Processing言語によるセキュアOS/侵入防御効果の可視化手法
全文
(2) Vol.2019-DPS-178 No.9 Vol.2019-CSEC-84 No.9 2019/3/4. ሗฎ⌮Ꮫ◊✲ሗ࿌ IPSJ SIG Technical Report ࢫࢸ࣒ไ㝈ࢆࡅࡿࡓࡵṇࡋࡃタᐃࡋ࡞࠸㝈ࡾࡣࢩࢫࢸ. 1.3 ᮏ✏ࡢᵓᡂ. ࣒Ṇ➼ࡢࢺࣛࣈࣝࢆㄏⓎࡍࡿྍ⬟ᛶࡀ࠶ࡿࡇ㸪⌧Ⅼ. ᮏ✏ࡢᵓᡂࡣ௨ୗࡢ㏻ࡾ࡛࠶ࡿ㸬ࡍ࡞ࢃࡕ㸪➨ 1 ❶࡛⫼. ࡛ࡢ⏝ࡀᑡ࡞ࡃຠᯝࡶ᫂☜࡞ࡇ࡞ࡀ࠶ࡾ㸪ࡇ. ᬒㄢ㢟㸪ᮏ◊✲ࡢ┠ⓗ㈉⊩ࡘ࠸࡚ㄝ᫂ࡋ㸪➨ 2 ❶࡛. ࢀࡽࢆࡲࡵࡿ㸪 ࠕ࣏ࣜࢩ࣮⟶⌮ᴗົࡢᡭ㛫ࢆᘬࡁཷࡅ࡚. 㛵㐃◊✲ࢆᩚ⌮ࡍࡿ㸬➨ 3 ❶࡛ࡣ㸪ᥦᡭἲࡘ࠸࡚ㄝ᫂. ࡲ࡛⏝ࡍࡿࡇᯝࡓࡋ࡚࣓ࣜࢵࢺࡀ࠶ࡿࡢࠖ࠸࠺. ࡍࡿ㸬ࡑࡢᚋ㸪➨ 4 ❶࡛ࡣᶍᨃᨷᧁࡘ࠸࡚㏙ࡓୖ࡛ࠊ. ᛕࢆ࣮ࣘࢨ㉳ࡉࡏ࡚࠸ࡿࡇࡀᐜ᫆᥎ ࡛ࡁࡿ㸬. ྍどᐇ㦂࡛ᚓࡽࢀࡓྍどᅗࢆලయⓗ♧ࡍ㸬⥆࠸࡚➨. ࡇࡢࡼ࠺࡞⫼ᬒࡢୗ㸪ࢭ࢟ࣗ OS ࡢ࠸ࡃࡉ㛵ࡋ࡚. 5 ❶࠾࠸࡚ᥦᡭἲ㛵ࡍࡿホ౯⪃ᐹࢆ㏙࡚ࡽ㸪. ࡣ㸪࣏ࣜࢩ࣮ࢆぢ᫆ࡃࡋࡓࡾゎᯒࢆᐜ᫆ࡋࡓࡾࡍࡿࡓࡵ. ᭱ᚋ➨ 6 ❶࡛ᮏ✏యࡢࡲࡵᚋࡢㄢ㢟ࢆ㏙ࡿ㸬. ࡢࣥࢱ࣮ࣇ࢙ࢫࡢ㛤Ⓨ࡞ࢆጞࡵࡍࡿ㸪࠸ࡃࡉ ࡢᨵၿྥࡅ࡚ࣉ࣮ࣟࢳࢆ⾜ࡗࡓඛ⾜◊✲ࡀ᪤Ꮡᅾࡋ ࡚࠸ࡿ୍᪉࡛㸪 ࢭ࢟ࣗ OS ࡢຠᯝࡸ࣓ࣜࢵࢺ↔Ⅼࢆᙜ. 2. 㛵㐃◊✲. ࡚࡚᫂☜ࡍࡿࡇ↔Ⅼࢆᙜ࡚ࡓ◊✲ࡣ㸪⌧≧ࡀᑡ࡞. ᮏ❶࡛ࡣ㸪 OS ⯡࠾ࡼࡧࢭ࢟ࣗ OS 㛵ࡍࡿ◊✲㸪. ࡃ༑ศ࡛࠶ࡿ㸬. ྍど㛵ࡍࡿ◊✲ศࡅ࡚㛵㐃◊✲ࢆᩚ⌮ࡍࡿ㸬. ᮏ◊✲࡛ࡣ㸪ࢭ࢟ࣗ OS ࡢ୰࡛ࡶ≉ TOMOYO Linux ↔Ⅼࢆᙜ࡚㸪ࡑࡢຠᯝࡢྍどࢆ┠ᣦࡍ㸬ᮏ◊✲࡛ྍど. 2.1 OS ⯡࠾ࡼࡧࢭ࢟ࣗ OS 㛵ࡍࡿ◊✲. ࡢᑐ㇟ࡍࡿࠕຠᯝࠖࡘ࠸࡚ࡣ㸪ࠕTOMOYO Linux ࡢ. ᶫᮏࡽࡢ◊✲[2]࡛ࡣ㸪 ሗࢭ࢟ࣗࣜࢸࢆᢸಖࡍࡿࡓ. ᙉไࢡࢭࢫไᚚᶵ⬟ࡢ↓ຠ᭷ຠ㸪ࢩࢫࢸ࣒. ࡵࡢ᭱ࡶᇶ♏ⓗ࡞ࢯࣇࢺ࢙࢘ࡋ࡚ OS ࢆ⨨࡙ࡅ㸪 ཧ. ධࡋࡓᨷᧁ⪅ࡀ⟶⌮⪅ࡋ࡚ᐇ⾜ྍ⬟࡛࠶ࡿࢥ࣐ࣥࢻᩘࢆ. ↷ࣔࢽࢱࡢせ௳ᑐᛂࡅ࡞ࡀࡽ㸪 ௬ᢏ⾡ࡸ OS ࣉࣟ. ẚ㍑ࡋࡓࡢᕪศࠖᐃ⩏ࡋ㸪 ࡇࡢᕪศࡢ♧ࡍ್ࡀࡁࡅ. ࢢ࣒ࣛࡢ᳨ドᢏ⾡㸪ࢡࢭࢫไᚚᢏ⾡↔Ⅼࢆᙜ࡚࡚㏆ᖺ. ࢀࡤࡁ࠸㸪ᨷᧁ⪅ࡼࡿࢩࢫࢸ࣒ෆ㒊ࡢ◚ቯάືࢆ. ࡢ◊✲ືྥࢆศ㢮࣭ᩚ⌮ࡋ࡚⤂ࡋ㸪ಶࠎࡢᢏ⾡㛵ࡍࡿ. 㣗࠸Ṇࡵࡿຠᯝࡀࡁ࠸⪃࠼ࡿ㸬ࡲࡓ㸪ᮏ◊✲࠾ࡅࡿ. ᚋࡢ◊✲ࡘ࠸࡚ࡢᒎᮃࡸㄢ㢟ࢆᩚ⌮ࡋ࡚࠸ࡿ㸬. ྍどࡣ㸪 ᶍᨃᨷᧁࡢ㐍ᤖẁ㝵ࡀ 20%㸪 40%㸪 60%࡛. ཎ⏣ࡽࡢ◊✲[3]࡛ࡣ㸪ᚑ᮶ࡢࢡࢭࢫไᚚ᪉ᘧࡢㄢ㢟࡛. ࠶ࡿሙྜ TOMOYO Linux ࡢᙉไࢡࢭࢫไᚚᶵ⬟ࡀ↓. ࠶ࡗࡓ㸪ࢡࢭࢫせồࡢྍྰุ᩿ࡢࢩࢫࢸ࣒ࡸࣉࣜࢣ࣮. ຠ᭷ຠࡢሙྜ࠸࠺ྜィ 6 ✀㢮ࡢ␗࡞ࡿ᮲௳ୗ࠾. ࢩࣙࣥࡢᙳ㡪࠾ࡼࡧྍྰุ᩿Ⅼ࡛ᐈయಖᏑࡉࢀ࡚࠸. ࠸࡚ᐇࡋࡓᶍᨃᨷᧁࡢ⤖ᯝࢆ㸪㇏ᐩ࡞ࢢࣛࣇࢵࢡᶵ⬟. ࡓሗࡢࢃࢀ᪉ࡀ⪃៖ࡉࢀ࡚࠸࡞࠸ၥ㢟ᑐࡍࡿゎỴ⟇. グ㏙ࡢᐜ᫆ᛶࢆ୧❧ࡍࡿ Processing ゝㄒࢆ⏝࠸࡚సᡂࡋ. ࡋ࡚㸪ࣉࣜࢣ࣮ࢩࣙࣥࡢᐇ⾜≧ἣࢆ⪃៖ࡋࡓ᪂ࡓ࡞. ࡓᅗ⾲ࡍࡇࡼࡾ㸪 ᮏ㡯࡛ᐃ⩏ࡍࡿࠕຠᯝࠖࢆどぬⓗ. ࢡࢭࢫไᚚ᪉ᘧࢆᥦࡋ㸪ࡑࡢᡭἲࡢ Linux ୖ࡛ࡢᐇ࡛. ㄆ㆑ྍ⬟࡞ࡿࡼ࠺ࡍࡿࡇ࡛࠶ࡿ㸬. ࠶ࡿ TOMOYO Linux ࠾ࡅࡿホ౯⤖ᯝࢆሗ࿌ࡋ࡚࠸ࡿ㸬 ᚑ᮶ࡢࢡࢭࢫไᚚ᪉ᘧ࡛ࡣ㸪ࢡࢭࢫయ࡛࠶ࡿࣉࣜ. 1.2 ᮏ◊✲ࡢ㈉⊩. ࢣ࣮ࢩࣙࣥࣉࣜࢣ࣮ࢩࣙࣥࡀࢡࢭࢫࡋࡼ࠺ࡍࡿࣇ. ᮏ◊✲ࡢ㈉⊩ࡣ㸪ࢭ࢟ࣗ OS ࡼࡿධ㜵ᚚࡢᵝᏊࢆ. ࣝ➼ࡢᐈయࡢ⤌ࡳྜࢃࡏࡼࡿࢡࢭࢫせồࡢྍྰุ. ྍどࡍࡿࡇ࡛㸪ࢭ࢟ࣗ OS ࡢຠᯝࢆㄆ㆑ࡋࡸࡍࡃࡋ. ᩿ࢆ⾜ࡗ࡚࠸ࡓࡀ㸪ཎ⏣ࡽࡢᥦᡭἲ࡛ࡣ㸪ࢩࢫࢸ࣒ࡀ㉳. ࡓࡇ࠶ࡿ㸬ᚑ᮶㸪ࢭ࢟ࣗ OS ࡢㄢ㢟ࡋ࡚ྲྀࡾ⤌ࡲ. ືࡉࢀ࡚ࡽࣉࣜࢣ࣮ࢩࣙࣥࡀᐇ⾜ࡉࢀࡿࡲ࡛ࡢᒚṔ. ࢀ࡚ࡁࡓ◊✲ࡣ㸪࠸ࡃࡉࡢᨵၿࡸᶵ⬟ࡑࡢࡶࡢࡢᙉ. ࣉࣜࢣ࣮ࢩࣙࣥࡢࢥ࣐ࣥࢻࣛࣥᘬᩘࡸࢡࢭࢫせồⓎ. ࢆ┠ᣦࡍࡶࡢࡀࢇ࡛࠶ࡗࡓࡀ㸪ᮏ◊✲࠾࠸࡚ࡣ㸪. ⏕ࡢࢥ࣐ࣥࢻࣛࣥᘬᩘ➼ࡢᵝࠎ࡞ሗࡽࣉࣜࢣ࣮. ᬑཬࡀ㐍ࡲ࡞࠸ูࡢཎᅉࡋ࡚㸪ຠᯝࡀศࡾ࡙ࡽ࠸ࡇ. ࢩࣙࣥࡢᐇ⾜≧ἣࢆゎ㔘ࡋ㸪ࡇࢀࡽࡢሗࢆ᮲௳ࡋ࡚. ࢆ௬ᐃࡋ㸪ࡑࢀࢆࢃࡾࡸࡍࡃࡍࡿࡇࢆヨࡳࡓࡶࡢ࡛࠶. ⏝ࡍࡿࡇࡼࡗ࡚ࢡࢭࢫྍྰࡢุ᩿ࡋ࡚࠸ࡿ㸬ᥦᡭ. ࡿ㸬ᥦࡋࡓどぬᡭἲࡣ㸪ࣉࣟࢢࣞࢫࣂ࣮ࡸⰍ㸪グྕࢆ. ἲࡘ࠸࡚ࡣ㸪ṇࢡࢭࢫࡸㄗ᧯సక࠺ࣜࢫࢡࢆ㍍ῶ. ⏝࠸࡚㸪ධ㜵ᚚࡢᵝᏊࢆどぬⓗᢕᥱࡋࡸࡍࡃ᳨ウ࣭ᕤ. ࡛ࡁࡿࡔࡅ࡛࡞ࡃ㸪ᆺⓗ࡞ṇࢡࢭࢫᡭἲࡢከࡃᑐ. ኵࢆ㔜ࡡࡓࡶࡢ࡛࠶ࡾ㸪ᙜึࡢ┠ⓗࢆ࠶ࡿ⛬ᗘࡣ㐩ᡂ࡛ࡁ. ࡍࡿຠᯝࡀ࠶ࡿࡇࡶ⪃ᐹࡉࢀ࡚࠸ࡿ㸬ࡋࡋ㸪ṇ࡞. ࡓ⪃࠼࡚࠸ࡿࡀ㸪ࡑࡢホ౯ࡘ࠸࡚ࡣ࠶ࡃࡲ࡛ࡶほⓗ. ࢡࢭࢫせồࡀⓎ⏕ࡋ࡚ࡽᥦᡭἲࡼࡗ࡚ᣄྰࡉࢀࡿ. ࡞⮬ᕫホ౯ࡢࡳ㢗ࡗ࡚࠸ࡿࡇࢁ࡛࠶ࡾ㸪ࡇࢀࡘ࠸࡚. ⮳ࡿࡲ࡛ࡢලయⓗ࡞ὶࢀ㛵ࡋ࡚ࡣ᳨ウᑐ㇟ࡋ࡚࠸࡞࠸㸬. ࡣᚋࡢࡁ࡞ㄢ㢟࡛࠶ࡿ㸬ᮏ◊✲ࢆ㊊ࡀࡾ㸪ᐈほⓗ࣭. ရᕝࡢ◊✲[4]࡛ࡣ㸪ࣥࢱ࣮ࢿࢵࢺࢆ⤒⏤ࡋ࡚ヨࡽࢀࡿ. ᐃ㔞ⓗホ౯ྍ⬟࡞ே㛫ㄆ㆑ࡋࡸࡍ࠸ධ㜵ᚚࡢどぬ. ṇࢡࢭࢫࢆᑐ㇟ࡋ࡚㸪 ◊✲ࡸ㛤Ⓨࡀ⾜ࢃࢀ࡚࠸ࡿ OS. ᡭἲ⧅ࡀࡾ㸪ࡑࢀࢆ࣮࣋ࢫࡋࡓࢭ࢟ࣗ OS ࡢᬑཬ. ࡼࡿṇࢡࢭࢫ㜵Ṇᢏ⾡ࢆ」ᩘ⤂ࡋ㸪ࡇࢀࡽࡢṇ. ⧅ࡀࡿࡇࢆᮇᚅࡋࡓ࠸㸬. ࢡࢭࢫ㜵Ṇᢏ⾡ࡀࡢࡼ࠺࡞✀㢮ࡢᨷᧁᑐࡋ࡚ࡢ⛬ ᗘࡢ᭷ຠᛶࢆᣢࡘࡢࢆศ㢮࣭ホ౯ࡋ࡚࠸ࡿ㸬᪤Ꮡࡢ࠸ࡃ ࡘࡢṇࢡࢭࢫࢆཷࡅࡓ㝿ࢩࢫࢸ࣒ࡀ⿕ࡿ⿕ᐖࡢ. ⓒ 2019 Information Processing Society of Japan. 2.
(3) Vol.2019-DPS-178 No.9 Vol.2019-CSEC-84 No.9 2019/3/4. ሗฎ⌮Ꮫ◊✲ሗ࿌ IPSJ SIG Technical Report ࡁࡉࢆィ ࡍࡿᣦᶆࢆᑟධࡋ࡚ࡑࢀࢆᇶホ౯ࢆ⾜࠸㸪ࡇ. ࢫไᚚᶵ⬟ࡼࡗ࡚ᐇ⾜ࢆไ㝈ࡍࡿࡇᡂຌࡋࡓࢥ࣐ࣥ. ࢀࡽࡢṇࢡࢭࢫᢏ⾡ࡀ㸪ㄽᩥ࡛ᑟධࡋࡓᣦᶆࡢࡢࡼ. ࢻࡢᩘᐇ⾜ྍ⬟࡛࠶ࡗࡓࢥ࣐ࣥࢻࡢᩘࢆྍど⤖ᯝࡢᅗ. ࠺࡞Ⅼᑐࡋ࡚ຠᯝࢆⓎࡍࡿࡘ࠸࡚ሗ࿌ࡋ࡚࠸ࡿ㸬. ᫎࡉࡏࡿࡇࡼࡗ࡚㸪ᨷᧁࡀ⾜ࢃࢀࡓᚋࡢ⿕ᐖᣑ. ࡋࡋ㸪ಶࠎࡢṇࢡࢭࢫ㜵Ṇᢏ⾡ࡀලయⓗࡣࡢࡼ. ࡢ㜵Ṇຠᯝࡀ୍┠࡛ࢃࡿࡼ࠺ࡍࡿ㸬. ࠺࡞ሗ㈨⏘ࢆಖㆤࡍࡿࡇࡀྍ⬟࡛࠶ࡿ࠸ࡗࡓࡼ࠺ ࡞㸪ṇࢡࢭࢫ㜵Ṇᢏ⾡ࡀᣢࡘຠᯝ㛵ࡍࡿ᳨ドᐇ㦂ࡣ ᐇࡋ࡚࠸࡞࠸㸬. 3.2 Processing ゝㄒ Processing ࡣ Java ࢆ࣮࣋ࢫࡍࡿࣅࢪࣗࣝࢹࢨࣥ➼ ࡢᥥ⏬ᶵ⬟≉ࡋࡓ࣮࢜ࣉࣥࢯ࣮ࢫࡢࣉࣟࢢ࣑ࣛࣥࢢゝ. 2.2 ྍど㛵ࡍࡿ◊✲. ㄒࡘ⤫ྜ㛤Ⓨ⎔ቃ࡛࠶ࡾ㸪࢟ࣕࢭ࣭ࣞࢫ࣋ࣥࢪࣕ. ⓑᒣࡢ◊✲[5]࡛ࡣྍどࢆ⾜࠺ᑐ㇟᪉ἲᛂࡌ࡚᪤. ࣑࣭ࣥࣇࣛࡼࡗ࡚ 2001 ᖺࡽ MIT ࣓ࢹ࡛ࣛ࣎㛤. Ꮡࡢྍどᡭἲࢆ㸪ࢹ࣮ࢱࡢྍど(Data Visualization)࣭. Ⓨࡀጞࡲࡗࡓ[6]㸬ᙜึࡣࣉࣟࢢ࣑ࣛࣥࢢࡢᇶ♏ࢆึᚰ⪅. ሗ ࡢ ྍ ど (Information Visualization) ࣭ ᑐ ヰ ᆺ ࡢ ྍ ど . ᣦᑟࡋࡸࡍࡃࡍࡿࡓࡵࡢᥥ⏬ࢯࣇࢺࡋ࡚ά⏝࡛ࡁࡿࡼ࠺. (Interactive Visualization)ࡢ 3 ࢝ࢸࢦࣜศࡅ࡚ᩚ⌮ࡋ㸪⭾. 㛤Ⓨࡉࢀࡓࡀ㸪ࡑࡢᚋࡣ⏝⪅ᒙࡀᣑࡋ㸪 ࢹ࣮ࢱྍど㸪. 㔞ࡢࢹ࣮ࢱࢆฎ⌮ࡍࡿࡇࡀồࡵࡽࢀࡿࣅࢵࢢࢹ࣮ࢱ௦. ࢿࢵࢺ࣮࣡ࢡ㸪3 ḟඖࡢ≀యࡢᥥ⏬➼ᵝࠎ࡞⏝㏵ྥࡅ. ࠾࠸࡚㸪ே㛫ࡢᡭసᴗࡼࡿྍどసᴗࢆ⮬ືࡋ㸪ຠ. Processing ࢥ࣑ࣗࢽࢸࡼࡾᩘ༓ࢆ㉸࠼ࡿ㔞ࡢࣛࣈ. ⋡ࡍࡿࡓࡵࡢྍど࢚࣮ࢪ࢙ࣥࢺࢆᥦ࣭タィࡋ࡚࠸ࡿ㸬. ࣛࣜࡀసࡽࢀ࡚࠸ࡿ㸬ࡲࡓ㸪Mac㸪Windows㸪Linux㸪Android. ᮏ◊✲ࡣ㸪ྍど࠸࠺⾜Ⅽࡸྍど⤖ᯝࡽఱࡀศࡿ. ➼ࡢせ࡞ OS ᑐᛂࡋ࡚࠾ࡾ㸪グ㏙ࡢᐜ᫆ࡉ࠸࠺ࡁ. ࡢ࠸࠺ၥ㢟ព㆑ࢆ㉳Ⅼࡋ࡚㸪ࣥࢱࣛࢡࢸࣈ(ே. ࡞≉ᛶࡶවࡡഛ࠼࡚࠸ࡿࡇࡽ㸪ࡇࢀࡲ࡛ከࡃࡢ⏝. 㛫ࢥࣥࣆ࣮ࣗࢱࡢ᪉ྥⓗ㐍ࡵࡽࢀࡿྍどࣉࣟࢭ. ⪅ࡼࡗ࡚㠀ᖖከᒱரࡿసရࡀసࡽࢀ࡚࠸ࡿ㸬2019 ᖺ. ࢫ࠾࠸࡚㸪ྍどࡋࡓ⤖ᯝ (࠼ࡤ⏬ീ➼) ࡀࡢࡼ࠺. 2 ᭶⌧ᅾ᭱᪂ࡢࣂ࣮ࢪࣙࣥࡣ 3㸬4(2018 ᖺ 7 ᭶࣮ࣜࣜࢫ)࡛. ㄆ▱ࡉࢀࡿࡢ࠸࠺ၥ㢟㸪ྍどࣉࣟࢭࢫ⮬యࡢ. ࠶ࡿ㸬ᑦ㸪Processing ࡣ㸪Windows ➼୍⯡ⓗ࡞ OS ୖ࡛ື. ሗᵓ㐀ࡼࡗ࡚ࣉࣟࢭࢫࢆ༙⮬ື࡛ࡁࡿ࠸࠺. సࡍࡿ Processing ࢯࣇࢺ࢙࢘ࡢ㸪p5㸬js㸪Processing for. ၥ㢟ࡢ 2 ࡘࢆ⪃ᐹ (ゎỴ) ࡋࡼ࠺ヨࡳࡿࡶࡢ࡛࠶ࡿ㸬ྍ. Android㸪processing㸬py ࡢࡁࡃศࡅ࡚ 3 ✀㢮ࡢὴ⏕ᐇ. どࡽศࡿࡇࡣᑐ㇟౫Ꮡ࡛࠶ࡾ㸪ྍどࢆᚲせࡋ. ࡀᏑᅾࡍࡿ㸬Processing ࡢࡑࡢࡢࡁ࡞≉㛗ࡋ࡚㸪ࢻ࢟. ࡞࠸ࡶࡢࡶ࠶ࡿࡔࡅ࡛࡞ࡃ㸪ゎ㔘ࡣಶࠎே௵ࡏࡿࡁ. ࣓ࣗࣥࢺࡢ㇏ᐩࡉࡶᣲࡆࡽࢀࡿ㸬. ᣦࡉࢀࡿሙྜࡶ࠶ࡿࡇ➼ࡽ㸪 ࠕࠗྍどࡽఱࡀศ ࡿࡢ࠘࠸࠺ၥࡣ㸪ఱࡀศࡿ࠸࠺௨እ⟅࠼ࡽ. 3.3 ධ㜵ᚚຠᯝࡢྍどἲ. ࢀࡿࡇࡣ࡞࠸ࠖᮏㄽᩥ࡛ⓑᒣࡣ㏙࡚࠸ࡿ㸬 ᚋࡢㄢ. 1) ࢧࣂ࣮࢟ࣝࢳ࢙࣮ࣥᨷᧁࢩࢼࣜ࢜. 㢟ࡋ࡚ࡣ㸪ᩥ୰࡛⤂ࡋࡓᵝࠎ࡞ྍどᡭἲࡸ࢚࣮ࢪ࢙. ⬤ᙅᛶࢆ⏝ࡋࡓᨷᧁᑐࡍࡿ TOMOYO Linux ࡢຠᯝ. ࣥࢺࡢᒎ㛤ࡣ◊✲ࡀጞࡲࡗࡓࡤࡾࡢࡶࡢࡶከࡃ㸪ྍど. ࢆྍどࡍࡿ࠶ࡓࡾ㸪ᨷᧁࡢ㐍ᤖẁ㝵ࢆᐃ⩏ࡍࡿࡓࡵ㸪. ◊✲ࡢⓎᒎࡢࡓࡵ᭦ከࡃࡢ◊✲ࡀᮃࡲࢀࡿࡋ࡚࠸ࡿ㸬. ࢧࣂ࣮࢟ࣝࢳ࢙࣮ࣥࢆ࣮࣋ࢫࡋ࡚௬ⓗ࡞⬣ጾࣔࢹࣝ. 3. ᥦᡭἲ. ࢆసᡂࡍࡿ㸬ࢧࣂ࣮࢟ࣝࢳ࢙࣮ࣥࡣ㸪⤌⧊ࡀᶆⓗᆺᨷ ᧁࡢ⬣ጾഛ࠼ࡿࡓࡵᨷᧁ⪅ࡢ⪃࠼᪉ࢆศᯒࡋ࡚ከᒙ㜵. ᮏ❶࡛ࡣ㸪 ᥦᡭἲࡢᴫせྍど⏝ࡍࡿ Processing. ᚚࡢᴫᛕࢆྲྀࡾධࢀ࡚㝵ᒙࡋࡓࡶࡢ࡛㸪Lockheed Martin. ゝㄒࡘ࠸࡚㏙㸪ලయⓗ࡞ྍどᡭἲࡘ࠸࡚ヲ⣽ㄝ. ♫ࡢ Mike Cleppert ࡼࡾᥦၐࡉࢀࡓࣇ࣮࣒࣮ࣞ࣡ࢡ࡛࠶. ᫂ࡍࡿ㸬. ࡿ[7]㸬ࢧࣂ࣮࢟ࣝࢳ࢙࣮ࣥࡢྛ㝵ᒙࡣࡢ⤌⧊࡛ࡶࡃ ྠࡌᵓᡂ୍࡛ᚊỴࡲࡗ࡚࠸ࡿࡣゝ࠼࡞࠸ࡀ㸪ᴫࡡ 7㹼8. 3.1 ᥦᡭἲࡢᴫせ ᮏ◊✲࡛ࡣ TOMOYO Linux ࡢไᚚ࣮ࣔࢻࢆ disabled(↓ ຠ)ࡢ≧ែタᐃࡋࡓሙྜ㸪enforcing(ᙉไ)ࡢ≧ែタᐃ. ࡢẁ㝵࡛ᵓᡂࡉࢀ࡚࠸ࡿ㸬 ᮏ◊✲࡛ࡣ㸪࣐ࢡࢽ࣭࢝ࢿࢵࢺ࣮࣡ࢡࢫ♫ࡢࢧࣂ࣮࢟ ࣝࢳ࢙࣮ࣥ[8]ࢆཧ⪃㸪ୗグࡢᨷᧁࢩࢼࣜ࢜ࢆタᐃࡍࡿ㸬. ࡋࡓሙྜࡢࡑࢀࡒࢀᑐࡋ࡚ᨷᧁࢆ⾜࠸㸪ࡑࢀࡒࢀࡢሙྜ ࠾࠸࡚ᐇ⾜ྍ⬟࡞ࢥ࣐ࣥࢻࢆẚ㍑ࡋࡓ⤖ᯝࢆࣉࣟࢢ࣑ࣛ ࣥࢢゝㄒࡢ୍ࡘ࡛ࢢࣛࣇࢵࢡᶵ⬟ὀຊࡋࡓ Processing ࢆ⏝࠸࡚ྍどࡍࡿ㸬 TOMOYO Linux ࡢᙉไࢡࢭࢫไᚚᶵ⬟ࢆ↓ຠࡍࡿ ሙྜ(disabled)㸪᭷ຠࡍࡿሙྜ(enforcing)ࡢሙྜ࠾࠸ ࡚㸪ᐇ⾜ྍ⬟࡛࠶ࡗࡓࢥ࣐ࣥࢻ/ᐇ⾜ྍ⬟࡛࠶ࡗࡓࢥ࣐ࣥ ࢻࢆලయⓗㄪࡓୖ࡛㸪 TOMOYO Linux ࡢᙉไࢡࢭ. ⓒ 2019 Information Processing Society of Japan. ձ ഄᐹ㸸ࢿࢵࢺ࣮࣡ࢡࢫ࣭࢟ࣕࣥ⬤ᙅᛶሗ㞟 ⿕ᐖ➃ᮎ (ᅇᐇ㦂ࢆ⾜࠺➃ᮎ)ྠ୍ࡢࢿࢵࢺ࣮࣡ࢡ ෆ࠶ࡿูࡢ➃ᮎࡽ㸪ࢿࢵࢺ࣮࣡ࢡࢫ࢟ࣕࣥ➼ࢆ⾜࠺ࡇ ࡼࡾ㸪➃ᮎࡢࢩࢫࢸ࣒ሗ࡞ࢆධᡭࡍࡿ㸬 ղ ࢹࣜࣂࣜ㸸USB ᥋⥆ࡼࡿṇࣉࣟࢢ࣒ࣛࡢ㏦ ⬤ᙅᛶࢆ⏝ࡋࡓᨷᧁࣉࣟࢢࣛࢆ USB ᥋⥆࡛㸪 ᶆⓗ ࡍࡿ➃ᮎෆタ⨨ࡍࡿ㸬. 3.
(4) Vol.2019-DPS-178 No.9 Vol.2019-CSEC-84 No.9 2019/3/4. ሗฎ⌮Ꮫ◊✲ሗ࿌ IPSJ SIG Technical Report ճ ࢚ࢡࢫࣉࣟࢺ㸸ῧࣇࣝࡢᐇ⾜ or ⬤ᙅᛶࢆ✺. ࡇࡢ࡞࠸ࡼ࠺ࣟࢢࡢ๐㝖ࢆ⾜࠸㸪ᚋࡢධഛ࠼࡚. ࠸ࡓᨷᧁ. ࣥࢳ࢘ࣝࢫࢯࣇࢺ(ᮏᐇ㦂ࡢ⎔ቃ࡛ࡣ Clam Antivirus ࡀ. ࣮࢝ࢿࣝࡢ⬤ᙅᛶࢆ⏝ࡋࡓᨷᧁࣉࣟࢢ࣒ࣛࢆᐇ⾜ࡍ. ࣥࢫࢺ࣮ࣝ῭) ࡶ๐㝖ࡍࡿᐃࡍࡿ㸬ࡲࡓ㸪ᨷᧁ⪅ࡀ┠. ࡿ㸬 ᐇ⾜కࡗ࡚㸪 ࣮ࣟ࢝ࣝᶒ㝈᪼᱁࣓ࣔࣜࡢ㒊ศⓗ. ⓗࡍࡿࣇࣝࡣ/etc/shadow ࠾ࡼࡧ /etc/passwd ࡢ 2 ࡘ. ࡞◚ቯࡀྠ⾜ࢃࢀࡿ㸬. ࡛࠶ࡿࡍࡿ㸬ഄᐹ࣭ࢹࣜࣂ࣭࢚ࣜࢡࢫࣉࣟࢺ࣭࣮ࣟ࢝. մ ࣮ࣟ࢝ࣝ⎔ቃࡢᐖ㸸࣮ࣟ࢝ࣝ⎔ቃࡢሗ㞟 or ࣟ. ࣝᶒ㝈ࡢᐖຍ࠼࡚㸪Ọ⥆ᛶࡢ☜❧┠ⓗࡢ㐩ᡂࡶ⾜ࢃ. ࣮࢝ࣝ⎔ቃࡢᶒ㝈᪼᱁. ࢀࡓ≧ែ࡛࠶ࡿࡓࡵ㸪ࣂ࣮ࡢ⾲♧ࡣ 60%ࡍࡿ㸬. ճ࡛⾜ࢃࢀࡓᨷᧁకࡗ࡚࣮ࣟ࢝ࣝᶒ㝈᪼᱁ࢆ⾜࠺ࡇ ࡀ࡛ࡁࡓࡓࡵ㸪ᵝࠎ࡞ࢥ࣐ࣥࢻࢆ㥑ࡋ࡚࣮ࣟ࢝ࣝ⎔ቃ. ࠙ࣉࣟࢢࣞࢫࣂ࣮ࡢⰍࡢ⃰ᗘࠚ ᨷᧁࡢ㐍ᤖࡀ᭱⤊┠ⓗ (┠ⓗࡢ㐩ᡂ) ࡢࡃࡽ࠸㏆࠸. ෆ㒊ࡢࣇࣝࢆཧ↷ࡍࡿ➼ࡋ࡚ྍ⬟࡞㝈ࡾࡢሗࢆ㞟ࡵ ࡿ㸬 յ Ọ⥆ᛶࡢ☜❧㸸ࣥࢳ࢘ࣝࢫࡢ↓ຠ. ࢆ♧ࡍࡓࡵࣂ࣮ࡢⰍࢆ⏝ࡍࡿ㸬ࣂ࣮ࡢⰍࡀⷧ࠸┠ or. ࣟࢢࡢ. ⓗࡽ㐲ࡃ㸪⃰ࡃ࡞ࡿ┠ⓗ㐩ᡂ㏆࠸). ๐㝖 ᚋࢆᐃࡋ࡚ࣥࢳ࢘ࣝࢫࢯࣇࢺࡀ㉮ࡗ࡚࠸ࢀࡤ. ࠙ྍどᅗ୰⾲♧ࡍࡿグྕࡢᐃ⩏ࣉࣟࢢࣞࢫࣂ࣮࠾ࡼ. ↓ຠࡋ㸪ࡑࡢ㝿ࣇ࢛࣮࢘ࣝ➼ࡢᶵ⬟ࡶ࢜ࣇࡋ. ࡧࡑࢀࡒࢀࡢグྕࡢ㓄ⰍࡢỴᐃࠚ. ࡚࠾ࡃ㸬ࡲࡓ㸪ࣟࢢࡢ๐㝖ࡶࡇࡢẁ㝵࡛⾜ࢃࢀࡿ㸬. ྍどᅗ୰⾲♧ࡍࡿグྕࡣ㸪ࢩࣥࣉࣝ࡞ྍどᅗࢆస. ն ┠ⓗࡢ㐩ᡂ㸸ࣇࣝ/ࢹ࣮ࢱᦤྲྀ࣭እ㒊ࡢ࣓࣮ࣝ㏦. ᡂࡍࡿ┠ⓗ࡛ࠐࡢࡳࢆ࠸㸪ࠐࡢ 1 ಶศࡣࡑࡢࡲࡲࢥ࣐ࣥ. ಙ. ࢻ 1 ࡘࢆ⾲⌧ࡍࡿᐃ⩏ࡍࡿ㸬ࡲࡓ㸪␗࡞ࡿ 4 ࡘࡢࢹࣞ. ┠ⓗࡢሗࢆ᥈ࡋฟࡋ㸪እ㒊ᣢࡕฟࡍ㸬. ࢡࢺࣜࡽࢥ࣐ࣥࢻࢆ㑅ࡧฟࡋ࡚ㄪᰝࡋ࡚࠸ࡿࡓࡵ㸪ࢹ ࣞࢡࢺࣜࡀ␗࡞ࡿࢥ࣐ࣥࢻࡣ␗࡞ࡿⰍ࡛⾲⌧ࡍࡿᚲせࡀ࠶. 2) ྍどᅗ୰⾲♧ࡍࡿࣉࣟࢢࣞࢫࣂ࣮ࡢᐃ⩏. ࡾ㸪ࣉࣟࢢࣞࢫࣂ࣮ࡢⰍᙬ㛵ࡋ࡚ࡶ㐍ᤖẁ㝵ࡀ㐍ࡴ. ᮏ◊✲࡛ࡣ㸪ᨷᧁࡢ㐍ᤖẁ㝵῝้ᗘࢆ♧ࡍࣉࣟࢢࣞࢫ. Ⰽࢆ⃰ࡃࡍࡿࡇࡋ㸪ୗグࡢࡼ࠺ⰍᙬࢆỴᐃࡋࡓ㸬. ࣂ࣮ࢆసᡂࡍࡿ㸬 ≉㸪ࢿࢵࢺ࣮࣡ࢡෆ㒊ࡢືࡁᅇࡾࡸ. ⰍᙬࡢỴᐃ࠶ࡓࡗ࡚ࡣ㸪ㄆ▱⛉ᏛࡸⰍᙬࢆᢅ࠺Ꮫၥࡢ. C&C ࢧ࣮ࣂࡢ᥋⥆➼ࡢẁ㝵ࢆྵࡴ㸪ᐇ㝿ࡢᨷᧁࢆᶍᨃࡋ. ほⅬࡽ୍┠࡛㆑ูࡋࡸࡍ࠸Ⰽࡢ⤌ࡳྜࢃࡏࢆ㑅ࡪࡓࡵ㸪. ࡓࢧࣂ࣮࢟ࣝࢳ࢙࣮ࣥࢆ࣮࣋ࢫࡋ࡚㸪ࡑࡢ࠺ࡕࡢ࠸ࡃ. ♫࠾ࡅࡿ࠸᫆࠸Ⰽᙬ⎔ቃࢆ┠ᣦࡍ≉ᐃ㠀Ⴀάືἲ. ࡘࡀ㐩ᡂࡉࢀࡓࢆ௨ࡗ࡚ᨷᧁࡢ㐍ᤖẁ㝵(%)ࢆᐃ⩏ࡍࡿ. ே࣮࢝ࣛࣘࢽࣂ࣮ࢧࣝࢹࢨࣥᶵᵓࡸ㛵ಀศ㔝ࡢ◊✲⪅ࡽ. ࡇࡍࡿ㸬ᶍᨃᨷᧁ࠾ࡅࡿࢧࣂ࣮࢟ࣝࢳ࢙࣮ࣥࡣ㸪. ࡛ᵓᡂࡉࢀࡿ࣮࢝ࣛࣘࢽࣂ࣮ࢧࣝࢹࢨࣥ㓄Ⰽࢭࢵࢺ〇స. ഄᐹ࣭ࢹࣜࣂ࣭࢚ࣜࢡࢫࣉࣟࢺ࣭ࣥࢫࢺ࣮࣭ࣝC&C࣭. ጤဨࡀⓎ⾜ࡋ࡚࠸ࡿ࣮࢝ࣛࣘࢽࣂ࣮ࢧࣝࢹࢨࣥ᥎ዡ㓄. ࣮ࣟ࢝ࣝ⎔ቃࡢᐖ࣭ෆ㒊ഄᐹ࣭ឤᰁᣑ࣭Ọ⥆ᛶ☜❧࣭. Ⰽࢭࢵࢺ࢞ࢻࣈࢵࢡ[9]ᥖ㍕ࡉࢀ࡚࠸ࡿ༳ๅ⏝ࡢぢࡸ. ┠ⓗᐇ⾜ࡢィ 10 ẁ㝵ࡢ㝵ᒙࢆ᭷ࡋ࡚࠸ࡿ㸬. ࡍ࠸㓄Ⰽ㛵ࡍࡿ࣮࣌ࢪࢆཧ⪃ࡋ࡚࠸ࡿ㸬 . ࠙ࣉࣟࢢࣞࢫࣂ࣮ࡢᐃ⩏ࠚ ࣭ࣉࣟࢢࣞࢫࣂ࣮1 : ഄᐹ࣭ࢹࣜࣂࣜࡀ⾜ࢃࢀࡓ≧ែ㸬ᅇ ࡢᐇ㦂᳨࡛ウࡋࡓ௬ⓗ࡞⬣ጾࣔࢹ࡛ࣝࡣ㸪PoC ࣉࣟࢢࣛ ࣒ exploit㸬c ࡢࢹࣜࣂࣜࡣ USB ࡛⾜ࢃࢀࡓࡶࡢࡍࡿ㸬. 4. ᶍᨃᨷᧁྍどᐇ㦂 ᮏ❶࡛ࡣ㸪 ᶍᨃᨷᧁࡑࢀࢆཷࡅ࡚ᐇࡋࡓྍどᐇ 㦂㛵ࡋ࡚ヲ⣽㏙ࡿ㸬. ࢧࣂ࣮࢟ࣝࢳ࢙࣮ࣥయࡢẁ㝵ᩘ 10 ẁ㝵ࡢ࠺ࡕ㸪ഄᐹ ࢹࣜࣂࣜࡀ⾜ࢃࢀࡓࡓࡵ㸪ࣂ࣮ࡢ⾲♧ࡣ 20㸣ࡍࡿ㸬. 4.1 ᐇ㦂ࡢᴫせ ᮏᐇ㦂࡛ࡣ㸪ࡣࡌࡵ㸪TOMOYO Linux ࢆࣥࢫࢺ࣮ࣝ. ࣭ࣉࣟࢢࣞࢫࣂ࣮2 : ࢚ࢡࢫࣉࣟࢺ࣭࣮ࣟ࢝ࣝ⎔ቃࡢᐖ. ࡋࡓ௬࣐ࢩࣥᑐࡋ࡚㸪࣮ࣟ࢝ࣝᶒ㝈᪼᱁࣓ࣔࣜ◚ቯ. ࡀ⾜ࢃࢀࡓ≧ែ㸬ᅇࡢᐇ㦂࡛ࡣ㸪PoC ࣉࣟࢢ࣒ࣛ exploit㸬. ࢆྠ⾜࠺ᶍᨃᨷᧁࢆ㸪ᙉไࢡࢭࢫไᚚࡀ↓ຠ᭷. c ࡀᐇ⾜ࡉࢀ࡚㒊ศⓗ࡞࣓ࣔࣜ◚ቯ࣮ࣟ࢝ࣝᶒ㝈᪼᱁. ຠศࡅ࡚ᐇࡍࡿ㸬ࡑࡢ㝿ࡣ㸪ணࡵỴࡵࡓ 132 ಶࡢ. ࡀ⾜ࢃࢀࡓ┤ᚋࡢ≧ែ㸬ࢧࣂ࣮࢟ࣝࢳ࢙࣮ࣥయࡢẁ㝵. ࢥ࣐ࣥࢻࢆࡑࢀࡒࢀࡢሙྜᐇ⾜ࡋ㸪TOMOYO Linux ࡢᙉ. ᩘ 10 ẁ㝵ࡢ࠺ࡕ㸪ഄᐹࢹࣜࣂࣜຍ࠼࢚ࢡࢫࣉࣟࢺ. ไࢡࢭࢫไᚚᶵ⬟᭷ຠᐇ⾜ࢆ㜵ࡄࡇࡀ࡛ࡁࡓࢥ࣐. ࣮ࣟ࢝ࣝᶒ㝈᪼᱁ࡶ⾜ࢃࢀࡓ≧ែࡢࡓࡵ㸪ࣂ࣮ࡢ⾲♧ࡣ. ࣥࢻᨷᧁᚋࡶᐇ⾜ࢆ㜵Ṇ࡛ࡁ࡞ࡗࡓࢥ࣐ࣥࢻ(࣓ࣔࣜ. 40%ࡍࡿ㸬. ◚ቯᙳ㡪ࢆཷࡅᐇ⾜࡛ࡁ࡞ࡗࡓࢥ࣐ࣥࢻࡶྵࡵࡿ) ศ㢮ࡍࡿ㸬ࡑࡢᚋ㸪ศ㢮ࡋࡓ⤖ᯝࢆ㸪ᥦᡭἲࢆ⏝࠸࡚ᡭ. ࣭ࣉࣟࢢࣞࢫࣂ࣮3 : Ọ⥆ᛶࡢ☜❧࣭┠ⓗࡢ㐩ᡂࡀ⾜ࢃࢀࡓ ≧ែ㸬ᅇࡢ⬣ጾࣔࢹ࡛ࣝࡣ㸪 ᨷᧁ⪅ࡀධࡢ㊧ࢆṧࡍ. ⓒ 2019 Information Processing Society of Japan. ື࡛ྍどࡍࡿ㸬 ᑦ㸪ᮏᐇ㦂࡛ᐇ⾜ᑐ㇟ࡍࡿࢥ࣐ࣥࢻࡣ㸪 ࢩࢫࢸ࣒⟶⌮. 4.
(5) Vol.2019-DPS-178 No.9 Vol.2019-CSEC-84 No.9 2019/3/4. ሗฎ⌮Ꮫ◊✲ሗ࿌ IPSJ SIG Technical Report ⪅ࡀ⏝ࡍࡿᇶᮏⓗ࡞ࢥ࣐ࣥࢻࡀ㓄⨨ࡉࢀ࡚࠸ࡿ/sbin . ᅗ 1 ㄪᰝᑐ㇟ࡢࢥ࣐ࣥࢻ୍ぴ. /usr/sbin㸪ࡑࡢ㸪ᇶᮏⓗ࡞ࢥ࣐ࣥࢻࡀ㓄⨨ࡉࢀ࡚࠸ࡿ/bin. Figure 1 list of the selected commands. /usr/bin ࡢ 4 ࡘࡢࢹࣞࢡࢺࣜࡽ⏝㢖ᗘࡀ㧗࠸⪃ ࠼ࡽࢀࡿࢥ࣐ࣥࢻࢆணࡵ 33 ಶࡎࡘ㑅ࡧ㸪ᐇ⾜ᑐ㇟ࡋࡓ㸬. 4.3 ᨷᧁᐇ㦂ࡢ⤖ᯝ. 4.2 ྍどᑐ㇟ࡍࡿᨷᧁ. ࡢሙྜ࠾࠸࡚㸪 TOMOYO Linux ࡢᙉไࢡࢭࢫไᚚᶵ. ᶍᨃᨷᧁࡢ㐍ᤖ≧ἣࡀ 20%㸪 40%㸪 60%␗࡞ࡿ 3 ࡘ ᮏ◊✲࡛ࡣ㸪ᶍᨃᨷᧁࢩࢼࣜ࢜ࡢෆ࡛㸪 ࠕእ㒊ࡽࢩࢫࢸ. ⬟ ࡀ ↓ ຠ ࡞ ሙ ྜ (disabled ࣔ ࣮ ࢻ ) ᭷ ຠ ࡛ ࠶ ࡿ ≧ ែ. ࣒ධᚋ㸪ᨷᧁ⪅ࡀ⟶⌮⪅ࡢ࣮ࣟ࢝ࣝᶒ㝈᪼᱁࣮࢝. (enforcing ࣮ࣔࢻ)࡛࠶ࡿࡑࢀࡒࢀᑐࡋ࡚ᐇ㦂 1㹼ᐇ㦂. ࢿࣝࡢ㒊ศⓗ࡞࣓ࣔࣜ◚ቯࡢ 2 ࡘࢆྠ⾜࠺ PoC ࣉࣟࢢ. 3 ࢆ⾜ࡗࡓ㸬. ࣒ࣛࢆࢩࢫࢸ࣒ෆ㒊タ⨨ࡋ㸪ྠࣉࣟࢢ࣒ࣛࢆᐇ⾜ࡋ࡚⟶. ᐇ㦂 1 ࡛ࡣ㸪ᶍᨃᨷᧁࡢ㐍ᤖ≧ἣࡀ 20%࡞ࡗ࡚࠾ࡾ㸪. ⌮⪅࡞ࡾෆ㒊ࡢ◚ቯάືࢆヨࡳࡿࠖࢆᑐ㇟ྍどࢆヨ. ࡍ࡞ࢃࡕྠ୍ࢿࢵࢺ࣮࣡ࢡෆࡢ➃ᮎ (ᮏᐇ㦂࡛ࡣ Kali. ࡳࡿ㸬ࡑࡢࡓࡵ㸪CVE2017-1000111 ࠾ࡼࡧ CVE2017-. Linux ࢆ⏝)ࡽᐇ㦂ᑐ㇟ࡢ➃ᮎᑐࡍࡿഄᐹᨷᧁ⏝. 1000112 ᑐᛂࡍࡿ࣮ࣟ࢝ࣝᶒ㝈᪼᱁࣭㒊ศⓗ࡞࣓ࣔࣜ◚. ࠸ࡿ PoC ࣉࣟࢢ࣒ࣛࡢࢹࣜࣂࣜ(USB ࢹࣂࢫ⤒⏤) ࡀ⾜. ቯࡢྍ⬟ᛶࡀ࠶ࡿ Linux ࣮࢝ࢿࣝෆࡢࣃࢣࢵࢺࢯࢣࢵࢺࡢ. ࢃࢀࡓ┤ᚋ࡛࠶ࡿ㸬 ᐇ㦂 2 ࡣ㸪 ᶍᨃᨷᧁࡀ㐍ࡳ㸪 PoC ࣉ. ᐇᏑᅾࡋ࡚࠸ࡿ⬤ᙅᛶࢆ⏝ࡋࡓᨷᧁࢆ⾜࠺ࣉࣟࢢࣛ. ࣟࢢ࣒ࣛࡀᐇ㦂ᑐ㇟ࡢࢩࢫࢸ࣒≧࡛ᐇ⾜ࡉࢀࡿࡇࡼࡗ. ࣒ࢆ⏝ࡍࡿ㸬ྠࣉࣟࢢ࣒ࣛࡣࡑࡢᐇ⾜ྠ࣮ࣟ࢝ࣝ. ࡚ᨷᧁ⪅ࡼࡿ㒊ศⓗ࡞࣓ࣔࣜ◚ቯᶒ㝈᪼᱁ࡀ⾜ࢃࢀࡓ. ᶒ㝈᪼᱁࣓ࣔࣜ◚ቯࡀ⾜ࢃࢀࡿࣉࣟࢢ࣒ࣛ࡞ࡗ࡚࠾ࡾ. ┤ᚋࡢ≧ែ࡛࠶ࡾ㸪 ᐇ㦂 3 ࡛ࡣ㸪 ᨷᧁ⪅ࡀ⮬㌟ࡢࢩࢫࢸ. [10]㸪2017 ᖺ 8 ᭶ 13 ᪥ Exploit Database Ⓩ㘓ࡉࢀࡓ. ࣒ධࢆ♧ࡍ㊧ࢆ๐㝖ࡋ࡚ᚋࡢධࢆ⾜࠸ࡸࡍࡃࡋࡓ. KASLR / SMEP (Linux Kernel < 4㸬4㸬0-83 / < 4㸬8㸬0-58. ୖ࡛┠ⓗࡍࡿࣇࣝࢆ᥈⣴ࡍࡿẁ㝵࡛࠶ࡿ㸬 ᐇ㦂 1㹼. Ubuntu14㸬04 / 16㸬04) ࡛ Andrey Konovalov ࡼࡗ࡚๓㏙. ᐇ㦂 3 ࡢࡑࢀࡒࢀࡢሙྜ࠾࠸࡚㸪 TOMOYO Linux ࡢࣔ. ࡢ⬤ᙅᛶࢆ⌧࡛ࡁࡿࡼ࠺ࡍࡿࡓࡵసᡂࡉࢀࡓ Proof. ࣮ࢻࡀ disabled enforcing ศࡅ࡚ᅗ 1 ิᣲࡋࡓྜィ. of Concept(PoC)ࡢ C ゝㄒࣉࣟࢢ࣒ࣛ 43418㸬c ࡛࠶ࡿ[11]㸬. 132 ಶࡢࢥ࣐ࣥࢻࡀᐇ⾜ྍ⬟࡛࠶ࡿྍ⬟࡛࠶ࡿࢆㄪ. ᮏᐇ㦂࡛ࡣ TOMOYO Linux ࡀணࡵࣥࢫࢺ࣮ࣝࡉࢀ࡚. ᰝࡋࡓ㸬. ࠸ࡿ Ubuntu 14㸬04 ᑐࡋ࡚๓㏙ࡢࣉࣟࢢ࣒ࣛࢆ⏝࠸ࡓᨷ. ᐇ㦂 1㹼3 ࡛ㄪᰝࢆ⾜ࡗࡓ⤖ᯝ㸪ᨷᧁ⪅ࡼࡿ࣮ࣟ࢝ࣝ. ᧁࢆᐇࡍࡿࡇࡼࡾ㸪TOMOYO Linux ࡢᙉไࢡࢭ. ⎔ቃࡢධࢆཷࡅࡓሙྜ࡛࠶ࡗ࡚ࡶ㸪 TOMOYO Linux. ࢫไᚚᶵ⬟ࡀ↓ຠࡢሙྜ(disabled ࣮ࣔࢻ )᭷ ຠࡢሙྜ. ࡼࡿᙉไࢡࢭࢫไᚚᶵ⬟ࡀ᭷ຠ࡞ࡗ࡚࠸ࡿ≧ែ࡛ࡣ㸪. (enforcing ࣮ࣔࢻ)࠾࠸࡚㸪ᅗ 1 ♧ࡍࡼ࠺ணࡵㄪᰝᑐ. ࢇࡢࢥ࣐ࣥࢻࢆᨷᧁ⪅ࡽᐇ⾜ࡉࢀ࡞࠸ࡼ࠺Ᏺࡿ. ㇟ࡋ࡚㑅ࢇࡔ 132 ಶࡢࢥ࣐ࣥࢻࢆࡑࢀࡒࢀࡢሙྜ࡛ᐇ⾜. ࡇࡀ࡛ࡁࡓࡇࡀศࡗࡓ㸬ࡲࡓ㸪 ᨷᧁࡢ㐍ᤖẁ㝵ࡀ 40%. ࡋ㸪ᐇ㝿ᐇ⾜ࡀྍ⬟࡛࠶ࡗࡓࢥ࣐ࣥࢻᩘࡢᕪࢆẚ㍑ࡍࡿ. ࡽ 60%㐍⾜ࡋࡓሙྜ࡛࠶ࡗ࡚ࡶ㸪 TOMOYO Linux ࡀ. ࡇ࡛ TOMOYO Linux ࡢຠᯝࢆྍどࡍࡿࡇࢆヨࡳࡿ㸬. ↓ຠ࣭᭷ຠࡢ࠸ࡎࢀࡢ≧ែ࠾࠸࡚ࡶᨷᧁ⪅ࡀᐇ⾜࡛ࡁࡿ ࢥ࣐ࣥࢻᩘኚࡣ࡞ࡗࡓ㸬⾲㸰ࡣ㸪 ᐇ㦂 1ࠥ3 ࡛ᚓࡓ ㄪᰝ⤖ᯝࡢ୍ぴࢆᩚ⌮ࡋ࡚ࡲࡵࡓࡶࡢ࡛࠶ࡿ㸬 ᐇ㦂 1 ࡢሙྜ࡛ࡣ㸪ᨷᧁࡢ㐍ᤖẁ㝵ࡀᮏ◊✲ࡢᐃ⩏࠾ ࠸࡚ 20%࡛࠶ࡾ㸪ࡇࡢⅬ࡛⾜ࢃࢀࡓᨷᧁࡣഄᐹᨷᧁ ⏝ ࡍ ࡿ PoC ࣉ ࣟ ࢢ ࣛ ࣒ ࡢ ࢹ ࣜ ࣂ ࣜ ࡢ ࡳ ࡢ ࡓ ࡵ 㸪 TOMOYO Linux ࡀ↓ຠ࡛࠶ࡿሙྜ࣭᭷ຠ࡛࠶ࡿሙྜࡢ࠸ࡎ ࢀ࡛࠶ࡗ࡚ࡶㄪᰝᑐ㇟ࡢࢥ࣐ࣥࢻ(ᐇ⾜ࣇࣝ) 132 ಶࡣ ࡚ᐇ⾜ࡍࡿࡇࡀྍ⬟࡛࠶ࡗࡓ㸬ࡲࡓ㸪ྠࡌ 20%ࡢ㐍ᤖ ẁ㝵࡛࠶ࡿሙྜࡣ TOMOYO Linux ࡢᙉไࢡࢭࢫไᚚᶵ ⬟ࡀ᭷ຠ࡛࠶ࡗ࡚ࡶ㸪132 ಶࡢࢥ࣐ࣥࢻࡀ࡚ᐇ⾜ྍ⬟࡛ ࠶ࡿࡇኚࡣ࡞ࡗࡓ㸬 ᨷᧁࡢ㐍ᤖẁ㝵ࡀ 40%ࡢሙྜ㸪 PoC ࣉࣟࢢ࣒ࣛࡼࡿ࢚ࢡࢫࣉࣟࢺ࣮ࣟ࢝ࣝ⎔ቃࡢ ᐖࡀ⾜ࢃࢀࡓࡓࡵ㒊ศⓗ࡞࣓ࣔࣜ◚ቯࡢᙳ㡪ࢆཷࡅ࡚ 6 ಶ ࡢࢥ࣐ࣥࢻࡀᐇ⾜ྍ⬟࡞ࡗࡓ⪃࠼ࡽࢀࡿࡀ㸪 TOMOYO Linux ࡀ↓ຠࡢሙྜ࡛ࡣࡑࢀࡽࡢࢥ࣐ࣥࢻࢆ㝖 ࡃྜィ 126 ಶࡀṇᖖᐇ⾜࡛ࡁࡓ㸬୍᪉࡛㸪TOMOYO Linux ࡢᙉไࢡࢭࢫไᚚᶵ⬟ࡀ᭷ຠࡢሙྜࡣ㸪࣓ࣔࣜ◚ቯࢆཷ ࡅࡓᙳ㡪࡛ṇᖖᐇ⾜࡛ࡁ࡞ࡗࡓ⪃࠼ࡽࢀࡿ 3 ಶࡢࢥ. ⓒ 2019 Information Processing Society of Japan. 5.
(6) Vol.2019-DPS-178 No.9 Vol.2019-CSEC-84 No.9 2019/3/4. ሗฎ⌮Ꮫ◊✲ሗ࿌ IPSJ SIG Technical Report ࣐ࣥࢻࢆ㝖ࡃ 129 ಶࡢࢥ࣐ࣥࢻࡀ TOMOYO Linux ࡢᙉไ. Figure 2 Layout of the visualization image. ࢡࢭࢫไᚚᶵ⬟ࡼࡗ࡚ᨷᧁ⪅ࡀᐇ⾜࡛ࡁ࡞࠸ࡼ࠺ಖㆤ ࡍࡿࡇࡀ࡛ࡁࡓࡇࡀ☜ㄆ࡛ࡁࡓ㸬⥆࠸࡚ᨷᧁࡢ㐍ᤖẁ. ᐇ⾜ྍ⬟࡞ࢥ࣐ࣥࢻྍ⬟࡞ࢥ࣐ࣥࢻ㛵ࡋ࡚ࡣ㸪ィ. 㝵ࡀ 60%ࡢሙྜࡣࣟࢢࡢ๐㝖ࡸ┠ⓗࡢࣇࣝࡢ᧯స. 132 ࡢࢥ࣐ࣥࢻࢆࡑࢀࡒࢀᐇ㦂 1 ࡽᐇ㦂 3 ࠾࠸࡚ᐇ⾜. ࡞ࡀ⾜ࢃࢀࡓ≧ែ࡛࠶ࡿࡀ㸪TOMOYO Linux ࡢᙉไࢡ. ࡋ࡚ㄪࡿࡇࡼࡗ࡚ᚓࡽࢀࡓ ᐇ㦂 1㹼3 ࡢᐇ㦂⤖ᯝࡢ. ࢭࢫไᚚᶵ⬟ࡀ↓ຠ࣭᭷ຠࡢ࠸ࡎࢀ࡛࠶ࡗ࡚ࡶᐇ⾜ྍ⬟࡞. ⾲ 2 ᇶ࡙࠸࡚࠸ࡿ㸬. ࢥ࣐ࣥࢻᩘࡣኚࡀ࡞ࡃ㸪ᨷᧁࡢ㐍ᤖẁ㝵ࡀ 40%ࡢ. ୖグ᳨࡛ウࡋࡓࣞ࢘ࢺ࠾ࡼࡧᐇ㦂⤖ᯝࢆグࡋࡓ⾲ ἢࡗ࡚㸪╔Ⰽ㒊ศ = ᐇ⾜ྍ⬟࡞ࢥ࣐ࣥࢻ࣭⅊Ⰽ㒊ศ =. ྠࡌ࡛࠶ࡗࡓ㸬. ࣓ࣔࣜ◚ቯࡢᙳ㡪ࡶࡋࡃࡣ TOMOYO Linux ࡢᙉไࢡࢭ ࢫไᚚᶵ⬟࡞ఱࡋࡽࡢ⌮⏤࡛) ᐇ⾜ྍ⬟࡞ࡗࡓ (ಖㆤࡉࢀࡓ)ࢥ࣐ࣥࢻ࠸࠺ᐃ⩏ࡢୗ㸪Processing ゝㄒࢆ⏝ ࠸࡚ᐇ㦂⤖ᯝࢆྍどࡋࡓࡇࢁ㸪ᅗ㸱♧ࡍࡼ࠺࡞ྍど ᅗࡀᚓࡽࢀࡓ㸬. ⾲ 2 ᶍᨃᨷᧁࡢ⤖ᯝ Table 2 results of the experimental attack 4.4 ᨷᧁ⤖ᯝࡢྍど ๓㡯࡛ᚓࡽࢀࡓᐇ㦂ࡢ⤖ᯝᇶ࡙ࡁ㸪ࣉࣟࢢࣞࢫࣂ࣮ࡢ 㐍ᤖẁ㝵ࡀ 20%㸪40%㸪60%ࡢሙྜ㸪࠾ࡼࡧ TOMOYO Linux ࡀ↓ຠࡢ≧ែ᭷ຠࡢ≧ែࡢሙྜࡢྜィ 6 ࡘࡢ␗࡞ࡿẁ㝵 ࠾࠸࡚㸪 ࠕⰍࡁ㸻ᐇ⾜ྍ⬟ࢥ࣐ࣥࢻࠖ㸪 ࠕⓑⰍ㸻ᨷᧁࡢᙳ 㡪ࢆཷࡅࡓ(⪃࠼ࡽࢀࡿ)ࢥ࣐ࣥࢻࠖ㸪ࠕ⅊Ⰽ㸻TOMOYO Linux ࡢᙉไࢡࢭࢫไᚚᶵ⬟࡛ᨷᧁ⪅ࡽಖㆤ࡛ࡁࡓࢥ ࣐ࣥࢻࠖࡢ 3 ࡘࡢࣃࢱ࣮ࣥศ㢮ࡋ㸪Processing ゝㄒࢆ. ᅗ 3. Processing ゝㄒࡼࡿྍどᅗ. Figure 3 visualization image by Processing 3. ⏝ࡋࡓྍどᅗࢆసᡂࡋࡓ㸬ᑦ㸪ྍどᅗ࠾࠸࡚㸪ࡢ ᅗࡀఱࡢ≧ែࢆ♧ࡋ࡚࠸ࡿ㛵ࡋ࡚ࡣ㸪ᅗ㸰グࡍ㏻ࡾ ࡛࠶ࡿ㸬. 5. ホ౯⪃ᐹ 5.1 ホ౯ ᮏ◊✲࡛ࡣ㸪どぬࡢຠᯝࢆ ᐃࡍࡿࡓࡵ㸪⾲㸱♧ ࡍホ౯㍈ࢆタᐃࡋࡓ㸬⾲㸱ࡣ㸪ࡇࡢホ౯㍈ࢆ⏝࠸࡚㸪ほ ⓗ࡞ホ౯ࢆ⾜ࡗࡓ⤖ᯝ࡛࠶ࡿ㸬. ⾲ 3 ྍどᅗࡢホ౯⤖ᯝ Table 3 the evaluation of the visualization image ᅗ 2. ྍどᅗࡢࣞ࢘ࢺ. ⓒ 2019 Information Processing Society of Japan. 6.
(7) Vol.2019-DPS-178 No.9 Vol.2019-CSEC-84 No.9 2019/3/4. ሗฎ⌮Ꮫ◊✲ሗ࿌ IPSJ SIG Technical Report ホ౯ࡣ 4 ẁ㝵࡛⾜࠸㸪ྛࠎ㸪(۔ኚศࡾ᫆࠸)࣭ࠐ(ࡲ. ᰝࡋࡓࢥ࣐ࣥࢻࡢᩘࡀ⌧Ⅼ࡛ࡣᩘᑡ࡞࠸ࡇࡸ㸪ᅗࡢᵓ. ࠶ࡲ࠶ศࡾ᫆࠸)࣭ࡾࡲ࠶(ڹศࡽ࡞࠸)࣭(ศࡽ࡞࠸). ᡂࡀ㠀ᖖࢩࣥࣉ࡛ࣝ࠶ࡿࡓࡵᅗࡢෆᐜࢆ┤ឤⓗ⌮ゎࡍ. ࡢ⾲グ࡛ᐃᛶⓗ♧ࡋ࡚࠸ࡿ㸬. ࡿࡣሗ㔞ࡀ㊊ࡾ࡞࠸➼ࡢၥ㢟ࡀ࠶ࡾ㸪≉ྍど⤖ᯝ. ᅗࡢయീ㛵ࡋ࡚ࡣ㸪ᵓᡂࡋ࡚ࡣࢩࣥࣉࣝసࡽࢀ ࡚ ࠸ ࡿ ୍᪉ ࡛ 㸪 ྍど ᅗ༢ య ࡢࡳ ࡛ ࡣ ᕥྑ ࡢ ࡕ ࡽ ࡀ. ࡢᅗᑐࡋ࡚㸪ࡢᅗࡸᡭἲࢆ⏝ࡋ࡚ࡳࡿ➼ࡢ᳨ウࡶྵ ࡵࡓᖜ࡞ᨵၿࡀᛴົ࡛࠶ࡿ㸬. TOMOYO Linux ࡢᙉไࢡࢭࢫไᚚᶵ⬟ࡀ↓ຠࡢሙྜࢆ ⾲ࡋ࡚࠸ࡿࡢ࡞ࡀศࡽࡎ㸪ู⣬ࡢྍどᅗࡢࣞ ࢘ࢺࢆཧ↷ࡋ࡞ࡅࢀࡤࡍࡄࡣศࡽ࡞࠸ࡓࡵ㸪ᚋࡢᨵ ၿࡀᚲせ⪃࠼࡚ࡢڹホ౯ࡋࡓ㸬⥆࠸࡚ᅗࡢศࡾ᫆ࡉ. 6. ࡲࡵᚋࡢㄢ㢟 6.1 ࡲࡵ. 㛵ࡍࡿ 2 ࡘࡢ㡯┠㛵ࡋ࡚ࡣ㸪ࢭ࢟ࣗ OS 㛵ࡍࡿ≉. ᮏ◊✲ࡣ㸪ࢭ࢟ࣗ OS ࠾ࡼࡧ TOMOYO Linux ࡀᐇ㝿ࡢ. Ṧ࡞⏝ㄒ➼ࡣᅗ୰Ⓩሙࡋ࡚࠾ࡽࡎ」㞧࡞ᵓ㐀ࡢᅗ࡞ࡗ. ᨷᧁᑐࡋ࡚Ⓨࡍࡿຠᯝࡀ᫂░࡛࠶ࡿ࠸࠺ㄢ㢟ᑐ. ࡚࠸࡞࠸ࡓࡵ㸪 ࠕࡲ࠶ࡲ࠶ศࡾ᫆࠸ࠖࢆពࡍࡿࠐグࡋ. ࡋ㸪࣮ࣟ࢝ࣝᶒ㝈᪼᱁ࢩࢫࢸ࣒ࡢ㒊ศⓗ࡞࣓ࣔࣜ◚ቯࢆ. ࡓ㸬ࡲࡓ㸪3 ␒┠ 4 ␒┠ࡢホ౯㡯┠ࡘ࠸࡚ࡣ㸪ලయⓗ. ⾜࠺⬤ᙅᛶࢆ✺ࡃᶍᨃᨷᧁࢆ TOMOYO Linux ࣥࢫࢺ࣮. ಖㆤࡉࢀࡓ㈨⏘ᩘࡣ┤ឤⓗ⌮ゎྍ⬟࡛࠶ࡿ⪃࠼ࡢ۔. ࣝ῭ࢩࢫࢸ࣒ᐇࡋࡓ⤖ᯝࢆ㸪Processing ゝㄒ࡛ྍど. ホ౯ࡋࡓ୍᪉࡛㸪ಶࠎࡢࢥ࣐ࣥࢻࡢ୰࡛ࡶ≉ᨷᧁ⪅. ࡍࡿᡭἲࢆᥦࡋࡓ㸬. ⏝ࡉࢀࡸࡍ࠸ࡶࡢ࡞ࡢࠕಖㆤࡉࢀࡓ㈨⏘ࡢ㔜せᛶࠖ. ྍど࠶ࡓࡗ࡚ࡣ㸪ྍ⬟࡞㝈ࡾ⌧ᐇⓗ࡞ᨷᧁ㏆࠸≧. ࡘ࠸࡚ࡣ⾲⌧ࡍࡿࡇࡀ࡛ࡁ࡞ࡗࡓࡓࡵࡋࡓ㸬ࣉࣟ. ἣ࠾࠸࡚ TOMOYO Linux ࡢຠᯝ᳨ドࢆ⾜࠺ࡃ㸪ᐇ㝿. ࢢࣞࢫࣂ࣮㛵ࡋ࡚ࡣ㸪⏝ࡋࡓᨷᧁࡢ≉ᛶࡽ㐍ᤖẁ㝵. ሗ࿌ࡉࢀࡓ࣮ࣟ࢝ࣝᶒ㝈᪼᱁ / ࣓ࣔࣜ◚ቯ⬤ᙅᛶࢆ. ࡀ⣽ࡃ 3 ẁ㝵ศࢀ࡚࠾ࡾ㸪Ⰽᙬࡢ㐪࠸ࡶࡣࡗࡁࡾ. ࡗࡓᨷᧁࢆ⌧ྍ⬟࡞ࣉࣟࢢ࣒ࣛࢆ࠸㸪ᨷᧁࡢ㐍ᤖẁ㝵. ༊ู࡛ࡁࡿࡓࡵᨷᧁࡢ㐍ᤖẁ㝵ࡀ୍┠ุ࡛᩿ྍ⬟࡛࠶ࡿ. ࢆࢧࣂ࣮࢟ࣝࢳ࢙࣮ࣥᚑࡗ࡚ᮏ◊✲⊂⮬ࡢᨷᧁᐃࢩ. ⪃࠼ࡓࡓࡵ㸪ホ౯ෆᐜࡣୖࡽ 2 ẁ㝵┠Ⰻ࠸ホ౯࡛࠶ࡿ. ࢼࣜ࢜ࢆ᳨ウࡋࡓୖ࡛ࢩࢼࣜ࢜ᇶ࡙࠸࡚ 20%㸪40%㸪60%. ࠐࡋࡓ㸬ᅗ୰ࡢグྕࡢពࡢศࡾ᫆ࡉ㛵ࡋ࡚ࡣ㸪ࢥ. ࠸࠺ 3 ✀㢮ࡢ㐍ᤖẁ㝵ࢆᐃ⩏ࡋࡓ㸬ࡑࡢᚋ㸪ྛࠎࡢ㐍ᤖ. ࣐ࣥࢻ 1 ಶࡀࠐ1 ಶศࢆ⾲ࡍ࠸࠺⡆༢࡞࣮ࣝࣝࡢࡳᚑ. ẁ㝵࠾࠸࡚ TOMOYO Linux ࡢᙉไࢡࢭࢫไᚚᶵ⬟ࡀ. ࡗࡓ࠸࠺ほⅬ࡛ࡣศࡾ᫆࠸ゝ࠼ࡿࡀ㸪ᅗ୰ࡑࡢ᪨. ↓ຠ᭷ຠࡢሙྜ/sbin㸪/bin㸪/usr/sbin㸪/usr/bin ࡢ 4 ࡘࡢ. ࡢㄝ᫂ࢆグ㍕࡛ࡁ࡚࠸࡞࠸ࡇࡽホ౯ࢆࡓࡋڹ㸬ᑦ㸪. ࢹࣞࢡࢺࣜࡽ⏝㢖ᗘࡀ㧗࠸⪃࠼ࡽࢀࡿࢥ࣐ࣥࢻ. ᅇ⾜ࡗࡓࡇࢀࡽࡢホ౯ࡣ⮬ᕫホ౯ࡢᇦࢆฟࡎ㸪ᐃ㔞ⓗ࡞. 33 ಶࡎࡘྜィ 132 ಶࢆㄪᰝᑐ㇟ࡋ࡚㑅ᐃࡋ㸪ᐇ⾜ྍ⬟. ホ౯ࢆ⾜࠺ࡇࡀ࡛ࡁ࡚࠸࡞࠸ࡓࡵ㸪ᐃᛶⓗ࡞ホ౯ᡭἲ௨. ྍ⬟ࢆุᐃࡍࡿᐇ㦂ࢆ⾜ࡗࡓࡇࢁ㸪ᨷᧁࡀ 20%ࡽ. እࡢホ౯᪉ἲࡶ᳨ウࡋ☜❧ࡋ࡚࠸ࡃᚲせࡀ࠶ࡿ㸬. 40%㐍ࡳᐇ㦂ᑐ㇟ࢩࢫࢸ࣒ࡀ㒊ศⓗ࡞࣓ࣔࣜ◚ቯ࣮ࣟ ࢝ࣝ⎔ቃࡢᐖࢆཷࡅ࡚ࡶ㸪TOMOYO Linux ࡀ↓ຠࡢሙྜ. 5.2 ⪃ᐹ. ࡣㄪᰝࡋࡓ 132 ಶࡢࢥ࣐ࣥࢻࡢ࠺ࡕ࣓ࣔࣜ◚ቯᙳ㡪ࢆ. ᮏ◊✲࡛⾜ࡗࡓᶍᨃᨷᧁ࡛ࡣ㸪࣮ࣟ࢝ࣝᶒ㝈᪼᱁࣓ࣔ. ཷࡅࡓ⪃࠼ࡽࢀࡿ 6 ಶࢆ㝖ࡃ 126 ಶࡣ⟶⌮⪅ᶒ㝈ࢆྲྀᚓ. ࣜ◚ቯࡢ 2 ࡘࢆྠ⾜࠺ᨷᧁࢆ⏝ࡋ㸪TOMOYO Linux. ࡋࡓᨷᧁ⪅ࡼࡗ࡚ṇᖖᐇ⾜ྍ⬟ࡔࡗࡓࡢᑐࡋ㸪᭷ຠ. ࡼࡿᙉไࢡࢭࢫไᚚᶵ⬟ࡀ↓࠸ሙྜ࠶ࡿሙྜࡢ 2 ࡘ. ࡢሙྜ࡛ࡣㄪᰝࡋࡓ 132 ಶࡢ࠺ࡕᨷᧁ⪅ࡀṇᖖ(࣓ࣔ. ࡢ≧ἣ࠾࠸࡚㸪ලయⓗࡢࡼ࠺࡞ࢥ࣐ࣥࢻࡀᐇ⾜࡛ࡁ. ࣜ◚ቯࡢᙳ㡪ࢆཷࡅࡎ)ᐇ⾜ࡍࡿࡇࡀ࡛ࡁࡓࢥ࣐ࣥࢻࡣ. ࡚ࡢࢥ࣐ࣥࢻࡀᐇ⾜࡛ࡁ࡞ࡃ࡞ࡿࡢࡢᕪศࢆẚ㍑ࡋ㸪. ഹ 3 ಶ࡛࠶ࡗࡓ㸬ࡇࡢࡇࡽ㸪ᨷᧁ⪅ࡀࢩࢫࢸ࣒. ྍど⤖ᯝࡢᅗࢆసᡂࡋࡓ㸬ྍど⤖ᯝࡢసᡂ࠶ࡓࡗ࡚. ධࡋᐇ㝿ᨷᧁࢆཷࡅࡓሙྜ࡛ࡶ㸪TOMOYO Linux ࡢᙉไ. ࡣ㸪⏝ࡍࡿᨷᧁࡢࣉࣟࢢ࣒ࣛྜࢃࡏ࡚ᨷᧁ㐍ᤖᗘࢆᐃ. ࢡࢭࢫไᚚᶵ⬟ࡀ᭷ຠࡢሙྜ࡛ࡣᨷᧁ⪅ࢥ࣐ࣥࢻࢆᐇ. ⩏ࡋ㸪㐍ᤖᗘྜࢃࡏ࡚ TOMOYO Linux ࡢ↓ຠ᭷ຠࡢ. ⾜ࡉࢀ࡞࠸ࡼ࠺ಖㆤࡍࡿࡇ᭷ព࡞ຠᯝࡀ࠶ࡿࡇࡀศ. 㝿ࡑࢀࡒࢀࡢࢥ࣐ࣥࢻࡀᐇ⾜ྍ⬟࡛࠶ࡿ㸪132 ࡢࢥ. ࡗࡓ㸬ྍどࢆ⾜ࡗࡓ⚍ࡣᐇ㦂᳨࡛ドࡋࡓຠᯝࡘ࠸. ࣐ࣥࢻࢆᐇ㝿ᐇ⾜ࡋㄪࡓ⤖ᯝࢆᫎࡋࡓ㸬ྍどࢆ⾜. ࡚ Processing ゝㄒࢆ⏝࠸㸪ᐇ⾜ྍ⬟࡞ࢥ࣐ࣥࢻྍ⬟࡞. ࡗࡓࡇࡼࡾ㸪TOMOYO Linux ࡢ⏝ࡼࡗ࡚ࢇ࡞ࢥ. ࢥ ࣐ ࣥ ࢻ Ⰽ ศ ࡅࡋ ࡚ ྍど ᅗ ♧ ࡍ ࡇ ࡼ ࡗ ࡚ 㸪. ࣐ࣥࢻࡢᐇ⾜ࢆ㜵Ṇ࡛ࡁࡓࡢࢆලయⓗ▱ࡿࡇࡀ࡛ࡁ㸪. TOMOYO Linux ࡢᙉไࢡࢭࢫไᚚᶵ⬟ࡀᨷᧁ⪅ࡢ᭦࡞. TOMOYO Linux ࡢᙉไࢡࢭࢫไᚚᶵ⬟ࢆ⏝ࡋ࡚࠸࡞. ࡿෆ㒊◚ቯάືࡢ㐍⾜ຠᯝࢆ♧ࡍࡇࢆどぬⓗ♧ࡋࡓ㸬. ࠸ሙྜẚ㸪⏝ࡋࡓሙྜࡣᨷᧁ࡛ᶒ㝈᪼᱁ࢆ⾜ࡗࡓ ᨷᧁ⪅ࡀᵝࠎ࡞ࢥ࣐ࣥࢻࢆᐇ⾜ࡋ࡚ࡋࡲ࠺ࡇࢆ㜼Ṇ࡛ࡁ. 6.2 ᚋࡢㄢ㢟. ࡓࡇࡽ㸪⟶⌮⪅ᶒ㝈ࢆྲྀᚓࡉࢀ࡚ࡶࡑࡢᚋ◚ቯάື. ձ⏝ࡍࡿ⬤ᙅᛶࡢ᳨ウ. ࢆᣑࡉࢀ࡞࠸ࡼ࠺㣗࠸Ṇࡵࡿຠᯝࡀ࠶ࡗࡓࡇࢆྍど. ᮏ◊✲࡛ࡣ㸪ࢩࢫࢸ࣒ࡢ㒊ศⓗ࡞࣓ࣔࣜ◚ቯ࣮ࣟ࢝ࣝ. ⤖ᯝࡢᅗࡽどぬⓗ☜ㄆࡍࡿࡇࡀ࡛ࡁࡓ㸬ࡋࡋ㸪ㄪ. ᶒ㝈᪼᱁ࢆྠ⾜࠺⬤ᙅᛶࢆ⏝ࡋ࡚ᨷᧁᐇ㦂ࢆ⾜ࡗࡓ. ⓒ 2019 Information Processing Society of Japan. 7.
(8) Vol.2019-DPS-178 No.9 Vol.2019-CSEC-84 No.9 2019/3/4. ሗฎ⌮Ꮫ◊✲ሗ࿌ IPSJ SIG Technical Report ࡶࡢࡢ㸪ࢿࢵࢺ࣮࣡ࢡෆࢆᨷᧁ⪅ࡀືࡁᅇࡗࡓࡾ࣐࢙ࣝ࢘. ㄪᰝࡍࡿࡇࢆ⪃࠼ࡓሙྜࡣ㸪ᡭື࡛ࡢྍどᅗసᡂࡣ⭾. ࢆࣥࢫࢺ࣮ࣝࡉࡏ࡚ C&C ࢧ࣮ࣂ᥋⥆ࡉࡏࡓࡾࡍࡿ. ࡞㛫ࢆせࡍࡿࡇ࡞ࡾ㸪⌧ᐇⓗࡣゝ࠸㞴࠸㸬ᚋ. ࠸ࡗࡓࡼ࠺࡞ᡤㅝᆺⓗ࡞ᶆⓗᆺᨷᧁ࡞ࡢ⌧ᐇⓗ࡞⬣. ࡣ㸪ྍどᅗసᡂࢆ⮬ືࡋ࡚ຠ⋡ⓗ࡞ྍどࢆ⾜࠼ࡿ᪉. ጾ㏆࠸≧ἣࢆ⌧ࡍࡿࡇࡀ࡛ࡁ࡞ࡗࡓ㸬ࡑࡢࡓࡵ㸪. ἲࡶὀຊࡋ᳨࡚ウࡍࡿᚲせࡀ࠶ࡿ㸬. Linux ࢩࢫࢸ࣒ࢆ≺࠺࣐࢙ࣝ࢘ࢆ⏝ࡍࡿ࡞㸪⌧ᐇⓗ ࡞ࢧࣂ࣮ᨷᧁࡢ⬣ጾᑐࡋ࡚ TOMOYO Linux ࡀᣢࡘຠ. ཧ⪃ᩥ⊩. ᯝࢆྍど࡛ࡁࡿࡼ࠺࡞ᶍᨃᨷᧁࢆ⾜࠺ࡓࡵ㸪⏝ࡍࡿ. [1] “TOMOYO Linux ࣉࣟࢪ࢙ࢡࢺ බᘧࢧࢺ” http://tomoyo㸬osdn㸬jp/index㸬html㸬ja (ཧ↷ 2016-02-20)㸬 [2] ᶫᮏṇᶞ࣭Ᏻ⸨㢮ኸ࣭๓⏣ಇ⾜࣭⏣୰ⱥᙪ㸪 ࠕሗࢭ࢟ࣗ ࣜࢸྥୖྥࡅࡓ OS ◊✲ࡢືྥࠖ2012ࠊሗฎ⌮Ꮫㄽᩥ ㄅ ࢥࣥࣆ࣮ࣗࢸࣥࢢࢩࢫࢸ࣒ Vol㸬5㸪No㸬2㸪pp㸬51̽ 62㸪(Mar㸬 2012) [3] ཎ⏣Ꮨᰤ࣭༙⏣ဴኵ࣭ᶫᮏṇᶞ࣭⏣୰ⱥᙪ㸪 ࠕࣉࣜࢣ࣮ ࢩࣙࣥࡢᐇ⾜≧ἣᇶ࡙ࡃᙉไࢡࢭࢫไᚚ᪉ᘧࠖ㸪 Vol53ࠊNo㸬9㸪 pp㸬1-18㸪 ሗฎ⌮Ꮫㄽᩥㄅ㸪 2012 [4] ရᕝ㧗ᘅ㸪ࠕ࣮࢜࣌ࣞࢸࣥࢢࢩࢫࢸ࣒ࡼࡿṇࢡࢭࢫ 㜵Ṇᢏ⾡ࠖ㸪ࢥࣥࣆ࣮ࣗࢱࢯࣇࢺ࢙࢘㸪 Vol㸬 21㸪 No㸬 6㸪 pp㸬 482̽493 (2004)㸬 ᱜ㈗ᩥ㸬 ┤ほ⩏ㄽ⌮ᆺ ⌮ㄽ㸬 ሗฎ⌮㸪 1999㸪 vol㸬 30㸪 no㸬 6㸪 p㸬 626634㸬 [5] ⓑᒣ㸪ࠕྍどࡽఱࡀศࡿࡢ What can we extract from the visualization?ࠖ㸪ࢩࢫࢸ࣒ᡂᏛ㸪➨ᅇᏛ⾡ㅮ₇ [6] “Processing බᘧࢧࢺ” https://processing㸬org (2018-12-30 ཧ↷) [7] lockheed martin ࢧࣂ࣮࢟ࣝࢳ࢙࣮ࣥ͆https://www㸬 lockheedmartin㸬com/en-us/capabilities/cyber/cyber-kill- chain㸬 html͇ (2018-09-04 ཧ↷) [8] ࣐ࢡࢽ࢝ࢿࢵࢺ࣮࣡ࢡ♫ ࢧࣂ࣮࢟ࣝࢳ࢙࣮ࣥ “https://www㸬macnica㸬net/solution/security_apt㸬html/” (2018-11-7 ཧ↷) [9] ࣮࢝ࣛࣘࢽࣂ࣮ࢧࣝࢹࢨࣥ᥎ዡ㓄Ⰽࢭࢵࢺ࢞ࢻࣈࢵࢡ➨ 2∧ [10]͆ࢧ࢜ࢫ⬤ᙅᛶሗ” ͆https://security㸬sios㸬 com/vulnerability/kernel-security-vulnerability-20170901㸬html͇ (2018-08-10 ཧ↷) [11] “Linux Kernel < 4㸬4㸬0-83 / < 4㸬8㸬0-58 (Ubuntu 14㸬04/16㸬 04) - Local Privilege Escalation (KASLR / SMEP)”㸪 ͆https://www㸬exploit-db㸬com/exploits/43418͇ (2018-8-19 ཧ↷). ⬤ᙅᛶࢆ⪃ࡍࡿᚲせࡀ࠶ࡿ㸬ලయⓗࡣ㸪࣮ࣜࣔࢺ➃ᮎ ࡽࣂࢵࢡࢻࢆసᡂࡋ࡚ධࡍࡿ⬤ᙅᛶ࡞㸪ᨷᧁࡀ⾜ ࢃࢀࡓ㝿ࡢ⿕ᐖࡀࡼࡾࡁ࡞ࡶࡢࢆࡗ࡚㸪ᶍᨃᨷᧁࡢ㉁ ࢆྥୖࡉࡏࡿࡇࡀᚋࡢㄢ㢟࡛࠶ࡿ㸬 ղྍどᅗࡢᨵၿ ᅇ⾜ࡗࡓྍど࡛ࡣ㸪㟼ⓗ࡞ྍどᅗࢆసᡂࡋ㸪ᅗ୰ ࡢᩥᏐࡣᨷᧁࡢ㐍ᤖẁ㝵ࢆ♧ࡍ%ࢆࣉࣟࢢࣞࢫࣂ࣮ࡢᶓ ♧ࡍࡢࡳࡍࡿ࡞ྍどᅗ⾲♧ࡍࡿᩥᏐᙧែ࡛ࡢሗ ࡣᚲせ᭱ᑠ㝈␃ࡵࡓ㸬ࡑࡢ⤖ᯝ㸪ࢩࣥࣉࣝ࡞ྍどᅗࢆ సᡂࡍࡿࡇࡀ࡛ࡁࡓ୍᪉࡛㸪సᡂࡋࡓྍどᅗ 1 ᯛࡢࡳ ࡛ࡣ㸪ࡢࢥ࣐ࣥࢻࡀᨷᧁࡢᙳ㡪ࢆཷࡅࡓྍ⬟ᛶࡀ࠶ࡗࡓ ࡾᨷᧁ⪅ࡽಖㆤ࡛ࡁ࡞ࡗࡓࡾࡋ࡚㏫ࡢࢥ࣐ࣥࢻ࡛ ࠶ࢀࡤ☜ᐇಖㆤࡍࡿࡇࡀ࡛ࡁࡓࡢࢆ⌮ゎࡍࡿ ࡇࡀ࡛ࡁ࡞࠸࠸࠺ㄢ㢟ࡀṧࡗ࡚࠸ࡿ㸬ᮏ◊✲࡛సᡂࡋ ࡓྍどᅗࡢෆᐜࢆ⌮ゎࡍࡿࡣ㸪ᶍᨃᨷᧁࡢ㡯┠࡛グࡋ ࡓࠕㄪᰝࢥ࣐ࣥࢻ୍ぴ⾲ࠖࡀᚲせ࡞ࡾ㸪 ࠕศࡾ᫆࠸ྍど ࠖࡣ࡞ࡗ࡚࠸࡞࠸≧ἣ࡛࠶ࡿࡓࡵ㸪࠼ࡤྠࡌ Processing ゝㄒࡢ୰࡛ࡶ p5㸬js ࡞ࡢ Java Script ేࡏ࡚ ⏝࡛ࡁࡿࣛࣈࣛࣜࢆࡗ࡚ືⓗࡘࣥࢱࣛࢡࢸࣈ ࡞ྍどࢆヨࡳࡿ࡞㸪ࡼࡾศࡾ᫆࠸ྍどࢆ┠ᣦࡋ࡚ ࠸ࡃᚲせࡀ࠶ࡿ㸬 ճホ౯ᡭἲࡢᢤᮏⓗ࡞ぢ┤ࡋ ᅇࡢྍどᅗࡢホ౯ࡣ㸪 ᐃᛶⓗࡘほⓗ࡞⮬ᕫホ ౯␃ࡲࡗࡓ㸬ᚋࡣᐈほⓗ࡞ホ౯ࢆ⾜࠼ࡿࡼ࠺ࡍࡿࡓ ࡵ㸪ࣥࢣ࣮ࢺࢆసᡂࡋ࡚ከࡃࡢேྍどᅗࢆᐈほⓗ ホ౯ࡋ࡚ࡶࡽ࠼ࡿࡼ࠺ࡍࡿࡓࡵホ౯㍈ࢆ᭦⣽ࡃタ ᐃࡍࡿ࡞㸪ྍ⬟࡞㝈ࡾከࡃࡢᐈほⓗពぢࢆ㞟ࡍࡿࡓࡵ ࡢᢤᮏⓗ࡞ぢ┤ࡋࢆ⾜ࡗ࡚࠸ࡃࡇࡀᚲせ࡛࠶ࡿ㸬ࡲࡓ㸪 ᐃ㔞ⓗホ౯ࡶᅇࡢホ౯࡛ࡣᐇࡍࡿࡇࡀ࡛ࡁ࡞ࡗࡓ ࡇࡽ㸪 ᐃ㔞ⓗ࡞ホ౯ᡭἲࡶేࡏ࡚☜❧ࡍࡿᚲせࡀ࠶ࡿ㸬 մྍどࡢࢥ࣐ࣥࢻࡢⰍศࡅ➼ࡢసᴗࡢ⮬ື ᅇࡢྍどᅗࡢసᡂ࠶ࡓࡗ࡚ࡣ㸪ᶍᨃᨷᧁࡘ࠸࡚ ㄪᰝࡋࡓࡑࢀࡒࢀࡢᨷᧁࡢ㐍ᤖẁ㝵 TOMOYO Linux ࡼࡿᙉไࢡࢭࢫไᚚᶵ⬟ࡀ↓ຠ/᭷ຠࡢࢥ࣐ࣥࢻᩘࢆ ࡚ᡭື࡛ྍどᅗᫎࡋࡓ㸬ࡑࡢࡓࡵ㸪ྍどᅗࡢస ᡂ㐣⛬ࡣ㠀ຠ⋡ⓗ࡛࠶ࡾ㸪ᚋᮏ◊✲ࢆ᭦Ⓨᒎࡉࡏ࡚࠸ ࡃࡇࢆ⪃࠼ࡓሙྜ㸪᭦ከࡃࡢࢥ࣐ࣥࢻࢆㄪࡓࡾ㸪 ᅇࡣㄪᰝࡋࡓࡾࡍࡿࡇࡀ࡛ࡁ࡞ࡗࡓ✀㢮ࡢࣇࣝࡶ. ⓒ 2019 Information Processing Society of Japan. 8.
(9)
図
関連したドキュメント
第1董 緒 言 第2章 調査方法 第3章 調査成績
The method is consisted of the following four steps : 1) Calculation of standard deviation (SD) map 2) Edge detection and removal on SD map 3) Interpolation of the removed
In this study, the standard deviation of gray level intensity Gsa, the ratio of surface area RA, the ratio of X-direction length RLX and the one of Y
The VLSI architecture is characterized by pipeline processing of the divided images, concurrent motion models estimation for multiple regions, and a common processing element
16 By combining the tissue clearing method CUBIC, melanin bleaching, and immunostaining, we succeeded in making the eye transparent and acquiring images of the retina from outside
This paper proposes a method of enlarging equivalent loss factor of a damping alloy spring by using a negative spring constant and it is confirmed that the equivalent loss factor of
We construct a Lax pair for the E 6 (1) q-Painlev´ e system from first principles by employing the general theory of semi-classical orthogonal polynomial systems characterised
The inclusion of the cell shedding mechanism leads to modification of the boundary conditions employed in the model of Ward and King (199910) and it will be