シャドーイング練習: MITRE ATT&CK® Framework - 動画で英語スピーキングを学ぶ

レッスンを作成中...
1
It's been reported that once an organization is breached, adversaries typically lurk on networks for months before being detected.
2
How did they get in?
3
How are they moving around?
4
What are they doing?
5
So where do you start?
6
MITRE's ATT&CK framework describes how adversaries penetrate networks and then move laterally, escalate privileges, and generally evade your defenses.
7
ATT&CK looks at the problem from the perspective of the adversary, what goals they are trying to achieve, and what specific methods they use.
8
ATT&CK organizes adversary behaviors into a series of tactics, specific technical objectives that an attacker wants to achieve.
9
Some examples of tactics include defense evasion, lateral movement, and exfiltration.
10
Within each tactic category, attack defines a series of techniques.
11
Each technique describes one way an adversary may try to achieve that objective.
12
There are multiple techniques within each tactic
13
because adversaries may use different methods based on their own expertise
14
or things like the availability of tools or how your systems are configured.
15
Each technique defined in attack includes a description of the method used by the adversary, the systems or platforms it applies to,
16
and where known, what specific adversary groups use this technique.
17
Techniques also describe ways to mitigate the behavior, along with any published references to the technique being employed.
18
ATT&CK helps you understand how adversaries might operate so you can plan how to detect or stop that behavior.
19
Armed with this knowledge, you can better understand the different ways an adversary prepares for, launches, and executes their attacks.
20
Another important use of ATT&CK is to help you detect an adversary's actions.
21
The ATT&CK framework includes resources designed to help you develop analytics that detect the techniques used by an adversary.
22
ATT&CK also maintains a library of information about selected adversary groups and the campaigns they have conducted.
23
And since ATT&CK is based on real-world observations, it allows you to correlate specific adversaries and the techniques they've used.
24
Because adversaries often use different techniques to attack different platforms and technologies, the ATT&CK framework is divided into a series of technology domains.
25
currently covered by ATT&CK include enterprise networks with Windows and Linux operating systems and mobile devices.
26
The ATT&CK framework can help your organization better understand the techniques specific adversaries are likely to use,
27
information you can use to evaluate your defenses and strengthen them where it matters most.
28
MITRE is building a community around ATT&CK so that experts in different domains
29
and technologies can come together to refine and extend the knowledge contained in the framework.
30
And because MITRE is a not-for-profit organization operating in the public interest, we can provide a conflict-free environment to create,
31
collect, share, and manage this information, making it available to everyone.
32
Learn more about ATT&CK and what else we're doing in cyber threat intelligence.
33
MITRE.
34
We solve problems for a safer world.

この動画は誰におすすめ?

英語スピーキング練習を始めたばかりの人や、ビジネス英語や技術系の会話に慣れたい人にぴったりです。動画ではサイバーセキュリティの専門用語が出てきますが、しっかりと説明されているので、聞き取り力と同時に専門知識も身につけられます。shadowing siteを使って繰り返し練習すれば、自然な発音とリズムが身につきますよ。

覚えておきたい単語とイディオム

  • lurk:忍び込んでいる、潜んでいる。「adversaries typically lurk on networks」は「攻撃者は通常ネットワークに潜んでいる」という意味。
  • lateral movement: lateral(横の)+ movement(移動)で、「横方向の移動」。サイバー攻撃では「ネットワーク内での水平移動」を指します。
  • escalate privileges: privilege(特権)をescalate(拡大する)、「権限昇格」。攻撃者がシステムの権限を奪うこと。

これらの単語は技術系の会話でよく使われるので、shadow speechの練習に組み込んでおくと便利です。

発音を上達させるコツ

この動画のスピーカーは比較的ゆっくりとはっきり話していますが、「MITRE ATT&CK® Framework」のような固有名詞や「exfiltration」(データ窃取)のような長い単語の発音に注意が必要です。「英語の発音を良くする」ためには、まず単語のアクセントを確認しましょう。例えば「escalate」は「エスカレイト」ではなく「エスカレイト」(アクセントは2番目の音節)です。shadowspeaksのようなshadowing siteを使って、スピーカーの発音を真似るshadow speechの練習をすると、自然なリズムが身につきます。また、「adversaries」(攻撃者)のような単語の末尾の「-ies」は「ズ」ではなく「ィーズ」と発音するので、注意してください。

英語スピーキング練習には、繰り返し聴いて真似ることが大切です。この動画を使ってshadowingを続ければ、発音だけでなく聞き取り力も向上し、自信をつけることができるでしょう。

シャドーイングとは?英語上達に効果的な理由

シャドーイング(Shadowing)は、もともとプロの通訳者養成プログラムで開発された言語学習法で、多言語習得者として知られるDr. Alexander Arguelles によって広く普及されました。方法はシンプルですが非常に効果的:ネイティブスピーカーの英語を聞きながら、1〜2秒の遅延で声に出してすぐに繰り返す——まるで「影(shadow)」のように話者を追いかけます。文法ドリルや受動的なリスニングと異なり、シャドーイングは脳と口の筋肉が同時にリアルタイムで英語を処理・再現することを強制します。研究により、発音精度、抑揚、リズム、連音、リスニング力、そして会話の流暢さが大幅に向上することが確認されています。IELTSスピーキング対策や自然な英語コミュニケーションを目指す方に特におすすめです。

シャドーイングのやり方: ステップ別の完全ガイドを読む →