ãæ°Žè²¬ãããšããæãããååã®ãµã€ããŒæ»æãããã®ããåç¥ã§ãããããããã¯å ã ã¢ã¡ãªã«ã§ãDNS Water Torture Attackããšåä»ãããããããåèš³ãããåŒã³åã§ããæ°Žãé¡ã«æµŽã³ããã倧éã«é£²ãŸãããããæ·åãèªæºãšããŠåœåããããšãããªããšãæããããªæ»æã§ãã
åç·šã§ã¯ã氎責ããè¿å¹Žå€ã芳枬ãããŠããã2023å¹Žã«æ¥æ¬ã§ã¯æ¿åºé¢é£çµç¹ãèªæ²»äœã®è¢«å®³ãå ±éãããããšãåãäžããŸãããä»åã¯ãã®åä»ãªæ°Žè²¬ãã®è¢«å®³ããã©ã®ããã«ããŠã·ã¹ãã ãå®ãããšãã察çã«ã€ããŠè§£èª¬ããŸãã
DDoS察çã®åºæ¬çãªèãæ¹
ãDoS(Denial of Service)æ»æãã¯ãæšçãšãªãã·ã¹ãã ãããã¯ãããã¯ãŒã¯åž¯åãéè² è·ç¶æ ã«ããŠäœ¿çšäžèœã«ããæ»æã§ãããããå€ãã®å€æ§ãªéä¿¡å ãã倧éã®ãã©ãã£ãã¯ã§è¡ãå Žåã«D(DistributedïŒåæ£ãšããæå³)ãä»ããDDoSæ»æãšãªããŸãããããé²ã解決çã倧å¥ãããšä»¥äžã®2ã€ãäž»ãªéžæè¢ãšãªããŸãã
1. æ»æã鮿ãã
äžæ£ãªéä¿¡ãæ€ç¥ãã察象ã·ã¹ãã ã«å°éããåã«é®æãããäžæ£ã§ããããšã®æ ¹æ ãšããŠããã®éä¿¡ã®äžèº«ãéä¿¡å
ã®IPã¢ãã¬ã¹ãªã©ã§å€æããææ³ãªã©ãæããããã
2. è² è·ã忣ãã
äžæ£ãªéä¿¡ãæšçã«ããã·ã¹ãã ãå°ççã«åæ£ãããã€åå Žæã«ãããŠãµãŒããè€æ°é
眮ããŠè² è·åæ£ãè¡ãã忣ããŠçºããããæ»æãåæµãããªãããšã§DDoSã®æç«ãé»ãã
ã鮿ãã¯å°é£
æ°Žè²¬ãæ»æã®åä»ãªãšããã¯ã鮿ãã¥ãããšããã§ããæ°Žè²¬ã以å€ã®DNSãæšçã«ããDDoSæ»æãšããŠã¯ããããããªãã¬ã¯ã·ã§ã³æ»æãªã©ã«ãããã©ãã£ãã¯ããªã¥ãŒã åã®æ»æããããŸããããããã®å Žåã«ã¯ISPããªã³ãã¬ãã¹åã®DDoS察çãœãªã¥ãŒã·ã§ã³ã«ãã£ãŠé®æãã察çãæå¹ã§ãã
察ããŠã氎責ãã¯åœ¢ã®äžã§ã¯ãã£ãã·ã¥DNSãµãŒãããæ¥ãŠããDNSã¯ãšãªã§ãããæ£åœãªãŸãŒã³æ å ±ãšç §ããåãããªãéãäžæ£ã¯ãšãªã§ãããšããå€å¥ãã€ããŸãããæ£åœãªISPã®ãã£ãã·ã¥DNSãµãŒããããçºè¡ããããããéä¿¡å ããŒã¹ã§é®æããããšãã§ããŸããã
è² è·ã忣ããæ¹æ³
çŸç¶ã氎責ãã«å¯ŸããŠã¯è² è·åæ£ãæãæå¹ã§ããæš©åšDNSãµãŒãã¯ãå ã è€æ°å°ã§æ§æããããšãæ³å®ãããŠããããŸãŒã³ããŒã¿ãè€æ°ãµãŒãã§åæãããããŸãŒã³è»¢éãæ©èœãæã£ãŠããŸãããããç©ççã«é¢ãã倧éã®DNSãµãŒãéã§æ§æããããšã§ãè² è·ã忣ãããããšãã§ããŸãã
ã§ãããäŒæ¥ãèªæ²»äœãèªåã§è€æ°ããŒã¿ã»ã³ã¿ãŒãšã€ã³ã¿ãŒãããåç·ã調éããããã«åæ£DNSãµãŒããæ§ç¯ããã®ã¯éçããããŸãããªããªãããã®åæ£ç°å¢ã¯æ°çŸã«æã«ãåã¶ç°å¢ã«åæ£ãããªããã°DDoSæ»æãé²ãããšã¯å°é£ã ããã§ãã
çè ã®æå±ããã¢ã«ãã€ã®é¡§å®¢ã®è©±ã§ã¯ãæ°åã®æ ç¹ã«åæ£ããDNSãµãŒãç°å¢ã§ãDDoSæ»æã®è¢«å®³ã«éã£ãŠããŸã£ãããšãã£ãã±ãŒã¹ããããŸããããããªããšæ°çŸæ ç¹ã«åæ£ããåºç€ãå¿ èŠã§ããããããéçšããã«ã¯è«å€§ãªåŽåãããããããèªå調éã¯ããããã§ããªãã®ã§ããã
ããã§ãã¯ã©ãŠããµãŒãã¹ã§æäŸãããåæ£åæš©åšDNSãµãŒããå©çšããæ¹æ³ãæå¹ã§ãã
å°ççã«åæ£ãåé·åãããåºç€ãéžã¶
ãµãŒãã¹æäŸè ã«ãã£ãŠåœå ããæµ·å€ãŸã§åæ£ã®åºŠåãã¯ç°ãªããŸããã忣åŠçãããæè¡ãšããŠIPãšããŒãã£ã¹ãã䜿ãããŠããŸããããã¯å ±éã®IPã¢ãã¬ã¹ãè€æ°ã®ãµãŒãã¹æäŸã«æã§äœµçšããããšã§ãã©ãã£ãã¯ã忣ãããæ¹æ³ã§ãã
ããã«ããã¯ã©ã€ã¢ã³ãããã®DNSã¯ãšãªã¯ãã€ã³ã¿ãŒãããçµè·¯å¶åŸ¡äžã§æãè¿æ¥ããIPã«å°éããããšã«ãªããŸããã€ãŸããã¯ã©ã€ã¢ã³ããæ¥ç¶ããŠããå Žæã«ãã£ãŠèªåçã«ç°ãªãæš©åšDNSãµãŒãã«éãããŠãå°ççã«åæ£ãããããšãã§ããŸãã
ãã®IPãšããŒãã£ã¹ããå©çšãã忣åºç€ã®åé·æ§ããæ°Žè²¬ã察çã®èŠç¹ã§ããäŸãšããŠãäžå³ã®åæ£åæš©åšDNSãµãŒãã®æ§æã§ã¯ã顧客ãå©çšãããŸãŒã³ããšã«6ã€ã®æš©åšDNSãµãŒãã®IPã¢ãã¬ã¹ãå²ãåœãŠãããŠããŸãã
ãã®6ã€ã®ãµãŒãIPã¯ãå ã«èšèŒããéãIPãšããŒãã£ã¹ãã®ãããããããã®IPã¢ãã¬ã¹ã®å ã«å®éã¯æ°å°ïœæ°çŸå°ã®ãµãŒãã皌åãããPoP(Poin of PresenceïŒãµãŒãã¹æäŸå Žæ)ããããããã®PoPãè€æ°ãŸãšãããããã©ãŒãã³ã¹ã¯ã©ãŠã/å¯çšæ§ã¯ã©ãŠãããšããæš©åšDNSãµãŒãã®ã°ã«ãŒããååšããŠããŸãã
ãã®ããã«è€æ°éå±€ã§åé·åãããç°å¢ã«ãã£ãŠåæ£åã®æš©åšDNSãµãŒããå©çšããããšãã§ããŸãããã®ç°å¢ã«æ°Žè²¬ãã®ã¯ãšãªãæµã蟌ãã§ããå®éã«ã¯å°éå ãæ£ããããŠããŸããŸãªå Žæã§åŠçãããã®ã§ãäžã«æã«è² è·ã¯ããããDDoSæ»æãæç«ããªããªããŸãã
忣åDNSãããã·ãšããéžæè¢
çµç¹ã«ãã£ãŠã¯ãäžè¿°ãã忣åã®æš©åšDNSãµãŒããå°å ¥ããããšãé£ããã±ãŒã¹ããããŸããäŸãã°ãæ¢åã§ãGSLB(Global Server Load Balancing)è£ çœ®ããå°å ¥ããŠãããšãããã«å€éšã®æš©åšDNSãµãŒãã¹ãçµã¿èŸŒãããšã¯å°é£ã§ãããã®å Žåã«ã¯DNSãããã·ã«ããDDoSæ»æå¯Ÿçããæ°ããªéžæè¢ãšãªããŸããããã¯ãæš©åšDNSãµãŒãã®æåã«åæ£åã®DNSãããã·ãµãŒããé 眮ããããã§åŠçã®ä»£æ¿ãè¡ãããæ¹æ³ã§ãã
å æ¥ã®DNSãããã·ã¯ãã¯ãšãªãæš©åšDNSãµãŒãã«è»¢éãããããã£ãã·ã¥ããããã®ãµãŒãã§ã氎責ãã®ããã«æ¬¡ã ã«æ°ãããµããã¡ã€ã³åãžã®åãåãããæ¥ãå Žåã«è² è·ã軜æžããèœåã¯ãããŸãããã§ããããã®DNSãããã·ã«ãååšãããµããã¡ã€ã³ã®ãªã¹ãããæãããã°ããååšããªããµããã¡ã€ã³åã®ã¯ãšãªïŒæ°Žè²¬ãããããã§æ¢ããããšãã§ããŸãã
äžå³ã®å ·äœçãªDNSãããã·æ§æäŸã§ã¯ããã£ã«ã¿æ©èœãæãããDNSãããã·ã忣é 眮ããå ã«è§£èª¬ããIPãšããŒãã£ã¹ãã«ãã£ãŠæ¯ãåããŠããŸãããããå©çšããã°ã氎責ãã¯ãã£ã«ã¿ãããŠæ£åœãªã¯ãšãªã ãããæ£èŠã®æš©åšDNSãµãŒãã«å°éããããšãã§ããŸãããããã«ãã©ãã£ãã¯ããªã¥ãŒã ã«ãããã©ããåæ»æã«ãè² è·åæ£ã§å¯Ÿå¿ã§ããŸãããã®åæ£åDNSãããã·ã®è¯ããšããã¯ãæ¢åã®æš©åšDNSãµãŒãç°å¢ã倿Žãããã¢ããªã³ãšããŠDDoS察çãå°å ¥ã§ããç¹ã§ãã
ãŸãšã
è¿å¹Žè©±é¡ã«ãªã£ã氎責ãã¯ãæ¢åã®DDoS察çãœãªã¥ãŒã·ã§ã³ã§ã¯é®æãå°é£ã§ããã被害ãç¶ç¶ããŠããŸããããã«ã¯æš©åšDNSãµãŒããæ°Žè²¬ããåãæ¢ãåãã®ã«ååãªã¹ã±ãŒã«ã§åæ£ããããããŸãŒã³æ å ±ãæããã忣åDNSãããã·ãåé¢ã«é 眮ããããæå¹ã§ãã
ãããã«ããå€§èŠæš¡ãªåæ£ç°å¢ãå¿ èŠãªãããèªç€Ÿã§åå¥èª¿éããã®ã¯å®¹æã§ã¯ãããŸããã忣åºç€ãæããã¯ã©ãŠããµãŒãã¹åãå©çšããã®ãçŸå®çã§ãã
ãã®éã«ã¯ãåè¿°ããéããã©ã®ãããªæ§æã§åæ£ãåé·æ§æãåãããŠããã®ãããéèŠãšãªããŸãããã£ããã¯ã©ãŠããµãŒãã¹ãå¥çŽããŠãã忣ãäžååã§ããã°æå³ããããŸãããæ¬çš¿ãèªè ã®ã»ãã¥ãªãã£åäžã«è²¢ç®ã§ããããšãåã«é¡ã£ãŠãããŸãã

