Breaking
INEight Indonesian airports closed due to volcanic ash from Anak KrakatauKRSouth Korea, US, Japan Begin Five-Day Freedom Edge Military Exercise Despite Ulchi Freedom Shield ReductionBRMaroon 5 opens Brazilian tour with show in São José do Rio PretoCNFireworks explosion at Temascalzingo festival in Mexico kills 10, injures 64DELawsuit before the Bavarian Supreme Court: Are only Munich innkeepers allowed to serve beer at Oktoberfest?KRJapan High School Baseball Federation considers introducing a 7-inning system as a measure against heat waves... Controversy heats upRUThe Deputy Head of the Russian Foreign Ministry confirmed the continuation of Russian LNG supplies to the EU, despite the decrease in volumesKRSouth Korea turns to foreign workers to address eldercare shortageCN無黨澎湖縣長候選人許智富提出澎湖居民優先機位政策CNNio CEO William Li Compares Future Cars to Robots Amid AI-Driven Mobility VisionINEight Indonesian airports closed due to volcanic ash from Anak KrakatauKRSouth Korea, US, Japan Begin Five-Day Freedom Edge Military Exercise Despite Ulchi Freedom Shield ReductionBRMaroon 5 opens Brazilian tour with show in São José do Rio PretoCNFireworks explosion at Temascalzingo festival in Mexico kills 10, injures 64DELawsuit before the Bavarian Supreme Court: Are only Munich innkeepers allowed to serve beer at Oktoberfest?KRJapan High School Baseball Federation considers introducing a 7-inning system as a measure against heat waves... Controversy heats upRUThe Deputy Head of the Russian Foreign Ministry confirmed the continuation of Russian LNG supplies to the EU, despite the decrease in volumesKRSouth Korea turns to foreign workers to address eldercare shortageCN無黨澎湖縣長候選人許智富提出澎湖居民優先機位政策CNNio CEO William Li Compares Future Cars to Robots Amid AI-Driven Mobility Vision
BackAIが脆弱性管理を変える、Check Pointのエクスポージャー管理とAEVの全貌
AIが脆弱性管理を変える、Check Pointのエクスポージャー管理とAEVの全貌
Developing
ITmedia3 hours agoTech7 min readJapanView translation

AIが脆弱性管理を変える、Check Pointのエクスポージャー管理とAEVの全貌

Quick Look

Check Pointのザンガー氏は、生成AIによる脆弱性発見の容易化が従来のパッチ対応を不可能にすると警告。CTEMや自社のExposure Managementプラットフォーム、特にAEVエンジンを通じて、脅威インテリジェンスと優先順位付けに焦点を当てた外部視点のアプローチを強調。実際の導入事例と、オープンソースや自社開発アプリケーションへの脅威増大にも言及した。

AI-generated summary

Why It Matters

生成AIの進化により、コードスキャンを通じた脆弱性の発見が容易になり、従来のパッチ中心の対応が限界を迎えている。これにより、脅威の優先順位付けと継続的なエクスポージャー管理の重要性が高まっている。

Font size

このようなツールの登場は、業界全体に脆弱性の急増という危機感を突きつけた。「コードセキュリティの手法を誰もが知ってしまった。見つけようと思えば見つけられる時代になった」とザンガー氏。今後1~2年のうちに、あらゆるベンダーから脆弱性の開示情報が「爆発的に」増えていくだろうというのが同氏の予測だ。「生成AIでコードスキャンをすれば、脆弱性はいくらでも見つかる。しかし、それら全てに対応できるわけではない時代が来る。全ての脆弱性にパッチを当てるという従来型の対応は、今後成り立たなくなっていく」とザンガー氏は話す。

この転換を語るに当たってザンガー氏が繰り返し引き合いに出すのが、ガートナーが提唱する「CTEM」(Continuous Threat Exposure Management:継続的脅威エクスポージャー管理)という考え方だ。スコーピング(対象範囲の特定)、ディスカバリー(資産・脆弱性の発見)、優先順位付け、検証、そして動員(対応の実行)という5つのステージで脅威に対応するというもので、ザンガー氏が特に強調するのが「優先順位付け」の重要性だ。

「重要なのは、見つかった脆弱性を片っ端からつぶすことではない。実際に悪用されるリスクが高いものから対応すること」とザンガー氏は説明する。攻撃者が特定の国、特定のIPアドレスから仕掛けてくると分かっていれば、その経路を止めればいい。Webアプリケーションへの通信を監視・遮断する「WAF」(Web Application Firewall)や、ネットワーク上の不正な通信パターンを検知・防御する「IPS」(Intrusion Prevention System:侵入防止システム)で防げるものもある。「パッチを当てなければならない」という発想は選択肢の一つにすぎないというのだ。

エクスポージャー管理とは何か

こうした転換に対応する新たな取り組みとして、Check Pointは「Exposure Management」(エクスポージャー管理)に投資してきた。攻撃者にさらされうる資産や脆弱性を継続的に洗い出し、優先順位付けから対策の実行までを支援するというものだ。

ゼネラルマネジャーとしてエクスポージャー管理の取り組みを率いるCheck Pointのヨハイ・コレム(Yochai Corem)氏によれば、「1.脅威インテリジェンス(攻撃者の動向把握)」「2.優先順位付け(ビジネスへの影響度・設定不備の評価)」「3.修復(実際の対策実行)」――という3要素で構成され、CTEMの5ステージ全体をカバーするプラットフォームだという。

このExposure Managementの中核を担うエンジンが、2026年6月に発表した「Agentic Exposure Validation」(AEV)だ。攻撃者の視点で推論するAIエージェントが、資産情報や脅威インテリジェンスを相関分析し、脆弱性が実際に悪用可能かどうかをエビデンスをもって判定する。AEVは先のCTEMの5ステージのうち、主にスコーピング、ディスカバリー、優先順位付けの部分をカバーする。「そこから先の検証・修復まで含めて全てをカバーできるのが、われわれのプラットフォーム(Exposure Management)のユニークな点だ」とコレム氏。パッチの適用、動的なパッチ当て、認証情報のローテーションなど、実際の対応まで自動的につなげられるという。

ザンガー氏はAEVを支える技術を4つの要素に分解して説明する。人間のように推論する基盤モデル、関連情報を蓄積するナレッジグラフ、モデルが操作するツール群、そしてそれらを束ねる「ハーネス」(AIエージェントにツールや指示を与えて動かすための制御の仕組み)だ。「特にハーネスの部分こそが、われわれの“秘伝のタレ”だ」とザンガー氏。「どの攻撃手法を優先的に模倣するかをモデルに指示しつつ、常に安全性を監視するエージェントを並行して走らせることで、攻撃側と安全管理側のバランスを取っている」と独自性を説明した。

Check PointのAEVは5つのエージェントが連携して動く仕組みだ。全体の状況を把握し文脈を整理する「インテリジェンス・オーケストレーター」、発見した資産をグループ分けする「クラスタリング・エージェント」、個々の資産に対して脆弱性の学習・攻撃コードの作成・パッチのリバースエンジニアリングまでする「アセット・エージェント」、攻撃時にサービス停止やデータ破壊など実害が出ないよう検証する「セーフティ・エージェント」、そして誤検知・過検知を判定する「バリデーター・エージェント」の5つだ。

「AIを攻撃側のエージェントとして使うと、リスクではないものをリスクだと過剰に判定してしまうことがある。だからこそバリデーター・エージェントが必要になる」とコレム氏は説明する。

Check Pointの差別化は外部視点からのアプローチ

コレム氏は、Exposure Managementを構成する3要素である脅威インテリジェンス、優先順位付け、修復が、実際にどう機能するのかの実例も紹介した。

まず脅威インテリジェンスの実例だ。ある大手欧州エネルギー企業では、同社ブランドを装うフィッシングサイト・なりすまし広告のキャンペーンが確認された。攻撃者はMeta広告を使い、フランス・イタリアの30歳以上の投資家層をターゲットに「月1000ユーロ以上のリターン」をうたう偽の投資案件へ誘導していた。地域を絞った巧妙な手口のため、米国や英国に検知センサーを置く一般的な脅威インテリジェンス企業では見つけられなかったという。Check Pointはこのキャンペーンを検知し、数時間以内に広告とフィッシングサイトの停止に至った。同社によれば、フィッシングサイトのテイクダウン率は99%超、平均対応時間は12時間だという。

また、ある大手航空会社では、自社ブランドを模した偽の搭乗券発行アプリが見つかった。Check Pointはアラートから3分後に対応を開始し、リバースエンジニアリングでソースコードの流出や内部不正ではないことを24時間以内に特定。GitHubに公開されていたアプリ生成アルゴリズムのソースコードも発見し、モバイルアプリストアからの削除まで対応した。

いずれも、攻撃者の動向を把握する「脅威インテリジェンス」の実力を示す例だ。

一方、AEVそのものが脆弱性の悪用可能性を検証し、対応にまでつなげた例もある。ある企業向けアプリケーションの脆弱性(CVSSスコア9.6、既知の悪用事例あり)に対し、AEVがこれを検知。対象のWAF(ここではCloudflare)に自動で防御ルールを作成、デプロイし、誤検知がないことを確認した上でブロックモードに移行した。所要時間は、検知からわずか1時間だ。

個々の攻撃への対応力だけでなく、企業全体での成果を示す数字もある。Exposure Managementは、企業が既に保有しているセキュリティ製品(ファイアウォール、WAF、エンドポイント製品など)について、実際に脅威をブロックできる状態まで正しく設定・有効化されているかどうかを点検し、監視モードからブロックモードへと段階的に是正していく。この「既存投資だけでどこまで防御できているか」を示す指標が「セキュリティ・ハードニング効果」だ。

ある企業では、Check Point、F5(WAF)、Ciscoなど複数ベンダーのセキュリティ製品群を統合した。これにより、ハードニング効果は95%に達し、平均対応時間はわずか1.7時間に短縮した。この期間中、IPSで1300万件、WAFで1万件の攻撃をブロックし、200件超の是正措置を実施したという。

別の企業では、導入開始時点でハードニング効果が30%だったのが、1カ月後には83.8%まで向上。平均対応時間2.3時間、2000件の是正措置を実施したとしている。

AIエージェントで注目されるエクスポージャー管理だが、Check Point以外のベンダーもソリューションを持つ。

ザンガー氏によると、同社の強みは脅威インテリジェンスを軸とした「外部(攻撃者)視点」からのアプローチにあるという。それを支えているのは、Cyberint(2024年10月)とVeriti(2025年5月合意)の2社の買収だ。これらにより、外部脅威インテリジェンスとエクスポージャー管理の両輪を強化してきた。

「(Qualys、Tenable、Rapid7といった)既存の脆弱性管理ベンダーは、内部スキャンを起点としたアプローチをとる。われわれは内部スキャンの仕組みを持っておらず、彼らに外部からの視点の情報を提供する立場にある」とザンガー氏は説明した。

Linuxだから安全は通用しない

このように、AIは脆弱性管理のアプローチを変える必要性をもたらしたが、ザンガー氏は、業界全体の議論に懸念を示す。現在、脆弱性を巡る議論はMicrosoft、Oracle、SAPといった大手ベンダーのOSやミドルウェア、あるいはブラウザといった領域に集中しがちだ。しかし同氏は、オープンソースのフレームワークや自社開発アプリケーションこそ、今後大きなインパクトを受ける可能性があると指摘する。

「Log4jやStrutsのように、オープンソースのフレームワークで過去に大きな脆弱性が見つかった例は多い。ECサイトのソフトウェアパッケージなども同様だ。エンタープライズ企業の多くが社内でJavaアプリケーションを開発しており、SaaSベンダーも同様の技術を使っている。誰もが意識しなければならない領域のはずなのに、その議論があまり聞こえてこない」とザンガー氏。

ザンガー氏は、AIが攻撃者側の開発力そのものを底上げしている現実にも触れる。Check Point Researchが2025年末に発表した内容によれば、Windows向けの有名なオープンソースのペネトレーションツールを、単独の開発者が1週間で8万行のコードに移植し、Linux環境で動作するよう改造していた例が確認されたという。ベンチマークとして、同じツールを「Amazon Web Services」(AWS)で動作するよう移植するプロジェクトもあり、OS環境が異なっても機能性を再現しようとする動きが見られたとしている。「かつては『Linuxだから安全』『AppleやiOSだから安全』といった前提があった。しかしAIによって、そうした前提はもはや成り立たなくなる」。

「今までは自分の知識の範囲でしか動けなかった攻撃者が、AIという“もう一人のパートナー”を手に入れた」とザンガー氏、「恐ろしいことだ」と続ける。

こうした変化を踏まえ、ザンガー氏は次のようにアドバイスする。まずビジネスの優先順位を見直すこと。ベンダーからのアナウンスメントを注視すること。そして、ゼロデイ対策をエンドポイントに組み込み、アップデートの優先順位を上げていくこと。「次の2~3年、こうした備えは間違いなく必要になる」とザンガー氏は述べた。

What to Watch

AI outlook — possibilities, not facts

  • 今後1~2年で脆弱性の開示情報がベンダーから爆発的に増える

    Likely · Within months

  • オープンソースフレームワークや自社開発アプリケーションへの脅威が増大する

    Likely · Within years

Open Questions

  • AEVの具体的な技術仕様や精度はどの程度か?
  • 中小企業でもExposure Managementを導入可能か?
  • オープンソースコミュニティへの影響と対策は?

Related Topics

This article was originally published by ITmedia.

Related Stories

National Police Agency decides to develop AI support for 110 calls, envisioning voice-to-text conversion and emergency analysis
Developing·

National Police Agency decides to develop AI support for 110 calls, envisioning voice-to-text conversion and emergency analysis

In response to the increasing number of 110 calls received, the National Police Agency has decided to develop an AI system that automatically converts call audio into text and analyzes the level of urgency. The aim is to quickly and accurately record the contents of reports and eliminate variations in interviews by responding police officers.

朝日新聞
1 min read
Comparing Samsung Galaxy Z Fold8 and Huawei Pura X Max: Differences in the design philosophy of folding smartphones
Developing·

Comparing Samsung Galaxy Z Fold8 and Huawei Pura X Max: Differences in the design philosophy of folding smartphones

Samsung Electronics' Galaxy Z Fold8 and Huawei's HUAWEI Pura X Max are both horizontal folding smartphones, but they have different design philosophies. Samsung emphasizes thinness and lightness (201g, 9.7mm), while Huawei emphasizes the camera (3 eyes), battery (5300mAh), charging performance (wired 66W/wireless 50W), and waterproof performance (IP58/IP59). The weight difference of 28g makes a difference that can be felt in daily use.

ITmedia
2 min read
IBM powers collaboration between humans and digital workers, with over 4,000 AI agents running on 450 projects
Developing·

IBM powers collaboration between humans and digital workers, with over 4,000 AI agents running on 450 projects

Yuko Kawakami of IBM Japan explained that the company will promote collaboration between humans and digital workers (AI agents) starting in 2023, with over 4,000 digital workers working in over 450 project teams. It claims to have created a productivity improvement effect of $4.5 billion in 2025 by redesigning work flows and deploying it company-wide. He pointed out that in order to link the results of AI utilization to the management level, it is necessary to redesign both the business level and the infrastructure level.

ITmedia
3 min read
Salesforce and Claude collaboration plug-in “Salesforce in Claude” announced, providing 37 types of skills for sales
Developing·

Salesforce and Claude collaboration plug-in “Salesforce in Claude” announced, providing 37 types of skills for sales

Salesforce and Anthropic announced a plug-in called ``Salesforce in Claude,'' which allows users to access Salesforce data from the Claude interaction screen and equips them with 37 skills for sales, such as deal preparation and pipeline confirmation. By linking with the Headless 360 architecture and MCP, operations can be completed within existing authority rules, and there is no need to configure settings for each user with centralized authentication of the administrator. Controls that require user confirmation can also be selected for write operations. Starting in fall 2026, Enterprise Frontier Safeguards will be phased in, combining zero data retention and abuse detection. Claude can also be used as an inference engine for Agentforce, has become the standard model on Slack, and has reported an annual productivity improvement of 8.1 million hours using an in-house Slackbot. In response to the controversy over the shrinking role of SaaS, we advocate the continued value of data and workflows. It is currently available to some pilot customers, and an open beta version is scheduled to start in September 2026. Skills for departments other than sales are planned to be added from the second half of 2026.

ITmedia
3 min read
NEC begins demonstration experiment of facial recognition payment at Softbank headquarters
Developing·

NEC begins demonstration experiment of facial recognition payment at Softbank headquarters

NEC announced on the 4th that it has started a demonstration experiment of a payment service using facial recognition at the employee cafeteria of SoftBank's headquarters. Users register their face photo and credit card in advance, and once their face is recognized by the in-store terminal, payment is completed in a few seconds. The demonstration period will run until November 30th, and is expected to involve more than 1,000 payments. The aim is to improve the purchasing experience of users by eliminating the complexity of cash register operations associated with the spread of cashless payments.

ITmedia
2 min read
More on this topicai