¿Í×ÁÇǧ¾Ú¤Ç¤¤Ê¤¤¡ÖÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¡×¤¬¥µ¥¤¥Ð¡¼¹¶·â¤Î¼åÅÀ¤Ë
¥µ¥¤¥Ð¡¼¥»¥¥å¥ê¥Æ¥£´ë¶È¤ÎSilverfort¤Ï¤³¤Î¤Û¤É¡¢¡ÖShining the Spotlight on the Rising Security Risks of Non-Human Identities¡×¤Ë¤ª¤¤¤Æ¡¢Active Directory¥µ¡¼¥Ó¥¹¤Ë¤ª¤±¤ëÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£(NHI: Non-Human Identity)¤ÎÄ´ºº·ë²Ì¤òÅÁ¤¨¤¿¡£Active Directory¤¬Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤Î¿¯³²¤ò¼õ¤±¤Æ¤¤¤ë¤È¤·¤Æ¡¢Ä´ºº¤ò¼Â»Ü¤·¤¿¤È¤¤¤¦¡£
Shining the Spotlight on the Rising Security Risks of Non-Human Identities
¡ûÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤Î¥ê¥¹¥¯¤È¤Ï
Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤È¤Ï¡¢¿Í´Ö°Ê³°¤Î¥µ¡¼¥Ó¥¹¤Ê¤É¤ËÍ¿¤¨¤é¤ì¤ëǧ¾Ú¾ðÊó¤Î¤³¤È¡£API¥¡¼¡¢¥µ¡¼¥Ó¥¹¥¢¥«¥¦¥ó¥È¡¢¥·¥¹¥Æ¥à¥¢¥«¥¦¥ó¥È¡¢OAuth¥È¡¼¥¯¥ó¤Ê¤É¤¬¤³¤ì¤Ë¤¢¤¿¤ë¡£¤³¤ì¤éǧ¾Ú¾ðÊó¤Ï¿Í×ÁÇǧ¾Ú(MFA: Multi-Factor Authentication)¤Ê¤É¤ÇÊݸî¤Ç¤¤Ê¤¤¤¿¤á¡¢¥µ¥¤¥Ð¡¼ÈȺá¼Ô¤ËÁÀ¤ï¤ì¤ä¤¹¤¤¤È¤µ¤ì¤ë¡£
¤Þ¤¿¡¢Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤òɬÍפȤ¹¤ë¥µ¡¼¥Ó¥¹¤Ï¡¢¹ÈϰϤΥ桼¥¶¡¼¾ðÊó¤ä¥Ç¡¼¥¿¤ò°·¤¦¤³¤È¤¬Â¿¤¯¡¢Æø¢¥ì¥Ù¥ë¤ÇÆ°ºî¤¹¤ë¤¿¤á¡¢¿¯³²»þ¤Î±Æ¶Á¤Ï¿¼¹ï¤È¤µ¤ì¤ë¡£Silverfort¤Ï¡¢Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤Ï¿Í´Ö¤ËÍ¿¤¨¤é¤ì¤ë¥¢¥«¥¦¥ó¥È¤è¤ê¤âÀøºßŪ¤Ê¥ê¥¹¥¯¤ÏÂ礤¤¤È»ØŦ¤·¤Æ¤¤¤ë¡£
¡ûÄ´ºº·ë²Ì¤Î³µÍ×
Silverfort¤Ë¤è¤ëÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ÎÄ´ºº·ë²Ì¤Î³µÍפϼ¡¤Î¤È¤ª¤ê¡£
¡ûËÄÂç¤ÊÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£
Âç´ë¶È¤Ç¤ÏActive DirectoryÆâ¤Î¥¢¥«¥¦¥ó¥È¤ÎÌó23%¤òÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤¬Àê¤á¤ë¡£´ë¶Èµ¬ÌϤ¬¾®¤µ¤¯¤Ê¤ë¤Ë¤Ä¤ìÈæΨ¤Ï¾å¾º¤¹¤ë·¹¸þ¤Ë¤¢¤ê¡¢¾®µ¬ÌÏÁÈ¿¥¤Î¾ì¹ç¤ÏÌó48%¤Ë¾å¾º¤¹¤ë¡£
´ë¶Èµ¬ÌϤ´¤È¤ÎÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ÎÀê¤á¤ë³ä¹ç¡¡°úÍÑ¡§Silverfort
¡ûÈó¿ä¾©¤Îǧ¾Ú¥×¥í¥È¥³¥ë
Windows¤Ç¤ÏÀȼå¤Êǧ¾Ú¥×¥í¥È¥³¥ë¤ÎNTLM¤¬¤¤¤Þ¤À¤Ë»ÈÍѤµ¤ì¤Æ¤¤¤ë¡£Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ÎÌó46%¤ÏÀȼå¤ÊNTLM¤ò»ÈÍѤ·¤Æ¤¤¤ë¡£
NHI¤Îǧ¾Ú¤Ë»ÈÍѤ¹¤ëNTLM/Kerberos¤Î³ä¹ç¡¡°úÍÑ¡§Silverfort
¡û¤½¤Î¾¤Î³µÍ×
Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤Î²Ä»ë²½¤ò¼Â¸½¤·¤Æ¤¤¤ëÁÈ¿¥¤Ï¤ï¤º¤«5.7%¤È¤µ¤ì¤ë¡£62%¤ÏÉôʬŪ¤Ê²Ä»ë²½¤·¤«¼Â¸½¤Ç¤¤Æ¤¤¤Ê¤¤¡£¤Þ¤¿¡¢Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ò¥µ¥¤¥Ð¡¼¹¶·â¤«¤éÊݸî¤Ç¤¤ë¤È³Î¿®¤·¤Æ¤¤¤ëÁÈ¿¥¤Ï20%ÄøÅÙ¡£8³ä¤ÎÁÈ¿¥¤¬Êݸî¤Ç¤¤Ê¤¤¤Èǧ¼±¤·¤Æ¤¤¤ë¡£
¡ûÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ÎÊݸî
Silverfort¤ÏÄ´ºº·ë²Ì¤ò´ð¤Ë¡¢Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ÎÊݸîÊýË¡¤òÄó°Æ¤·¤Æ¤¤¤ë¡£¤½¤Î³µÍפϼ¡¤Î¤È¤ª¤ê¡£
ºÇ¾®¸¢¸Â¤Î¸¶Â§¤òÄɵ᤹¤ë¡£Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ËÂФ·¤Æ¤â¡¢¥½¡¼¥¹¡¢°¸Àè¡¢¥×¥í¥È¥³¥ë¡¢»þ´Ö¡¢¤½¤Î¾¤ÎÍ×°ø¤Ë´ð¤Å¤¤¤¿ºÇ¾®¸¢¸Â¤òÀßÄꤹ¤ë
Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ËÍ¿¤¨¤é¤ì¤ë¡ÖÀµ¾ï¤ÊÆ°ºî¡×¤òÄêµÁ¤¹¤ë
¡ÖÀµ¾ï¤ÊÆ°ºî¡×¤Ë°ãÈ¿¤¹¤ë°Û¾ï¤Ê³èÆ°¤ò¸¡½Ð¤·¡¢·Ù¹ð¤¹¤ë
°Û¾ï¤Ê³èÆ°¤ò¸¡½Ð¤·¤¿ºÝ¤Ë¤Ï¡¢¼«Æ°¤Ç³èÆ°¤ò¥Ö¥í¥Ã¥¯¤¹¤ë
¿Í×ÁÇǧ¾Ú¤ÈƱÍͤˡ¢Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤Ë2½Å¤ÎÊݸî¤òƳÆþ¤¹¤ë
¶áǯ¤Ï¿¤¯¤Î´ë¶È¤«¤éÆü¡¹¿·¤·¤¤¥µ¡¼¥Ó¥¹¤¬À¸¤ß½Ð¤µ¤ì¤Æ¤¤¤ë¡£¤³¤ì¤é¿·¤·¤¤¥µ¡¼¥Ó¥¹¤Ï´û¸¤ÎÊ£¿ô¤Î¥µ¡¼¥Ó¥¹¤ÈÏ¢·È¤·¡¢¼«Æ°²½¤ò¼Â¸½¤¹¤ë¤¿¤á¿¤¯¤ÎÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ò»ÈÍѤ¹¤ë¡£
¤³¤Î·¹¸þ¤ÏAI(Artificial Intelligence)¤ÎÅоì¤Ë¤è¤ê¤µ¤é¤Ë²Ã®¤¹¤ë¤ÈͽÁÛ¤µ¤ì¤Æ¤ª¤ê¡¢Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤Ï¤µ¤é¤ËÁýÂ礹¤ë¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£¤³¤ì¤Ï¥µ¥¤¥Ð¡¼ÈȺá¼Ô¤ÎɸŪ¤¬Áý¤¨Â³¤±¤ë¤³¤È¤ò°ÕÌ£¤·¤Æ¤ª¤ê¡¢·üÇ°¤µ¤ì¤ë¥ê¥¹¥¯¤ò·Ú¸º¤¹¤ë¤¿¤á¡¢´ë¶È¤äÁÈ¿¥¤Ë¤ÏÀѶËŪ¤Ê²Ä»ë²½¤ÈÂкö¤Î¼Â»Ü¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£
;;link;
https://news.mynavi.jp/techplus/article/20240814-3004721/
https://news.mynavi.jp/techplus/article/20240813-3002171/
https://news.mynavi.jp/techplus/article/20240813-3002775/
https://news.mynavi.jp/techplus/article/20240812-3002641/
¡ûÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤Î¥ê¥¹¥¯¤È¤Ï
Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤È¤Ï¡¢¿Í´Ö°Ê³°¤Î¥µ¡¼¥Ó¥¹¤Ê¤É¤ËÍ¿¤¨¤é¤ì¤ëǧ¾Ú¾ðÊó¤Î¤³¤È¡£API¥¡¼¡¢¥µ¡¼¥Ó¥¹¥¢¥«¥¦¥ó¥È¡¢¥·¥¹¥Æ¥à¥¢¥«¥¦¥ó¥È¡¢OAuth¥È¡¼¥¯¥ó¤Ê¤É¤¬¤³¤ì¤Ë¤¢¤¿¤ë¡£¤³¤ì¤éǧ¾Ú¾ðÊó¤Ï¿Í×ÁÇǧ¾Ú(MFA: Multi-Factor Authentication)¤Ê¤É¤ÇÊݸî¤Ç¤¤Ê¤¤¤¿¤á¡¢¥µ¥¤¥Ð¡¼ÈȺá¼Ô¤ËÁÀ¤ï¤ì¤ä¤¹¤¤¤È¤µ¤ì¤ë¡£
¤Þ¤¿¡¢Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤òɬÍפȤ¹¤ë¥µ¡¼¥Ó¥¹¤Ï¡¢¹ÈϰϤΥ桼¥¶¡¼¾ðÊó¤ä¥Ç¡¼¥¿¤ò°·¤¦¤³¤È¤¬Â¿¤¯¡¢Æø¢¥ì¥Ù¥ë¤ÇÆ°ºî¤¹¤ë¤¿¤á¡¢¿¯³²»þ¤Î±Æ¶Á¤Ï¿¼¹ï¤È¤µ¤ì¤ë¡£Silverfort¤Ï¡¢Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤Ï¿Í´Ö¤ËÍ¿¤¨¤é¤ì¤ë¥¢¥«¥¦¥ó¥È¤è¤ê¤âÀøºßŪ¤Ê¥ê¥¹¥¯¤ÏÂ礤¤¤È»ØŦ¤·¤Æ¤¤¤ë¡£
¡ûÄ´ºº·ë²Ì¤Î³µÍ×
Silverfort¤Ë¤è¤ëÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ÎÄ´ºº·ë²Ì¤Î³µÍפϼ¡¤Î¤È¤ª¤ê¡£
¡ûËÄÂç¤ÊÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£
Âç´ë¶È¤Ç¤ÏActive DirectoryÆâ¤Î¥¢¥«¥¦¥ó¥È¤ÎÌó23%¤òÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤¬Àê¤á¤ë¡£´ë¶Èµ¬ÌϤ¬¾®¤µ¤¯¤Ê¤ë¤Ë¤Ä¤ìÈæΨ¤Ï¾å¾º¤¹¤ë·¹¸þ¤Ë¤¢¤ê¡¢¾®µ¬ÌÏÁÈ¿¥¤Î¾ì¹ç¤ÏÌó48%¤Ë¾å¾º¤¹¤ë¡£
´ë¶Èµ¬ÌϤ´¤È¤ÎÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ÎÀê¤á¤ë³ä¹ç¡¡°úÍÑ¡§Silverfort
¡ûÈó¿ä¾©¤Îǧ¾Ú¥×¥í¥È¥³¥ë
Windows¤Ç¤ÏÀȼå¤Êǧ¾Ú¥×¥í¥È¥³¥ë¤ÎNTLM¤¬¤¤¤Þ¤À¤Ë»ÈÍѤµ¤ì¤Æ¤¤¤ë¡£Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ÎÌó46%¤ÏÀȼå¤ÊNTLM¤ò»ÈÍѤ·¤Æ¤¤¤ë¡£
NHI¤Îǧ¾Ú¤Ë»ÈÍѤ¹¤ëNTLM/Kerberos¤Î³ä¹ç¡¡°úÍÑ¡§Silverfort
¡û¤½¤Î¾¤Î³µÍ×
Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤Î²Ä»ë²½¤ò¼Â¸½¤·¤Æ¤¤¤ëÁÈ¿¥¤Ï¤ï¤º¤«5.7%¤È¤µ¤ì¤ë¡£62%¤ÏÉôʬŪ¤Ê²Ä»ë²½¤·¤«¼Â¸½¤Ç¤¤Æ¤¤¤Ê¤¤¡£¤Þ¤¿¡¢Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ò¥µ¥¤¥Ð¡¼¹¶·â¤«¤éÊݸî¤Ç¤¤ë¤È³Î¿®¤·¤Æ¤¤¤ëÁÈ¿¥¤Ï20%ÄøÅÙ¡£8³ä¤ÎÁÈ¿¥¤¬Êݸî¤Ç¤¤Ê¤¤¤Èǧ¼±¤·¤Æ¤¤¤ë¡£
¡ûÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ÎÊݸî
Silverfort¤ÏÄ´ºº·ë²Ì¤ò´ð¤Ë¡¢Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ÎÊݸîÊýË¡¤òÄó°Æ¤·¤Æ¤¤¤ë¡£¤½¤Î³µÍפϼ¡¤Î¤È¤ª¤ê¡£
ºÇ¾®¸¢¸Â¤Î¸¶Â§¤òÄɵ᤹¤ë¡£Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ËÂФ·¤Æ¤â¡¢¥½¡¼¥¹¡¢°¸Àè¡¢¥×¥í¥È¥³¥ë¡¢»þ´Ö¡¢¤½¤Î¾¤ÎÍ×°ø¤Ë´ð¤Å¤¤¤¿ºÇ¾®¸¢¸Â¤òÀßÄꤹ¤ë
Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ËÍ¿¤¨¤é¤ì¤ë¡ÖÀµ¾ï¤ÊÆ°ºî¡×¤òÄêµÁ¤¹¤ë
¡ÖÀµ¾ï¤ÊÆ°ºî¡×¤Ë°ãÈ¿¤¹¤ë°Û¾ï¤Ê³èÆ°¤ò¸¡½Ð¤·¡¢·Ù¹ð¤¹¤ë
°Û¾ï¤Ê³èÆ°¤ò¸¡½Ð¤·¤¿ºÝ¤Ë¤Ï¡¢¼«Æ°¤Ç³èÆ°¤ò¥Ö¥í¥Ã¥¯¤¹¤ë
¿Í×ÁÇǧ¾Ú¤ÈƱÍͤˡ¢Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤Ë2½Å¤ÎÊݸî¤òƳÆþ¤¹¤ë
¶áǯ¤Ï¿¤¯¤Î´ë¶È¤«¤éÆü¡¹¿·¤·¤¤¥µ¡¼¥Ó¥¹¤¬À¸¤ß½Ð¤µ¤ì¤Æ¤¤¤ë¡£¤³¤ì¤é¿·¤·¤¤¥µ¡¼¥Ó¥¹¤Ï´û¸¤ÎÊ£¿ô¤Î¥µ¡¼¥Ó¥¹¤ÈÏ¢·È¤·¡¢¼«Æ°²½¤ò¼Â¸½¤¹¤ë¤¿¤á¿¤¯¤ÎÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ò»ÈÍѤ¹¤ë¡£
¤³¤Î·¹¸þ¤ÏAI(Artificial Intelligence)¤ÎÅоì¤Ë¤è¤ê¤µ¤é¤Ë²Ã®¤¹¤ë¤ÈͽÁÛ¤µ¤ì¤Æ¤ª¤ê¡¢Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤Ï¤µ¤é¤ËÁýÂ礹¤ë¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£¤³¤ì¤Ï¥µ¥¤¥Ð¡¼ÈȺá¼Ô¤ÎɸŪ¤¬Áý¤¨Â³¤±¤ë¤³¤È¤ò°ÕÌ£¤·¤Æ¤ª¤ê¡¢·üÇ°¤µ¤ì¤ë¥ê¥¹¥¯¤ò·Ú¸º¤¹¤ë¤¿¤á¡¢´ë¶È¤äÁÈ¿¥¤Ë¤ÏÀѶËŪ¤Ê²Ä»ë²½¤ÈÂкö¤Î¼Â»Ü¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£
;;link;
https://news.mynavi.jp/techplus/article/20240814-3004721/
https://news.mynavi.jp/techplus/article/20240813-3002171/
https://news.mynavi.jp/techplus/article/20240813-3002775/
https://news.mynavi.jp/techplus/article/20240812-3002641/