ãã«ãŒããã€ã³ãããHuman Factor 2023ãæ¥æ¬èªçãçºè¡šïŒ æ»æè ã¯ãããŒã«ããã¯ããã¯ããã¯ãŒã¢ããããŠããããšãæããã«
çŸä»£ã®ãµã€ããŒæ»æãã§ãŒã³ãšæå€§ã®è åšã«å¯Ÿããææ°ã®è©³çްåæçµæ
ãµã€ããŒã»ãã¥ãªãã£ãšã³ã³ãã©ã€ã¢ã³ã¹ã®ãªãŒãã£ã³ã°ã«ã³ãããŒã§ããæ¥æ¬ãã«ãŒããã€ã³ãæ ªåŒäŒç€ŸïŒæ¬ç€ŸïŒæ±äº¬éœå代ç°åºã代衚åç· åœ¹ç€Ÿé·ïŒèæšæ£ä¹ã以äžãã«ãŒããã€ã³ãã¯ã幎次ã¬ããŒããHuman Factor 2023ïŒãµã€ããŒæ»æãã§ãŒã³ã§çããã人çèŠå åæïŒãã®æ¥æ¬èªçãçºè¡šããŸããããã®ã¬ããŒãã¯ãã³ããçŠãåŒãèµ·ãããæ··ä¹±ã®2幎ãçµãŠã2022幎ã«ã¯äžçã®ãµã€ããŒç¯çœªè ãã³ãã以åã®è¡åã«æ»ã£ãããšãæããã«ããŠããŸããæ°åã³ãããŠã€ã«ã¹ææç察çã«æ²¿ã£ãå»çäœå¶ãçµæžæ¿çãç·©åããå§ãããšãæ»æè ã¯ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã¹ãã«ã«ç£šãããããããŒã«ããã¯ãŒã¢ããããæ³å®å€ã®æ»æãäºæ³å€ã®å Žæã§æ¬¡ã ãšç¹°ãåºããŸããã
ã¯ã©ãŠãããã³ãã«å¯Ÿããç·åœããæ»æãæšçåæ»æã®èп𡿡倧ãããäŒè©±åã¹ããã·ã³ã°æ»æã®æ¥å¢ãå€èŠçŽ èªèšŒïŒMFAïŒãã€ãã¹æ»æã®æ¡æ£ãŸã§ããµã€ããŒæ»æã®ç¶æ³ã¯2022幎ã«ããã€ãã®é¢ã§å€§ããªçºå±ããããŸããã2022幎ã¯ãæ»æãã§ãŒã³ã倿§åããé ä¿¡ã¡ã«ããºã ãè¿ éã«ãã¹ãããŠç Žæ£ãããªã©ãæ»æè ããã€ãŠãªãã»ã©ã®åµé æ§ãçºæ®ãã1幎ã§ããã
äž»ãªèª¿æ»çµæ
- Officeãã¯ãã䜿çšããæ»æã¯ãMicrosoftã®ãããã¯çã«ãã£ãŠè¡°éïŒ çŽ30幎ã«ããããã«ãŠã§ã¢ã®é åžææ®µãšããŠå©çšãããŠããOfficeãã¯ãã¯ããã€ã¯ããœãããWebããããŠã³ããŒããããã¡ã€ã«ã®åãæ±ã仿§ã倿ŽããåŸãããããå©çšãæžå°ãå§ããŸããããã®æŽæ°ããã£ããã«ãæ»æè ã¯ãæšçãæ»æããããã®å¥ã®ææ³ã暡玢ããããã«ãªããçŸåšãæ§ã ãªå®éšãç¶ããããŠããŸãã
- æ»æè ã¯ã嵿工倫ã«å ããæ£ç¢ºããšå¿èåãäŒŽãæ»æãžïŒ æšå¹Žã¯ãæ»æè ãäžèŠç¡å®³ãªã¡ãã»ãŒãžãéä¿¡ããããšããå§ãŸããäŒè©±åã¹ããã·ã³ã°ãããPig ButcheringïŒè±ã®ããã¿åãè©æ¬ºãããã³ã¹è©æ¬ºãšãåŒã°ããïŒãè åšãæ¥å¢ããŸãããã¢ãã€ã«çã§ã¯ããã®è åšã¯æšå¹Žæãæ¥æé·ãããã®éã¯12åã«ãå¢å ããŸããããŸããé»è©±ãçšãããµããŒãè©æ¬ºïŒTOADïŒTelephone-Oriented Attack DeliveryïŒã¯ãããŒã¯æã«ã¯æé1,300äžã¡ãã»ãŒãžã«éããŠããŸããããã€ãã®åœå®¶ãæ¯æŽããAPTã®æ»æè ã®å€ãã¯ãæ°é±éãæã«ã¯æ°ãæã«ãããã£ãŠæšçãšåœããéãã®ãªãã¡ãã»ãŒãžãéãåããããªãã®æéããããŠãä¿¡é Œé¢ä¿ãç¯ããŠããŸãã
- åžè²©ã®MFAãã€ãã¹ãã£ãã·ã³ã°ããããã¢ã³ããŒã°ã©ãŠã³ãã§å
¬éãããããšã«ãããæè¡åã®ãªãç¯çœªè
ã§ããã£ãã·ã³ã°ãã£ã³ããŒã³ãå±éããããšãå¯èœã«ïŒ EvilProxyãEvilginx2ãNakedPagesãªã©ã®MFAãã€ãã¹æ§é ã¯ã1ã¶æããã100äžä»¶ä»¥äžã®ãã£ãã·ã³ã°ã¡ãã»ãŒãžãèšé²ããŠããŸãã

- å€ãã®ã¯ã©ãŠãããŒã¹ã®æ»æã§ã¯ãæ£åœãªã€ã³ãã©ãéèŠãªåœ¹å²ãæãããã«ãŒã«ãåºç€ãšããä¿è·ã®éçã瀺ããŠããïŒ å€ãã®çµç¹ã¯ãã¯ã©ãŠã倧æã®MicrosoftãšAmazonãèµ·ç¹ãšããè åšã«çŽé¢ããŠããããããã®ã€ã³ãã©ã¯ãçµç¹ãä¿¡é Œããç¡æ°ã®æ£èŠãµãŒãã¹ããã¹ããšããŠããŸãã
- æ°ããªé åžæ¹æ³ã«ããSocGholishã¯ã¡ãã»ãŒãžä»¶æ°ã®å€ããã«ãŠã§ã¢ã®ããã5ã«ïŒ SocGholishïŒTA569ïŒã¯ãèªåããŠã³ããŒããšåœã®ãã©ãŠã¶ ã¢ããããŒãèŠåãå«ãæ°ããé åžæ¹æ³ã«ãã£ãŠããŠã§ããµã€ããææãããèªåããŠã³ããŒãã®ã¿ã§ãã«ãŠã§ã¢ãé åžããåœã®ãã©ãŠã¶ ã¢ããããŒãèŠåã«ãã£ãŠè¢«å®³è ãéšããŠããŠã³ããŒããããããšãã§ããããã«ãªã£ãŠããŠããŸããSocGholishã®ãã«ãŠã§ã¢ã眮ããŠãããµã€ãã®å€ãã¯ããã®ãµã€ãèªäœããã«ãŠã§ã¢ã眮ãããŠããããšã«æ°ã¥ããŠãããããã«ãŠã§ã¢ã®é ä¿¡ãããã«æ¡æ£ãããŠããŸãã
- ã¯ã©ãŠãã®è åšã¯éåšçãªååšã«: ã¯ã©ãŠãããã³ãã®94ïŒ ãæ¯æãçãæã¡ã®æ»æãŸãã¯ç·åœããæ»æã®ããããã«çãããŠãããããã¯ã¡ãŒã«ãã¢ãã€ã«ã§ãåçšåºŠã®æ»æãè¡ãããŠããããšã瀺åãããŠããŸãã2023 幎ã«å ¥ã£ãŠãããŒã¿ã®ç·åœããæ»æãç¹ã«ãã¹ã¯ãŒãã¹ãã¬ãŒæ»æã®æ°ã¯ãæå¹³å 4000äžä»¶ãã 2 åè¿ããŸã§å¢å ããŠããŸãã
- æåãªãã©ã³ããéšãããã®ãªãã¿ããããšä¿¡é Œæãæªçšããããšã¯ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®æãã·ã³ãã«ãªææ³ã®1ã€ïŒãã«ãŒããã€ã³ãã®èª¿æ»ããŒã ã確èªããæ»æãã£ã³ããŒã³ã®ãã¡ãæãäžæ£äœ¿çšãããŠããã®ã¯ Amazon ã§ãããäžäœ 5 ãã©ã³ãã®ãã¡æ®ãã® 4 ãã©ã³ã㯠Microsoft ã®ãã®ã§ãã
- æåã®ã¢ã¯ã»ã¹ã«æåãããšãã©ã³ãµã ãŠã§ã¢ã®ææãæ å ±çªåãªã©ã®ããã¡ã€ã³å šäœã«åœ±é¿ãããã¶æ»æãžãšæ¥éã«ã€ãªããå¯èœæ§ãããïŒ å€ãã®çµç¹ã§ãèšå®ã誀ã£ããã€ãŸãã圱ãã®ç®¡çè ã®ååšããèªèšŒæ å ±ãçªåããããªã¹ã¯ãããã«é«ããŠããŸãããããã®ã·ã£ããŒã¢ããã³ ã¢ã«ãŠã³ãã® 40% ã®èªèšŒæ å ±ã¯ããã¡ã€ã³ã®ãã¹ã¯ãŒããåèšå®ããŠãã£ãã«æš©éãææ Œããããªã©ãæªçšãããå¯èœæ§ããããŸãããŸããã·ã£ããŒã¢ããã³ã® 13% ã¯ããã§ã«ãã¡ã€ã³ç®¡çè æš©éãåŸãŠããããšã倿ããæ»æè ã¯èªèšŒæ å ±ãæ¡åããŠäŒæ¥ã·ã¹ãã ã«ã¢ã¯ã»ã¹ããããšãã§ããŸãããšã³ããã€ã³ãã®ããã10%ã¯é©åã«ä¿è·ãããŠããªãç¹æš©çãªã¢ã«ãŠã³ãã®ãã¹ã¯ãŒããæã£ãŠããããã®ãã¡ã®26%ã¯ãã¡ã€ã³ã®ç®¡çè ã§ããããšã倿ããŠããŸãã
- 2021幎1æã«æ³çæªçœ®ã«ããäžçã§æãæŽ»çºãªãã«ãŠã§ã¢ãEmotetã®ãããããããééãããŠãã1幎åŸã«åŸ©æŽ»ïŒ 2022幎ã«2,500äžä»¶ãè¶ ããã¡ãã»ãŒãžãéä¿¡ããããã¯2çªç®ã«å€ãè åšã®2å以äžã®éã§ããã«ãé¢ããããEmotetã®æŽ»åã¯æç¶çã§ããã®æ»æã°ã«ãŒãã¯ãã¯ãåŸã®è åšã®ç¶æ³ã«é©å¿ããããšã«ç¡æ°åãªå åã瀺ããŠããŸãã
- ééç®çã®ãµã€ããŒç¯çœªãè
åšã®å€§éšåãå ããäžæ¹ã§ãç°åžžå€çãªAPTïŒAdvanced Persistent ThreatïŒæ»æã1åã§ãããã°ã倧ããªåœ±é¿ãäžããå¯èœæ§ãããïŒ äžè¬äŒæ¥ãæ¿åºã®ã¹ãã€æŽ»åãè¡ããã·ã¢ç³»ã®APTæ»æã°ã«ãŒãã§ããTA471ã«ããå€§èŠæš¡æ»æãã£ã³ããŒã³ã¯ãAPTã¡ãã»ãŒãžã®ä»¶æ°ã§ç¬¬1äœã«ãªããŸããããŸããäžåœåœå®¶ãšçµã³ã€ããAPTã®æ»æè
ã§ããTA416ã¯ãæãã¢ã¯ãã£ããªã°ã«ãŒãã«å±ããŸãããç¹ã«ãTA416ã«ããæ°ããªéèŠæ»æãã£ã³ããŒã³ã¯ããã·ã¢ãšãŠã¯ã©ã€ãæŠäºã®éå§ãšåæã«èµ·ããã飿°ã»ç§»æ°ãµãŒãã¹ã«é¢é£ãããšãŒãããã®å€äº€æ©é¢ãæšçãšããŠããŸããã

æ¥æ¬ãã«ãŒããã€ã³ãæ ªåŒäŒç€ŸãããŒã ãšãã³ãžã§ãªã¹ãã®å¢ç° 幞çŸã¯æ¬¡ã®ããã«è¿°ã¹ãŠããŸãããå€ãã®äŒæ¥ã䜿ã£ãŠããMicrosoft 365 ãæ»æå¯Ÿè±¡ã«ãããäžãOfficeãã¯ãããOneNoteææžãOneDriveãªã©ã®Microsoftããã€æ©èœããã©ãããã©ãŒã ããæ»æãæ ãéèŠãªããŒããšããŠæªçšãããŠããŸãããŸããã€ãŠã¯APTïŒåœå®¶ãåŸãçŸã«ããæ»æã°ã«ãŒãïŒã®ã¿ãçšããŠããäºèŠçŽ èªèšŒããã€ãã¹ããAiTMãšåŒã°ãããã£ãã·ã³ã°ãã¯ããã¯ã¯ãã¢ã³ããŒã°ã©ãŠã³ãã§ãµãŒãã¹åãããããã«äžè¬çã«ãªããé»è©±ã«ãããµããŒãè©æ¬ºããä»ãå€ãã®ãµã€ããŒç¯çœªè ãæ°è»œã«äœ¿ãããšãã§ãããã®ãšãªã£ãŠããŸããŸãããå€ãã®æ»æã°ã«ãŒããããŸããŸãªæ°ããæ»æãã¯ããã¯ã詊ããŠããããšã芳枬ãããŠããŸãããæ»æè 㯠â人âã®è匱æ§ãæšçã«ãç¶ããŠããããšã«å€ããã¯ãããŸããã
調æ»ç¯å²
ãHuman Factor 2023ãã¬ããŒãã¯ããã«ãŒããã€ã³ããäžçäžã§åéããé»åã¡ãŒã«ãã¯ã©ãŠããã¢ãã€ã«ã³ã³ãã¥ãŒãã£ã³ã°ã«ãããæ¥çæå€§ãã€æã倿§ãªããŒã¿ã§ããã°ããŒãã«ãµã€ããŒã»ãã¥ãªã㣠ããŒã¿ã»ãããProofpoint Nexus Threat Graphã§åæãããã®ã§ãããã«ãŒããã€ã³ãã§ã¯ãæ¯æ¥26åãè¶ ããã¡ãŒã«ã490åã®URLã19åã®æ·»ä»ãã¡ã€ã«ã2,800äžã®ã¯ã©ãŠãã¢ã«ãŠã³ãã17åã®äžå¯©ãªSMSãªã©ãåæããŠããŸããæ¬ã¬ããŒãã¯ã2022幎1æ1æ¥ãã12æ31æ¥ã察象æéãšããŠãããåäžãã³ããŒã«ããæ¥çã§æãå æ¬çãªã¬ããŒãã§ããããŠãŒã¶ãŒãªã¹ã¯ã®3ã€ã®äž»èŠãªèŠçŽ ïŒè匱æ§ãæ»æãæš©éïŒã®ãã¡ãçŸä»£ã®ãµã€ããŒæ»æãéåžžã«å±éºã«ããŠãããã¯ãããžãŒãšäººã®å¿çã®çµã¿åããã«çŠç¹ãåœãŠãè åšç°å¢å šäœã®æ°ããªå±éãæãäžããŠããŸãã
ãHuman Factor 2023ãïŒæ¥æ¬èªçïŒã¯ä»¥äžãªã³ã¯ããããŠã³ããŒãããŠãã ããïŒ
https://www.proofpoint.com/jp/resources/threat-reports/human-factor
Proofpoint | ãã«ãŒããã€ã³ãã«ã€ããŠ
Proofpoint, Inc.ã¯ããµã€ããŒã»ãã¥ãªãã£ã®ã°ããŒãã« ãªãŒãã£ã³ã° ã«ã³ãããŒã§ããçµç¹ã®æå€§ã®è³ç£ã§ããããåæã«æå€§ã®ãªã¹ã¯ãšããªãããã人ããå®ãããšã«çŠç¹ãããŠãŠããŸããProofpointã¯ãã¯ã©ãŠãããŒã¹ã®çµ±åãœãªã¥ãŒã·ã§ã³ã«ãã£ãŠãäžçäžã®äŒæ¥ãæšçåæ»æãªã©ã®ãµã€ããŒæ»æããããŒã¿ãå®ãããããŠããããã®ãŠãŒã¶ãŒããµã€ããŒæ»æã«å¯ŸããŠããã«åŒ·åãªå¯ŸåŠèœåãæãŠãããæ¯æŽããŠããŸãããŸããFortune 100äŒæ¥ã®75%ãå«ãããŸããŸãªèŠæš¡ã®äŒæ¥ãããã«ãŒããã€ã³ãã®ãœãªã¥ãŒã·ã§ã³ãå©çšããŠãããã¡ãŒã«ãã¯ã©ãŠãããœãŒã·ã£ã«ã¡ãã£ã¢ãWebé¢é£ã®ã»ãã¥ãªãã£ã®ãªã¹ã¯ããã³ã³ã³ãã©ã€ã¢ã³ã¹ã®ãªã¹ã¯ãäœæžããããæ¯æŽããŠããŸãã
詳现㯠www.proofpoint.com/jp ã«ãŠã確èªãã ããã
© Proofpoint, Inc. Proofpointã¯ç±³åœåã³ãã®ä»ã®åœã ã«ãããProofpoint, Inc.ã®åæšã§ããæ¬ããã¥ã¡ã³ãã«èšèŒãããŠããäŒç€Ÿåã補ååããµãŒãã¹åã¯ãäžè¬ã«å瀟ã®ç»é²åæšãŸãã¯åæšã§ããæ¬ããã¥ã¡ã³ãã®èšèŒå 容ã補ååã³ãµãŒãã¹ã®ä»æ§ã¯äºåãªã倿ŽãããããšããããŸãã