ãã«ãŒããã€ã³ããšããžãµãŒãã®ã¡ãŒã«å¯Ÿçãœãªã¥ãŒã·ã§ã³ã暪æµéè¡ãå°å ¥
暪æµéè¡ãæ¶è²»è ä¿è·ã®èгç¹ããDMARCãšBIMIãžæºæ ããã£ãã·ã³ã°ã¡ãŒã«å¯Ÿçã宿œãProofpointã®ãœãªã¥ãŒã·ã§ã³ãå©çšããŠçæéã§DMARCã«å¯Ÿå¿
2024幎11æ5æ¥ïŒæ±äº¬ïŒ --ãµã€ããŒã»ãã¥ãªãã£ãšã³ã³ãã©ã€ã¢ã³ã¹åéã®ãªãŒãã£ã³ã°ã«ã³ãããŒã§ããæ¥æ¬ãã«ãŒããã€ã³ãæ ªåŒäŒç€ŸïŒæ¬ç€ŸïŒæ±äº¬éœå代ç°åºã代衚åç· åœ¹ç€Ÿé·ïŒèæšæ£ä¹ã以äžãã«ãŒããã€ã³ã)ãšããžãµãŒãã»ãžã£ãã³ååäŒç€ŸïŒæ¬ç€ŸïŒæ±äº¬éœäžå€®åºã代衚è
ïŒè·åå·è¡è
ãã€ã±ã«ã»ãŠãŒãžãŒã³ã»ãžã§ã³ãœã³ã以äžããžãµãŒãïŒã¯ã暪æµéè¡ã«ãããããã£ãã·ã³ã°ã¡ãŒã«å¯Ÿçãœãªã¥ãŒã·ã§ã³ãæäŸãããã®äºäŸãå
¬éããŸããããã«ãŒããã€ã³ããæäŸããProofpoint EFD (Email Fraud Defence) ã¯ãã¡ãŒã«éä¿¡çµç¹ãDMARCïŒDomain-based Message Authentication, Reporting and ConformanceïŒèŠæ Œã«å¯Ÿå¿ããããšãæ¯æŽããããã«ããæšªæµéè¡ã¯ãåœè£
ããããšãããã£ãã·ã³ã°ã¡ãŒã«ãéä¿¡ãããããšãé²ãããšãã§ããŸãããŸãããžãµãŒããæäŸããèªèšŒããŒã¯èšŒææžã«ããDMARCèŠæ Œã«å¯Ÿå¿ããæ£èŠã®ã¡ãŒã«ã«æšªæµéè¡ã®ããŽã衚瀺ããããšãã§ããæ¶è²»è
ã¯èŠèŠçã«éè¡ããã®ã¡ãŒã«ã§ããããšãèªèã§ããŸããDMARCãšBIMIïŒBrand Indicators for Message IdentificationïŒã®äž¡ã¡ãŒã«èŠæ Œãžã®å¯Ÿå¿ãåæã«æšé²ããå¢å ãç¶ãããã£ãã·ã³ã°ã¡ãŒã«ãæ¶è²»è
ã«å±ãããšãé²ãäºäŸãšããŠåæå
¬éãå®çŸããŸããã
æšä»ããã£ãã·ã³ã°è¢«å®³çã«äŒŽãã¯ã¬ãžããã«ãŒãäžæ£å©çšè¢«å®³ãã€ã³ã¿ãŒããããã³ãã³ã°ã«ä¿ãäžæ£ééè¢«å®³ãæ¥å¢ããŠããããã£ãã·ã³ã°å¯Ÿçåè°äŒãåé ãã2023幎1æãã12æãŸã§ã®ãã£ãã·ã³ã°å ±åä»¶æ°ã¯é廿é«ã®100äžä»¶ãè¶ ãã119äžä»¶ä»¥äžãšãªãã2022å¹Žãšæ¯èŒããŠçŽ1.23åãšãªããŸããããŸãã2023幎äžåæã®ã€ã³ã¿ãŒããããã³ãã³ã°ã«ä¿ãäžæ£éé被害ã¯ã幎éã®è¢«å®³ä»¶æ°ãšæ¯èŒããŠãé廿å€ã被害ç·é¡ãé廿å€ã«è¿«ãç¶æ³ã§ãããŸãããã«ãŒããã€ã³ãã®èª¿æ» (2024 State of the Phish)ã§ã¯ãæ¥æ¬ã«ããã調æ»å¯Ÿè±¡çµç¹ã®36%ã2023幎ã«å°ãªããšã1åã®ãã£ãã·ã³ã°æ»æã®è¢«å®³ã«ãã£ãŠããããã®ãã¡ã©ã³ãµã ãŠã§ã¢ã®ææãåŒãèµ·ããããçµç¹ã56%ã«ã®ãŒã£ãŠããŸããæšçãšãªããã©ã³ãã¯éèé¢é£ãäžäœãå ãããã£ãã·ã³ã°ã¡ãŒã«ããµã€ããŒæ»æã®èµ·ç¹ãšãªãã±ãŒã¹ãå€ããããçŽæ¥é¡§å®¢ã被害ã«å·»ã蟌ãŸããæããããéèæ©é¢ã«ãšã£ãŠãã®å¯Ÿçã¯å«ç·ã®èª²é¡ãšãªã£ãŠããŸãã
ããã§æ³šç®ã济ã³ãŠããã¡ãŒã«èªèšŒæè¡ã«DMARCãšBIMIããããŸããDMARCã¯ãEã¡ãŒã«ã®èªèšŒãããªã·ãŒãã¬ããŒãã£ã³ã°ã«é¢ãããããã³ã«ã§ããåºãæ®åããŠããSPFãDKIMãããã³ã«ãããŒã¹ã«ãäœæè ïŒãFrom:ã)ã®ãã¡ã€ã³åãšã®é¢é£ä»ããèªèšŒã«å€±æããå Žåã«åä¿¡è ãã¡ãŒã«ãåŠçããæ¹æ³ãå®ããå ¬éããªã·ãŒãéä¿¡è ãžã®ã¬ããŒãã£ã³ã°ã远å ããããšã§ããã¡ã€ã³ãäžæ£ãªã¡ãŒã«ããä¿è·ããã¢ãã¿ãªã³ã°ããŸãããã ããçµç¹å ã§èªèãããŠããªãã¡ãŒã«éä¿¡ã·ã¹ãã ãååšãããããSPFãDKIMã®èšå®ã«èŠåŽããããšãå°ãªããããŸããããŸãåä¿¡ãããšã©ãŒã¬ããŒããçè§£ããã®ã¯é£ãããããŒã«ãå©çšããã®ãäžè¬çã§ããä»å暪æµéè¡ã§ã¯ãã«ãŒããã€ã³ãã®ãœãªã¥ãŒã·ã§ã³ãå°å ¥ããããšã«ããDMARC察å¿ãå®äºããŸããã
BIMIã¯ãDMARCãèšå®ãããŠãããã¡ã€ã³ãä¿æããçµç¹ã«å¯Ÿããåæšç»é²æžã¿ããŽãšçµç¹ã®èªèšŒãè¡ãããšã§é»åèšŒææžãçºè¡ããã¡ãŒã«èªèšŒèŠæ Œã§ããããžãµãŒãã¯çµç¹ãå®åšããåæšç»é²æžã¿ããŽããã®çµç¹ãæããŠããããšãªã©ãèªèšŒããããšã«ãããGmailãiPhoneãªã©ã®åä¿¡è ã®ã¡ãŒã«ã«çµç¹ã®ããŽã衚瀺ããããšãã§ããŸããDMARCã§ã¯ãã¡ã€ã³ã®åœè£ ã«ã¯å¹æããããã®ã®åä¿¡è ã«ã¯æ£èŠã¡ãŒã«ã§ããã®ãäŒããã«ããäžé¢ããããŸããããŽã衚瀺ãããããšã§å®å¿ããŠã¡ãŒã«ãéãããšãã§ããããã«ãªããŸãã
DMARCã®å®è£ ããããŠãã®åŸBIMIã®å®è£ ãšæ°å¹ŽéããããŠå¯Ÿå¿ããçµç¹ãå€ãäžã暪æµéè¡ã§ã¯ããªãããŸãã¡ãŒã«å¯Ÿçã§ããDMARCããæ¶è²»è ä¿è·ã®èŠç¹ããèŠèŠçã«ãåºå¥ã§ããBIMIã®å®è£ ãŸã§ãã察çéå§ããçŽïŒå¹Žã§å®äºããŸãããããã¯éèæ©é¢ã®äžã§ãéåžžã«çŽ æ©ã察å¿ã§ãå°æ¹éè¡æå€§æãšããŠæ¥çãçœåŒããŸãã
暪æµéè¡ã® ICTæšé²éšã»ãã¥ãªãã£çµ±æ¬å®€ äºååµ ä¿è¡æ°ã¯ã次ã®ããã«è¿°ã¹ãŠããŸãããDMARC察å¿ã¯æ°ããªéèåºã®ã¬ã€ãã©ã€ã³ã§ãæç€ºãããŠããŸãããªãããŸãã¡ãŒã«å¯Ÿçãžã®åãçµã¿ä¿é²ã¯ã暪æµéè¡ã ãã®åé¡ã§ã¯ãªãéèæ¥çå šäœã®åé¡ãšãšãããŠããŸããä»åã®åãçµã¿ãéããŠåŸãããŠããŠããä»ã®éèæ©é¢ã«ãæäŸããæ¥çå šäœã®DMARC察å¿ãBIMI 察å¿ãçœåŒããŠãããããšèããŠããŸãã
æ¥æ¬ãã«ãŒããã€ã³ãæ ªåŒäŒç€Ÿããµã€ããŒã»ãã¥ãªã㣠ããŒã ãšãã³ãžã§ãªã¹ãã®å¢ç° 幞çŸã¯æ¬¡ã®ããã«è¿°ã¹ãŠããŸãããã¡ãŒã«ã®ãªãããŸãè©æ¬ºã®ææ³ã«ã¯ãâãã¡ã€ã³ã®ãªãããŸãâãâ衚瀺åè©æ¬ºâãâé¡äŒŒãã¡ã€ã³ã®äœ¿çšâã®ïŒã€ã®ã¿ã€ãããããŸãããã®ãã¡ãDMARCãâæåŠïŒReject)âã¢ãŒãã§éçšããããšã«ãããâãã¡ã€ã³ã®ãªãããŸãâãé²ãããšãã§ããŸãããŸãBIMIãŸã§å°å ¥ãããšæ®ãã®ïŒã€ã®ã¿ã€ãã«ã倧ããªå¹æãçºæ®ããŸããDMARCãšBIMIãå°å ¥ããã¡ãŒã«ã®ãªãããŸããé²ãããšã«ãããã¡ãŒã«ã¢ã«ãŠã³ãã®ä¹ã£åãã«ã广ãããããããšãã§ããŸããèªçµç¹ã ãã§ãªããµãã©ã€ãã§ãŒã³å šäœãã²ããŠã¯æ¥æ¬å šäœããµã€ããŒæ»æããå®ãããã«ãããã²DMARCãšBIMIã®å°å ¥ãé²ããŠããã ãããã§ãã
ããžãµãŒãã®ããžã¿ã«ã»ãã©ã¹ãã»ãµãŒãã¹æ åœã·ãã¢ã»ãã£ã¬ã¯ã¿ãŒã§ãããã£ãŒã³ã»ã³ã¯ãªã³ïŒDean CoclinïŒã¯ã次ã®ããã«è¿°ã¹ãŠããŸãããã¡ãŒã«åä¿¡è ã«ããŽãæç€ºããããšã¯ãæ¶è²»è ã«ãä¿¡é Œããäžããããã«éåžžã«éèŠã§ããéä¿¡è åã®æšªã«è¡šç€ºãããèªèšŒæžã¿ããŽãšïŒGmailã®ïŒéããã§ãã¯ããŒã¯ã®çµã¿åããã¯ãèŠèŠçã«ããã«äŒãããã®ã§ãããã®ããŽã衚瀺ããããã«ååŸããèªèšŒããŒã¯èšŒææžã¯ãçµç¹ã®å®åšãåæšç»é²ãç³è«è ã«å¯Ÿãå³ãã審æ»ã»èªèšŒããŠããçºè¡ãããŸãããã®å³ããèªèšŒã«ããã¡ãŒã«ã«ããŽã衚瀺ãããŠããããšãæ¬ç©ã®ã¡ãŒã«ã§ããããšãåä¿¡è ã«å¯Ÿãä¿èšŒãããã®ã§ãã
ãã«ãŒããã€ã³ãã®äºäŸã¯ãã¡ããã確èªã§ããŸãã
URL: https://www.proofpoint.com/jp/customer-stories/bank_of_yokohama
ããžãµãŒãã®äºäŸã¯ãã¡ããã確èªã§ããŸãã
URL: https://www.digicert.com/content/dam/digicert/pdfs/case-study/bank-of-yokohama-vmc-case-study-jp.pdf
â»æ¬æäžã«èšèŒã®ç€Ÿååã³è£œååã¯ãå瀟ã®åæšãŸãã¯ç»é²åæšã§ãã
â»ãã¥ãŒã¹ãªãªãŒã¹ã«æ²èŒãããŠããæ
å ±ïŒè£œåäŸ¡æ Œã仿§çãå«ãïŒã¯ãçºè¡šæ¥çŸåšã®æ
å ±ã§ãããã®åŸäºåãªãã«å€æŽãããããšããããŸãã®ã§ãããããããæ¿ç¥ãã ããã
Proofpoint | ãã«ãŒããã€ã³ãã«ã€ããŠ
Proofpoint, Inc.ã¯ããµã€ããŒã»ãã¥ãªãã£ã®ã°ããŒãã« ãªãŒãã£ã³ã° ã«ã³ãããŒã§ããçµç¹ã®æå€§ã®è³ç£ã§ããããåæã«æå€§ã®ãªã¹ã¯ãšããªãããã人ããå®ãããšã«çŠç¹ãããŠãŠããŸããProofpointã¯ãã¯ã©ãŠãããŒã¹ã®çµ±åãœãªã¥ãŒã·ã§ã³ã«ãã£ãŠãäžçäžã®äŒæ¥ãæšçåæ»æãªã©ã®ãµã€ããŒæ»æããããŒã¿ãå®ãããããŠããããã®ãŠãŒã¶ãŒããµã€ããŒæ»æã«å¯ŸããŠããã«åŒ·åãªå¯ŸåŠèœåãæãŠãããæ¯æŽããŠããŸãããŸããFortune 100äŒæ¥ã®85%ãå«ãããŸããŸãªèŠæš¡ã®å€§æäŒæ¥ããã¡ãŒã«ãã¯ã©ãŠãããœãŒã·ã£ã«ã¡ãã£ã¢ãWebã«ãããæãéèŠãªãªã¹ã¯ã軜æžãã人ãäžå¿ãšããã»ãã¥ãªãã£ããã³ã³ã³ãã©ã€ã¢ã³ã¹ã®ãœãªã¥ãŒã·ã§ã³ãšããŠããã«ãŒããã€ã³ãã«ä¿¡é Œãå¯ããŠããŸãã
詳现㯠www.proofpoint.com/jpã«ãŠã確èªãã ããã
DigiCertãšã¯
ç±³ããžãµãŒãã»ã€ã³ã¯ïŒæ¬ç€ŸïŒãŠã¿å·ãªãŒãã€ãéå
¬éäŒæ¥ïŒã¯ãã€ã³ã¿ãŒãããäžã§äººãšäŒæ¥ãé»åçãªä¿¡é Œã§ã€ãªããããšãã§ããããã«ãããããžã¿ã«ãã©ã¹ãã®äžççãªãªãŒãã£ã³ã°ã»ãããã€ããŒã§ãããã®ããžã¿ã«ãã©ã¹ãã匷åºã«ãããã©ãããã©ãŒã ã DigiCert® ONE ã§ãããããªãã¯ãã©ã¹ããšãã©ã€ããŒããã©ã¹ãã®å¹
åºãããŒãºãããã£ãŠäžå
çãªå¯èŠåãšå¶åŸ¡ãå®çŸãããŠã§ããµã€ããäŒæ¥ã®ã¢ã¯ã»ã¹ãšéä¿¡ããœãããŠã§ã¢ãIDãã³ã³ãã³ããããã€ã¹ãä¿è·ããŸããããžãµãŒãã¯ãåè³æŽã®ãããœãããŠã§ã¢ãšãæšæºããµããŒããéçšã«é¢ããæ¥çã®ãªãŒããŒã·ãããšãçµã³ä»ããŠãããå
šäžçã®äž»èŠäŒæ¥ã«éžã°ããããžã¿ã«ãã©ã¹ããããã€ããŒã§ãã
ããžãµãŒãã»ãžã£ãã³ååäŒç€Ÿã¯ç±³ããžãµãŒãã»ã€ã³ã¯ã®100%åäŒç€Ÿã§ãã