Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
応募課題(’25広島)
Search
BocchiMan
March 22, 2026
Education
1.3k
0
Share
応募課題(’25広島)
BocchiMan
March 22, 2026
More Decks by BocchiMan
See All by BocchiMan
セキュリティ・キャンプミニ@26in東京 Aトラック応募課題
forget1900
0
7
セキュリティ・キャンプミニ@26in東京 Bトラック応募課題
forget1900
0
6
Other Decks in Education
See All in Education
コミュニティを通じた_キャリア設計のススメ_20260424.pdf
masakiokuda
0
270
Gitがない時代 インターネットがない時代の 開発話
sapi_kawahara
0
110
この講義について / 00-setup
kaityo256
PRO
2
370
Data Physicalisation - Lecture 9 - Next Generation User Interfaces (4018166FNR)
signer
PRO
1
980
Laura Wilson - The Quarterly PR Pivot
laurawilsonbseo1
1
280
勾配ブースティングと決定木の話 / gradient boosting and decision trees
kaityo256
PRO
6
1.2k
AWS Certified Generative AI Developer - Professional Beta 不合格体験記
amarelo_n24
1
240
Course Review - Lecture 13 - Next Generation User Interfaces (4018166FNR)
signer
PRO
0
2.3k
2026年度春学期 統計学 第5回 分布をまとめるー記述統計量(平均・分散など) (2026. 5. 7)
akiraasano
PRO
0
110
JAWS-UG初心者支部#81 GWにEduJAWSと何か作ろうもくもく会!
otsuki
0
110
Design Guidelines and Principles - Lecture 7 - Information Visualisation (4019538FNR)
signer
PRO
0
3k
自己紹介 / who-am-i
yasulab
6
6.7k
Featured
See All Featured
Fantastic passwords and where to find them - at NoRuKo
philnash
52
3.7k
How People are Using Generative and Agentic AI to Supercharge Their Products, Projects, Services and Value Streams Today
helenjbeal
1
180
Thoughts on Productivity
jonyablonski
76
5.2k
10 Git Anti Patterns You Should be Aware of
lemiorhan
PRO
659
62k
Data-driven link building: lessons from a $708K investment (BrightonSEO talk)
szymonslowik
1
1.1k
Building an army of robots
kneath
306
46k
[SF Ruby Conf 2025] Rails X
palkan
2
1k
Fashionably flexible responsive web design (full day workshop)
malarkey
408
66k
From π to Pie charts
rasagy
0
180
Reality Check: Gamification 10 Years Later
codingconduct
0
2.1k
AI Search: Where Are We & What Can We Do About It?
aleyda
0
7.5k
Accessibility Awareness
sabderemane
1
120
Transcript
ηΩϡϦςΟɾΩϟϯϓϛχ'25 ౡ։࠵ Ԡื՝ࡽ͠ ΅ͬͪ·Μ/ @forget1900
ʲ̍ʳ Ԡืಈػʹ͍ͭͯ
ճ ɹࢲ౷ܭղੳݚڀࣨʹॴଐ͠ɺ౷ܭֶͷࣝPythonɾRΛ༻͍ ͨσʔλੳΛֶश͍ͯ͠·͢ɻͱͱֶʹؔ৺͕͋Γࣗओ ֶशΛਐΊ͓ͯΓ·͕ͨ͠ɺେֶͷߨٛͰɺֶ͕҉߸ ཧූ߸ཧΛհͯ͠ใཧͱີʹ݁ͼ͍͍ͭͯΔ͜ͱΛ Γ·ͨ͠ɻಛʹɺֶతͳཧ͕͍͔ʹͯ͠ใͷ҆ఆ͔ͭਖ਼֬ͳ ୡΛ࣮ݱ͍ͯ͠Δͷ͔ͱ͍͏Έʹڧ͍ح৺Λ๊͍͍ͯ· ͢ɻɹຊϛχΩϟϯϓͷࢀՃΛ௨͡ɺ͜Ε·ͰֶΜͰ͖ͨཧ͕ ࣮ࣾձʹٕज़ͱͯ͠ͲͷΑ͏ʹ׆༻͞Ε͍ͯΔͷ͔Λਂֶ͘ͼͨ ͍ͱߟ͑ɺԠื͍ͨ͠·ͨ͠ɻ
ʲ͖̍ͭͮʳ ͜ͷߨٛͰֶΜͩ͜ͱΛԿʹཱ͍͔ͯͨ
ճ ɹຊߨٛΛ௨ͯ͡ɺใཧͷநతͳ֓೦͕ɺ࣮ࡍͷ௨৴σʔ λॲཧͷݱͰ۩ମతʹͲͷΑ͏ʹ׆༻͞Ε͍ͯΔͷ͔Λֶͼ͍ͨ ͱߟ͍͑ͯ·͢ɻ·ͨɺཧΛ࣮ʹམͱ͠ࠐΉࡍͷٕज़తͳ ɺݱࡏ໘͍ͯ͠Δ՝ͱͦͷରॲ๏ΛֶͿ͜ͱͰɺଟ֯తͳࢹ Λཆ͍͍ͨͰ͢ɻকདྷɺ͜͜ͰಘͨݟΛࣗͷݚڀʹ׆͔͢ ͱͱʹɺΑΓݎ࿚ͳ҉߸ٕज़ͷൃలʹߩݙͰ͖ΔਓࡐΛࢦ͠ ͍ͨͱߟ͍͑ͯ·͢ɻ
ʲ2ʳ TLS௨৴ʹ͓͍ͯɺΫϥΠΞϯταʔόʔ͔Βૹ৴͞Ε Δূ໌ॻͷݕূΛߦ͍·͢ɻ ͜ͷূ໌ॻݕূͷΈʹ͍ͭͯௐɺαʔόʔͷਖ਼ੑΛͲͷΑ ͏ͳखॱͰ֬ೝ͍ͯ͠Δͷ͔ɺॱংཱͯͯઆ໌͍ͯͩ͘͠͞ɻ
ճ(1/3) ɹTLS௨৴ʹ͓͍ͯɺΫϥΠΞϯτʢWebϒϥβʣଓઌͷ αʔόʔ͕ਅਖ਼ͳͷͰ͋Δ͔Λ֬ೝ͢ΔͨΊɺʮެ։伴ূ໌ॻʯ Λ༻͍ͨݕূΛߦ͍·͢ɻݕূͷྲྀΕʹ͍ͭͯҎԼͰઆ໌͢Δɻ 1. ূ໌ॻͷडྖͱ༗ޮੑͷ֬ೝ αʔόʔ͔Βૹ৴͞Εͨʮαʔόʔূ໌ॻʯΛड͚औΓɺ·ͣ༗ ޮظݶʢNot Before ʙ
Not AfterʣͰ͋Δ͜ͱΛ֬ೝ͠·͢ɻ ͋Θͤͯɺূ໌ॻ͕ࣦޮϦετʢCRLOCSPʣʹؚ·Ε͍ͯͳ͍ ͔νΣοΫ͠·͢ɻ
(2/3) 2. ॺ໊ͷݕূͱ৴པͷ࿈ͷ֬ೝ ূ໌ॻʹ༩͞Εͨσδλϧॺ໊ΛɺൃߦݩͰ͋ΔೝূہʢCAʣ ͷެ։伴Λ༻͍ͯݕূ͠·͢ɻ͜ͷࡍɺதؒೝূہ͔ΒɺOSϒ ϥβʹϓϦΠϯετʔϧ͞Ε͍ͯΔʮϧʔτCAূ໌ॻʯ·Ͱḷ Γɺ৴པͷ࿈ཱ͕͍ͯ͠Δ͔Λ֬ೝ͠·͢ɻ 3. υϝΠϯͷ߹ੑ֬ೝ ଓ͠Α͏ͱ͍ͯ͠ΔURLͷϗετ໊͕ɺূ໌ॻͷʮSubject
Alternative Name (SAN)ʯ·ͨʮCommon Name (CN)ʯʹه ࡌ͞Ε͍ͯΔ໊લͱҰக͢Δ͔Λর߹͠·͢ɻ
(3/3) 4. ݕূྃͱ҉߸Խ௨৴ͷ։࢝ ্هͷݕূ͕ͯ͢ޭͨ͠߹ɺΫϥΠΞϯταʔόʔΛਖ਼ ͳͷͱஅ͠·͢ɻͦͷޙɺڞ௨伴ͷڞ༗ʢTLSϋϯυγΣ ΠΫʣΛܧଓ͠ɺ҆શͳ҉߸Խ௨৴Λཱ֬͠·͢ɻ
ʲ3ʳ OWASP ASVSͱɺιϑτΣΞWebϓϩμΫτʹ͓͍ ͯɺͲͷΑ͏ͳׂΛͨ͢ϦετͰ͠ΐ͏͔ʁ LLMͳͲΛ༻͍ͳ͕Βௐɺࣗͷݴ༿Ͱ500จࣈҎ্Ͱ͑ͯ͘ ͍ͩ͞ɻ
ճ(1/4) OWASP ASVSʢApplication Security Verification Standardʣɺ ຊޠͰʮΞϓϦέʔγϣϯηΩϡϦςΟݕূඪ४ʯͱ༁͞Εɺ WebΞϓϦέʔγϣϯͷ҆શੑΛ٬؍తʹධՁɾ୲อ͢ΔͨΊͷ ʮڞ௨ͷͷ͞͠ʯͱͯ͠ͷׂΛՌͨ͠·͢ɻੈքతͳηΩϡϦ ςΟίϛϡχςΟͰ͋ΔOWASP͕ࡦఆ͓ͯ͠Γɺ։ൃऀηΩϡϦ
ςΟΤϯδχΞ͕ࢀর͖͢۩ମతͳཁ͕݅ମܥతʹ·ͱΊΒΕͯ ͍·͢ɻͦͷओͳׂҎԼͷ3ʹू͞Ε·͢ɻ
(2/4) ୈҰʹɺʮηΩϡϦςΟཁ݅ͷཏతͳΨΠυϥΠϯʯ ͱͯ͠ͷ ׂͰ͢ɻASVS୯ͳΔ੬ऑੑஅͷνΣοΫϦετʹཹ·Γ·ͤ ΜɻೝূɺΞΫηε੍ޚɺσʔλͷ҉߸ԽɺΤϥʔॲཧͳͲଟذʹ ΘͨΔ߲ʢϨϕϧ1Ͱ131߲ɺϨϕϧ3Ͱ286߲ʹٴͼ·͢ʣ Λཏ͓ͯ͠Γɺ͜ΕΒΛ։ൃͷઃܭஈ֊͔Βࢀর͢Δ͜ͱͰɺη ΩϡϦςΟΛޙ͚Ͱͳ͘ʮઃܭஈ֊͔ΒΈࠐΉʢSecurity by Designʣʯ͜ͱ͕ՄೳʹͳΓ·͢ɻ
(3/4) ୈೋʹɺʮϦεΫʹԠͨ͡ஈ֊తͳηΩϡϦςΟࢦඪʯ ͷఏڙͰ ͢ɻASVSͰɺΞϓϦέʔγϣϯͷॏཁʹԠͯ͡3ͭͷϨϕϧΛ ఆ͍ٛͯ͠·͢ɻશͯͷΞϓϦ͕࠷ݶຬ͖ͨ͢ʮϨϕϧ1ʯɺػ ີσʔλΛѻ͏ҰൠతͳϏδωεΞϓϦʹదͨ͠ʮϨϕϧ2ʯɺͦ͠ ͯॏཁΠϯϑϥ܉ࣄϨϕϧͷߴͳ৴པੑ͕ٻΊΒΕΔʮϨϕϧ 3ʯͰ͢ɻϨϕϧ্͕͕ΔʹͭΕɺݕূ߲͕૿͑Δ͚ͩͰͳ͘ɺ ݕূख๏มԽ͠·͢ɻྫ͑Ϩϕϧ1ͰϒϥοΫϘοΫεܗࣜͷ DASTʢಈతղੳʣ͕த৺Ͱ͕͢ɺϨϕϧ2Ҏ্ͰϗϫΠτϘοΫ
εܗࣜͷSASTʢ੩తղੳʣίʔυϨϏϡʔΛΈ߹ΘͤͨɺΑΓ ଟతͳݕূ͕ٻΊΒΕ·͢ɻ
(4/4) ୈࡾʹɺʮ৫֎ʹ͓͚Δίϛϡχέʔγϣϯͷඪ४Խʯ Ͱ͢ɻ ։ൃνʔϜͱஅϕϯμʔɺ͋Δ͍ൃݩͱडऀͷؒͰʮͲ͜ ·Ͱରࡦ͖͔͢ʯͱ͍͏߹ҙܗࠔΛۃΊ·͢ɻ͔͠͠ɺ ASVSΛڞ௨ݴޠͱͯ͠ಋೖ͢Δ͜ͱͰɺʮࠓճASVS Ϩϕϧ1ʹ ४ڌ͢Δʯͱ͍ͬͨ໌֬ͳඪઃఆ͕ՄೳʹͳΓɺ৫શମͷη ΩϡϦςΟϓϩηεͷಁ໌ੑͱ࣭Λ্ͤ͞ΔׂΛ୲͍·͢ɻ ͜ͷΑ͏ʹASVSɺٕज़తͳνΣοΫϦετͰ͋Δͱಉ࣌ʹɺ։
ൃɾӡ༻ɾධՁͷϥΠϑαΠΫϧશମΛ௨ͯ͡ιϑτΣΞͷ৴པ ੑΛࢧ͑ΔɺۃΊͯॏཁͳϑϨʔϜϫʔΫͰ͋Δͱݴ͑·͢ɻ