·šããåŸ
ã¡ãã ãããŸãã åèè³æ CloudWatchã®æéã«é¢ããAWSã®èšäºã§ãã CloudWatch ã®æéãææ¡ããä»åŸã®æéãæãã AWS ã®è«æ±æžã«èšèŒãããŠãã Amazon CloudWatch ã®æéãé«é¡ã§ãããCloudWatch ã®äœ¿çšç¶æ³ãææ¡ããä»åŸã®æéãæããããšèããŠããŸãã repost.aws
ããã«ã¡ã¯ãåºéã§ãã 以åã以äžã®èšäºã§ AWS AppSync ã« Mutation ãããã AWS Lambda 颿°ã³ãŒãã以äžã®èšäºå
ã§ç޹ä»ããŠããã®ã§ãããNode.js ã§æžãããã®ã§ãããå
æ¥ Node.js 16 ã EoL ã«ãªã£ãããšãåããŠãAWS Lambda 颿°ã Python 3.12 ã§æžãæããã®ã§æžãæ®ããŠãããŸãã AWS AppSync ã䜿ã£ãŠ React ã¢ããªããããã¯ããéåæãžã§ãã®çµæãããã·ã¥éç¥ã§åãåã éåæãžã§ããå®è¡ããåŸãçµæãã©ãåãåããïŒãšããã®ã¯éçºè
ãšããŠäœã蟌ã¿ç²æã®ããããŒãã§ããä»å㯠React ã¢ããªãéåæãžã§ããå®è¡ããåŸã«ãAWS AppSync çµç±ã§ãžã§ãå®äºã®ããã·ã¥éç¥ãåãåãä»çµã¿ã玹ä»ããŸãã blog.usize-tech.com 2022.12.01 AWS Lambda 颿°ã³ãŒã å眮ããªãã§ãããªãã³ãŒã玹ä»ã«å
¥ããŸãã mutation ã§æž¡ãå€ã¯æ¶ç©ºã®ãã®ã§ãã import boto3 import json import requests from requests_aws_sign import AWSV4Sign session = boto3.session.Session() credentials = session.get_credentials() auth = AWSV4Sign(credentials, 'ap-northeast-1', 'appsync') #AppSyncããããã€ãããŠãããªãŒãžã§ã³ãæå® def lambda_handler(event, context): try: endpoint = 'AppSyncEndpointUrl' #AppSyncã®URLãæå® headers = {'Content-Type': 'application/json'} query = """ mutation updateJobstatus( $serviceiduser: String!, $datetime: String!, $url1: String, $url2: String, $status: String ) { updateJobstatus(input: { serviceiduser: $serviceiduser, datetime: $datetime, url1: $url1, url2: $url2, status: $status }) { serviceiduser } } """ variables = { 'serviceiduser': 'xxxxxxxx', 'datetime': 'xxxxxxxx', 'url1': 'xxxxxxxx', 'url2': 'xxxxxxxx', 'status': 'xxxxxxxx' } payload = {'query': query, 'variables': variables} result = requests.post(endpoint, auth=auth, json=payload, headers=headers).json() if 'errors' in result: print(result['errors']) except Exception as error: print(error) result = {'errors': [{'message': str(error)}]} AWS AppSync ã¯åãã Mutation ãå®è¡ããŠããã®ãã©ãããå®è¡å
(AWS Lambda 颿°) ããéãããŠãã IAM æ
å ±ãšç
§åããŸãããã®ãããéä¿¡æã« Signature V4 ãšããä»çµã¿ã䜿çšããŠæ
å ±ã眲ååãããªã¯ãšã¹ãã®ããããŒã«å
¥ããåŠçãå¿
èŠã«ãªããŸãã 以äžãåæäºé
ã§ãã AWS Lambda 颿°ã«ãappsync:GraphQL ãå®è¡ã§ãã IAM ããŒã«ãé¢é£ä»ããŠããããšã AWS AppSync ã®ã¹ããŒãèšå®ã§ã該åœãã Mutation ã®èšå®ã« IAM ã§ã¢ã¯ã»ã¹å¯èœãªèšè¿°ãããŠããããšã import ããŠãã requests ã¢ãžã¥ãŒã«ã¯ã©ããŒãã«ã® AWS Lambda 颿°ã§ã¯ import ã§ããªãã®ã§ãrequests ã® Lambda ã¬ã€ã€ãŒãäœæããŠããããšãrequests ãã€ã³ã¹ããŒã«ããŠãåæã«ã€ã³ã¹ããŒã«ãããã¢ãžã¥ãŒã«ãšã»ããã§ ZIP ã§åºããŸãã Lambda ã¬ã€ã€ãŒã®äœææ¹æ³ã¯ä»¥äžã®èšäºãåèã«ããŠãã ããã AWS Lambda (Python 3.12) ã§äœ¿çšå¯èœãª pandas ã® Lambda Layer ãæºåãã ããŒã¿åæãå å·¥ã§ãã䜿ãããã©ã€ãã©ãªã«ãpandas ããããšæããŸããæ¬èšäºã§ã¯ãAWS Lambda (Python 3.12) ã§åäœãã pandas ã® Lambda Layer ãæºåããæé ã玹ä»ããŸãã blog.usize-tech.com 2022.06.07 詳现㪠AWS AppSync é¢é£èšå®æ
å ±ã¯ãç¹°ãè¿ãã«ãªããŸãã以äžã®åèèšäºãã芧äžããã AWS AppSync ã䜿ã£ãŠ React ã¢ããªããããã¯ããéåæãžã§ãã®çµæãããã·ã¥éç¥ã§åãåã éåæãžã§ããå®è¡ããåŸãçµæãã©ãåãåããïŒãšããã®ã¯éçºè
ãšããŠäœã蟌ã¿ç²æã®ããããŒãã§ããä»å㯠React ã¢ããªãéåæãžã§ããå®è¡ããåŸã«ãAWS AppSync çµç±ã§ãžã§ãå®äºã®ããã·ã¥éç¥ãåãåãä»çµã¿ã玹ä»ããŸãã blog.usize-tech.com 2022.12.01 ãŸãšã ãããã§ããã§ããããã AWS AppSync ã䜿çšããŠããã¢ããªã§ã¢ããªå€ããç»é¢æŽæ°ãããããšãã«ã¯ AWS Lambda 颿°ããã® Mutation ãå¿
èŠãšãªãã±ãŒã¹ãå€ããšæããŸãã æ¬èšäºãçæ§ã®ã圹ã«ç«ãŠãã°å¹žãã§ãã
ããã«ã¡ã¯ãSCSKã®æ±æšã§ãã Google Cloud Generative AI Summit Osakaã§ã玹ä»ãããŠãããBigQuery MLã®ML.GENERATE_TEXT颿°ã䜿ã£ãŠãããã¹ãã®ããŒã¿ã»ãããèŠçŽããŠã¿ãã®ã§ãå®è£
æ¹æ³ã玹ä»ããŸãã Google Cloud Generative AI Summit Osakaã§ã®è©³ããå
容ã¯éå»ã®èšäºãã確èªããã ããŸããšå¹žãã§ãã Google Cloud Generative AI Summit Osakaã«åå ããŠã¿ãïŒ Google Cloud Generative AI Summit Osakaã«åå ããã®ã§ãã€ãã³ãã®å
å®¹ãšææ³ãæçš¿ããŸãã2023幎12æ14æ¥ã«å€§éªã®ã³ã³ã°ã¬ã³ã³ãã³ã·ã§ã³ã»ã³ã¿ãŒã§éå¬ãããã«ã³ãã¡ã¬ã³ã¹ã€ãã³ãã§ãã blog.usize-tech.com 2023.12.20 BigQuery MLãšã¯ïŒ BigQuery MLãšã¯ãGoogle Cloudã®æ©æ¢°åŠç¿ãµãŒãã¹ã§ãBigQueryäžã§æ©æ¢°åŠç¿ã¢ãã«ãäœæãè©äŸ¡ãå®è¡ããããšãã§ããŸããBigQuery MLãå©çšããããšã§ãæ©æ¢°åŠç¿ã®å°éç¥èããªããŠããBigQueryã§èç©ãããããŒã¿ããæ©æ¢°åŠç¿ã¢ãã«ãäœæããããšãã§ããŸãã ãã詳ããå
容ã¯å
¬åŒããã¥ã¡ã³ããåç
§ãã ãã BigQuery ML ãšã¯  | Google Cloud cloud.google.com å®è£
æç« ããŒã¿ã®æºå ããŒã¿ãCSVãã¡ã€ã«ã«å€æ json圢åŒã® èŠçŽçšã®ããŒã¿ã»ãã ãçšããŸãããcsvãã¡ã€ã«ãšããŠæ±ãããã£ãã®ã§ã以äžã®ããã°ã©ã ãçšããŠãããã¹ãéšåãæœåºããdataset.csvãã¡ã€ã«ãäœæããŸãã import pandas as pd import json from pandas.io.json import json_normalize #倿ãããJSONãã¡ã€ã«ãèªã¿èŸŒã df = pd.read_json('./japanese_test.jsonl',orient='records', lines=True) # read_jsonããçµæã ãšãã¹ãããjsonãå±éã§ããªãã®ã§normalizeã§å±éããã df_json = df['text'].iloc[:20] #csvãã¡ã€ã«ã§åºå df_json.to_csv("dataset.csv", encoding='utf-8') Cloud Storageã«ã¢ããããŒã ãã±ãŒã·ã§ã³ãã¹ãã¬ãŒãžã¯ã©ã¹ãæå®ããCloud Storageã®ãã±ãããäœæããŸãã ãã±ããã«dataset.csvãã¢ããããŒãããŸãã æç« ããŒã¿ãBigQueryãžã€ã³ããŒã ããŒã¿ã»ããã®äœæ BigQueryã«ããã¹ãããŒã¿ãã€ã³ããŒãããããã«ããŒã¿ã»ãããäœæããŸãã BigQuery Studioã®ãšã¯ã¹ãããŒã©ã§ãããžã§ã¯ãã®å³åŽã«ãã[ïž]â[ããŒã¿ã»ãããäœæ]ãéžæããŸã ããŒã¿ã»ããIDãšãªãŒãžã§ã³ãæå®ããŠãããŒã¿ã»ãããäœæããŸãã ããŒãã«ã®äœæ ããŒã¿ãã€ã³ããŒãããããã®ããŒãã«ãããŒã¿ã»ããã®äžã«äœæããŸãã äœæããããŒã¿ã»ããã®å³åŽã«ãã[ïž]â[ããŒãã«ãäœæ]ãéžæããŸã ããŒãã«ã®äœæå
ã«ã¯Google Cloud StorageãéžæããŸããdataset.csvãã¡ã€ã«ãéžæãããããžã§ã¯ããããŒã¿ã»ããããã³ããŒãã«ãæå®ããèšå®ãè¡ããŸãã äœæããããŒã¿ã»ããããã¬ãã¥ãŒãããšä»¥äžã®éãã§ãã äœèšãªè¡ãšåãã§ããŠããŸã£ãã®ã§ãããŒã¿ã»ãããæŽåœ¢ããŸãããŸããããŒã¿ã®æ°ãå€ãããã®ã§ãããŒã¿ã®æ°ã調æŽããŸãã以äžã®ã¯ãšãªã§æŽåœ¢ãã€ã€ãå
é ãã20åã®ããŒã¿ã®ããŒãã«ãäœæããŸãã SELECT string_field_1 FROM `ãããžã§ã¯ãå.ããŒã¿ã»ããå.ããŒãã«å` LIMIT 20 OFFSET 1 äžèšã®ã¯ãšãªãå®è¡ããããã«ã¯ãšãªäœæç»é¢ãéããŸãããšã¯ã¹ãããŒã©ã«ãã[ïŒ]ãæŒäžããŸãã å
ã»ã©ã®ã¯ãšãªãå
¥åãã[å®è¡]ãæŒäžããããŒã¿æŽåœ¢ãè¡ããŸãã æŽåœ¢ããããŒã¿ãããŒãã«ã«ä¿åããŸãã[ã¯ãšãªçµæ]â[çµæãä¿å]â[BigQueryããŒãã«]ãéžæããŸãã ããŒã¿ã»ãããéžæããããŒãã«åãå
¥åããåŸã[ãšã¯ã¹ããŒã]ãéžæããŸãã æŽåœ¢ããçµæãåºåããããŒãã«ã以äžã®éãã§ãã ããã§ããŒã¿ã®æºåãã§ããŸããããã®ããŒã¿ã«å¯ŸããŠãML.GENERATE_TEXT颿°ã䜿ã£ãŠèŠçŽããŠãããŸãã ML.GENERATE_TEXT颿°ã䜿ãããã®æºå APIã®æå¹å Google Cloudã³ã³ãœãŒã«ããBigQuery API,BigQuery Connection API,Vertex AI APIãæå¹ã«ããŸãã ã³ã³ãœãŒã«ã®[APIãšãµãŒãã¹]â[æå¹ãªAPIãšãµãŒãã¹]â[APIãšãµãŒãã¹ã®æå¹å]ãéžæããŸãã APIã©ã€ãã©ãªãéãã®ã§ãðã®æ€çŽ¢æ¬ã§æå¹ã«ããAPIã®æ€çŽ¢ãè¡ããŸãã æ€çŽ¢äžèЧããæå¹ã«ããAPIãéžæããããšã§ã以äžã®ãããªç»é¢ïŒå³ã¯BigQuery APIã®å ŽåïŒã«é·ç§»ããã®ã§ã[æå¹ã«ãã]ãéžæããŸãã æ¥ç¶ã®äœæ CloudãªãœãŒã¹æ¥ç¶ãäœæãããµãŒãã¹ã¢ã«ãŠã³ããååŸããŸãã BigQueryã³ã³ãœãŒã«ã®ãšã¯ã¹ãããŒã©ã®å³åŽã«ãã[ïž]â[+远å ]ãéžæããŸãã [äžè¬çãªãœãŒã¹]â[å€éšããŒã¿ãœãŒã¹ãžã®æ¥ç¶]ãéžæããŸãã æ¥ç¶IDãæ±ºããæ¥ç¶ã¿ã€ãããªãŒãžã§ã³ãèšå®ãã[æ¥ç¶ãäœæ]ãéžæããŸãã æ¥ç¶æ
å ±ã確èªããããããšã¯ã¹ãããŒã©ã®[å€éšæ¥ç¶]ããäœæããæ¥ç¶ãéžæããŸãã æ¥ç¶ã®ãµãŒãã¹ã¢ã«ãŠã³ãã確èªããã³ããŒããŠãããŸãã ãµãŒãã¹ã¢ã«ãŠã³ãã«Vertex AIãžã®ã¢ã¯ã»ã¹æš©ãä»äž å
ã»ã©ã³ããŒãããµãŒãã¹ã¢ã«ãŠã³ãã«Vertex AIãŠãŒã¶ããŒã«ãä»äžããŸãã ã³ã³ãœãŒã«ã®[IAMãšç®¡ç]â[IAM]â[æš©é]â[ã¢ã¯ã»ã¹æš©ãä»äž]ãéžæããŸãã æ°ããããªã³ã·ãã«ã«å
ã»ã©ã³ããŒãããµãŒãã¹ã¢ã«ãŠã³ããå
¥åãããŒã«ã«Vertex AI ãŠãŒã¶ãŒãéžæãã[ä¿å]ãæŒäžããŸãã ã¢ãã«ã®äœæ 以äžã®ã¯ãšãªãå®è¡ããããšã§ãèŠçŽæç« ãçæããããã®ã¢ãã«ãäœæããŸãã CREATE OR REPLACE MODEL `ãããžã§ã¯ãå.ããŒã¿ã»ããå.llm_model` REMOTE WITH CONNECTION `ãããžã§ã¯ãå.æ¥ç¶ã®ãã±ãŒã·ã§ã³.æ¥ç¶å` OPTIONS (REMOTE_SERVICE_TYPE = 'CLOUD_AI_LARGE_LANGUAGE_MODEL_V1'); ãšã¯ã¹ãããŒã©ã§äœæããããŒã¿ã»ããã®äžã«ã¢ãã«ãåºæ¥ãŠããããšã確èªã§ããŸãã ããã§æºåã¯å®äºã§ãã ML.GENERATE_TEXT颿°ã䜿ã£ãŠæç« ããŒã¿ãèŠçŽ ML.GENERATE_TEXT颿°ã䜿ã£ãèŠçŽã¯ãšãªã¯ä»¥äžã®éãã§ãã SELECT * FROM ML.GENERATE_TEXT( MODEL `ããŒã¿ã»ããå.llm_model`, ( SELECT CONCAT('æç« ãèŠçŽããŠãã ããã', string_field_1) AS prompt FROM `ããŒã¿ã»ããå.æŽåœ¢åŸã®ããŒãã«å` ), STRUCT( 0.2 AS temperature, 650 AS max_output_tokens, 0.2 AS top_p, 15 AS top_k, TRUE AS flatten_json_output)); ä»åã¯èŠçŽããããã®ã§ãäžèšã¯ãšãªã®6è¡ç®ã®CONCATå
ã®ç¬¬äžåŒæ°ãã’æç« ãèŠçŽããŠãã ããã’ããšããŠããŸããæç« ã®ã¿ã€ãã«ãã€ãããå Žåã¯ã’æç« ã®ã¿ã€ãã«ãã€ããŠãã ããã’ããšããŸããïŒããããããã³ãããšã³ãžãã¢ãªã³ã°ã§ããïŒ STURCT以äžã¯ã¢ãã«ã®ãã©ã¡ãŒã¿ã§ãã詳ããèšå®ã¯å
¬åŒããã¥ã¡ã³ããåç
§ãã ããã ML.GENERATE_TEXT 颿°  | BigQuery  | Google Cloud cloud.google.com èŠçŽçµæã¯ä»¥äžã®éãã§ããml_generate_text_llm_resultåãèŠçŽçµæã衚ããŠããŸãã ããŒã¿ã®å
é 3ã€ã®å
ã®æç« ãšèŠçŽçµæã衚ã«ããŠã¿ãŸããã å
ã®æç« èŠçŽçµæ ãã ã»ãšããžã³ãã³ BBCãªã¢ãªãã£ãŒã»ãã§ãã¯ïŒãã¡ã¯ããã§ãã¯ïŒããŒã ãã€ãŠåŽåå
å
éŠãåãããã¬ã¢æ°ã¯ãBBCã©ãžãª4ã®çªçµãTodayãã§ããè°äŒã¯è¡ãè©°ãŸã£ããè°äŒã決ããããªããªããåœæ°ã決ããåœ¢ã«æ»ããããšèªã£ãã åŽåå
ã®å
¬åŒãªç«å Žã¯ãããªãŒã¶ã»ã¡ã€è±éŠçžã欧å·é£åïŒEUïŒãšåæããé¢è±å宿¡ãè°äŒã§åŠæ±ºãããå Žåãè§£æ£ç·éžæã®å§åãããããšãããã®ãããç·éžæãå®çŸããªãã£ãå Žåã¯ãå床ã®åœæ°æç¥šãæ¯æããã®ãéžæè¢ã«ãªããããšãåŽåå
ã¯è¡šæããŠããã ãããã¡ã€éŠçžã¯ãååœæ°æç¥šã®äºæž¬ãåŠå®ããŠãããã¡ã€æ°ã¯äžé¢è°å¡ãã«å¯Ÿãã2016幎ã«å®æœããåœæ°æç¥šã®çµæããå°éãããã¹ãã ããšç¹°ãè¿ãèªã£ãŠããã ã ãããããã¬ã¢æ°ãæ±ããŠããéããäžé¢ããã¬ã°ãžããããããè çïŒããã¡ããïŒç¶æ
ãæã¡ç Žãããã«2床ç®ã®åœæ°æç¥šã宿œãããšæ±ºå®ããããã©ããªãã®ã ãããïŒ è±éžæç®¡çå§å¡äŒã¯BBCãã¥ãŒã¹ã«å¯Ÿãããé©åãªå¯Ÿå¿çããæããŠããããããããäºå®å€ã®æç¥šã«è¿
éã«å¯Ÿå¿ãããæºåãã§ããŠãããšèªã£ãã æéã¯è¿«ã£ãŠãã ã€ã®ãªã¹ã®EUé¢è±äºå®æ¥ã¯ã2019幎3æ29æ¥ãæ®ã100æ¥ãåããæéãæãå·®ãè¿«ã£ãåé¡ã ã è±è°äŒã2床ç®ã®åœæ°æç¥šå®æœãæ¡æããå Žåãæç¥šèŠåãéžæéåèŠåãå®ããæ³åŸã«ãäžäžäž¡é¢ã®æ¯æãå¿
èŠã«ãªãã 2016幎ã®åœæ°æç¥šã§ã¯ãæç¥šæ¥ã®7ã«æåã«é¢é£æ³æ¡ãè°æ±ºãããã ããããä»åã¯ãã£ãšæ©ãæ³å¶åãå¯èœãªã®ã ãããïŒ æ³å¶åã®é床ãäžãããããååã®åœæ°æç¥šã«é¢ãã諞èŠåãå®ãã2015å¹Žåœæ°æç¥šæ³ãã²ãªåã«ããå®è³ªçã«å€§éšåãåããŠããŸãã®ããããåŸãéžæè¢ã®1ã€ã ã è±ãŠããŽã¡ãŒã·ãã£ãŒã»ã³ã¬ããžã»ãã³ãã³å
Œ
±æ¿ç倧åŠé¢æ²æ³ãŠãããã®ã¢ã©ã³ã»ã¬ã³ãŠã£ãã¯å¯ãŠãããé·ã¯ããçè«äžããã®ããæ¹ã¯éåžžã«çŽ æ©ãå®äºã§ããããšè©±ãã ãããã®ããæ¹ãæ¡çšãããŠããæ³æ¡ã®è°äŒééã¯ããã11é±éããããšã¬ã³ãŠã£ãã¯æ°ã¯æšèšããŠããã ãã®äºå®è¡šãåºã«ãããšãæ³æ¡ééã¯2æåŸåã«ãªããšäºæ³ãããããã ããæ³å¶éçšãä»éå§ããã°ã®è©±ã ã æç¥šçšçŽã®éžæè¢ãã2016幎ã®åœæ°æç¥šã«ããããé¢è±ãããæ®çããã®2æã§ã¯ãªãããè€æ°ã®éžæè¢ãå«ããããäžé¢ãèŠæ±ããå Žåããããæéã¯ãã£ãšãã£ãšé·ããªããšãã¬ã³ãŠã£ãã¯æ°ã¯ä»ãå ããã 2016幎ã®åœæ°æç¥šã§EUæ®ç掟ãšããŠæŽ»åãããããŒã»ãã¬ã¢å
éŠçžã¯ã2床ç®ã®åœæ°æç¥šãè°äŒã®è çç¶æ
ãè§£æ¶ããå¯èœæ§ããããšäž»åŒµãã äœãåãã®ã ããåŸãéžæè¢ã®ç¯å²ããã©ããªè³ªåãéžã¶ãã¯ãæçµçã«ã¯è±è°äŒã®æ±ºå®ã«å§ããããã é¢è±åå®ã®æçµåæã«åœæ°æç¥šãæ±ãããPeople’s Vote ïŒäººæ°ã®æç¥šïŒãéåã®èŠè§£ã§ã¯ãããªãŒã¶ã»ã¡ã€éŠçžã®é¢è±åå®ãšEUæ®çã®ã©ã¡ãããéžã¶ã®ãæšå¥šãããéžæè¢ã ããæç¥šåå è
ã«3ã€ã®éžæè¢ããéžã°ããå¯èœæ§ãé€å€ããªããšããã åã³åœæ°æç¥šã宿œããããªããæç¥šçšçŽã«ãæ®çãã®éžæè¢ã¯ããã¹ãã§ãªããã¡ã€éŠçžã®é¢è±åå®ããåæãªãã§ã®EUé¢è±ãã®äºè
æäžã§ããã¹ããšã®äž»åŒµãããã ä»ã®éžæè¢ãããããã€ãŽã£ããã»ãã£ã¡ãã³å
é£ã§é茞çžãåœééçºçžãã¡ã€å
é£ã§æè²çžã女æ§ã»å¹³çæ
åœçžãæŽä»»ãã2床ç®ã®åœæ°æç¥šãæ¯æããŠãããžã£ã¹ãã£ãŒã³ã»ã°ãªãŒãã³ã°æ°ã¯ä»¥åã3ã€ã®éžæè¢ãæ±ããââã è€æ°ã®éžæè¢ãããå Žåãäžé¢ã¯ã©ããªæç¥šå¶åºŠã䜿ãããæ±ºå®ããå¿
èŠããããããšãã°ãéžæè¢ã1ã€éžã¶ã®ããæãŸããã»ãããé çªãã€ããã®ãããšããããã«ã éžæç®¡çå§å¡äŒã¯ãææ¡ããã質åã詊éšãããããããæçœã«ãåçŽã«ããããŠäžç«ã«ã瀺ãããŠãããšç¢ºèªããå¿
èŠãããã éžæéåãè¡ãå
¬èªå£äœã®éžå®ãå¿
èŠã ã éžæç®¡çå§å¡äŒã¯ãããããåœæ°æç¥šã®åå æ¹æ³ãææš©è
ã«æ
å ±æäŸããå¿
èŠãããããŸããå
šåœã§é祚æ
åœè
ã®ç¢ºä¿ãå¿
èŠã ã ãããã®æºåãçµãããšãéžæéåæéãå§ãŸããéåæéã¯ãéåžž4é±éç¶ãããããŠãã£ãšãæç¥šãã®ãã®ã宿œãããã ãžã£ã¹ãã£ãŒã³ã»ã°ãªãŒãã³ã°æ°ã¯2床ç®ã®åœæ°æç¥šæ¡ãæ¯æããåœæ°ã«ã¯3ã€ã®éžæè¢ãäžããããã¹ãã ãšäž»åŒµãã éžç®¡ã¯BBCãã¥ãŒã¹ã«å¯Ÿãã2000幎å¶å®ã®æ¿å
ãéžæãåœæ°æç¥šæ³ã§å®ããããŠããæ³æ¡ééããæç¥šåœæ¥ãŸã§ã®å
šãŠã®æé ã«ã¯ãæçã§ã10é±éããããšèª¬æããã ãã®ããšãããæ³æ¡ééãšéžæéçšã®äž¡æ¹ããã€ã®ãªã¹ãEUãé¢è±ããäºå®ææ¥ã§ãã2019幎3æ29æ¥ãŸã§ã«çµããå¯èœæ§ã¯æ¥µããŠäœããšç€ºåãããã çºè¡šãã10æ¥ã§ã®åœæ°æç¥š ããããéåžžã«å³ããææå
ã«åœæ°æç¥šã宿œããåäŸãä»åœã«ãªãããã§ã¯ãªãã 3幎åãã®ãªã·ã£ã¯1é±éã»ã©ã®æºåæéã§åœæ°æç¥šããšããŸãšãããææš©è
ã¯ãã®åœæ°æç¥šã§ãååœã®çµæžå±æ©ã«å¯Ÿããåœé嵿š©å£ã®ææžæ¡ãåŠæ±ºããã ããããåœæ°æç¥šãããŸãã«æ©æ¥ã«å®æœããŠããŸããšããéåžžã®æç¶ãã«åŸã£ãŠããªãããšã®å°è±¡ãäžããææš©è
ãæçµçµæãéåæ³ãªãã®ãšã¿ãŠããŸãå¯èœæ§ããããšãã¬ã³ãŠã£ãã¯æ°ã¯èªãã ããšãã°ã2015幎ã®ã®ãªã·ã£ãšäŒŒãæºåæéã§åœæ°æç¥šããããšãéµéã«ããæç¥šãåãä»ããããæç¥šçšçŽã«æžããã質åãè©äŸ¡ãããããååãªæéã®ç¢ºä¿ãèš±ãããªãããšã«ãªãã ãªã¹ãã³æ¡çŽ50æ¡ã§å®ããããæéã®å»¶é· ã€ã®ãªã¹ã¯EUã«å¯ŸããEUåºæ¬æ¡çŽïŒãªã¹ãã³æ¡çŽïŒç¬¬50æ¡ã§å®ããããé¢è±äº€æžæéãå»¶é·ããããæ±ããå¯èœæ§ãããããªã¹ãã³æ¡çŽã¯ãã¡ã€éŠçžã第50æ¡ãçºåãã2017幎3æ29æ¥ãã2幎éããé¢è±æ¡ä»¶ã®åæã«å¿
èŠãªæéãšããŠå®ããŠããããã®æéãå»¶é·ãããã°ãæ°ããªåœæ°æç¥šã宿œããããã®æéãå¢ããã ããããè±ã±ã³ããªããžå€§åŠã§æ¬§å·æ³ãç ç©¶ãããã£ã¹ãªã³ã»ããŒããŒãææã«ãããšã2019幎3æ29æ¥ãšããé¢è±æéãå»¶é·ãããããã詊æ¡ã«ã¯ãä»ã®EUå ç27ã«åœã®å
šäŒäžèŽã§ã®æ¯æãå¿
èŠã«ãªãã EUã¯ãã€ã®ãªã¹ã®é¢è±å»¶æãèªããå¯èœæ§ããããšç€ºåããŠããããã ããããšãã°ç·éžæãããã¯æ°ããªåœæ°æç¥šã宿œããããªã©ãæ¿å±ãå€åããå Žåã®ã¿ã ãšããããã§ã«åæãããé¢è±åå®ã«ã€ããŠãåã«å亀æžããããã®è¿œå æéã®ç¢ºä¿ã¯èªããããªãã ãŸããæéå»¶é·ã«ã¯ã€ã®ãªã¹è°äŒã®åæãå¿
èŠã«ãªãã ïŒé¢é£èšäºïŒ ããã«æ¬§å·åžæ³è£å€æïŒECJïŒã¯å
ã«ãã€ã®ãªã¹ã¯ä»åœã®æ¿èªãåŸãã«ãªã¹ãã³æ¡çŽç¬¬50æ¡ã®çºåãå®å
šã«åãæ¶ãæš©éãæã€ãšã®å€æãäžããã ãããããã¯ããã¬ã°ãžããã®éçšå
šäœãäžæ¢ã§ãããšããæå³ã ãåã«å»¶æãããšããæå³ã§ã¯ãªãã ãªã®ã§çµå±ãã€ã®ãªã¹ã2床ç®ã®åœæ°æç¥šå®æœãæããªãããŸãã¯ç¬¬50æ¡ã§å®ããããé¢è±æéã®å»¶é·ã暡玢ããããšã«ãªãã ããã ãããŠãæç¥šã®çµæã«åŸã£ãŠãã€ã®ãªã¹ã¯æç¥šåŸã«ç¬¬50æ¡ã®çºåãæ€åãããã©ããæ±ºããããã ã€ã®ãªã¹ã®EUé¢è±äºå®æ¥åŸã«åœæ°æç¥šã宿œããã®ãä»£æ¿æ¡ãããããªãããããããã®æ¡ã¯ããªãçŸå®çãªå°é£ãåŒãèµ·ãããããªããç¹ã«ãæ¢ã«é¢è±ããã«ãããããããã€ã®ãªã¹åœæ°ãEUã®äžå¡ã§ããç¶ããéžæãããå Žåã«ã¯ã ïŒè±èªèšäº Brexit: How could another referendum on leaving the EU work?ïŒ ãããŒã»ãã¬ã¢å
éŠçžã¯ãã€ã®ãªã¹ã®EUé¢è±ããããè¡ãè©°ãŸããæéããããã2床ç®ã®åœæ°æç¥šã宿œãã¹ãã ãšäž»åŒµããŠããŸãããããã2床ç®ã®åœæ°æç¥šã宿œããããã«ã¯ãå€ãã®èª²é¡ããããŸãã ãŸãã2床ç®ã®åœæ°æç¥šã宿œããããã®æ³åŸãå¶å®ããå¿
èŠããããŸãããã®æ³åŸã«ã¯ãæç¥šã®ã«ãŒã«ãéžæéåã®ã«ãŒã«ãªã©ãå®ããããŸãã2016幎ã®åœæ°æç¥šã§ã¯ãæç¥šæ¥ã®7ã«æåã«é¢é£æ³æ¡ãè°æ±ºãããŸããããä»åã¯ãã£ãšæ©ãæ³å¶åãå¯èœãªã®ã§ããããïŒ æ¬¡ã«ã2床ç®ã®åœæ°æç¥šã§äœãåãã®ããæ±ºããå¿
èŠããããŸãã2016幎ã®åœæ°æç¥šã§ã¯ããé¢è±ããšãæ®çãã®2æã§ããããä»åã¯è€æ°ã®éžæè¢ãå«ããããšãæ€èšãããŠããŸãã ãŸãã2床ç®ã®åœæ°æç¥šã宿œããããã®è²»çšãåé¡ã§ãã2016幎ã®åœæ°æç¥šã§ã¯ãçŽ1å2,000äžãã³ãïŒçŽ170ååïŒã®è²»çšãããããŸããã ããã«ã2床ç®ã®åœæ°æç¥šã宿œããå Žåãã€ã®ãªã¹ã®EUé¢è±ãé
ããå¯èœæ§ããããŸããã€ã®ãªã¹ã¯2019幎3æ29æ¥ã«EUãé¢è±ããäºå®ã§ããã2床ç®ã®åœæ°æç¥šã宿œããå Žåããã®æéãå»¶é·ãããå¯èœæ§ããããŸãã ãã®ããã«ã2床ç®ã®åœæ°æç¥šã宿œããããã«ã¯ãå€ãã®èª²é¡ããããŸãããããããã¬ã¢å
éŠçžã¯ã2床ç®ã®åœæ°æç¥šãè°äŒã®è çç¶æ
ãè§£æ¶ããå¯èœæ§ããããšäž»åŒµããŠããŸãã ã€ã³ã°ã©ã³ãWTBã¡ã€ã¯2åéã§2ã€ã®ãã©ã€ã決ãã åå倧äŒã§1次ãªãŒã°æéã®å±èŸ±ãå³ãã£ãã€ã³ã°ã©ã³ãã«ãšã£ãŠã¯ã3倧äŒã¶ãã®æºæ±ºåé²åºã 26æ¥ã«æšªæµã§éãããæºæ±ºåã§ã倧äŒ3é£èŠãçãäžççè
ãã¥ãŒãžãŒã©ã³ããšå¯ŸæŠããããã¥ãŒãžãŒã©ã³ãã¯ãã®æ¥ãæºã
決åã®2詊åç®ã§ã¢ã€ã«ã©ã³ããç Žã£ãŠ4匷å
¥ãããã ã€ã³ã°ã©ã³ãã¯3åç¡æïŒ1詊åã¯éšå€©åŒãåãïŒã§1次ãªãŒã°Cçµã1äœçªç Žãäžæ¹ããªãŒã¹ãã©ãªã¢ã¯ãDçµã3å1æã§2äœééããŠããã ã€ã³ã°ã©ã³ãã¯1次ãªãŒã°æçµæŠãå°é¢šã®åœ±é¿ã§äžæ¢ãšãªãã5æ¥ä»¥æ¥2é±éã¶ãã®è©Šåã ã£ãããã£ã·ããšäŒé€ãåã£ãäžæ¹ãããã«æ¬æ¥ã®åããçºæ®ã§ããã®ãäžå®èŠãã声ããã£ãããç¡çšã®å¿é
ã ã£ãã ãã©ã€ã§ããé転 å
å¶ç¹ã¯ãªãŒã¹ãã©ãªã¢ãæããã åå11åãã€ã³ã°ã©ã³ããå±éºãªãã€ã¿ãã¯ã«ã®ååãç¯ããšããªãŒã¹ãã©ãªã¢ã®SOã¯ãªã¹ãã£ã³ã»ãªã¢ãªãŒãã¡ããããã«ãã£ãŽãŒã«æ±ºããã ããããã€ã³ã°ã©ã³ãã®åæã¯æ©ãã£ãã åå17åãã€ã³ã°ã©ã³ãã¯å³ãµã€ãããå·Šãµã€ããžãšå€§ãããã¹ãã€ãªããæåŸã¯WTBãžã§ããŒã»ã¡ã€ãå·Šãµã€ãã«é£ã³ããã§é転ãSOãªãŠãšã³ã»ãã¡ã¬ã«ãã³ã³ããŒãžã§ã³ããã¯ã決ããã ãã®3ååŸãã¡ã€ãåã³ãã©ã€ã決ããããªãŒã¹ãã©ãªã¢ã®ãã¹ãã€ã³ã¿ãŒã»ããããCTBãã³ãªãŒã»ã¹ã¬ã€ããé§ãäžãããåæ¹ã«ãŽãã®ããã¯ã蹎ãåºããããããã¡ã€ãã€ãã¿ããŸããå·Šãµã€ãã«æ»ã蟌ãã ã ã³ã³ããŒãžã§ã³ããã¯ã決ãŸããã€ã³ã°ã©ã³ãã¯14ïŒ3ãšãªãŒããåºããããã®æ¥ãããã«ãŒã®ãã¡ã¬ã«ã¯æçŸ€ã®å®å®æ§ãèŠããã ãã©ã€çãã確å®ã«åŸç¹ åå25åãã€ã³ã°ã©ã³ãã¯èªé£ãŽãŒã«ãã10ã¡ãŒãã«è¶³ããã®å Žæã§ååãç¯ãããªãŒã¹ãã©ãªã¢ã¯ãã®å¥œæ©ã«ãè¿·ããããã«ãã£ããã¯ãéžæããã©ã€ã«åºå·ããçå®ã«ç¹å·®ãè©°ãããæ±ºåããŒãã¡ã³ããããæŠè¡ããšã£ãã ããããªã¢ãªãŒãã¡ãã確å®ã«æ±ºãã6ïŒ14ã«ç¹å·®ãçž®ããã ã€ã³ã°ã©ã³ãã¯åå29åããã¡ã¬ã«ãçžæååããçŽ30ã¡ãŒãã«ã®ããã«ãã£ãŽãŒã«ãæåãããã ãããååçµäºééããªãŒã¹ãã©ãªã¢ã®ãªã¢ãªãŒãã¡ããããã«ãã£ãŽãŒã«ã決ãè¿ãã9ïŒ17ã®8ç¹å·®ã§ããŒãã¿ã€ã ãè¿ããã ç远ãäºæãããã 1次ãªãŒã°ã®è©Šåã§ã¯åŸåã«åŸç¹ãéäžãããã¹ããŒã¹ã¿ãŒã¿ãŒã¶ããèŠãããªãŒã¹ãã©ãªã¢ã¯ããã®æ¥ãåŸåãç远ãäºæãããèŠäºãªåãããåå§åããã åŸå2åãWTBããªã«ã»ã³ãã€ããã£ãèŠäºãªã¹ããŒããšã¹ãããã§ãã£ãã§ã³ã¹ãããããšãäžæ°ã«ãŽãŒã«ãšãªã¢ãŸã§é§ã蟌ãã ã ã³ã³ããŒãžã§ã³ããã¯ãæåã1ç¹å·®ã«è©°ãå¯ã£ãã ããããã€ã³ã°ã©ã³ãã¯èœã¡çãã倱ãããèªåãã¡ã®ããŒã¹ãä¹±ããªãã£ãã ã€ã³ã°ã©ã³ãã®PRã·ã³ã¯ã©ãŒã®ãã©ã€ã¯ãåæã ãŒãã®ãªãŒã¹ãã©ãªã¢ã«ãšã£ãŠçæãšãªã£ã åŸå5åããã¹ãåããPRã«ã€ã«ã»ã·ã³ã¯ã©ãŒãçžæãã£ãã§ã³ã¹ã©ã€ã³ã®ããéãçªç ŽãããŽãŒã«äžå€®éšåã«ãã©ã€ãã³ã³ããŒãžã§ã³ããã¯ã決ããåã³8ç¹å·®ã«æ»ããã åŸå10åã«ã¯ãã¡ã¬ã«ããŽãŒã«ãã¹ãæ£é¢ããããã«ãã£ãŽãŒã«ã«æåããªãŒãã27ïŒ16ã«åºããã åè² æ±ºããæ»é² äžæ¹ããªãŒã¹ãã©ãªã¢ã¯åŸå18åããŽãŒã«ç®åã®ãã€ããŒã«ã®ã¹ã¯ã©ã ããæ³¢ç¶æ»æãå±éããã©ã¯ãŒãé£ã®çªé²ã§ãŽãŒã«2ã¡ãŒãã«ãŸã§è¿«ãå Žé¢ããã£ãããã€ã³ã°ã©ã³ãã¯äœã匵ã£ãŠæŒãæ»ãç¶ããã€ãã«ã¯ããŒã«ã奪ãããšã«æåããã ãªãŒã¹ãã©ãªã¢ã«ãšã£ãŠã¯å€§ããªãã£ã³ã¹ãéããå Žé¢ã ã£ããããã§æ°èœã¡ããã®ãããªãŒã¹ãã©ãªã¢ã¯ä»¥éãèŠãå Žãã»ãšãã©äœããªãã£ãã å察ã«ã€ã³ã°ã©ã³ãã¯ãåŸå25åãš33åã«ããã¡ã¬ã«ããã®è©Šå3ã€ç®ãšïŒã€ç®ã®ããã«ãã£ãŽãŒã«ããšãã«æåããããªãŒã¹ãã©ãªã¢ãçªãæŸããã åŸå35åã«ã¯ããªãŒã¹ãã©ãªã¢ãå·Šã«æŸã£ãé·ããã¹ãã€ã³ã°ã©ã³ãã®WTBã¢ã³ãããŒã»ã¯ããœã³ãã€ã³ã¿ãŒã»ãããããŽãŒã«ãŸã§é§ãäžãã£ãŠãã¡æŒãã®ãã©ã€ã決ããã ãªãŒã¹ãã©ãªã¢ã¯åŸå37åãã³ãã€ããã£ãåã³å¿«è¶³ãé£ã°ãããã£ãã§ã³ã¹ãæ¯ãåã£ãŠãŽãŒã«ãšãªã¢ãŸã§é§ã蟌ãã ããããããã®åã®ãã¬ãŒã§ãã¹ãã¹ããŒãã©ã¯ãŒãã®ååãšå€æããããã©ã€ã¯ç¡å¹ã«ãªã£ãã çŽåŸã詊åçµäºã®éã鳎ã£ãã ïŒé¢é£èšäºïŒ ã€ã³ã°ã©ã³ãã®ãšãã£ã»ãžã§ãŠã³ãºç£ç£ã¯è©ŠååŸããæåã®20åéã¯çžæã«ããŒã«ã75ïŒ
æ¯é
ãããŠããããéžæãã¡ã¯èŠäºã«ç²ã£ããããŸãå®ããæµããåãæ»ããããšéžæãã¡ãç§°ããã ããã«ããåŸåãçžæãåæããŠããŠããããã£ãŠããããšãªã£ãããããŸã察å¿ã§ããããšæ¯ãè¿ã£ãã ãæºæ±ºåé²åºã«ãã¿ããªãããçãäžãã£ãŠããããŸã æé«æœ®ã«ãªã£ãŠããªãã®ã§ããã®ç¶æ
ã«ã©ããã£ãŠãã©ãã€ããã課é¡ã ã 21æ³ã®ã€ã³ã°ã©ã³ãã®FLã«ãªãŒã¯çµå§çŽ æŽãããåããèŠãç¶ãã ãã®è©Šåã®æåªç§éžæïŒãã ã»ã«ãªãŒïŒã€ã³ã°ã©ã³ãïŒ ãã®è©Šåã®æåªç§éžæã«ã¯ã16åã®ã¿ãã¯ã«ããããªã©ãçµå§èŠäºãªãã¬ãŒãèŠããã€ã³ã°ã©ã³ãã®FLãã ã»ã«ãªãŒãéžã°ããã ïŒè±èªé¢é£èšäº England beat Australia to make semisïŒ ã€ã³ã°ã©ã³ãã¯ã26æ¥ã«æšªæµã§è¡ãããæºæ±ºåã§ã倧äŒ3é£èŠãçãäžççè
ãã¥ãŒãžãŒã©ã³ããšå¯ŸæŠãããã€ã³ã°ã©ã³ãã¯ããªãŒã¹ãã©ãªã¢ãšã®æºã
決åã§ãååã«2ãã©ã€ãæããŠãªãŒããåºããåŸåã¯ãªãŒã¹ãã©ãªã¢ã®çè¿œãæ¯ãåã£ãŠ27-19ã§åå©ããã ãã®ã¯ã¯ãã³ã¯è€æ°ã®åç©å®éšã§ãå®å
šæ§ãã广çãªå
ç«åå¿ãåŒãèµ·ããããšã瀺ãããŠããã ä»åã®ç¬¬1段éã®åŸã«ã¯ã6000人ã察象ãšããå¥ã®èšåºè©Šéšãä»å¹Ž10æã«äºå®ãããŠããã ã€ã³ããªã¢ã«ïœ¥ã³ã¬ããžïœ¥ãã³ãã³ã®ããŒã ã¯ã2021å¹Žã®æ©ãææããã€ã®ãªã¹ãæµ·å€ã§ã¯ã¯ãã³ãé
åžã§ããããã«ããããšããŠããã ïŒé¢é£èšäºïŒ äžçäžã§ã¯çŽ120ã®ã¯ã¯ãã³ã®éçºãé²ããããŠãããè±ãªãã¯ã¹ãã©ãŒã倧åŠã®å°éå®¶ãã¡ã¯ãã§ã«èšåºè©Šéšãéå§ããŠããã æ°ããã¢ãããŒã å€ãã®åŸæ¥ã®ã¯ã¯ãã³ã¯ã匱äœåããããŠã€ã«ã¹ãæ¹å€ãããŠã€ã«ã¹ãªã©ãããšã«ãªã£ãŠããããããä»åã®ã¯ã¯ãã³ã¯æ°ããã¢ãããŒãã«åºã¥ãããã®ã§ãéºäŒåã®RNAïŒãªãæ žé
žïŒã䜿ãã çèã«æ³šå°ãããšãRNAã¯èªå·±å¢æ®ããæ°åãŠã€ã«ã¹ã®è¡šé¢ã«ã¿ãããã¹ãã€ã¯ã¿ã³ãã¯è³ªã®ã³ããŒãã€ãããããäœå
ã®çްèã«æç€ºãåºãã ãã®æ¹æ³ã§ãCOVID-19ïŒæ°åãŠã€ã«ã¹ã«ããææçïŒãçºçããããšãªãæ°åãŠã€ã«ã¹ãèªèããŠæŠãããã®å
ç«ã·ã¹ãã ãèšç·Žã§ãããšããã ã·ã£ããã¯ææã¯ããæã
ã¯ãŒãããã¯ã¯ãã³ã補é ãããããæ°ã«æã§èšåºè©Šéšã«æã¡èŸŒãããšãã§ããããšè¿°ã¹ãã ãæã
ã®ã¢ãããŒããããŸããã£ãŠãã¯ã¯ãã³ããã®ç
æ°ã广çã«é²åŸ¡ã§ããã°ãå°æ¥çãªã¢ãŠããã¬ã€ã¯ïŒå€§æµè¡ïŒãžã®å¯Ÿå¿æ¹æ³ã«é©åœãããããå¯èœæ§ãããã 䞻任ç ç©¶å¡ã®ã«ããªãŒãã»ãããã¯å士ã¯ãã¯ã¯ãã³ã®å¹æã«æåŸ
ããŠãã ãã®ç ç©¶ã®äž»ä»»ç ç©¶å¡ãã«ããªãŒãã»ãããã¯å士ã¯ããåå è
ã«å€§ããªå
ç«åå¿ãã¿ãããã ãããšãæ
éãªãããæ¥œèгçã«æããããªãã£ãããç§ã¯ãã®èšåºè©Šéšã«åãçµãã§ããªãã£ãã ããããšä»ãå ããã ãåèšåºããŒã¿ã¯éåžžã«æåŸ
ãããŠããã®ã ã£ããææããä¿è·ããŠããããå
ç«åå¿ã§ããäžåæäœå¿çã¯ç¢ºèªã§ããŠãããããã®ã¯ã¯ãã³ãè©äŸ¡ããã«ã¯ãŸã éã®ãã¯é·ãã ãã®ç ç©¶ã¯è±æ¿åºãã4100äžãã³ãïŒçŽ54å5500äžåïŒã®è³éæäŸãåããŠãããã»ãã«ã500äžãã³ãïŒçŽ6å6500äžåïŒã®å¯ä»ãå¯ããããŠããã ããŠã€ã«ã¹ãåãã®ã«ååããããŠå¿é¡ã éèæ¥çã§åããã£ã·ãŒããïŒ39ïŒã¯ãã€ã³ããªã¢ã«ïœ¥ã³ã¬ããžïœ¥ãã³ãã³ã®èšåºè©Šéšã«åå ããŠããæåã®ãã©ã³ãã£ã¢ã®1人ã ã æ°åãŠã€ã«ã¹ãšã®æŠãã®äžç«¯ãæ
ããããŠå¿é¡ãããšããã ãèªåã«äœãã§ããã®ãããŸãããåãã£ãŠããªãã£ããã©ããããç§ã«ã§ããããšã ã£ããšåãã£ãã ãããã«ãã¯ã¯ãã³ãã§ãããŸã§æ¥åžžã«æ»ããå¯èœæ§ã¯äœãããšãçè§£ããããšã§ãã¯ã¯ãã³éçºã®äžç«¯ãæ
ããããšæã£ãã ãã£ã·ãŒããã¯ãã€ã³ããªã¢ã«ïœ¥ã³ã¬ããžïœ¥ãã³ãã³ã®èšåºè©Šéšã«åå ããŠããæåã®ãã©ã³ãã£ã¢300人ã®1人 ããããäžãã±ã³ããªããžå
¬çµãŠã£ãªã¢ã çåã¯ãªãã¯ã¹ãã©ãŒã倧åŠã®èšåºè©Šéšã«åå ããŠãããã©ã³ãã£ã¢ãã¡ãšããªãã¯ã¹ãã©ãŒãåžå
ã®ãã£ãŒãã«ç
é¢ã§é¢äŒããã ãŠã£ãªã¢ã çåã¯ãã©ã³ãã£ã¢ã«å¯Ÿãããã¿ãªããå
šå¡ãåå ããŠããã®ã¯ãä¿¡ããããªããããèžãèºããéåžžã«åŸ
ã¡æãŸãããããžã§ã¯ãã ãã ããã¿ããªãå¿ã奪ãããŠããããšè¿°ã¹ãã 忥ã®è¢«éšè
ã¯1人ã ã BBCã®ãã¡ãŒã¬ã¹ã»ãŠã©ã«ã·ã¥å»çæ
åœç·šéå§å¡ã«ãããšããã¹ãŠã®èšåºè©Šéšã¯å®å
šæ§ã®ãªã¹ã¯è»œæžã®ããã«æ
éã«ããã£ããéå§ãããããªãã¯ã¹ãã©ãŒã倧åŠã§4æã«èšåºè©Šéšãéå§ãããéã«ã¯ãåæ¥ã«æ¥çš®ãåããã®ã¯ãã©ã³ãã£ã¢2人ã ãã§ã1é±é以å
ã«100äººã«æ¥çš®ãããã ããã«å¯ŸããŠãã€ã³ããªã¢ã«ïœ¥ã³ã¬ããžïœ¥ãã³ãã³ã®èšåºè©Šéšã§ã¯åæ¥ã«ã¯1人ã ãã«ã¯ã¯ãã³ãæ¥çš®ããããã®åŸ48æéããšã«3äººã«æ¥çš®ããåŸã
ã«è¢«éšè
ãå¢ãããŠããã ãŸãã1ååã®æäžéã䜿çšãããªãã¯ã¹ãã©ãŒã倧åŠãšã¯ç°ãªããã€ã³ããªã¢ã«ïœ¥ã³ã¬ããžïœ¥ãã³ãã³ã®èšåºè©Šéšã§ã¯4é±éã®ééããããŠã2åã®æ¥çš®ãè¡ããšããã ã·ã£ããã¯ææãã®ããŒã ã¯ãæ
éã«é²ããŠããçç±ã«ã€ããŠãã¯ã¯ãã³ã«ç¹æ®µã®å®å
šæ§ã®æžå¿µãããããã§ã¯ãªããåã«ã¢ãããŒããæ°ããããã ãšèª¬æããŠããã æ°åã³ãããŠã€ã«ã¹ç¹é ææå¯Ÿç åšå®
å€åã»éé¢ç掻 ïŒè±èªèšäº Human trial of new coronavirus vaccine starts in UKïŒ ã€ã³ããªã¢ã«ã»ã«ã¬ããžã»ãã³ãã³ã¯ãæ°åã³ãããŠã€ã«ã¹ã«å¯Ÿããæ°ããã¯ã¯ãã³ã®ç¬¬1段éã®èšåºè©Šéšãéå§ããŸããããã®ã¯ã¯ãã³ã¯ãéºäŒåã®RNAïŒãªãæ žé
žïŒã䜿çšããŠãããçèã«æ³šå°ãããšãèªå·±å¢æ®ããŠæ°åãŠã€ã«ã¹ã®è¡šé¢ã«ã¿ãããã¹ãã€ã¯ã¿ã³ãã¯è³ªã®ã³ããŒãã€ãããããäœå
ã®çްèã«æç€ºãåºããŸãããã®æ¹æ³ã§ãCOVID-19ïŒæ°åãŠã€ã«ã¹ã«ããææçïŒãçºçããããšãªãæ°åãŠã€ã«ã¹ãèªèããŠæŠãããã®å
ç«ã·ã¹ãã ãèšç·Žã§ãããšããã ãã®ã¯ã¯ãã³ã¯è€æ°ã®åç©å®éšã§ãå®å
šæ§ãã广çãªå
ç«åå¿ãåŒãèµ·ããããšã瀺ãããŠãããä»åã®ç¬¬1段éã®åŸã«ã¯ã6000人ã察象ãšããå¥ã®èšåºè©Šéšãä»å¹Ž10æã«äºå®ãããŠãããã€ã³ããªã¢ã«ã»ã«ã¬ããžã»ãã³ãã³ã®ããŒã ã¯ã2021å¹Žã®æ©ãææããã€ã®ãªã¹ãæµ·å€ã§ã¯ã¯ãã³ãé
åžã§ããããã«ããããšããŠããã æç« ãããªãçããªã£ãŠããã®ã§ãèŠçŽèªäœã¯æåã§ãããšæãããŸããããããããŸãèŠçŽã§ããŠããªãç®æãããã®ã§ãããã¯ããã³ãããšã³ãžãã¢ãªã³ã°ã®è
ã®èŠãæã§ãããšèããŠããŸãã çµããã« ä»åã¯BigQuery MLã®ML.GENERATE_TEXT颿°ã䜿ã£ãèŠçŽã«ã€ããŠç޹ä»ãããŠããã ããŸãããä»åã¯èŠçŽã§ããããããã³ããæ¬¡ç¬¬ã§æ§ã
ãªã¿ã¹ã¯ãå¯èœãšãªããŸãã æåŸãŸã§èªãã§ããã ããããããšãããããŸããïŒ
ããã«ã¡ã¯ãSCSKã®ç°äžã§ãã æ¬èšäºã§ã¯USiZEã·ã§ã¢ãŒãã¢ãã«ã®ã©ã³ãµã ãŠã§ã¢å¯Ÿçã«åãããµãŒãã¹ãæ°ããæ€èšããã«ããããã©ã³ãµã ãŠã§ã¢ã«ã€ããŠèª¿ã¹ãããšãèšèŒããŸãã USiZEã·ã§ã¢ãŒãã¢ãã«ã«èå³ãæã£ãŠããã ããæ¹ã¯ä»¥äžã®ããŒãžããåç
§ãã ããã 運用付きの国産クラウドサービス│SCSK株式会社 VMwareããŒã¹ã§æ§ç¯ããããé«å¯çšæ§ã髿©å¯ãåããåœç£ã®ãã©ã€ããŒãã¯ã©ãŠãã§ãããã¡ã·ãªãã£ã¹ã¿ã³ããŒãæé«ã¬ãã«ã®ãã£ã¢4ã«é©åããæ¥æ¬åœå
ã®ããŒã¿ã»ã³ã¿ãŒäžã§çšŒåããã客æ§ããŒã¿ã®ä¿è·ãšããŒã¿äž»æš©ã確ä¿ããŸãã www.scsk.jp ã©ã³ãµã ãŠã§ã¢ãšã¯ ã©ã³ãµã ãŠã§ã¢ã®å®çŸ©ã«ã€ããŠIPAãå
¬éããŠãããã©ã³ãµã ãŠã§ã¢å¯Ÿçç¹èšããŒãžãã§ä»¥äžã®å®çŸ©ããããŠããŸãã ã©ã³ãµã ãŠã§ã¢ãšã¯ãã身代éããšãSoftware(ãœãããŠã§ã¢)ããçµã¿åãããé èªã§ãã ææããããœã³ã³ã«ç¹å®ã®å¶éãããããã®å¶éã®è§£é€ãšåŒãæãã«ééãèŠæ±ããæåããã ãã®ãããªäžæ£ããã°ã©ã ãã©ã³ãµã ãŠã§ã¢ãšåŒã°ããŠããŸãã IPAãã©ã³ãµã ãŠã§ã¢å¯Ÿçç¹èšããŒãžã ããåŒçš ã©ã³ãµã ãŠã§ã¢ã®ã¿ã€ãã«ã€ã㊠ã©ã³ãµã ãŠã§ã¢ã«ã¯å€§ããåããŠ2çš®é¡ã®ã¿ã€ãããããŸãã ã©ã³ãµã ãŠã§ã¢ã®ã¿ã€ã å¶éãããã察象 æ»æãåãããã¡ã€ã«ãæå·åãããéããªããªãã¿ã€ã ç»åãææžçã®ãã¡ã€ã« 端æ«ã®ã¹ã¯ãªãŒã³ãããã¯ãããæäœãã§ããªãããã«ã¿ã€ã 端æ«ã®OSãªã© ã©ã¡ããå¶éè§£é€ãšåŒãæãã«èº«ä»£éçã®å¯ŸäŸ¡ãèŠæ±ããç»é¢ã衚瀺ããŸãã ç»é¢ã®è¡šç€ºæ¹æ³ã¯ãããã¹ãããã©ãŠã¶ç»é¢ãç»åãªã©ããã¡ã€ã«åœ¢åŒãã¡ãã»ãŒãžã®å
å®¹ã¯æ§ã
ãªãã®ã確èªãããŠããŸãã çŸåšãäž»æµãšãªã£ãŠããã©ã³ãµã ãŠã§ã¢ã¯ãã¡ã€ã«æå·ååã§ãã ã©ã³ãµã ãŠã§ã¢ããã¡ã€ã«æå·åãããŸã§ã®å€§ãŸããªæµãã¯ä»¥äžã®éãã§ãã ãŸãæè¿ã¯æå·åãããã«ããŒã¿ã®å
¬éãšèº«ä»£éçã®å¯ŸäŸ¡ãèŠæ±ãããããŒãŠã§ã¢ã©ã³ãµã ããšåŒã°ããã¿ã€ãã芳枬ãããŠããŸãã æå·åã®æéãçãããšãã§ãããšããã¡ãªããããããŸãã ã©ã³ãµã ãŠã§ã¢ã®ææçµè·¯ ã©ã³ãµã ãŠã§ã¢ã®ææçµè·¯ã¯VPNæ©åšããã®äŸµå
¥ã63ä»¶ã§62%ã ãªã¢ãŒããã¹ã¯ãããããã®äŸµå
¥ã19ä»¶ã§18%ãå ããŸãã èŠå¯åºã什ãµã€ããŒç©ºéããããè
åšã®æ
å¢çã å
ã什åïŒå¹Žã«ããããµã€ããŒç©ºéããããè
åšã®æ
å¢çã«ã€ããŠå³è¡šïŒ(CSV)åç
§ VPNæ©åšãžã®ãµã€ããŒæ»æã§ã¯ãèªèšŒã«å©çšããVPNã®æ
å ±ããVPNã®è匱æ§ãæªçšãããŸãã äŸâ äžæ£ã«å
¥æããVPNã®ã¢ã«ãŠã³ãã®èªèšŒæ
å ±ã䜿ãããããã¯ãŒã¯ãçµç¹å
éšã«äŸµå
¥ãå³ããŸãã äŸâ¡VPNã®è匱æ§ãæ»æãå
éšã«äŸµå
¥ããŸããå®å
šãªã¯ãã®VPNãæ»æã®äŸµå
¥å£ã«ãªã£ãŠããŸããŸãã æè¿(2023幎)ã®ã©ã³ãµã ãŠã§ã¢ã«é¢ããæµã è¿å¹Žãæ§ã
ãªäŒæ¥ã§ã©ã³ãµã ãŠã§ã¢ã«ãã被害ã確èªãããŠããŸããäŒæ¥ã»å£äœçã«ãããã©ã³ãµã ãŠã§ã¢è¢«å®³ãšããŠã 什å4幎ã«éœéåºçèŠå¯ããèŠå¯åºã«å ±åã®ãã£ãä»¶æ°ã¯ä»¥äžã®æšç§»ã§ããã什å2幎äžåæä»¥éãå³è©äžããã§å¢å ããŠããŸãã èŠå¯åºã什ãµã€ããŒç©ºéããããè
åšã®æ
å¢çã å
什åïŒå¹Žã«ããããµã€ããŒç©ºéããããè
åšã®æ
å¢çã«ã€ããŠå³è¡š1(CSV)åç
§ ãããã被害çºçä»¶æ°ã®å¢å ãªã©ããã£ãŠãã IPAã®ãæ
å ±ã»ãã¥ãªãã£10倧è
åšã ã®çµç¹ç·šã«ãŠ2021幎床ãã2023幎床ãŸã§3幎é£ç¶ããŠ1äœãšãªã£ãŠãããŸãã ãã®ããšããã©ã³ãµã ãŠã§ã¢ã倧ããªè
åšãšæããããŠãããåäŒæ¥ã§ã©ã³ãµã ãŠã§ã¢ã®å¯ŸçãéèŠèŠãããŠããããšãããããŸãã 2021 幎 2022 幎 2023 幎 1äœ ã©ã³ãµã ãŠã§ã¢ã«ãã被害 ã©ã³ãµã ãŠã§ã¢ã«ãã被害 ã©ã³ãµã ãŠã§ã¢ã«ãã被害 2äœ æšçåæ»æã«ããæ©å¯æ
å ±ã®çªå æšçåæ»æã«ããæ©å¯æ
å ±ã®çªå ãµãã©ã€ãã§ãŒã³ã®åŒ±ç¹ãæªçšããæ»æ 3äœ ãã¬ã¯ãŒã¯çã®ãã¥ãŒããŒãã«ãªåãæ¹ãçã£ãæ»æ ãµãã©ã€ãã§ãŒã³ã®åŒ±ç¹ãæªçšããæ»æ æšçåæ»æã«ããæ©å¯æ
å ±ã®çªå ã©ã³ãµã ãŠã§ã¢ã«ææããªãããã«ããããã«ã¯ã©ããããããã – ãŠãŒã¶åŽ ãŠãŒã¶åŽã§ãšãã察çãšäºé²çã«ã€ããŠã¯ä»¥äžã®ãã®ããããŸãã ãã£ãã·ã³ã°ã¡ãŒã«ãªã©ã䟵å
¥æã«äœ¿çšãããæ»æææ³ãçè§£ããéšãããªãããã«ããã äžå¯©ãªã¡ãŒã«ããªã³ã¯ã宿ã«ã¯ãªãã¯ããªãã æå±çµç¹ã®ã»ãã¥ãªãã£ããªã·ãŒãé å®ãããœãããŠã§ã¢ãææ°ã®ç¶æ
ã«ä¿ã€ ãã¬ã³ããã€ã¯ã è
åšè§£èª¬-ã©ã³ãµã ãŠã§ã¢ ããåŒçš ã©ã³ãµã ãŠã§ã¢ã«ææããªãããã«ããããã«ã¯ã©ããããããã â 管çè
åŽ ç®¡çè
åŽã§ãšãã察çãšäºé²çã«ã€ããŠã¯ä»¥äžã®ãã®ããããŸãã ãšã³ããã€ã³ãããµãŒãã«ã¯ç·åçãªã»ãã¥ãªãã£ãœãããå°å
¥ãã ã¡ãŒã«ãµãŒãã«ãããŠæ»æã¡ãŒã«ãæ€åºãããœãªã¥ãŒã·ã§ã³ãå°å
¥ãã å€éšãžã®äžæ£ãªãããã¯ãŒã¯éä¿¡ã»æ¥ç¶ãæ€åºãããœãªã¥ãŒã·ã§ã³ãå°å
¥ãã ãããã¯ãŒã¯å
éšã®ç£èŠãšäžå¯©ãªæåãå¯èŠåããããã®ãœãªã¥ãŒã·ã§ã³ãå°å
¥ãã ã»ãã¥ãªãã£ããªã·ãŒãçå®ãã管çè
æš©éã®ç®¡çãã·ã¹ãã ã®è匱æ§ç®¡çãé©åã«è¡ã 3-2-1ã«ãŒã«ã«åããããŒã¿ã®åé·æ§ãååã«æ
ä¿ã§ãããããªããã¯ã¢ããããªã·ãŒãçå®ãã ã€ã³ã·ãã³ã察å¿äœå¶ãæ§ç¯ãã åŸæ¥å¡ã«å¯Ÿããã»ãã¥ãªãã£æè²ã泚æåèµ·ã宿œãã ãã¬ã³ããã€ã¯ã è
åšè§£èª¬-ã©ã³ãµã ãŠã§ã¢ ããåŒçš 3-2-1ã«ãŒã«ã¯ä»¥äžã®ã«ãŒã«ã®ããšãæããŸãã ã«ãŒã«â ïŒ ããŒã¿ã¯å°ãªããšãã3ã€ãã®ããã¯ã¢ããã³ããŒãæã€ ã«ãŒã«â¡ ïŒ ããã¯ã¢ããããŒã¿ãã2çš®é¡ã以äžã®ç°ãªãåªäœã«ä¿åãã ã«ãŒã«â¢ ïŒ ããŒã¿ä¿ç®¡å
ã®ãã¡ã1ã€ãã¯ç©ççæåšå°ãé éå°ã«ãããã®ãéžå® äžãäžãã©ã³ãµã ãŠã§ã¢ã«ææããŠããŸã£ãã ãã£ãŠã¯ãããªãããš 1.åèµ·å ææã確èªããã端æ«ãåèµ·åãããšãæå·åãé²ã¿è¢«å®³ãæ¡å€§ããæãããããŸãã 2.調æ»åã®é§é€ 調æ»å®äºåã«é§é€ãããŠããŸããšã©ã³ãµã ãŠã§ã¢ã®äŸµå
¥çµè·¯ãªã©ã®æ
å ±ã倱ããã調æ»ãã§ããªããªãæãããããŸãã ä»åŸã®ææäºé²çã®èŠçŽãã®ããã«ã¯èª¿æ»ãå¿
èŠã§ããã調æ»ãè¡ãå Žåã¯ãé§é€ã®åã«èª¿æ»ãè¡ã£ãŠãã ããã 3.é§é€åã®ããã¯ã¢ããã®ååŸ ææäžã«ããã¯ã¢ãããååŸããããšã§ããã¯ã¢ããããŒã¿ã®ä¿ç®¡å
ã§è¢«å®³ãæ¡å€§ããæãããããŸãã å¿
ãã©ã³ãµã ãŠã§ã¢ãé§é€ããåŸã«ããã¯ã¢ãããååŸããŸãããã 4.調æ»ãé§é€åã®ããã¯ã¢ããããŒã¿ã«ãã埩å
調æ»å®äºåã«åŸ©å
ããããšåè¿°2.ãšåæ§ã«èª¿æ»ã«å¿
èŠãªæ
å ±ã倱ããã調æ»ãã§ããªããªãæãããããŸãã ãŸãææäžæç¹ã®ããã¯ã¢ããããŒã¿ã«ãã埩å
ããããšå床ææããæãããããŸãã 5.å°éå®¶ãèŠå¯ãžçžè«ããã«èº«ä»£éãæã 身代éãæ¯æã£ãŠãæå·åã®è§£é€ãããããšã¯éããŸããããŸã1床æãããšã§ãã®åŸãç¹°ãè¿ããçãããæãããããŸãã ãã®ããå°éå®¶ãèŠå¯ã«çžè«ããããšãéèŠã§ãã ããã¹ãããš 1.ãããã¯ãŒã¯ãã鮿 ãææã確èªããã端æ«ã¯ãããã¯ãŒã¯ãã鮿ããå¿
èŠããããŸãã ããã«ãã£ãŠãããã¯ãŒã¯äžã®ä»ã®ç«¯æ«ã«ææãåºããã®ãé²ããŸãã 2.ã©ã³ãµã ãŠã§ã¢ã®çš®é¡ãç¹å®&é§é€ ã©ã³ãµã ãŠã§ã¢ã®çš®é¡ã«ãã£ãŠã¯è§£é€ããŒã«ãé
åžãããŠããããé§é€ã§ããå ŽåããããŸãã ãŸãé©åãªè§£é€ã»åŸ©å·ããŒã«ãæ¢ãããã«ãã©ã³ãµã ãŠã§ã¢ã®çš®é¡ãç¹å®ããããšãéèŠã«ãªããŸãã ãã ãé§é€ãããŠããŸããšã©ã³ãµã ãŠã§ã¢ã®äŸµå
¥çµè·¯ãæ»ææ
å ±ãªã©ã®èª¿æ»ãè¡ã£ããã§ããªããªãæãããããŸãã ãã®ããã調æ»ãè¡ãå Žåã¯ãé§é€ã®åã«èª¿æ»ãè¡ã£ãŠãã ããã 3.ããŒã¿ã埩å
埩å·ããŒã«ã¯ãID RansomwareãããNo More Ransomãã§æ¢ãããšãã§ããã»ãããã¬ã³ããã€ã¯ãæ ªåŒäŒç€Ÿããã«ãã£ãŒãªã©ã®ã»ãã¥ãªãã£ãã³ããŒã§ãã©ã³ãµã ãŠã§ã¢ã«å¯Ÿå¿ãã埩å·ããŒã«ãé
åžããŠããŸãã ãŸã宿çã«ããã¯ã¢ãããååŸããããšã§ææåã®ç¶æ
ã«åŸ©å
ã§ããŸãã 4.ææäºé²çã®èŠçŽã ç¹°ãè¿ãæšçã«ãããããšãé¿ããããã«ãææçµè·¯ãšãªãã»ãã¥ãªãã£ã®ç©Žãå¡ãããšãéèŠã§ãã ãã£ãŠäœ¿çšããŠãããããã¯ãŒã¯æ©åšã»ã·ã¹ãã ã®è匱æ§ã瀟å
ã®ã¢ã¯ã»ã¹ãã°ç£èŠäœå¶ã察å¿ãããŒãèŠçŽãå¿
èŠããããŸãã çµããã« USiZEã·ã§ã¢ãŒãã¢ãã«ã§ã¯ã©ã³ãµã ãŠã§ã¢ã®æ»æã«åããæ°èŠãµãŒãã¹ã®éçºäžã§ãã ãµãŒãã¹ã®è©³çŽ°ãªæ
å ±ãæ±ºãŸããŸãããããã¡ãã§çºè¡šããããšæããŸãã æåŸãŸã§èªãã§ããã ãããããšãããããŸããã åèè³æ IPAãã©ã³ãµã ãŠã§ã¢å¯Ÿçç¹èšããŒãžã ã©ã³ãµã ãŠã§ã¢å¯Ÿçç¹èšããŒãž | æ
å ±ã»ãã¥ãªã㣠| IPA ç¬ç«è¡æ¿æ³äºº æ
å ±åŠçæšé²æ©æ§ æ
å ±åŠçæšé²æ©æ§ïŒIPAïŒã®ãã©ã³ãµã ãŠã§ã¢å¯Ÿçç¹èšããŒãžãã«é¢ããæ
å ±ã§ãã www.ipa.go.jp IPAãæ
å ±ã»ãã¥ãªãã£10倧è
åšã æ
å ±ã»ãã¥ãªãã£10倧è
åš | æ
å ±ã»ãã¥ãªã㣠| IPA ç¬ç«è¡æ¿æ³äºº æ
å ±åŠçæšé²æ©æ§ æ
å ±åŠçæšé²æ©æ§ïŒIPAïŒã®ãæ
å ±ã»ãã¥ãªãã£10倧è
åšãã«é¢ããæ
å ±ã§ãã www.ipa.go.jp èŠå¯åºããµã€ããŒç©ºéããããè
åšã®æ
å¢çã ãµã€ããŒç©ºéããããè
åšã®æ
å¢çïœèŠå¯åºWebãµã€ã www.npa.go.jp ãã¬ã³ããã€ã¯ããVPNããµã€ããŒæ»æè¢«å®³ã«å
±éããã»ãã¥ãªãã£ã®æ³šæç¹ã VPNããµã€ããŒæ»æè¢«å®³ã«å
±éããã»ãã¥ãªãã£ã®æ³šæç¹ | ãã¬ã³ããã€ã¯ã VPNæ©åšãžã®ãµã€ããŒæ»æã«èµ·å ãã被害ãç¶ããŠããŸããã©ã³ãµã ãŠã§ã¢è¢«å®³ã§ã¯ããã®å€ããVPNæ©åšã䟵å
¥ã®èµ·ç¹ã«ãªã£ãŠãããšã®èª¿æ»ããããŸãããããã®æ»æã«ãããçµæçã«äºæ¥åæ¢ãšãã£ãäºæ
ã«è¿œã蟌ãŸããçµç¹ããããæ³šæãå¿
èŠã§ããVPNæ©åšã®ã»ãã¥ãªãã£å¯Ÿçã解説ããŸãã www.trendmicro.com ãã¬ã³ããã€ã¯ããè
åšè§£èª¬-ã©ã³ãµã ãŠã§ã¢ã ã©ã³ãµã ãŠã§ã¢ | ãã¬ã³ããã€ã¯ã ãã¬ã³ããã€ã¯ãã®ã»ãã¥ãªãã£ãšãã¹ããŒãã解説ããã©ã³ãµã ãŠã§ã¢ã«ã€ããŠã®ããŒãžã§ããã©ã³ãµã ãŠã§ã¢ã®æŠèŠãæ»æã®ææ³ãšç¹åŸŽã察çãšäºé²ãåœç€Ÿãœãªã¥ãŒã·ã§ã³ãã玹ä»ããŸããã©ã³ãµã ãŠã§ã¢ãšã¯ããã«ãŠã§ã¢ã®äžçš®ã§ãææããã³ã³ãã¥ãŒã¿ãããã¯ãããããã¡ã€ã«ãæå·åãããããããšã«ãã£ãŠäœ¿çšäžèœã«ããã®ã¡ãå
ã«æ»ãããš... www.trendmicro.com
ããã«ã¡ã¯ãSCSKãæ± ç°ã§ãã 2024幎ãå§ãŸãããã£ãšããéã«åæãçµã£ãŠããŸããæã®éãã«ææãèŠãã€ã€ããä»å¹Žãæ°ããããšã仿ããŠããããšèããŠãã仿¥ãã®é ã§ãã ããŠ1æ17æ¥ã«ã LifeKeeperã®ãµã€ããæ°ããããŸããïŒ â»ã¯ãªãã¯ãããšæ°ãµã€ãã«ç§»åããŸãã ïŒïŒãããŸã§ã®ãµã€ãã®èª²é¡ãšæ¹å æšå¹Ž8æé ãããµã€ãå·æ°ãããžã§ã¯ããã¹ã¿ãŒããããŸãã¯æ§ãµã€ãã®åé¡ç¹ãã²ãšã€ãã€æŽçãããããããã©ã®ããã«å€ããŠããããšã§æ¹åã«ç¹ããããè°è«ããŠãããŸããã æ§ãµã€ãã®äž»ãªèª²é¡ æ°ãµã€ãã§ã®æ¹å 1 æåã°ããã§è§£ãã¥ãã ã€ã¡ãŒãžå³ã掻çšããããšã§è§£ãããã 2 LifeKeeperèªäœã®äŸ¡å€ã説æã§ããŠããªã LifeKeeperã®äŸ¡å€ãè§£ããããèšŽæ± 3 ããæ©ã¿ãã®è§£æ±ºçãå€ããªã ãæ©ã¿ãCaseã§å¥ããåã
ãè§£ãããã解説 4 SCSKã®åŒ·ã¿ãå€ãã¥ãã SCSKã®åŒ·ã¿ã§ããããããªãã¯ã¯ã©ãŠããåããã«ãŠã§ã¢ã®å°ä»»éšéã®ååšã«ããããŒã¿ã«ãªææ¡åãèšŽæ± 5 å°å
¥äºäŸãæåã®ã¿ã§è§£ãã¥ãã åçãã·ã¹ãã æ§æå³ãé
眮ããç°¡æœã«è§£ãããã æ§ãµã€ãïŒå·ŠïŒãšæ°ãµã€ãïŒå³ïŒã§äžŠã¹ãŠã¿ããšãæ
å ±éãæ Œæ®µã«å¢ããŠããããšãšãã€ã¡ãŒãžå³ãå€çšããŠããã®ã§ãè§£ãããããå¢ããŠããããšãäžç®çç¶ã§ããã ïŒïŒ2çš®é¡ã®ãªãŒãã¬ãããäœæããŸããã ãã®ã¿ã€ãã³ã°ã§SCSKãšããŠã®åã®LifeKeeperãªãŒãã¬ãããäœæããŸããã LifeKeeperã®ç¹åŸŽããSCSKã®åŒ·ã¿ãšãã£ãæ
å ±ãç°¡æœã«è¡šçŸããå
容ãšãªã£ãŠããŸãã â»ã¯ãªãã¯ãããšpdfã衚瀺ãããŸãã ãŸãæšå¹Žå®æœããZabbix補åãLifeKeeperã§åé·ããããšã®ã¡ãªããã蚎æ±ãããªãŒãã¬ãããäœæããŸããã Zabbixç¬èªã®å¯çšæ§ã®ä»çµã¿ã ãã§ã¯ã«ããŒã§ããªãç®æãLifeKeeperã䜿ãããšã§è§£æ±ºããããšãã§ããããšèšã£ãå
容ãã玹ä»ããŠããŸãã â»ã¯ãªãã¯ãããšpdfã衚瀺ãããŸãã æ°ãµã€ãã¯ãã¡ããã ã SCSK ã¯ã©ã¹ã¿ãŒãœãããŠã§ã¢ãLifeKeeperã
ããã«ã¡ã¯ãSCSKã®ã²ãããã¬ã§ãã 2024幎ã«ãªããæ©äºé±éãçµéããŸãããæéã®çµéãæ©ãæããããã«ãªã£ã仿¥ãã®ããã§ãã æ©éäœè«ãªã®ã§ãããã人çã®äœææéã¯å¹Žéœ¢ãéããããšã«çããªãããšèšãããŠããããããæ°åŒãçšããŠè¡šçŸãããã®ãããžã£ããŒã®æ³åããšèšãããã§ãããã®æ³åã«åŸãèšç®ããããšãç§ã¯ãã§ã«äººçã®çŽ75%ãçµãã¹ããšã«ãªã£ãŠããã¿ããã§ããâŠäžæ¥äžæ¥ã倧åã«çããããšæããŸãã ¹寿åœã«ã€ããŠã¯ãåçåŽåçãçºè¡šããã 什å4幎簡æçåœè¡š ããããç·æ§ã®å¹³å寿åœã§ãã81.05æ³ã§èšç®ããŠããŸããèšç®ããŒã«ã¯ ãã¡ã ã§æäŸãããŠãããã®ã䜿çšããŸããã ãžã£ããŒã®æ³åã«ã€ããŠåèïŒãšæãããææžïŒã¯ ãã¡ã ã§ãã ãã©ã³ã¹èªã§ãããèå³ã®ããæ¹ã¯æ¯éèªãã§ã¿ãŠãã ããã æ¬é¡ã«æ»ããŸããä»åã¯æ°äººã§ããç§ããé
å±ãããŠããããã3ã¶æã»ã©ã§åãçµãã ã AWSãæŽ»çšãããµãŒãã¹ã®æ§ç¯ ãã«ã€ããŠã玹ä»ããããšæããŸããæ§ç¯ã®éã«çšããéçºç°å¢ã«ã€ããŠã¯ã ååã®ç§ã®èšäº ã«ãŠã玹ä»ããŠãããŸãã®ã§ããããããã°ã芧ãã ããã ãµãŒãã¹ã®æŠèŠ ä»åã¯ãã åçš®ãµãŒãã¹ã§èšå®å€ãæ§ããŠãããã©ã¡ãŒã¿ã·ãŒããèªã¿èŸŒã¿ãããããCloudFormationã§çšããäºã®ã§ããYAMLãã¡ã€ã«ãèªåçã«çæãã ããšããæ©èœãæ§ç¯ããŸãããå
šäœçãªã¢ãŒããã¯ãã£ãäžå³ã«ç€ºããŸããCloud9äžã§éçºãè¡ããæ§ç¯ããããã°ã©ã ãCodeCommitãžã³ãããããŠããŸãã å©çšè
ãèšå®å€ã®èšèŒããããã©ã¡ãŒã¿ã·ãŒããCodeCommitã«ã³ããããããšãæçµçã«CloudFormationãã³ãã¬ãŒãã§ããYAMLãã¡ã€ã«ãS3ãã±ããã«æ ŒçŽããããšããæµãã§ãã ç®ç ææç©ãäœæããã«ããããæå°å¡ã®æ¹ãšçžè«ããŠãããšããã çŸç¶ã§ã¯äººæã§äœæããCloudFormationãã³ãã¬ãŒãã§æ§ç¯ãããªãœãŒã¹ã®å€ãšããã©ã¡ãŒã¿ã·ãŒãã«èšèŒãããå€ã 人éãäžã€ãã€æäœæ¥ã§æ¯èŒã»ç¢ºèª ããŠãããéå¹çãã€ééããèµ·ãã å¯èœæ§ããã ãšããã話ãããã ããããããã®èšå®å€ãèªåã§æ¯èŒãããµãŒãã¹ãäœããïŒãšããããšã«ãªããŸããã âŠã§ããããã®åŸã®è©±ãåãã®äžã§ã ãããã CloudFormationã®ãã³ãã¬ãŒãããã©ã¡ãŒã¿ã·ãŒãããèªåã§çæ ããŠãããã°ããã®ãããªåé¡ã¯èµ·ãããªã ãšããããšã«ãªããå
è¿°ãããµãŒãã¹ãæ§ç¯ããéã³ãšãªããŸããã ãããå®çŸããããšã«ãããAWSã«ç²ŸéããŠãã人ã¯ãã¡ããã®ããšããããŸã§è©³ãããªã人ã§ãç°¡åã«ãã©ã¡ãŒã¿ã·ãŒããäœæã§ããããã«ãªãããšãæåŸ
ãããŸãã ãã©ã¡ãŒã¿ã·ãŒãèªåçæããã°ã©ã ãã®ããã°ã©ã ã¯äžå³ã«ç€ºããããªæµãã§åäœãããŸããããããã®åŠçã«ã€ããŠãã³ãŒãã®äžéšÂ²ã亀ããªããã玹ä»ããŸãã ²ã³ãŒãã«ã€ããŠã¯èªã¿ã«ããç®æãéå¹çãªåŠçãè¡ã£ãŠããç®æãå€ã
ãããšæããŸãããã容赊ãã ããã ãã©ã¡ãŒã¿ã·ãŒãã®äœæ ãŸãã¯ããã©ã¡ãŒã¿ã·ãŒããäœæããŸãããã©ã¡ãŒã¿ã·ãŒãã¯ãªãœãŒã¹ã®çš®é¡ããšã«äœæããå¿
èŠããããŸãã 以äžã«Lambdaçš IAM – Role ãã©ã¡ãŒã¿ã·ãŒãã®äžäŸã瀺ããŸãã ãã©ã¡ãŒã¿ã·ãŒãã®èªã¿èŸŒã¿ 次ã«CodeCommitã«ã³ãããããããã©ã¡ãŒã¿ã·ãŒãã確èªããŸãããã©ã¡ãŒã¿ã·ãŒãã®ãã¡ã€ã«åãåºã«ãããã°ã©ã å
ã§ã©ã®ãã©ã¡ãŒã¿ã·ãŒããã©ã®ãªãœãŒã¹ã®å
容ãèšè¿°ããŠããã®ããå€å¥ããŸããå€å¥ãè¡ã£ããããã©ã¡ãŒã¿ã·ãŒãããèšå®å€ãåã蟌ã¿ãŸãã以äžã¯ãExcelã§äœæããããã©ã¡ãŒã¿ã·ãŒãããèšå®å€ãååŸãããªã¹ãã«æ ŒçŽããããã°ã©ã ã§ãã def convert(source_dir: str) -> list: book = openpyxl.load_workbook(source_dir) ws = book.worksheets[0] # Read Key and Value data_from_ps = [] # Read from row 1 for row in ws.rows: # liståãšããŠåè¡ã®å€ãæ ŒçŽ key = [] for col_num in range(len(row)): # æ¡ä»¶ïŒå€ãååšããã»ã«ã®ã¿åã蟌ã¿ïŒæçµåãé€ãïŒ if col_num != (len(row) - 1) and (row[col_num].value == None or row[col_num].value == ""): pass else: key.append(row[col_num].value) data_from_ps.append(key) book.close() return data_from_ps ãã®ãªã¹ãããªãœãŒã¹ã«å¿ããèŸæžåã«å€æããŸããAPI Gateway – Accountã®äŸã以äžã«ç€ºããŸãã class AWSApiGatewayAccount: def __init__(self): self.logical_id = "" self.type = "AWS::ApiGateway::Account" self.properties = { "CloudWatchRoleArn" : "" } # Setter def set_resource(self, data: list) -> None: for i in range(len(data)): # åé
ç®ããèšå®é
ç®ã»å€ãååŸ setting_type = data[i][len(data[i])-2] setting_value = data[i][len(data[i])-1] # é
ç®ã«å¿ããŠå€ãæ ŒçŽ if not setting_value: continue if setting_type == "Logical ID": self.logical_id = setting_value elif setting_type == "CloudWatchRoleArn": self.properties["CloudWatchRoleArn"] = setting_value CloudFormationãã³ãã¬ãŒãã®äœæ èšå®å€ãåã蟌ãã ãCloudFormationãã³ãã¬ãŒãã®åœ¢ã«å€æããYAMLãã¡ã€ã«ãçæããŸãã çµã¿èŸŒã¿é¢æ°ïŒ!Sub xxx ãªã©ïŒãèªèãããããã«ã¯ã¯ã©ãŒããŒã·ã§ã³ãå€ãå¿
èŠããã£ãã®ã§ãããã¯ã€ã«ãã«ãŒãã§ããã*ãã«ã€ããŠã¯ã¯ã©ãŒããŒã·ã§ã³ãä»ããªããšãšã©ãŒãåºãŠããŸããšããç¹ã«å°ã
èŠæŠããŸããã def output(source: dict, file_name: str) -> None: with open(file_name, "w") as f: yaml.dump(source, f, sort_keys=False) with open(file_name, "r") as f: contents = f.read() contents = contents.replace("'", "") # *ã¯ã¯ã©ãŒããŒã·ã§ã³ã§æ¬ã£ãŠããªããšãšã©ãŒ contents = contents.replace(" *", " '*'") with open(file_name, "w") as f: f.write(contents) ãªãœãŒã¹ã®è©Šéšæ§ç¯ YAMLãã¡ã€ã«ãçæããããããã®ãã¡ã€ã«ãçšããŠCloudFormationã§ãªãœãŒã¹ã®æ§ç¯ãå®è¡ããæ£ããæ§ç¯ãã§ããã確èªãè¡ããŸããåŸæ®µã®äœæ¥ã®ããã«waiterãèšå®ããæ§ç¯ãçµãããŸã§åŸ
æ©ããŸãã ä»å㯔create_stack”颿°ãçŽæ¥åŒã³åºããŠããŸãããããã§ã¯ã¹ã¿ãã¯äœæã«å€±æããéã«äŸå€ãšã©ãŒãšãªãã®ã§ãäŸå€ããã£ããããä»çµã¿ããäºåã«ãã³ãã¬ãŒãã®åŠ¥åœæ§ãæ€èšŒãã “validate_template”颿° ãæ¿å
¥ããŠãè¯ããšæããŸãã def convert(yaml_path: str, stack_name: str) -> None: f = open(yaml_path, "r") template_body = f.read() f.close() cfn = boto3.client("cloudformation") response = cfn.create_stack( StackName=stack_name, TemplateBody=template_body, Capabilities=[ "CAPABILITY_NAMED_IAM", ], ) waiter = cfn.get_waiter("stack_create_complete") waiter.wait(StackName=stack_name) äžèšã³ãŒãã§ã¹ã¿ãã¯ãäœæãã颿°ãcreate_stackãã®åŒæ°ã«ãCapabilitiesãã远å ããŠããŸããããã¯ãIAMã«é¢é£ãããªãœãŒã¹ãäœæããããã«è¡ã£ãŠãããã®ã§ãã æ£ããæ§ç¯ã§ããããæ§ç¯ããããªãœãŒã¹ã«ã¢ã¯ã»ã¹ãããªãœãŒã¹ã®èšå®å€ãååŸããŸãã # Get properties from AWS def get_resource(self, logical_resource_id: str, physical_resource_id: str, stack_name: str) -> None: # æ§ææ
å ±ã®ååŸ client = boto3.client("apigateway") response = client.get_account() self.logical_id = logical_resource_id self.properties["CloudWatchRoleArn"] = response["cloudwatchRoleArn"] ååŸãããªãœãŒã¹ã®èšå®å€ãšããã©ã¡ãŒã¿ã·ãŒãã®å€ãäžã€ã®ã¯ã©ã¹ã«éçŽããŸãã # 2ã€ã®ãªãœãŒã¹ãã¡ã€ã«ã®çµæãäžã€ã«ãŸãšãã def summarize_properties(self, cfn_template: dict) -> dict: logical_ids = [self.logical_id, cfn_template.logical_id] summary = template.summary.Summary(logical_ids, self.type) if self.properties["CloudWatchRoleArn"]: key = summary.key_default.copy() key.append("CloudWatchRoleArn") value = [self.properties["CloudWatchRoleArn"], cfn_template.properties["CloudWatchRoleArn"]] summary.properties[tuple(key)] = value return summary èšå®å€ã®æ¯èŒ ååŸããèšå®å€ãšããã©ã¡ãŒã¿ã·ãŒãã®å€ãçãããã©ããã確èªããŸãã def compare(all_resources: list) -> list: compared_resources = all_resources.copy() # 1ã€ãã€ã®ãªãœãŒã¹ã®å€ãæ¯èŒ for resource in compared_resources: property = resource.properties # 1ã€ãã€ã®èšå®å€ãæ¯èŒ for key, values in property.items(): # èšå®å€ã®åã«ããåŠçãåå² if type(values[0]) == list: for val in values: result = val[0] == val[1] val.append(result) else: # èšå®å€ã®ç¢ºèª result = values[0] == values[1] values.append(result) property[key] = values return compared_resources ãã¡ã€ã«ã®åºåã»æçµåŠç æçµçã«ãçæããYAMLãã¡ã€ã«ãšå€ã®æ¯èŒçµæããŸãšããExcelãã¡ã€ã«ãS3ã«åºåããåŸã«ãè©Šéšæ§ç¯ãããªãœãŒã¹ãåé€ããåŠçã¯å®äºã§ãã åãçµãã ææ³ ä»åã¯æ°äººãšããŠã®åãçµã¿ãšããããšã§ãLambdaãAPI Gatewayã®äžéšã®ãªãœãŒã¹ã®ã¿ã察象ã«ããŸãããæ§ç¯ããéã«ããããã®CloudFormationã®ããã¥ã¡ã³ããèªã¿èŸŒãã ã®ã§ãCloudFormationã®ä»çµã¿ã«ã€ããŠçè§£ãæ·±ããããšãã§ããã»ãããªãœãŒã¹ãã©ã®ããã«æ§ç¯ãããã®ãããããããã©ã®ãããªãªãã·ã§ã³ãæã£ãŠããã®ãã詳ããç¥ãããšãã§ããŸãããç¹ã«API Gatewayã§ã¯ãç°ãªããªãœãŒã¹ã§åããããªèšå®é
ç®ãããã€ããã£ãããšãè峿·±ãã£ãã§ãã äžæ¹ã§ãªãœãŒã¹ã®å€ãååŸããboto3ã®é¢æ°ïŒget_xxxxxïŒã®åºåã«ã€ããŠãåããããªé
ç®ã§ãè¡šèšæ¹æ³ãç°ãªããã®ããããæžæãããšããããŸããã äŸãã°ã¿ã°ã«ã€ããŠèŠãŠã¿ããšãIAMããŒã«ã®æ
å ±ãå
¥æãã”get_role”ã§ã¯ã 'Tags' : [ { 'Key' : 'string' , 'Value' : 'string' }, ] ãšãªã£ãŠããã®ã«å¯ŸããŠãLambda颿°ã®æ
å ±ãå
¥æãã”get_function”ã§ã¯ã 'Tags' : { 'string' : 'string' } ãšãªã£ãŠãããKeyãšValueã®æ ŒçŽæ¹æ³ãç°ãªã£ãŠããããšãåãããŸãããŸããAPI Gatewayã®ã¹ããŒãžã®æ
å ±ãååŸãã”get_stage”ã§ã¯ã ' tags ' : { 'string' : 'string' } ãšãã¿ã°ã®Keyãã®ãã®ãå°æåã§è¡šèšãããŠããŸãã ãªãæ ŒçŽæ¹æ³ã衚èšãç°ãªã£ãŠããã®ãã¯ç§ã«ã¯åãããŸããããçµ±äžããŠããããšåããããããªãã®ã§ã¯ãªãããªããšæããŸããã get_role - Boto3 1.34.6 documentation boto3.amazonaws.com get_function - Boto3 1.34.6 documentation boto3.amazonaws.com get_stage - Boto3 1.34.6 documentation boto3.amazonaws.com ä»åŸã¯ãæåã®å·¥çšã§ãããã©ã¡ãŒã¿ã·ãŒãã®äœæãããåãããããæ¹è¯ããŠããããããŠä»ã®ãªãœãŒã¹ã«ã€ããŠã察å¿ã§ããããã«æ¡åŒµãããŠãããããªãšèããŠãããŸãã æåŸãŸã§ã芧ããã ããããããšãããããŸããïŒ