Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
応募課題(’25広島)
Search
BocchiMan
March 22, 2026
Education
980
0
Share
応募課題(’25広島)
BocchiMan
March 22, 2026
Other Decks in Education
See All in Education
【ZEPメタバース校舎操作ガイド】
ainischool
1
160
Visualisation Techniques - Lecture 8 - Information Visualisation (4019538FNR)
signer
PRO
1
2.9k
コマンドラインの使い方 / 01-d-cli
kaityo256
PRO
0
130
Introduction - Lecture 1 - Next Generation User Interfaces (4018166FNR)
signer
PRO
2
4.6k
Why the humanities may be your best career bet
figarospeech
0
150
この講義について / 00-setup
kaityo256
PRO
2
290
Analysis and Validation - Lecture 4 - Information Visualisation (4019538FNR)
signer
PRO
0
2.6k
環境・社会理工学院(建築学系)大学院説明会 2026|東京科学大学(Science Tokyo)
sciencetokyo
PRO
0
1.2k
事業紹介資料(トレーナー養成講座)
kentaro1981
0
130
Data Presentation - Lecture 5 - Information Visualisation (4019538FNR)
signer
PRO
1
3k
AI進化史:LLMからAIエージェントへ
mickey_kubo
0
100
Multimodal Interaction - Lecture 3 - Next Generation User Interfaces (4018166FNR)
signer
PRO
0
2.1k
Featured
See All Featured
職位にかかわらず全員がリーダーシップを発揮するチーム作り / Building a team where everyone can demonstrate leadership regardless of position
madoxten
62
53k
SEO in 2025: How to Prepare for the Future of Search
ipullrank
3
3.4k
The Art of Programming - Codeland 2020
erikaheidi
57
14k
Heart Work Chapter 1 - Part 1
lfama
PRO
5
35k
For a Future-Friendly Web
brad_frost
183
10k
A Guide to Academic Writing Using Generative AI - A Workshop
ks91
PRO
1
260
From π to Pie charts
rasagy
0
160
AI in Enterprises - Java and Open Source to the Rescue
ivargrimstad
0
1.2k
Designing Powerful Visuals for Engaging Learning
tmiket
1
320
Templates, Plugins, & Blocks: Oh My! Creating the theme that thinks of everything
marktimemedia
31
2.7k
The Illustrated Children's Guide to Kubernetes
chrisshort
51
52k
Put a Button on it: Removing Barriers to Going Fast.
kastner
60
4.2k
Transcript
ηΩϡϦςΟɾΩϟϯϓϛχ'25 ౡ։࠵ Ԡื՝ࡽ͠ ΅ͬͪ·Μ/ @forget1900
ʲ̍ʳ Ԡืಈػʹ͍ͭͯ
ճ ɹࢲ౷ܭղੳݚڀࣨʹॴଐ͠ɺ౷ܭֶͷࣝPythonɾRΛ༻͍ ͨσʔλੳΛֶश͍ͯ͠·͢ɻͱͱֶʹؔ৺͕͋Γࣗओ ֶशΛਐΊ͓ͯΓ·͕ͨ͠ɺେֶͷߨٛͰɺֶ͕҉߸ ཧූ߸ཧΛհͯ͠ใཧͱີʹ݁ͼ͍͍ͭͯΔ͜ͱΛ Γ·ͨ͠ɻಛʹɺֶతͳཧ͕͍͔ʹͯ͠ใͷ҆ఆ͔ͭਖ਼֬ͳ ୡΛ࣮ݱ͍ͯ͠Δͷ͔ͱ͍͏Έʹڧ͍ح৺Λ๊͍͍ͯ· ͢ɻɹຊϛχΩϟϯϓͷࢀՃΛ௨͡ɺ͜Ε·ͰֶΜͰ͖ͨཧ͕ ࣮ࣾձʹٕज़ͱͯ͠ͲͷΑ͏ʹ׆༻͞Ε͍ͯΔͷ͔Λਂֶ͘ͼͨ ͍ͱߟ͑ɺԠื͍ͨ͠·ͨ͠ɻ
ʲ͖̍ͭͮʳ ͜ͷߨٛͰֶΜͩ͜ͱΛԿʹཱ͍͔ͯͨ
ճ ɹຊߨٛΛ௨ͯ͡ɺใཧͷநతͳ֓೦͕ɺ࣮ࡍͷ௨৴σʔ λॲཧͷݱͰ۩ମతʹͲͷΑ͏ʹ׆༻͞Ε͍ͯΔͷ͔Λֶͼ͍ͨ ͱߟ͍͑ͯ·͢ɻ·ͨɺཧΛ࣮ʹམͱ͠ࠐΉࡍͷٕज़తͳ ɺݱࡏ໘͍ͯ͠Δ՝ͱͦͷରॲ๏ΛֶͿ͜ͱͰɺଟ֯తͳࢹ Λཆ͍͍ͨͰ͢ɻকདྷɺ͜͜ͰಘͨݟΛࣗͷݚڀʹ׆͔͢ ͱͱʹɺΑΓݎ࿚ͳ҉߸ٕज़ͷൃలʹߩݙͰ͖ΔਓࡐΛࢦ͠ ͍ͨͱߟ͍͑ͯ·͢ɻ
ʲ2ʳ TLS௨৴ʹ͓͍ͯɺΫϥΠΞϯταʔόʔ͔Βૹ৴͞Ε Δূ໌ॻͷݕূΛߦ͍·͢ɻ ͜ͷূ໌ॻݕূͷΈʹ͍ͭͯௐɺαʔόʔͷਖ਼ੑΛͲͷΑ ͏ͳखॱͰ֬ೝ͍ͯ͠Δͷ͔ɺॱংཱͯͯઆ໌͍ͯͩ͘͠͞ɻ
ճ(1/3) ɹTLS௨৴ʹ͓͍ͯɺΫϥΠΞϯτʢWebϒϥβʣଓઌͷ αʔόʔ͕ਅਖ਼ͳͷͰ͋Δ͔Λ֬ೝ͢ΔͨΊɺʮެ։伴ূ໌ॻʯ Λ༻͍ͨݕূΛߦ͍·͢ɻݕূͷྲྀΕʹ͍ͭͯҎԼͰઆ໌͢Δɻ 1. ূ໌ॻͷडྖͱ༗ޮੑͷ֬ೝ αʔόʔ͔Βૹ৴͞Εͨʮαʔόʔূ໌ॻʯΛड͚औΓɺ·ͣ༗ ޮظݶʢNot Before ʙ
Not AfterʣͰ͋Δ͜ͱΛ֬ೝ͠·͢ɻ ͋Θͤͯɺূ໌ॻ͕ࣦޮϦετʢCRLOCSPʣʹؚ·Ε͍ͯͳ͍ ͔νΣοΫ͠·͢ɻ
(2/3) 2. ॺ໊ͷݕূͱ৴པͷ࿈ͷ֬ೝ ূ໌ॻʹ༩͞Εͨσδλϧॺ໊ΛɺൃߦݩͰ͋ΔೝূہʢCAʣ ͷެ։伴Λ༻͍ͯݕূ͠·͢ɻ͜ͷࡍɺதؒೝূہ͔ΒɺOSϒ ϥβʹϓϦΠϯετʔϧ͞Ε͍ͯΔʮϧʔτCAূ໌ॻʯ·Ͱḷ Γɺ৴པͷ࿈ཱ͕͍ͯ͠Δ͔Λ֬ೝ͠·͢ɻ 3. υϝΠϯͷ߹ੑ֬ೝ ଓ͠Α͏ͱ͍ͯ͠ΔURLͷϗετ໊͕ɺূ໌ॻͷʮSubject
Alternative Name (SAN)ʯ·ͨʮCommon Name (CN)ʯʹه ࡌ͞Ε͍ͯΔ໊લͱҰக͢Δ͔Λর߹͠·͢ɻ
(3/3) 4. ݕূྃͱ҉߸Խ௨৴ͷ։࢝ ্هͷݕূ͕ͯ͢ޭͨ͠߹ɺΫϥΠΞϯταʔόʔΛਖ਼ ͳͷͱஅ͠·͢ɻͦͷޙɺڞ௨伴ͷڞ༗ʢTLSϋϯυγΣ ΠΫʣΛܧଓ͠ɺ҆શͳ҉߸Խ௨৴Λཱ֬͠·͢ɻ
ʲ3ʳ OWASP ASVSͱɺιϑτΣΞWebϓϩμΫτʹ͓͍ ͯɺͲͷΑ͏ͳׂΛͨ͢ϦετͰ͠ΐ͏͔ʁ LLMͳͲΛ༻͍ͳ͕Βௐɺࣗͷݴ༿Ͱ500จࣈҎ্Ͱ͑ͯ͘ ͍ͩ͞ɻ
ճ(1/4) OWASP ASVSʢApplication Security Verification Standardʣɺ ຊޠͰʮΞϓϦέʔγϣϯηΩϡϦςΟݕূඪ४ʯͱ༁͞Εɺ WebΞϓϦέʔγϣϯͷ҆શੑΛ٬؍తʹධՁɾ୲อ͢ΔͨΊͷ ʮڞ௨ͷͷ͞͠ʯͱͯ͠ͷׂΛՌͨ͠·͢ɻੈքతͳηΩϡϦ ςΟίϛϡχςΟͰ͋ΔOWASP͕ࡦఆ͓ͯ͠Γɺ։ൃऀηΩϡϦ
ςΟΤϯδχΞ͕ࢀর͖͢۩ମతͳཁ͕݅ମܥతʹ·ͱΊΒΕͯ ͍·͢ɻͦͷओͳׂҎԼͷ3ʹू͞Ε·͢ɻ
(2/4) ୈҰʹɺʮηΩϡϦςΟཁ݅ͷཏతͳΨΠυϥΠϯʯ ͱͯ͠ͷ ׂͰ͢ɻASVS୯ͳΔ੬ऑੑஅͷνΣοΫϦετʹཹ·Γ·ͤ ΜɻೝূɺΞΫηε੍ޚɺσʔλͷ҉߸ԽɺΤϥʔॲཧͳͲଟذʹ ΘͨΔ߲ʢϨϕϧ1Ͱ131߲ɺϨϕϧ3Ͱ286߲ʹٴͼ·͢ʣ Λཏ͓ͯ͠Γɺ͜ΕΒΛ։ൃͷઃܭஈ֊͔Βࢀর͢Δ͜ͱͰɺη ΩϡϦςΟΛޙ͚Ͱͳ͘ʮઃܭஈ֊͔ΒΈࠐΉʢSecurity by Designʣʯ͜ͱ͕ՄೳʹͳΓ·͢ɻ
(3/4) ୈೋʹɺʮϦεΫʹԠͨ͡ஈ֊తͳηΩϡϦςΟࢦඪʯ ͷఏڙͰ ͢ɻASVSͰɺΞϓϦέʔγϣϯͷॏཁʹԠͯ͡3ͭͷϨϕϧΛ ఆ͍ٛͯ͠·͢ɻશͯͷΞϓϦ͕࠷ݶຬ͖ͨ͢ʮϨϕϧ1ʯɺػ ີσʔλΛѻ͏ҰൠతͳϏδωεΞϓϦʹదͨ͠ʮϨϕϧ2ʯɺͦ͠ ͯॏཁΠϯϑϥ܉ࣄϨϕϧͷߴͳ৴པੑ͕ٻΊΒΕΔʮϨϕϧ 3ʯͰ͢ɻϨϕϧ্͕͕ΔʹͭΕɺݕূ߲͕૿͑Δ͚ͩͰͳ͘ɺ ݕূख๏มԽ͠·͢ɻྫ͑Ϩϕϧ1ͰϒϥοΫϘοΫεܗࣜͷ DASTʢಈతղੳʣ͕த৺Ͱ͕͢ɺϨϕϧ2Ҏ্ͰϗϫΠτϘοΫ
εܗࣜͷSASTʢ੩తղੳʣίʔυϨϏϡʔΛΈ߹ΘͤͨɺΑΓ ଟతͳݕূ͕ٻΊΒΕ·͢ɻ
(4/4) ୈࡾʹɺʮ৫֎ʹ͓͚Δίϛϡχέʔγϣϯͷඪ४Խʯ Ͱ͢ɻ ։ൃνʔϜͱஅϕϯμʔɺ͋Δ͍ൃݩͱडऀͷؒͰʮͲ͜ ·Ͱରࡦ͖͔͢ʯͱ͍͏߹ҙܗࠔΛۃΊ·͢ɻ͔͠͠ɺ ASVSΛڞ௨ݴޠͱͯ͠ಋೖ͢Δ͜ͱͰɺʮࠓճASVS Ϩϕϧ1ʹ ४ڌ͢Δʯͱ͍ͬͨ໌֬ͳඪઃఆ͕ՄೳʹͳΓɺ৫શମͷη ΩϡϦςΟϓϩηεͷಁ໌ੑͱ࣭Λ্ͤ͞ΔׂΛ୲͍·͢ɻ ͜ͷΑ͏ʹASVSɺٕज़తͳνΣοΫϦετͰ͋Δͱಉ࣌ʹɺ։
ൃɾӡ༻ɾධՁͷϥΠϑαΠΫϧશମΛ௨ͯ͡ιϑτΣΞͷ৴པ ੑΛࢧ͑ΔɺۃΊͯॏཁͳϑϨʔϜϫʔΫͰ͋Δͱݴ͑·͢ɻ