é¢é£ã€ã³ã·ãã³ã
Loading...
è
åšã¢ã¯ã¿ãŒã¯ãæ¶è²»è
ããªãã¬ãŒã¿ãŒãAI ãšãŒãžã§ã³ã (ããã) éã® 10,210,800 ä»¶ãè¶
ããäŒè©± ãå«ããã©ãããã©ãŒã ã®ç®¡çããã·ã¥ããŒãã«äžæ£ã«ã¢ã¯ã»ã¹ããŸãããçãŸããããŒã¿ã¯ãé«åºŠãªè©æ¬ºè¡çºããœãŒã·ã£ã« ãšã³ãžãã¢ãªã³ã° ãã£ã³ããŒã³ãAI ã䜿çšãããã®ä»ã®ãµã€ããŒç¯çœªæŠè¡ã®ç·šæã«äœ¿çšãããå¯èœæ§ããããŸãããã®ã€ã³ã·ãã³ãã¯é©æã«æ€åºããã圱é¿ãåããåœäºè
ã«èŠåããæ³å·è¡æ©é¢ãšååããããšã§ã被害ã®è»œæžã«æåããŸãããæ®å¿µãªããšã«ãæªæã®ãã人ç©ã倧éã®æ
å ±ãçã¿ãæ¶è²»è
ã®ãã©ã€ãã·ãŒãå±éºã«ããããŸãããå©çšå¯èœãªãã¥ãŒãã³ã€ã³ããªãžã§ ã³ã¹ (HUMINT) ã«åºã¥ããŠãResecurity ã¯ããã®ã¢ã¯ã¿ãŒããã€ã³ã·ãã³ãã«é¢é£ãã远å ã®ã¢ãŒãã£ãã¡ã¯ããååŸããŸãã:
\ ç¹å®ãããæªæã®ããã¢ã¯ãã£ããã£ã®é倧ãªåœ±é¿ã® 1 ã€ã¯ãAI ãšãŒãžã§ã³ããšæ¶è²»è
éã®éä¿¡ã䟵害ãããåœæ° ID ææžãç¹å®ã®èŠæ±ã«å¯Ÿå¿ããããã«æäŸããããã®ä»ã®æ©å¯æ
å ±ãå«ãå人è奿
å ± (PII) ãæããã«ãªã£ãããšã§ããæ»æè
ã¯ãããŒã¿ãã€ãã³ã°ããã³æœåºææ³ ãé©çšããŠé¢å¿ã®ããã¬ã³ãŒããååŸããé«åºŠãªãã£ãã·ã³ã°ã·ããªãªããã®ä»ã®ãµã€ããŒæ»æç®çã§ãããã䜿çšããå¯èœæ§ããããŸãã
### AI ãã©ãããã©ãŒã ãžã®ä¿¡é Œ: ããŒã¿æŒæŽ©ã®åå
䟵害ã®çµæãæ»æè
ã¯ç¹å®ã®é¡§å®¢ã»ãã·ã§ã³ã«ã¢ã¯ã»ã¹ããŠããŒã¿ãçã¿ãAI ãšãŒãžã§ã³ããšã®ããåãã®ã³ã³ããã¹ã ã«é¢ããç¥èãååŸããåŸã« ãã€ãžã£ã㯠ã«ã€ãªããå¯èœæ§ããããŸãããã®ãã¯ãã«ã¯ãæ»æè
ã KYC æ€èšŒãç¹å®ã®éèæ©é¢ãŸãã¯æ±ºæžãããã¯ãŒã¯ããã®æè¡ãµããŒããå£å®ã«ããŠè¢«å®³è
ããæ¯æãæ
å ±ãååŸããããšã«çŠç¹ãåœãŠãŠããå Žåãè©æ¬ºããœãŒã·ã£ã« ãšã³ãžãã¢ãªã³ã° ãã£ã³ããŒã³ã§ç¹ã«å¹æçã§ããå¯èœæ§ããããŸããå€ãã®äŒè©±å AI ãã©ãããã©ãŒã ã§ã¯ããŠãŒã¶ãŒã AI æ¯æŽãªãã¬ãŒã¿ãŒãšäººéãåãæ¿ããããšãã§ããŸããæªæã®ãã人ç©ã¯ã»ãã·ã§ã³ãååããäŒè©±ãããã«å¶åŸ¡ã§ããŸãããŠãŒã¶ãŒã®ä¿¡é ŒãæªçšããŠãæªæã®ãã人ç©ã¯è¢«å®³è
ã«æ©å¯æ
å ±ãæäŸããããã«èŠæ±ããã ãè©æ¬ºèšç»ã«äœ¿çšã§ããç¹å®ã®ã¢ã¯ã·ã§ã³ (OTP ã®ç¢ºèªãªã©) ãæé
ãããããå¯èœæ§ããããŸãã Resecurity ã¯ãä¿¡é Œã§ããäŒè©±å AI ãã©ãããã©ãŒã ãæªçšããŠã¢ã¯ã»ã¹ããããšã§ãããŸããŸãªãœãŒã·ã£ã« ãšã³ãžãã¢ãªã³ã° ã¹ããŒã ãå®è¡ãããå¯èœæ§ããããšäºæž¬ããŠããŸãã
æçµçãªè¢«å®³è
(æ¶è²»è
) ã¯ãæ»æè
ãã»ãã·ã§ã³ãååããŠããŸã£ããæ°ã¥ãããã»ãã·ã§ã³ã¯å®å
šã§ããããã®åŸã®è¡åã¯æ£åœã§ãããšèããAI ãšãŒãžã§ã³ããšã®å¯Ÿè©±ãç¶ããŸããæ»æè
ã¯ã被害è
ã® AI ãã©ãããã©ãŒã ãžã®ä¿¡é Œãæªçšããæ©å¯æ
å ±ãå
¥æããå¯èœæ§ããããŸããããã¯ãåŸã§æ¯æãè©æ¬ºãå人æ
å ±ã®çé£**ã«äœ¿çšãããå¯èœæ§ããããŸãã
ä¿æãããå人æ
å ±ã®åé¡ã¯ãå©çšå¯èœãªäŒè©±å AI ãã©ãããã©ãŒã ããŒã¿ãšãã®ã¢ãã«ã§æœåšçãªæµå¯Ÿè
ãèŠã€ãã䟵害ãããéä¿¡ã§ç¢ºèªãããå¯èœæ§ããããŸããããšãã°ããªãŒã¹ãã©ãªã¢ä¿¡å·å±ã®ãªãŒã¹ãã©ãªã¢ ãµã€ã㌠ã»ãã¥ãªã㣠ã»ã³ã¿ãŒ (ASD ã® ACSC) ãåœéããŒãããŒãšååããŠå
¬éãã ã±ãŒã¹ ã¹ã¿ã㣠㮠1 ã€ã«ãããšããµãŒãããŒãã£ããã¹ããã AI ã·ã¹ãã ã«ã¯å
æ¬çãªãªã¹ã¯è©äŸ¡ãå¿
èŠã§ãã2023 幎 11 æãç ç©¶è
ããŒã ã AI èšèªã¢ãã«ããèšæ¶ããããã¬ãŒãã³ã° ããŒã¿ãæœåºãã詊ã¿ã®çµæãçºè¡šããŸãããç ç©¶è
ãå®éšããã¢ããªã±ãŒã·ã§ã³ã® 1 ã€ã ChatGPT ã§ãã ã ChatGPT ã®å Žåãç ç©¶è
ãã¯ãã¢ãã«ã«åèªãæ°žé ã«ç¹°ãè¿ãããã«æç€ºãããšãã¢ãã«ãéåžžã®åäœãããŠããå Žåãããã¯ããã«é«ãå²åã§ãã¬ãŒãã³ã° ããŒã¿ãæŒæŽ©ããããšãçºèŠããŸãããæœåºããããã¬ãŒãã³ã° ããŒã¿ã«ã¯ãå人ãç¹å®ã§ããæ
å ± (PII) ãå«ãŸããŠããŸããã ### ãµãŒãããŒãã£ããã¹ããã AI ã·ã¹ãã : ãµãã©ã€ ãã§ãŒã³ã«å¯Ÿãã倧ããªãªã¹ã¯ AI ãšãŒãžã§ã³ããšãšã³ã ãŠãŒã¶ãŒéã®éä¿¡ ã«ä¿åããã ä¿æãããå人ãç¹å®ã§ããæ
å ± (PII) ã®åé¡ã«å ããŠãæªæã®ããè¡çºè
ã¯ãäŒæ¥ãå€éšãµãŒãã¹ãã¢ããªã±ãŒã·ã§ã³ã® API ã䜿çšããŠãµãŒãã¹ãå®è£
ããããã«äœ¿çšã§ããã¢ã¯ã»ã¹ ããŒã¯ã³ãã¿ãŒã²ããã«ããããšãã§ããŸãã:
ããŒã¯ã³æäœ ã«ããããµããŒããããŠããçµ±åãã£ãã«ãžã®æªæã®ããããŒã¿æ¿å
¥ãèµ·ãããAI äŒè©±ãã©ãããã©ãŒã ã®ãšã³ã ãŠãŒã¶ãŒã«æªåœ±é¿ãäžããå¯èœæ§ããããŸãã AI ãšãŒãžã§ã³ãã®åºåã¯ããŸããŸãªãã©ãããã©ãŒã ã«çµ±åã§ããããã㯠DiscordãWhatsAppãSlackãZapier ãªã©ã®ä»ã®ã¢ããªã±ãŒã·ã§ã³ã«è¿œå ã§ããŸããå€éš AI ã·ã¹ãã ããšã³ã¿ãŒãã©ã€ãº ã€ã³ãã©ã¹ãã©ã¯ãã£ã«å€§ããæµžéããèšå€§ãªéã®ããŒã¿ãåŠçããããããé©åãªãªã¹ã¯è©äŸ¡ãè¡ããã«å®è£
ããããšã¯ãIT ãµãã©ã€ ãã§ãŒã³ã®ãµã€ããŒã»ãã¥ãªãã£ã®æ°ããªãªã¹ã¯ãšèŠãªãå¿
èŠããããŸããGartner ã«ãããšããµãŒãããŒãã£ã® AI ããŒã«ã¯ããŒã¿ã®æ©å¯æ§ãªã¹ã¯ããããããŸããçµç¹ããµãŒãããŒã㣠ãããã€ããŒã® AI ã¢ãã«ãšããŒã«ãçµ±åãããšããããã® AI ã¢ãã«ã®ãã¬ãŒãã³ã°ã«äœ¿çšãããå€§èŠæš¡ãªããŒã¿ã»ãããåžåãããŸãããŠãŒã¶ãŒã¯ä»ã® AI ã¢ãã«å
ã®æ©å¯ããŒã¿ã«ã¢ã¯ã»ã¹ããå¯èœæ§ããããçµç¹ã«èŠå¶ã忥ãè©å€äžã®åœ±é¿ãåãŒãå¯èœæ§ããããŸãã ### AI 察å¿ã·ã¹ãã ã«å¯Ÿããæ»æã®ç¯å² å®éã®æ»æèгå¯ã«åºã¥ã AI 察å¿ã·ã¹ãã ã«å¯Ÿããæµå¯Ÿè
ã®æŠè¡ãšææ³ã®ç¯å²ã¯ãMITRE ATLAS Matrix ã§å®çŸ©ãããŠããŸããããã¯ãAI ã·ã¹ãã ã®è匱æ§ãç¹å®ããŠå¯ŸåŠããããã®ãã¬ãŒã ã¯ãŒã¯ãæäŸããæ»æã鲿¢ããŠæ©å¯ããŒã¿ãä¿è·ããã®ã«åœ¹ç«ã¡ãç ç©¶è
ã人工ç¥èœã·ã¹ãã ã«å¯Ÿããè
åšã®ç¶æ³ãææ¡ã§ããããã«ããŸãã
MITRE ATLAS ãããªãã¯ã¹ã䜿çšããŠãResecurity ã¯ã芳å¯ãããæªæã®ããã¢ã¯ãã£ããã£ãäž»èŠãª TTP ã«ãããã³ã°ããŸããã - AML.T0012\ æå¹ãªã¢ã«ãŠã³ã - AML.T0049\ å
¬éã¢ããªã±ãŒã·ã§ã³ã®æªçš - AML.T0052\ ãã£ãã·ã³ã° - AML.T0055\ ä¿è·ãããŠããªãèªèšŒæ
å ± - AML.T0007\ ML ã¢ãŒãã£ãã¡ã¯ãã®æ€åº - AML.T0035\ ML ã¢ãŒãã£ãã¡ã¯ãã®åé - AML.T0043\ æµå¯ŸçããŒã¿ã®äœæ - AML.T0025\ ãµã€ããŒææ®µã«ããæµåº - AML.T0024\ ML ã€ã³ã¿ãŒãã§ãŒã¹ API ã«ããæµåº- AML.T0048\ å€éšããã®æå®³ïŒè²¡åç圱é¿ïŒ ### ç·©åç Resecurity ã§ã¯ãAI ã·ã¹ãã ãæºæ ããå
¬æ£ã§ãä¿¡é Œæ§ãé«ããããŒã¿ã®ãã©ã€ãã·ãŒãä¿è·ãããããšãç©æ¥µçã«ä¿èšŒããããã®å
æ¬ç㪠**AI ä¿¡é Œããªã¹ã¯ãã»ãã¥ãªãã£ç®¡ç (TRiSM) ** ããã°ã©ã ã®éèŠæ§ã匷調ãããŠããŸããEU AI æ³ããåç±³ãäžåœãã€ã³ãã®ãã®ä»ã®èŠå¶æ çµã¿ã§ã¯ãAI ã¢ããªã±ãŒã·ã§ã³ã®ãªã¹ã¯ã管çããããã®èŠå¶ããã§ã«ç¢ºç«ãããŠããŸããããšãã°ãã·ã³ã¬ããŒã«ã®æè¿ã® PDPC AI ã¬ã€ãã©ã€ã³ã§ã¯ãäŒæ¥ãé瀺ãéç¥ãéããŠå人ããŒã¿ã®äœ¿çšã«é¢ããåæãæ±ããéã«éææ§ãé«ããããšããã§ã«æšå¥šãããŠããŸããäŒæ¥ã¯ AI ã·ã¹ãã ãä¿¡é Œã§ããããšãä¿èšŒããããã«ãã£ãŠæ¶è²»è
ã«å人ããŒã¿ã®äœ¿ç𿹿³ã«å¯Ÿããä¿¡é ŒãæäŸããå¿
èŠããããŸããã«ããã®ãã©ã€ãã·ãŒä¿è·ã³ããã·ã§ããŒäºåæãšãã®ä»ã®æ¥çèŠå¶åœå±ã«ãã£ãŠçºè¡ãããã責任ãããä¿¡é Œã§ããããã©ã€ãã·ãŒä¿è·å¯èœãªçæ AI ãã¯ãããžãŒã®ååãå
¬éæžã¿ã«ããã°ãçæ AI ã·ã¹ãã (ãŸãã¯è©²åœããå Žåã¯ãã®ææ¡ããã䜿çš) ããã©ã€ãã·ãŒã«äžããå¯èœæ§ãããæœåšçãŸãã¯æ¢ç¥ã®åœ±é¿ãç¹å®ããŠè»œæžããããã«ããã©ã€ãã·ãŒåœ±é¿è©äŸ¡ (PIA) ãªã©ã®è©äŸ¡ã宿œããããšãéèŠã§ããåœå®¶å®å
šä¿éå± (NSA) ã«ããå®å
šã§å埩åã®ãã AI ã·ã¹ãã ã®å°å
¥ã«é¢ãããã¹ã ãã©ã¯ãã£ã¹ å
¬éæžã¿ ã«ãããšãå°éå®¶ã¯ã䟵害ã¯é¿ããããªããããã§ã«çºçããŠãããšæ³å®ãã ãŒã ãã©ã¹ã (ZT) ã®èãæ¹ ãæ¡çšããããšãæšå¥šããŠããŸããäŒè©±å AI ãã©ãããã©ãŒã ã®äŸµå®³ãäŒŽãæªæã®ããã¢ã¯ãã£ããã£ã芳å¯ããã顧客ã®ãã©ã€ãã·ãŒã«é倧ãªåœ±é¿ãåã¶ããšãèæ
®ãããšãResecurity 㯠AI ãšãŒãžã§ã³ããšæçµæ¶è²»è
éã® å®å
šãªéä¿¡ ã®éèŠæ§ã匷調ããå ŽåããããŸããããã«ã¯ãå人ãç¹å®ã§ããæ
å ± (PII) ã®ä¿æãæå°éã«æãã ããšããµãŒãããŒãã£ããã¹ããã AI ãœãªã¥ãŒã·ã§ã³ã®ã³ã³ããã¹ãã§ãµãã©ã€ ãã§ãŒã³ã®ãµã€ã㌠ã»ãã¥ãªãã£ã«ããã¢ã¯ãã£ããªã¢ãããŒããæ¡çšããããš ãå«ãŸããŸãã ### éèŠæ§ äŒè©±å AI ãã©ãããã©ãŒã ã¯ã倧æäŒæ¥ãæ¿åºæ©é¢ã«ãšã£ãŠãçŸä»£ã® IT ãµãã©ã€ ãã§ãŒã³ã®éèŠãªèŠçŽ ãšãªã£ãŠããŸãããããã®ãã©ãããã©ãŒã ãä¿è·ããã«ã¯ãSaaS (Software-as-a-Service) ã«é¢é£ããåŸæ¥ã®ãµã€ã㌠ã»ãã¥ãªãã£å¯ŸçãšãAI ã®ç¹æ§ã«åãããŠç¹åããã³èª¿æŽããã察çãšã®ãã©ã³ã¹ãåãå¿
èŠããããŸããããæç¹ã§ãäŒè©±å AI ãã©ãããã©ãŒã ãåŸæ¥ã®éä¿¡ãã£ãã«ã«åã£ãŠä»£ããå§ããŸãããããã®ãã©ãããã©ãŒã ã¯ããæ§åŒã®ãé»åã¡ãŒã« ã¡ãã»ãŒãžã³ã°ã®ä»£ããã«ãAI ãšãŒãžã§ã³ããä»ããŠå¯Ÿè©±ãå¯èœã«ããå¿çãéããã»ãŒãªã¢ã«ã¿ã€ã ã§é¢å¿ã®ãããµãŒãã¹éã§ãã«ã ã¬ãã«ã®ããã²ãŒã·ã§ã³ãæäŸããŸãããã¯ãããžã®é²åã«ãããã°ããŒãã« ICT åžå Žã®ææ°ã®ãã¬ã³ããšååãèªåãã¡ã®å©çã®ããã«å©çšããããšããæµå¯Ÿè
ã«ããæŠè¡ã®èª¿æŽãããããããŸãããResecurity ã¯ãäŒè©±å AI ãã©ãããã©ãŒã ã«ãµã€ããŒç¯çœªè
ã³ãã¥ããã£ãšåœå®¶ã®åæ¹ããæ³šç®ã«å€ããé¢å¿ãå¯ããããŠããããšãæ€åºããŸãããããã¯ãAI ã«ãã£ãŠãµããŒãããã察話ããã³ããŒãœãã©ã€ãºãããã»ãã·ã§ã³äžã«åŠçãããèšå€§ãªéã®æ
å ±ãšãçžåœæ°ã®æ¶è²»è
ã®ååšã«ãããã®ã§ãããµã€ããŒç¯çœªè
ã¯ãæ°ããæ¶è²»è
åã補åã®ç»å Žã«ãããäŒè©±å AI ãã©ãããã©ãŒã ãã¿ãŒã²ããã«ããŸããäŸãã°ãäžåœã¯ä»å¹Žãä»®æ³çè·å©æãšå»åž«ãæ£è
ãšå¯Ÿè©±ãããã«ã¹ã±ã¢ãžã®é©æ°çãªã¢ãããŒãã玹ä»ããããã«ãAIç
é¢ã®ãããã¿ã€ããç«ã¡äžããŸãããäŒè©±åAIã¯å»çããŒã¿ã«é¢ããæ©å¯æ
å ±ãéä¿¡ããã³åŠçããå¯èœæ§ãããããããã®ãããªé©æ°ã¯é·æçã«æ£è
ã®ãã©ã€ãã·ãŒã«é倧ãªãªã¹ã¯ãããããå¯èœæ§ããããŸããäŒè©±åAIã¯ã顧客ãµããŒãã®èªååãããŒãœãã©ã€ãºããã財åã¬ã€ãã³ã¹ã®æäŸãååŒå¹çã®åäžã顧客æºè¶³åºŠãšéçšå¹çã®åäžã«ããããã§ã«éè¡ããã³ãã£ã³ããã¯æ¥çã«é©åœããããã ãŠããŸãããããã®äŸã¯ãæ¶è²»è
åãã®ä»®æ³ã¢ã·ã¹ã¿ã³ããããšã³ã¿ãŒãã©ã€ãºã¬ãã«ã®èªååããã³ãµããŒãã·ã¹ãã ã«è³ããŸã§ãäŒè©±åAIã®å€æ§ãªçšéã蚌æããŠããŸãããã¯ãããžãŒãé²åãç¶ããã«ã€ããŠãå°æ¥çã«ã¯äŒè©±åAIã®ããã«åµé çãªäœ¿çšäŸãšããã®ãããªãã¯ãããžãŒãšãšã³ããŠãŒã¶ãŒãæšçãšããæ°ãããµã€ããŒã»ãã¥ãªãã£ã®è
åšãèŠãããããã«ãªããšäºæ³ãããŸãã ### åèè³æ - AI ãšãŒãžã§ã³ãã«ããæ°ããªãªã¹ã¯ãšã»ãã¥ãªãã£ã®è
åšã軜æžãã\ https://securitymea.com/2024/09/10/mitigate-emerging-risks-and-security-threats-from-ai-agents/ - AI ã¢ãã«ã«ãããä¿¡é Œããªã¹ã¯ãã»ãã¥ãªãã£ãžã®åãçµã¿\ https://www.gartner.com/en/articles/what-it-takes-to-make-ai-safe-and-effective - 責任ãããä¿¡é Œã§ããããã©ã€ãã·ãŒä¿è·ãããçæ AI ãã¯ãããžãŒã®åå\ https://www.priv.gc.ca/en/privacy-topics/technology/artificial-intelligence/gd_principles_ai/ - 人工ç¥èœ (AI) ãšã®é¢ãã\ https://media.defense.gov/2024/Jan/23/2003380135/-1/-1/0/CSI-ENGAGING-WITH-ARTIFICIAL-INTELLIGENCE.P...