IIJ Technical WEEK セキュリティ動向 2012

Similar documents
CPEデバイスのセキュリティ

IW2001-B2 1 Internet Week 2001 ( ) Copyright 2001 All Rights Reserved, by Seiji Kumagai IW2001-B2 2 CodeRed Copyright 2001 All Rights

1. 2

情報セキュリティの現状と課題

今企業が取るべきセキュリティ対策とは策

Flash Player ローカル設定マネージャー

Copyright

tonan-cs.indd

DNS (BIND, djbdns) JPNIC・JPCERT/CC Security Seminar 2005


IW2002-B5 1 Internet Week ( ) 9:30 12:30 ( ) Copyright 2002 All Rights Reserved, by Seiji Kumagai ADSL FTTH 24 IP LAN

総セク報告書(印刷発出版_.PDF

Anti-Spam Seminar (IAjapan)

102 APWG(Anti-Phishing Working Group) % 6 National Cyber-Forensics and Training Alliance NCFTA Pharming Google FBI / FBI Web

untitled

untitled

untitled

FirePass Edge Client TM Edge Client LAN Edge Client 7.0 Edge Client Edge Client Edge Client Edge Client Edge Client Edge Client LAN Edge Client VPN Wi

Google Apps Google Apps for Work Education Government Drive for Work Google Apps Unlimited

目次

IPA

untitled

Linux Activities for Promoting Desktop Linux Utilization Jun Iio Research Center for Information Technology, Mitsubish

2


untitled

ネットワークユーティリティ説明書


Web Web Web Web i

...i A

内閣官房情報セキュリティセンター(NISC)

ウイルスバスター ビジネスセキュリティ インストールガイド

[ ] ( IPA ) IPA Warning! ( ) (1) IPA ( ) IPA 1-1 IPA ( 1-2 ) IPA - 1 -

表紙4_1/山道 小川内 小川内 芦塚

Jp

LAPLINK ヘルプデスク 導入ガイド

No.208_honbun.indd

ガイドブック

wide97.dvi

untitled

分析レポート2_Gaobot

IT Craig Williams - Cisco Talos Security Intelligence and Research Group Michael C. Weil - Deloitte Financial Advisory Service LLP Computer and Cyber

jogms9号.indd

コミュニケーションユーティリティー編

1 LAN SSID SSID SSID SSID SSID: SSID SSID IP SSID, VLAN IP SSID, eduroam SSID: SSID eduroam , ,,,, 3 LAN Mac (215 4 ) 17, (

2004 SYN/ACK SYN Flood G01P014-6

2 [2] Flow Visualizer 1 DbD 2. DbD [4] Web (PV) Web Web Web 3 ( 1) ( 1 ) Web ( 2 ) Web Web ( 3 ) Web DbD DbD () DbD DbD DbD 2.1 DbD DbD URL URL Google

Microsoft Word - 11_thesis_08k1131_hamada.docx


RT58i 接続ガイド

Jp

Cisco Configuration Professional(CCP)Express 3.3 による Cisco 841M J シリーズ初期設定ガイド

11 Windows XP IP WEP (Web )

LAN IP MAC IP MAC MAC IP IP IP IP IP IP [1][2][3] [4][5] IP IP IP IP (MARS MAC Address Reporting System) [6] IP IP MAC 2 MAC MATT MAC Address Tracing

DNS DNS(Domain Name System) named(bind), tinydns(djbdns), MicrosoftDNS(Windows), etc 3 2 (1) ( ) IP IP DNS 4

Cisco Identity Services Engine Supported Mac OS X AV/AS Products Version

オンラインによる 「電子申告・納税等開始(変更等)届出書」 提出方法

/07/ /10/12 I

タイムビジネス利用に関する国内動向調査

untitled

rzat10pdf.ps

CCC DATAset 2009 によるマルウェア配布元の可視化

HP

ECに関わる法的問題検討報告書

Central Processing Unit 2

AirMac ネットワーク for Windows

ウイルスバスター2012 クラウド ガイドブック

Cisco Identity Services Engine Supported Mac OS X AV/AS Products Version

1 基本的考え方


LAPLINK ヘルプデスク 操作ガイド

Adobe AIR のセキュリティ


johokiso-internet

RT57i 設定マニュアル

PDF

Cisco® ASA シリーズルーター向けDigiCert® 統合ガイド

山梨県ホームページ作成ガイドライン


DNS DNS 2002/12/19 Internet Week 2002/DNS DAY 2

Jp

2011 Future University Hakodate 2011 System Information Science Practice Group Report Project Name Visualization of Code-Breaking Group Name Implemati

Vol. 28 No. 2 Apr Web Twitter/Facebook UI Twitter Web Twitter/Facebook e.g., Web Web UI 1 2 SNS 1, 2 2

JPRS JANOG13 1. JP DNS Update 2. ENUM (ETJP) 3. JP ( ) 3 1. JP DNS Update

Cisco Identity Services Engine Supported Mac OS X AV/AS Products Version

untitled

IPSJ SIG Technical Report Vol.2014-EIP-63 No /2/21 1,a) Wi-Fi Probe Request MAC MAC Probe Request MAC A dynamic ads control based on tra

付加情報をもったファイル共有システム

v6

FIFA 7 IETF LAN ( ) IT IPv6 ( ) (TAO) WIDE JR 4 SG(Special Group) FIFA

Cisco NAC Appliance Supported Mac OS X AV/AS Products Version

2006/6/ /9/1 2007/11/9 () 2011/4/ ( ()) ii

TCP/IP Internet Week 2002 [2002/12/17] Japan Registry Service Co., Ltd. No.3 Internet Week 2002 [2002/12/17] Japan Registry Service Co., Ltd. No.4 2

Adobe Acrobat DC 製品比較表


MSSGuideline ver. 1.0


OSC_isshiki_090710c.ppt

/02/ /09/ /05/ /02/ CA /11/09 OCSP SubjectAltName /12/02 SECOM Passport for Web SR

untitled

Transcription:

IIJ Technical WEEK 2012 2012 12 11 16 1

Agenda 2012 2

2012 2012 Anonymous 3

2012 Anonymous #OpJapan Anonymous Timeline 2012/06/25 AnonOps "Operation Japan (#opjapan)" 2012/06/26 HomePage DDoS 2012/06/27 29 DDoS IRC 20 HOIC,Slowloris,Tor s Hammer IP 27 4

2012 Web 5

2012 PC OS Jailbreak (root ) http://www.soumu.go.jp/menu_news/s-news/ 01kiban08_02000087.html 6

2012 Microsoft RSA1024 SSL/TLS : PKI ComodoHacker : RA 500 Flame : MD5 Adobe : PKI CA/Browser Forum 7 7

2012 ( ) ID ID ( ) ID ID ( ) ( ) 8

Agenda 2012 DCWG 9

DCWG DNS Changer DNS DNS Changer 10

DCWG Operation Ghost Click: FBI DCWG Rove Digital https://inet.trendmicro.co.jp/doc_dl/select.asp?type=1&cid=81 http://www.fbi.gov/news/stories/2011/ november/malware_110911/malware_110911 http://www.dcwg.org/ http://www.fbi.gov/newyork/press-releases/2011/manhattan-u.s.-attorney-charges-seven-individuals-forengineering-sophisticated-internet-fraud-scheme-that-infected-millions-of-computers-worldwide-andmanipulated-internet-advertising-business Georgia Tech, Internet Systems Consortium, Mandiant, National Cyber-Forensics and Training Alliance, Neustar, Spamhaus, Team Cymru, Trend Micro, University of Alabama at Birmingham,( ISP) 11

DCWG DNS Changer DNS DNS DNS DNS Microsoft Windows Apple Mac OS 400 Web drive by download (FBI ) DNS 2012 7 9 12

DCWG DNS Changer timeline ( ) 2005 DNS Changer (TDSS FAKEAV ) 2006 ( Rove Digital ) 2008 9 Atrivo IX Estdomains ICANN 2009 Nelicash FAKEAV 2011 11 08 FBI 7 6 ( 1 ) 13

DCWG OS MyDoom(2004) hosts ARP cache poisoning DNS poisoning DHCP DNS Changer OS DNS IIJ Internet Infrastructure Review IIR Vol.15 http://www.iij.ad.jp/company/development/report/iir/015.html 14

DCWG DNS Changer IIJ Internet Infrastructure Review IIR Vol.15 http://www.iij.ad.jp/company/development/report/iir/015.html 15

DCWG DNS Changer DNS 1 4 Google, Yahoo!,Bing, Ask.com Google Ads, Overture,Doubleclick ( ) wikileaks.org TDSS HTML DNS DNS FAKEAV Rove Digital https://inet.trendmicro.co.jp/doc_dl/select.asp?type=1&cid=81 16

DNS Changer DNS Changer MBR DNS (IIJ ) UTSTARCOM,routers from BNSL(India),D-Link,Linksys,OpenWRT/DD-WRT,A-Link,Netgear,ASUS ZVMODELVZ Web Manager, SMC (ISC Merike Kaeo Nanog54 Security BoF ) (FAKEAV) FAKEAV(Protection Center) http://www.mcafee.com/japan/security/vird.asp?v=dnschanger.bu FAKEAV(AntiMalware) http://www.threatexpert.com/report.aspx?md5=9f09ff8dba53c3f3734295528297d015 FAKEAV(MacGuard) http://blog.f-secure.jp/archives/50605046.html FAKEAV(WindowsAntiSpyware) http://www.gfi.com/blog/movie-time-dns-changer-trojan/ FAKEAV(SpySheriff) http://www.youtube.com/watch?v=ve5ku01jya8 17

連携の成功事例DCWG 犯人グループの逮捕 エストニアに本拠地を持つRove Digital を親会社にした企業グループ http://www.fbi.gov/newyork/pressreleases/2011/manhattan-u.s.attorney-charges-sevenindividuals-for-engineeringsophisticated-internet-fraudscheme-that-infected-millions-ofcomputers-worldwide-andmanipulated-internet-advertisingbusiness F-Secure 社のMikko HipponenのPintrest よりhttp://pinterest.com/mikkohypponen/case-dns-changer/ 18

DCWG timeline 2011 11 04 2011 11 08 2012 02 06 2012 02 27 2012 2 2012 03 06 2012 03 07 2012 05 22 DCWG.org (Rove Digital ) 551,436 ISC DNS DNS (2012 3 9 ) NANOG 54 ISC Merike Kaeo ISP IIJ-SECT blog DNS Changer JPCERT/CC TelecomISAC Japan WorkingGroup ISP JPCERT/CC DNS (DNS Changer) DNS 120 407,927 IIJ-SECT blog DNS Changer ( ) JPCERT/CC DNS Changer 2012 05 23 Google Notifying users affected by the DNSChanger malware. 2012 05 30 2012 06 04 2012 07 09 2012 07 10 Telecom-ISAC Japan Facebook Notifying DNSChanger Victims. DNS 210,851 IIJ-SECT blog DCWG http://www.dcwg.org/wp-content/uploads/2012/07/dcwg-unique-ips-20120708.txt 19

DCWG DNS Changer Working Group http://www.dcwg.org/last-day-of-dcwg-data/ 20

DCWG IIJ-SECT blog https://sect.iij.ad.jp/d/2012/02/245395.html https://www.jpcert.or.jp/at/2012/at120008.html https://www.telecom-isac.jp/news/news20120530.html 21

DCWG http://googleonlinesecurity.blogspot.jp/2012/05/notifying-users-affected-by-dnschanger.html https://www.facebook.com/notes/facebook-security/notifying-dnschanger-victims/10150833689760766 http://dns-ok.jpcert.or.jp/ http://www.dns-ok.us/ DNS DNS 22

DCWG (ISP ) DCWG DNS ( google public DNS ) DNS ISP DCWG 7 9 5,522 23

DCWG DNS Changer Forward-looking Threat Research Feike Hacquebord Paul Ferguson WG DCWG DCWG CSIRT ISP 24

DCWG DNS Changer (2) DCWG ( DNS ) ISP http://www.dcwg.org/category/data/ 25

Agenda 2012 DCWG 26

(1) http://www.npa.go.jp/safetylife/seianki26/theme_a/a_d_1.html 27

(2) http://law.e-gov.go.jp/htmldata/h10/h10ho114.html 11 4 ( ) ( ) ( ) ( ) ( ) 28

(3) CERT/CC KB/VN JPCERT/CC JVN IPA 16 235 (JVN) http://www.ipa.go.jp/security/ciadr/partnership_guide.html 29

( ) 30

Culture of Security 31

(SEC) I. (iii) CF Disclosure Guidance: Topic No. 2 Cybersecurity http://www.sec.gov/divisions/corpfin/guidance/cfuidgance-topic2.htm http://www.nisc.go.jp/conference/seisaku/dai28/pdf/28shiryou1-1.pdf 32

Agenda 2012 DCWG 33

IM Web 34

IM Web 35

CEPTOAR Council WG ( ) (J-CSIP) ( IPA,JPCERT/CC) (NiCT,TelecomISAC Japan) ( 4,800 ) (AV ) (ISOG-J) WG5 NISC (IPA,JPCERT/CC, NiCT,TelecomISAC Japan) ( ISOG-J) 36

IT (ISOG-J WG5 NSF2012 B5, http://www.jnsa.org/seminar/nsf/2012/pro.html) 37

38

2012 2012 Anonymous DCWG 39

IIJ TEL 03-5205-4466 9 30 17 30 / / info@iij.ad.jp http://www.iij.ad.jp/ 40