
OSS
ã€ãã³ã
ãã¬ãžã³
æè¡ããã°
ããã«ã¡ã¯ãAI LabããŒã ã®Han Kil Roã§ãããµãŒãã¹ã«å¿
èŠãªAIã¢ãã«ããœãªã¥ãŒã·ã§ã³ãéçºããããŒã ã§æ¥åã«æºãã£ãŠããŸããæè¿ãLINEã€ããŒç€Ÿå
ã§å®æœããã Orchestrati...
æ¬ããã°ã¯ 2026 幎 4 æ 7 æ¥ã«å
¬éããã AWS Blog â Building AI defenses at scale: Before the threats emerge â ã翻蚳ãããã®ã§ãã AWS ã¯æ°å幎ã«ããããäžçäžã§äºæ¥ãå±éããäœçŸäžã®ã客æ§ãåæã«ä¿è·ããããã®ããã»ã¹ãšããŒã«ãéçºããŠããŸãããAWS ã®ã»ãã¥ãªãã£ããŒã ãšè
åšã€ã³ããªãžã§ã³ã¹ããŒã ã¯ãæ¥ã
ã衚ã«åºãããšã®ãªã AI ãšèªååãé§äœ¿ããåãçµã¿ãç¶ããŠããŸããAI ãæŽ»çšãããã°åæã·ã¹ãã ã«ãããSecOps ãšã³ãžãã¢ã®ã»ãã¥ãªãã£ãã°åæã«èŠããæéã¯å¹³å 6 æéããããã 7 åã«ãŸã§ççž®ãããŸããããã® 50 åãã®çç£æ§åäžã«ãããè
åšã®æ€åºãšå¯Ÿå¿ããã€ãŠãªãã¹ããŒãã§è¡ããããã«ãªã£ãŠããŸããAWS å
šäœã§ã¯ã1 æ¥ããã 400 å
ãè¶
ãããããã¯ãŒã¯ãããŒãåæããæ°ããªè
åšã®å
åãšãªããã¿ãŒã³ãæ€åºããŠããŸãã2025 幎ã ãã§ããAmazon S3 äžã®ã客æ§ã®ãã¡ã€ã«ãäžæ£ã«æå·åããããšãã 3 åä»¶ãè¶
ãã詊ã¿ããããã¯ããŸããã ããã客æ§ãä¿è·ããéçšã§åŸãç¥èŠã¯ããã¹ãŠã®ã客æ§ã®ä¿è·ã«åœ¹ç«ã¡ãŸãããã®èŠæš¡ã§éçšããŠãããããããæ°ãã«æ€åºããè
åšããã¹ãŠã®ã客æ§ã®é²åŸ¡åŒ·åã«çŽçµããŸããAI ã¯ãã§ã«ãã®äžæ žãæ
ã£ãŠããŸãã ãµã€ããŒã»ãã¥ãªãã£ã®ããã®æ°ããªã¯ã©ã¹ã® AI æ¬æ¥ (2026 幎 4 æ 7 æ¥)ã Anthropic ã Project Glasswing ãçºè¡šããŸãã ãããã¯ãäžçã§æãéèŠãªãœãããŠã§ã¢ã®ä¿è·ãšãAI ã®é²åã«äŒŽãæ¥çã«æ±ãããããµã€ããŒã»ãã¥ãªãã£ã®å®è·µãåé²ãããããšãç®çãšããã€ãã·ã¢ããã§ããéèŠãªããžã¿ã«ã€ã³ãã©ã¹ãã©ã¯ãã£ãæ§ç¯ã»éçšããçµç¹ã¯ãäžçãäŸåããã·ã¹ãã ã®è匱æ§ãçºèŠãä¿®æ£ããããã®æ°ããã¯ã©ã¹ã® AI ã¢ãã«ã§ãã Claude Mythos Preview ã«æ©æã¢ã¯ã»ã¹ã§ããããã«ãªããŸããäžçã§æãéèŠãªã€ã³ãã©ã¹ãã©ã¯ãã£ã®äžç«¯ãä¿è·ãã圹å²ãæ
ã AWS ã¯ããã®åãçµã¿ãæšé²ããããã§éèŠãªåœ¹å²ãæãããŠããŸãã ãã®ãããžã§ã¯ããæ¯ããã®ã¯ãAnthropic ã®ãããŸã§ã§æãé«åºŠãª AI ã¢ãã«ã§ããããµã€ããŒã»ãã¥ãªãã£ã«ãããæšè«èœåãš AI èœåã®é£èºçãªé²æ©ãå®çŸãã Claude Mythos Preview ã§ããClaude Mythos Preview ã¯æ ¹æ¬çã«æ°ããã¢ãã«ã¯ã©ã¹ã§ãããAnthropic ã®ãããŸã§ã®ããã³ãã£ã¢ã¢ãã«ãäžåãç¥æ§ãšèœåãåãããµã€ããŒã»ãã¥ãªãã£ããœãããŠã§ã¢ã³ãŒãã£ã³ã°ãè€éãªæšè«ã¿ã¹ã¯ã§ããé«ãããã©ãŒãã³ã¹ãçºæ®ããŸãã Project Glasswing ã®äžç°ãšããŠãAWS ã§ã¯ç¶ç¶ç㪠AI ã»ãã¥ãªãã£ã¬ãã¥ãŒãè¡ãããŠããéèŠãªã³ãŒãããŒã¹ã« Claude Mythos Preview ããã§ã«é©çšããŠããŸããååã«ãã¹ããããç°å¢ã§ãã£ãŠããã³ãŒããããã«åŒ·åã§ããç®æã®ç¹å®ã«åœ¹ç«ã£ãŠããŸããå
éšãã¹ãã§ã¯ãClaude Mythos Preview ãã»ãã¥ãªãã£ã®æ€åºçµæãæŽãåºãéã«åŸæ¥ã®ã¢ãã«ãããé«ãçç£æ§ãçºæ®ãããšã³ãžãã¢ã«ããæåã®ã¬ã€ãã³ã¹ãå°ãªããŠãå®çšçãªçµæãæäŸã§ããããšãå®èšŒãããŸãããäžéšã®ã客æ§ã«ãæ©æã¢ã¯ã»ã¹ãæäŸããŠãããèªç€Ÿã®ã»ãã¥ãªãã£ã¯ãŒã¯ãããŒãžã® Claude Mythos Preview ã®å°å
¥ãéããŠãã¢ãã«ã®é²åã®æ¹åæ§ã圢äœãããšã«è²¢ç®ããŠããŸããAWS ã«ãšã£ãŠ Claude Mythos Preview ã¯ããã§ã«æŽ»çšããŠãã AI ããŒã«ã®èªç¶ãªé²å圢ã§ãããã¯ãããžãŒããã匷åã«ãªãã«ã€ããŠãé²åŸ¡ãããã«åãããŠåŒ·åããŠãããªããã°ãªããŸããã ããããã€ãããŒã·ã§ã³ããã AWS ã®åãçµã¿ãæšé²ãããã®ã§ãããClaude Mythos Preview ããšã³ã¿ãŒãã©ã€ãºã§ã®å©çšã«å¯Ÿå¿ã§ãããã Anthropic ãšç·å¯ã«é£æºããŠããŸãããAWS ã¯ãAnthropic ã®ããã·ã§ã³ã¯ãªãã£ã«ã«ãªã¯ãŒã¯ããŒããå®å
šæ§ã®ç ç©¶ãåºç€ã¢ãã«éçºãæ¯ããäž»èŠãªã¯ã©ãŠããããã€ããŒã§ããããåºãèŠç¹ã§èŠããšãäžçããªãŒããã AI äŒæ¥ãæå
端ã¢ãã«ã®æ§ç¯ããã¬ãŒãã³ã°ããããã€ã«å©çšããåºç€ã€ã³ãã©ã¹ãã©ã¯ãã£ã AWS ãæäŸããŠããŸããæ°å幎ã«ãããã»ãã¥ãªãã£ã®çµéšããã®ããŒãããŒã·ããã«æŽ»ãããããã«å€ãã®çµç¹ã Claude Mythos Preview ãåºç€ãšããŠå®å
šãã€å€§èŠæš¡ã«éçšã§ããããæ¯æŽããŠããŸãã Claude Mythos Preview ã¯ããããŸã§ã«ãªãã¹ã±ãŒã«ãšé床ã§è匱æ§ãçºèŠããå®éã«æ©èœãããšã¯ã¹ããã€ããæ§ç¯ã§ããæ°äžä»£ã¢ãã«ã®å
é§ãã§ããAnthropic ãš AWS ã¯æå³çã«æ
éãªãªãªãŒã¹ã¢ãããŒãããšã£ãŠããŸãããŸãå°æ°ã®çµç¹ããã¢ã¯ã»ã¹ãéå§ããæ°å人ã®ãŠãŒã¶ãŒã«åœ±é¿ãäžãããœãããŠã§ã¢ãããžã¿ã«ãµãŒãã¹ãæäŸããã€ã³ã¿ãŒãããã®éèŠã€ã³ãã©äŒæ¥ããªãŒãã³ãœãŒã¹ã®ã¡ã³ãããŒãåªå
ãããŸããç®æšã¯ãäžçã§æãéèŠãªãœãããŠã§ã¢ã®è匱æ§ãçºèŠãä¿®æ£ããããšã§ããClaude Mythos Preview 㯠Amazon Bedrock ãéããŠéå® (ãªãµãŒã) ãã¬ãã¥ãŒãšããŠå©çšå¯èœã§ãã«ã¹ã¿ããŒãããŒãžãæå·åãVPC åé¢ã詳现ãªãã°èšé²ãªã©ã®ãšã³ã¿ãŒãã©ã€ãºã°ã¬ãŒãã®ã»ãã¥ãªãã£ã³ã³ãããŒã«ãåããŠããŸããããã«ãããæ¬çªç°å¢ã®ã¢ã»ãããäžèŠãªãªã¹ã¯ã«ãããããšãªããClaude Mythos Preview ã®æ©èœãæ€èšŒã§ããŸãã ã»ãã¥ãªãã£ãäžæ žã«æ®ãã AWS ã®ãµãŒãã¹èšèš Project Glasswing ã«ããã AWS ã®åãçµã¿ã¯ãããã·ã§ã³ã¯ãªãã£ã«ã«ãªã¯ãŒã¯ããŒãã 20 幎以äžã«ããã£ãŠä¿è·ããŠããçµéšã®äžã§å¹ã£ãç念ã«åºã¥ããŠããŸããè
åšãçŸå®åããŠããé²åŸ¡ãæ§ç¯ããã®ã§ã¯é
ãã®ã§ããå
ãèŠè¶ããŠæ°ãããã¯ãããžãŒãæ¡çšãããŸãä¿è·çãæ§ç¯ããŠèªç€Ÿã®éçšã«å€§èŠæš¡ã«ãããã€ããããããåŸãç¥èŠã«åºã¥ããŠæ¹åãéããŠããå¿
èŠããããŸãã ããããã AWS ã AI ãšã»ãã¥ãªãã£ã«ãããŠå®è·µããŠããããšã§ããAWS ã®ã¢ãããŒãã¯å€å²ã«ããããŸããè
åšãã³ãã£ã³ã°ãšè匱æ§ãªãµãŒãã«ããããã¢ã¯ãã£ããªé²åŸ¡ãé²è¡äžã®æ»æãã£ã³ããŒã³ãžã®åçãªå¯Ÿå¿ããããŠã»ãã¥ãªãã£ã®åãçµã¿ãæ¥çæé«æ°Žæºãæºããããšãæ€èšŒãã第äžè
èªèšŒã§ããããããéçšçµéšãããAI ãã»ãã¥ãªãã£æ¥åãã©ãã§å éããã人éã®å€æãã©ãã§äžå¯æ¬ ãªã®ããåŠã³ãŸããããŸããã»ãã¥ãªãã£ã®ã€ãããŒã·ã§ã³ã¯å®çšçã§ãªããã°ãªããªããã€ãŸãã客æ§ã«ã掻çšããã ãåã«æ¬çªç°å¢ã§å®èšŒãããŠããå¿
èŠããããšããããšãæ¹ããŠå®æããŸããã ã ãããã AWS ã¯ãå®å
šãª AI ãšã¯ã©ãããã¹ãããå®çŸ©ããåãçµã¿ã«ãè²¢ç®ããŠããŸããAWS 㯠AI ãµãŒãã¹ã«ããã ISO 42001 èªèšŒãååŸããæåã®äž»èŠã¯ã©ãŠããããã€ããŒãšãªããŸãããOWASPãCoalition for Secure AIãFrontier Model Safety Framework ã«ãç©æ¥µçã«åå ããŠããŸãããŸãããšã³ã·ã¹ãã å
šäœã§ã®ããåªããè
åšã€ã³ããªãžã§ã³ã¹ã®å
±æãå®çŸãããããOpen Cybersecurity Schema Framework (OCSF) ãå
±åèšç«ããŸããã AWS Nitro System ã¯ã¯ãŒã¯ããŒãéã®æ°åŠçã«èšŒæãããåé¢ãå®çŸããŸãããŒããªãã¬ãŒã¿ã¢ã¯ã»ã¹ã¢ãŒããã¯ãã£ã«ãããAWS ã®ãªãã¬ãŒã¿ãŒãã客æ§ã®ããŒã¿ã«ã¢ã¯ã»ã¹ããããšã¯ã§ããŸããããããã¯å°æ¥ã®çæ³åã§ã¯ãªããAWS ãçŸåšãå€§èŠæš¡ã«æ¥ã
å®è·µããŠããããšã§ãã Amazon Bedrock ã¯ããããã®ååã AI ã®é åã§å®çŸãããµãŒãã¹ã§ããããªã·ãŒé©çšåã®ã¢ã¯ã»ã¹å¶åŸ¡ãã¢ãã«ã«ããè匱æ§ã®ç¹å®ã»æ€èšŒã®æå¹æ§ã枬å®ããçµã¿èŸŒã¿ã®è©äŸ¡ããŒã«ãã客æ§å°çšã®ä»®æ³ãã©ã€ããŒãã¯ã©ãŠãå
ã§ã¯ãŒã¯ããŒããå®è¡ããæ©èœãæäŸããŸããããã« AWS ã¯ãäžè¬æäŸãããŠãã Claude åºç€ã¢ãã«ã«ã€ã㊠FedRAMP High ããã³ Department of Defense Security Requirements Guide Impact Level 4/5 ã®èªå®ãååŸããæåã®ã¯ã©ãŠããããã€ããŒã§ããããŸããæãå³ããã»ãã¥ãªãã£èŠä»¶ãæã€çµç¹ããAnthropic ã®ãã¯ãããžãŒãå®å¿ããŠå©çšã§ããå Žãšã㊠Amazon Bedrock ãéžãã§ããããšã®èšŒã§ãã ä»ããå§ããã«ã¯ AWS ã®å€§èŠæš¡éçšãæ¯ããååã¯ã䜿çšãã AI ããŒã«ã«é¢ä¿ãªãé©çšã§ããŸããå
æ¬çãªãªãã¶ãŒãããªãã£ãå€å±€é²åŸ¡ã䟡å€ãçãé åã§ã®èªååããããŠäžå¯æ¬ ãªå Žé¢ã§ã®äººéã®å€æã§ãã以äžã«ãã®å®è·µæ¹æ³ãã玹ä»ããŸãã æ¬¡äžä»£ã® AI ã»ãã¥ãªãã£ã«åããã Claude Mythos Preview ã¯ããµã€ããŒã»ãã¥ãªãã£ãå€é©ããæ°äžä»£ã® AI ã¢ãã«ã®å
é§ããšãªããã®ã§ãããããã®æ©èœãããåºãå©çšå¯èœã«ãªã£ããšãã«åããŠãä»ããã»ãã¥ãªãã£ãã¹ãã£ã®åŒ·åãå§ããŠãã ãããClaude Mythos Preview 㯠Amazon Bedrock ãéããéå®ãã¬ãã¥ãŒãšããŠå©çšå¯èœã§ãããã¢ã¯ã»ã¹ã¯èš±å¯ãªã¹ãã«ç»é²ãããåæã®çµç¹ã«éå®ãããŠããŸããèš±å¯ãªã¹ãã«ç»é²ãããŠããå Žåã¯ãAWS ã¢ã«ãŠã³ãããŒã ããçŽæ¥ãé£çµ¡ããŸãã AWS Security Agent ã§ãªã³ããã³ãã®ãããã¬ãŒã·ã§ã³ãã¹ããå®è¡ããã äžè¬æäŸãéå§ããã AWS Security Agent ã¯ãæåã®ãããã¬ãŒã·ã§ã³ãã¹ããšæ¯ã¹ãŠããããªã³ã¹ãã§ 24 æé 365 æ¥çšŒåããèªåŸåãããã¬ãŒã·ã§ã³ãã¹ããæäŸããŸãããããã¬ãŒã·ã§ã³ãã¹ããã宿çã«çºçããããã«ããã¯ãããAWSãAzureãGCPããã®ä»ã®ã¯ã©ãŠããããã€ããŒããªã³ãã¬ãã¹ã«ãããéçºé床ã«åãããŠã¹ã±ãŒã«ãããªã³ããã³ãæ©èœãžãšå€é©ããŸããAWS Security Agent ã¯æ°ããã¯ã©ã¹ã®ããã³ãã£ã¢ãšãŒãžã§ã³ãã§ããç®æšéæã®ããã«èªåŸçã«åäœããåæäžŠè¡ã®ã¿ã¹ã¯ã«å¯Ÿå¿ããããã«ã¹ã±ãŒã«ãã人éã®åžžæç£èŠãªãã«ç¶ç¶çã«çšŒåããŸããé«åºŠãªå€æ®µéã®æ»æã·ããªãªãéããŠã»ãã¥ãªãã£ã®è匱æ§ãçºèŠãæ€èšŒãå ±åããå°éç㪠AI ãšãŒãžã§ã³ãããããã€ããŸããæ€èšŒãªãã«æ€åºçµæãçæããåŸæ¥ã®ã¹ãã£ããšã¯ç°ãªããAWS Security Agent ã¯æœåšçãªè匱æ§ãç¹å®ããåŸãæšçãçµã£ããã€ããŒããšæ»æãã§ãŒã³ã䜿çšããŠãšã¯ã¹ããã€ãã詊ã¿ãæ£åœãªã»ãã¥ãªãã£ãªã¹ã¯ã§ããããšã確èªããŸãã忀åºçµæã«ã¯ãCVSS ãªã¹ã¯ã¹ã³ã¢ãã¢ããªã±ãŒã·ã§ã³åºæã®é倧床è©äŸ¡ã詳现ãªåçŸæé ãä¿®æ£ã®ææ¡ãå«ãŸããŸãããã®çµæããã€ãŠæ°é±éããã£ãŠãããããã¬ãŒã·ã§ã³ãã¹ããæ°æéã§å®äºããæãéèŠãªã·ã¹ãã ã ãã§ãªãã¢ããªã±ãŒã·ã§ã³ããŒããã©ãªãªå
šäœã«ããã£ãŠã»ãã¥ãªãã£ã«ãã¬ããžãã¹ã±ãŒã«ã§ããããã«ãªããŸããæ°èŠã®ã客æ§ã¯ 2 ãæéã®ç¡æãã©ã€ã¢ã«ã§ AWS Security Agent ãã詊ãããã ããŸãã Amazon Bedrock ã§ä¿¡é Œã§ãã AI ã¢ããªã±ãŒã·ã§ã³ãæ§ç¯ããã çæ AI ãæŽ»çšããŠæ§ç¯ããããŒã ã«ãšã£ãŠã®èª²é¡ã¯ãAI ãæ©èœãããããšã ãã§ã¯ãªããAI ãå®å
šã«æ©èœãããããšã§ããAmazon Bedrock ã¯ã責任ãã AI ã®ãããã€ã«å¿
èŠãªã»ãã¥ãªãã£ãšå®å
šæ§ã®ã³ã³ãããŒã«ãæäŸããŸãã èªåæšè« ã¯ã圢åŒçè«çã䜿çšããŠãã«ã·ããŒã·ã§ã³ã«ããäºå®ã®èª€ããé²ããå
é§çãã€å¯äžã® AI ã»ãŒãã¬ãŒãã§ããã99% ã®ç²ŸåºŠã§æ€èšŒå¯èœãªèª¬æãæäŸããŸããããã¯ãAWS ã®ã¹ãã¬ãŒãžãã¢ã€ãã³ãã£ãã£ããããã¯ãŒãã³ã°å
šäœã§ 10 幎以äžã«ããã圢åŒçææ³ãé©çšããŠããçµéšãåºã«ç£šãäžããŠãããã®ã§ããAmazon Bedrock ã¯ããã«ãæå®³ãªã³ã³ãã³ãããããã¯ãã³ã³ãã³ãããªã·ãŒãé©çšããã«ã¹ã¿ãã€ãºå¯èœãªã¬ãŒãã¬ãŒã«ã«å ããã¯ãŒã¯ããŒãå
šäœã«ããã£ãŠ AI ã®åäœã远跡ãç°åžžãæ€åºããå
æ¬çãªãªãã¶ãŒãããªãã£ãæäŸããŸãã è
åšã®ç¶æ³ã¯åŸ
ã£ãŠãããªã è
åšã®ç¶æ³ã¯ããã¡ãã®å¯Ÿå¿ãåŸ
ã£ãŠã¯ãããŸãããåœå®¶ã¬ãã«ã®æ»æè
ãã©ã³ãµã ãŠã§ã¢ãªãã¬ãŒã¿ãŒããµãã©ã€ãã§ãŒã³æ»æè
ã¯ããã§ã« AI ãæŽ»çšããŠæ»æã®ã¹ã±ãŒã«ãæ¡å€§ããŠããŸããAWS ã®äœ¿åœã¯ããŸãé²åŸ¡ãæ§ç¯ããå€§èŠæš¡ã«ãããã€ããããã§åŸãç¥èŠãã³ãã¥ããã£å
šäœã«å
±æã»éå
ããããšã§ãåžžã«äžæ©å
ãè¡ãããšã§ãã ãããã AWS ãæ¥ã
å®è·µããŠããããšã§ããã客æ§ã«ã䜿ãããã ãåã«ããŸãèªç€Ÿã®éçšã§ãã¯ãããžãŒãæ©èœããããšãå®èšŒããŠããŸããæšæºã«åŸãã®ã§ã¯ãªããèªãæšæºãæã¡ç«ãŠãŠããŸãããããŠãå
ãèŠè¶ããŠææ¥ã®èª²é¡ã«ä»æ¥ããåãçµãã§ããŸãã AI ã®æ©èœãã©ãã ãé²åããŠãããã®ã¢ãããŒãã¯å€ãããŸãããAWS ã¯åŒãç¶ãé²åŸ¡ãå
ã«æ§ç¯ããå€§èŠæš¡ãªéçšã®äžã§æ¹è¯ãéããŠãããŸãããã㊠Anthropic ã®ãããªããŒãããŒãšååããæ¬¡äžä»£ã® AI ã»ãã¥ãªãã£ããŒã«ããã®èŠæš¡ã§é²åŸ¡ãè¡ããšã³ã¿ãŒãã©ã€ãºã®å®éã®ããŒãºã«å¿ããããããåãçµãã§ãããŸãã é¢é£æ
å ± AWS Security Agent ã®å©çšãéå§ãã AI ã³ã³ãã³ãã®å®å
šæ§ãå®çŸãã Amazon Bedrock Guardrails ã確èªãã Securing AI at AWS ã§åãçµã¿ã確èªãã AWS Responsible AI ã«ã€ããŠç¢ºèªãã AWS AI Compliance ã«ã€ããŠç¢ºèªãã æ°ããªè
åšã«ã€ã㊠AWS Security Bulletins ã確èªãã Amy Herzog Amy Herzog 㯠Amazon Web Services (AWS) ã®ãã€ã¹ãã¬ãžãã³ãå
Œæé«æ
å ±ã»ãã¥ãªãã£è²¬ä»»è
(CISO) ã§ããã»ãã¥ãªãã£ãæåªå
ã«æ²ãã AWS ã«ãããŠãã¯ã©ãŠãã»ãã¥ãªãã£ãããã§ãã·ã§ãã«ã®ã°ããŒãã«çµç¹ãçããŠããŸããAWS å
¥ç€Ÿåã¯ãAmazon ã® Devices and ServicesãMedia and EntertainmentãAdvertising ã®åäºæ¥ã§ CISO ãåããAlexa+ ã Ring ãªã©ã®ã³ã³ã·ã¥ãŒããŒãã¯ãããžãŒè£œåã®ã»ãã¥ãªãã£ãçµ±æ¬ããŸããããŸããäœè»éè¡æãéããŠäžçäžã®ã客æ§ãã³ãã¥ããã£ã«é«éãã€é«ä¿¡é Œã®ãããŒããã³ããæäŸãã Amazon ã®ã€ãã·ã¢ããã§ãã Project Kuiper ã®ã»ãã¥ã¢ãªéçºã«ãéèŠãªåœ¹å²ãæãããŸããã <!-- '"` --> æ¬ããã°ã¯ Security Solutions Architect ã® äžå³¶ ç« å ã翻蚳ããŸããã
ç®æ¬¡ ã¯ããã« ECR ã€ã¡ãŒãžã¹ãã£ã³ãšã¯ æ§æã®å
šäœå æ€ç¥ã®ç¶²çŸ
æ§ éç¥ã®ãã€ãºäœæž èªç¥ã®ã¹ããŒã ã³ã¹ã 詊ç®ã®èãæ¹ 詊ç®äŸ Terraform ã«ããæ§ç¯ 1. ECR ã¹ãã£ã³èšå® 2. EventBridge ã«ãŒã« 3. SNS ããã㯠4. AWS ChatbotïŒSlack éç¥ïŒ å®éã®éç¥ãšéçš å°å
¥ããŠã¿ãŠ ãŸãšã ã¯ããã« ããã«ã¡ã¯ãéçºæ¬éšéçº1éšãã¢ããã°ã«ãŒãã®ãšã³ãžãã¢ã® ãã³ãã /rymiyamoto ã§ãã 2025幎æ«ã« Next.js ã® React Server Components ã« DoSïŒãµãŒãã¹æåŠïŒãšãœãŒã¹ã³ãŒãé²åºã®è匱æ§ãå
¬é ãããApp Router ã䜿çšãããµãŒãã¹ã§ã®ã¢ããã°ã¬ãŒã察å¿ãæ±ããããŸããã ãã®ããã«ãå©çšããŠãããã¬ãŒã ã¯ãŒã¯ãã©ã€ãã©ãªã«æ·±å»ãªè匱æ§ãèŠã€ããããšã¯çãããããŸããã ããããè匱æ§ãå
¬éäžã®ãµãŒãã¹ã«åœ±é¿ããŠããªãããçŽ æ©ãææ¡ã§ããäœå¶ãæŽããã¹ããåŒç€Ÿã§ã ECR ã®ã€ã¡ãŒãžã¹ãã£ã³ãå°å
¥ããŸããã æ¬èšäºã§ã¯ããã®åãçµã¿ã®äžã€ãšã㊠ECR ã®ã€ã¡ãŒãžã¹ãã£ã³ãå°å
¥ããéã®èšèšã»æ§ç¯ã»éçšã«ã€ããŠç޹ä»ããŸãã åãããã« ECR ã®ã€ã¡ãŒãžã¹ãã£ã³ãããããå°å
¥ããããšããŠããæ¹ã®åèã«ãªãã°å¹žãã§ãã ECR ã€ã¡ãŒãžã¹ãã£ã³ãšã¯ Amazon ECR ã®ã€ã¡ãŒãžã¹ãã£ã³ã¯ãã³ã³ããã€ã¡ãŒãžã«å«ãŸãããœãããŠã§ã¢ã®è匱æ§ïŒCVEïŒãæ€åºããæ©èœã§ãã ã¹ãã£ã³ã«ã¯ Basic Scanning ãš Enhanced Scanning ã®2çš®é¡ããããŸãã é
ç® Basic Scanning Enhanced Scanning ã¹ãã£ã³ãšã³ãžã³ ClairïŒãªãŒãã³ãœãŒã¹ïŒ Amazon Inspector2 æ€åºå¯Ÿè±¡ OS ããã±ãŒãžã®èåŒ±æ§ OS ããã±ãŒãž + ããã°ã©ãã³ã°èšèªããã±ãŒãžïŒnpm, pip, Maven çïŒ ã¹ãã£ã³ã¿ã€ãã³ã° ããã·ã¥æ / æå ããã·ã¥æ / ç¶ç¶ã¹ãã£ã³ æé ç¡æ ææïŒã¹ãã£ã³ããã€ã¡ãŒãžæ°ã«å¿ããåŸé課éïŒ æ§æã®å
šäœå å°å
¥ããæ§æã¯ä»¥äžã®éãã§ãã ECR Enhanced Scanning (Inspector2) â èåŒ±æ§æ€ç¥ EventBridge Rule (CRITICAL ã®ã¿ãã£ã«ã¿) â SNS Topic â AWS Chatbot â Slack ãã£ã³ãã«ã«éç¥ èšèšã«ããã£ãŠæèããã®ã¯ä»¥äžã§ãã æ€ç¥ã®ç¶²çŸ
æ§ OS ããã±ãŒãžã ãã§ãªãèšèªããã±ãŒãžãã«ããŒãããã£ããããEnhanced Scanning ãæ¡çšããŸããã察å¿èšèªã®è©³çްã¯å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã docs.aws.amazon.com äžæ¹ã§ãOS ããã±ãŒãžã®èåŒ±æ§æ€ç¥ã ãã§ååãªã±ãŒã¹ãããŸãã¯ç¡æã§å§ãããã±ãŒã¹ã§ã¯ Basic Scanning ãæåãªéžæè¢ã§ããèªç€Ÿã®èŠä»¶ã«åãããŠæ€èšããŠã¿ãŠãã ããã éç¥ã®ãã€ãºäœæž ãã¹ãŠã® severity ãéç¥ãããšå¯Ÿå¿ã远ãã€ããªããªãããããŸã㯠CRITICAL ã«çµã£ãŠéçšãéå§ããŸãããå®éã« HIGH ãŸã§å«ããŠè©ŠããŠã¿ããšãããæ¬åœã«å¯Ÿå¿ãã¹ãéç¥ãåãããããªããšæããã®ã§ããŸã㯠CRITICAL ã§éçšãéå§ããå¿
èŠã«å¿ããŠãã£ã«ã¿ãåºããæ¹éãšããŠããŸãã èªç¥ã®ã¹ããŒã è匱æ§ã®ååšã«æ°ã¥ããªãããšãäžçªã®ãªã¹ã¯ãªã®ã§ãSlack ãžã®å³æéç¥ãçµã¿èŸŒã¿ãŸãããSlack ãžã®éç¥æ¹æ³ãšããŠã¯ EventBridge â Lambda ã§éç¥å
容ãã«ã¹ã¿ãã€ãºããæ¹æ³ããããŸãããä»åã¯ãŸãæ€ç¥ã§ããç¶æ
ãçŽ æ©ãäœãããšãåªå
ããã³ãŒããæžããã«æ§ç¯ã§ãã AWS Chatbot ãæ¡çšããŸããã ã³ã¹ã Enhanced Scanning 㯠Amazon Inspector2 ã®æéäœç³»ã«åºã¥ããŸããæéã¯ä»¥äžã®2ã€ã§æ§æãããŸãïŒ2026幎4ææç¹ïŒã ææ°ã®æéã¯å
¬åŒããã¥ã¡ã³ããã確èªãã ããã aws.amazon.com ååã¹ãã£ã³: ã€ã¡ãŒãžãããã·ã¥ãããæã®ã¹ãã£ã³ã$0.09 / ã€ã¡ãŒãž åã¹ãã£ã³: ç¶ç¶ã¹ãã£ã³ã«ããæ°ãã CVE ãå
¬éãããéã®èªååã¹ãã£ã³ã$0.01 / ã€ã¡ãŒãž 詊ç®ã®èãæ¹ ã¹ãã£ã³é »åºŠã«ãã£ãŠã³ã¹ãã®æ§é ãç°ãªããŸãã ã¹ãã£ã³é »åºŠ çºçããã³ã¹ã èšç®åŒ ããã·ã¥æ ååã¹ãã£ã³ã®ã¿ æéããã·ã¥æ° à $0.09 ç¶ç¶ã¹ãã£ã³ ååã¹ãã£ã³ + åã¹ãã£ã³ äžèš + ä¿æã€ã¡ãŒãžæ° à åã¹ãã£ã³åæ°/æ à $0.01 åŒç€Ÿã§ã¯æ¬çªç°å¢ã¯ç¶ç¶ã¹ãã£ã³ãéçºç°å¢ã¯ããã·ã¥æã¹ãã£ã³ã§éçšããŠããŸããæ¬çªç°å¢ã§ã¯æ°ãã CVE ãå
¬éãããã¿ã€ãã³ã°ã§ãå³åº§ã«æ€ç¥ãããããç¶ç¶ã¹ãã£ã³ãéçºç°å¢ã§ã¯è匱æ§ãå«ãå®è£
ãå
¥ã£ãæç¹ã§çŽ æ©ãæ€ç¥ãã€ã€ã³ã¹ããæãããããããã·ã¥æã¹ãã£ã³ãé©ããŠããŸãã 詊ç®äŸ äŸãã°ã5ã€ã®ãªããžããªã«å¯ŸããŠæé100åããã·ã¥ããæ¬çªã§ã¯åãªããžããªã«2ã€ã¡ãŒãžãä¿æïŒèš10ã€ã¡ãŒãžïŒããã±ãŒã¹ã§è©Šç®ããŸããåã¹ãã£ã³åæ°ã¯æã«ã©ããããã®é »åºŠã§å¯Ÿè±¡ã® CVE ãæ°ãã«å
¬éããããã«äŸåããŸãããããã§ã¯æ15åçšåºŠãèŠèŸŒã¿ãŸããã é
ç® èšç®åŒ ã³ã¹ã ååã¹ãã£ã³ 100 push à $0.09 $9.00 åã¹ãã£ã³ 10 images à 15å à $0.01 $1.50 æé¡åèš $10.50 å®éã®ã³ã¹ãã¯ãªããžããªæ°ã»ããã·ã¥é »åºŠã»ä¿æã€ã¡ãŒãžæ°ã«ãã£ãŠå€ããã®ã§ãèªç€Ÿã®éçšã«åãããŠè©Šç®ããŠã¿ãŠãã ããã Basic ScanningïŒç¡æïŒãšæ¯èŒãããšã³ã¹ãã¯ããããŸãããèšèªããã±ãŒãžã®èåŒ±æ§æ€ç¥ãæ°èŠ CVE ã®èªååã¹ãã£ã³ãåŸãããããšãèãããšãæ€èšãã䟡å€ã¯ãããšæããŸãã Terraform ã«ããæ§ç¯ 1. ECR ã¹ãã£ã³èšå® ãŸã ECR ã¬ãžã¹ããªã«å¯Ÿã㊠Enhanced Scanning ãæå¹åããŸãã resource "aws_ecr_registry_scanning_configuration" "this" { scan_type = "ENHANCED" rule { scan_frequency = "CONTINUOUS_SCAN" repository_filter { filter = "*" filter_type = "WILDCARD" } } } filter = "*" ã§ã¬ãžã¹ããªå
ã®ãã¹ãŠã®ãªããžããªãã¹ãã£ã³å¯Ÿè±¡ã«ããŠããŸãããªããžããªãåå¥ã«æå®ããæ¹æ³ããããŸãããæ°ãããªããžããªã远å ããéã«ã¹ãã£ã³å¯Ÿè±¡ãžã®è¿œå ãå¿ãããªã¹ã¯ããããããã¯ã€ã«ãã«ãŒãã§å
šäœã察象ã«ããŠããŸãã scan_frequency ã¯ç°å¢ã«ãã£ãŠäœ¿ãåããŠããŸããæ¬çªç°å¢ã§ã¯ CONTINUOUS_SCAN ãéçºç°å¢ã§ã¯ SCAN_ON_PUSH ãèšå®ããŠããŸãã 2. EventBridge ã«ãŒã« resource "aws_cloudwatch_event_rule" "ecr_scan_finding" { name = "ecr-scan-finding-notification" event_pattern = jsonencode ( { "source" : [ "aws.inspector2" ] , "detail-type" : [ "Inspector2 Finding" ] , "detail" : { "status" : [ "ACTIVE" ] , "severity" : [ "CRITICAL" ] , "resources" : { "type" : [ "AWS_ECR_CONTAINER_IMAGE" ] } } } ) state = "ENABLED" } resource "aws_cloudwatch_event_target" "ecr_scan_finding_sns" { rule = aws_cloudwatch_event_rule.ecr_scan_finding.name arn = var.ecr_scan_finding_sns_topic_arn } Enhanced Scanning ã§ã¯ Inspector2 ãã¹ãã£ã³ãšã³ãžã³ãšãªããããã€ãã³ããœãŒã¹ã¯ aws.inspector2 ã«ãªããŸãã Basic Scanning ã®å Žå㯠aws.ecr ã«ãªãã®ã§æ³šæãå¿
èŠã§ãã 3. SNS ããã㯠EventBridge ããåãåã£ãã€ãã³ãã AWS Chatbot ã«æž¡ãããã® SNS ãããã¯ãäœæããŸãã resource "aws_sns_topic" "ecr_scan_finding_topic" { name = "ecr-scan-finding-topic" } resource "aws_sns_topic_policy" "ecr_scan_finding_topic_policy" { arn = aws_sns_topic.ecr_scan_finding_topic.arn policy = data.aws_iam_policy_document.sns_ecr_scan_finding_topic_policy.json } data "aws_iam_policy_document" "sns_ecr_scan_finding_topic_policy" { # EventBridge ããã® Publish ãèš±å¯ statement { sid = "AllowEventBridgeToPublishSNS" effect = "Allow" actions = [ "sns:Publish" ] principals { type = "Service" identifiers = [ "events.amazonaws.com" ] } resources = [ aws_sns_topic.ecr_scan_finding_topic.arn ] condition { test = "StringEquals" variable = "AWS:SourceAccount" values = [ data.aws_caller_identity.current.account_id ] } condition { test = "ArnEquals" variable = "aws:SourceArn" values = [ "arn:aws:events:$ { data.aws_region.current.name } :$ { data.aws_caller_identity.current.account_id } :rule/ecr-scan-finding-notification" ] } } # Chatbot ããã® Subscribe ãèš±å¯ statement { sid = "AllowChatbotToSubscribe" effect = "Allow" actions = [ "sns:Subscribe" ] principals { type = "Service" identifiers = [ "chatbot.amazonaws.com" ] } resources = [ aws_sns_topic.ecr_scan_finding_topic.arn ] condition { test = "StringEquals" variable = "AWS:SourceAccount" values = [ data.aws_caller_identity.current.account_id ] } condition { test = "ArnEquals" variable = "aws:SourceArn" values = [ "arn:aws:chatbot::$ { data.aws_caller_identity.current.account_id } :chat-configuration/slack-channel/alert-to-slack" ] } } } SNS ãããã¯ããªã·ãŒã§ã¯ãEventBridge ããã® Publish ãš Chatbot ããã® Subscribe ã®ã¿ãèš±å¯ããŠããŸãã condition ã§çºä¿¡å
ãçµãããšã§ãæå³ããªããªãœãŒã¹ããã®æäœãé²ãã§ããŸãã 4. AWS ChatbotïŒSlack éç¥ïŒ æåŸã«ãSNS ãããã¯ã®ã¡ãã»ãŒãžã Slack ã«è»¢éãã Chatbot ã®èšå®ã§ãã resource "aws_chatbot_slack_channel_configuration" "chatbot_alert_to_slack" { configuration_name = "alert-to-slack" slack_channel_id = "XXXXXXXXX" # éç¥å
ã® Slack ãã£ã³ãã« ID slack_team_id = "XXXXXXXXX" # Slack ã¯ãŒã¯ã¹ããŒã¹ ID iam_role_arn = var.chatbot_role_arn sns_topic_arns = [ var.ecr_scan_finding_topic_arn, # ä»ã®éç¥çš SNS ãããã¯ãããã«è¿œå ã§ãã ] guardrail_policy_arns = [ "arn:aws:iam::aws:policy/ReadOnlyAccess" ] logging_level = "ERROR" } ããã§ CRITICAL ãªè匱æ§ãæ€ç¥ãããéã«ãSlack ãã£ã³ãã«ã«éç¥ãå±ãããã«ãªããŸãã ãªããAWS Chatbot ã§ã¯åã Slack ãã£ã³ãã«ã«å¯ŸããŠè€æ°ã® configuration ãäœæã§ããŸããããã®ãã configuration_name 㯠alert-to-slack ã®ããã«æ±çšçãªååã«ããŠããŸããããããŠããã°ãä»åŸ WAF ã®ã¢ã©ãŒããªã©å¥ã®éç¥ã远å ããããªã£ãŠã sns_topic_arns ã«ãããã¯ãè¶³ãã ãã§æžã¿ãŸãã å®éã®éç¥ãšéçš å®éã«å±ãéç¥ã¯ä»¥äžã®ãããªåœ¢åŒã§ãã æå㯠CVE ã®è©³çްãŸã§ Slack ã§ç¢ºèªã§ãããã®ã ãšæã£ãŠããã®ã§ãããå®éã«å±ãéç¥ã«ã¯ Inspector2 Finding ãšããã€ãã³ãåãšå¯Ÿè±¡ã® ECR ã€ã¡ãŒãžã® ARN ã衚瀺ãããã ãã§ãCVE åãããã±ãŒãžåã衚瀺ãããŸããã§ããã ãã®ãããEventBridge ã® input_transformer ã䜿ããChatbot ã®ã«ã¹ã¿ã éç¥ã§éç¥å
å®¹ãæ¹åããŸããã resource "aws_cloudwatch_event_target" "ecr_scan_finding_sns" { rule = aws_cloudwatch_event_rule.ecr_scan_finding.name target_id = "SendToSNS" arn = var.ecr_scan_finding_sns_topic_arn input_transformer { input_paths = { "severity" = "$.detail.severity" "title" = "$.detail.title" "description" = "$.detail.description" "repository" = "$.detail.resources[0].details.awsEcrContainerImage.repositoryName" } input_template = <<TEMPLATE { "version": "1.0", "source": "custom", "content": { "textType": "client-markdown", "title": ":rotating_light: ECR <severity> èåŒ±æ§æ€åº [ç°å¢å (AWSã¢ã«ãŠã³ãID)]", "description": "*éèŠåºŠ*: <severity>\n*ãªããžããª*: <repository>\n*è匱æ§*: <title>\n*詳现*: <description>" } } TEMPLATE } } ãã€ã³ã㯠input_paths ã§ã€ãã³ãããå¿
èŠãªé
ç®ãæœåºããã«ã¹ã¿ã éç¥ãã©ãŒãããã§æŽåœ¢ããŠããç¹ã§ããæ¹ååŸã®éç¥ã¯ä»¥äžã®ãããªåœ¢åŒã§ãã CVE-ID ãããã±ãŒãžåããªããžããªåã衚瀺ãããããã«ãªããSlack äžã§è匱æ§ã®æŠèŠãææ¡ã§ããããã«ãªããŸããã詳现ãªå¯Ÿå¿å€æãå¿
èŠãªå Žå㯠Inspector2 ã®ããã·ã¥ããŒãã確èªããéçšã§ãããéç¥ãèŠãã ãã§å¯Ÿå¿èŠåŠããããããšãå¢ããŸããã ããã«éç¥å
容ãèªç±ã«ã«ã¹ã¿ãã€ãºãããå Žåã¯ãEventBridge â SNS â Chatbot ã®çµè·¯ã§ã¯ãªããEventBridge â Lambda ã§æŽåœ¢ããæ¹æ³ããããŸãã å°å
¥ããŠã¿ãŠ CRITICAL ã«çµã£ã倿ã¯ããŸããããŸãããæåã®éç¥ãæ¥ããšãããããã¯æ¬åœã«å¯Ÿå¿ãå¿
èŠãªãã®ã ããšèœã¡çããŠå¯ŸåŠã§ããã®ã§ãçãéãã§ããã äžæ¹ã§ãChatbot ã®ããã©ã«ãã®éç¥ã§ã¯ CVE ã®è©³çްãåºããæ£çŽããå°ãæ
å ±ãåºããšæã£ãŠããŸãããå®éã«äœ¿ã£ãŠã¿ãŠåããŠæ°ã¥ããéšåã§ã input_transformer ã䜿ã£ãŠã«ã¹ã¿ãã€ãºã§ããããšãåŸããç¥ããŸããã Terraform ã§ã®è€æ°ç°å¢å±éãã¹ãã£ã³é »åºŠã®äœ¿ãåãã¯ãããªããããŸããã ãŸãšã ä»åã¯ããã¬ãŒã ã¯ãŒã¯ãã©ã€ãã©ãªã®è匱æ§ã«çŽ æ©ã察å¿ã§ããäœå¶ã¥ããã®äžç°ãšããŠãECR ã® Enhanced Scanning ãå°å
¥ããäºäŸã玹ä»ããŸããã æ§æãšããŠã¯ ECR Enhanced Scanning â EventBridge â SNS â Chatbot â Slack ãšããã·ã³ãã«ãªãã€ãã©ã€ã³ã§ãããTerraform ã§ã³ãŒãåããããšã§åçŸæ§ã®ãã圢ã§è€æ°ç°å¢ã«å±éã§ããŸããã ãŸãæ€ç¥ã§ããç¶æ
ãäœãããšãç¬¬äžæ©ãããããè¶
ããã°éçšããªãã粟床ãäžããŠãããŸããæ¬èšäºããã®äžæ©ãèžã¿åºããã£ããã«ãªãã°å¬ããã§ãã æåŸãŸã§èªãã§ããã ãããããšãããããŸããïŒ


























