クイックスタートガイド
クイックスタートガイド
DuoKey PQCスキャナーをわずか数分で使い始めましょう。このガイドでは、インストール、最初のスキャン、そして結果の解釈までを順を追って説明します。
適用対象:
WindowsLinuxmacOSDocker
インストール
Linux
# Download latest release
curl -LO https://downloads.duokey.com/dke-scanner-agent/linux/dke-scanner-agent-latest-x86_64.tar.gz
# Extract
tar xzf dke-scanner-agent-latest-x86_64.tar.gz
# Install
sudo mv dke-scanner-agent /usr/local/bin/
sudo chmod +x /usr/local/bin/dke-scanner-agent
# Verify installation
dke-scanner-agent --version
macOS
# Using Homebrew (recommended)
brew tap duokey/tap
brew install dke-scanner-agent
# Or download directly
curl -LO https://downloads.duokey.com/dke-scanner-agent/macos/dke-scanner-agent-latest-universal.tar.gz
tar xzf dke-scanner-agent-latest-universal.tar.gz
sudo mv dke-scanner-agent /usr/local/bin/
# Verify
dke-scanner-agent --version
Windows
# Download installer
Invoke-WebRequest -Uri "https://downloads.duokey.com/dke-scanner-agent/windows/dke-scanner-agent-setup.exe" -OutFile "dke-scanner-agent-setup.exe"
# Run installer (GUI)
.\dke-scanner-agent-setup.exe
# Or use winget
winget install DuoKey.PQCScanner
# Verify (in new PowerShell window)
dke-scanner-agent --version
最初のスキャン
簡単なヘルスチェック
まずは、公開ウェブサイトの簡単なスキャンから始めましょう。
# Scan a domain
dke-scanner-agent domain --target example.com:443
ローカルシステムのスキャン(エージェントモード)
ローカルマシンの包括的な評価を行うには次のようにします。
# Run with elevated privileges
sudo dke-scanner-agent agent --output my-system-scan.json
# View results
cat my-system-scan.json | jq '.summary'
アプリケーションディレクトリのスキャン(ファイルシステムモード)
アプリケーションの証明書ディレクトリをスキャンします。
# Scan recursively
dke-scanner-agent filesystem --path /opt/myapp --recursive --output app-scan.json
# View high-risk findings
cat app-scan.json | jq '.findings[] | select(.risk_assessment.severity == "HIGH")'
ネットワークトラフィックのスキャン(ネットワークモード)
権限が必要
ネットワークモードには root/admin 権限または CAP_NET_RAW ケーパビリティが必要です。
# Capture TLS handshakes for 5 minutes
sudo dke-scanner-agent network --interface eth0 --duration 5m --output network-scan.json
# Real-time monitoring with TUI
sudo dke-scanner-agent network --interface eth0 --tui
出力の理解
リスク重大度レベル
スキャナーは 4 つの重大度レベルのいずれかを割り当てます。
| 重大度 | スコア範囲 | 意味 | 必要な対応 |
|---|---|---|---|
| CRITICAL | 9.0-10.0 | 即時の量子脅威 | 緊急対応 |
| HIGH | 7.0-8.9 | 重大な脆弱性 | 3〜6 か月以内に計画 |
| MEDIUM | 4.0-6.9 | 中程度のリスク | 12 か月以内に計画 |
| LOW | 0-3.9 | 軽微または情報提供 | 監視 |
アルゴリズムの脆弱性
一般的なアルゴリズムとその量子リスク。
| アルゴリズム | リスク | 備考 |
|---|---|---|
| RSA-1024 | Critical (10/10) | 旧式 — 今すぐ置き換える |
| RSA-2048 | High (8/10) | 現行の標準、量子脆弱 |
| RSA-4096 | Medium (5/10) | 現在は強力だが将来的に脆弱 |
| ECDSA P-256 | High (8/10) | 一般的な ECC、脆弱 |
| EdDSA (Ed25519) | High (7/10) | モダンだが量子脆弱 |
| ML-KEM-768 | Low (1/10) | ポスト量子で安全 |
サンプルレポート構造
一般的なスキャンパターン
インフラストラクチャの初回評価。
#!/bin/bash
# comprehensive-assessment.sh
echo "=== DuoKey PQC Scanner - Initial Assessment ==="
# 1. Scan local system
echo "Scanning local system..."
sudo dke-scanner-agent agent --output results/agent-scan.json
# 2. Scan application directories
echo "Scanning application directories..."
dke-scanner-agent filesystem \
--path /opt/applications \
--recursive \
--output results/filesystem-scan.json
# 3. Scan public endpoints
echo "Scanning public endpoints..."
dke-scanner-agent domain \
--targets-file production-endpoints.txt \
--test-versions \
--output results/domain-scan.json
# 4. Generate summary report
echo "Generating summary..."
cat results/*.json | jq -s 'map(.summary) | add' > results/summary.json
echo "Assessment complete! Check results/ directory"
次のステップ
1. 結果の分析
# Get high-priority findings
jq '.findings[] | select(.risk_assessment.priority == "P0" or .risk_assessment.priority == "P1")' scan-results.json
# Count by algorithm
jq '.findings | group_by(.algorithm) | map({algorithm: .[0].algorithm, count: length})' scan-results.json
# Export to CSV for reporting
jq -r '.findings[] | [.location, .algorithm, .key_size, .risk_assessment.severity] | @csv' scan-results.json > findings.csv
2. 移行計画の作成
スキャナーに組み込まれた移行プランナーを使用します。
# Generate migration roadmap
dke-scanner-agent plan --input scan-results.json --output migration-plan.json
# View roadmap
cat migration-plan.json | jq '.phases'
3. ダッシュボードのセットアップ
結果を監視システムに送信します。
# Prometheus
dke-scanner-agent agent --format prometheus | curl -X POST http://pushgateway:9091/metrics/job/pqc_scanner
# Elasticsearch
dke-scanner-agent agent --format json | curl -X POST http://elasticsearch:9200/pqc-scans/_doc -H 'Content-Type: application/json' -d @-
# Splunk
dke-scanner-agent agent --format json | gzip | curl -X POST https://splunk:8088/services/collector \
-H "Authorization: Splunk $SPLUNK_TOKEN" \
--data-binary @-
4. 定期スキャンのスケジュール
スキャンの頻度(ケイデンス)を確立します。
- 毎日: クリティカルな本番システム
- 毎週: すべての本番インフラストラクチャ
- 毎月: 組織全体の完全な評価
- オンデマンド: 主要なデプロイや変更の前
トラブルシューティング
ベストプラクティス
推奨されるプラクティス
小さく始める
スコープを広げる前に、単一のアプリケーションでのパイロットスキャンから始める
バージョン管理
タイムスタンプ付きでスキャンを保存し、バージョン管理で追跡
自動化
ラッパースクリプトを作成し、定期スキャンをスケジュール
データの保護
機密性の高いスキャン結果を暗号化し、ファイル権限を制限
学習リソース
まとめ
学んだこと
PQCスキャナーをインストールするバイナリ、ソース、または Docker
最初のスキャンを実行するドメイン、エージェント、ファイルシステムの各モード
スキャン結果を理解する重大度レベルとリスクスコア
CI/CD と統合するGitHub Actions ワークフロー
監視をセットアップするダッシュボードと定期スキャン
ベストプラクティスに従う自動化、セキュリティ、バージョン管理
次に推奨されるステップ
- システムの包括的なエージェントスキャンを実行する
- 検出結果を優先度別にレビューして分類する
- P0/P1 項目の移行ロードマップを作成する
- 自動化された週次スキャンをセットアップする
- 結果をセキュリティチームと共有する
ヘルプが必要ですか?
問題が発生した場合や質問がある場合は、トラブルシューティングガイド を確認するか、[email protected] までサポートにお問い合わせください
クイックリファレンスカード
# Common Commands Cheat Sheet
# Agent mode (system scan)
sudo dke-scanner-agent agent --output agent-scan.json
# Filesystem mode (directory scan)
dke-scanner-agent filesystem --path /app --recursive
# Domain mode (TLS endpoint scan)
dke-scanner-agent domain --target example.com:443 --test-versions
# Network mode (packet capture)
sudo dke-scanner-agent network --interface eth0 --duration 60m
# Batch domain scanning
dke-scanner-agent domain --targets-file domains.txt --concurrency 20
# Output formats
--format json # Machine-readable (default)
--format yaml # Human-readable
--format terminal # Pretty-printed
--format sarif # CI/CD integration
# Common filters
--include-extensions .jks,.p12,.pem
--exclude-paths node_modules,target
--max-depth 3
# Performance tuning
--threads 20
--timeout 30