Microsoftãããæããæ»æãçµç¹ã«æ¯å¹Žèšå€§ãªé¡ã«äžãæå€±ãäžããæ å ±ã»ãã¥ãªãã£ããŒã ãšãŠãŒã¶ãŒã«ãã©ã¹ãã¬ãŒã·ã§ã³ããããããŠããŸãã
ãã®ã·ãªãŒãºã§ã¯ãMicrosoft ã®ã»ãã¥ãªãã£ãããæããŠããæ»æã®è©³çްãæããã«ãããªãMicrosoft ã®ã¡ãŒã« ã»ãã¥ãªãã£ã®é²åŸ¡ãããæããŠããŸãçç±ã説æããŸãããããã®è åšã«ã¯ä»¥äžã®ãããªãã®ããããŸãã
- ããžãã¹ã¡ãŒã«è©æ¬º (BEC)
- ã©ã³ãµã ãŠã§ã¢
- ãµãã©ã€ã€ãŒè©æ¬º
- ã¢ã«ãŠã³ã䟵害
- æŠåšåããããã¡ã€ã«å ±æ
ãã«ãŒããã€ã³ãã¡ãŒã«è åšã¢ã»ã¹ã¡ã³ãã§ã¯ãMicrosoftã®ã»ãã¥ãªãã£ãããæããŠããè åšãå¯èŠåã§ããŸãããã²ããªãã®çµç¹ã®ãªã¹ã¯ææ¡ã«ã圹ç«ãŠãã ããã
ãµãã©ã€ã€ãŒæ»æã®æŠèŠ
ãµãã©ã€ã€ãŒè©æ¬ºã¯ããéãçãããã®é«åºŠã§è€éãªã¹ããŒã ã§ãããã®äžã«ã¯ãèªèšŒæ å ±ã®çªåããã«ãŠã§ã¢ãå«ãŸããŸãããæãå€ãã®ã¯ ããžãã¹ã¡ãŒã«è©æ¬º(BEC) è åšã§ããFBI ã® Internet Crime Complaint Center ããçºè¡šããã 2020 幎ã®ã€ã³ã¿ãŒãããç¯çœªã¬ããŒãã«ãããšãå»å¹Žã® BEC ã¹ããŒã ã«ããå»å¹Žã®è¢«å®³é¡ã¯ 19 åãã«ã«ã®ãŒãããµã€ããŒè åšã®äžã§æå€§ã®è¢«å®³é¡ãšãªã£ãŠããŸãã
BEC æ»æã®äžè¬çãªæ¹æ³ã¯ãåœã®è«æ±æžãæ£åœãªãã®ãšããŠæç€ºããããæ»æè ã管çããéè¡å£åº§ã«æ¯æããè¿åããããããããšã§ãã
ãã«ãŒããã€ã³ãã®èª¿æ»ã«ãããšã3,000 瀟ã®èª¿æ»å¯Ÿè±¡çµç¹ã®ãã¡ 98% ã 7 æ¥é以å ã«ãµãã©ã€ã€ãŒãã¡ã€ã³ããã®è åšãåããŠããŸããããããã®æ»æã®çŽ 4 åã® 3 (74%) ã¯ãã£ãã·ã³ã°ããªãããŸãã§ããããµãã©ã€ã€ãŒãã¡ã€ã³ããéä¿¡ãããè åšã® 30% 匱ã¯ãã«ãŠã§ã¢é¢é£ã®ãã®ã§ããããã®ããšã¯ãæ»æè ã BEC åã®ãœãŒã·ã£ã« ãšã³ãžãã¢ãªã³ã°ãå€çšããŠæåãåããŠããããšãæµ®ã圫ãã«ããŠããŸãã

å³ 1.ãµãã©ã€ã€ãŒè©æ¬ºã®çµ±èš
æ¯æç¢ºèªããã BEC æ»æã¯æ°çŸäžä»¶ã«åã¶
ãã«ãŒããã€ã³ãã¯å¹³åããŠæ¯ææ°çŸäžä»¶ã® BEC æ»æãæ€ç¥ããŠããŸãããããã®æ»æã®ãã¹ãŠããµãã©ã€ã€ãŒãžã®äžæ£ã¢ã¯ã»ã¹ã«é¢é£ããŠããããã§ã¯ãããŸãããããããB2B (äŒæ¥éååŒ) ã®åéã§ã¯ããµãã©ã€ã€ãŒãååããµãŒãã¹ã®å¯ŸäŸ¡ãšããŠå€é¡ã®æ¯æããæ¥åžžçã«åããŠããããããµãã©ã€ã€ãŒè©æ¬ºã®ãã£ã³ããŒã³ã«ã¯å€§ããªå¹æããããšèšããŸãã
ãã 1 ãæã§ã¯ãè åšã¢ã»ã¹ã¡ã³ãã®éå®çãªããŒã¿ã»ããã ãã§ããMicrosoft ã®é²è¡ç·ãããæãã BEC è åšã 4,800 件以äžãæ·»ä»ãã¡ã€ã«ã®è åšã 84,000 ä»¶ãURL ã®è åšã 168,000 ä»¶æ€ç¥ããŸãããããšãã°ã次ã®ãããªããšãæ€åºãããŸããã
- 20,000 人以äžã®åŸæ¥å¡ãæ±ããåœéçãªéè¡ã§ã¯ã1,800 件以äžã® BEC è åšãåããŸããã
- çŽ 9,000 人ã®åŸæ¥å¡ãæ±ããæ¶è²»è 補åäŒæ¥ã§ã¯ã8,000 件以äžã®URL ã®è åšãæ·»ä»ãã¡ã€ã«ã®è åšãé ä¿¡ãããŸããã
- çŽ 2,000 人ã®åŸæ¥å¡ãæ±ãããšãŒãããã®ã¡ãã£ã¢ã°ã«ãŒãã§ã¯ãMicrosoft ã®ã»ãã¥ãªãã£ãããæãã 650 件以äžã® BEC è åšãåããŸããã
ãŸããMicrosoft ã§ã¯ãOneDrive ãªã©ã®èªç€ŸãµãŒãã¹ããã©ã³ãµã ãŠã§ã¢ãšé£æºãããã«ãŠã§ã¢ããã¹ãããŠããäºäŸã倿°å ¬éãããŠããŸã (äžå³ãåç §)ã

å³ 2.Microsoft ã OneDrive ãªã©ã®ãµãŒãã¹äžã§ã©ã³ãµã ãŠã§ã¢ãšé£æºãããã«ãŠã§ã¢ããã¹ãã£ã³ã°ããŠããããšã瀺ããã€ãŒã
以äžã«ç€ºãã®ã¯ãæè¿ã®ãã«ãŒããã€ã³ãã®è åšã¢ã»ã¹ã¡ã³ãã§æããã«ãªã£ããMicrosoft ãããæãããµãã©ã€ã€ãŒæ»æã®ã¿ã€ãã«é¢ãã詳现ã§ãã
Microsoft ãããæãããµãã©ã€ã€ãŒæ»æ: äŸ 1
ãµãã©ã€ã€ãŒè«æ±æ»æã¯ãéåžžã«äžè¬ç㪠B2B åã®è åšã§ããã®ããã«ãŒãè©æ¬ºã®ãããªæ¶è²»è ã察象ãšããã¹ããŒã ããCOVID-19 ã®ãããªããšãã®ã¹ããŒã ã BEC è åšã®ããªãã®æ°ãå ããŠããŸããã ãµãã©ã€ã€ãŒè©æ¬ºã«ã¯æšçåãŸãã¯æ¥åèŠçãªæ§è³ªãããããããããã®å°éã®æ»æã«ãã被害ã¯çžåœãªé¡ã«ãªãå¯èœæ§ããããŸãã
ãµãã©ã€ã€ãŒã«ãªãããŸããè«æ±è©æ¬ºæ»æã®æŠèŠ:
- ç°å¢: Microsoft 365
- è åšã«ããŽãªãŒ: BEC
- æ»æã®ã¿ã€ã: ãµãã©ã€ã€ãŒã«ãªãããŸããè«æ±è©æ¬º
- æšç: æ¯æãã®ååž

å³ 3.Microsoft ã«ããèŠéããããµãã©ã€ã€ãŒè©æ¬ºã®äŸ
æ»æã®æ¹æ³:
ãã®ãµãã©ã€ã€ãŒã«ãªãããŸããè«æ±è©æ¬ºæ»æã¯ãMicrosoft ãå ã åããŠããã¡ãŒã« ã»ãã¥ãªã㣠ã³ã³ãããŒã«ãããæããããšã«æåããŸãããè©æ¬ºåž«ã¯ãããŒãããŒäŒæ¥ã«å ¥ç€Ÿããå åŸæ¥å¡ã«ãªãããŸããGmail ã¢ã«ãŠã³ãã䜿ã£ãŠã¢ã«ãŠã³ãæ å ±ãèŠæ±ããéèè©æ¬ºã詊ã¿ãŸããã
Gmail ããã®ä»ã®ããªãŒã¡ãŒã«ãµãŒãã¹ããéä¿¡ãããã¡ãã»ãŒãžã䌎ãååã®ãªãããŸãã®äœ¿çšã¯ãSPF (Sender Policy Framework) ã DKIM (DomainKeys Identified Mail) ãªã©ã®ã¡ãŒã«èªèšŒãã§ãã¯ãåé¿ããããã«æ»æè ã䜿çšããäžè¬çãªæå£ã§ãããŸãããµãã©ã€ã€ãŒæ»æã§ã¯ãäžæ£ãª URL ãæ·»ä»ãã¡ã€ã«ã䜿ã£ãŠã䟵害ãããã¢ã«ãŠã³ãããè²¡åæ å ±ãä»ã®éèŠãªããŒã¿ã«ã¢ã¯ã»ã¹ããããšããããŸãã
Microsoft ãèŠéãããµãã©ã€ã€ãŒæ»æ: äŸ 2
ãµãã©ã€ã€ãŒã®ãªãããŸãæ»æã¯å±éºã§ããã䟵害ãããã¢ã«ãŠã³ãã¯ããããã¯ããã«ç倧ãªè¢«å®³ããããããŸãããŠãŒã¶ãŒã¯ããããè åšã«å¯ŸããŠæ²¹æããŠããŸãå¯èœæ§ããããŸãããªããªãããããã®ã¡ãã»ãŒãžã¯ããã調ã¹ãŠããæ£èŠã®ãã¡ã€ã³ããéä¿¡ãããŠãããããæ£åœãªãã®ã«èŠããããã§ãã
ãµãã©ã€ã€ãŒã®äŸµå®³ãããã¢ã«ãŠã³ãèªèšŒæ å ±æ»æã®æŠèŠ:
- ç°å¢: Microsoft 365
- è åšã«ããŽãªãŒ: èªèšŒæ å ±ã®çªå
- æ»æã®ã¿ã€ã: ãã£ãã·ã³ã°ãšãµãã©ã€ã€ãŒãžã®äžæ£ã¢ã¯ã»ã¹
- æšç: ã«ã¹ã¿ã㌠ãããžã§ã¯ã ãããŒãžã£ãŒ

å³ 4: äžèšã®èªèšŒæ å ±ããŒãžã¯ãMicrosoft 365 ã®ãã°ã€ã³ãè£ ã£ããã®ã§ãããMicrosoft ã¯ãã®æ»æããŠãŒã¶ãŒã«å°éããã®ãæ€ç¥ããŠé»æ¢ããããšãã§ããŸããã§ããã
æ»æã®æ¹æ³:
ãã®èªèšŒæ å ±åéæ»æã¯ã顧客ã宿çã«é£çµ¡ãåãåã£ãŠãã建èšäŒç€Ÿã®æ£èŠã®ã¢ã«ãŠã³ãããéä¿¡ãããŠããããã«èŠããŸãããå®éã«ã¯ããã¯äŸµå®³ãããã¢ã«ãŠã³ãã§ããå³ 3 ã®ç»åã瀺ãããã«ããã®ããŒãžã§ã¯Microsoft ãã©ã³ãã®ãªãããŸãã䜿çšãããæ»æè 㯠Microsoft 365 ã®èªèšŒæ å ±ãåéããããšããŠããŸãã
Microsoft ããã®æ»æã黿¢ã§ããªãã£ãçç±:
- Microsoft ã®ã¬ãã¥ããŒã·ã§ã³ ã¹ãã£ã³ã¯ãURL ãæ€ç¥ããŸããã§ããããã®æ©èœã¯ããã® URL ãå«ããMicrosoft ã®ãã©ã³ããè£ ã£ãæ°ããäžæ£ãª URL ã®æ€ç¥ã«å¯Ÿå¿ã§ããªãããšããããããŸãã
- ãã®ã¡ãã»ãŒãžã¯æ£èŠã®ãã¡ã€ã³ããéä¿¡ãããŠãããããéçãªã¬ãã¥ããŒã·ã§ã³åæã§ã¯éä¿¡è ãäžæ£ã§ãããšã¯å€æãããŸããã
- ãšã³ãããŒãã¯ãæãããªãªãããŸãã®ãŠãŒã¹ã±ãŒã¹ãããªã¬ãŒãããã®ã§ã¯ãããŸããã§ããã
Microsoft ãããæãããµãã©ã€ã€ãŒæ»æ: äŸ 3
Microsoft ã®ã»ãã¥ãªãã£ãããæãããæè¿ã®ãµãã©ã€ã€ãŒè©æ¬ºæ»æã®äŸã¯ã䟵害ããããµãã©ã€ã€ãŒã¢ã«ãŠã³ãããã®æ·»ä»ãã¡ã€ã«åœ¢åŒã®è åšã§ãã
ãµãã©ã€ã€ãŒã®äŸµå®³ãããã¢ã«ãŠã³ãèªèšŒæ å ±æ»æã®æŠèŠ:
- ç°å¢: Microsoft 365
- è åšã«ããŽãªãŒ: æ å ±åé
- æ»æã®ã¿ã€ã: æªæã®ããæ·»ä»ãã¡ã€ã«
- æšç: ã¡ãŒã«ã§ã¯ BCC ã§é衚瀺ã«ãªã£ãŠãã
å³ 5.Microsoft ãããæããLoki Bot æ»æã®äŸ
æ»æã®æ¹æ³:
äŸµå ¥ããã¯ã©ã€ã¢ã³ãããéä¿¡ããããã®æ»æã§ã¯ãã¡ãã»ãŒãžã« Word ææžãå«ãŸããŠãããæ°åŒãšãã£ã¿ã®ããŸããŸãªè匱æ§ãæªçšã㊠Loki Bot ãããŠã³ããŒãããŠããŸããããã®ãããã¯ããã©ãŠã¶ãFTP/SSH ã¢ããªã±ãŒã·ã§ã³ãã¡ãŒã«ã¢ã«ãŠã³ããããã¹ã¯ãŒããçãããšãã§ããŸãã
Microsoft ã¯ä»¥äžã®ãããªããŸããŸãªçç±ã§ãã®æ»æãèŠéããŠããŸããã
- ã¡ãã»ãŒãžã¯æ£èŠã®ãã¡ã€ã³ããçºä¿¡ãããŠãããããéçãªã¬ãã¥ããŒã·ã§ã³åæã§ã¯ã¡ãã»ãŒãžãäžæ£ã§ãããšå€æãããŸããã§ããã
- ã¡ãã»ãŒãžã¯ SPF èªèšŒãééããŠããŸããã
- ãã®äžæ£ãªãã€ããŒãã¯ããµã³ãããã¯ã¹åé¿ãšãã¡ã€ã«é£èªåã®ãã¯ããã¯ã䜿çšããŠããŸããã
ãã«ãŒããã€ã³ãã®é«åºŠãªã¡ãŒã«ã»ãã¥ãªãã£ã§ããã°ããã®è åšãæ€ç¥ããã¢ã¯ãã£ããã£ã黿¢ããŠããã¯ãã§ããå®éã«ããã«ãŒããã€ã³ãã¯ãMicrosoft ãèŠéããäžèšã®ãã¹ãŠã®ãµãã©ã€ã€ãŒè©æ¬ºæ»æã®äºäŸã§ã¡ãã»ãŒãžãæ€ç¥ãã黿¢ããŠããã§ãããã
ãã«ãŒããã€ã³ãã®ãµãã©ã€ã€ãŒæ»æå¯Ÿç
ãã«ãŒããã€ã³ãã¯ããµãã©ã€ã€ãŒæ»æã黿¢ãããšã³ãããŒãšã³ãã®çµ±åãœãªã¥ãŒã·ã§ã³ãæäŸããå¯äžã®ãã³ããŒã§ããåŒç€Ÿã§ã¯ãæè¿çºè¡šãã BEC æ€ç¥ãã©ãããã©ãŒã ãSupernova ãã¯ãããšãããã«ãã¬ã€ã€ãŒã®æ€ç¥æè¡ãæ§ç¯ããŠãããé²åãç¶ããè åšã«å¯ŸæããŸãããã®ãã©ãããã©ãŒã ã¯ãã€ã³ããŠã³ãããã³ã¢ãŠãããŠã³ãã®ã²ãŒããŠã§ã€ ãã¬ã¡ããªããµãã©ã€ãã§ãŒã³ ãªã¹ã¯åæããããŠã¯ã©ãŠãçç£æ§ãã©ãããã©ãŒã ããã® API ããŒã¿ã掻çšããéåžžã«é«åºŠãªã¡ãŒã«è©æ¬ºã®æ»æãçºèŠããŸãã
Proofpoint Email Fraud Defense ãœãªã¥ãŒã·ã§ã³ã®Nexus Supplier Risk Explorer æ©èœã¯ãäžæ£ãªãã€ããŒããå«ãæ»æãªã©ããµãã©ã€ã€ãŒ è©æ¬ºã®ãªã¹ã¯ãããããã¢ã¯ãã£ãã«æ€ç¥ããã³é²æ¢ããã®ã«åœ¹ç«ã¡ãŸããäžçäžããéããããæ¯é¡ã®ãªãããŒã¿ã»ãããšãä»ã®ã©ã®ã»ãã¥ãªãã£ãããã€ããããå€ãã® Fortune 100ãFortune 1000ãããã³ Global 2000 äŒæ¥ã§æå€§ã®æ»æçµè·¯ãé²è·ããå±éãéããŠãSupplier Risk Explorer ã® URL ãšæ·»ä»ãã¡ã€ã«ä¿è·ã®æ©æ¢°åŠç¿ã³ã³ããŒãã³ãã¯èšç·ŽãããŠããŸãã

å³ 6: ãã«ãŒããã€ã³ãã® Supplier Risk Explorer ã«ãããçµç¹ã«ãªã¹ã¯ããããããµãã©ã€ã€ãŒã®ãã¡ã€ã³ãç¹å®ããå¯èŠåããŸãã
ãµãã©ã€ã€ãŒæ»æã黿¢ããããã®æšå¥šäºé
ãã«ãŒããã€ã³ã㯠Proofpoint Threat Protection ãã©ãããã©ãŒã ã䜿çšããŠãµãã©ã€ã€ãŒæ»æã黿¢ããå€å±€ã¢ãããŒãããšã£ãŠããŸãããããã®å±€ã«ã¯æ¥çããªãŒãããæ€ç¥, åé¢, èªèšŒ, æè² ããã³èªåå¯ŸåŠ æ©èœãå«ãŸããŸãããŸããæ©æ¢°åŠç¿ãšé«åºŠãªãµã³ãããã¯ã¹æè¡ã䜿çšããŠãBECãã©ã³ãµã ãŠã§ã¢ã ãã£ãã·ã³ã°, ã¢ã«ãŠã³ãä¹ã£åããªã©ã黿¢ããŸãã
ãã«ãŒããã€ã³ãã®Proofpoint Threat Protection ãã©ãããã©ãŒã ããã客æ§ã®ç°å¢ãæšçãšãããµãã©ã€ã€ãŒæ»æããã®ä»ã®è åšãã©ã®ããã«é»æ¢ãããã«ã€ããŠè©³çްã調ã¹ãã«ã¯ããã²ç¡æã®è åšã¢ã»ã¹ã¡ã³ãããå©çšãã ããã
