¥µ¥¤¥Ð¡¼¥»¥­¥å¥ê¥Æ¥£´ë¶È¤ÎSilverfort¤Ï¤³¤Î¤Û¤É¡¢¡ÖShining the Spotlight on the Rising Security Risks of Non-Human Identities¡×¤Ë¤ª¤¤¤Æ¡¢Active Directory¥µ¡¼¥Ó¥¹¤Ë¤ª¤±¤ëÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£(NHI: Non-Human Identity)¤ÎÄ´ºº·ë²Ì¤òÅÁ¤¨¤¿¡£Active Directory¤¬Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤Î¿¯³²¤ò¼õ¤±¤Æ¤¤¤ë¤È¤·¤Æ¡¢Ä´ºº¤ò¼Â»Ü¤·¤¿¤È¤¤¤¦¡£

Shining the Spotlight on the Rising Security Risks of Non-Human Identities

¡ûÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤Î¥ê¥¹¥¯¤È¤Ï

Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤È¤Ï¡¢¿Í´Ö°Ê³°¤Î¥µ¡¼¥Ó¥¹¤Ê¤É¤ËÍ¿¤¨¤é¤ì¤ëǧ¾Ú¾ðÊó¤Î¤³¤È¡£API¥­¡¼¡¢¥µ¡¼¥Ó¥¹¥¢¥«¥¦¥ó¥È¡¢¥·¥¹¥Æ¥à¥¢¥«¥¦¥ó¥È¡¢OAuth¥È¡¼¥¯¥ó¤Ê¤É¤¬¤³¤ì¤Ë¤¢¤¿¤ë¡£¤³¤ì¤éǧ¾Ú¾ðÊó¤Ï¿Í×ÁÇǧ¾Ú(MFA: Multi-Factor Authentication)¤Ê¤É¤ÇÊݸî¤Ç¤­¤Ê¤¤¤¿¤á¡¢¥µ¥¤¥Ð¡¼ÈȺá¼Ô¤ËÁÀ¤ï¤ì¤ä¤¹¤¤¤È¤µ¤ì¤ë¡£

¤Þ¤¿¡¢Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤òɬÍפȤ¹¤ë¥µ¡¼¥Ó¥¹¤Ï¡¢¹­ÈϰϤΥ桼¥¶¡¼¾ðÊó¤ä¥Ç¡¼¥¿¤ò°·¤¦¤³¤È¤¬Â¿¤¯¡¢Æø¢¥ì¥Ù¥ë¤ÇÆ°ºî¤¹¤ë¤¿¤á¡¢¿¯³²»þ¤Î±Æ¶Á¤Ï¿¼¹ï¤È¤µ¤ì¤ë¡£Silverfort¤Ï¡¢Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤Ï¿Í´Ö¤ËÍ¿¤¨¤é¤ì¤ë¥¢¥«¥¦¥ó¥È¤è¤ê¤âÀøºßŪ¤Ê¥ê¥¹¥¯¤ÏÂ礭¤¤¤È»ØŦ¤·¤Æ¤¤¤ë¡£

¡ûÄ´ºº·ë²Ì¤Î³µÍ×

Silverfort¤Ë¤è¤ëÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ÎÄ´ºº·ë²Ì¤Î³µÍפϼ¡¤Î¤È¤ª¤ê¡£

¡ûËÄÂç¤ÊÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£

Âç´ë¶È¤Ç¤ÏActive DirectoryÆâ¤Î¥¢¥«¥¦¥ó¥È¤ÎÌó23%¤òÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤¬Àê¤á¤ë¡£´ë¶Èµ¬ÌϤ¬¾®¤µ¤¯¤Ê¤ë¤Ë¤Ä¤ìÈæΨ¤Ï¾å¾º¤¹¤ë·¹¸þ¤Ë¤¢¤ê¡¢¾®µ¬ÌÏÁÈ¿¥¤Î¾ì¹ç¤ÏÌó48%¤Ë¾å¾º¤¹¤ë¡£

´ë¶Èµ¬ÌϤ´¤È¤ÎÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ÎÀê¤á¤ë³ä¹ç¡¡°úÍÑ¡§Silverfort

¡ûÈó¿ä¾©¤Îǧ¾Ú¥×¥í¥È¥³¥ë

Windows¤Ç¤ÏÀȼå¤Êǧ¾Ú¥×¥í¥È¥³¥ë¤ÎNTLM¤¬¤¤¤Þ¤À¤Ë»ÈÍѤµ¤ì¤Æ¤¤¤ë¡£Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ÎÌó46%¤ÏÀȼå¤ÊNTLM¤ò»ÈÍѤ·¤Æ¤¤¤ë¡£

NHI¤Îǧ¾Ú¤Ë»ÈÍѤ¹¤ëNTLM/Kerberos¤Î³ä¹ç¡¡°úÍÑ¡§Silverfort

¡û¤½¤Î¾¤Î³µÍ×

Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤Î²Ä»ë²½¤ò¼Â¸½¤·¤Æ¤¤¤ëÁÈ¿¥¤Ï¤ï¤º¤«5.7%¤È¤µ¤ì¤ë¡£62%¤ÏÉôʬŪ¤Ê²Ä»ë²½¤·¤«¼Â¸½¤Ç¤­¤Æ¤¤¤Ê¤¤¡£¤Þ¤¿¡¢Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ò¥µ¥¤¥Ð¡¼¹¶·â¤«¤éÊݸî¤Ç¤­¤ë¤È³Î¿®¤·¤Æ¤¤¤ëÁÈ¿¥¤Ï20%ÄøÅÙ¡£8³ä¤ÎÁÈ¿¥¤¬Êݸî¤Ç¤­¤Ê¤¤¤Èǧ¼±¤·¤Æ¤¤¤ë¡£

¡ûÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ÎÊݸî

Silverfort¤ÏÄ´ºº·ë²Ì¤ò´ð¤Ë¡¢Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ÎÊݸîÊýË¡¤òÄó°Æ¤·¤Æ¤¤¤ë¡£¤½¤Î³µÍפϼ¡¤Î¤È¤ª¤ê¡£

ºÇ¾®¸¢¸Â¤Î¸¶Â§¤òÄɵ᤹¤ë¡£Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ËÂФ·¤Æ¤â¡¢¥½¡¼¥¹¡¢°¸Àè¡¢¥×¥í¥È¥³¥ë¡¢»þ´Ö¡¢¤½¤Î¾¤ÎÍ×°ø¤Ë´ð¤Å¤¤¤¿ºÇ¾®¸¢¸Â¤òÀßÄꤹ¤ë

Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ËÍ¿¤¨¤é¤ì¤ë¡ÖÀµ¾ï¤ÊÆ°ºî¡×¤òÄêµÁ¤¹¤ë

¡ÖÀµ¾ï¤ÊÆ°ºî¡×¤Ë°ãÈ¿¤¹¤ë°Û¾ï¤Ê³èÆ°¤ò¸¡½Ð¤·¡¢·Ù¹ð¤¹¤ë

°Û¾ï¤Ê³èÆ°¤ò¸¡½Ð¤·¤¿ºÝ¤Ë¤Ï¡¢¼«Æ°¤Ç³èÆ°¤ò¥Ö¥í¥Ã¥¯¤¹¤ë

¿Í×ÁÇǧ¾Ú¤ÈƱÍͤˡ¢Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤Ë2½Å¤ÎÊݸî¤òƳÆþ¤¹¤ë

¶áǯ¤Ï¿¤¯¤Î´ë¶È¤«¤éÆü¡¹¿·¤·¤¤¥µ¡¼¥Ó¥¹¤¬À¸¤ß½Ð¤µ¤ì¤Æ¤¤¤ë¡£¤³¤ì¤é¿·¤·¤¤¥µ¡¼¥Ó¥¹¤Ï´û¸¤ÎÊ£¿ô¤Î¥µ¡¼¥Ó¥¹¤ÈÏ¢·È¤·¡¢¼«Æ°²½¤ò¼Â¸½¤¹¤ë¤¿¤á¿¤¯¤ÎÈó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤ò»ÈÍѤ¹¤ë¡£

¤³¤Î·¹¸þ¤ÏAI(Artificial Intelligence)¤ÎÅоì¤Ë¤è¤ê¤µ¤é¤Ë²Ã®¤¹¤ë¤ÈͽÁÛ¤µ¤ì¤Æ¤ª¤ê¡¢Èó¿Í´Ö¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¤Ï¤µ¤é¤ËÁýÂ礹¤ë¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£¤³¤ì¤Ï¥µ¥¤¥Ð¡¼ÈȺá¼Ô¤ÎɸŪ¤¬Áý¤¨Â³¤±¤ë¤³¤È¤ò°ÕÌ£¤·¤Æ¤ª¤ê¡¢·üÇ°¤µ¤ì¤ë¥ê¥¹¥¯¤ò·Ú¸º¤¹¤ë¤¿¤á¡¢´ë¶È¤äÁÈ¿¥¤Ë¤ÏÀѶËŪ¤Ê²Ä»ë²½¤ÈÂкö¤Î¼Â»Ü¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£

;;link;

https://news.mynavi.jp/techplus/article/20240814-3004721/

https://news.mynavi.jp/techplus/article/20240813-3002171/

https://news.mynavi.jp/techplus/article/20240813-3002775/

https://news.mynavi.jp/techplus/article/20240812-3002641/