More Related Content
Similar to Kobe sec#11 summary
Similar to Kobe sec#11 summary (20)
More from Yukio NAGAO (7)
Kobe sec#11 summary
- 1. 第 11 å ç¥æžæ
å ±ã»ãã¥ãªããå匷äŒ
(ã»ãã¥ã¡ã) ãŸãšã
2010幎02æ27æ¥
- 4. ç³å
ç
颚è©ãããã #1
ï§ ãå®å
šç§å¿æå·ã§ãªããã°ãå¿
ãç Žãããšãã§ããã
ï§ =>ãç¥ããªãã
ï§ ãã®ã³ã³ãã¯ãéµã®å
šæ¢çŽ¢ã
ï§ å¹³æãšæå·æã®ããããã³ãã«ãéµãæ¢çŽ¢ã§ããããšã
ï§ çµå±ãå®çšçãããªãã
ï§ éµã®å®å
šæ§ã¯ãããã¡ãã£ã
ï§ ã ãã©ãå§åçã«é²åŸ¡åŽã«åãè¯ãã
ï§ Copacobana ã¯å¹³å 6.4 æ¥ã§ DES ã解èªãéµã®ãããé·ãå¢å
ãããšãæ¢çŽ¢æéãå¢å ã
ï§ éµãã¡ãã£ãšé·ãããã ãã§ãææ°é¢æ°çã«è§£æã«èŠããæé (æ
é) ãå¢ããã
ï§ æå·è§£æã®ç 究è
ã¯ãææ°é¢æ°æ²ç·ã®åºŠåã (ã«ãŒã) ãäœãã
(ç·©ãã) æç«ãŠãæ¢ã
- 5. ç³å
ç
颚è©ãããã #2
ï§ 2006/7 MISTY ã«é¢ããçºè¡š (äžçåïŒ)
ï§ ãããå€ãªé¢šè©ãåºãã
ï§ ãå·®åæ»æãç·åœ¢æ»æã«é¢ããŠå®å
šã§ããããšã蚌æããããã ã
ãªã®ã«ãé倧ã«è©äŸ¡ãããå ±éã§ããåã£ã±ã¡ãåŒã°ãããããäœ
å°ãã§ããŠããŸãã
ï§ RSA 㯠AES ããå®å
šïŒ
ï§ çŽ å æ°å解åé¡ã¯ãæªã å¹æçãªãã«ãŽãªãºã ãçºèŠãããŠããªãã
ã®ã§æå¹ã
ï§ ã§ããéµã®æ¢çŽ¢ã ããå¯äžã®æ»æã§ã¯ãªããäŸãã° SSL ãµãŒãã®
åå¿ (SSL ãã³ãã·ã§ã㯠: éµã®å©çšå¯åŠãã§ãã¯) ãå©çšããŠã
æå·æãšå¹³æã®ããã䜿ã£ãŠãç·åœãçãªæ»æãæããããšãã§ã
ãïŒ
ï§ ãã®çè«ãçºè¡šãããŠãããSSL ã®ä»çµã¿ãå€æŽãããã
- 6. ç³å
ç
ãŸãšããQA
ï§ æå·ã¯ã³ãæè¡ããã€æ°åŠçãªæè¡ã®è©³çŽ°ãç解ãã¥ãã
ã®ã§ã颚è©ãå€ããã§ããæè¡ã®è©³çŽ°ãããããªããŠãã
ææ¡ã§ããïŒ
ï§ QA
ï§ Q1:ã2010 幎åé¡ (8bit æå·ãçŠæ¢ãããïŒ)ããšã¯ïŒ
ï§ A1:åæã«å°å
¥ãããã80bit æå·ããçŠæ¢ãããã
ï§ SHA-1 ãªã©ããã·ã¥é¢æ°ã®å¯¿åœãçãããšãèŠè¶ããä»çµã¿ãå€ãã
ããåã«ããŸãã¯çãéµé·ã®èŠå¶ãã察çããããšãç®çïŒ
ï§ Q2:äžè¬ãŠãŒã¶ããããŠããSSL éä¿¡ãã§ã®ããåãã¯ãç ŽãããŠ
ãããã®ãïŒ
ï§ A2:ææ°ãã©ãŠã¶ã䜿ãããåãããŠãå Žåã¯ãéä¿¡è·¯äžã§ãŸãç Ž
ãããªãã
ï§ ãã ããSSL ãµãŒããä¿¡é Œã«è¶³ããã©ããã¯ã話ãå¥ãå®å®³ããã
- 9. æŠç°å
ç
ãã»ãã¥ãªãããããã§ãã·ã§ãã«ã®æèãšãã£ãªãã#3
ï§ æ
å ±ã»ãã¥ãªãããšã¯ïŒ
ï§ CIA (ç§å¿ãå®å
šãå¯çš) ãæ°åŠç©çã®ãå
¬åŒããšèããããïŒ
ï§ äŸ¿å©ãªã·ã¹ãã ã»ã©å±éºãé«ãïŒ
ï§ æ
å ±ãªã¹ã¯ = è³ç£ * è
åš * è匱æ§
ï§ çµç¹ã®ç®çãšç®æšãã»ãã¥ãªããã®ç®çãšç®æšã¯ãçžåããŠãïŒ
ï§ ç®æšéæã®èŠä»¶ã¯ãïœããªããŠã¯ãªããªããã§ãã»ãã¥ãªããèŠä»¶ã¯
ãïœãã£ãŠã¯ãªããªããã§ãããã»ãã¥ãªããã¯éå
·ã«ããéããªãã
ï§ è²»çšå¯Ÿå¹æã®èãæ¹ã¯ãã(äºæ
çºçç¢ºç« * æ倱) - ã³ã¹ãããïŒ
ï§ æ£ç¢ºã«ã¯ã(æåŸ
æ倱é¡ã®å€å - 察çã³ã¹ã) / 察çã³ã¹ãã
ï§ ãã»ãã¥ãªãã察çã¯ããªãã»ããè¯ãããçµè«ïŒ
ï§ äžçªè¯ãã®ã¯ãäœã察çããããäœãèµ·ãããªãã
- 10. æŠç°å
ç
ãã»ãã¥ãªãããããã§ãã·ã§ãã«ã®æèãšãã£ãªãã#4
ï§ ã»ãã¥ãªãããããã§ãã·ã§ãã«ã®æè
ï§ é¡§å®¢ãã»ãã¥ãªãããããã§ãã·ã§ãã«ã«æ±ãããã®ã¯ããå®å
šã
ã®ã¿ãã»ãã¥ãªãããããã§ãã·ã§ãã«ãåºããŠãããã®ã¯ãæ
æãã§ããã¹ãããã
ï§ å»è
ã«ããšãããšåãããããã
ï§ äžã€ã®äŸãšããŠãã察çãªããŠããããŸã§ã§è¯ãã§ãããã ãšå®å¿
ãããïŒ
ï§ ãªã¹ã¯å¯Ÿçããããªã¹ã¯ããªãã (ç¡å¹åãã) ã§ã®åé¿
ï§ Secure by Design ã®äŸ:
ï§ Web ãããªã§ã®äžèŠãª SQL ãµãŒãã®æé€ (äŸãã°ããããã«ããŒã¹
ã§ããåã)
ï§ æš©éã®åé¢ãäžèŠãªå人æ
å ±ã®æé€ (å¿
èŠä»¥å€ã®æ
å ±ã¯å
¥åãããªã)ã
å
éšåŠçã§ã®å
éšã³ãŒãã®äœ¿çš (å€éš I/F ããåé¢ããã)
- 11. æŠç°å
ç
ãã»ãã¥ãªãããããã§ãã·ã§ãã«ã®æèãšãã£ãªãã#5
ï§ å¿
èŠãªã³ã
ï§ ãããªãªãã¢ã¬ãªã
ï§ (MECE : Mutually Exclusive and Collectively Exhaustive)
ï§ å
šãŠã®è
åšã«å¯ŸããŠã察çãæŒããªãèããã
ï§ ããã¯ãããŒã¹ã§èãããæã蟌㿠(æ¶æž¬) ã§ãªãã仮説
ãšæ€èšŒã§ã
ï§ ããããã®æ
å ±ã»ãã¥ãªããã¯ïŒ
ï§ ãå®ããããªã«ãããªããŠããå®å
šããªãœãªã¥ãŒã·ã§ã³ïœ
ï§ ã»ãã¥ãªããã¹ãã·ã£ãªã¹ãã¯ãžã§ãã©ãªã¹ã
ï§ ç¹å®æè¡ç¹ååã®äººããããã©ããããŠããžã§ãã©ãªã¹ãèŠçŽ ãã
ï§ ã§ããã瀟é·ãããªããšããããïŒããªé åã«çªå
¥ããããã
- 12. æŠç°å
ç
ãã»ãã¥ãªãããããã§ãã·ã§ãã«ã®æèãšãã£ãªãã#6
ï§ QA
ï§ Q: ã»ãã¥ãªããã«æºããã²ãšã®å«ç芳ã®æè²ã¯ïŒ
ï§ A: (ããçš®å±éºãª) èœåãçºæ®ã§ããå Žãèšããããšã§ãææ矩ãª
æ¹åã«æã£ãŠãããã®ã§ã¯ïŒæ¥æ¬ã§ã¯ãªãã©ã·ãæ¯èŒçé«ãïŒå±éº
(ç掻ãç Žå£ããã) ãåããªã¹ã¯ãé«ãã
ï§ äºåãã³ã±ãŒãã§ã® Question
ï§ Q1:ãã¬ã³ãã©ãŒãã«ãããµããæ¹ããã話é¡ã ããã¯ã©ãã«ãŒã«
çãããäŒæ¥ã«ã€ããŠãçãããããäœãå
±éç¹ã¯ãããïŒ
ï§ A1 :察çã®åŒ±ããšãããè€æ°ãµããã被害ã«éã£ãã®ã¯ãã³ã³ãã³
ãäºæ¥è
ãè€æ° Web ãµããã®ãããããŒããããŠããããã
ï§ Q2:éã®ãã¯ã©ããã³ã°æ
å ±æäŸãã«ãŒãããã販売ããããŠããµ
ãããæçºããããšãããã¥ãŒã¹ãèããªãã®ã¯äœæ
ãïŒ
ï§ A2:åçŽãªã販売ããæ
å ±æäŸãã ãã§ã¯æçºã§ããªãããã ãã
ISPãªã©ã§ç· ãåºãããšãªã©ã¯ãã£ãŠããã
- 13. ãã³ã¿ãŒããã·ã§ã³
ãã¯ã©ãŠãã»ãã¥ãªããã«é¢ãã 1ã€ã®ããããŒãã
ï§ ãšããå®èšŒå®éš
ï§ ãããœã³ã³ã®äžã«ä¿åããã®ã«ãããŒã¿ã»ã³ã¿ãŒãšããœã³ã³ã§åæ£
ä¿ç®¡ãããïŒã
ï§ ãããã«ãæ§æããå
šãŠã®ãå²ç¬Šããæããªããšãæ©å¯æ§ãä¿ã¡ãã
ãããéèŠãªæ
å ±ãããéèŠãããªãæ
å ±ãã«åå²ããïŒ
ï§ æ
å ±ã®æ¡æ£ãšä¹³åãå·¥åŠçåŠçãªã®ã§ãæå·ãã§ã¯ãªãã
ï§ ç§å¯åæ£ããã 1 çã®ãããŒã¿ãã®æ±ãã«ã€ããŠããå人
æ
å ±ã§ã¯ãªããã説æ責任ãªãããæ°äºèšŽèšã¯åé¿ã§ã
ãããšããã³ã¡ã³ã (å
¬åŒèŠè§£ã§ã¯ãªã) ã¯ãçåºãé¢ä¿
åŒè·å£«ããåŸãããŠããã
ï§ å€éšã¹ãã¬ãŒãžã®äœ¿çšãªã¹ã¯ãã³ã¹ãããã¯ã©ãŠããã«
ãã£ãŠåé¿ã§ããïŒ
- 14. ããã¹ã«ãã·ã§ã³
ãã¯ã©ãŠããµãŒãã¹ã£ãŠã䜿ããŸããïŒã
ï§ è°è«ã®ããã³ã
ï§ ãGmailããªã©ã¯ã©ãŠããµãŒãã¹ãå©çšããŠãŸããïŒäœ¿çšãããã
ãŠããªãçç±ã
ï§ (瀟å
)ã·ã¹ãã ãã¯ã©ãŠãåã§ããŸããïŒ
ï§ éèŠããŒã¿ãã¯ã©ãŠããµãŒãã¹ãžå§ããããšã«æµæãããŸããïŒ
ãã®çç±ã¯ïŒ
ï§ (瀟å
ãªã©ã§)æ¢ã«ã¯ã©ãŠããå°å
¥ããŠããå Žåãã©ããªäœ¿ãæ¹ã
ããŠããŸããïŒ
ï§ ã¯ã©ãŠãã®æ®åã«ãããŠã解決ãã¹ã課é¡ã¯ïŒ
ï§ æµè¡ããšæããŸããïŒå»ãããšæããŸããïŒ
ï§ ããºã¯ãŒããšããŠã¯ãæµè¡ã£ãŠããŸãããã
ï§ ãããšããããæ®åããŠããïŒ
ï§ ãåºç€ããéçšãããŠãŒã¶ãããããã®èŠç¹ã§è°è«
- 15. ããã¹ã«ãã·ã§ã³
ãã¯ã©ãŠããµãŒãã¹ã£ãŠã䜿ããŸããïŒã#éçšåŽ
ï§ ããŒã¯ãŒããåæãã圢ã§ã
ï§ ããã³ããããã«æ²¿ã圢ã§èª¬æãããŠããŸãã
ï§ ãã¯ã©ãŠããã¯æåŸ
ã®çã§ããã
ï§ ãã¯ã©ãŠããã«éãããããµãŒãã¹ãããããŒã¿ãããµãŒãããå€
éšã«å§ããããšãã®ãã®ã«æµæãããã
ï§ ããµãŒãã¹ãã®å€éšå§èšã«ããã£ãŠãèªç€Ÿåºæã®ããµãŒãã¹ãæ©èœ
ããæšæºåããããããšãã§ãããããŸããã®ã³ã¹ãã«ã€ããŠãæª
ç¥æ°ã§ããã
ï§ ãå±æ©ç®¡çãã®èŠ³ç¹ãããããšããèéããªã©ã®åºæºãæºãããçµ
ç¹ã«ãµãŒããèšçœ®ããããšã¯ãªã¹ã¯äœæžãšãªãããããéçšã³ã¹ã
ãäžããå¯èœæ§ãããã
ï§ ãµãŒãã¹æäŸãè¡ãçµç¹ã§ã®ã¹ã±ãŒã«ã¡ãªããã«ããã³ã¹ãããŠã³ã
æ©åšãªã©ã®ãªãã¬ãŒã¹è²»çšäœæžãç¡èŠã§ããªãã
ï§ ãã ãããŸã ã¯ã©ãŠããµãŒãã¹ãèŠæ¥µããæ
å ±ã足ããªãéããã
- 16. ããã¹ã«ãã·ã§ã³
ãã¯ã©ãŠããµãŒãã¹ã£ãŠã䜿ããŸããïŒã#ãŠãŒã¶ãã®ïŒ
ï§ ããããããç®ã«èŠããªããã®(ããŒã¿)ããã©ãã(ããã
ãªããšãã)ã«ä¿åããããšãããªã¹ã¯ã
ï§ ã§ããã¯ã©ãŠããããããæ¢ã«æ°ã¥ããã«äœ¿ã£ãŠãŸããïŒ
ï§ èŠæš¡ (ãã¡ãªã«ã§ã®æšé²) ã«ããå€å§ïŒ
ï§ NW æ¥ç¶ãªãã§ã¯ããanytime ahywhereãã¯ç¡çïŒ
ï§ ãªãã©ãã³ã¯ïŒå°åæ Œå·®ã¯ïŒ
ï§ ããŒã¿ã®ä¿åç®æã¯ïŒ
ï§ ããŒã«ã«ïŒãã³ã¿ãŒããã (ããã¯ãããã¡ãªãã)
ï§ ã¯ã©ãŠãã¯å®å
šïŒèªåã®ããŒã PC ãšæ¯ã¹ãŠå®å
šã§ã¯ïŒ
ï§ ãã¯ã©ãŠããã売ãã«ããŠããéã¯å®å¿ã§ããªãã
ï§ éè¡ãæ¯èŸŒã¿ãATM ãåŒãåãã«èãããšããªã«ããã¯ã©ãŠ
ããã£ãŠã ãã§ããããçç±ã¯ãªãã®ãããªãïŒ
ï§ ãããŒã¿ã DC ã«ä¿åãããã¯ã©ãŠããå©çšãžã®ç¬¬äžæ©ïŒ
ï§ ãã¯ã©ãŠãäºæ¥è
ãã¯ãéè¡ã«æ¯è©ããååšãã«ãªãã¹ãïŒ
- 18. ããã¹ã«ãã·ã§ã³
ãã¯ã©ãŠããµãŒãã¹ã£ãŠã䜿ããŸããïŒã#åºç€æ§ç¯
ï§ äœ¿ã£ãŠãïŒ => 7åäž 3å (Gmail ããããªã)
ï§ ã客æ§ã«è¿«ãããŠããïŒå£²ãåºãåŽã«ãªãããã
ï§ ä¿¡çšããŸããïŒ
ï§ ä¿¡çšããŠãããã ãã¡ãŒã«éåä¿¡ã«éãã
ï§ ä¿¡çšã§ããããå¥çŽããŸãããã
ï§ ä¿¡çšããŠããªããä¿¡çšä»¥åã®åé¡ (ããããªéçšãç®ã®åœããã«)ã
ï§ SLA ã¯éèŠã§ããŠãŒã¶ã責任åçç¹ãææ¡ãã¹ãã
ï§ æäŸè
ãä¿¡çšã§ãããã
ï§ ãã¯ã©ãŠãããããæäŸæ©èœãšèŠæ±ããŸãšãŸããªããšè©±ã«ãªããªãã