Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
応募課題(’25広島)
Search
BocchiMan
March 22, 2026
Education
980
0
Share
応募課題(’25広島)
BocchiMan
March 22, 2026
Other Decks in Education
See All in Education
Avoin jakaminen ja Creative Commons -lisenssit
matleenalaakso
0
2.1k
SSH公開鍵認証 / 02-b-ssh
kaityo256
PRO
0
140
Gesture-based Interaction - Lecture 6 - Next Generation User Interfaces (4018166FNR)
signer
PRO
1
2.1k
Introduction - Lecture 1 - Advanced Topics in Big Data (4023256FNR)
signer
PRO
2
2.3k
教育現場から見た Ruby on Rails
yasslab
PRO
0
110
演習:Gitの基本操作 / 04-git-basic
kaityo256
PRO
0
410
Interactive Tabletops and Surfaces - Lecture 5 - Next Generation User Interfaces (4018166FNR)
signer
PRO
1
2.1k
Introduction - Lecture 1 - Next Generation User Interfaces (4018166FNR)
signer
PRO
2
4.6k
GOBUSATA紹介
chankawa919
0
140
Science Tokyo国際卓越研究大学計画_202604
sciencetokyo
PRO
0
430
AI進化史:LLMからAIエージェントへ
mickey_kubo
0
110
PE testbench data order
songchch
0
480
Featured
See All Featured
Agile Actions for Facilitating Distributed Teams - ADO2019
mkilby
0
170
Building Adaptive Systems
keathley
44
3k
GraphQLの誤解/rethinking-graphql
sonatard
75
12k
Dominate Local Search Results - an insider guide to GBP, reviews, and Local SEO
greggifford
PRO
0
130
The Myth of the Modular Monolith - Day 2 Keynote - Rails World 2024
eileencodes
27
3.4k
Speed Design
sergeychernyshev
33
1.6k
What the history of the web can teach us about the future of AI
inesmontani
PRO
1
500
Mind Mapping
helmedeiros
PRO
1
140
Paper Plane
katiecoart
PRO
1
49k
Reflections from 52 weeks, 52 projects
jeffersonlam
356
21k
Breaking role norms: Why Content Design is so much more than writing copy - Taylor Woolridge
uxyall
0
240
The Art of Delivering Value - GDevCon NA Keynote
reverentgeek
16
1.9k
Transcript
ηΩϡϦςΟɾΩϟϯϓϛχ'25 ౡ։࠵ Ԡื՝ࡽ͠ ΅ͬͪ·Μ/ @forget1900
ʲ̍ʳ Ԡืಈػʹ͍ͭͯ
ճ ɹࢲ౷ܭղੳݚڀࣨʹॴଐ͠ɺ౷ܭֶͷࣝPythonɾRΛ༻͍ ͨσʔλੳΛֶश͍ͯ͠·͢ɻͱͱֶʹؔ৺͕͋Γࣗओ ֶशΛਐΊ͓ͯΓ·͕ͨ͠ɺେֶͷߨٛͰɺֶ͕҉߸ ཧූ߸ཧΛհͯ͠ใཧͱີʹ݁ͼ͍͍ͭͯΔ͜ͱΛ Γ·ͨ͠ɻಛʹɺֶతͳཧ͕͍͔ʹͯ͠ใͷ҆ఆ͔ͭਖ਼֬ͳ ୡΛ࣮ݱ͍ͯ͠Δͷ͔ͱ͍͏Έʹڧ͍ح৺Λ๊͍͍ͯ· ͢ɻɹຊϛχΩϟϯϓͷࢀՃΛ௨͡ɺ͜Ε·ͰֶΜͰ͖ͨཧ͕ ࣮ࣾձʹٕज़ͱͯ͠ͲͷΑ͏ʹ׆༻͞Ε͍ͯΔͷ͔Λਂֶ͘ͼͨ ͍ͱߟ͑ɺԠื͍ͨ͠·ͨ͠ɻ
ʲ͖̍ͭͮʳ ͜ͷߨٛͰֶΜͩ͜ͱΛԿʹཱ͍͔ͯͨ
ճ ɹຊߨٛΛ௨ͯ͡ɺใཧͷநతͳ֓೦͕ɺ࣮ࡍͷ௨৴σʔ λॲཧͷݱͰ۩ମతʹͲͷΑ͏ʹ׆༻͞Ε͍ͯΔͷ͔Λֶͼ͍ͨ ͱߟ͍͑ͯ·͢ɻ·ͨɺཧΛ࣮ʹམͱ͠ࠐΉࡍͷٕज़తͳ ɺݱࡏ໘͍ͯ͠Δ՝ͱͦͷରॲ๏ΛֶͿ͜ͱͰɺଟ֯తͳࢹ Λཆ͍͍ͨͰ͢ɻকདྷɺ͜͜ͰಘͨݟΛࣗͷݚڀʹ׆͔͢ ͱͱʹɺΑΓݎ࿚ͳ҉߸ٕज़ͷൃలʹߩݙͰ͖ΔਓࡐΛࢦ͠ ͍ͨͱߟ͍͑ͯ·͢ɻ
ʲ2ʳ TLS௨৴ʹ͓͍ͯɺΫϥΠΞϯταʔόʔ͔Βૹ৴͞Ε Δূ໌ॻͷݕূΛߦ͍·͢ɻ ͜ͷূ໌ॻݕূͷΈʹ͍ͭͯௐɺαʔόʔͷਖ਼ੑΛͲͷΑ ͏ͳखॱͰ֬ೝ͍ͯ͠Δͷ͔ɺॱংཱͯͯઆ໌͍ͯͩ͘͠͞ɻ
ճ(1/3) ɹTLS௨৴ʹ͓͍ͯɺΫϥΠΞϯτʢWebϒϥβʣଓઌͷ αʔόʔ͕ਅਖ਼ͳͷͰ͋Δ͔Λ֬ೝ͢ΔͨΊɺʮެ։伴ূ໌ॻʯ Λ༻͍ͨݕূΛߦ͍·͢ɻݕূͷྲྀΕʹ͍ͭͯҎԼͰઆ໌͢Δɻ 1. ূ໌ॻͷडྖͱ༗ޮੑͷ֬ೝ αʔόʔ͔Βૹ৴͞Εͨʮαʔόʔূ໌ॻʯΛड͚औΓɺ·ͣ༗ ޮظݶʢNot Before ʙ
Not AfterʣͰ͋Δ͜ͱΛ֬ೝ͠·͢ɻ ͋Θͤͯɺূ໌ॻ͕ࣦޮϦετʢCRLOCSPʣʹؚ·Ε͍ͯͳ͍ ͔νΣοΫ͠·͢ɻ
(2/3) 2. ॺ໊ͷݕূͱ৴པͷ࿈ͷ֬ೝ ূ໌ॻʹ༩͞Εͨσδλϧॺ໊ΛɺൃߦݩͰ͋ΔೝূہʢCAʣ ͷެ։伴Λ༻͍ͯݕূ͠·͢ɻ͜ͷࡍɺதؒೝূہ͔ΒɺOSϒ ϥβʹϓϦΠϯετʔϧ͞Ε͍ͯΔʮϧʔτCAূ໌ॻʯ·Ͱḷ Γɺ৴པͷ࿈ཱ͕͍ͯ͠Δ͔Λ֬ೝ͠·͢ɻ 3. υϝΠϯͷ߹ੑ֬ೝ ଓ͠Α͏ͱ͍ͯ͠ΔURLͷϗετ໊͕ɺূ໌ॻͷʮSubject
Alternative Name (SAN)ʯ·ͨʮCommon Name (CN)ʯʹه ࡌ͞Ε͍ͯΔ໊લͱҰக͢Δ͔Λর߹͠·͢ɻ
(3/3) 4. ݕূྃͱ҉߸Խ௨৴ͷ։࢝ ্هͷݕূ͕ͯ͢ޭͨ͠߹ɺΫϥΠΞϯταʔόʔΛਖ਼ ͳͷͱஅ͠·͢ɻͦͷޙɺڞ௨伴ͷڞ༗ʢTLSϋϯυγΣ ΠΫʣΛܧଓ͠ɺ҆શͳ҉߸Խ௨৴Λཱ֬͠·͢ɻ
ʲ3ʳ OWASP ASVSͱɺιϑτΣΞWebϓϩμΫτʹ͓͍ ͯɺͲͷΑ͏ͳׂΛͨ͢ϦετͰ͠ΐ͏͔ʁ LLMͳͲΛ༻͍ͳ͕Βௐɺࣗͷݴ༿Ͱ500จࣈҎ্Ͱ͑ͯ͘ ͍ͩ͞ɻ
ճ(1/4) OWASP ASVSʢApplication Security Verification Standardʣɺ ຊޠͰʮΞϓϦέʔγϣϯηΩϡϦςΟݕূඪ४ʯͱ༁͞Εɺ WebΞϓϦέʔγϣϯͷ҆શੑΛ٬؍తʹධՁɾ୲อ͢ΔͨΊͷ ʮڞ௨ͷͷ͞͠ʯͱͯ͠ͷׂΛՌͨ͠·͢ɻੈքతͳηΩϡϦ ςΟίϛϡχςΟͰ͋ΔOWASP͕ࡦఆ͓ͯ͠Γɺ։ൃऀηΩϡϦ
ςΟΤϯδχΞ͕ࢀর͖͢۩ମతͳཁ͕݅ମܥతʹ·ͱΊΒΕͯ ͍·͢ɻͦͷओͳׂҎԼͷ3ʹू͞Ε·͢ɻ
(2/4) ୈҰʹɺʮηΩϡϦςΟཁ݅ͷཏతͳΨΠυϥΠϯʯ ͱͯ͠ͷ ׂͰ͢ɻASVS୯ͳΔ੬ऑੑஅͷνΣοΫϦετʹཹ·Γ·ͤ ΜɻೝূɺΞΫηε੍ޚɺσʔλͷ҉߸ԽɺΤϥʔॲཧͳͲଟذʹ ΘͨΔ߲ʢϨϕϧ1Ͱ131߲ɺϨϕϧ3Ͱ286߲ʹٴͼ·͢ʣ Λཏ͓ͯ͠Γɺ͜ΕΒΛ։ൃͷઃܭஈ֊͔Βࢀর͢Δ͜ͱͰɺη ΩϡϦςΟΛޙ͚Ͱͳ͘ʮઃܭஈ֊͔ΒΈࠐΉʢSecurity by Designʣʯ͜ͱ͕ՄೳʹͳΓ·͢ɻ
(3/4) ୈೋʹɺʮϦεΫʹԠͨ͡ஈ֊తͳηΩϡϦςΟࢦඪʯ ͷఏڙͰ ͢ɻASVSͰɺΞϓϦέʔγϣϯͷॏཁʹԠͯ͡3ͭͷϨϕϧΛ ఆ͍ٛͯ͠·͢ɻશͯͷΞϓϦ͕࠷ݶຬ͖ͨ͢ʮϨϕϧ1ʯɺػ ີσʔλΛѻ͏ҰൠతͳϏδωεΞϓϦʹదͨ͠ʮϨϕϧ2ʯɺͦ͠ ͯॏཁΠϯϑϥ܉ࣄϨϕϧͷߴͳ৴པੑ͕ٻΊΒΕΔʮϨϕϧ 3ʯͰ͢ɻϨϕϧ্͕͕ΔʹͭΕɺݕূ߲͕૿͑Δ͚ͩͰͳ͘ɺ ݕূख๏มԽ͠·͢ɻྫ͑Ϩϕϧ1ͰϒϥοΫϘοΫεܗࣜͷ DASTʢಈతղੳʣ͕த৺Ͱ͕͢ɺϨϕϧ2Ҏ্ͰϗϫΠτϘοΫ
εܗࣜͷSASTʢ੩తղੳʣίʔυϨϏϡʔΛΈ߹ΘͤͨɺΑΓ ଟతͳݕূ͕ٻΊΒΕ·͢ɻ
(4/4) ୈࡾʹɺʮ৫֎ʹ͓͚Δίϛϡχέʔγϣϯͷඪ४Խʯ Ͱ͢ɻ ։ൃνʔϜͱஅϕϯμʔɺ͋Δ͍ൃݩͱडऀͷؒͰʮͲ͜ ·Ͱରࡦ͖͔͢ʯͱ͍͏߹ҙܗࠔΛۃΊ·͢ɻ͔͠͠ɺ ASVSΛڞ௨ݴޠͱͯ͠ಋೖ͢Δ͜ͱͰɺʮࠓճASVS Ϩϕϧ1ʹ ४ڌ͢Δʯͱ͍ͬͨ໌֬ͳඪઃఆ͕ՄೳʹͳΓɺ৫શମͷη ΩϡϦςΟϓϩηεͷಁ໌ੑͱ࣭Λ্ͤ͞ΔׂΛ୲͍·͢ɻ ͜ͷΑ͏ʹASVSɺٕज़తͳνΣοΫϦετͰ͋Δͱಉ࣌ʹɺ։
ൃɾӡ༻ɾධՁͷϥΠϑαΠΫϧશମΛ௨ͯ͡ιϑτΣΞͷ৴པ ੑΛࢧ͑ΔɺۃΊͯॏཁͳϑϨʔϜϫʔΫͰ͋Δͱݴ͑·͢ɻ