
- TOP
- ã¿ã°äžèЧ
- Cisco
Cisco
ã€ãã³ã
ãã¬ãžã³
該åœããã³ã³ãã³ããèŠã€ãããŸããã§ãã
æè¡ããã°
ã¯ããã« JANOG57 NOC BackboneããŒã ã§ã¹ã¯ã©ã ãã¹ã¿ãŒçãªåããããŠããhokkai7goã§ãã JANOGãšã¯JApan Network Operators' Groupãæå³ããã€ã³ã¿ãŒãããã«æŒ […]
æ¬ããã°ã¯ 2026 幎 3 æ 18 æ¥ã«å
¬éããã AWS Blog â Amazon threat intelligence teams identify Interlock ransomware campaign targeting enterprise firewalls â ã翻蚳ãããã®ã§ãã Amazon Threat Intelligence ã¯ãCisco Secure Firewall Management Center (FMC) Software ã®é倧ãªèåŒ±æ§ CVE-2026-20131 ãæªçšãã Interlock ã©ã³ãµã ãŠã§ã¢ã®ã¢ã¯ãã£ããªãã£ã³ããŒã³ã確èªããŸããããã®è匱æ§ã¯ãèªèšŒãå¿
èŠãšããã«ãªã¢ãŒãã®æ»æè
ã察象ããã€ã¹äžã§ root æš©éã«ããä»»æã® Java ã³ãŒããå®è¡ã§ãããšãããã®ã§ã2026 幎 3 æ 4 æ¥ã« Cisco ãå
¬éããŸããã Cisco ã«ãã è匱æ§ã®å
¬é ãåããAmazon Threat Intelligence 㯠Amazon MadPot ã®ã°ããŒãã«ã»ã³ãµãŒãããã¯ãŒã¯ã䜿çšããŠããã®è匱æ§ã®èª¿æ»ãéå§ããŸãããAmazon MadPot ã¯ããµã€ããŒç¯çœªè
ã®ã¢ã¯ãã£ããã£ããã³ãå¯ããŠç£èŠãããããŒããããµãŒããŒã®ã·ã¹ãã ã§ããéå»ããçŸåšã«ãããŠã®ãšã¯ã¹ããã€ãã調æ»ããçµæãInterlock ãè匱æ§å
¬éã® 36 æ¥åã«ããã 2026 幎 1 æ 26 æ¥ããæªçšãéå§ããŠããããšã倿ããŸãããããã¯åãªãè匱æ§ã®æªçšã§ã¯ãããŸããã§ãããInterlock ã¯ãŒããã€ãæã«ããŠãããé²åŸ¡åŽããã®è匱æ§ã®ååšãèªèãããããåã«ãçµç¹ã䟵害ããããã®æ°é±éã®ç¶äºãåŸãŠããã®ã§ãããã®çºèŠãåããŠãAWS 㯠Cisco ã®èª¿æ»ãæ¯æŽãããšãšãã«ã客æ§ãä¿è·ããããã調æ»çµæã Cisco ãšå
±æããŸããã èšå®ã«èª€ãã®ãã£ãã€ã³ãã©ã¹ãã©ã¯ãã£ãµãŒããŒãã€ãŸãæ»æè
ã䜿çšããŠããã»ãã¥ãªãã£ãäžååãªã¹ããŒãžã³ã°é åãããInterlock ã®æ»æããŒã«ãããã®å
šå®¹ãæããã«ãªããŸããããã®ãŸããªèšå®ãã¹ã«ãããAmazon ã®ã»ãã¥ãªãã£ããŒã ã¯ãã©ã³ãµã ãŠã§ã¢ã°ã«ãŒãã®å€æ®µéæ»æãã§ãŒã³ãã«ã¹ã¿ã ã®ãªã¢ãŒãã¢ã¯ã»ã¹åããã€ã®æšéЬ (RATãæ»æè
ã䟵害ããã·ã¹ãã ããªã¢ãŒãå¶åŸ¡ããããã®ããã¯ãã¢ããã°ã©ã )ãåµå¯ã¹ã¯ãªãã (被害è
ã®ãããã¯ãŒã¯ããããã³ã°ããèªååããŒã«)ãããã³åé¿ãã¯ããã¯ã®å
šå®¹ãææ¡ããããšãã§ããŸããã ä»åã®ãã£ã³ããŒã³ã«ãããŠãAWS ã€ã³ãã©ã¹ãã©ã¯ãã£ã AWS äžã®ã客æ§ã®ã¯ãŒã¯ããŒãã圱é¿ãåããäºå®ã¯ç¢ºèªãããŠããŸãããæ¬ã¢ããã€ã¶ãªã§ã¯ãæœåšçãªäŸµå®³ã®ç¹å®ãš Interlock ã®æŽ»åããã®é²åŸ¡ã«åœ¹ç«ãŠãŠããã ãããããå
æ¬çãªæè¡åæãšäŸµå®³ã€ã³ãžã±ãŒã¿ (IoC) ãå
±æããŸããCisco Secure Firewall Management Center ã䜿çšããŠããçµç¹ã¯ãCisco ã®ã»ãã¥ãªãã£ããããçŽã¡ã«é©çšãã以äžã«ç€ºã IoC ã確èªããŠãã ããã çºèŠãšèª¿æ»ã®ã¿ã€ã ã©ã€ã³ Amazon Threat Intelligence ã¯ãCVE-2026-20131 ã«é¢é£ããå¯èœæ§ã®ããè
åšã¢ã¯ãã£ããã£ããè匱æ§ã®å
¬éã«å
ç«ã€ 2026 幎 1 æ 26 æ¥ããçºçããŠããããšãç¹å®ããŸããã確èªãããã¢ã¯ãã£ããã£ã«ã¯ã圱é¿ãåãããœãããŠã§ã¢ã®ç¹å®ã®ãã¹ã«å¯Ÿãã HTTP ãªã¯ãšã¹ããå«ãŸããŠããŸããããªã¯ãšã¹ãæ¬æã«ã¯ãJava ã³ãŒãã®å®è¡ã詊ã¿ãã³ãŒããš 2 ã€ã®åã蟌㿠URL ãå«ãŸããŠããŸããã1 ã€ã¯ãšã¯ã¹ããã€ãã«å¿
èŠãªèšå®ããŒã¿ã®é
ä¿¡çšã§ããã 1 ã€ã¯è匱ãªã¿ãŒã²ãããã HTTP PUT ãªã¯ãšã¹ãã§çæãã¡ã€ã«ãã¢ããããŒããããæªçšã®æåã確èªããããã®ãã®ã§ãããè€æ°ã®ãšã¯ã¹ããã€ã詊è¡ãéããŠããããã® URL ã«ããŸããŸãªããªãšãŒã·ã§ã³ã確èªãããŸããã 調æ»ãããã«é²ããè
åšã€ã³ããªãžã§ã³ã¹ãåŸããããAWS ã¯æ³å®ããããã¡ã€ã«å
容ãå«ã HTTP PUT ãªã¯ãšã¹ããéä¿¡ããäŸµå®³ã«æåããã·ã¹ãã ãè£
ããŸãããããã«ãã Interlock ã¯æ»æã®æ¬¡ã®ã¹ããŒãžã«é²ã¿ããªã¢ãŒããµãŒããŒããæªæã®ãã ELF ãã€ã㪠(Linux å®è¡ãã¡ã€ã«) ãããŠã³ããŒãããŠå®è¡ããã³ãã³ããéä¿¡ããŠããŸããã ã¢ããªã¹ãããã®ãã€ããªãååŸãããšãããåäžã®ãã¹ã (æ»æè
ãå¶åŸ¡ãããµãŒããŒ) ã Interlock ã®æ»æããŒã«ãããå
šäœã®é
åžã«ã䜿çšãããŠããããšã倿ããŸããããã®å€éšã«é²åºããŠããã€ã³ãã©ã¹ãã©ã¯ãã£ã§ã¯ãã¢ãŒãã£ãã¡ã¯ããæšçããšã«åå¥ã®ãã¹ã§æŽçãããŠããã䟵害ãããã¹ããžã®ããŒã«ã®ããŠã³ããŒããšã¹ããŒãžã³ã°ãµãŒããŒãžã®ã¢ãŒãã£ãã¡ã¯ãã®ã¢ããããŒãã®äž¡æ¹ã«åããã¹ã䜿çšãããŠããŸããã Interlock ã©ã³ãµã ãŠã§ã¢ãžã®ã¢ããªãã¥ãŒã·ã§ã³ ELF ãã€ããªãšé¢é£ã¢ãŒãã£ãã¡ã¯ãã¯ãæè¡çããã³éçšé¢ã®ææšã®äžèŽãããInterlock ã©ã³ãµã ãŠã§ã¢ãã¡ããªãŒã«ãããã®ãšå€æãããŸããåã蟌ãŸããã©ã³ãµã ããŒããš TOR äžã®èº«ä»£é亀æžããŒã¿ã«ã¯ãInterlock ãåŸæ¥äœ¿çšããŠããç¹åŸŽçãªæå£ãã€ã³ãã©ã¹ãã©ã¯ãã£ãšåèŽããŠããŸããã©ã³ãµã ããŒãã§è€æ°ã®ããŒã¿ä¿è·èŠå¶ã«èšåããŠããããšã¯ãèŠå¶äžã®ãªã¹ã¯ãææããŠè¢«å®³è
ã«å§åãããããšãã Interlock ã®æ¢ç¥ã®ææ³ãåæ ããŠããŸããããŒã¿ã®æå·åã ãã§ãªããèŠå¶äžã®çœ°éãã³ã³ãã©ã€ã¢ã³ã¹éåããå©çšããŠçµç¹ãè
è¿«ããæå£ã§ããã©ã³ãµã ããŒãã«åã蟌ãŸãããã£ã³ããŒã³åºæã®çµç¹èå¥åããInterlock ã被害è
ããšã«è¿œè·¡ãè¡ãã¢ãã«ãšäžèŽããŠããŸãã Interlock ã¯ãããŸã§ãæ¥åã®äžæãèº«ä»£éæ¯æããžã®å€§ããªå§åãšãªãç¹å®ã®ã»ã¯ã¿ãŒãæšçãšããŠããŸãããæšçãšããŠæãå€ãã®ã¯æè²ã»ã¯ã¿ãŒã§ã次ãã§ãšã³ãžãã¢ãªã³ã°ã»å»ºç¯ã»å»ºèšäŒæ¥ã補é ã»ç£æ¥çµç¹ãå»çæ©é¢ãæ¿åºã»å
Œ
±ã»ã¯ã¿ãŒã®é ãšãªã£ãŠããŸãã 芳枬ãããè
åšã¢ã¯ãã£ããã£ã®ã¿ã€ã ã¹ã¿ã³ããèšå®ã«èª€ãã®ãã£ãã€ã³ãã©ã¹ãã©ã¯ãã£ãµãŒããŒäžã®ã¢ãŒãã£ãã¡ã¯ããããã³ååŸããè
åšã¢ãŒãã£ãã¡ã¯ãã«åã蟌ãŸããã¡ã¿ããŒã¿ã®æéåæããããã®è
åšã¢ã¯ã¿ãŒã¯ 75ïœ80% ã®ç¢ºåºŠã§ UTC+3 ã¿ã€ã ãŸãŒã³ã«ãããŠæŽ»åããŠãããšæšå®ãããŸãããã¹ãŠã® UTC ãªãã»ããã察象ãšããäœç³»çãªåæã®çµæãUTC+3 ãæãäžèŽããŸãããã¢ã¯ãã£ããã£ã®éå§ã¯ 08:30 é ãããŒã¯ã¯ 12:00ïœ18:00ãæšå®ãããéæŽ»åæé垯㯠00:30ïœ08:30 ã§ããã å³ 1: Interlock ã©ã³ãµã ãŠã§ã¢ã®èº«ä»£é亀æžããŒã¿ã«ã被害è
ãçµç¹ ID ãšã¡ãŒã«ã¢ãã¬ã¹ãå
¥åããèªèšŒããŒã¯ã³ãåãåã£ãŠäº€æžãã£ããã»ãã·ã§ã³ãéå§ãã æè¡åæ: Interlock ã®æ»æããŒã«ããã 䟵害åŸã®åµå¯ã¹ã¯ãªãã Interlock ã¯åæã¢ã¯ã»ã¹ãç²åŸããåŸãããŸããŸãªããŒã«ã䜿çšããŠæ»æãå±éããŸããAmazon Threat Intelligence ããŒã ã¯ãWindows ç°å¢ãäœç³»çã«åæãã (被害è
ã®ãããã¯ãŒã¯æ
å ±ãèªååéãã) PowerShell ã¹ã¯ãªãããååŸããŸããããã®ã¹ã¯ãªããã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãšããŒããŠã§ã¢ã®è©³çްãå®è¡äžã®ãµãŒãã¹ãã€ã³ã¹ããŒã«æžã¿ãœãããŠã§ã¢ãã¹ãã¬ãŒãžæ§æãHyper-V ä»®æ³ãã·ã³ã€ã³ãã³ããªããã¹ã¯ãããã»ããã¥ã¡ã³ãã»ããŠã³ããŒãã®åãã£ã¬ã¯ããªã«ããããŠãŒã¶ãŒãã¡ã€ã«äžèЧãChromeãEdgeãFirefoxãInternet Explorerã360 ãã©ãŠã¶ããã®ãã©ãŠã¶ã¢ãŒãã£ãã¡ã¯ã (å±¥æŽãããã¯ããŒã¯ãä¿åãããèªèšŒæ
å ±ãæ¡åŒµæ©èœãå«ã)ãããã»ã¹ã«é¢é£ä»ããããã¢ã¯ãã£ããªãããã¯ãŒã¯æ¥ç¶ãARP ããŒãã«ãiSCSI ã»ãã·ã§ã³ããŒã¿ãããã³ Windows ã€ãã³ããã°ããã® RDP èªèšŒã€ãã³ããåéããŸãã ãã®ã¹ã¯ãªããã¯ãåã·ã¹ãã ã®å®å
šä¿®é£Ÿãã¹ãåã«åºã¥ããŠå°çšãã£ã¬ã¯ããªãäœæããçµæãéçŽçšãããã¯ãŒã¯å
±æ (\JK-DC2\Temp) ã«ã¹ããŒãžã³ã°ããŸããã€ãŸãã䟵害ããåã³ã³ãã¥ãŒã¿ã«ãã©ã«ããäœæãããŸããåéãå®äºãããšãããŒã¿ã¯ãã¹ãåã«åºã¥ãååã® ZIP ã¢ãŒã«ã€ãã«å§çž®ãããå
ã®çããŒã¿ã¯åé€ãããŸãããã®ãããªãã¹ãåäœã®æ§é åãããåºå圢åŒã¯ãã¹ã¯ãªããããããã¯ãŒã¯å
ã®è€æ°ãã·ã³ã«ãŸããã£ãŠå®è¡ãããŠããããšã瀺ããŠãããçµç¹å
šäœã®æå·åã«åããæºåãè¡ãã©ã³ãµã ãŠã§ã¢äŸµå
¥ãã§ãŒã³ã®å
žåçãªç¹åŸŽã§ãã ã«ã¹ã¿ã ãªã¢ãŒãã¢ã¯ã»ã¹åããã€ã®æšéЬ ãªã¢ãŒãã¢ã¯ã»ã¹åããã€ã®æšéЬ (RAT) ãšã¯ãæ»æè
ã䟵害ããã·ã¹ãã ãžã®æç¶çãªå¶åŸ¡ãå¯èœã«ããæªæã®ããããã°ã©ã ã§ãããäžæ£ãªãªã¢ãŒããã¹ã¯ããããœãããŠã§ã¢ã®ããã«æ©èœããŸãã JavaScript ã€ã³ãã©ã³ã: Amazon Threat Intelligence ã¯ãé£èªåããã JavaScript ããŒã¹ã® RAT ãååŸããŸããããã® RAT ã¯ãã©ãŠã¶ã³ã³ãœãŒã«ã®ã¡ãœããããªãŒããŒã©ã€ãããŠãããã°åºåãæå¶ããåºæ¬çãªæ€åºããŒã«ããã¢ã¯ãã£ããã£ãé èœããŸããå®è¡æã«ã¯ãPowerShell ãš Windows Management Instrumentation (WMI) ã䜿çšããŠææãã¹ãã®ãããã¡ã€ãªã³ã°ãè¡ããã·ã¹ãã IDããã¡ã€ã³ã¡ã³ããŒã·ããããŠãŒã¶ãŒåãOS ããŒãžã§ã³ãæš©éã³ã³ããã¹ããåéããäžã§ãæå·åãããåæåãã³ãã·ã§ã€ã¯ã§ãããã®ããŒã¿ãéä¿¡ããŸãã ã³ãã³ãã¢ã³ãã³ã³ãããŒã« (C2) éä¿¡ã«ã¯æ°žç¶ç㪠WebSocket æ¥ç¶ã䜿çšãããã¡ãã»ãŒãžããšã«ãã±ããããããŒã«åã蟌ãŸãã 16 ãã€ãã®ã©ã³ãã ããŒã«ãã RC4 æå·åãé©çšãããŸããåã¡ãã»ãŒãžãç°ãªãæå·åããŒã䜿çšãããããååãããå°é£ã«ãªãä»çµã¿ã§ããã€ã³ãã©ã³ãã¯ããªãã¬ãŒã¿ãŒãå¶åŸ¡ããè€æ°ã®ãã¹ãåãš IP ã¢ãã¬ã¹ãã©ã³ãã ãªé åºã§å·¡åãã忥ç¶è©Šè¡éã«ã¯ãšã¯ã¹ããã³ã·ã£ã«ããã¯ãªããé©çšããŸãã ãã®ã€ã³ãã©ã³ãã¯ãã€ã³ã¿ã©ã¯ãã£ããªã·ã§ã«ã¢ã¯ã»ã¹ãä»»æã®ã³ãã³ãå®è¡ãåæ¹åãã¡ã€ã«è»¢éãTCP ãã©ãã£ãã¯ã®ãã³ããªã³ã°ã«å¯Ÿå¿ãã SOCKS5 ãããã·æ©èœ (æªæã®ãããã©ãã£ãã¯ãä»ã®ã·ã¹ãã çµç±ã§ã«ãŒãã£ã³ã°ããŠçºä¿¡å
ãé èœ) ãšãã£ãæ©èœãåããŠããŸãããŸããèªå·±æŽæ°ããã³èªå·±åé€ã®æ©èœãããããªãã¬ãŒã¿ãŒã¯åææã䌎ããã«ã€ã³ãã©ã³ãã眮æãŸãã¯åé€ã§ãããã©ã¬ã³ãžãã¯èª¿æ»ã劚害ããçè·¡æ¶å»ã«ã察å¿ããŸãã Java ã€ã³ãã©ã³ã: Java ã§å®è£
ãããæ©èœçã«åçã®ã¯ã©ã€ã¢ã³ããååšããåäžã® C2 æ©èœãæäŸããŸããGlassFish ãšã³ã·ã¹ãã ã©ã€ãã©ãªäžã«æ§ç¯ãããŠããããã³ããããã³ã° I/O ãã©ã³ã¹ããŒãã«ã¯ Grizzly ããWebSocket ãããã³ã«éä¿¡ã«ã¯ Tyrus ã䜿çšããŠããŸããã€ãŸã Interlock ã¯ãåãããã¯ãã¢ã 2 ã€ã®ç°ãªãããã°ã©ãã³ã°èšèªã§æ§ç¯ããããšã§ãé²åŸ¡åŽãäžæ¹ã®ããŒãžã§ã³ãæ€åºããå Žåã§ãã¢ã¯ã»ã¹ã確å®ã«ç¶æã§ããããã«ããŠããã®ã§ãã ã€ã³ãã©ã¹ãã©ã¯ãã£ãã³ããªã³ã°ã¹ã¯ãªãã é«åºŠãªè
åšã¢ã¯ã¿ãŒã¯èªèº«ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ããçŽæ¥æ»æã仿ããã®ã§ã¯ãªããäœ¿ãæšãŠã®äžç¶ãããã¯ãŒã¯ãæ§ç¯ããŠçè·¡ãé èœããŸããAmazon Threat Intelligence ããŒã ã¯ãLinux ãµãŒããŒã HTTP ãªããŒã¹ãããã· (æ»æè
ã®å®éã®æåšå°ãé ãããã«ãã©ãã£ãã¯ã転éããäžéãµãŒããŒ) ãšããŠæ§æãã Bash ã¹ã¯ãªãããç¹å®ããŸããããã®ã¹ã¯ãªããã¯ãã·ã¹ãã ã¢ããããŒãã®å®è¡ãSSH ãã«ãŒããã©ãŒã¹ä¿è·æ©èœãæã€ fail2ban ã®ã€ã³ã¹ããŒã«ãHAProxy 3.1.2 ã®ãœãŒã¹ããã®ã³ã³ãã€ã«ãè¡ããŸããæ§æããã HAProxy ã€ã³ã¹ã¿ã³ã¹ã¯ããŒã 80 ã§ãªãã¹ã³ãããã¹ãŠã®ã€ã³ããŠã³ã HTTP ãã©ãã£ãã¯ãããŒãã³ãŒããããã¿ãŒã²ãã IP ã«è»¢éããŸãããŸããsystemd ã«ããã·ã¹ãã åèµ·ååŸãæç¶æ§ã確ä¿ãããŸãã ç¹ã«æ³šç®ãã¹ãã³ã³ããŒãã³ããã5 åããšã« cron ãžã§ããšããŠå®è¡ããããã°æ¶å»ã«ãŒãã³ã§ãããã®ã«ãŒãã³ã¯ /var/log é
äžã®ãã¹ãŠã® *.log ãã¡ã€ã«ãåãè©°ããHISTFILE 倿°ãã¢ã³ã»ããããŠã·ã§ã«å±¥æŽãæå¶ããŸãã5 åééã§ãã°ãæ¶å»ãããã®ç©æ¥µçãªèšŒæ ç Žå£ã¯ãå°çšã«æ§ç¯ããã HTTP 転éãããã·ãšçµã¿åãããŠèãããšããã®ã¹ã¯ãªãããäœ¿ãæšãŠã®ãã©ãã£ãã¯ãã³ããªã³ã°çšäžç¶ããŒãã®æ§ç¯ãç®çãšããŠããããšã瀺ããŠããŸãããããã®ããŒãã¯ããšã¯ã¹ããã€ããã©ãã£ãã¯ã®çºä¿¡å
é èœãC2 éä¿¡ã®äžç¶ãããŒã¿çªåã®ãããã·ãšããŠæ©èœããæ»æã®çºä¿¡æºãžã®è¿œè·¡ãã»ãŒäžå¯èœã«ããŸãã ã¡ã¢ãªåžžé§å Web ã·ã§ã« Amazon Threat Intelligence ããŒã ã¯ãELF ãã€ããªã®æäžã«ä»£ããææ®µãšããŠé
ä¿¡ããã Java ã¯ã©ã¹ãã¡ã€ã«ã確èªããŸãããJava Virtual Machine (JVM) ã«ãã£ãŠããŒãããããšãéçã€ãã·ã£ã©ã€ã¶ãããµãŒããŒã® StandardContext ã« ServletRequestListener ãç»é²ãããã£ã¹ã¯ãžã®ãã¡ã€ã«æžã蟌ã¿ãäžåè¡ããã« HTTP ãªã¯ãšã¹ããååããæ°žç¶çãªã¡ã¢ãªåžžé§åããã¯ãã¢ãã€ã³ã¹ããŒã«ããŸãããã®ããã¡ã€ã«ã¬ã¹ãã¢ãããŒãã«ãããæªæã®ãããã¡ã€ã«ãæ¢çŽ¢ããåŸæ¥ã®ãŠã€ã«ã¹å¯Ÿçã¹ãã£ã³ãåé¿ããããšãå¯èœã«ãªããŸãã ãªã¹ããŒã¯åä¿¡ãªã¯ãšã¹ããæ€æ»ããæå·åãããã³ãã³ããã€ããŒããå«ãç¹æ®ãªãã©ã¡ãŒã¿ã®æç¡ã確èªããŸãããã€ããŒãã¯ãããŒãã³ãŒããããã·ãŒãå€ âgeckoformboundary99fec155ea301140cbe26faf55ed2f40â ã® MD5 ããã·ã¥ããå°åºãããã㌠(å
é 16 æåã® 09b1a8422e8faed0 ã䜿çš) ã«ãã AES-128 ã§åŸ©å·ãããŸãã埩å·ããããã€ããŒãã¯ã³ã³ãã€ã«æžã¿ã® Java ãã€ãã³ãŒããšããŠæ±ãããJVM ã«åçã«ããŒããããŠå®è¡ãããŸããããã¯ãæªæã®ããã³ãŒããå®å
šã«ã¡ã¢ãªå
ã§å®è¡ããããšã§ããã¡ã€ã«ããŒã¹ã®æ€åºãåé¿ããããã«èšèšããããã¯ããã¯ã§ãã æ¥ç¶ç¢ºèªããŒã« Amazon Threat Intelligence ããŒã ã¯ãããŒã 45588 ã§ãªãã¹ã³ããåºæ¬ç㪠TCP ãµãŒããŒãå®è£
ãã Java ã¯ã©ã¹ãã¡ã€ã«ãååŸããŸãã (ããŒãçªå·ã¯éçåæã«ããç¹å®ãå°é£ã«ãããããUnicode æå ë ãšããŠãšã³ã³ãŒããããŠããŸãã)ããµãŒããŒã¯æ¥ç¶ãåãå
¥ãããšãæ¥ç¶å
ã® IP ã¢ãã¬ã¹ããã°ã«èšé²ããæšæ¶ã¡ãã»ãŒãžãéä¿¡ããåŸãå³åº§ã«æ¥ç¶ãåæããŸãããã®åäœãã¿ãŒã³ã¯ãåæãšã¯ã¹ããã€ãå®è¡åŸã®ã³ãŒãå®è¡æå確èªããããã¯ãŒã¯ããŒããžã®å°éæ§ç¢ºèªã«äœ¿çšããã軜éãªãããã¯ãŒã¯ããŒã³ã³ (ããããããã©ã³ããŒã ãããŒã«) ã®ç¹åŸŽãšäžèŽããŠããŸãã æ£èŠããŒã«ã®æªçš Interlock ã¯ã«ã¹ã¿ã ã€ã³ãã©ã³ããšäžŠè¡ããŠãæ£èŠã®åçšãªã¢ãŒããã¹ã¯ãããããŒã«ã§ãã ConnectWise ScreenConnect ããããã€ããŠããŸãããã©ã³ãµã ãŠã§ã¢ãªãã¬ãŒã¿ãŒãæ£èŠã®ãªã¢ãŒãã¢ã¯ã»ã¹ããŒã«ãã«ã¹ã¿ã ãã«ãŠã§ã¢ãšäœµçšããã®ã¯ãããã°ä¿éºããããŠãããããªãã®ã§ããé²åŸ¡åŽã 1 ã€ã®ããã¯ãã¢ãçºèŠããŠé€å»ããŠããå¥ã®äŸµå
¥çµè·¯ãæ®ããŸããããã¯åé·ãªãªã¢ãŒãã¢ã¯ã»ã¹ææ®µãè€æ°ç¢ºä¿ãããã¿ãŒã³ã§ãããåã
ã®è¶³å Žãé€å»ãããŠãã¢ã¯ã»ã¹ãç¶æããããšããã©ã³ãµã ãŠã§ã¢ãªãã¬ãŒã¿ãŒã®å
žåçãªææ³ãšäžèŽããŠããŸããæ£èŠããŒã«ãªãã§ã¯ã®ãããã¯ãŒã¯ãããããªã³ãã«ãããèš±å¯ããããªã¢ãŒã管çãã©ãã£ãã¯ã«çŽã蟌ãããšãã§ããæ€åºãããã«å°é£ã«ãªããŸãã Amazon Threat Intelligence ããŒã ã¯ãã€ã³ã·ãã³ãã¬ã¹ãã³ããŒãåºã䜿çšãããªãŒãã³ãœãŒã¹ã®ã¡ã¢ãªãã©ã¬ã³ãžãã¯ãã¬ãŒã ã¯ãŒã¯ã§ãã Volatility ãååŸããŸãã (é²åŸ¡åŽãæ»æèª¿æ»ã«äœ¿çšããã®ãšåãããŒã«ã§ã)ãèªååããã䜿çšã瀺ãã¢ãŒãã£ãã¡ã¯ãã¯ç¢ºèªãããªãã£ããã®ã®ãã«ã¹ã¿ã ã€ã³ãã©ã³ããåµå¯ã¹ã¯ãªãããšãšãã«é
眮ãããŠããããšã¯ãé«åºŠãªè
åšãªãã¬ãŒã·ã§ã³ã®ç¹åŸŽãšåèŽããŠããŸããã©ã³ãµã ãŠã§ã¢ã°ã«ãŒããšåœå®¶æ¯æŽåã¢ã¯ã¿ãŒã®åæ¹ãã䟵å
¥æã« Volatility ããããã€ããŠããããšã確èªãããŠããŸããã¡ã¢ãªãã³ãã®è§£æã«ç¹åãããã®ããŒã«ã¯ãRAM ã«ä¿åãããèªèšŒæ
å ±ãªã©ã®æ©å¯ããŒã¿ãžã®ã¢ã¯ã»ã¹ãå¯èœã«ããã©ãã©ã«ã ãŒãã¡ã³ã (ãããã¯ãŒã¯å
ã®æšªå±é) ãããæ·±ãç°å¢äŸµå®³ãéããŠã©ã³ãµã ãŠã§ã¢ãªãã¬ãŒã·ã§ã³ãã¹ãã€æŽ»åãæ¯æŽããŸãã ããã« Interlock ã¯ãActive Directory Certificate Services (AD CS) ã®èšå®ãã¹ãæªçšããããã®ãªãŒãã³ãœãŒã¹ã®æ»æçã»ãã¥ãªãã£ããŒã«ã§ãã Certify ã䜿çšããŠããŸãããã©ã³ãµã ãŠã§ã¢ãªãã¬ãŒã¿ãŒã«ãšã£ãŠãCertify ã¯è匱ãªèšŒææžãã³ãã¬ãŒãããèªèšŒçšèšŒææžã®èŠæ±ãèš±å¯ããç»é²æš©éãç¹å®ããææ®µãšãªããŸããååŸããèšŒææžã¯ããŠãŒã¶ãŒã®ãªãããŸããæš©éã®ææ Œãæ°žç¶çãªã¢ã¯ã»ã¹ã®ç¶æã«æªçšã§ããŸãããããã®æ©èœã¯ãã©ã³ãµã ãŠã§ã¢ãªãã¬ãŒã·ã§ã³ã«ãããåæäŸµå®³ãšé·æçãªæ°žç¶åã®åæ¹ãçŽæ¥æ¯æŽãããã®ã§ãã 䟵害ã€ã³ãžã±ãŒã¿ (IoC) 以äžã®ã€ã³ãžã±ãŒã¿ã¯ã圱é¿ãåããå¯èœæ§ã®ããçµç¹ã§ã®é²åŸ¡ã«åœ¹ç«ãŠãããšãã§ããŸããInterlock ã¯ã³ã³ãã³ãããªãšãŒã·ã§ã³ææ³ã䜿çšããŠãããããã»ãšãã©ã®ãã¡ã€ã«ããã·ã¥ã¯ä¿¡é Œæ§ã®é«ãã€ã³ãžã±ãŒã¿ãšããŠã¯æ²èŒããŠããŸãããè
åšã¢ã¯ã¿ãŒã¯ãç°ãªãã¿ãŒã²ããã«é
ä¿¡ããã¹ã¯ãªããããã€ããªãªã©ã®ã¢ãŒãã£ãã¡ã¯ãã«éæ¬¡å€æŽãå ããŠãããæ©èœçã«ã¯åäžã®ããŒã«ã§ãã£ãŠããã¡ã€ã«ããã·ã¥ãç°ãªããã®ãšãªã£ãŠããŸããããã®ã«ã¹ã¿ãã€ãºã«ããããã¡ã€ã«ã®å®å
šäžèŽã«äŸåããã·ã°ããã£ããŒã¹ã®æ€åºãåé¿ãããŠããŸããã 206.251.239[.]164 ãšã¯ã¹ããã€ããœãŒã¹ IP 2026 幎 1 æã«æŽ»åç¢ºèª 199.217.98[.]153 ãšã¯ã¹ããã€ããœãŒã¹ IP 2026 幎 3 æã«æŽ»åç¢ºèª 89.46.237[.]33 ãšã¯ã¹ããã€ããœãŒã¹ IP 2026 幎 3 æã«æŽ»åç¢ºèª Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:136.0) Gecko/20100101 Firefox/136.0 ãšã¯ã¹ããã€ã HTTP User-Agent 2026 幎 1 æããã³ 3 æã«èŠ³æž¬ b885946e72ad51dca6c70abc2f773506 ãšã¯ã¹ããã€ã TLS JA3 2026 幎 1 æããã³ 3 æã«èŠ³æž¬ f80d3d09f61892c5846c854dd84ac403 ãšã¯ã¹ããã€ã TLS JA3 2026 幎 3 æã«èŠ³æž¬ t13i1811h1_85036bcba153_b26ce05bbdd6 ãšã¯ã¹ããã€ã TLS JA4 2026 幎 1 æããã³ 3 æã«èŠ³æž¬ t13i4311h1_c7886603b240_b26ce05bbdd6 ãšã¯ã¹ããã€ã TLS JA4 2026 幎 3 æã«èŠ³æž¬ 144.172.94[.]59 C2 ãã©ãŒã«ãã㯠IP 2026 幎 3 æã«æŽ»åç¢ºèª 199.217.99[.]121 C2 ãã©ãŒã«ãã㯠IP 2026 幎 3 æã«æŽ»åç¢ºèª 188.245.41[.]78 C2 ãã©ãŒã«ãã㯠IP 2026 幎 3 æã«æŽ»åç¢ºèª 144.172.110[.]106 ããã¯ãšã³ã C2 IP 2026 幎 3 æã«æŽ»åç¢ºèª 95.217.22[.]175 ããã¯ãšã³ã C2 IP 2026 幎 3 æã«æŽ»åç¢ºèª 37.27.244[.]222 ã¹ããŒãžã³ã°ãã¹ã IP 2026 幎 3 æã«æŽ»åç¢ºèª hxxp://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid[.]onion/chat.php 身代é亀æžããŒã¿ã« 2026 幎 3 æã«æŽ»åç¢ºèª cherryberry[.]click ãšã¯ã¹ããã€ããµããŒããã¡ã€ã³ 2026 幎 1 æã«æŽ»åç¢ºèª ms-server-default[.]com ãšã¯ã¹ããã€ããµããŒããã¡ã€ã³ 2026 幎 3 æã«æŽ»åç¢ºèª initialize-configs[.]com ãšã¯ã¹ããã€ããµããŒããã¡ã€ã³ 2026 幎 3 æã«æŽ»åç¢ºèª ms-global.first-update-server[.]com ãšã¯ã¹ããã€ããµããŒããã¡ã€ã³ 2026 幎 3 æã«æŽ»åç¢ºèª ms-sql-auth[.]com ãšã¯ã¹ããã€ããµããŒããã¡ã€ã³ 2026 幎 3 æã«æŽ»åç¢ºèª kolonialeru[.]com ãšã¯ã¹ããã€ããµããŒããã¡ã€ã³ 2026 幎 3 æã«æŽ»åç¢ºèª sclair.it[.]com ãšã¯ã¹ããã€ããµããŒããã¡ã€ã³ 2026 幎 3 æã«æŽ»åç¢ºèª browser-updater[.]com C2 ãã¡ã€ã³ 2026 幎 3 æã«æŽ»åç¢ºèª browser-updater[.]live C2 ãã¡ã€ã³ 2026 幎 3 æã«æŽ»åç¢ºèª os-update-server[.]com C2 ãã¡ã€ã³ 2026 幎 3 æã«æŽ»åç¢ºèª os-update-server[.]org C2 ãã¡ã€ã³ 2026 幎 3 æã«æŽ»åç¢ºèª os-update-server[.]live C2 ãã¡ã€ã³ 2026 幎 3 æã«æŽ»åç¢ºèª os-update-server[.]top C2 ãã¡ã€ã³ 2026 幎 3 æã«æŽ»åç¢ºèª d1caa376cb45b6a1eb3a45c5633c5ef75f7466b8601ed72c8022a8b3f6c1f3be æ»æçã»ãã¥ãªãã£ããŒã« (Certify) 2026 幎 3 æã«èŠ³æž¬ 6c8efbcef3af80a574cb2aa2224c145bb2e37c2f3d3f091571708288ceb22d5f ã¹ã¯ãªãŒã³ããã«ãŒ 2026 幎 3 æã«èŠ³æž¬ é²åŸ¡ã«é¢ããæšå¥šäºé
Interlock ã©ã³ãµã ãŠã§ã¢ã®è
åšããçµç¹ãå®ãããã«ã以äžã®å¯Ÿçã宿œããŠãã ããã çŽã¡ã«å®æœãã¹ãã¢ã¯ã·ã§ã³: Cisco Secure Firewall Management Center ã«å¯Ÿãã Cisco ã®ã»ãã¥ãªãã£ããããé©çšãã äžèšã® IoC ã«ã€ããŠãã°ã確èªãã 䟵害ã®å
åããªããã»ãã¥ãªãã£è©äŸ¡ã宿œãã ScreenConnect ã®äžæ£ãªã€ã³ã¹ããŒã«ããªãã確èªãã æ€åºã®ãã€ã³ã: ãããã¯ãŒã¯å
±æã«ãã¹ãåããŒã¹ã®ãã£ã¬ã¯ããªæ§é ã§ããŒã¿ãã¹ããŒãžã³ã°ãã PowerShell ã¹ã¯ãªãããç£èŠãã Web ã¢ããªã±ãŒã·ã§ã³ã³ã³ããã¹ãã§ã® Java ServletRequestListener ã®ç»é² (Java Web ã¢ããªã±ãŒã·ã§ã³ãžã®éåžžãšã¯ç°ãªã倿Ž) ãæ€åºãã ç©æ¥µçãªãã°æ¶å»çš cron ãžã§ãã䌎ã HAProxy ã®ã€ã³ã¹ããŒã« (5 åééã§èªèº«ã®ãã°ãæ¶å»ãããããã·ãµãŒããŒ) ãç¹å®ãã éåžžãšã¯ç°ãªãé«çªå·ããŒã (äŸ: 45588) ãžã® TCP æ¥ç¶ãç£èŠãã é·æçãªå¯Ÿç: è€æ°ã®ã»ãã¥ãªãã£å¶åŸ¡ã¬ã€ã€ãŒã«ããå€å±€é²åŸ¡æŠç¥ãå®è£
ãã ç¶ç¶çãªè
åšç£èŠãšã¹ã¬ãããã³ãã£ã³ã°ã®èœåãç¶æãã 䟵害ãåããå¯èœæ§ã®ããã·ã¹ãã ãšã¯åé¢ãããå®å
šã§äžå
åããããã°ã¹ãã¬ãŒãžã«ããå
æ¬çãªãã°åéã確ä¿ãã ã©ã³ãµã ãŠã§ã¢ã·ããªãªã«å¯Ÿããã€ã³ã·ãã³ãã¬ã¹ãã³ã¹æé ã宿çã«ãã¹ããã Interlock ã®æŠè¡ããã¯ããã¯ãæé ã«ã€ããŠã»ãã¥ãªãã£ããŒã ãæè²ãã ããã§æ¬åœã«éèŠãªã®ã¯ããããç¹å®ã®è匱æ§ãç¹å®ã®ã©ã³ãµã ãŠã§ã¢ã°ã«ãŒãã ãã®åé¡ã§ã¯ãªããšããããšã§ãããŒããã€ãšã¯ã¹ããã€ããããããã»ãã¥ãªãã£ã¢ãã«ã«çªãã€ããæ ¹æ¬çãªèª²é¡ãªã®ã§ããããããååšããªã段éã§æ»æè
ã«è匱æ§ãæªçšãããŠããŸãã°ãã©ãã»ã©åŸ¹åºããããã管çãè¡ã£ãŠããŠãããã®éèŠãªæéäžã¯é²åŸ¡ã§ããŸãããã ããããå€å±€é²åŸ¡ãäžå¯æ¬ ãªã®ã§ããè€æ°ã®ã»ãã¥ãªãã£å¶åŸ¡ãéããããšã§ãããããã®å¯Ÿçãæ©èœããªãå ŽåãããŸã å°å
¥ãããŠããªãå Žåã§ãä¿è·ãç¶æã§ããŸããè¿
éãªãããé©çšã¯è匱æ§ç®¡çã®åºç€ã§ããç¶ããŸãããå€å±€é²åŸ¡ã¯ããšã¯ã¹ããã€ãã確èªãããŠããããããæäŸããããŸã§ã®ç©ºçœæéã«ãçµç¹ãç¡é²åã«ãªããªãããã®éèŠãªææ®µã§ãã Amazon Threat Intelligence ããŒã 㯠Interlock ã©ã³ãµã ãŠã§ã¢ã®æŽ»åãåŒãç¶ãç£èŠããŠãããæ°ããªæ
å ±ãå€æãæ¬¡ç¬¬ã¢ããããŒããæäŸããŸããä»åã®ãã£ã³ããŒã³ããåéããã€ã³ããªãžã§ã³ã¹ã¯ãã客æ§ãããã¢ã¯ãã£ãã«ä¿è·ãããããAWS ã®ã»ãã¥ãªãã£ãµãŒãã¹ã«çµ±åãããŠããŸãã ãã®èšäºã«é¢ããã質åã¯ã AWS ãµããŒã ãŸã§ãåãåãããã ããã CJ Moses CJ Moses 㯠Amazon Integrated Security ã® CISO ã§ããAmazon å
šäœã®ã»ãã¥ãªãã£ãšã³ãžãã¢ãªã³ã°ãšãªãã¬ãŒã·ã§ã³ãçµ±æ¬ããŠãããã»ãã¥ãªãã£ã®å®è·µãæãèªç¶ã§ç°¡åãªéžæè¢ãšãªãããã«ããããšã§ Amazon ã®ããžãã¹ãæ¯ããããšã䜿åœãšããŠããŸãã2007 幎 12 æã« Amazon ã«å
¥ç€ŸããConsumer CISOãçŽè¿ã§ã¯ AWS CISO ãå«ãããŸããŸãªåœ¹è·ãæŽä»»ããåŸã2023 幎 9 æã«çŸè·ã«å°±ä»»ããŸããã Amazon å
¥ç€Ÿä»¥åã¯ãé£éŠææ»å± (FBI) ãµã€ããŒéšéã§ã³ã³ãã¥ãŒã¿ããã³ãããã¯ãŒã¯äŸµå
¥ã«é¢ããæè¡åæãçããŠããŸããããŸãã空è»ç¹å¥ææ»å± (AFOSI) ã®ç¹å¥ææ»å®ãåããŸãããçŸåšã®ã»ãã¥ãªãã£æ¥çã®åºç€ãç¯ãããšããããè€æ°ã®ã³ã³ãã¥ãŒã¿äŸµå
¥ææ»ãææ®ããŸããã CJ ã¯ã³ã³ãã¥ãŒã¿ãµã€ãšã³ã¹ãšåäºåžæ³ã®åŠäœãååŸããŠãããSRO GT America GT2 ã®ã¬ãŒã¹ã«ãŒãã©ã€ããŒãšããŠã掻èºããŠããŸãã æ¬ããã°ã¯ Security Solutions Architect ã® äžå³¶ ç« å ã翻蚳ããŸããã
æ¬ããã°ã¯ 2026 幎 3 æ 10 æ¥ã«å
¬éããã AWS Blogãâ AWS Security Hub is expanding to unify security operations across multicloud environments â ã翻蚳ãããã®ã§ãã å€ãã®ã客æ§ãšè©±ãããŠã1 ã€æç¢ºãªããšããããŸããããã¯ãã»ãã¥ãªãã£ã®èª²é¡ã¯å®¹æã«ãªã£ãŠããªããšããããšã§ãã仿¥ã®äŒæ¥ã¯ããªã³ãã¬ãã¹ã€ã³ãã©ã¹ãã©ã¯ãã£ããã©ã€ããŒãããŒã¿ã»ã³ã¿ãŒãè€æ°ã®ã¯ã©ãŠããªã©ãè€éã«æ··åšããç°å¢ã§éçšããŠãããå€ãã®å Žåã飿ºãåæã«èšèšãããŠããªãããŒã«ã䜿çšããŠããŸãããã®çµæãäŒæ¥ã®ã»ãã¥ãªãã£ããŒã ã¯ããªã¹ã¯ç®¡çãããããŒã«ç®¡çã«å€ãã®æéãè²»ããããšã«ãªãããŸããŸãè€éåããç°å¢å
šäœã§è
åšã«å
åãããããšãå°é£ã«ãªã£ãŠããŸãã Amazon Web Service (AWS) ã§ã¯ãã»ãã¥ãªãã£ã¯ã·ã³ãã«ã§ãçµ±åãããäŒæ¥ãå®éã«éçšããæ¹æ³ã«åãããŠæ§ç¯ãããã¹ãã ãšèããŠããŸãããã®ä¿¡å¿µãã AWS Security Hub ãåæ§ç¯ããåäžã®ãšã¯ã¹ããªãšã³ã¹ãéããŠãã«ã¹ã¿ãã¯ã»ãã¥ãªãã£ãæäŸããåååãšãªãããã®ããžã§ã³ãç§ãã¡ã®æ¬¡ã®å±éãæšãé²ããŠããŸãã çµ±åã»ãã¥ãªãã£ã®åºç€ã®äžã« ç§ãã¡ã¯ Security Hub ãã çµ±åã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ãœãªã¥ãŒã·ã§ã³ ã«å€é©ããŸãããããã¯ã Amazon GuardDuty ã Amazon Inspector ã AWS Security Hub Cloud Security Posture Management (Security Hub CSPM) ã Amazon Macie ãå«ã AWS ã»ãã¥ãªãã£ãµãŒãã¹ãçµ±åããè
åšãè匱æ§ãèšå®ãã¹ãæ©å¯ããŒã¿ã«é¢ããã»ãã¥ãªãã£ã·ã°ãã«ãèªåçãã€ç¶ç¶çã«åæããåäžã®ãšã¯ã¹ããªãšã³ã¹ãå®çŸããŠããŸããSecurity Hub ã¯å
±éã®åºç€ãæäŸããAWS ç°å¢å
šäœããã®æ€åºçµæãçµ±åããããšã§ãã»ãã¥ãªãã£ããŒã ãã·ã°ãã«ã®è§£éã«è²»ããæéãæžããã察å¿ã«ããå€ãã®æéãå²ããããã«ããŸãããã®åºç€ã®äžã«æ§ç¯ãããçµ±åãªãã¬ãŒã·ã§ã³ã¬ã€ã€ãŒã¯ãã»ãã¥ãªãã£ããŒã ã«ãã¢ãªã¢ã«ã¿ã€ã ã®ãªã¹ã¯åæãèªååãããåæãåªå
é äœä»ããããã€ã³ãµã€ããæäŸããå€§èŠæš¡ã«æãéèŠãªããšã«éäžã§ããããæ¯æŽããŸãã ãŸããäŒæ¥ããšã³ããã€ã³ããIDãã¡ãŒã«ããããã¯ãŒã¯ãããŒã¿ããã©ãŠã¶ãã¯ã©ãŠããAIãã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³å
šäœã«ããããã«ã¹ã¿ãã¯ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã調éããããã€ãçµ±åããæ¹æ³ãç°¡çŽ åããæ°æ©èœ ( the Extended plan ) ãå°å
¥ããŸãããçŸåšãã客æ§ã¯ Security Hub ã䜿çšããŠãå³éžããã AWS ããŒãããŒãœãªã¥ãŒã·ã§ã³ (ããŒã³ãæ: 7AIãBritiveãCrowdStrikeãCyeraãIslandãNomaãOktaãOligoãOptiãProofpointãSailPointãSplunk (Cisco åäž)ãUpwindãZscaler) ãéããŠããã¹ãŠ 1 ã€ã®çµ±äžããããšã¯ã¹ããªãšã³ã¹ã§ã»ãã¥ãªãã£ããŒããã©ãªãªãæ¡åŒµã§ããŸããAWS ã販売å
ãšãªããããåŸéå¶æéã®æéäœç³»ãåäžã®è«æ±æžãé·æå¥çŽãªããšããã¡ãªããã享åã§ããŸããç§ãã¡ã®ãŽãŒã«ã¯ã·ã³ãã«ã§ããäŒæ¥ãéå¶ããããããå Žæã§ãçµ±äžãããã»ãã¥ãªãã£ãæäŸããããšã§ãã ã¯ãŒã¯ããŒããã©ãã«ãã£ãŠããèªç±ã«ã€ãããŒã·ã§ã³ã AWS ã§ã¯ãçžäºéçšæ§ãšã¯ãã客æ§ã®ããŒãºã«æé©ãªãœãªã¥ãŒã·ã§ã³ãèªç±ã«éžæã§ããã¯ãŒã¯ããŒããå®è¡ãããå Žæã§ãããã䜿çšã§ããããšãæå³ããŸãããããããã«ãã¯ã©ãŠãç°å¢å
šäœã§èªç±ã«ã€ãããŒã·ã§ã³ãèµ·ãããšããããšã¯ãéçšã®è€éããå¢ãããšãªããäžè²«ããŠããããä¿è·ããããšãéèŠã§ããããšãæå³ããŸãã Security Hub ã®ä»åŸã®å±é ä»åŸæ°ãæéã§ãAWS ãè¶
ããçµ±åã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ãæ¡åŒµããæ°ãããã«ãã¯ã©ãŠãæ©èœã Security Hub ã«è¿œå ããŸãããã®æ¡åŒµã®åºç€ãšãªãã®ã¯ãã¯ãŒã¯ããŒããã©ãã§å®è¡ãããŠããŠããã»ãã¥ãªãã£ã·ã°ãã«ãçµ±åããå
±éããŒã¿ã¬ã€ã€ãŒã§ãããã®äžã«ãçµ±åãããããªã·ãŒãšãªãã¬ãŒã·ã§ã³ã¬ã€ã€ãŒããäžè²«ãããã¹ãã£ç®¡çããšã¯ã¹ããŒãžã£ãŒåæããªã¹ã¯ã®åªå
é äœä»ããæäŸãããããã»ãã¥ãªãã£ããŒã ã¯æçåãããã³ã³ãœãŒã«ã®éåã§ã¯ãªããåäžã®ãªã¹ã¯ãã¥ãŒããéçšã§ããŸãã Security Hub ã¯ããã«ãã¯ã©ãŠãç°å¢å
šäœã«ãããéèŠãªãªã¹ã¯ãæããã«ããçµ±åãªã¹ã¯åæãæäŸããŸããäžè²«ããã»ãã¥ãªãã£ãã¹ãã£ã®å¯èŠæ§ãæäŸãã Security Hub CSPM ãã§ãã¯ã䜿çšããŠã¯ã©ãŠãã»ãã¥ãªãã£ãã¹ãã£ã管çã§ããä»®æ³ãã·ã³ã¹ãã£ã³ãã³ã³ããã€ã¡ãŒãžã¹ãã£ã³ããµãŒããŒã¬ã¹ã¹ãã£ã³ãå«ãæ¡åŒµããã Amazon Inspector æ©èœã«ãããè匱æ§ç®¡çãæ¡åŒµã§ããŸãããŸããSecurity Hub ã¯ãå€éšãããã¯ãŒã¯ã¹ãã£ã³ã«ãããAWS 以å€ã§å®è¡ãããŠãããªãœãŒã¹ãå«ããã«ãã¯ã©ãŠãç°å¢å
šäœã®ã€ã³ã¿ãŒãããå
¬éç¶æ
ã«é¢ããã³ã³ããã¹ãã§ã»ãã¥ãªãã£æ€åºçµæããšã³ãªããããŸãã ãã®çµæãäŒæ¥å
šäœã§ããå
æ¬çãªãªã¹ã¯ã«ãã¬ããžãå®çŸãããŸããããã¯ãã»ãã¥ãªãã£ããŒã ã«å¯ŸããŠãã©ãã§éçšããŠããŠãããªã¹ã¯ãæ€åºããŠå¯Ÿå¿ããããã®åäžã®çµ±äžããããšã¯ã¹ããªãšã³ã¹ãæäŸããããšãç®çãšããŠããŸãã ããžãã¹ãå éããã»ãã¥ãªã㣠ç§ã話ãããã»ãã¥ãªãã£ãªãŒããŒãã¡ã¯ãåã«ããè¯ãããŒã«ãæ±ããŠããããã§ã¯ãããŸãããæ±ããŠããã®ã¯ããªã¹ã¯ã管çããã ãã§ãªãããªã¹ã¯ã«å
åãããæ¹æ³ã§ããããžãã¹ã®ããŒã¹ã«ã€ããŠããã»ãã¥ãªãã£ãæ±ããŠãããããžãã¹ãé
ãããã»ãã¥ãªãã£ã§ã¯ãããŸããã ããã AWS Security Hub ã®ããžã§ã³ã§ããå
±éã®ããŒã¿åºç€äžã«æ§ç¯ãããã€ã³ããªãžã§ã³ããªåæã«ãã£ãŠåŒ·åãããäžè²«ããéçšã¬ã€ã€ãŒãéããŠæäŸããããåäžã®çµ±åãããã»ãã¥ãªãã£éçšäœéšã«ããçµ±äžãããã»ãã¥ãªãã£ã§ããããã«ãããã»ãã¥ãªãã£ãªã¹ã¯ã®è»œæžãããŒã ã®çç£æ§åäžãAWS å
šäœããã³ãã以å€ã§ã®ã»ãã¥ãªãã£éçšã®åŒ·åãæ¯æŽããŸãã ãã«ãã¯ã©ãŠããžã®æ¡å€§ã¯é²è¡äžã§ããããŸã å§ãŸã£ãã°ããã§ãã 詳现ã«ã€ããŠã¯ã aws.amazon.com/security-hub ãã芧ããã ããã3 æ 23 æ¥ãã 26 æ¥ã«ãµã³ãã©ã³ã·ã¹ã³ã§éå¬ããã RSA Conference ã® AWS ããŒã¹ (S-0466) ã«ãè¶ããã ããã Gee Rittenhouse Gee 㯠AWS ã®ã»ãã¥ãªãã£ãµãŒãã¹æ
åœãã€ã¹ãã¬ãžãã³ãã§ãSecurity HubãGuardDutyãInspector ãªã©ã®äž»èŠãµãŒãã¹ãçµ±æ¬ããŠããŸããMIT ã§å士å·ãååŸãããšã³ã¿ãŒãã©ã€ãºã»ãã¥ãªãã£ãšã¯ã©ãŠãåéã§è±å¯ãªãªãŒããŒã·ããçµéšãæã£ãŠããŸãã以å㯠Skyhigh Security ã® CEO ããã³ Cisco ã»ãã¥ãªãã£ããžãã¹ã°ã«ãŒãã® SVP å
Œ GM ãåããŠããŸããã 翻蚳㯠Security Solutions Architect ã® æŸåŽ åæ ãæ
åœããŸããã
åç»
該åœããã³ã³ãã³ããèŠã€ãããŸããã§ãã












