è»èŒECUã®ãµã€ããŒã»ãã¥ãªãã£ïŒ SELinuxãšHost Protectionã®ãã¯ãã«ãªçµåã
ECUã¯è»äž¡ã®ã€ã³ããªãžã§ã³ã¹ã»ããã§ãããã¡ãã£ã¢ããšã³ã¿ãŒãã€ã³ã¡ã³ããå€éšéä¿¡ãªã©ã®å¶åŸ¡ãæ ã£ãŠããŸãããœãããŠã§ã¢ã»ããã¡ã€ã³ãã»ããŒã¯ã«ïŒSDVïŒã®åºçŸã«ãããECUã¯çžäºæ¥ç¶ãããåæ¹åéä¿¡ãå€éšãããã¯ãŒã¯ãšã®éä¿¡ãè¡ãããã«ãªã£ãŠããŸãããã®ãããªã³ãã¯ãã£ããã£ã®åäžã¯ãæ©èœæ§ãšå©äŸ¿æ§ã®åäžãå¯èœã«ããäžæ¹ã§ããœãããŠã§ã¢ã®è匱æ§ããã®ä»ã®ãµã€ããŒè åšã«å¯Ÿããæ»æå¯Ÿè±¡ãæ¡å€§ãããŠããŸããŸãã
Linuxäžã§åäœããECUïŒAndroidäžã§åäœãããã®ããããŸãïŒã«ã¯ãSELinuxïŒSecurity-Enhanced LinuxïŒãšããŠç¥ããããªãŒãã³ãœãŒã¹ã®ä¿è·ã¬ã€ã€ãŒãä»å±ããŠããŸããSELinuxã¯ãœãããŠã§ã¢éçºè ã«ãšã£ãŠã¯å¹æçãªæ±çšããŒã«ã§ãããèªåè»ã®ãµã€ããŒã»ãã¥ãªãã£ã®èгç¹ããã¯ããã¹ãŠã®èŠä»¶ãæºãããŠãããšã¯èšããŸããããã®ãããå€ãã®OEMã¯ãè»èŒãããã¯ãŒã¯ãã³ã³ããŒãã³ããä¿è·ããæ°ããªèªåè»ãµã€ããŒã»ãã¥ãªãã£èŠå¶ãæšæºïŒISO 21434ãUNR 155ãäžåœã®GB/Tãªã©ïŒã«æºæ ããããã«ãäŸµå ¥æ€ç¥ã»é²åŸ¡ã·ã¹ãã ïŒIDPSïŒãå°å ¥ããŠããŸãã
ãã®èšäºã§ã¯ãè€éãªãµã€ããŒè åšããã³ãã¯ãããECUãä¿è·ããããã«ãOEMããã£ã¢1ãµãã©ã€ã€ãŒãSELinuxã«å ããŠã»ãã¥ãªãã£ãå¿ èŠãšããçç±ã«ã€ããŠèª¬æããŸãã
è»èŒçšéã«ãããSELinuxïŒ åŒ·ã¿ãšèª²é¡
SELinuxã¯Linuxã«ãŒãã«ã»ã»ãã¥ãªãã£ã»ã¢ãžã¥ãŒã«ã§ãããã·ã¹ãã 管çè ããŠãŒã¶ãŒãããã°ã©ã ããµãŒãã¹ã«å¯ŸããŠèšå®ããã¢ã¯ã»ã¹å¶åŸ¡ã»ãã¥ãªãã£ã»ããªã·ãŒã管çã»å®è¡ããããã®ã¡ã«ããºã ãæäŸããŸãããã®ãããSELinuxãæå¹ãªç°å¢å ã®ã¢ããªã±ãŒã·ã§ã³ã¯ãæå®ãããå¢çãè¶ ããŠã·ã¹ãã ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããšãã詊ã¿ããä¿è·ãããŸãããã®ã»ãŒãã¬ãŒãã¯ãã¢ããªã±ãŒã·ã§ã³ã®äžè²«ããå®å šãªåäœãä¿èšŒããŸãã
SELinuxã¯ãLinuxäžã§åäœããèªåè»çšECUã®ç®¡çãšã»ãã¥ãªãã£ã«ãããŠæ¥µããŠéèŠãªåœ¹å²ãæãããŠããŸããã·ã¹ãã ããã»ã¹ããã现ããå¶åŸ¡ããããã·ã§ã³ã¯ãªãã£ã«ã«ãªè»äž¡ã·ã¹ãã ã®ã»ãã¥ãªãã£ã匷åããŸãããã®æ©èœã¯ãé«åºŠåãããµã€ããŒè åšããè»èŒECUãä¿è·ããããšããOEMãšTier 1ãµãã©ã€ã€ãŒã®åæ¹ã«ãšã£ãŠæ¥µããŠéèŠã§ãã
ãããã匷ã¿ãããã«ãããããããèªåè»æ¥çã«ãããSELinuxã®å®è£ ã«é¢ããŠãããã€ãã®æ¥çç¹æã®èª²é¡ããããŸãïŒ
- æ©èœãæãªãããšãªãã»ãã¥ãªãã£ãæå€§åããããš – ãµã€ããŒã»ãã¥ãªãã£ãå®è£ ããéã«ã¯ãæ»æå¯Ÿè±¡é åãæå°åããããšïŒã€ãŸããã·ã¹ãã ãå¶éããããšïŒãšãéåžžã®ã·ã¹ãã æ©èœã«å¿ èŠãªæ©èœãèš±å¯ããããšã®éã§ãåžžã«ãã©ã³ã¹ãåãå¿ èŠããããŸããèšãæããã°ãç°åžžãªåäœã«å¯ŸããŠã·ã¹ãã ã匷åãããã«ãããããããæ¥åžžçãªéçšãå¯èœã«ããããã«ã·ã¹ãã ãååã«ãªãŒãã³ã«ããŠããå¿ èŠããããšããããšã§ãããã®ããã«ã¯ãããããã»ã¹ã«å¯ŸããŠã¯æ©èœãå¶éããå¥ã®ããã»ã¹ã«å¯ŸããŠã¯åãæ©èœãèš±å¯ãããšããæè»æ§ãå¿ èŠãšããããšã«ãªããŸãããããSELInuxã§å®çŸããã®ã¯é£ããããšã§ãã
- ãªã¢ã«ã¿ã€ã ã¬ã¹ãã³ã¹æ©èœã®å¿ èŠæ§ – SELinuxã®ãããªããŒããã³ã°ä¿è·ã¬ã€ã€ãŒã¯åªããŠããŸãããéçãªãã®ã§ãããæ¥éã«é²åããæ»æææ³ã«å¯Ÿå¿ããããã«ã¯æ§ç¯ãããŠããŸãããå¯Ÿç §çã«ãäžå¯ç¥è«çã§æè»ãªãœãªã¥ãŒã·ã§ã³ïŒäŸãã°ãSELinuxãEDRïŒEndpoint Detection and ResponseïŒãèªåè»åãIDPSãšçµã¿åãããïŒã¯ã宿çãªã¡ã³ããã³ã¹ãå¿ èŠãšããããšãªããåçãªæ¹æ³ã§å æ¬çã§è©³çްãªä¿è·ãæäŸããããšãã§ããŸãã
- ã»ãã¥ãªãã£ã»ã€ãã³ãã®ãã° – ããã¯SELinuxã®æšæºæ©èœã§ããããã§é£ããã®ã¯ããã°ãäœæãããåŸã®ãã³ããªã³ã°ã§ããã€ãã³ãã®åéãšä¿åããã£ã«ã¿ãªã³ã°ãåæã®ããã®ããã¯ãšã³ã管çã·ã¹ãã ãžã®éä¿¡ãªã©ãããã«åœãããŸãããã®äœæ¥ã¯ITã®èгç¹ããã¯ç°¡åãªããã«èããããããããŸããããå®éã®ãšãããã»ãšãã©ã®OEMã¯ãã®æ©èœããµããŒãããããšãã§ããŠããŸãããããã«ããã°ãåãããšã¯ãUNR155ãšGB/Tã«æºæ ããããã«å¿ èŠãªèŠä»¶ã§ãã
- ãªãŒãã³ãœãŒã¹ – ãªãŒãã³ãœãŒã¹ãœãããŠã§ã¢ã¯éçºè ã«ãšã£ãŠã¯çŽ æŽããããã®ã§ãããã»ãã¥ãªãã£ã®èгç¹ããã¯è«žåã®å£ãšãªãããŸããã³ãŒãã¯å®¹æã«å ¥æå¯èœã§ããããããã©ã®ããã«å®è£ ãããŠãããèŠããã®ã§ãç±å¿ãªããã«ãŒã¯æçµçã«ãã€ãã¹ããæ¹æ³ãèŠã€ããŸããSELinuxã¯æ§ã ãªç®çã«äœ¿çšã§ãããã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ã«å¿ èŠãªããã§ã¯ãªããããèšèšäžåãå€ãå¯èœã§ãããå·§åŠãªãã«ãŠã§ã¢ã«ãã£ãŠç¡å¹åãããæãããããŸãã
- ä¿å®æ§ – ãªãŒãã³ãœãŒã¹ã®ããäžã€ã®æ¬ ç¹ã¯ãé·æã«ããã£ãŠä¿å®ããå¿ èŠãããããšã§ããã¢ããªã±ãŒã·ã§ã³ãã¢ããã°ã¬ãŒããããã³ã«ãSELinuxãšã®äºææ§ããã§ãã¯ããå¿ èŠããããŸããäŸãã°ãSELinuxã®ãã°ãã£ãã¯ã¹ãšã¢ããã°ã¬ãŒããèªèãããããŠããããã®ã¢ããããŒãããµããŒãããããã«èªåã®ã³ãŒããé©å¿ãããã¢ããããŒãããå¿ èŠããããŸãããããã©ã€ãšã¿ãªãªãœãããŠã§ã¢ãšã¯å¯Ÿç §çã«ããªãŒãã³ãœãŒã¹ã¯ãµããŒããã¢ããã°ã¬ãŒããæäŸããŸããããããèŠå¶ã«æ°ããèŠä»¶ã远å ãããå Žåãèªåè»æ¥çã«ãµãŒãã¹ãæäŸãããœãããŠã§ã¢ãã³ããŒã¯ããã«ããã«å¯Ÿå¿ããŸãããªãŒãã³ãœãŒã¹ã䜿çšããå Žåãã€ã³ã¿ãŒãããäžã®ãã©ãŒã©ã ã«æ¯æŽãæ±ããããç¬èªã®ãªãœãŒã¹ã䜿çšããŠèŠä»¶ãæºããå¿ èŠããããŸãã
1å±€ã®ã»ãã¥ãªãã£ã§ã¯äžåå
äŸããŠèšããªããæåãªçŸè¡é€šãèŠåããå Žåãæ£éã«éµããããã ãã§ååãšã¯æããªãã®ã§ã¯ãªãã§ãããããã«ã¡ã©ãã¢ãŒã·ã§ã³ã»ã³ãµãŒãªã©ãäžæ£äŸµå ¥ãé²ãããã®è£ 眮ãèšçœ®ããããšã§ããããã»ãã¥ãªãã£ã®ã¬ã€ã€ãŒã1ã€ã«çµãã®ã¯å±éºããããšããããšã§ããçŸè¡é€šã«ãšã£ãŠããèªåè»ã«ãšã£ãŠããã»ãã¥ãªãã£ãäžãæã«é Œãããšã¯åãå ¥ããããŸããã
ãµã€ããŒã»ãã¥ãªãã£ã®åºæ¬çãªèãæ¹ã®ã²ãšã€ã¯ãåäžã®ä¿è·ã¬ã€ã€ãŒã§ã¯ãé¢é£ããæ»æãã¯ãã«ããšã¯ã¹ããã€ããã·ããªãªã®ãã¹ãŠã«å¯ŸåŠããã«ã¯äžååã ãšããããšã§ããç¹ã«SELinuxã¯ãåœç€Ÿã®ãªãµãŒãããŒã ãäœåºŠãå®èšŒããŠããããã«ãç°¡åã«ãã€ãã¹ãŸãã¯ç¡å¹ã«ããããšãã§ããŸããããããSELinuxã ããä¿è·ã¬ã€ã€ãŒãšããŠé Œãã¹ãã§ãªãããäžã€ã®éèŠãªçç±ã§ãã
èªåè»ã®ãµã€ããŒã»ãã¥ãªãã£èŠä»¶ãžã®å¯Ÿå¿
å€å±€é²åŸ¡ã¯ãè€æ°ã®ãã³ããŒã®ãœãããŠã§ã¢ãæ§ã ãªã³ã³ããŒãã³ãã§æ§æãããŠãã仿¥ã®ECUã«ãããŠç¹ã«å¿ èŠã§ãããã®ããã«å€æ§ã§éå±€åããããšã³ã·ã¹ãã ã¯ãçµ±åã®åé¡ãäºæãã¬ã»ãã¥ãªãã£è匱æ§ãåŒãèµ·ããå¯èœæ§ããããŸãããããã£ãŠOEMã¯ã詊è¡é¯èª€çã«ç¹å®ã®ããŒããã³ã°ãè¡ãã®ã§ã¯ãªããå æ¬çãªã»ãã¥ãªãã£ã€ã¡ãŒãžãæäŸããå šäœçãªã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãå¿ èŠãšããŠããŸãã
SELinuxã®ããªã·ãŒã¯ãäž»ã«æšæºçãªLinuxã®äœ¿çšãã©ãã€ã ãäžå¿ã«èšèšãããŠãããèªåè»åºæã®ããŒãºãšã¯å¿ ãããäžèŽããŠããŸããã詊è¡é¯èª€ã®ã¢ãããŒãã«åºã¥ãããšãå€ããèªåè»ã¢ããªã±ãŒã·ã§ã³ã«ç¹åããæ©èœãã·ã§ãŒãã«ãããæ¬ ããŠãããããèªåè»ã®ã»ãã¥ãªãã£ç¢ºä¿ã«å¿ èŠãªã·ããªãªããŠãŒã¹ã±ãŒã¹ïŒã«ãŒãã«ãã©ã¡ãŒã¿ã®ä¿è·ãªã©ïŒãå®çŸ©ããããšãå°é£ã§ãã
HostProtectionïŒIDPSïŒïŒ ECUãµã€ããŒã»ãã¥ãªãã£ã®ã®ã£ãããåãã
ãã®å€å±€é²åŸ¡ã¢ãããŒããåæ ããŠãå€ãã®OEMãSELinuxã®äžã«ECUã»ãã¥ãªãã£ã®è¿œå ã¬ã€ã€ãŒãšããŠHost IDPS Protectionãœãªã¥ãŒã·ã§ã³ãå°å ¥ããããšãéžæããŠããŸããHost Protectionã¯ãæ¢åã®SELinuxæ©èœãè£å®ããèªåè»ã»ãã¥ãªãã£ç¹æã®ããŒãºã«å¯Ÿå¿ããããã«èšèšãããŠããŸããã·ã³ãã«ã§ç°¡åã«èšå®ãå¯èœãªã«ãŒã«ã«åºã¥ããHost Protectionã¯ã峿 Œãªå®è¡å¶åŸ¡ãªã©ãSELinuxã察åŠã§ããªãããããã¯å¶åŸ¡ãå°é£ãªç¹å®ã®ã»ãã¥ãªãã£ã®ã£ãããåããŸãã
Host Protectionã¯ãSELinuxãšäœµããŠã以äžã®ã»ãã¥ãªãã£ã¬ã€ã€ãŒã远å ã§æäŸããããšã§ãOEMã«å®å šãªèªåè»ã°ã¬ãŒãã®ã·ã¹ãã ã»ãœãªã¥ãŒã·ã§ã³ãæäŸããŸãïŒ
- ä¿è· – Host IDPS Protectionã¯ããã¹ãŠã®å®è¡ãã¡ã€ã«ãšç¹æ®ãã¡ã€ã«ã®å®å šæ§ãšçæ£æ§ã確ä¿ããããšã§ãECUã®ä¿è·ã匷åããŸããã·ã¹ãã ã§å®è¡ãããåå®è¡ãã¡ã€ã«ã¯ãOEMã«ãã£ãŠçœ²åãããèšŒææžãšåäžã§ããå¿ èŠããããŸãããã¡ã€ã«ãžã®å€æŽãä¿®æ£ãæ€åºããããšããã®ãã¡ã€ã«ã¯ãããã¯ãããŸããããã«ãHost Protectionã§ã¯ãæ§ã ãªèªåè»ç¹æã®ã·ããªãªãã«ããŒããã«ãŒã«ãäœæãããã®æªçšã鲿¢ããããšãã§ããŸãã
- æ€ç¥ – å ã»ã©ã®äŸã«æ»ããšãä¿è·ã¬ã€ã€ãŒã¯ã²ãŒãã®ããã¯ãæ€åºã¬ã€ã€ãŒã¯çŸè¡é€šã®åšå²ãå éšã®ã«ã¡ã©ãã»ã³ãµãŒãšãªããŸããHost Protectionã·ã¹ãã ã¯éåžžãã·ã¹ãã ã®ç°åžžåäœãæç¥ããããšãã§ããECUäžã®ã»ã³ãµãŒã®ãã³ãã«ãå«ã¿ãŸããããã¯ãSELinuxèªäœãåé€ããããæ¹ãããããŠããªãããšã確èªããããã«ç£èŠããå°çšã»ã³ãµãŒãããããªã調æ»ãè¡ãããã«ã·ã¹ãã ã®æž¬å®å€ãCPU䜿çšçãªã©ãç£èŠããå°çšã»ã³ãµãŒãå«ãŸããŸãã
- ãã®ã³ã° – ãã®ã¬ã€ã€ãŒã¯ãã·ã¹ãã å ã®ãã¹ãŠã®SELinuxãã°ãšä»ã®ãã¹ãŠã®ã»ãã¥ãªãã£ã€ãã³ããåéã»ç®¡çããSEvsïŒã»ãã¥ãªãã£ã€ãã³ãïŒãšããŠIdsMïŒäŸµå ¥æ€ç¥ã·ã¹ãã ãããŒãžã£ãŒïŒãŸãã¯åéãšãã£ã«ã¿ãªã³ã°ã®ããã«èšå®ãããã·ã³ã¯ã«éä¿¡ããŸãã UNR 155ãšGB/Tã«ãã£ãŠçŸ©åä»ããããŠãããããã®éçšæ©èœã¯ãSELinuxã®åºæ¬çãªãã°æ©èœãè£å®ããŸãã
åè¿°ããããã«ããããã®åã¬ã€ã€ãŒã¯ãè»äž¡ãECUããµã€ããŒæ»æããä¿è·ãããšãšãã«ãååŒèªèšŒã®ããã®ãµã€ããŒã»ãã¥ãªãã£èŠä»¶ãžã®æºæ ãä¿é²ããããšããOEMã«ãšã£ãŠäžå¯æ¬ ãªãã®ã«ãªããŸãã
çµè«
SELinuxã¯éçºè ã«ãšã£ãŠåªãã䟡å€ãæäŸããŸãããLinuxããŒã¹ã®ECUãä¿è·ããèŠå¶èŠä»¶ãæºããããã«ã¯ãèªåè»ã°ã¬ãŒãã®ã»ãã¥ãªãã£ã®ã¬ã€ã€ãŒã远å ããŠè£å®ããå¿ èŠããããŸãã
SELinuxãšHost IDPS Protectionã®çµã¿åããã¯ãèªåè»ãµã€ããŒã»ãã¥ãªãã£ã«ããã匷åãªçžä¹å¹æãåŸãããŸããSELinuxã¯å ç¢ãªåºç€ãæäŸããHost Protectionã¯èªåè»æ¥çç¹æã®èª²é¡ã«å¯ŸåŠããããã«å¿ èŠãªã¢ãžãªãã£ãšç¹ç°æ§ãæäŸããŸãããã®äºéã®ã¢ãããŒãã«ãããèªåè»ã¯çŸåšã®ãµã€ããŒã»ãã¥ãªãã£ã®è åšã«å¯Ÿå¿ã§ããã ãã§ãªããå°æ¥ã®é²åãã課é¡ã«ãåããããšãã§ããŸãã
å·çïŒ2024幎06æ06æ¥