Program

/

CODE BLUE 2026

Time Table

AI時代におけるインシデント対応の品質保証

インシデント調査報告書は、システムの復旧、再発防止策の策定、関係者とのコミュニケーション、および対外公表に関する重要な意思決定を支えるものである。しかし、被害に遭った組織は、行われた調査が十分であったか、あるいはその結論が証拠によって適切に裏付けられているかを判断するための専門知識を欠いていることが多い。 JPCERT/CCは、国内のインシデント対応プロバイダー、企業のCSIRT、およびSOCチームなど13の組織と協力し、報告書の品質向上のための2つのチェックリストとサンプルレポートを開発した。さらに、これらの資料を用いてインシデント調査報告書を査読(レビュー)するLLMエージェントを構築した。このエージェントは、調査の目的が達成されているか、調査対象となったシステム、ログ、期間が明確に記述されているか、そして主要な結論が証拠IDやログの抜粋によって裏付けられているかを検証する。 本セッションでは、この品質保証モデル、LLM支援型レビュー手法、その限界、および人間のアナリストの管理下に留めるべきインシデント対応タスクについて提示する。

  • Location :

    • Track 1(HALL B)

  • Category :

    • General

  • Share :

Speakers

  • 朝長 秀誠 の写真

    Shusei Tomonaga

    朝長 秀誠

    Shusei Tomonaga is a CTO of JPCERT/CC. Since December 2012, he has been engaged in malware analysis and forensic investigation. In particular, he spearheads the analysis of targeted attacks affecting critical Japanese industries. In addition, he has written blog posts on malware analysis and technical findings (https://blogs.jpcert.or.jp/en/). He has presented at CODE BLUE, BsidesLV, Botconf, VB Conference, Hitcon, PHDays, PacSec, FIRST Conference, DEF CON, BlackHat ASIA, USA Arsenal and more.

  • 矢野 雄紀 の写真

    Yuki Yano

    矢野 雄紀

    Yuki Yano is a member of the Incident Response Group at JPCERT/CC. Prior to joining JPCERT/CC in July 2025, he worked on cybercrime investigations at a prefectural police department and later served as an Associate Professor at the National Police Academy, where he was responsible for training cybersecurity professionals. At JPCERT/CC, he is engaged in incident report handling, incident response support, malware analysis, and digital forensic investigations. He has presented at BlackHat USA Arsenal.