> ## Documentation Index
> Fetch the complete documentation index at: https://docs-staging-feat-init-gt-translations.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

> Auth0 が攻撃を検知して、アプリケーションへの悪意あるアクセス試行を防ぎ、不審なアクティビティをあなたやユーザーに通知し、以後のログイン試行をブロックする仕組みについて説明します。

# 攻撃対策

Auth0 は攻撃を検知し、特定の IP からのトラフィックをブロックしたり CAPTCHA を表示したりすることで、アプリケーションへの悪意あるアクセス試行を防止できます。

[Auth0 Dashboard](https://manage.auth0.com/#/security/attack-protection) では、攻撃を軽減するために、次の <Tooltip tip="攻撃対策: Auth0 が攻撃を検知して軽減するために提供する機能です。これには、ブルートフォース対策、不審な IP のスロットリング、漏えいパスワードの検知、ボット検知、適応型多要素認証が含まれます。" cta="用語集を表示" href="/docs/ja-jp/glossary?term=attack+protection">攻撃対策</Tooltip> オプションを有効にできます。

* [ボット検知](/docs/ja-jp/secure/attack-protection/bot-detection)
* [不審な IP のスロットリング](/docs/ja-jp/secure/attack-protection/suspicious-ip-throttling)
* [ブルートフォース対策](/docs/ja-jp/secure/attack-protection/brute-force-protection)
* [漏えいパスワードの検知](/docs/ja-jp/secure/attack-protection/breached-password-detection)

<Frame>
  <img src="https://mintcdn.com/docs-staging-feat-init-gt-translations/lFCCXa5dVspGIuTF/docs/images/cdy7uua7fh8z/7IxNz72aMoNqIEgGKPZiuv/ee9f7ec600bd2495bf51d0b338939b25/dashboard-attack-protection-list.png?fit=max&auto=format&n=lFCCXa5dVspGIuTF&q=85&s=09d0573d379e0ed184295ca75b669eca" alt="Auth0 Dashboard の Security > Attack Protection ページ" data-og-width="1504" width="1504" data-og-height="990" height="990" data-path="docs/images/cdy7uua7fh8z/7IxNz72aMoNqIEgGKPZiuv/ee9f7ec600bd2495bf51d0b338939b25/dashboard-attack-protection-list.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/docs-staging-feat-init-gt-translations/lFCCXa5dVspGIuTF/docs/images/cdy7uua7fh8z/7IxNz72aMoNqIEgGKPZiuv/ee9f7ec600bd2495bf51d0b338939b25/dashboard-attack-protection-list.png?w=280&fit=max&auto=format&n=lFCCXa5dVspGIuTF&q=85&s=12be323af9880ea4791b2d1691fe72f8 280w, https://mintcdn.com/docs-staging-feat-init-gt-translations/lFCCXa5dVspGIuTF/docs/images/cdy7uua7fh8z/7IxNz72aMoNqIEgGKPZiuv/ee9f7ec600bd2495bf51d0b338939b25/dashboard-attack-protection-list.png?w=560&fit=max&auto=format&n=lFCCXa5dVspGIuTF&q=85&s=13e582c6cd44ffdd5e27e53b4a65e7e7 560w, https://mintcdn.com/docs-staging-feat-init-gt-translations/lFCCXa5dVspGIuTF/docs/images/cdy7uua7fh8z/7IxNz72aMoNqIEgGKPZiuv/ee9f7ec600bd2495bf51d0b338939b25/dashboard-attack-protection-list.png?w=840&fit=max&auto=format&n=lFCCXa5dVspGIuTF&q=85&s=c63faac802274e7d8ab3ce9cbdc2b372 840w, https://mintcdn.com/docs-staging-feat-init-gt-translations/lFCCXa5dVspGIuTF/docs/images/cdy7uua7fh8z/7IxNz72aMoNqIEgGKPZiuv/ee9f7ec600bd2495bf51d0b338939b25/dashboard-attack-protection-list.png?w=1100&fit=max&auto=format&n=lFCCXa5dVspGIuTF&q=85&s=fcae99d9904b1432da1f957c6eb63beb 1100w, https://mintcdn.com/docs-staging-feat-init-gt-translations/lFCCXa5dVspGIuTF/docs/images/cdy7uua7fh8z/7IxNz72aMoNqIEgGKPZiuv/ee9f7ec600bd2495bf51d0b338939b25/dashboard-attack-protection-list.png?w=1650&fit=max&auto=format&n=lFCCXa5dVspGIuTF&q=85&s=772b4785e97169300b6f866b91fb5ebd 1650w, https://mintcdn.com/docs-staging-feat-init-gt-translations/lFCCXa5dVspGIuTF/docs/images/cdy7uua7fh8z/7IxNz72aMoNqIEgGKPZiuv/ee9f7ec600bd2495bf51d0b338939b25/dashboard-attack-protection-list.png?w=2500&fit=max&auto=format&n=lFCCXa5dVspGIuTF&q=85&s=b8f8f60647ecfbbeccfbf2a72b97c12b 2500w" />
</Frame>

<div id="how-it-works">
  ## 仕組み
</div>

不正利用対策に決定打となる万能策はありません。Auth0 は、さまざまなシグナルを用いて攻撃を検知・緩和する、多層防御というセキュリティの考え方を採用しています。

| 機能                          | リスクシグナル                                        | 仕組み                                                      |
| --------------------------- | ---------------------------------------------- | -------------------------------------------------------- |
| Bot Detection               | 各 IP で観測されたトラフィックの質を分析して算出される **IP レピュテーション**。 | ボットによる利用が疑われる IP からログイン試行があった場合に、CAPTCHA を要求します。         |
| Suspicious IP Throttling    | テナント内の複数アカウントに対する、ある IP からのログイン試行の **頻度**。     | ボットやスクリプトが短時間に多数の identifier とパスワードの組み合わせを試している場合に検知します。 |
| Brute-force Protection      | 特定のアカウントに対する、ある IP からのログイン試行の **頻度**。          | 悪意のある第三者が一定時間内に同じアカウントへのログインを何度も試みた場合に検知します。             |
| Breached Password Detection | ダークウェブ上の漏えいパスワードのリストに含まれる **漏えい済みパスワードの使用**。   | 一部のサードパーティ サイトですでに漏えいが確認されているパスワードを、ユーザーが使用できないようにします。   |

<div id="notification">
  ## 通知
</div>

攻撃が発生した場合、ログイン回数にかかわらず、ユーザーには 1 時間に 1 回メールで通知されます。たとえば、あるユーザーが 1 時間 30 分の間に 200 回ログインを試みた場合、送信されるメールは 2 通です。パスワードリセットリンクの有効期限は 5 日間です。ユーザーに送信する[メールはカスタマイズ](/docs/ja-jp/customize/email/customize-blocked-account-emails)できます。

<Callout icon="file-lines" color="#0EA5E9" iconType="regular">
  ブロックをリセットした後に再び攻撃が発生した場合は、追加でメールが送信されます。
</Callout>

攻撃が継続している場合、一度に数千もの IP アドレスからのトラフィックがブロックされることがあります。Auth0 は、攻撃に関与する IP アドレスの数にかかわらず、トラフィックがブロックされている間、各管理者に 1 時間ごとに 1 通のメールを送信します。

<div id="monitoring">
  ## 監視
</div>

応答設定を構成せずに攻撃対策機能を有効化すると、監視モードが有効になり、関連するイベントはテナントログにのみ記録されます。テナントログには、ログインがリスクありと判断されたかどうかに関する情報が記録されるため、応答を構成するかどうかを判断できます。

<div id="reporting">
  ## レポート
</div>

テナントログデータを使用してレポートを作成し、[攻撃対策イベントを確認する](/docs/ja-jp/secure/attack-protection/view-attack-protection-events)こともできます。

<div id="learn-more">
  ## 詳細はこちら
</div>

* [ボット検知](/docs/ja-jp/secure/attack-protection/bot-detection)
* [不審な IP のスロットリング](/docs/ja-jp/secure/attack-protection/suspicious-ip-throttling)
* [ブルートフォース対策](/docs/ja-jp/secure/attack-protection/brute-force-protection)
* [漏えいパスワードの検知](/docs/ja-jp/secure/attack-protection/breached-password-detection)
* [攻撃対策のログイベントを確認する](/docs/ja-jp/secure/attack-protection/view-attack-protection-events)
