セキュリティ用語集
メールおよび一般的なセキュリティの重要用語を一か所に。各項目をタップすると、CEO/CISO向けの要点をご覧いただけます。
攻撃の種類
피싱 (Phishing)▾信頼されている相手になりすまし、認証情報・金銭・機密情報を盗み取ろうとする欺瞞的なメッセージです。
侵害の大半は1通のメールから始まりますが、多くの組織は「スパムフィルターが防いでくれる」と過信しています。技術的な検知と従業員研修は、どちらか一方だけでは不十分です。 見落としがちな点: 従業員が不審に気づいても、「通報ボタン」とその後のトリアージ体制がなければ行動につながりません。通報→分類→フィードバックのループを必ず整備してください。
続きを読む →스피어 피싱 (Spear phishing)▾特定の個人・組織を狙い、調査した情報を用いて精巧に作り込まれた標的型フィッシングです。
経営層・財務・人事など権限の大きい少数が標的となるため、全社平均の検知率指標ではリスクが見えなくなります。攻撃者はSNSや企業サイトの公開情報を使って文脈を精緻化します。 見落としがちな点: VIPや財務担当者向けの専用保護ポリシーと、外部に露出している役員情報(メールアドレス・肩書き)の最小化を併せて行いましょう。
続きを読む →비즈니스 이메일 침해BEC▾経営層や取引先になりすまし、送金・口座変更・情報漏えいを誘導するソーシャルエンジニアリング攻撃です。添付やリンクを使わず、権限・緊急性・信頼を悪用します。
単独では最大の金銭的損失を招くベクトルです(1件あたり数千万円〜数億円)。マルウェアを使わないためウイルス対策やサンドボックスは無力で、「人によるプロセス」が最後の防衛線となります。 見落としがちな点: 技術だけでは防げません。一定額以上の送金・口座変更は必ず別チャネルでの二重承認を財務プロセスに組み込み、「緊急・極秘」という要求こそ疑うよう研修しましょう。
続きを読む →공급망 이메일 침해VEC▾信頼している取引先のアカウントが乗っ取られ、請求書の振込先口座がすり替えられるサプライチェーン型のBECです。
自社のセキュリティが万全でも、取引先のアカウントが侵害されれば「本物の取引先」から偽の請求書が届きます。既存のメールスレッドに自然に紛れ込むため検知が困難です。 見落としがちな点: 口座変更の連絡はメール返信ではなく、事前に登録済みの電話番号で逆確認し、取引先の振込先変更履歴を別途管理しましょう。
続きを読む →큐싱 (Quishing)▾QRコードの裏に悪意あるリンクを隠し、URLフィルターを回避するフィッシング手法です。
QRコードは画像であるため、既存のURL/リンク検査をそのまま通過してしまいます。さらに利用者はセキュリティの弱い私物スマートフォンでスキャンし、会社の管理範囲外に出てしまいます。 見落としがちな点: 導入を検討しているソリューションが、QR画像を実際に「デコード」して中のURLまで検査しているか必ず確認してください(多くの製品はこれができていません)。
続きを読む →스미싱 / 비싱 (Smishing / Vishing)▾SMS(スミッシング)や音声通話(ビッシング)を利用したフィッシングで、メール攻撃と組み合わされることもあります。
攻撃はチャネルをまたいで展開されます(メール→SMS→電話で信頼を積み上げる)。メールだけを守っても回避されてしまいます。 見落としがちな点: ヘルプデスクやコールセンターの本人確認手続きが甘いと、電話一本でパスワードやMFAがリセットされてしまいます。人を狙うソーシャルエンジニアリング対策の手順を点検しましょう。
続きを読む →스푸핑 (Spoofing)▾送信者アドレスや表示名を偽装し、正規の送信者に見せかける手法です。
自社ドメインがなりすまされると顧客・パートナーが被害を受け、その責任は自社ブランドに跳ね返ってきます。技術的な防御がなければ誰でも自社名でメールを送信できてしまいます。 見落としがちな点: DMARCを「モニターモード(p=none)」のまま放置しているケースが多く見られます。実際にブロックされるrejectポリシーまで段階的に引き上げましょう。
続きを読む →표시이름 사칭 (Display-name spoofing)▾実際の送信アドレスは異なるまま、表示名だけを経営層やブランド名になりすます手法です。
DMARCでも防げません。実際のドメインは正規のもので、「表示名」だけが偽装されているためです。アドレスが隠れがちなモバイル端末では特に騙されやすくなります。 見落としがちな点: SPF/DKIM/DMARCといった認証だけを信頼せず、経営層やブランドを騙る表示名の検知機能がソリューションに含まれているか確認しましょう。
続きを読む →유사 도메인 (Lookalike / Homoglyph)▾正規ドメインに酷似した偽装ドメインです(例: rnとm、0とoの見間違い)。
目視での判別はほぼ不可能で、攻撃者は使用直前にドメインを新規登録するため、レピュテーションベースのブロックもすり抜けます。 見落としがちな点: 事後検知だけでは手遅れです。自社ブランドに似たドメインを先回りして監視・登録・テイクダウンする体制を整えましょう。
続きを読む →계정 탈취ATO▾窃取した認証情報で正規のアカウントを乗っ取り、組織内部から攻撃を仕掛けることです。
正規アカウントから送信されるため認証・レピュテーションの両方を通過してしまい、内部拡散やVECへと発展します。最も危険な「信頼された送信者」による攻撃です。 見落としがちな点: ログイン保護(MFA)だけでなく、乗っ取り後の異常な振る舞い(あり得ない場所からのアクセス、大量送信、自動転送ルールの新規作成)の検知まで対応しましょう。
続きを読む →자격증명 탈취 (Credential harvesting)▾偽のログインページなどを使ってユーザー名・パスワードを収集する行為です。
従業員が会社と個人サイトで同じパスワードを使い回していれば、どこかで漏えいした認証情報が会社アカウントの鍵になってしまいます。 見落としがちな点: パスワードポリシーだけでは不十分です。MFAを全社で義務化し、ダークウェブ上の漏えい認証情報の監視で、すでに流出したアカウントを先回りして無効化しましょう。
続きを読む →제로데이 (Zero-day)▾パッチやシグネチャがまだ存在しない、新種の脆弱性・攻撃です。
定義上、シグネチャやレピュテーションでは防げません。「既知の悪性のもの」だけをブロックする防御は、真っ先に被害者になります。 見落としがちな点: 未知の脅威に備えた行動・文脈ベースの検知と、パッチ適用までの時間(露出ウィンドウ)を短縮する迅速なパッチ運用を併せて行いましょう。
続きを読む →AI 생성 피싱 (AI-Generated Phishing)▾An attack that uses large language models to mass-produce highly natural, personalized phishing emails free of grammatical errors.
앵글러 피싱 (Angler Phishing)▾A phishing technique using fake customer-support accounts on social media to approach complaining users and steal their information.
베이팅 (Baiting)▾A technique that lures victims into running malware themselves using enticing bait such as infected USB drives or free downloads.
브랜드 사칭 (Brand Impersonation)▾A technique that mimics a well-known brand's logo, design, and domain to deceive users with emails or sites that look authentic.
CEO 사기 (CEO Fraud)▾A common BEC variant in which an attacker impersonates a CEO or top executive to instruct finance staff to make urgent wire transfers.
클론 피싱 (Clone Phishing)▾A phishing technique that copies a legitimate previously delivered email and resends it with attachments or links swapped for malicious ones.
동의 피싱 (Consent Phishing)▾A phishing technique that tricks users into granting permissions to a malicious OAuth app, enabling data access without stealing passwords.
대화 가로채기 (Conversation Hijacking)▾An attack where adversaries monitor an ongoing business email conversation and inject themselves to alter payment details or commit fraud.
딥페이크 피싱 (Deepfake Phishing)▾An attack using AI-generated fake audio or video to impersonate executives in calls or voice messages to induce wire transfers or data leaks.
이메일 계정 탈취 (Email Account Takeover)ATO▾An attack where adversaries steal credentials to seize a legitimate email account and abuse it for internal impersonation or fraud.
기프트카드 사기 (Gift Card Scam)▾A common BEC social-engineering scam that impersonates an executive to urgently ask an employee to buy gift cards and send the codes.
호모그래프 공격 (Homograph Attack)IDN homograph▾An attack using visually identical Unicode characters (e.g., Cyrillic 'a' vs Latin 'a') to create fraudulent domains that look legitimate.
사칭 공격 (Impersonation Attack)▾A general class of attacks that masquerade as trusted persons, brands, or organizations so victims believe requests are legitimate.
송장 사기 (Invoice Fraud)▾A BEC-style financial fraud that sends fake or altered invoices to redirect payments to attacker-controlled accounts.
악성 첨부파일 (Malicious Attachment)▾An attack vector delivering malware or malicious macros hidden in email attachments such as documents or archives that infect upon opening.
악성 스팸 (Malspam)▾Spam email carrying malicious attachments or links, sent in bulk and serving as a primary vector for malware infections.
급여 가로채기 (Payroll Diversion)▾A BEC scam that impersonates an employee to ask HR or payroll to change direct-deposit details, diverting wages to an attacker's account.
파밍 (Pharming)▾An attack that redirects users to fraudulent websites via DNS poisoning or host-file manipulation even when they enter a legitimate address.
PhaaS (Phishing-as-a-Service)PhaaS▾A cybercrime business model that sells phishing infrastructure, kits, and hosting as a subscription service, lowering the barrier to attacks.
피싱 킷 (Phishing Kit)▾A pre-built package bundling fake login pages and collection scripts so non-experts can quickly deploy phishing sites.
프리텍스팅 (Pretexting)▾A social-engineering technique where an attacker fabricates a plausible scenario or false identity to gain a victim's trust and extract information.
퀴드 프로 쿠오 (Quid Pro Quo)▾A social-engineering technique that offers a service or benefit, such as fake tech support, in exchange for credentials or access.
리플라이 체인 공격 (Reply-Chain Attack)▾An email attack that inserts malicious links or attachments into an existing reply chain from a compromised account so recipients open them without suspicion.
섹스토션 이메일 (Sextortion Email)▾An extortion scam email that threatens to release supposed compromising sexual material unless the victim pays money such as Bitcoin.
스미싱 (Smishing)▾A phishing attack delivered via SMS text messages using malicious links or fraudulent prompts to deceive users.
사회공학 (Social Engineering)▾The manipulation of human psychology and trust, rather than technical vulnerabilities, to induce information disclosure or security bypass.
스팸 (Spam)▾Unsolicited bulk email sent without recipient consent, often abused as a vector for phishing or malware distribution.
스팸 폭탄 (Spam Bombing)email bombing▾An attack that floods a victim's inbox with massive email volume in a short time to bury legitimate security or fraud-alert notifications, often as a precursor to follow-on scams.
테일게이팅 (Tailgating)▾A physical social-engineering technique of following an authorized person into a restricted area without credentials, also known as piggybacking.
스레드 하이재킹 (Thread Hijacking)▾An attack that replies into an existing conversation thread from a compromised mailbox to insert malicious content while exploiting established trust.
타이포스쿼팅 (Typosquatting)▾Registering misspelled variants of popular domains to capture users who make typing errors and redirect them to malicious sites.
URL 리디렉션 피싱 (Open Redirect Phishing)▾A technique abusing open-redirect vulnerabilities on trusted sites so links appear legitimate but forward victims to malicious destinations.
보이스 피싱 (Vishing)▾A social-engineering attack that uses phone or voice calls to deceive victims into divulging personal or financial information.
음성 복제 사기 (Voice Cloning Fraud)▾A fraud technique where AI clones a target's voice from short samples to impersonate family or superiors and demand urgent money transfers.
워터링 홀 공격 (Watering Hole Attack)▾A targeted attack that compromises websites frequently visited by a target group to infect their visitors.
무기화된 문서 (Weaponized Document)▾An Office or PDF document manipulated with macros, exploits, or embedded objects to execute malware merely upon opening.
웨일링 (Whaling)▾A form of spear phishing that targets high-profile executives such as CEOs or CFOs to exploit their authority and access to funds.
メール認証
SPF▾送信ドメインがどのメールサーバーから送信できるかをDNSで宣言する認証方式です。
設定がなければ誰でも自社ドメインでメールを送信でき、正規のメールまでスパム扱いされてしまいます。DMARCの前提条件でもあります。 見落としがちな点: SPFには参照回数10回という制限があり、SaaSツールが増えるとひそかに破綻します。送信ツールを追加するたびにSPFレコードを点検しましょう。
続きを読む →DKIM▾メールに暗号署名を付与し、改ざんの有無を検証する認証方式です。
メールの到達性と改ざん防止の要であり、署名のないメールは受信側で疑われます。 見落としがちな点: 短い(1024ビット)鍵を長期間使い回し、ローテーションを行っていないケースが多く見られます。2048ビット鍵と定期的な鍵交換を運用項目として定めましょう。
続きを読む →DMARC▾SPF/DKIMの結果をポリシー(拒否/隔離)として強制し、レポートを受け取る標準規格です。
ドメインなりすましを防ぐ最も効果的な単一施策であり、取引・メール送信における事実上の必須要件になりつつあります。 見落としがちな点: 大半がp=none(モニターモード)のままで、実際には何もブロックしていません。レポートで正規の送信元を整理したうえで、quarantine→rejectまで必ず引き上げましょう。
続きを読む →ARC▾メールが中継サーバーを経由する際、認証結果を保持・再署名して引き継ぐチェーン方式です。
メーリングリストや転送を経由するとSPF/DKIMが崩れ、正規のメールがブロックされることがありますが、ARCはこの誤検知を減らし業務上の摩擦を軽減します。 見落としがちな点: DMARCをrejectに引き上げる際、転送シナリオを検証しないと正規の業務メールが大量にブロックされる可能性があります。導入前に転送経路をテストしましょう。
続きを読む →MX 레코드 (MX record)▾ドメインの受信メールサーバーを指すDNSレコードで、インライン型ゲートウェイはこれを書き換えます。
インライン(ゲートウェイ)型セキュリティを導入すると、メールの流れがそのセキュリティシステムを経由するようになり、そのシステム自体が単一障害点になります。 見落としがちな点: 可用性(冗長構成)と障害時のメールキューイングポリシーを契約・設計段階で確認しましょう。セキュリティシステムが停止すると全社のメールが止まりかねません。
続きを読む →BIMI (Brand Indicators for Message Identification)BIMI▾A standard that displays a brand's verified logo next to authenticated messages in the inbox for domains passing DMARC, with the logo validated via DNS and a Verified Mark Certificate.
DANE (DNS-based Authentication of Named Entities)DANE▾A protocol that binds TLS certificates or public keys to DNS names using DNSSEC-protected TLSA records, enabling verification of server certificates for protocols such as SMTP without relying solely on CAs.
DKIM 셀렉터 (DKIM Selector)▾An identifier used to distinguish among multiple DKIM keys for a domain; the corresponding public key is published at the DNS location selector._domainkey.domain.
DMARC 집계 리포트 (DMARC Aggregate Report / RUA)RUA▾A periodic XML report sent by receiving servers to a domain owner, summarizing statistics on SPF, DKIM, and DMARC authentication results for the domain's mail.
DMARC 정렬 (DMARC Alignment)▾The core DMARC requirement that the domain authenticated by SPF or DKIM match the domain in the message's From header, evaluated in strict or relaxed mode.
DNSSEC (Domain Name System Security Extensions)DNSSEC▾Extensions that add digital signatures to DNS responses to provide data integrity and origin authentication, preventing DNS spoofing and cache poisoning and underpinning DANE.
순방향 비밀성 (Forward Secrecy)PFS▾A TLS property using ephemeral per-session keys so that even if a long-term private key is later compromised, previously recorded encrypted traffic cannot be decrypted.
MTA-STS (SMTP MTA Strict Transport Security)MTA-STS▾A mechanism letting a domain publish, over HTTPS, a policy requiring TLS encryption and certificate validation for inbound SMTP connections, defending against downgrade and man-in-the-middle attacks.
OpenPGP▾An open standard for email encryption derived from PGP (RFC 4880 and successors) that defines message and key formats so implementations like GnuPG can interoperate.
PGP (Pretty Good Privacy)PGP▾A public-key cryptography program for encrypting and signing email and files, using a web-of-trust model to validate keys.
리턴 패스 (Return-Path)▾The envelope sender (MAIL FROM) address of an email, where bounce messages are returned, and whose domain is the basis for SPF verification and DMARC alignment.
S/MIME (Secure/Multipurpose Internet Mail Extensions)S/MIME▾A standard for end-to-end signing and encryption of email messages using X.509 certificate-based public-key cryptography, providing message integrity, authentication, and confidentiality.
SMTP (Simple Mail Transfer Protocol)SMTP▾The standard internet protocol for transmitting email between mail servers and from clients to servers; plaintext by default, it is secured with STARTTLS or SMTPS.
SMTPS (SMTP over TLS)SMTPS▾A method of encrypting SMTP with TLS from the start of the connection (implicit TLS, typically port 465), encrypting from the outset rather than via the opportunistic upgrade of STARTTLS.
SPF 레코드 (SPF Record)▾A DNS TXT record listing a domain's authorized sending mail servers, beginning with v=spf1 and composed of mechanisms like include, a, mx, ip4 and qualifiers such as -all.
STARTTLS▾A command that opportunistically upgrades an existing plaintext protocol connection to a TLS-encrypted one, used in SMTP, IMAP, and POP3 to secure the transport while keeping standard ports.
TLS-RPT (SMTP TLS Reporting)TLS-RPT▾A standard that lets domains using MTA-STS or DANE receive daily aggregate reports from sending mail servers about TLS negotiation successes and failures.
VMC (Verified Mark Certificate)VMC▾A digital certificate issued by an authority that verifies a brand's trademark rights to a logo, used in BIMI to display a validated logo in the inbox.
アーキテクチャ・導入
보안 이메일 게이트웨이SEG▾MXレコードの手前に配置し、配送前にメールをフィルタリングする従来型のインライン方式です。
配送前のブロックは強力ですが侵襲的であり、すでに受信箱に届いているメール(社内間)や、乗っ取りアカウントによる攻撃は見えません。 見落としがちな点: SEGがあれば安心と思いがちですが、BECや内部拡散は死角になります。API方式(ICES)による可視化で補完できているか点検しましょう。
続きを読む →통합 클라우드 이메일 보안ICES▾M365/Workspaceに API 経由で連携し、配送後にスキャン・是正を行う現代的な方式です(MX変更不要)。
MX変更不要で5分で導入でき、ダウンタイムもないため価値実現が早く、社内メールも可視化できます。市場における現在の主流の方向性です。 見落としがちな点: 「配送後」方式であるため、ユーザーが先に開封してしまう短い時間差が存在します。クロークバック(自動回収)の速度と、高リスク案件のブロックポリシーを確認しましょう。
続きを読む →저널링 (Journaling)▾すべてのメールのコピーをセキュリティシステムに転送し、業務を止めずに監視・監査を行う仕組みです。
メールの流れに一切影響を与えないため導入リスクがほぼなく、価値検証(PoC)や監査の入り口として理想的です。 見落としがちな点: ジャーナリングは「見る」だけで「止める」ことはできません。モニタリングで終わらせず、価値検証後にインラインでのブロックへ移行する計画も併せて立てましょう。
続きを読む →샌드박스 (Sandbox)▾疑わしい添付ファイルやリンクを隔離環境で実行し、悪性の挙動を観察する動的解析手法です。
未知の悪性添付ファイルには有効ですが、解析に時間がかかり、巧妙なマルウェアはサンドボックスを認識して挙動を隠すこともあります。 見落としがちな点: サンドボックスは添付・リンク中心であるため、添付のないBECには無力です。サンドボックスだけでメールセキュリティが完結していると考えないでください。
続きを読む →콘텐츠 무해화·재구성CDR▾添付ファイルからマクロなどの能動的な要素を除去し、安全な形に再構成して配送する仕組みです。
「解析して判断する」のではなく「危険要素そのものを除去する」ため、ゼロデイの添付ファイルにも強い対策です。 見落としがちな点: マクロや埋め込み機能が除去されると業務用文書が破損する場合があります。財務・設計などマクロに依存する部門への影響と例外ポリシーを事前に合意しておきましょう。
続きを読む →데이터 주권 (Data sovereignty)▾データをその管轄区域の法律・管理下に留めることで、オンプレミスやリージョン内配備によって実現します。
規制(個人情報保護法など)への準拠と顧客の信頼の要であり、公共・金融分野の取引では成約を左右します。 見落としがちな点: 「クラウドセキュリティ」を謳う製品でも、メール本文を海外の外部LLMやリージョンに送信している場合があります。データが実際にどこで処理・保存されているか(特にAI推論)を必ず確認しましょう。
続きを読む →백스캐터 (Backscatter)▾Collateral spam in which bounce messages or auto-replies to spam with forged sender addresses flood innocent third parties.
외부 발신 배너 경고 (External Sender Banner)▾A security control that inserts a warning banner at the top of messages from outside the organization to raise user awareness.
사후 회수·교정 (Post-Delivery Remediation)▾A core ICES capability that automatically retracts or removes messages already delivered to inboxes once they are found malicious, via API (clawback).
연결 제한 (Connection Throttling)▾A mail server control that limits SMTP connection or send rates per source IP or domain to mitigate spam, abuse, and overload.
이메일 연속성 (Email Continuity)▾An availability and disaster-recovery capability ensuring users can send and receive email even during a primary mail system outage.
이메일 데이터 유출 방지 (Email Data Loss Prevention)DLP▾A technology that inspects outbound email content to detect, block, or encrypt unauthorized transmission of sensitive data.
이메일 암호화 게이트웨이 (Email Encryption Gateway)▾A gateway solution that automatically encrypts outbound email according to policy to protect sensitive information.
이메일 격리 (Email Quarantine)▾A feature that holds suspected spam, malware, or phishing email in a separate quarantine area instead of the inbox for admin or user review.
이메일 샌드박스 (Email Sandbox)▾A technology that detonates suspicious attachments or URLs in an isolated virtual environment to dynamically analyze malicious behavior.
이메일 스풀링 (Email Spooling)▾A capability that temporarily stores mail on a backup server when the destination is down and re-delivers it after recovery to prevent loss.
그레이리스팅 (Greylisting)▾A technique that temporarily rejects email from unknown senders, relying on legitimate MTAs to retry, thereby filtering out spambots.
인터넷 메시지 접근 프로토콜 (Internet Message Access Protocol)IMAP▾An email retrieval protocol that keeps messages on the server and allows synchronized access across multiple devices.
인라인 대 API 배포 (Inline vs API Deployment)▾The two email security deployment models: inline, which sits in the mail flow to block in transit, versus API-based, which integrates with mailbox APIs to act post-delivery.
메일 큐 (Mail Queue)▾A queue within an MTA that temporarily holds email that cannot be delivered immediately and manages retries.
메일 배달 에이전트 (Mail Delivery Agent)MDA▾Software that delivers email received from an MTA into the recipient's mailbox.
메일 제출 에이전트 (Mail Submission Agent)MSA▾A server that receives outgoing mail from clients, applies authentication and policy checks, and hands it to an MTA, typically over port 587.
메일 전송 에이전트 (Mail Transfer Agent)MTA▾Software that transfers and routes email between mail servers using SMTP.
메일 사용자 에이전트 (Mail User Agent)MUA▾Client software that lets users compose, read, and manage email, commonly known as an email client.
포스트 오피스 프로토콜 3 (Post Office Protocol 3)POP3▾An email retrieval protocol that downloads messages from the server to a local client, typically removing them from the server.
실시간 블랙홀 목록 (Realtime Blackhole List)RBL▾A reputation-based blocklist of IP addresses known to send spam, queried via DNS to reject mail.
평판 필터링 (Reputation Filtering)▾A filtering technique that uses reputation scores based on the historical behavior of sending IPs or domains to block or allow mail.
스마트호스트 (Smarthost)▾A designated external relay server through which a mail server routes all outbound email instead of delivering directly to destinations.
SMTP 릴레이 (SMTP Relay)▾The process by which one mail server forwards email through another, which if misconfigured can be abused as an open relay.
SMTP 스머글링 (SMTP Smuggling)▾An attack technique that exploits differing interpretations of message-end sequences between sending and receiving servers to inject spoofed email.
SMTP TLS (STARTTLS)TLS▾Encrypting an SMTP connection via the STARTTLS command to protect message content in transit.
SMTPS 포트 465 (Implicit TLS SMTP)SMTPS▾An SMTP submission port using implicit TLS where encryption applies from the start of the connection.
제출 포트 587 (Submission Port 587)▾The standard SMTP submission port used by authenticated clients to submit mail, distinct from port 25 used for relaying.
클릭 시점 보호 (Time-of-Click Protection)▾A protection that re-evaluates a link's safety at the moment a user clicks it, catching URLs weaponized after delivery.
전송 규칙 (Mail Flow/Transport Rule)▾A mail flow policy rule that evaluates conditions on email and automatically applies actions such as blocking, redirecting, adding headers, or encryption.
URL 재작성 (URL Rewriting)▾A technique that rewrites links in email to point to a security proxy so their safety is checked in real time at click time.
運用・SOC
SIEM▾セキュリティイベント・ログを集約し相関分析するプラットフォームです(Splunk、Sentinelなど)。
セキュリティの可視性と規制対応(監査ログ)の中核であり、メールの判定結果を流し込むことで攻撃の全体像が一箇所に集まります。 見落としがちな点: ログを蓄積するだけで見られていなければコストがかかるだけです。どのアラートに誰がどう対応するか(ルール・担当・SLA)まで定義して初めてSIEMは機能します。
続きを読む →SOAR▾アラートへの対応を自動化・オーケストレーションする仕組みです。
アラートが急増する環境で人手に代わって定型対応を自動化できるため、人員削減と対応速度の面でROIが大きい施策です。 見落としがちな点: 精査されていないアラートを自動化すると誤りも自動化されてしまいます。信頼度の高いシナリオから段階的に導入し、人による確認ステップ(ヒューマン・イン・ザ・ループ)を残して始めましょう。
続きを読む →침해 지표IOC▾侵害を示唆する痕跡です(悪性IP・ドメイン・ハッシュ値など)。
脅威共有・ブロックの基本単位ですが、IOCは「すでに知られている過去」であるため新しい攻撃には一歩遅れます。 見落としがちな点: IOCによるブロックだけに頼らず、行動・意図に基づく検知(TTP)も併せて備え、初めて見る攻撃も捕捉できるようにしましょう。
続きを読む →격리 (Quarantine)▾危険と判定されたメールを受信箱から隔離(移動・保留)する是正措置です。
実質的な防御アクションですが、誤検知で正規のメールが隔離されると業務上の摩擦とセキュリティチームへの不信につながります。 見落としがちな点: ユーザーによるセルフ解除、レビューキュー、解除SLAといった運用ポリシーがなければ、隔離は「メールが消えた」というクレームに直結します。運用プロセスも併せて設計しましょう。
続きを読む →다중요소 인증MFA▾パスワードに加えて追加の認証要素を要求し、アカウント乗っ取りを軽減する仕組みです。
費用対効果が最も高い単一の統制策であり、全社導入を最優先課題とすべきです。 見落としがちな点: SMSやプッシュ通知型のMFAはAiTMやMFA疲労攻撃に破られます。高リスクのアカウントから、フィッシング耐性のあるMFA(パスキー/FIDO2)へアップグレードしましょう。
続きを読む →지능형 지속 위협 (Advanced Persistent Threat)APT▾A targeted adversary that uses sophisticated techniques to maintain stealthy, long-term access. It is often associated with nation-state actors.
경보 피로 (Alert Fatigue)▾The desensitization of analysts caused by an overwhelming volume of alerts, leading to missed critical threats. It is a major challenge in SOC operations.
감사 로그 (Audit Log)▾A chronological record of activities and changes within a system. It is essential for accountability and post-incident investigation.
블루팀 (Blue Team)▾A defensive team responsible for protecting assets and detecting and responding to attacks. They are the core staff of SOC operations.
침해 통지 (Breach Notification)▾The mandatory process of informing regulators and affected individuals when a data breach occurs. It is required under regulations such as GDPR and data protection laws.
증거 연속성 (Chain of Custody)▾The documented chronological handling of digital evidence to ensure its integrity. It is essential for legal admissibility.
명령제어 (Command and Control)C2▾The communication channel and infrastructure attackers use to remotely control compromised systems. It is used for data exfiltration and issuing further commands.
침해사고대응팀 (Computer Emergency Response Team)CERT▾A specialized organization that receives, coordinates, and responds to security incidents. They operate at national, sector, and organizational levels.
컴퓨터보안사고대응팀 (Computer Security Incident Response Team)CSIRT▾A dedicated team responsible for handling security incidents within an organization. It performs detection, analysis, recovery, and post-incident activities.
사이버 킬 체인 (Cyber Kill Chain)▾A model defined by Lockheed Martin describing the stages of a cyberattack. It breaks an attack into seven phases from reconnaissance to actions on objectives.
데이터 유출 (Data Exfiltration)▾The unauthorized transfer of data from inside an organization to an external destination. It is often the ultimate goal of an attack.
디지털 포렌식·사고대응 (Digital Forensics and Incident Response)DFIR▾A field combining forensic investigation with incident response. It simultaneously determines root cause and drives rapid remediation.
디지털 포렌식 (Digital Forensics)▾The discipline of collecting, preserving, and analyzing digital evidence to determine the cause and course of an incident. It emphasizes legal admissibility.
엔드포인트 탐지·대응 (Endpoint Detection and Response)EDR▾A solution that continuously monitors endpoint activity to detect, investigate, and respond to threats. It uses behavioral analysis to identify advanced attacks.
오탐 (False Positive)FP▾An alert that incorrectly flags benign activity as a threat. Excessive false positives cause analyst fatigue and alert dismissal.
일반 개인정보보호법 (General Data Protection Regulation)GDPR▾The European Union's regulation on personal data protection and processing. It includes breach notification obligations and strong penalties.
거버넌스·위험·컴플라이언스 (Governance, Risk and Compliance)GRC▾An integrated approach to managing an organization's governance, risk management, and regulatory compliance. It aligns security decisions with business objectives.
사고대응 (Incident Response)IR▾The structured process of detecting, containing, eradicating, and recovering from security incidents. Its goal is to minimize damage and restore normal operations.
공격지표 (Indicator of Attack)IOA▾Indicators that reveal an attacker's intent and behavioral patterns. They focus on detecting an attack in progress before compromise completes.
ISO/IEC 27001ISO 27001▾An international standard for information security management systems (ISMS). It requires risk-based controls and continual improvement.
횡적 이동 (Lateral Movement)▾A technique where an attacker expands access from a compromised system to others within the network. It is used to reach target assets.
로그 관리 (Log Management)▾The practice of collecting, storing, analyzing, and retaining system and application logs. It underpins detection, forensics, and compliance.
평균 탐지 시간 (Mean Time to Detect)MTTD▾The average time taken to detect a security incident after it occurs. It is a key metric for SOC detection performance.
평균 대응 시간 (Mean Time to Respond)MTTR▾The average time taken to respond to and remediate an incident after detection. It measures response efficiency.
MITRE ATT&CKATT&CK▾A globally accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. It serves as a common framework for detection and defense.
네트워크 탐지·대응 (Network Detection and Response)NDR▾A solution that analyzes network traffic to detect and respond to anomalous behavior and threats. It excels at identifying lateral movement and stealthy attacks.
NIST 사이버보안 프레임워크 (NIST Cybersecurity Framework)NIST CSF▾A cybersecurity management framework from the U.S. NIST organized around Identify, Protect, Detect, Respond, and Recover functions. It provides a common language for risk management.
PCI DSSPCI DSS▾A security standard that organizations handling payment card data must comply with. It governs the storage, transmission, and processing of cardholder data.
지속성 (Persistence)▾Techniques that allow an attacker to maintain access across reboots or credential changes. It is one of the key tactics in MITRE ATT&CK.
플레이북 (Playbook)▾A standardized set of procedures for responding to a specific type of incident. It forms the basis for SOAR automation.
권한 상승 (Privilege Escalation)▾An attack technique for gaining higher privileges from a lower-privileged context. It is a key step toward system control and persistence.
퍼플팀 (Purple Team)▾An exercise that has offensive (red team) and defensive (blue team) collaborate to improve detection and response. It integrates feedback from both sides.
레드팀 (Red Team)▾An offensive team that emulates real adversaries to test an organization's defenses. It exposes gaps in detection and response.
런북 (Runbook)▾A step-by-step guide documenting operational tasks or response procedures. It ensures consistency and repeatability.
보안관제센터 (Security Operations Center)SOC▾A centralized team and facility that continuously monitors, detects, and responds to security events. It combines analysts, processes, and technology to manage threats.
시그마 룰 (Sigma Rule)▾A generic, vendor-agnostic format for log-based detection rules. It allows a rule to be written once and converted for multiple SIEM platforms.
SOC 2SOC 2▾An AICPA audit report attesting to a service organization's adherence to trust principles such as security, availability, and confidentiality. It is widely used by SaaS firms to demonstrate trustworthiness.
STIXSTIX▾A standardized language for representing structured cyber threat intelligence. It supports consistent sharing of threat information.
시스로그 (Syslog)▾A standard protocol used by network devices and systems to send log messages. It is widely used for centralized log collection.
테이블탑 훈련 (Tabletop Exercise)▾A discussion-based exercise that walks through a hypothetical incident scenario. It surfaces gaps in procedures and communication beforehand.
전술·기법·절차 (Tactics, Techniques and Procedures)TTP▾A concept describing adversary behavior at the levels of tactics, techniques, and procedures. It serves as the basis for threat analysis and detection.
TAXIITAXII▾A transport protocol for exchanging STIX-based threat intelligence. It enables automated sharing of threat information.
위협 행위자 (Threat Actor)▾An individual or group responsible for causing a security incident. They are classified by motivation, capability, and resources.
탐지 룰 (Detection Rule)▾A rule defining specific malicious patterns or conditions that trigger alerts. It is the basic unit of SIEM and EDR detection logic.
위협 헌팅 (Threat Hunting)▾The proactive, hypothesis-driven search for threats that evade existing detection tools. Analysts actively look for signs of compromise.
위협 인텔리전스 (Threat Intelligence)CTI▾Collected and analyzed information about threat actors and attacks. It supports defensive decision-making and proactive response.
사용자·엔티티 행위 분석 (User and Entity Behavior Analytics)UEBA▾Technology that learns baselines of normal user and entity behavior to detect anomalies. It is effective at spotting insider threats and account takeover.
확장 탐지·대응 (Extended Detection and Response)XDR▾A solution that unifies detection and response across endpoints, network, cloud, and email layers. It provides visibility beyond isolated security silos.
YARA▾A tool and rule language for identifying and classifying malware based on patterns. It is widely used in malware hunting and forensics.
AI・検知エンジン
LLM / sLLM▾大規模言語モデル(LLM)と、自前でホスティング可能な小型モデル(sLLM)です。意図分類に利用されます。
自然言語に潜む微妙な意図(なりすまし、送金への圧力)を捉えるのに強力ですが、ホスト型LLMを使うとメール本文を外部に送信することになります。 見落としがちな点: 「AI搭載」という言葉よりもデータがどこへ送られるかが重要です。データ主権が必要な場合は、sLLM/オンプレミスの選択肢とコスト管理(ティアリング)を確認しましょう。
続きを読む →인공신경망 (ANN)▾連続値・密な演算をベースとする標準的なニューラルネットワークです。トランスフォーマー型LLMもここに含まれます(現行の検知エンジン)。
現在の主流技術であり精度も高い一方、GPU・推論コスト・電力が運用上の重要な変数となります。 見落としがちな点: すべてのメールをモデルに通すとコストが急増します。まずルールでふるいにかけ、判断が難しいものだけをモデルに回すコストティアリング設計があるか確認しましょう。
続きを読む →스파이킹 신경망 (SNN)▾離散的なスパイクで動作する第3世代のニューラルネットワークです。超低消費電力・ストリーミング処理に強みがあります(研究段階)。
低消費電力・エッジ推論において将来性は大きいものの、まだ研究段階であり、現時点での購買判断の決め手にはなりません。 見落としがちな点: ベンダーが「SNN/ニューロモルフィック搭載」を謳う場合、実際に製品に組み込まれているのか、研究・ロードマップの段階にすぎないのかを区別して検証しましょう(誇大表現に注意)。
続きを読む →검색증강생성 (RAG)▾外部の知識(脅威インテリジェンス)を検索し、モデルの判断の根拠として補強する手法です。
モデルの判断に最新の脅威情報と根拠を加えることで、説明可能性と信頼性を高めます。 見落としがちな点: 検索対象となる知識(脅威インテリジェンス)が古ければ、RAGの精度も古いままです。インテリジェンスの更新頻度と情報源の信頼性も併せて点検しましょう。
続きを読む →에이전트형 AI (Agentic AI)▾複数の専門エージェントが手がかりを組み合わせて意図を判断する、アナリストのような自動化の仕組みです。
不足しがちなセキュリティ人員を補い、人間のアナリストのように複数の手がかりを総合して標的型攻撃を捕捉します。 見落としがちな点: 導入における信頼の核心は「なぜそう判断したのか」という説明可能性です。ブラックボックスのスコアだけを返す製品なのか、根拠を追跡できるのかを確認しましょう。
続きを読む →적대적 예제 (Adversarial Example)▾An input subtly perturbed to be misclassified by a model while appearing normal to humans. A core threat in ML security.
적대적 머신러닝 (Adversarial Machine Learning)AML▾The study of attacks that deceive or subvert machine learning models, and the defenses against them.
AI 에이전트 (AI Agent)▾An autonomous LLM-based system that invokes tools and reasons over multiple steps to accomplish goals.
AI 정렬 (AI Alignment)▾The research field of steering AI systems' goals and behavior toward human intent and values. Central to safe LLM operation.
이상 탐지 (Anomaly Detection)▾A technique for identifying data or behavior that deviates from normal patterns. Central to intrusion and fraud detection.
어텐션 메커니즘 (Attention Mechanism)▾A neural network technique that weights the most relevant parts of an input sequence. A key component of the Transformer.
백도어 공격 (Backdoor Attack)▾An attack that implants a hidden function in a model so it behaves maliciously only when a specific trigger is present.
분류기 (Classifier)▾A model that assigns inputs to one of a set of predefined categories. Used for spam/ham and malicious/benign decisions.
혼동 행렬 (Confusion Matrix)▾An evaluation table that cross-tabulates a classifier's predictions versus true labels, showing TP, FP, TN, and FN.
데이터 포이즈닝 (Data Poisoning)▾An attack that injects malicious samples into training data to manipulate a model's performance or behavior.
딥러닝 (Deep Learning)DL▾A subfield of machine learning using multi-layer neural networks to learn complex representations. Applied to image- and text-based threat detection.
임베딩 (Embedding)▾A dense vector representation that captures the semantic meaning of words or documents. Forms the basis of similarity search and RAG.
설명 가능한 AI (Explainable AI)XAI▾Techniques and a field for making AI model predictions interpretable to humans. Important for trusting detection outcomes.
F1 점수 (F1 Score)▾The harmonic mean of precision and recall, summarizing classification performance in a single value.
거짓양성률 (False Positive Rate)FPR▾The rate at which actual negatives are incorrectly classified as positive. Directly linked to alert fatigue in detection systems.
특징 공학 (Feature Engineering)▾The process of transforming and selecting raw data into features suitable for a model. Greatly impacts detection performance.
파인튜닝 (Fine-tuning)▾The process of further training a pre-trained model on task- or domain-specific data. Used to specialize security classifiers.
생성적 적대 신경망 (Generative Adversarial Network)GAN▾A neural architecture where a generator and discriminator compete during training. Used to create deepfakes and synthetic attack data.
그래디언트 부스팅 (Gradient Boosting)▾An ensemble technique that sequentially combines weak learners to reduce error. Used in detection models such as XGBoost.
가드레일 (Guardrails)▾Safety controls that inspect and constrain LLM inputs/outputs to block harmful or policy-violating content.
환각 (Hallucination)▾The phenomenon where an LLM plausibly generates false or unsupported content. Treated as a reliability threat.
탈옥 (Jailbreak)▾A technique that bypasses safety guardrails to make an LLM produce prohibited content. Carried out through prompt manipulation.
머신러닝 (Machine Learning)ML▾A branch of AI where systems learn patterns from data to make predictions or classifications without explicit programming. Widely used in security for spam and malware detection.
멤버십 추론 공격 (Membership Inference Attack)MIA▾A privacy attack that infers whether a specific data point was part of a model's training set.
모델 컨텍스트 프로토콜 (Model Context Protocol)MCP▾An open protocol that standardizes how LLM applications connect to external tools and data sources.
회피 공격 (Evasion Attack)▾An attack that manipulates inputs at inference time to evade a detection model. Common in malware detection bypass.
모델 추출 공격 (Model Extraction Attack)▾An attack that replicates a target model's functionality or parameters through repeated query-response probing.
모델 역전 공격 (Model Inversion Attack)▾A privacy attack that reconstructs sensitive training inputs by analyzing a model's outputs.
나이브 베이즈 (Naive Bayes)▾A probabilistic classifier based on Bayes' theorem assuming feature independence. A standard for early spam filtering.
자연어 처리 (Natural Language Processing)NLP▾The AI field enabling computers to understand and generate human language. Applied to phishing text analysis.
인공신경망 (Neural Network)NN▾A computational model of interconnected nodes inspired by biological neurons. Forms the basis of pattern recognition and anomaly detection.
과적합 (Overfitting)▾When a model fits the training data too closely and fails to generalize to new data.
OWASP LLM Top 10▾An OWASP list cataloging the ten most critical security risks for large language model applications.
정밀도와 재현율 (Precision and Recall)▾Precision is the fraction of positive predictions that are correct; recall is the fraction of actual positives detected. Key evaluation metrics.
랜덤 포레스트 (Random Forest)▾A machine learning algorithm that ensembles many decision trees for prediction. Frequently used for malicious traffic classification.
AI 레드팀 (AI Red Teaming)▾An adversarial evaluation that deliberately probes an AI model for vulnerabilities and harmful outputs.
강화 학습 (Reinforcement Learning)RL▾Learning an action policy by optimizing for reward signals. Researched for automated defense and penetration simulation.
인간 피드백 강화학습 (RLHF)RLHF▾A reinforcement learning method that aligns models using human preference feedback as reward. Used to suppress harmful LLM outputs.
ROC AUCAUC▾The area under the true-positive-rate vs false-positive-rate curve across thresholds, measuring classifier performance.
지도 학습 (Supervised Learning)▾Learning an input-output mapping from labeled data. Used for label-based detection such as spam/ham classification.
서포트 벡터 머신 (Support Vector Machine)SVM▾A classification algorithm that finds a hyperplane maximizing the margin between classes. Used in classic spam filters.
토큰화 (Tokenization)▾The preprocessing step of splitting text into smaller units called tokens for model input.
전이 학습 (Transfer Learning)▾A machine learning approach that reuses knowledge learned on one task for a related task. Useful in data-scarce security domains.
트랜스포머 (Transformer)▾A neural network architecture based on the self-attention mechanism, the core of modern LLMs. Excels at processing sequential data.
비지도 학습 (Unsupervised Learning)▾Learning structure or patterns from unlabeled data. Used in clustering-based anomaly detection.
벡터 데이터베이스 (Vector Database)▾A database that stores embedding vectors and performs approximate nearest-neighbor search. Used in RAG and semantic search.
一般セキュリティ・最新トレンド
랜섬웨어 / RaaS▾データを暗号化して身代金を要求するマルウェアです。RaaSはこれをサブスクリプション形式で販売する犯罪エコシステムを指します。
多くはフィッシングや認証情報の窃取から始まるため、メールセキュリティが第一の予防線となります。RaaSにより参入障壁が下がり、標的は大企業に限られません。 見落としがちな点: バックアップがあっても、それごと暗号化・削除されれば意味がありません。オフライン/イミュータブル(改ざん不能)なバックアップと実際の復旧訓練、情報漏えいを脅す二重恐喝への備えを整えましょう。
続きを読む →중간자 피싱 (AiTM)AiTM▾リアルタイムのプロキシでログインセッショントークンを奪い取り、MFAまで回避するフィッシング手法です(急増中)。
「MFAを有効にしているから安全」という思い込みを打ち砕く攻撃であり、急速に増加しています。トークンを奪われれば、パスワードやMFAが無事でもアカウントは開けられてしまいます。 見落としがちな点: 通常のMFAでは防げません。フィッシング耐性のあるMFA(パスキー/FIDO2)と、異常なセッション・デバイスの検知を必ず追加しましょう。
続きを読む →MFA 피로 공격 (MFA fatigue)▾MFAの承認プッシュ通知を繰り返し送りつけ、ユーザーが不注意に承認してしまうよう仕向ける攻撃です。
技術ではなく、人間の疲労や不注意を狙う攻撃であるため、MFAを有効にしただけでは終わりません。 見落としがちな点: 番号照合(ナンバーマッチング)方式やフィッシング耐性MFAへの切り替えと、「予期しないMFA通知は拒否して通報する」よう従業員を教育することを併せて行いましょう。
続きを読む →딥페이크 (Deepfake)▾AIで合成した音声・映像です。経営層の声や顔を偽造し、BECやビッシングを高度化させます。
「電話の声もビデオ通話も信用できない」時代となり、実際に多額の送金詐欺事例が報告されています。信頼の最後の砦だった声や顔が崩れつつあります。 見落としがちな点: 高額取引では「電話で本人確認」がもはや安全ではありません。事前に取り決めた合言葉、コールバック番号、複数人承認など、チャネルと要素を分離した検証手順を構築しましょう。
続きを読む →프롬프트 인젝션 (Prompt injection)▾AIモデルに隠れた指示を注入し、意図と異なる動作を引き起こす攻撃です(LLM時代の新種の脅威)。
業務や製品にAIを導入するほど、全く新しい攻撃面が生まれます(例: メールや文書に隠された指示でAIアシスタントを操る)。 見落としがちな点: 従来のセキュリティ点検項目には含まれていません。AI入力の信頼境界、出力のガードレール、AIに与える権限の最小化をセキュリティレビューに新たに組み込みましょう。
続きを読む →섀도 AI (Shadow AI)▾承認されていないAIツールに従業員が機密情報を入力してしまうことで生じる情報漏えいリスクです。
生産性向上への欲求から、従業員はすでに非公認のAIにコード・顧客情報・契約書を貼り付けている可能性が高い状況です。 見落としがちな点: 全面禁止はかえって利用を潜在化させるだけです。安全な社内代替手段の提供、明確なAI利用ポリシー、DLPによる機密情報漏えい防止を組み合わせて対応しましょう。
続きを読む →제로 트러스트 (Zero Trust)▾「決して信頼せず、常に検証する」— ネットワーク上の位置ではなく、アイデンティティと文脈でアクセスを制御するモデルです。
リモートワーク・クラウド時代において「社内ネットワーク=安全」という前提が崩れ、事実上のセキュリティ基準になりました。 見落としがちな点: ゼロトラストは製品ではなく旅路(ジャーニー)です。一度に導入しようとせず、MFA・最小権限・セグメンテーション・デバイス信頼から段階的に適用しましょう。
続きを読む →공급망 공격 (Supply chain attack)▾信頼している協力会社・ソフトウェア・アップデート経路を侵害し、多数を一度に狙う攻撃です。
自社内部のセキュリティが完璧でも、信頼している外部(協力会社・オープンソース・アップデート)が侵害されればそのまま突破されてしまいます。 見落としがちな点: セキュリティの範囲を自社の境界内だけに限定しがちです。協力会社のセキュリティ査定、ソフトウェア部品表(SBOM)、最小権限での連携をポリシー化しましょう。
続きを読む →EDR / XDR▾エンドポイント(EDR)、およびメール・クラウド・ネットワークまで拡張した(XDR)検知・対応ソリューションです。
メール・エンドポイント・クラウドをつなぐ可視性により、攻撃の全経路(メールのクリック→端末感染→拡散)を追跡できます。 見落としがちな点: ツールを導入しても24時間365日の監視・対応要員がいなければアラートが積み上がるだけです。社内の運用体制、あるいはMDR(監視委託)計画を併せて確認しましょう。
続きを読む →데이터 유출 방지DLP▾機密情報の外部流出(メール・アップロードなど)を検知・遮断する統制です。
規制対応と営業秘密保護の要であり、送信メールが最も一般的な流出経路です。 見落としがちな点: ルールが厳しすぎれば業務が滞り、緩すぎれば情報が漏れます。分類基準と例外・教育を併せて設計し、誤操作による流出(誤送信)まで対象範囲に含めましょう。
続きを読む →내부자 위협 (Insider threat)▾内部者(悪意によるものか不注意によるものかを問わず)による情報漏えい・被害です。乗っ取られたアカウントも内部者のように振る舞います。
外部からの防御に集中するあまり、最も大きなアクセス権を持つ内部を見落としがちです。乗っ取られたアカウントも、結局は「正規の内部者」のように振る舞います。 見落としがちな点: 最小権限や行動監視だけでなく、退職・部署異動時にアクセス権を即座に回収する手順(オフボーディング)を必ず整備しましょう。ここが最も突破されやすい箇所です。
続きを読む →피싱 저항 MFA (Passkey / FIDO2)▾フィッシングや中間者攻撃に耐性のある認証方式です(パスキー、FIDO2セキュリティキー)。パスワードレスへの方向性を示します。
AiTMや認証情報窃取に対する現時点で最強の対策であり、トークンの横取り自体が成立しなくなります。 見落としがちな点: 全社展開には時間がかかるため、経営層・管理者・財務担当など高リスクなアカウントから優先的に適用し、紛失・復旧手順も併せて整備しましょう。
続きを読む →초기 침투 브로커IAB▾侵入して得たアクセス権限を、ランサムウェア集団など他の攻撃者に販売する犯罪の専門分業層です。
サイバー犯罪が分業化している証です。あるグループが侵入して「鍵」を売り、別のグループがランサムウェアで収益化する — つまり小さな侵害が大きな事故につながります。 見落としがちな点: 「大したことのない」フィッシングや認証情報の流出を軽視しがちです。初期侵入の阻止と迅速な認証情報の無効化が、そのままランサムウェア予防になることを忘れないでください。
続きを読む →공격 표면 관리ASM▾外部に露出している資産・ドメイン・サービスを継続的に発見・管理し、攻撃経路を減らす活動です。
知らない資産は守れませんが、忘れられたサーバー、テスト用ドメイン、放置されたSaaSアカウントが最も一般的な侵入口です。 見落としがちな点: 資産一覧を一度作って終わりにすると、すぐに陳腐化します。継続的な自動発見と、自社ブランドに似た類似ドメイン・露出サービスの監視を運用に組み込みましょう。
続きを読む →