2022幎2æ9æ¥ã®æ¥æ¬çµæžæ°èã«ãã¡ãŒã«ãªãããŸãæ»æãæ¥æ¬äŒæ¥ã®çŽ8å²ã察çäžå - æ¥æ¬ãã«ãŒããã€ã³ãã調æ»ãæ¬§ç±³äŒæ¥ã«æ¯ã¹å¯Ÿçé ãããšããèŠåºãã®èšäºãæ²èŒãããŸããããã«ãŒããã€ã³ãã®èª¿æ»ãå ã«ããèšäºã§ããæ¬ããã°ã§ã¯ãã®æ¥æ¬ãé ããŠãã察çã¯äœãªã®ãïŒãªããã®ãããªå¯Ÿçãå¿ èŠãªã®ãã以äžã«èšèŒãããã€ã³ãã§è©³ãã解説ããããšæããŸãã
- æ»æã®èµ·ç¹ã¯ã人ãã®è匱æ§ãã€ããã£ãã·ã³ã°ã¡ãŒã«ãæå€
- éšãã®ææ³ïŒãªãããŸãã®ïŒã€ã®æå£
- æ¥æ¬ã®çµç¹ã倧ããé ããDMARC察ç
- DMARCãšã¯
- ã¡ãŒã©ãŒã«è¡šç€ºãããã¡ãŒã«ã¢ãã¬ã¹ã¯ç°¡åã«åœè£ ã§ãã
- DMARCã®ä»çµã¿
- DMARCã§ã§ããããš
- èªçµç¹ãDMARCã«å¯Ÿå¿ããŠããã調ã¹ãã«ã¯ïŒ
æ»æã®èµ·ç¹ã¯ã人ãã®è匱æ§ãã€ããã£ãã·ã³ã°ã¡ãŒã«ãæå€
å šäžçã§çåšãæ¯ããã©ã³ãµã ãŠã§ã¢ããå®ã¯æ»æã®èµ·ç¹ã®75%以äžã¯ã¡ãŒã«ã§ããããšãPalo Alto Networksã®èª¿æ»*1ã«ãã倿ããŠããŸãããŸãVerizon瀟ã®DBIR(2021幎床ããŒã¿æŒæŽ©/䟵害調æ»å ±åæž)*2ã«ãããšãããŒã¿æŒæŽ©/䟵害ã®85%ã¯äººçèŠå ã«ãããã®ã§ããã®äžã§ããã£ãã·ã³ã°ã¡ãŒã«ã¯äŸµå®³ã®36%ãšãã£ãšã倧ããªèŠå ã§ãããšå ±åãããŠããŸãã
å®éãäžçã§ãã£ãšãå€ãã®ã¡ãŒã«ãæ€é²ããŠãããã«ãŒããã€ã³ãã®èª¿æ»ããããæšå¹Ž2021幎ã®ã¡ãŒã«ã«ãããæ»æåé¡ã§ã¯ãèªèšŒæ å ±ãçªåãããã£ãã·ã³ã°ã¡ãŒã«ããã£ãšãå€ãããšãåãããŸããïŒå³ïŒãåç §ïŒ

å³ïŒïŒ2021幎ãæå€§ã®æ»æçµè·¯ã§ããã¡ãŒã«ã®æ»æåé¡
OSã®ã¢ããããŒããé »ç¹ã«ãªãã«ã€ããŠãã·ã¹ãã ã®è匱æ§ã¯ä»¥åãããçŽ æ©ãåãããã€ã€ãããŸãããŸãé«åºŠãªã»ãã¥ãªãã£é²åŸ¡ãåããããšã«ããé«åºŠãªæ»æã¯ããã»ã¹ã®æ¯ãèããªã©ã§é²åŸ¡ã·ã¹ãã åŽã§èŠç Žããããã«ãªããŸããããã®ãããªäžã§ãé«åºŠãªãã¯ããã¯ã䜿ããããŠãèªèšŒæ å ±ããã£ãã·ã³ã°ïŒé£ãïŒããããŒãã¯ãªæ»æææ³ã¯ãæ»æè ã®äžã§ä»¥åãšããŠæè³å¯Ÿå¹æé«ããæåçãé«ããã®ãšããŠäººæ°ããããŸãã
ãŸããµã€ããŒç¯çœªãšã³ã·ã¹ãã ã®é²åã«ããããã£ãã·ã³ã°ãªã©ã§çªåããèªèšŒæ å ±ãã¢ã³ããŒã°ã©ãŠã³ãã§å¥ã®æ»æè ã«å£²ããã¢ã¯ã»ã¹ãããŒã«ãŒããšåŒã°ããæ»æã°ã«ãŒãã®ç»å Žã«ããã売ãããèªèšŒæ å ±ãçšããŠå¥ã®æ»æè ããããã«æ å ±ãçã¿åã£ãããç Žå£ã®æ»æãå®è¡ããããã©ã³ãµã ãŠã§ã¢ãã°ããŸã倿®µéã®æ»æãèŠãããããã«ãªããŸãããæ»æè ã¯ãäŸµå ¥ã®å ¥å£ãšããŠã人ãã®è匱æ§ãçãããšã«ãããå¹ççã«äŸµå ¥ããããªã£ãŠããŸãã
éšãã®ææ³ïŒãªãããŸãã®ïŒã€ã®æå£
ã§ã¯ãã£ãã·ã³ã°ã¡ãŒã«ã䜿ãããªãããŸããã®ææ³ã«ã¯ã©ã®ãããªãã®ãããã§ããããïŒãã£ãã·ã³ã°ã¡ãŒã«æ»æã®èã¯ãä¿¡é Œã§ããéä¿¡è ã«ãªãããŸãåœè£ ããŠãæ£èŠã®äººç©ããã®ã¡ãŒã«ã§ãããšæãããç¹ã«ãããŸããåœè£ ããããã®ãã¯ããã¯ã¯äž»ã«ïŒã€ããããããããããªãã¹ã察å¿ã¯ç°ãªããŸããã€ãŸãå€å±€ã¢ãããŒããå¿ èŠã§ããïŒå³ïŒåç §ïŒ

å³ïŒïŒäž»ãªããªãããŸãã¡ãŒã«ãã®æå£
ãªãããŸãã¡ãŒã«ã®æå£â ã衚瀺å(Display Name)è©æ¬º
ã¡ãŒã«å·®åºäººã®è¡šç€ºåã¯ãå±±ç°å€ªéããšãªã£ãŠããã®ã«ãã¡ãŒã«ã¢ãã¬ã¹ã¯ãŸã£ããå¥äººã®ã¢ãã¬ã¹ãattacker@attacker.comãã䜿ãããŠãããã®ã§ããããã¯åã«ã¡ãŒã«ã¢ãã¬ã¹ã確èªããã°ããã«èŠç Žãããšãã§ããåçŽãªæ»æã§ãããæ°å€ãè©æ¬ºã¡ãŒã«ãéä¿¡ããã°ãäžå®æ°ã®äžæ³šæãªäººãåŒã£ãããããã«ãã䜿ããããã¯ããã¯ã§ãã
ãã£ãã·ã³ã°æ»æãã£ã³ããŒã³ã¯ãæ¥æ¬ã®éè¡ãæ¥æ¬ã®ã¯ã¬ãžããã«ãŒãäŒç€Ÿã«ãªãããŸããããæ¥æ¬ã®æåãªã·ã§ããã³ã°ãµã€ãã«çŽãããã®ãéåžžã«å€ãã§ãããããã¯æ¥æ¬ã®å人æ å ±ãã¯ã¬ãžããã«ãŒãæ å ±ã¯ãã¢ã³ããŒã°ã©ãŠã³ãã§ä»ã®åœã®äººã®å人æ å ±ããé«ã売ããããã§ãã
衚瀺åè©æ¬ºã«å¯Ÿããæå¹ãªå¯ŸçãšããŠã¯ããŠãŒã¶ãŒã®ã»ãã¥ãªãã£æèãåäžãããã¬ãŒãã³ã°ãå¿ èŠã«ãªããŸãããããã¯åãåãåŽã®ã¡ãŒã«ã»ãã¥ãªãã£ã§åããŠåãåãéä¿¡å ã§ããããšã泚æåèµ·ãããããªä»çµã¿ã圹ç«ã¡ãŸãã
ãªãããŸãã¡ãŒã«ã®æå£â¡ãã¿ã€ãã¹ã¯ã¯ããã£ã³ã°
ããã«æãå ãããªãããŸãã®æå£ãšããŠãæ»æè ã¯ãªãããŸã人ç©ã«ãã䌌ãã¡ãŒã«ãã¡ã€ã³ã䜿ãå ŽåããããŸããã¡ãŒã«ãã¡ã€ã³ãšã¯@(ã¢ããããŒã¯)ããåŸãã®éšåãæããŸããäŸãã°ãã¡ãŒã«ã¢ãã¬ã¹ãtaro.yamada@yamada-shoji.co.jpã§ããã°ããã¡ã€ã³ã¯yamada-shoji.co.jpã®éšåã§ããæ»æè ã¯ãªãããŸã人ç©ã䜿ã£ãŠãããã¡ã€ã³ã«ãã䌌ããã¡ã€ã³ã䜿ããŸããäŸãã°ããyamada-shojiãã®o(ãªãŒ)ã0(ãŒã)ã«çœ®ãæãããªã©ããŠéåžžã«ãã䌌ãé¡äŒŒãã¡ã€ã³ãçšããã®ã§ãããã®å¯ŸçãšããŠã¯ãèªç€Ÿã®ã¡ãŒã«ãã¡ã€ã³ã«äŒŒããããªãã¡ã€ã³ãç»é²ãããŠããªããã宿çã«äŒæ¥åŽã§èŠåŒµããå¿ èŠã«å¿ããŠãã®ãã¡ã€ã³ããã€ã¯ããŠã³ãã(䜿çšã忢ããã)å¿ èŠããããŸãã
ãªãããŸãã¡ãŒã«ã®æå£â¢ Reply-toè©æ¬º
Reply-toè©æ¬ºãšã¯ã衚瀺ãããŠããã¡ãŒã«ã¢ãã¬ã¹ã§ã¯ãªããè¿ä¿¡ããéã«å¥ã®ã¡ãŒã«ã«è¿ä¿¡ãããReply-toãã®æ©èœãæªçšãããã®ã§ãããã®æ»æãžã®å¯ŸçãšããŠã¯ãåãåãåŽã®ã¡ãŒã«ãœãããŠã§ã¢ã®æ©èœãšããŠãéãã¢ãã¬ã¹ã«è¿ä¿¡ããããšããŠããããšãäŒããæ©èœãæ±ããããŸãã
ååŒå ã«ãªãããŸããŠééãæç€ºãããããªããžãã¹ã¡ãŒã«è©æ¬º(BEC)ã§ããã®ãªãããŸãã®ææ³ã¯ãã䜿ãããŸãã
ãªãããŸãã¡ãŒã«ã®æå£â£ ãã¡ã€ã³ã®ãªãããŸã
æåŸã«ãªãããŸãææ³ã®äžã§ãã£ãšãé«åºŠãªãã®ããã¡ã€ã³ã®ãªãããŸãã§ããã¡ãŒã«ãœããã«è¡šç€ºãããéä¿¡è åãã¡ãŒã«ã¢ãã¬ã¹(header-from)ãæ£èŠã®ãã®ã䜿ãããŠããããã«ãã¡ãŒã«ã®åãåãæãèŠç Žãããšã¯éåžžã«é£ãããã®ã«ãªããŸãã
ããããã®ãã¡ã€ã³ãªãããŸããèªåã§èŠç Žãããšãã§ããéåžžã«æå¹ãªå¯ŸçããããŸãããããDMARCèªèšŒã§ãããªãããŸãããåŽã®äŒæ¥ããèªçµç¹ã«ãªãããŸããã¡ãŒã«ãã©ãã ãäžã«åºãŠããããå¯èŠåã§ããã ãã§ãªãããã®ãªãããŸãã¡ãŒã«ãåé€ããããéé¢ãããªã©ã®åŠçãæå®ããããšãã§ããæ±ºå®çãªæå¹æãšãªããã®ã§ããéåžžã«åŒ·åãªå¯Ÿçã§ãããæ®å¿µãªããæ¥æ¬äŒæ¥ã®å¯Ÿå¿ã¯ãä»ã®åœãšæ¯èŒããŠå€§ããé ããŠããŸãã
æ¥æ¬ã®çµç¹ã倧ããé ããDMARC察ç
DMARCã¯ããã¡ã€ã³ã®ãªãããŸãã匷åã«é²ãããšãã§ããå¯äžã®èªèšŒæè¡ã§ãããããäžçªãããããªèšå®ã§ããã°ãçŽ15åã§å¯Ÿçãéå§ããããšãã§ããŸãã

å³3: ååœã®DMARC察å¿ç¶æ³(2021幎12æèª¿ã¹)
ãã«ãŒããã€ã³ãã2021幎12æã«ãããªã£ã調æ»ïŒå³3ãåç §ïŒã«ãããšãã¢ã¡ãªã«ã§ã¯82%ããã©ã³ã¹ã§75%ããªãŒã¹ãã©ãªã¢75%ãã€ã®ãªã¹ã§72%ãªã©ã欧米ã§ã¯DMARC察çãé²ãã§ããããšãåãããŸããäžæ¹ã§ãæ¥æ¬ã®æ¥çµ225äŒæ¥ã§ã¯ãã£ãã®24%ãã察çãã§ããŠããŸãããããïŒå¹Žã§æ¬§ç±³ã§ã¯DMARCã®å°å ¥ãå éãã15-20ãã€ã³ãè¿ããŸã§å°å ¥çãããããŸããããæ¥æ¬ã¯ã»ãŒå€ããããªããæ¥çµ225äŒæ¥ã®çŽ4åã®3ããã¡ã€ã³ãªãããŸãã®å¯Ÿçã«çæã§ããŠããªãããšãåãããŸãã
ãŸã什å3幎11æ22æ¥ã¥ãã®éèåºéè¡å èš±äžèЧãããéœåžéè¡ïŒè¡ãä¿¡èšéè¡13è¡ããã®ä»16è¡ã®DMARCå°å ¥çã調ã¹ããšããã2022幎1æ7æ¥ã®æç¹ã§ã¯ããªããšæ¥æ¬ã®äž»èŠéè¡ã®55%ãDMARCãæªå°å ¥ãšããããšã倿ããŸãããäžçã«æµéããŠãããã£ãã·ã³ã°ã¡ãŒã«ã®äžã§ããæ¥æ¬ã®éè¡ãã¯ã¬ãžããã«ãŒãäŒç€Ÿã«ãªãããŸããã£ãã·ã³ã°ã¡ãŒã«ã¯äžäœãå ããã«ãé¢ããã察çãã§ããŠããªãã®ã宿 ã§ãã
DMARCãšã¯ïŒ
DMARC (Domain-based Message Authentication Reporting and Conformanceãèªã¿æ¹ïŒãã£ãŒããŒã¯ïŒ ã¯ãEã¡ãŒã«ã«é¢ããäž»èŠãªçµç¹ã«ãã£ãŠçå®ããã2012幎2æã«çºè¡šãããéä¿¡ãã¡ã€ã³èªèšŒæè¡ã§ããããžãã¹ã¡ãŒã«è©æ¬º (BEC / Business email compromise) ããã£ãã·ã³ã°æ»æããªãããŸãã¡ãŒã«ãšã®éãã«ãããŠãçŸæç¹ã§æã匷åã§ããã¢ã¯ãã£ãã«é²åŸ¡ãã§ããæŠåšã®1ã€ã§ãã
DMARCã¯æ¢åã®æšæºæè¡ã§ããSPF (Sender Policy Framework) ããã³DKIM (DomainKeys Identified Mail) ãããŒã¹ã«ããŠããã ã¡ãŒã«ã«è¡šç€ºãããéä¿¡å ã¢ãã¬ã¹ãheader-fromããã¡ã€ã³ããªãããŸãããŠããªãããä¿¡é Œã§ãããã®ãã©ããã倿ããããšãã§ããæåã®æšæºæè¡ã§ãçŸæç¹ã§åºãéçšãããŠãããã®ãšããŠã¯å¯äžã®ãã¯ãããžãŒã§ãã
ã¡ãŒã©ãŒã«è¡šç€ºãããã¡ãŒã«ã¢ãã¬ã¹ã¯ç°¡åã«åœè£ ã§ãã

å³4: ã¡ãŒã©ãŒã«è¡šç€ºãããã¡ãŒã«ã¢ãã¬ã¹ãæ¬ç©ã ãšã¯éããªã
å®ã¯ã¡ãŒã«ãœããã«è¡šç€ºãããã¡ãŒã«ã¢ãã¬ã¹ã¯ãç°¡åã«åœè£ ããããšãã§ããŸããå®éã®éä¿¡ããã¡ãŒã«ã¢ãã¬ã¹ãšãã¡ãŒã«ãœããã«è¡šç€ºãããŠããã¡ãŒã«ã¢ãã¬ã¹(header-from)ãåããã®ã§ããã®ãããã€SPFãããã¯DKIMèªèšŒãã¯ãªã¢ããæ£åœãªã¡ãŒã«ãªã®ããèŠç Žã£ãŠãããã®ãDMARCã§ãã
DMARCã®ä»çµã¿
DMARCã®ä»çµã¿ã¯ãŸãå¥ã®èªèšŒæè¡ã§ããSPFãšDKIMãåæãšãªã£ãŠããŸãããããŠSPFãDKIMãæèŒããŠããã°ãããã«DMARCãå§ããããšãå¯èœã§ãã以äžã®ãããªã§ã¯DMARCãšSPFãDKIMã®é¢ä¿ãã¢ãã¡ãŒã·ã§ã³ã§åããããã解説ããŠããŸãã
DMARCã§ã§ããããš
DMARCãå°å ¥ãããšãããªãã®çµç¹ã®ãã¡ã€ã³ãæªçšãããªãããŸããã¡ãŒã«ãå¶åŸ¡ããããšãã§ããŸããDMARCã¯ä»¥äžã®ïŒçš®é¡ã®å¶åŸ¡ãæœãããšãã§ããŸãã
- none(ç£èŠã®ã¿)ïŒã¡ãã»ãŒãžã¯åä¿¡è ã«é ä¿¡ãããŸãã
- quarantine (éé¢)ïŒã¡ãã»ãŒãžãéé¢ãã©ã«ãã«ç§»åããŸãã
- reject (æåŠ)ïŒã¡ãã»ãŒãžã¯å šãé ä¿¡ãããŸããã
DMARCèªèšŒãå®ç§ã«éçšããã«ã¯ã"reject"èšå®ã«ããã®ãæãŸããã§ãããèªçµç¹ã䜿ã£ãŠããã¡ãŒã«ã·ã¹ãã ããã¹ãŠææ¡ããå¿ èŠããããŸãããããã"none"ã®ã¢ãã¿ãªã³ã°ããã ãã®èšå®ã§ããã°ãããã«å§ããããšãã§ããŸãããããç¹ã«è²»çšã¯ããããŸããã
ã¢ãã¿ãªã³ã°(DMARCèšå®ã§ã¯p=none)ãå§ããã°ããã®çµç¹ã«ãªãããŸããã¡ãŒã«ã®ç¶æ³ãã¬ããŒããããããã«ãªããããæ»æè ã身å ãã°ããã®ãæ¬é ããŠãªãããŸãããããªããªãããã«ãªããŸãã
ä»äžåºŠãã¡ãŒã«ã·ã¹ãã ã®æ£åžããå ŒããŠãDMARCå°å ¥ãæ€èšããŠã¯ãããã§ããããïŒæ»æã¯ãµãã©ã€ãã§ãŒã³ã䜿ã£ãŠå±éãããäŸµå ¥ã®çµè·¯ãšããŠã¯ã人ãã®è匱æ§ãçãããŠããŸãããµã€ããŒã»ãã¥ãªãã£ã¯èªçµç¹ãå®ãããã ãã®ãã®ã§ã¯ãªããããªãã®çµç¹ãšã€ãªãããã¹ãŠã®çµç¹ãšäººãå®ãããã®èŠç¹ãå¿ èŠã§ãã
DMARCãå§ããã
ããªãã®çµç¹ãDMARCãå°å ¥ããŠããã®ã調ã¹ãã«ã¯ããDMARCãã§ãã¯ããŒã«ãã§ç°¡åã«èª¿ã¹ãããšãã§ããŸãããŸããã®ããŒã«ããã貎瀟ã®DMARCã¬ã³ãŒããäœæããããšãå¯èœã§ãã
ãŸãç¡æã®ãDMARCã¹ã¿ãŒãã¬ã€ãããç¡æã®ãŠã§ãããŒã15åã§èšå®ïŒDMARCãããçšæããŠãããŸãã®ã§ãããããŠãå©çšããã ããŸããšå¹žãã§ãã
ãã«ãŒããã€ã³ãã§ã¯ãå€ãã®ãã¡ã€ã³ãæã¡ãããŸããŸãªãµãŒãããŒãã£ã·ã¹ãã ãªã©ããã¡ãŒã«ãéä¿¡ããè€éãªã¡ãŒã«ãšã³ã·ã¹ãã ããæã¡ã®ã客æ§åãã«DMARCèªèšŒã容æã«ãããœãªã¥ãŒã·ã§ã³Proofpoint EFD (Email Fraud Defense)ãæäŸããŠããŸãããã²ãæ°è»œã«ãçžè«ãã ããã
*1: Paloalto Networks ãRansomware Families: 2021 Data to Supplement the Unit 42 Ransomware Threat Reportãhttps://unit42.paloaltonetworks.com/ransomware-families/
*2: Verizon ãDBIR 2021ã: https://www.verizon.com/business/resources/reports/dbir/
