ã¯ã©ãŠããµãŒãã«å¯Ÿããè匱æ§èšºæã®äºåç³è«ã«ã€ããŠå瀟ã«åãåãããŠã¿ãçµæ
å
æ¥ãã®ãããªããã°èšäºãå
¬éãããŸããã
ã¯ã©ãŠããµãŒãã¹ãè匱æ§èšºæããæã®ãäœæ³Â
ãšããäŒæ¥ã«ãããŠè匱æ§èšºæããããŠããããšãã蚺æå¡ãããã®ããã°ã§ãã¯ã©ãŠããµãŒãã¹ïŒIaaSïŒã®å©çšè
ãè匱æ§èšºæãããéã®æ³šæç¹ããŸãšããããŠããŸãã
è匱æ§èšºæã宿œããéã«ã¯ããèªèº«ã®å©çšããŠãããã©ãããã©ãŒã ã®äºæ¥è
ã«ã¡ãããšç¢ºèªãããæ¹ãè¯ããšèããŸãã
ãšããèšåããããŸãã
VAddyã¯ãµãŒããŒäžã®Webã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿããè匱æ§èšºæïŒãã©ãã¯ããã¯ã¹ãã¹ãïŒãè¡ããµãŒãã¹ã§ãã®ã§ãããã«åœãŠã¯ãŸããŸãã
äžèšã®ããã°èšäºã§ã¯AWSãMicrosoft AzureãGoogle Cloud Platformã®ããªã·ãŒããŸãšããŠããã ããŠããã®ã§ã䟿ä¹ããŠæ¥æ¬åœå
ã®ã¯ã©ãŠãäºæ¥è
ã®ããªã·ãŒã«ã€ããŠãŸãšããŠã¿ãŸããã
äž»èŠã¯ã©ãŠãäºæ¥è
ã®è匱æ§èšºæã«é¢ããããªã·ãŒ
ãAmazon Web Servicesã
䟵å
¥ãã¹ã - AWS ã¯ã©ãŠãã»ãã¥ãªã㣠| AWS
AWSã®å Žåãè匱æ§ãã¹ãïŒäŸµå
¥ãã¹ããè¡ãå Žåã¯äºåç³è«ãå¿
èŠã«ãªããŸããç³è«çšã®å°çšãã©ãŒã ãçšæãããŠããŸãã®ã§ãVAddyã§è匱æ§èšºæãè¡ãéã¯AWSã«äºåç³è«ããé¡ãããŸããå
¥åé
ç®ã«ããã»ã©é£ããå
容ã¯ãããŸãããããTotal Bandwidth (Please provide expected Gbps)*ããªã©ãã©ãèšå
¥ããŠè¯ããããããªãå Žåã¯ãé£çµ¡ãã ããã
Microsoft Cloud Unified Penetration Testing Rules of Engagement
As of June 15, 2017, Microsoft no longer requires pre-approval to conduct a penetration test against Azure resources.
2017幎6æ15æ¥çŸåšããã€ã¯ããœããã¯Azureã®ãªãœãŒã¹ã«å¯Ÿãã䟵å
¥ãã¹ãã宿œããããã®äºåæ¿èªãå¿
èŠãšããŸããã
äžèšã®ããã«ã䟵å
¥ãã¹ãïŒa penetration testïŒãã«ã€ããŠã¯ç³è«äžèŠã®ããã§ãããã ãVAddyã®æ€æ»ã¯ã䟵å
¥ãã¹ãïŒa penetration testïŒããšããããã¯ãèåŒ±æ§æ€æ»ïŒVulnerability test / scanningïŒãã®å±ãããã®ãªã®ã§ã念ã®ããåãåããäžã§ãã
ãGoogle Cloud PlatformïŒGCPïŒã
Security and Compliance on the Google Cloud Platform  |  Google Cloud Platform
Google Cloud Platform ã®ã»ãã¥ãªãã£ãè©äŸ¡ããããã«ãããã¬ãŒã·ã§ã³ ãã¹ããè¡ãéã«ãGoogle ãžé£çµ¡ããå¿
èŠã¯ãããŸããã
Azureåæ§ãã¡ããäžèšã®ãããªèšèŒããããŸãããVAddyã¯GCPã®ã»ãã¥ãªãã£ãè©äŸ¡ããããã®ãã¹ãã§ã¯ãªããGCPäžã§åããŠããWebã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ãæ€æ»ãããã®ãªã®ã§ããã¡ãã念ã®ããåãåããäžã§ãã
èåŒ±æ§æ€æ»ãè² è·è©Šéšãè¡ããŸããïŒ
æ€æ»æã®ãã©ãã£ãã¯ãæ°çŸMbpsãè¶
ããããšãèŠèŸŒãŸããå Žåãé€ããååãšããŠäºåç³è«ã¯äžèŠã§ããVAddyã®æ€æ»ã§ã¯ããã»ã©ã®ãã©ãã£ãã¯ã¯çºçããŸããã®ã§ãäºåç³è«ç¡ãã§VAddyã§ã®èåŒ±æ§æ€æ»ãèµ°ãããããšãã§ããŸãã
ããããã£ã¯ã©ãŠãã
è匱æ§ã¹ãã£ã³ã宿œããŸãããç³è«ã¯å¿
èŠã§ããããã
ãå©çšèŠçŽã®ç¯å²å
ã§å®æœããã ããã°åé¡ãªããããç³è«ã¯äžèŠã§ãã ã
ãšã®èšè¿°ããããå©çšèŠçŽç¬¬8æ¡ïŒçŠæ¢äºé
ïŒ2é
ã«ã¯
ããŠãŒã¶ãŒã¯ãæ¬ãµãŒãã¹ã«çšãããããã£ã®èšåïŒéä¿¡èšåãéä¿¡åç·ãé»åèšç®æ©ããã®ä»ã®æ©åšåã³ãœãããŠãšã¢ããããŸããïŒã«ç¡æš©éã§ã¢ã¯ã»ã¹ããåã¯ãã®å©çšè¥ããã¯éå¶ã«æ¯éãäžããè¡çºïŒæ¯éãäžãããããã®ããè¡çºãå«ã¿ãŸããïŒãããªããã®ãšããŸããã
ãšã®èšè¿°ããããŸãã
VAddyã䜿ã£ãèåŒ±æ§æ€æ»ã§ããããã£ã®èšåã«æ¯éãäžãããããšã¯èãã«ããã®ã§ããã¡ããäºåç³è«ã¯äžèŠãšèããããŸãã
ããããã¯ã©ãŠãã
è² è·ãã¹ããè匱æ§èšºæã¯å¯èœã§ããïŒ
è² è·ãã¹ããè匱æ§èšºæã®å®æœã«é¢ããŸããŠäºåã®é£çµ¡ã¯äžèŠã§å®æœå¯èœã§ãããã ããè² è·ãã¹ããè匱æ§èšºæãªã©ã«ãã£ãŠä»ã®ã客æ§ãžã®åœ±é¿ããµãŒãã¹ç¶ç¶ã«æ¯éããããšå€æãããå Žåã«ã¯ãå¶éçã宿œãããŠããã ãå ŽåãããããŸãã
ãšããããšã§ããã¡ããVAddyãå©çšããéã®äºåç³è«ã¯äžèŠã§ãã
ãIIJ GIOã€ã³ãã©ã¹ãã©ã¯ãã£ãŒP2ã
èåŒ±æ§æ€æ»ã®å®æœã«ã€ããŠã®èŠå®ãèŠã€ãããªãã£ãã®ã§ããµããŒãã«åãåããããšããã以äžã®ãããªåçãããã ããŸããïŒå³æ¥åçïŒïŒã転èŒèš±å¯ãããã ããŠããŸãã®ã§ã以äžã«è»¢èŒãããŠããã ããŸãïŒ2017幎6æ27æ¥æç¹ïŒ
æç¢ºã«èŠå®ã¯ããããŸãããèåŒ±æ§æ€æ»ãè² è·è©Šéšã¯ãåºæ¬çã«ç³è«ãªã©ã¯äžèŠã§ãããã ããåŒç€Ÿããå€éšããã®æ»æããç°åžžãªæ¯ãèããïŒäž»ã«è² è·ïŒãšå€æããå Žåãä»ã®ã客æ§ãå®ãããšãç®çãšããŠãµãŒãã¹æäŸã«å¶éïŒéä¿¡å¶éã忢ïŒããããšããå¥çŽè
æ§ã«ç¢ºèªããããŠããã ãå¯èœæ§ãããããŸãã
ãšããããšã§ããã¡ããVAddyãå©çšããéã®äºåç³è«ã¯äžèŠã§ãã
ConoHaããããµããŒããã以äžã®ãããªåçãããã ããŸããïŒ2017幎6æ28æ¥æç¹ïŒããã¡ããããã°ãžã®è»¢èŒã¯å¿«è«Ÿãããã ããŠãããŸãã
ãåãåããã®ä»¶ã«ã€ããŸããŠãConoHaã«ãããŸããŠã¯è匱æ§èšºæã«ãããäºåç³è«ã®å¿
èŠã¯ããããŸããã
ã客æ§ã®ãä»»æã§è¡ã£ãŠããã ããŠåé¡ããããŸããããæ€æ»ã«èµ·å ããŠä»ã®ã客æ§ãžã®åœ±é¿ãæžå¿µãããè² è·çãçºçããå Žåã¯ãµãŒãã¹ã®å¶éã宿œãããŠããã ãå¯èœæ§ãããããŸãããšãããããããäºæ¿ãã ããã
è² è·çã«ãããµãŒãã¹ã®å¶éãšãªãå¯èœæ§ãããããŸããããäºåã«åŒç€Ÿãžãç¥ããããã ãããšã§äœãåé¡ãçºçããéã®å¯Ÿå¿ãåæ»ããããšã¯å¯èœãšãªããŸãã
ãšããããšã§ããã¡ããVAddyãå©çšããéã®äºåç³è«ã¯äžèŠã§ãã
ãã¯ã©ãŠãã»ãšãïŒCloudnïŒã
éèŠäºé
ã«é¢ãã説æã«ã€ããŠ
ãã¡ãã®çŠæ¢äºé
ã®äžã«
æ¬ãµãŒãã¹ããåœç€ŸãæäŸããè³ç£ãžã®æ»æãã»ãã¥ãªãã£æ©æ§ã®ç Žå£è¡çºããããã¯èª¿æ»ãæœè¡ã
ãšã®èšèŒããããŸãããµããŒãã«ãåãåãããŸããããæ®å¿µãªããVAddyã§ã®èåŒ±æ§æ€æ»ã¯çŠæ¢ãšã®ããšã§ããã
VAddyã®æ€æ»æã®ãã©ãã£ãã¯ã£ãŠã©ããªã®ïŒ
å
ã»ã©VAddyã®æ€æ»ã§ã¯ã¯ã©ãŠãäºæ¥è
ã«åœ±é¿ãåºããããªãã©ãã£ãã¯ã¯çºçããªããšæžããŸããããå
·äœçã«ã¯ã©ããããã®ãã©ãã£ãã¯ãæ³å®ãããã®ã§ããããã
VAddyã®èåŒ±æ§æ€æ»ã«ãããŠãæ€æ»ãªã¯ãšã¹ãã䞊åã«éä¿¡ããããšã¯ãããŸããã1ã€ã®ãµãŒãã«å¯Ÿããæ€æ»ãªã¯ãšã¹ãã®éä¿¡åŸãã¬ã¹ãã³ã¹ã®åä¿¡å®äºãåŸ
ã£ãŠæ¬¡ã®æ€æ»ã«ç§»ããŸãã
æ€æ»ã®å®è¡ééã¯ãã¹ã察象ãµãŒãã®ã¬ã¹ãã³ã¹æéã«å€§ããäŸåããŸãããäŸãã°å¯Ÿè±¡ã®ãµãŒããŒãç§é2ãªã¯ãšã¹ããåŠçã§ãããšããŠãæ€æ»ãªã¯ãšã¹ããšã¬ã¹ãã³ã¹ãåèš500KBã®å Žåã¯ã1MB/secã®ãã©ãã£ãã¯ãçºçãããšããèšç®ã«ãªããŸãã
æ€æ»å¯Ÿè±¡ã¯åºæ¬çã«ç»åã§ã¯ãªãhtmlãjsonãã¡ã€ã«ãªã©ã®ãããå®éã«çºçãããã©ãã£ãã¯ã¯ãã£ãšå°ãªããã®ãã»ãšãã©ã§ãã
ãã®ããã«ãAWSãé€ããŠåœå
å€ã®äž»èŠã¯ã©ãŠããµãŒãã¹ã§VAddyã«ããè匱æ§èšºæãè¡ãéã®äºåç³è«ã¯äžèŠãšã®ããšã§ããã
å
šäœçã«æããã®ã¯åäºæ¥è
ãšãè匱æ§èšºæãè¡ã£ãéã®ããã©ãã£ãã¯éããæ°ã«ãããŠããããã§ãïŒåœããåãïŒã
VAddyã«ããèåŒ±æ§æ€æ»ã§ã¯ããã»ã©å€§éã®ãã©ãã£ãã¯ã¯çºçããŸããã®ã§ãã¡ãã£ãšå®å¿ã§ããã
äžèšã®æ
å ±ã¯ã¢ããããŒããããå¯èœæ§ããããŸãã®ã§ããå©çšã®éã¯ææ°æ
å ±ã確èªãããããšããªã¹ã¹ã¡ããŸãã
ãŸããããã¡ã®ãµãŒãã¹ãå
¥ã£ãŠããªãïŒããããã®ã¯ã©ãŠãäºæ¥è
ã«ã€ããŠã調ã¹ãŠïŒããšãããªã¯ãšã¹ããããããŸãããããé£çµ¡ãã ããã
åãåããã«å³ã¬ã¹ããã ããã¯ã©ãŠãäºæ¥è
ã®ãµããŒãçªå£ã®çæ§ããååããããšãããããŸããm(_ _)m