DDoSæ»æã®åºç€ãããã®å¯Ÿçæ¹æ³ããã¬ã³ããªã©ãã²ããšãæ¬é£èŒãååãŸã§ã¯ä»æ¥DDoSæ»æå¯Ÿçãæ±ããããçç±ã«ã€ããŠè§£èª¬ããŠããŸãããä»åã¯DDoSæ»æãçãã¬ã€ã€ãŒãšããã®æ»æææ³ã«ã€ããŠèª¬æããŸãã
çãããã¬ã€ã€ãŒãšãããããžã®DDoSæ»æã®ææ³
DDoSæ»æã¯å€§éã®ãã©ãã£ãã¯ãäžæ£ãªéä¿¡ãéä¿¡ããããšã§ãããã¯ãŒã¯åç·ããããã¯ãŒã¯æ©åšããµãŒããŒæ©åšã®ãªãœãŒã¹ãæ¯æžãããããšãç®çã«ããæ»æã§ãã
æ»æè ããã®ç®çãéæããããã«ã©ã®ãããªDDoSæ»æãè¡ã£ãŠããã®ããçè§£ããããã2017幎ã«DDoSæ»æãåãã200ã®äŒæ¥ã察象ã«å®æœãããA10 NetworksãšIDG Connectã®èª¿æ»çµæã玹ä»ããŸãã
äžå³ã®ã°ã©ãã¯äŒæ¥ãDDoSæ»æãåããã¬ã€ã€ãŒã®å²åã«ãªããŸãã
ãã€ã³ãã©ã¬ã€ã€ãŒãã¯DNSãCGNATãªã©ãããã¯ãŒã¯ãµãŒãã¹ã®åºç€ãæ¯ããã¬ã€ã€ãŒã§ããã®ã¬ã€ã€ãŒã«å¯Ÿããæ»æã¯å šäœã®21%ãå ããŠããŸãã
ããããã¯ãŒã¯ã¬ã€ã€ãŒãã¯ãã¡ã€ã¢ãŠã©ãŒã«ãã«ãŒã¿ãŒãªã©ãããã¯ãŒã¯æ©åšã®ã¬ã€ã€ãŒã«ãªããŸãããã®ã¬ã€ã€ãŒãžã®æ»æã¯å šäœã®29%ãå ããæãæ»æã®å€ãã£ãã¬ã€ã€ãŒã«ãªããŸãã
ããããã¯ãŒã¯åž¯åã¬ã€ã€ãŒãã¯æ¥ç¶ããŠããåç·ã®ã¬ã€ã€ãŒã§ãããã«å¯Ÿããæ»æã¯å šäœã®25%ããã¢ããªã±ãŒã·ã§ã³ã¬ã€ã€ãŒãã¯ãŠã§ããµãŒãã¹ãªã©ã¢ããªã±ãŒã·ã§ã³ã®ã¬ã€ã€ãŒã§ãããã«å¯Ÿããæ»æã¯ãã¡ããå šäœã®25%ã«ãªããŸãã
æ¯èŒçãããã¯ãŒã¯ã¬ã€ã€ãŒãžã®æ»æãå€ãã§ãããæºéãªãåã¬ã€ã€ãŒãçãããŠããããšãããããŸããæ¬¡ã¯ãåã¬ã€ã€ãŒã«ãããŠã©ã®ãããªæ»æãè¡ãããŠããã®ããèŠãŠãããŸãã
ã€ã³ãã©ã¬ã€ã€ãŒæ»æ
ã€ã³ãã©ã¬ã€ã€ãŒãžã®æ»æã¯ãDNSãCGNATãªã©ã€ã³ãã©ãæ¯ããåºç€ã«å¯ŸããŠè¡ããããããã¯ãŒã¯ãµãŒãã¹ãæ£åžžã«æ©èœã§ããªããããµãŒãã¹ãžã®æ¥ç¶ãäžèœã«ããŸãã
ãŸããDNSã«å¯Ÿããæ»æã¯ãå€ãã®ã¯ãšãªãŒã倧éã«çºããããšã§DNSãµãŒããåå¿ã§ããªããªãããã«ããæçµçã«æ£èŠã®åå解決ãã§ãããµãŒãã¹ã«æ¥ç¶ã§ããªãããŸãããã®çš®ã®æ»æã§ã¯æ°Žæ»ãæ»æãæåã§ãã
æ°Žæ»ãæ»æã¯ãè€æ°ã®ãããåãããæ»æç«¯æ«ããååšããªãã©ã³ãã ã«çæãããã¹ãåã§åå解決ã®ãªã¯ãšã¹ãã倧éã«çºçãããŸãããã£ãã·ã¥DNSãµãŒãã«ãã£ãã·ã¥ããªãããããã¹ãŠã®ãªã¯ãšã¹ããæš©åšDNSãµãŒããŒã«éä¿¡ããããšã«ãªããŸãããã®çµæãæš©åšDNSãµãŒããå¿çã§ããªããªããæ£èŠã®ãªã¯ãšã¹ããåŠçã§ãããåå解決ãã§ããªããªããŸãã
CGNATã¯ãã©ã€ããŒãIPã¢ãã¬ã¹ãã°ããŒãã«IPã¢ãã¬ã¹ã«å€æããå€§èŠæš¡ãªNATæ©èœã§ããã©ã€ããŒãIPã¢ãã¬ã¹ãšã°ããŒãã«IPã¢ãã¬ã¹ãéä¿¡å ããŒããå®å ããŒãã®ãããã³ã°æ å ±ãã倿ããŒãã«ã§ç¶æããŠããŸãããããã³ã°ã§ããæ°ã«ã¯é床ãããã倧éã®éä¿¡å ããŒããšå®å ããŒãã®çµã¿åããã®éä¿¡ãçºçãããæ»æã«ãããNATã®ãããã³ã°ã§ããæ°ãéçãè¶ ããæ£åžžãªã¯ã©ã€ã¢ã³ããéä¿¡ã§ããªããªããŸãã
ãããã¯ãŒã¯ã¬ã€ã€ãŒæ»æ
ãããã¯ãŒã¯ã¬ã€ã€ãŒãžã®æ»æã¯ããã¡ã€ã¢ãŠã©ãŒã«ãã«ãŒã¿ã®ãªãœãŒã¹ã®æ¯æžãç®çãšããŸãã代衚çãªSYNãã©ããæ»æã¯ãTCPãããã³ã«ã®Synãã±ããã«å¯ŸããŠSyn/Ackãè¿çããããã«Ackãè¿çãããšããã¹ãªãŒãŠã§ã€ãã³ãã·ã§ãŒã¯ãæªçšããŸããSynãã±ãããåœã®IPã¢ãã¬ã¹ãã倧éã«éããAckãåŸ ã¡ç¶ããäžéå端ãªã³ãã¯ã·ã§ã³ç¶æ ã«ããã³ãã¯ã·ã§ã³ãè§£æŸããã蚱容ã§ããã³ãã¯ã·ã§ã³æ°ãè¶ ããããæ°ããæ¥ç¶ãã§ããªãããŸãã
ãŸãã倧éãã©ã°ã¡ã³ããã±ãããäºæããªãTCP flagã®æäœããããããã±ããã®éä¿¡é åºãäžæ£ã«æäœãããããªã¢ãããªãã±ããã§ãã¡ã€ã¢ãŠã©ãŒã«ã®ãã±ããæ€æ»ãçºçããCPUãªãœãŒã¹ãæ¶è²»ããããããããšã§ããã¡ã€ã¢ãŠã©ãŒã«ãã«ãŒã¿ãŒã®åŠçèœåãèœãšããé äžã«ãããµãŒãã¹ã«æ¥ç¶ã§ããªãããæ»æããããŸãã
æšå¹Žæ«ããã³ããŒã¯ã®ãªãµãŒãã£ãŒããçºè¡šãããBlackNurseã¯ãã¡ã€ã¢ãŠã©ãŒã«ã®CPUãæ¯æžãããæ»æäŸãšããŠå ±åãããŸãããBlackNurseã¯ã15ïœ18Mbpsã®ICMP Type3 Code3ã®ãã±ãããéä¿¡ããããšã§ãç¹å®ã®ãã¡ã€ã¢ãŠã©ãŒã«ã®CPUãé«è² è·ã«ãªãããã¡ã€ã¢ãŠã©ãŒã«ãåŠçã§ããªããªãããšã§æ»æãæç«ããŸãã
ãããã¯ãŒã¯åž¯åã¬ã€ã€ãŒæ»æ
ãããã¯ãŒã¯åž¯åã¬ã€ã€ãŒãžã®æ»æã¯ãåç·ã飜åãããããšã§ãµãŒãã¹ã«æ¥ç¶ã§ããªãããããšãç®çãšããŸãããã®æ»æã¯ããã«å€ãã®ãã±ãããéä¿¡ãããããšãã§ãããããæåã®ã«ã®ã«ãªããŸãããã©ãã£ãã¯ã®ããªã¥ãŒã ãå¢ããããã«å€ãã®ç«¯æ«ããæ»æå¯Ÿè±¡ã«éä¿¡ãçºçãããããå°ãªããªã¯ãšã¹ããã±ãããã倧ããã¬ã¹ãã³ã¹ãã±ãããã¿ãŒã²ããã«è¿ãããšãçã£ãã¢ã³ãæ»æãè¡ã£ããããããšã§ããããã¯ãŒã¯åž¯åã飜åãããããšããŸããã¢ã³ãæ»æã¯DNSãNTPãSSDPãããã³ã«ãå©çšããæ»æãäžè¬çã§ãæå€§çŽ60åã®ã¬ã¹ãã³ã¹ãã±ãããéä¿¡ã§ããŸãã
ã¢ã³ãæ»æã¯ãœãŒã¹IPãåœè£ ããŠDNSã«åãåããããã®å€§ãããªã£ãçµæãã¿ãŒã²ããã«åå°ããããã«éä¿¡ãããããããªãã¬ã¯ã·ã§ã³æ»æãšãåŒã°ããŸãã
DNSãžã®ã¢ã³ãæ»æã§ã¯ãTXTã¬ã³ãŒããªã©ã¬ã¹ãã³ã¹ãµã€ãºã倧ãããªãã¯ãšãªãŒãã¿ãŒã²ãããµãŒããè¡ã£ããã®ããã«åãåãããŸãããã®æ»æã¯è匱æ§ã®ããDNSãµãŒããèžã¿å°ã«ããŠæ»æãè¡ããŸããããã®èžã¿å°ã§äœ¿ã£ããµãŒããã©ãããã§ãDNSã¯ãšãªãŒãåãä»ããŠããŸãå Žåãæ»æã€ã³ãã©ãšããŠå©çšãããŠããŸããŸãã
äŸãã°ãNTPã¯æå»åæããããã«äœ¿ããããµãŒãã§ãããmonlistãšããNTPãµãŒãã®ã¹ããŒã¿ã¹ãè¿ããªã¯ãšã¹ããéãããšã§ã倧ãããµã€ãºã®ã¬ã¹ãã³ã¹ãåãåãããšãã§ããŸãã
ãŸããSSDP(Simple Service Discovery Protocol)ãšãããããã¯ãŒã¯æ©åšåå£«ã§æ¥ç¶ãã§ããããã«ããããã®ãããã³ã«ã«å¯Ÿå¿ãããããã¯ãŒã¯æ©åšã«å¯ŸããŠãæ»æå ã®IPã¢ãã¬ã¹ã«åœè£ ããŠãªã¯ãšã¹ããçºããããšã§ããªã¯ãšã¹ããã倧ããã¬ã¹ãã³ã¹ãã±ãããè¿ãããšãã§ããŸãã
ã¢ããªã±ãŒã·ã§ã³ã¬ã€ã€ãŒæ»æ
ã¢ããªã±ãŒã·ã§ã³ã¬ã€ã€ãŒãžã®æ»æã¯ãŠã§ããµãŒãã¹ãªã©ãŠãŒã¶ãŒã«æäŸããã¢ããªã±ãŒã·ã§ã³ãªãœãŒã¹ãæ¯æžããããµãŒãã¹ã«æ¥ç¶ã§ããªãããããšãç®çãšããŸããäŸãã°ãHTTPéä¿¡ã§ãªã¯ãšã¹ãããã£ããéä¿¡ããããšã§ã¢ããªã±ãŒã·ã§ã³ã®ã»ãã·ã§ã³ãé·ãç¶æãããããšããæ»æããããŸãã
代衚çãªã®ã¯Slow POSTæ»æã§ãHTTPã®POSTã¡ãœããã§ãã£ãããã±ãããéä¿¡ãç¶ããåææ¥ç¶æ°ãå¢ããããšã§WebãµãŒãããªã¯ãšã¹ããåãä»ããããããµãŒãã¹äžèœãªç¶æ ã«ãªããŸãã人æ°ã®ãããµã€ãã§ãŠãŒã¶ãŒãæŒãå¯ããã®ãšåããããªç¶æ ãäœãã ãææ³ã§ãã
ããããããïŒããããããïŒãããããïŒ
ãã®ããã«DDoSæ»æã¯ã¿ãŒã²ãããšãªãã·ã¹ãã ãµãŒãã¹ãäžèœã«ãããããã·ã¹ãã ãµãŒãã¹ãã®ãã®ã ãã§ãªãããããæ¯ããã€ã³ãã©åºç€ããããã¯ãŒã¯æ©åšãåç·ã®æ©èœãäžèœã«ããããšã§ã·ã¹ãã ãµãŒãã¹ãäžèœã«ããŸãããã®ãããã·ã¹ãã ãµãŒãã¹ã«åœ±é¿ãåãŒãç°å¢ãçè§£ããäžã§ãç¶²çŸ çã«å¯ŸçããšãããšãéèŠã«ãªããŸãã
åæ³ åå©ïŒãã€ããªããã€ãšãïŒ
A10ãããã¯ãŒã¯ã¹æ ªåŒäŒç€Ÿãããžãã¹éçºæ¬éš ããžãã¹ãœãªã¥ãŒã·ã§ã³éçºéš ã»ãã¥ãªãã£ããžãã¹ãã£ããããã¡ã³ãïŒã¢ã©ã€ã¢ã³ã¹ããžãã¹ãããŒãžã£
å ¬èªæ å ±ã·ã¹ãã ç£æ»äººïŒCISAïŒãCertfied Information System Security Professional (CISSP)ãGIAC Certifed Intrusion Analyst (GCIA)
ã»ãã¥ãªãã£ãŒãã³ããŒã®ããªã³ã·ãã«ã¢ãŒããã¯ããã³ã³ãµã«ãã£ã³ã°ãã¡ãŒã ã®ã·ãã¢ãããŒãžã£ãçµãŠã2016幎ããA10ãããã¯ãŒã¯ã¹ã®ã»ãã¥ãªãã£ããžãã¹ã®è²¬ä»»è ã«çä»»ãã€ãã³ãã§ã®è¬æŒãæžç±ãå¯çš¿èšäºã®å·çãªã©ã»ãã¥ãªãã£ã®åçºæŽ»åã«ãåŸäºã




