æ¬ããã°ã¯ãè±èªçããã°ãhttps://www.proofpoint.com/us/threat-insight/post/cybersecurity-predictions-2019ãã®ç¿»èš³ã§ãã
æŠèŠ
Proofpointã§ã¯æ¯å¹Žãè åšç°å¢ã«åœ±é¿ãäžããå¯èœæ§ããããã¬ã³ããã€ãã³ãã«ã€ããŠã®äºæž¬ãçºè¡šããŠããŸãã2019幎ã¯ãæå·é貚åžå Žã®æŽèœã«ãã£ãŠæ»æè ã«ããééã®ç§»åïŒãããŠçé£ã®ïŒæ¹æ³ãå€ããã§ãããããŸããé»åã¡ãŒã«è©æ¬ºã®ææ³ãIDã®åœè£ ããçãŸããIDã®å©çšã«ç§»è¡ããããšã§ãæ»æãããå¹ççã«ãªããšå ±ã«ãè åšã®æ€åºãå°é£ã«ãªããšèããããŸããããã«ãæ»æè ã¯æ£èŠã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®äžæ£å©çšãå éããæ³èŠå¶ãšé²åŸ¡æè¡ãæ°ããæ©èœãã¿ãŒã²ãããžã®å¯Ÿå¿ã«è¿œãããäžãåœå®¶ãæ¯æŽããã¢ã¯ã¿ãŒã¯æŽ»åãæŽ»çºåãããã§ãããããœãŒã·ã£ã«ã¡ãã£ã¢ã«ããè åšãšã³ã³ãã©ã€ã¢ã³ã¹ãªã¹ã¯ãå¢å€§ããè åšã¢ã¯ã¿ãŒïŒæ»æè ïŒã¯ãã£ã«ã¿ãªã³ã°ãšã¿ãŒã²ãã£ã³ã°ã®èœåãåäžãããæ·±ãæœè¡ããŠæ»æãè¡ããåçãå¢ããã§ãããã
æ»æè ã¯éããã質ã«éç¹ã眮ãããã«ãªã
2016幎ãš2017幎ã®è åšç°å¢ã®ç¹åŸŽã¯ãæªæãæã£ãå€§èŠæš¡ãªé»åã¡ãŒã«æ»æã§ãããããã®ãã¡æå€§ã®ãã®ã¯äžæ¡ãã®æåãªã¢ã¯ã¿ãŒã«ãããã®ã§ããããããšã¯å¯Ÿç §çã«ã2018å¹Žã¯æå€§èŠæš¡ã®Lockyã©ã³ãµã ãŠã§ã¢æ»æãè¡ã£ãã¢ã¯ã¿ãŒããã®çŽåŸã«äžèŠæš¡ã®ãªã¢ãŒãã¢ã¯ã»ã¹åããã€ã®æšéЬïŒRATïŒæ»æãè¡ããªã©ãæ»æã现ååããããŸããŸãªããŠã³ããŒããŒããã³ãã³ã°åããã€ã®æšéЬãããã¯InfoStealerãã©ã³ãµã ãŠã§ã¢ã«ãšã£ãŠä»£ãããŸãããè åšã¢ã¯ã¿ãŒã¯ãé·æéã«ããã£ãŠåçãããããå¯èœæ§ã®ãããé«åè³ªã®ææãã«æ³šåãã¯ããããããèŠæš¡ãæ±ããã²ãŒã ã¯ã»ãŒçµãããŸããã
ãé«åè³ªã®ææãïŒã»ãã¥ãªãã£ãã³ããŒãç ç©¶è ã«æ°ã¥ãããããšãªããç¹å®ã®ãã«ãŠã§ã¢èŠä»¶ã«åèŽããå°åã®ã¿ã«ææããïŒãå®çŸããããã«ã¯ããã£ã«ã¿ãªã³ã°æè¡ããã³é²åŸ¡ãåé¿ããæè¡ã®åäžãå¿ èŠã§ããProofpointã¯ã2019幎ã«ã¯URLæ»æããã³äžéãã«ãŠã§ã¢ãçµç±ããæ»æã«ãããŠããã广çã§åºç¯å²ãªãã£ã«ã¿ãªã³ã°ãå¢ãããšäºæž¬ããŠããŸãã2018幎ã«èŠ³æž¬ãããsLoadãªã©ã®æŽç·Žããããã«ãŠã§ã¢ãSocGholishã®ãããªææãã§ãŒã³ããµã³ãããã¯ã¹ãç ç©¶çšãœãããŠã§ã¢ã®æç¡ãå°åãèšèªãã¿ã€ã ãŸãŒã³ãã®ä»ã®å±æ§ã«åºã¥ãããã£ã«ã¿ãªã³ã°ãåŒãç¶ãå©çšãããã§ãããã
ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãšã¯ã¬ãã³ã·ã£ã«ãã£ãã·ã³ã°ããã«ãŠã§ã¢æ»æãäžåã
2019幎ã«ã¯ãã¹ããŒããã£ã«ã¿ãªã³ã°ãšå·§åŠãªãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®çµã¿åããã«ããããã«ãŠã§ã¢æ»æã«ãããææã®è³ªãšæå¹æ§ãåäžããã§ããããããã«Proofpointã¯ããã«ãŠã§ã¢æ»æãäžåãèŠæš¡ã§ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãšã¯ã¬ãã³ã·ã£ã«ãã£ãã·ã³ã°ãåŒãç¶ãå¢å ãããšäºæ³ããŠããŸããã¯ã¬ãã³ã·ã£ã«ãã£ãã·ã³ã°ã®æåã«ãã£ãŠã䟵害ãããã¢ã«ãŠã³ãã®äŸçµŠãå¢ããããããæªçšããæ»æãå¢å ããããšãèŠèŸŒãŸããŸããããã¯ã2018幎ã«ãã§ã«èгå¯ãããŠãããã¬ã³ãã§ãã
åæã«ãæ»æè ã¯Microsoft OneDriveãGoogle Driveãªã©ã®æ£èŠã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®äžæ£å©çšãæ¡å€§ããã§ããããæ£èŠã®ãã¡ã€ã³ã䜿ã£ããªã³ã¯ã¯ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®ä¿¡é Œæ§ãåäžãããã ãã§ãªããæ£èŠã®ãµãŒãã¹ãå©çšããããšã§é²åŸ¡ã·ã¹ãã ãæ»æãæ€åºããããšãé£ãããªããŸãã
Windowsã»ãã¥ãªãã£ã¡ã«ããºã ã®æã穎ãèŠã€ããæªæã®ããæ·»ä»ãã¡ã€ã«æ»æã§.wizã.pubã®ãããªæ°ãããã¡ã€ã«åœ¢åŒã詊ãããšã§ãè åšã¢ã¯ã¿ãŒã¯ãŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã®ç£èŠç¶²ããããããããšãã§ããããã¯2018å¹ŽãææããããŸãããé²åŸ¡ã·ã¹ãã ãåé¿ããææ®µãšããŠã®çŸæç¹ã§ã®æå¹æ§ãèãããšããã®åŸåã¯ç¶ããšäºæ³ãããŸãã
èŠå¶ã®åœ±é¿ãå šæ¥çš®ã«æ³¢åãã
GDPRæœè¡åŸã®WHOIS*1ããŒã¿ãçã äžè¶³ãããã®æå³ããªãçµæãšããŠã2019幎ã¯ãã¡ã€ã³ã®äžæ£å©çšãå¢å ããã§ããããããŒã¿ã®äžè¶³ã¯ããã¡ã€ã³ã«é¢é£ããæªæã®ããæŽ»åãçµç¹çãªãµã€ããŒã¹ã¯ã¯ããã£ã³ã°*2ãèå¥ããã®ãé£ãããªãããšãæå³ããŸãããã®çµæããã©ã³ãã®ææè ã¯èªãã®åæšæš©ãå®ãããµã€ããŒã¹ã¯ã¯ããã£ã³ã°ã«å¯Ÿæããããã®æ°ããããŒã«ãšãã¯ããã¯ãå¿ èŠãšããã§ããããååŸã«å¶éã®ç¡ããããã¬ãã«ãã¡ã€ã³ïŒTLDïŒã®äŸçµŠã¯å¢ãç¶ããŠããããã¯ãããžãŒãšé²åŸ¡ãããã³ã«ãæ³èŠå¶ãšããžãã¹ããŒãºãžã®å¯Ÿå¿ã«è¿œãããäžã§ããã¡ã€ã³ã¬ãã«ã§ã®ãã©ã³ãã®ãªãããŸããããäžè¬çã«ãªããšäºæ³ãããŸãã
*1 WHOISãšã¯ãIPã¢ãã¬ã¹ããã¡ã€ã³åã®ç»é²è ãªã©ã«é¢ããæ å ±ããã€ã³ã¿ãŒããããŠãŒã¶ãŒã誰ã§ãåç §ã§ãããµãŒãã¹ã
*2 äŒæ¥åãåæšãæå人ã®ååãªã©ã®ãã¡ã€ã³ã転売ç®çã§ç»é²ã»ä¿æããããšã
ãããããœãŒã·ã£ã«ã¡ãã£ã¢ãããžãã¹ã³ãã¥ãã±ãŒã·ã§ã³ããã³ããŒã±ãã£ã³ã°ã®ããã®ããŒã«ãšããŠæçããã«ã€ããŠãç¹ã«éèæ¥çã«ãããŠãæ°ããªæ³èŠå¶ã¯ç£èŠããã³ã³ã³ãã©ã€ã¢ã³ã¹ãœãªã¥ãŒã·ã§ã³ãžã®æè³ãå éãããã§ããããäžäŸãæãããšãäŒæ¥ã¯ãœãŒã·ã£ã«ã¡ãã£ã¢ã«ãããFINRA*3éåã«ã€ããŠãŸããŸãç¥çµãå°ãããŠããã2019幎ã«ã¯æ³èŠå¶ã«å¯Ÿå¿ããããã«ããªã·ãŒãšãã¯ãããžãŒã®äž¡æ¹ã®é¢ã§å¯Ÿå¿ãé²ããã§ãããã
*3 Financial Industry Regulatory Authorityã®ç¥ãç±³åœã«ãããéèååŒæ¥ã®èªäž»èŠå¶æ©é¢ã
ã¡ãŒã«è©æ¬ºã¯å€æ§åããããæŽç·ŽãããããŒã«ã䜿çšããŠãããå€ãã®ãéãBECã¢ã¯ã¿ãŒã«æµã蟌ã
2018幎ãéããŠãããžãã¹ã¡ãŒã«è©æ¬ºïŒBECïŒãå«ãã¡ãŒã«è©æ¬ºãæ¡å€§ããã¢ã¯ã¿ãŒã¯æ§ã ãªè©Šã¿ã«ãããã¯ãããžãŒãæŽç·ŽãããŠããŸãããã¡ãŒã«è©æ¬ºã®ã¢ã¯ã¿ãŒãã¿ãŒã²ãããæ¡å€§ãããã®æå¹æ§ãåäžãããã°ã2019幎ã¯ãããã®åªåã®ææãåŸãã§ãããã
ç¹ã«éèŠãªã®ã¯ãã¡ãŒã«è©æ¬ºã¢ã¯ã¿ãŒãIDã®åœè£ ïŒãªãããŸãïŒããã䟵害ãããIDã®æªçšã«ç§»è¡ããã ãããšããããšã§ããBECæ»æãæ£èŠã®å éšã¢ã«ãŠã³ãã䜿ã£ãŠè¡ãããã°ãå€éšã¿ã°ä»ããDMARCãªã©ã®é²åŸ¡çãåé¿ããããšãã§ããŸããæ»æè ã¯æ»æã仿ããããŒã¿äŸµå®³ã«ãã£ãŠã¯ã¬ãã³ã·ã£ã«ãååŸãããã«ãŒããã©ãŒã¹æ»æ*4ãè¡ããã¯ã¬ãã³ã·ã£ã«ãçããã«ãŠã§ã¢ãªã©ã«ãã£ãŠã䟵害ãããã¢ã«ãŠã³ãã®å©çšãå éããã§ãããã
*4 ãŠãŒã¶ãŒã®ã¢ã«ãŠã³ãã»ãã¹ã¯ãŒããè§£èªãããããèããããå šãŠã®ãã¿ãŒã³ãè©Šãæ¹æ³ãç·åœããæ»æãšãåŒã°ããã
ãã®äžæ¹ã§ãæŽç·Žãšã¯ç¡çžãšèããããŠãããã€ãžã§ãªã¢ã®BECã¢ã¯ã¿ãŒããç·é¡5åãã«è¿ãè³éãéããŸããããããã®è³éã®å°ãªããšãäžéšã¯ãããæŽç·ŽãããããŒã«ããã¯ããã¯ã®éçºã«åæè³ãããè±å¯ãªè³éãæã€å€§èŠæš¡ãªç¯çœªè éå£ã«ããè åšãå¢å€§ãããã§ãããããã€ãžã§ãªã¢åœå å€ã®è åšã¢ã¯ã¿ãŒã2019幎ã«ãã®è³éãçã£ãŠã¡ãŒã«è©æ¬ºåžå Žã«åå ¥ããåé¡ã®å€§èŠæš¡åãšBECãžã®ã¢ãããŒãã®å€æ§åãé²ãã§ãããã
Proofpointã¯é·æéã«ããã£ãŠBECåæ»æã®å¯Ÿè±¡ãšãªãããããè€éãªãµãã©ã€ãã§ãŒã³ãæã€æ¥çã芳å¯ããŠããŸãããã2019幎ã«ã¯ãµãã©ã€ãã§ãŒã³ã®è匱æ§ã®æªçšãããäžè¬çã«ãªãã§ããããããå€ãã®äŒæ¥ã䟵害ããããµã€ããŒç¯çœªè ãæŽç·Žãããããšã§ãäŒæ¥ã®ä¿¡é Œã§ããããŒãããŒãšäž»èŠãªå€éšã®ã¹ããŒã¯ãã«ããŒãã·ã¹ããããã¯ã«ç¹å®ããããšãå€§èŠæš¡ã«è¡ããããã«ãªããŸããè åšã¢ã¯ã¿ãŒãçµç¹ã®ä¿¡é Œã®èŒªïŒCircle of TrustïŒãçè§£ããããšã§ãä¿¡é Œé¢ä¿ã«ããå€éšIDã®è匱æ§ãå©çšã§ããããã«ãªãããããã®ãã£ãã«ãéããŠããå€ãã®BECã¡ãŒã«ãšãã«ãŠã§ã¢ãéä¿¡ããããšãå¯èœã«ãªããŸãã
åœå®¶ãæ¯æŽããå ¬ç¶ãšããæŽ»åãç§å¯ã®äœæŠã«åã£ãŠä»£ãã
åœå®¶ãæ¯æŽããã¢ã¯ã¿ãŒãAPTã°ã«ãŒãã¯ããã€ãããã¡ã€ã«ãªæ»æã«ãããèªãã®æŽ»åãé ããªã
ãªã£ãŠããŸãã2019幎ã«ã¯ããããã®ã°ã«ãŒãã«ããæ»æã¯æ¡å€§ãç¶ããåœå®¶ãæ¯æŽããã¢ã¯ã¿ãŒã¯ãäžçäžã®äžç¢ºå®ãªæ¿æ²»æ
å¢ã®äžã§å
¬ç¶ãšæŽ»åããã§ãããããšãŒããããã¢ãžã¢ãåç±³ã§ã®å°æ¿åŠçãªåé¢ä¿ïŒãã€ããã¯ã¹ïŒã®å€åããè
åšã¢ã¯ã¿ãŒãšãããæ¯æŽããåœå®¶ã®ç®çã«å¿ããŠãæ°ééšéãšå
Œ
±éšéã®äž¡æ¹ã§ãã€ã³ãã©ã¹ãã©ã¯ãã£ãã³ã³ãã¥ãŒã¿ã·ã¹ãã ãããŒã¿ã¹ãã¢ãªã©ãžã®æ»æã®æ¿åã«ç¹ããã§ãããã
2019幎ã¯ããŠãŒã¶ãŒãªã¹ã¯åæãã®å¹Žã«ãªã
ITçµç¹ã¯ãéèŠãªã·ã¹ãã ãšããŒã¿ã確å®ã«ä¿è·ããããã«ãé·å¹Žã«ããã£ãŠãªã¹ã¯åæãè¡ã£ãŠããŸããããããŠç§ãã¡ã¯ä»ããããšäŒŒããããæŽç·Žãããã¢ãããŒããã人ãã«å¯ŸããŠé©çšããããã®ããŒã¿ãšåæèœåãæã«å ¥ããŸããã2019幎ãçµç¹ã¯ã¿ãŒã²ããã«ãããé »åºŠãšçšåºŠã圹å²ãã¢ã¯ã»ã¹ããããŠé²åºã®çšåºŠã«åºã¥ããŠãæãå±éºã«ãããããŠããåŸæ¥å¡ãç¹å®ããããã«ãæ»æè ããŠãŒã¶ãŒãã©ã®ããã«èŠãŠããããšãããæ»æè ã®èŠç¹ããéèŠããããã«ãªãã§ãããããã®ã人ãäžå¿ãšããèŠç¹ãã«ãããçµç¹ã¯ãããã®ãŠãŒã¶ãŒã«é©åãªã¬ãã«ã®ä¿è·ãšç·©åçãé©çšããæãå¿ èŠãšãããéšåã«ãªãœãŒã¹ãå²ãåœãŠãããšãã§ããŸãã
æå·éè²šã®æ··ä¹±ã¯ãã€ããŒãšã©ã³ãµã ãŠã§ã¢ãžã®ååž°ãçã
2018å¹Žã¯æå·é貚ã«ãšã£ãŠã¯äžéãªå¹Žã§ããããå€ãã®ã¢ããªã¹ãã¯ããããæå·é貚åžå Žã«æçµçãªå®å®æ§ãšæç¶æ§ãããããããã®å€§ããªæ··ä¹±ã®å§ãŸãã«ãããªããšèããŠããŸããBitcoinã®äŸ¡å€ã¯äžããç¶ããŠãããæªè³ªãªã³ã€ã³ãã€ãã³ã°ã«é¢é£ãããããã¯ãŒã¯ã¢ã¯ãã£ããã£ãåŒãç¶ã芳枬ãããŠããŸãããæå·é貚ãé·æçã«ã¯åç¶ããŠè¡ãã§ããããšããå åãèŠãããŸãã2019幎ã«ã¯ããããã®éè²šã®æçãé¢é£åžå Žã®å®å®åãèŠå¶ã®æ çµã¿ã®å°å ¥ãäžå®å®ãªé貚ã®åžå Žããã®æ€éã«ãããç¬ç«åã®ã³ã€ã³ãã€ããŒãšã©ã³ãµã ãŠã§ã¢ã«ååž°ããã§ãããã
å€ãã®ãã³ãã³ã°åããã€ã®æšéЬãInfoStealerã«ã¯ãã³ã€ã³ãã€ãã³ã°ã®ããã®ã¢ãžã¥ãŒã«ãšãŠã©ã¬ãããçãæ©èœãåãã£ãŠããŸããCoinHiveããã³ä»ã®WebããŒã¹ã®ã³ã€ã³ãã€ããŒã¯ãä»ã§ããã®éçšè ã®ããã«ãç¡æã®ãéãã皌ãã§ããŸããããã2019幎ã«ã¯ãæå·é貚é¢é£ã®æŽ»åã¯åçã«å¢å ããã§ããããããã«ã¯ãç ç²è ããBitcoinã«ãã£ãŠçãããæ®éã«èšèšããããã«ãŠã§ã¢ã®ã»ããåªããçµæžæ§ãæã€ããšã«ãããå€§èŠæš¡ãªã©ã³ãµã ãŠã§ã¢ã®åå°å ¥ãå«ãŸããŸãããã ãã2016幎ãã2017幎ã«ãããŠã©ã³ãµã ãŠã§ã¢ã§èŠãããããã«ãåäžã®ãã«ãŠã§ã¢ãã¡ããªãåªå¢ã«ãªãããšã¯ãªãã§ããããããããããã³ãã³ã°åããã€ã®æšéЬããããã«ãšã©ãŸãç¶ãããã®äžã§å€ãã®äºçš®ããã¡ããªãŒãæå·é貚ã«é¢é£ããæ©èœã远å ããã§ãããã
çµè«
2018幎ã«ã¯ãã«ãŠã§ã¢é åžãã¡ãŒã«è©æ¬ºãã¯ããã¯ããœãŒã·ã£ã«ã¡ãã£ã¢é²åŸ¡ãªã©ã«åœ±é¿ãäžããè åšç°å¢ãæ¥éã«å€åããŸãããã2019幎ã«ã¯ããã«å€§ããªå€åãèŠèŸŒãŸããŸããGDPRãæå·é貚åžå Žã®æ··ä¹±ããããŠäžççãªæ¿æ²»æ å¢ãªã©ã¯ãã¹ãŠãæ»æè ã人ã ãçµç¹ãçãæ¹æ³ãããããæ¥çã®é²åŸ¡æŠç¥ã®æ§ç¯ã«ãããŠéèŠãªåœ¹å²ãæããã§ãããã