AI時代におけるインシデント対応の品質保証
DAY 2
11:30-
12:10
インシデント調査報告書は、システムの復旧、再発防止策の策定、関係者とのコミュニケーション、および対外公表に関する重要な意思決定を支えるものである。しかし、被害に遭った組織は、行われた調査が十分であったか、あるいはその結論が証拠によって適切に裏付けられているかを判断するための専門知識を欠いていることが多い。 JPCERT/CCは、国内のインシデント対応プロバイダー、企業のCSIRT、およびSOCチームなど13の組織と協力し、報告書の品質向上のための2つのチェックリストとサンプルレポートを開発した。さらに、これらの資料を用いてインシデント調査報告書を査読(レビュー)するLLMエージェントを構築した。このエージェントは、調査の目的が達成されているか、調査対象となったシステム、ログ、期間が明確に記述されているか、そして主要な結論が証拠IDやログの抜粋によって裏付けられているかを検証する。 本セッションでは、この品質保証モデル、LLM支援型レビュー手法、その限界、および人間のアナリストの管理下に留めるべきインシデント対応タスクについて提示する。
-
Location :
-
Track 1(HALL B)
-
-
Category :
-
General
-
-
Share :
Speakers
-
Shusei Tomonaga
朝長 秀誠
Shusei Tomonaga is a CTO of JPCERT/CC. Since December 2012, he has been engaged in malware analysis and forensic investigation. In particular, he spearheads the analysis of targeted attacks affecting critical Japanese industries. In addition, he has written blog posts on malware analysis and technical findings (https://blogs.jpcert.or.jp/en/). He has presented at CODE BLUE, BsidesLV, Botconf, VB Conference, Hitcon, PHDays, PacSec, FIRST Conference, DEF CON, BlackHat ASIA, USA Arsenal and more.
-
Yuki Yano
矢野 雄紀
Yuki Yano is a member of the Incident Response Group at JPCERT/CC. Prior to joining JPCERT/CC in July 2025, he worked on cybercrime investigations at a prefectural police department and later served as an Associate Professor at the National Police Academy, where he was responsible for training cybersecurity professionals. At JPCERT/CC, he is engaged in incident report handling, incident response support, malware analysis, and digital forensic investigations. He has presented at BlackHat USA Arsenal.