メインコンテンツまでスキップ

クイックスタートガイド

適用対象:
WindowsLinuxmacOSDocker

インストール​

Linux​

# Download latest release
curl -LO https://downloads.duokey.com/dke-scanner-agent/linux/dke-scanner-agent-latest-x86_64.tar.gz

# Extract
tar xzf dke-scanner-agent-latest-x86_64.tar.gz

# Install
sudo mv dke-scanner-agent /usr/local/bin/
sudo chmod +x /usr/local/bin/dke-scanner-agent

# Verify installation
dke-scanner-agent --version

macOS​

# Using Homebrew (recommended)
brew tap duokey/tap
brew install dke-scanner-agent

# Or download directly
curl -LO https://downloads.duokey.com/dke-scanner-agent/macos/dke-scanner-agent-latest-universal.tar.gz
tar xzf dke-scanner-agent-latest-universal.tar.gz
sudo mv dke-scanner-agent /usr/local/bin/

# Verify
dke-scanner-agent --version

Windows​

# Download installer
Invoke-WebRequest -Uri "https://downloads.duokey.com/dke-scanner-agent/windows/dke-scanner-agent-setup.exe" -OutFile "dke-scanner-agent-setup.exe"

# Run installer (GUI)
.\dke-scanner-agent-setup.exe

# Or use winget
winget install DuoKey.PQCScanner

# Verify (in new PowerShell window)
dke-scanner-agent --version

最初のスキャン​

簡単なヘルスチェック​

まずは、公開ウェブサイトの簡単なスキャンから始めましょう。

# Scan a domain
dke-scanner-agent domain --target example.com:443

ローカルシステムのスキャン(エージェントモード)​

ローカルマシンの包括的な評価を行うには次のようにします。

# Run with elevated privileges
sudo dke-scanner-agent agent --output my-system-scan.json

# View results
cat my-system-scan.json | jq '.summary'

アプリケーションディレクトリのスキャン(ファイルシステムモード)​

アプリケーションの証明書ディレクトリをスキャンします。

# Scan recursively
dke-scanner-agent filesystem --path /opt/myapp --recursive --output app-scan.json

# View high-risk findings
cat app-scan.json | jq '.findings[] | select(.risk_assessment.severity == "HIGH")'

ネットワークトラフィックのスキャン(ネットワークモード)​

権限が必要

ネットワークモードには root/admin 権限または CAP_NET_RAW ケーパビリティが必要です。

# Capture TLS handshakes for 5 minutes
sudo dke-scanner-agent network --interface eth0 --duration 5m --output network-scan.json

# Real-time monitoring with TUI
sudo dke-scanner-agent network --interface eth0 --tui

出力の理解​

リスク重大度レベル​

スキャナーは 4 つの重大度レベルのいずれかを割り当てます。

重大度スコア範囲意味必要な対応
CRITICAL9.0-10.0即時の量子脅威緊急対応
HIGH7.0-8.9重大な脆弱性3〜6 か月以内に計画
MEDIUM4.0-6.9中程度のリスク12 か月以内に計画
LOW0-3.9軽微または情報提供監視

アルゴリズムの脆弱性​

一般的なアルゴリズムとその量子リスク。

アルゴリズムリスク備考
RSA-1024Critical (10/10)旧式 — 今すぐ置き換える
RSA-2048High (8/10)現行の標準、量子脆弱
RSA-4096Medium (5/10)現在は強力だが将来的に脆弱
ECDSA P-256High (8/10)一般的な ECC、脆弱
EdDSA (Ed25519)High (7/10)モダンだが量子脆弱
ML-KEM-768Low (1/10)ポスト量子で安全

サンプルレポート構造​

一般的なスキャンパターン​

インフラストラクチャの初回評価。

#!/bin/bash
# comprehensive-assessment.sh

echo "=== DuoKey PQC Scanner - Initial Assessment ==="

# 1. Scan local system
echo "Scanning local system..."
sudo dke-scanner-agent agent --output results/agent-scan.json

# 2. Scan application directories
echo "Scanning application directories..."
dke-scanner-agent filesystem \
--path /opt/applications \
--recursive \
--output results/filesystem-scan.json

# 3. Scan public endpoints
echo "Scanning public endpoints..."
dke-scanner-agent domain \
--targets-file production-endpoints.txt \
--test-versions \
--output results/domain-scan.json

# 4. Generate summary report
echo "Generating summary..."
cat results/*.json | jq -s 'map(.summary) | add' > results/summary.json

echo "Assessment complete! Check results/ directory"

次のステップ​

1. 結果の分析​

# Get high-priority findings
jq '.findings[] | select(.risk_assessment.priority == "P0" or .risk_assessment.priority == "P1")' scan-results.json

# Count by algorithm
jq '.findings | group_by(.algorithm) | map({algorithm: .[0].algorithm, count: length})' scan-results.json

# Export to CSV for reporting
jq -r '.findings[] | [.location, .algorithm, .key_size, .risk_assessment.severity] | @csv' scan-results.json > findings.csv

2. 移行計画の作成​

スキャナーに組み込まれた移行プランナーを使用します。

# Generate migration roadmap
dke-scanner-agent plan --input scan-results.json --output migration-plan.json

# View roadmap
cat migration-plan.json | jq '.phases'

3. ダッシュボードのセットアップ​

結果を監視システムに送信します。

# Prometheus
dke-scanner-agent agent --format prometheus | curl -X POST http://pushgateway:9091/metrics/job/pqc_scanner

# Elasticsearch
dke-scanner-agent agent --format json | curl -X POST http://elasticsearch:9200/pqc-scans/_doc -H 'Content-Type: application/json' -d @-

# Splunk
dke-scanner-agent agent --format json | gzip | curl -X POST https://splunk:8088/services/collector \
-H "Authorization: Splunk $SPLUNK_TOKEN" \
--data-binary @-

4. 定期スキャンのスケジュール​

スキャンの頻度(ケイデンス)を確立します。

  • 毎日: クリティカルな本番システム
  • 毎週: すべての本番インフラストラクチャ
  • 毎月: 組織全体の完全な評価
  • オンデマンド: 主要なデプロイや変更の前

トラブルシューティング​

ベストプラクティス​

推奨されるプラクティス

小さく始める

スコープを広げる前に、単一のアプリケーションでのパイロットスキャンから始める

バージョン管理

タイムスタンプ付きでスキャンを保存し、バージョン管理で追跡

自動化

ラッパースクリプトを作成し、定期スキャンをスケジュール

データの保護

機密性の高いスキャン結果を暗号化し、ファイル権限を制限

学習リソース​

まとめ​

学んだこと

PQCスキャナーをインストールするバイナリ、ソース、または Docker
最初のスキャンを実行するドメイン、エージェント、ファイルシステムの各モード
スキャン結果を理解する重大度レベルとリスクスコア
CI/CD と統合するGitHub Actions ワークフロー
監視をセットアップするダッシュボードと定期スキャン
ベストプラクティスに従う自動化、セキュリティ、バージョン管理
次に推奨されるステップ
  1. システムの包括的なエージェントスキャンを実行する
  2. 検出結果を優先度別にレビューして分類する
  3. P0/P1 項目の移行ロードマップを作成する
  4. 自動化された週次スキャンをセットアップする
  5. 結果をセキュリティチームと共有する
ヘルプが必要ですか?

問題が発生した場合や質問がある場合は、トラブルシューティングガイド を確認するか、[email protected] までサポートにお問い合わせください

クイックリファレンスカード​

# Common Commands Cheat Sheet

# Agent mode (system scan)
sudo dke-scanner-agent agent --output agent-scan.json

# Filesystem mode (directory scan)
dke-scanner-agent filesystem --path /app --recursive

# Domain mode (TLS endpoint scan)
dke-scanner-agent domain --target example.com:443 --test-versions

# Network mode (packet capture)
sudo dke-scanner-agent network --interface eth0 --duration 60m

# Batch domain scanning
dke-scanner-agent domain --targets-file domains.txt --concurrency 20

# Output formats
--format json # Machine-readable (default)
--format yaml # Human-readable
--format terminal # Pretty-printed
--format sarif # CI/CD integration

# Common filters
--include-extensions .jks,.p12,.pem
--exclude-paths node_modules,target
--max-depth 3

# Performance tuning
--threads 20
--timeout 30