Pass-the-Device:エンドポイント侵害後におけるSASE/VPNの「信頼」の移植
DAY 2
9:50-
10:30
ゼロトラストに巨額の投資が行われているにもかかわらず、現代の多くのSASE/VPN導入環境では、エンドポイントの侵害後に「信頼(トラスト)」を他へ移植することが依然として可能である。アイデンティティ、証明書、およびポスチャ(セキュリティ状態)のチェックは、デバイスに厳密に紐付けられているというよりも、他への転送が可能であるケースが多いことが判明している。 本講演では、SASE/VPNソリューションが関わるほとんどのレッドチーム演習において、その中核技術が有効であることが証明された実践的な手法「Pass-the-Device」を紹介する。攻撃者が証明書をエクスポートまたは再発行し、セッションをリプレイし、登録(エンロールメント)フローを悪用し、さらにポスチャ状態を再構成することで、攻撃者が制御するホストから独立したアクセスを確立する方法を実演する。また、Palo Alto、Cisco、Netskope、Zscalerにわたって繰り返し発生する「信頼の乗っ取り(トラスト・ハイジャック)」のプリミティブを分類し、それぞれの技術がどのような場合に成功または失敗するのかを解説する。 受講者は、攻撃者が元のホストのEDRによる可視性を超えて活動しながらも、IdP(アイデンティティプロバイダー)、SASE、およびネットワークのテレメトリに検知可能な痕跡をいかに残すかを学ぶことができる。最後に、実践的な緩和策と検知の機会を提示して講演を締めくくる。
-
Location :
-
Track 1(HALL B)
-
-
Category :
-
Technical
-
-
Share :
Speakers
-
Ruslan Sayfiev
ルスラン・サイフィエフ
Ruslan Sayfiev is a Principal Consultant and Red Team Architect at Fujitsu Uvance Wayfinders, with more than a decade of experience in offensive security, adversary simulation, exploit development, and vulnerability research.
Previously, as Director of Offensive Security at GMO Cybersecurity by Ierae, he built and led the company’s red team practice from the ground up, delivering hundreds of engagements focused on real-world adversary emulation for major enterprises in Japan.
His work focuses on advanced post-compromise techniques, including trust transplantation in SASE and VPN environments, endpoint detection evasion, and identity-focused attacks. He is particularly interested in connecting offensive research with detection engineering, incident response, and practical improvements to enterprise security.
Ruslan holds the OSEE, OSCE3, GXPN, and CRTL certifications. He is a former OffSec instructor, a Code Blue speaker, and has been credited with multiple CVEs affecting major vendors.