Edge ApplianceからIdentity侵害へ ― F5 / Confluence攻撃Chainが示す境界防御の盲点
Executive Summary
Microsoftは2026年5月22日、Internet-facing F5 BIG-IP Applianceを起点としてLinux環境へ侵入し、内部のConfluence ServerへPivotしてCredential TheftとIdentity Compromiseへ進んだMulti-stage Attackを報告しました。観測されたBIG-IP Versionは2024年末にEOLとなっていたものです。1
この事例の重要点は、Edge Device侵害を「Network機器の問題」で終わらせず、Edge → Internal Server → Credential → IdentityというAttack Pathで捉える必要があることです。
なぜ今なのか
Firewall、VPN、Load Balancer等のEdge ApplianceはInternetへ公開され、高権限Network位置を持つ一方、Server/Endpointと比べてEDRや通常のAsset Managementが適用しにくい場合があります。
EOL Productや管理不足のVirtual Applianceが残ると、内部侵入の入口になります。
攻撃Chain
- Internet-facing Edge Applianceへの侵入
- SSH等によるLinux HostへのAccess
- Internal Reconnaissance
- Confluence等のServerへPivot
- Credential Access
- Identity / Additional Systemへ横展開
Microsoftは特定Incidentだけでなく、Edge DeviceのN-day Vulnerabilityを入口にする高Impact Incidentの増加傾向も指摘しています。
MITRE ATT&CK® Mapping
この表は、攻撃・Campaignの理解に有用な場合だけ表示します。Source-labeled は一次情報がATT&CK IDを明示したもの、Analyst-mapped は一次情報に記載された行動を本LibraryがATT&CKへ対応付けたものです。後者は、元情報の発行者がそのATT&CK IDを明示したことを意味しません。
| Technique | Tactic | Basis | Article context |
|---|---|---|---|
| T1021.004 Remote Services: SSH | Lateral Movement | Source-labeled | Microsoftが本CampaignのObserved ATT&CK TechniqueとしてSSH利用を明示。 |
| T1083 File and Directory Discovery | Discovery | Source-labeled | MicrosoftがLinux Host上のFile EnumerationをObserved ATT&CK Techniqueとして明示。 |
| T1190 Exploit Public-Facing Application | Initial Access | Source-labeled | Microsoftが脆弱なConfluence ServerへのRCEをObserved ATT&CK Techniqueとして明示。 |
| T1505 Server Software Component | Persistence | Source-labeled | MicrosoftがConfluence Web Server上のWeb ShellによるPersistent AccessをT1505として明示。 |
| T1078.002 Valid Accounts: Domain Accounts | Initial Access, Persistence, Privilege Escalation, Defense Evasion | Source-labeled | MicrosoftがConfluence ServerのDomain Credential利用をObserved ATT&CK Techniqueとして明示。 |
| T1187 Forced Authentication | Credential Access | Source-labeled | MicrosoftがDomain Controllerを狙うAuthentication Coercion / Relay行動を明示。 |
| T1557 Adversary-in-the-Middle | Credential Access, Collection | Source-labeled | MicrosoftがRelay-style Authentication AttackをAdversary-in-the-Middleとして明示。 |
経営インパクト
| 観点 | 影響 |
|---|---|
| Asset Management | Network ApplianceもServer同等のLifecycle管理が必要 |
| Legacy Risk | EOL ApplianceはPatch不能・Detection不足の二重Risk |
| Identity | Edge侵害後の最終TargetがCredentialになる |
| Cloud | Marketplace / Templateから古いImageが残る可能性 |
日本企業への示唆
Cloud上のVirtual ApplianceやSIerが導入したGatewayは「Network機器」として別管理されることがあります。Version / EOL / Exposure / Admin AccessをCMDBへ統合し、Identity側の監視とつなげる必要があります。
推奨アクション
- Internet-facing Edge ApplianceをAsset Inventoryで特定する
- Version / EOL / Security Update状況を継続確認する
- 管理InterfaceとSSH Accessを制限する
- Edgeから内部Serverへの通信をSegmentationする
- Edge侵害後のCredential AccessをITDR / SIEMで監視する
- Cloud Template / Marketplace Imageの古いVersionを棚卸しする
用語解説
Edge Appliance
Firewall、VPN、Load Balancer、Gateway等、Internetと内部Networkの境界付近で動作するSecurity / Network機器。