ç±³åœé£éŠæ¿åºæ©é¢ CISA ãæ°ããªæŠç¥ã§ãªãŒãã³ãœãŒã¹ ãœãããŠã§ã¢ã®ä¿è·ã匷調
ç±³åœé£éŠãµã€ããŒã»ãã¥ãªãã£ã»ã€ã³ãã©ã¹ãã©ã¯ãã£ã»ãã¥ãªãã£åº (CISA) ã¯ããªãŒãã³ãœãŒã¹ ãœãããŠã§ã¢ã®ã»ãã¥ãªãã£ã匷åããããã®ããŒã¹ããŒã³èšç»ãçºè¡šããŸããã

ç±³åœé£éŠCybersecurity & Infrastructure Security Agency (CISA)æè¿ããªãŒãã³ãœãŒã¹ ãœãããŠã§ã¢ (OSS) ã®ã»ãã¥ãªãã£ã匷åããããã®å æ¬çãªæŠç¥ãå°å ¥ããŸããããã®åãçµã¿ã¯ããµã€ããŒã»ãã¥ãªãã£ã®éèŠæ§ãåãäžãããã®åŒ·åã«åããæªçœ®ã瀺åãã2021幎5æã®ãžã§ãŒã»ãã€ãã³å€§çµ±é ã®å€§çµ±é 什ã«å¯ŸããéèŠãªå¯Ÿå¿ã§ããããã®åœä»€ä»¥æ¥ããããã®ãµã€ããŒã»ãã¥ãªãã£ç®æšãéæããããã®å¹æçãªã¬ã€ãã©ã€ã³ãäŒæ¥ã«æäŸãããšãã倧ããªåãããããŸããã
æ°ãã«çºè¡šãããããŒããããã¯ããããã®ãµã€ããŒã»ãã¥ãªãã£å¯Ÿçã匷åããããã®CISAã®åçã§ãããç¹ã« OSS ã®å®å šæ§ã«çŠç¹ãåœãŠãŠããŸãã
ååºã¯ãã€ãããŒã·ã§ã³ã®ä¿é²ãšãœãããŠã§ã¢éçºããã»ã¹ã®ä¿é²ã«ããã OSS ã®å€§ããªå¯èœæ§ãèªèããŠãããé£éŠæ¿åºå å€ã®äž¡æ¹ã§ãã®å®å šãªå®è£ ãšéçºãå¯èœã«ããããšåªããŠããŸãã
ãã®ããŒããããã§ã¯ããªãŒãã³ãœãŒã¹ ãœãããŠã§ã¢ã«é¢é£ãã 2 ã€ã®äž»èŠãªã¿ã€ãã®åœ±é¿ãæŠèª¬ããŠããŸãã 1 ã€ã¯ãåºã䜿çšãããŠãã OSS ã®è匱æ§ã®æœåšçãªæ³¢å广ã§ããLog4Shell ã€ã³ã·ãã³ãã«ä»£è¡šãããããã«ãOSS ã®äŸµå®³åŸã«åºç¯ãªæªåœ±é¿ã芳å¯ãããŸããã 2 çªç®ã®ã¿ã€ãã«ã¯ãOSS ãªããžããªã®ãµãã©ã€ ãã§ãŒã³ã«å¯Ÿããæ»æãå«ãŸããŸããããã«ãããéçºè ã®ã¢ã«ãŠã³ãã䟵害ãããæ»æè ãæªæã®ããã³ãŒããåã蟌ãããšãå¯èœã«ãªããªã©ãäžæµã«æå®³ãªåœ±é¿ãçããå¯èœæ§ããããŸãã
ãã®æŠç¥ã§ã¯ããªãŒãã³ãœãŒã¹ ã»ãã¥ãªãã£ã«ãããCISAã®æ¯æŽç圹å²ã®å®çŸ©ãOSS ã«é¢é£ããå©çšãšãªã¹ã¯ã®å¯èŠæ§ã®åäžãé£éŠæ¿åºãžã®ãªã¹ã¯ã®è»œæžããªãŒãã³ãœãŒã¹ ãšã³ã·ã¹ãã ã®åŒ·åãªã©ã4 ã€ã®äž»èŠãªåªå äºé ãå®ããŠããŸãã
CISA ããããã®æªçœ®ããªãŒãã³ãœãŒã¹ ãœãããŠã§ã¢ã®æ³å®ãã屿ã«è²¢ç®ãããšä¿¡ããŠããŸããååºã¯ãå ç¢ã§å€æ§ãã€ãã€ãããã¯ãªã³ãã¥ããã£ã«æ¯ãããããå®å šã§ããã ãã§ãªãæç¶å¯èœã§å埩åã®ãã OSS ãšã³ã·ã¹ãã ãæ§æ³ããŠããŸãã
ãµãã©ã€ ãã§ãŒã³ ã»ãã¥ãªãã£äŒæ¥ã§ãã Chainguard ã® CEO å Œå ±ååµèšè ã§ãã Dan Lorenc æ°ãããã®æèŠã«å調ããŸããåæ°ã¯CISAãã®åéã®èª²é¡ã詳现ã«åé¡ãããã®è§£æ±ºã«åªå é äœãä»ããŠããããšãç§°è³ãããåæ°ã¯ããã®äœæ¥ã¯ãäžæµãã§è¡ãããå¿ èŠããããè·å¡ã¯é¢é£ã³ãã¥ããã£ãšçŽæ¥é¢ããã¹ãã§ãããšããCISAã®èªèãé«ãè©äŸ¡ããŠãããåæ°ã¯ãã®ç¹ã®å®æœã«é¢ããŠè¥å¹²ã®äžç¢ºå®æ§ã衚æãããã®ã®ã楜芳çãªèŠæ¹ãç¶æããŠããã
Lorenc æ°ã¯ãæ¿åºã¯ãªãŒãã³ãœãŒã¹ ãããžã§ã¯ããžã®è³éæäŸãæ€èšãã¹ãã ãšææ¡ããŠããŸãããããã¯çŸåšããŒããããã§åãäžããããŠããªãããšã§ãããããã®ãããžã§ã¯ãã財æ¿çã«æ¯æŽããæ¿åºã®èœåã¯ãã¡ã¢ãªã®å®å šæ§ã®åŒ·åãè匱æ§ã®è§£æ±ºãSBOM ããŒã«ã®æ¹åãªã©ã®ç®æšãå€§å¹ ã«ä¿é²ããå¯èœæ§ããããŸãã
ããŒã¬ã³ã¯æ°ã¯ãŸããæ¿åºã®ååã¢ãã«ã¯ååçãªç®¡çãè¶ ããŠããããã®æªçœ®ã®æ¹åã«ç©æ¥µçã«è²¢ç®ãã¹ãã§ãããšè¿°ã¹ãã
AppMasterãªã©ã®ãã©ãããã©ãŒã ã¯ãå ç¢ãªã»ãã¥ãªãã£ãæè»æ§ãæé«çŽã®ãŠãŒã¶ãŒ ãšã¯ã¹ããªãšã³ã¹ãå ŒãåãããªãŒãã³ ãœãŒã¹ ãœãããŠã§ã¢ã«å€§ããäŸåããŠããŸãã圌ããåæ§ã®æžå¿µã衚æããŠããããã®ããŒãããããæåè£ã«å®æœãããããšãæåŸ ããŠããŸãã


