Microsoft - æ»æè ãå·£ããå Žæ
ãã®æçš¿ã¯ãMicrosoft ãèŠéããŠããããŸããŸãªçš®é¡ã® People-Centric ãªã¡ãŒã«æ»æã«é¢ããããã°ã®ç¶ç¶ã·ãªãŒãºã§ããMicrosoft ã¡ãŒã«ã»ãã¥ãªãã£ãæã€æä»£é ãã®æ€ç¥æè¡ãšåºæã®å¶éã«ãããããããæ»æãçµç¹ã«æ¯å¹Žèšå€§ãªé¡ã«äžãæå€±ãäžããæ å ±ã»ãã¥ãªãã£ããŒã ãšãŠãŒã¶ãŒã«ãã©ã¹ãã¬ãŒã·ã§ã³ããããããŠããŸãããã®ã·ãªãŒãºã§ã¯ãMicrosoft ãèŠéããŠããããã€ãã®çš®é¡ã®æ»æã«ã€ããŠç޹ä»ããäºå®ã§ãããæè¿ã®äºäŸããæ¬¡ã«ã€ããŠè©³çްãã芧ããã ããŸãã
- ããžãã¹ã¡ãŒã«è©æ¬ºãã¡ãŒã«è©æ¬º
- ã©ã³ãµã ãŠã§ã¢
- ãµãã©ã€ãã§ãŒã³ ãªã¹ã¯
- ã¢ã«ãŠã³ã䟵害
- æŠåšåããããã¡ã€ã«å ±æ
ãã®æçš¿ã®äžçªäžããããã°ã®è³Œèªãç³ã蟌ã¿ããã®ãããªçµç¹ã«åœ±é¿ãåãŒãå¯èœæ§ã®ããèŠéãããŠããæ»æã®ææ°æ å ±ãåŸãŠãè åšã¢ã»ã¹ã¡ã³ãã§çµç¹ã®ãªã¹ã¯ãææ¡ããŸãããã
Microsoft ãèŠéããããžãã¹ã¡ãŒã«è©æ¬ºæ»æ
ããžãã¹ã¡ãŒã«è©æ¬º (BEC) ã¯ã¡ãŒã«è©æ¬ºã®äžçš®ã§ãèŠæš¡ãæ¥çã«ãããããééç被害ã倧ããè åšã§ãããçµæžçæå€±ã«ã€ããŠã¯ä»ã®ãµã€ããŒç¯çœªã®ååšãèŠå£ãããã»ã©ã§ãã
FBI ãšã€ã³ã¿ãŒãããç¯çœªèŠæ åŠçã»ã³ã¿ãŒ (IC3) ã®ãµã€ããŒç¯çœªå¹Žæ¬¡å ±åæžã«ãããšã2020 幎ã ãã§ã BEC ã®æå£ã«ããäŒæ¥ãšå人ãåãã被害ã¯ããã 20 åãã«ã«äžãã çµæžçæå€±ç·é¡ã® 44% ãå ãããšã®ããšã§ãããã㯠2019 幎ãã 1 åãã«å¢å ããŠããããšã«ãªããŸããä»ã«ã The Ponemon 2021 Cost of Phishing Study (Ponemon: ãã£ãã·ã³ã°æ»æã«ããæå€± 2021 ã¬ããŒã) ãªã©ã®èª¿æ»ã«ãããå€§äŒæ¥ 1 瀟ã 1 幎éã«åããçŽæ¥ããã³éæ¥æå€±ã®å¹³åé¡ã¯ããã 600 äžãã«ã§ããã£ãã·ã³ã°ã®ç·è¢«å®³é¡ã® 40% ãå ããããšã瀺ãããŠããŸãã

å³ 1: ãã«ãŒããã€ã³ãã¯æ¯æ¥ 1 äž 5000 ä»¶ãè¶ ãã BEC ã¡ãã»ãŒãžããããã¯ããŠããŸã
ãã«ãŒããã€ã³ãã¯å¹³åããŠæ¯æããã 45 äžä»¶ã® BEC æ»æãæ€ç¥ããŠããŸãããã 1 ãæã§ã¯ãè åšã¢ã»ã¹ã¡ã³ãã®éå®çãªããŒã¿ã»ããã ãã§ããMicrosoft ã®é²è¡ç·ãããæãã BEC è åšãããã 2100 ä»¶æ€ç¥ããŸããã
åŸæ¥å¡æ° 1 äž 8000 人ãè¶ ãããã倧æã¡ãŒã«ãŒã§ã¯ãããã 300 ä»¶ã®ãªãããŸãæ»æãéãããŸãããåŠçå®å¡ 1000 人ã®ãã倧åŠã§ã¯ãMicrosoft ã®ç£èŠã®ç®ãããæãã 150 ä»¶è¶ ã®ãªãããŸãã¡ãã»ãŒãžãè·å¡ã«éä¿¡ãããŸããããŸããåŸæ¥å¡æ°ããã 600 äººã®æ¯èŒçå°ããçµç¹ã§ããMicrosoft ã«ãã£ãŠæ€ç¥ãããªãã£ã 80 ä»¶è¶ ã®ãªãããŸãã¡ãã»ãŒãžãåä¿¡ããŠããŸãããããããPOC ã«ããã 1 ãæãè²»ãããŠããŸãã
以äžãæè¿è¡ããããã«ãŒããã€ã³ãã®è åšã¢ã»ã¹ã¡ã³ãã§ Microsoft ãåä¿¡ããã³éä¿¡ã§èŠéãã BEC æ»æã®çš®é¡ã玹ä»ããŸãã
çµŠäžæ¯èŸŒå 倿޿»æã®æŠèŠ:
çµŠäžæ¯èŸŒå 倿Žã¯ãäž»ãšããŠè²¡åãçšåã絊äžã人äºéšéã®åŸæ¥å¡ãæšçãšããã¡ãŒã«è©æ¬ºæ»æã§ãããã®æ»æã¯ããŸããŸãªãœãŒã·ã£ã« ãšã³ãžãã¢ãªã³ã°ã®ææ³ãåãå ¥ããŠãããæ€ç¥ããããšã¯å®¹æã§ã¯ãããŸããããã«ãŒããã€ã³ãã¯å¹³åããŠæ¯æããã 6 äžä»¶ã®çµŠäžæ¯èŸŒå 倿޿»æãæ€ç¥ããŠããŸãã
çµŠäžæ¯èŸŒå 倿Žã¯äºæ¥ãçµç¹ã«ãšã£ãŠäžçšåºŠã®ãªã¹ã¯ãšèŠãªãããŸããFBI ã€ã³ã¿ãŒãããç¯çœªèŠæ ã»ã³ã¿ãŒã® BEC ã«é¢ãã 2019 幎床çå ±åæžã«ããã°ã絊äžè©æ¬ºã®å¹³å被害é¡ã¯ã€ã³ã·ãã³ãåœãã 7904 ãã«ãšãªã£ãŠããŸãã
Microsoft ã«ããèŠéãããæ»æã®äžäŸã玹ä»ããŸãã
- ç°å¢: Microsoft 365
- è åšã«ããŽãªãŒ: ããžãã¹ã¡ãŒã«è©æ¬º
- æ»æã®ã¿ã€ã: çµŠäžæ¯èŸŒå 倿Ž
- æšç: çŠå©åçæ åœè
å³ 2çµŠäžæ¯èŸŒå 倿޿»æã®äŸ
çµŠäžæ¯èŸŒå 倿޿»æã®ä»çµã¿:
ãã®çµŠäžæ¯èŸŒå 倿޿»æã¯ãMicrosoft ãå ã åããŠããã¡ãŒã« ã»ãã¥ãªã㣠ã³ã³ãããŒã«ãããæããããã«ãªãããŸãç¯ãšè¢«å®³è ã®ããåããå¯èœãšãªã£ãŠããŸããããªãããŸãç¯ã¯ Gmail ã¢ã«ãŠã³ãã䜿çšããæ°ããéè¡å£åº§ã«æ¯èŸŒå å£åº§ã®å€æŽãæ±ããåŸæ¥å¡ãè£ ã£ãŠããŸãããåŸæ¥å¡ã®ãªãããŸãèªäœãåé¡ã§ãããããã圹å¡ã¯ã©ã¹ã®ãªãããŸãã«ãªã£ãå Žåãçµæžçæå€±ã¯é倧ãªãã®ãšãªãåŸãŸãã
圹å¡ã®ãªãããŸãæ»æã®æŠèŠ:
ãªãããŸãæ»æã®äžã§ãã圹å¡ã«ãªãããŸãããã®ãåŽåç°å¢ã®å€åã«äŒŽãåçã«å¢å ããŠããŸãã2020 幎 3 æä»¥éããã«ãŒããã€ã³ã㯠7000 人ãè¶ ãã CEO ã«ãªãããŸããã¡ãŒã«è©æ¬ºã確èªããŠããŸãããã«ãŒããã€ã³ãã®ã客æ§ã®åæ°ä»¥äžããå°ãªããšã 1 åã®åœ¹å¡ã®ãªãããŸããšããã®æ¬äººãè£ ãã¡ãŒã«ãè©æ¬ºè¡çºã«å©çšãããçµéšãæã£ãŠããŸãã
Microsoft ã«ããèŠéãããæ»æã®äžäŸã玹ä»ããŸãã
- ç°å¢: Microsoft 365
- è åšã«ããŽãªãŒ: ããžãã¹ã¡ãŒã«è©æ¬º
- æ»æã®ã¿ã€ã: ãªãããŸã
- æšç: æŠç¥ããã³äºæ¥éçºãã£ã¬ã¯ã¿ãŒ

å³ 3圹å¡ã®ãªãããŸãæ»æã®äŸ
圹å¡ã®ãªãããŸãæ»æã®ä»çµã¿:
ãã®ãªãããŸãæ»æã¯ãMicrosoft ãå ã åããŠããã¡ãŒã« ã»ãã¥ãªã㣠ã³ã³ãããŒã«ãããæããããšã«æåããŸãããæ»æè 㯠Gmail ã¢ã«ãŠã³ãã䜿çšã㊠CEO ã«ãªãããŸããåŸæ¥å¡ã«å¯Ÿå¿ãæ±ããå 容ã®ã¡ãŒã«ãéããŸãããåŸæ¥å¡ããã®ã¡ãŒã«ã«åå¿ãããšãæ»æè ã¯é£ãªãéšãç¶ããããŒã¿ãééçãªå©çãåŒãåºãããšãã§ããã®ã§ãã
Microsoft ã BEC æ»æãèŠéããŠããçç±
ãã®ãããªæ»æã¯é«åºŠãªéšãã®æå£ãçšããŠãããMicrosoft ããã®ã©ããèŠéããŠããŸã£ãã®ã«ã¯ããã€ãã®çç±ããããŸãã
- ãã®ãããªã¡ãŒã«ã¯ç°¡åãªéä¿¡è ã®ã¬ãã¥ããŒã·ã§ã³ ãã§ãã¯ãééããŸããGmail ã䜿çšããŠãããããSPF (Sender Policy Framework) ãš DKIM (DomainKeys Identified Mail) ã©ã¡ãã®èªèšŒã®ç¢ºèªãééããã®ã§ããæ£èŠã®ãµãŒãã¹ã䜿çšããããšã¯ãå€ãã®ã¬ãã¥ããŒã·ã§ã³ããŒã¹ã®ãã³ããŒãæ€ç¥ã«èŠåŽããäžè¬çãªæ¹æ³ã§ãã
- ãã®ãããªã¡ãã»ãŒãžã§ã¯åŸæ¥å¡ã®è¡šç€ºåãåœè£ ãããŸããMicrosoft ãååãæ€ç¥ããã®ã¯æåã§èå¥ããå Žåã ãã§ãããŸããæ»æè ã¯äžè¬çã«ããã¯ããŒã ã䜿çšããããŸãã¯åŸæ¥å¡ã®ååãå€åãããŠäœ¿çšããããšã§ãMicrosoft ã®ã¡ãã»ãŒãž ããããŒåæãããæããŸãã
- Microsoft ã¯ãã¡ãã»ãŒãžã§äœ¿ãããŠãã衚çŸã®èªèª¿ãæå³ãèªã¿è§£ãããã®ã¡ããã㌠(èšãæã) ã®æ€ç¥ãæäŸããŠããŸããããã®ãããªè åšã¯ã¡ãŒã«è©æ¬ºã§ããããšãæçœã«ç€ºã衚çŸã䜿ã£ãŠããŸãã
- ã¡ãŒã«ã«æªæã®ãããã€ããŒããå«ãŸããŠããªãããšãããMicrosoft ã®å èµãããµã³ãããã¯ã¹ã«ã¯ãã®çš®ã®è åšãæ€ç¥ããè¡ã¯ãããŸããã
ãã®ãããªæ»æãèŠéãããšã«ãããçµç¹ã¯æ»æã®ä¿®åŸ© (å€ãã®å Žåæåäœæ¥) ã«èšå€§ãªæéãšãªãœãŒã¹ãè²»ããããšãå¿ èŠã«ãªããŸããããã±ãŒã¹ã¹ã¿ãã£ã§ã¯ããã«ãŒããã€ã³ãã®åŒ·åãããã¡ãŒã«ã»ãã¥ãªãã£æ€ç¥æ©èœã䜿çšããçµç¹ã¯ã3 äººãæ£èŠéçšããã®ãšåçã®è²»çšãããã 34 äž 5000 ãã«ã 3 å¹Žä»¥äž ã«ããã£ãŠç¯çŽã§ããããšã瀺ãããŸããã
ãã«ãŒããã€ã³ãã®ããžãã¹ã¡ãŒã«è©æ¬ºå¯Ÿç

å³ 4ãã«ãŒããã€ã³ãã® BEC 察çã衚ããªã¬ãŒã·ã§ã³ã·ãã ã°ã©ã
ãã«ãŒããã€ã³ãã¯ãBEC ã黿¢ã§ãããšã³ãããŒãšã³ãã®çµ±ååãœãªã¥ãŒã·ã§ã³ãæäŸããå¯äžã®ãã³ããŒã§ãããã«ãŒããã€ã³ãã®æ©æ¢°åŠç¿ãšã³ãžã³ã§ãã Supernova ã¯ãéåä¿¡ã²ãŒããŠã§ã€ ãã¬ã¡ããªããµãã©ã€ãã§ãŒã³ ãªã¹ã¯åæããã㊠Office 365 ã Google Workspace ãã¯ãããšããã¯ã©ãŠãçç£æ§ãã©ãããã©ãŒã ããã® API ããŒã¿ã掻çšããAdvanced BEC Defense ãå®çŸããŠããŸãã
Supernova ã¯ãŸããæ©æ¢°åŠç¿ãã¹ããŒããã«åæãè¡ååæãã«ãŒã«ã»ããããããŠæ»æè ã®æŠè¡ã远跡ããç ç©¶ææãçµã¿åãããŠå©çšããããšã§ãé«ã广ãšäœã誀æ€ç¥çããåœç€Ÿã®ã©ã®æ€ç¥ãã©ãããã©ãŒã ã§ãã£ãŠãå®çŸããŸããSupernova ã®æ©æ¢°åŠç¿ã³ã³ããŒãã³ãã¯ãå€ãã® Fortune 100ãFortune 1000ãGlobal 2000 äŒæ¥ã§äœ¿çšããã¡ãŒã«è åšã«å¯Ÿããä¿è·ããåŸããèšå€§ãªããŒã¿ã»ããã䜿ã£ãŠèšç·ŽãããŠããŸãã
äžã®äŸã§ã¯ããã«ãŒããã€ã³ããããããã¡ãã»ãŒãžãæ€ç¥ããããšã§ãã¡ãã»ãŒãžããŠãŒã¶ãŒã®åä¿¡ãã¬ã€ã«å±ãã®ãé²ãããšãã§ããŠããç¹ã«æ³šç®ããããšãéèŠã§ãã
ããžãã¹ã¡ãŒã«è©æ¬ºæ»æ ã黿¢ããããã®ææ¡

å³ 5ãã«ãŒããã€ã³ãã BEC æ»æã黿¢ããããã«æ¡çšããŠããå€å±€ã¢ãããŒãã®æŠèŠ
ãã«ãŒããã€ã³ãã¯èªç€Ÿã® Proofpoint Threat Protection ãã©ãããã©ãŒã ã䜿çšã㊠BEC æ»æã黿¢ããå€å±€ã¢ãããŒãããšã£ãŠããŸãããããã®å±€ã«ã¯æ¥çããªãŒãããæ€ç¥ãåé¢ãèªèšŒãæè²ããã³èªå修埩æ©èœãå«ãŸããŸããå¢å ã®äžéããã©ããã£ãã·ã³ã°ã®è åšã«ç¹å¹è¬ã¯ãããŸããããã®ãããå€å±€åãçµ±åãããè åšä¿è·ãœãªã¥ãŒã·ã§ã³ãå¿ èŠãªã®ã§ãããã«ãŒããã€ã³ãã¯æ©æ¢°åŠç¿ãšé«åºŠãªãµã³ãããã¯ã¹æè¡ã䜿çšããŠãBEC æ»æã ãã§ãªãã©ã³ãµã ãŠã§ã¢ããã£ãã·ã³ã°ãã¢ã«ãŠã³ãä¹ã£åãã黿¢ããŸãã
Proofpoint Threat Protection ãã©ãããã©ãŒã ã䜿ããšãåè¿°ããè åšããã®ä»ã®è åšããã客æ§ããããã®ç°å¢ã§é»æ¢ããããšãã§ããŸãã詳现ã¯ãã¡ãã®ããŒãžã§ã芧ãã ããããŸããç¡æã®Eã¡ãŒã«è åšçºèŠã¢ã»ã¹ã¡ã³ãã®äºçŽããæ€èšãã ããããçšæããŠããŸãã
