ãã»ãã¥ãªãã£ããšäžå£ã«èšã£ãŠããã»ãã¥ãªãã£ãã³ããŒã ãã§ã¯ãªããããŸããŸãªãã³ããŒããDoSæ»æãããã«ãŠã§ã¢ã«ããæ»æãŸã§ãããŸããŸãªãµã€ããŒæ»æãžã®å¯Ÿç補åãæäŸããŠããŸãããã®é£èŒã§ã¯ããããã¯ãŒã¯ãã³ããŒããèŠãã»ãã¥ãªãã£ã®çŸç¶ã解説ããŠãããŸãã第1åã®ããŒãã¯ãSSLãã«ãããåé¡ç¹ã§ãã
SSLãå¢ããWebã®äžç
ããç¥ãããŠããããã«ãWebãã©ãŠã¶ãšWebãµãŒãéã§éä¿¡ãæå·åããçèŽãæ¹ããã鲿¢ããæè¡ãSSLã§ãã
SSLã䜿çšããéã¯æå·ååŠçãå¿ èŠã«ãªããŸãããCPUã«å€§ããªè² è·ãããããŸããHTTPSã§WebããŒãžã«ã¢ã¯ã»ã¹ããå Žåãç»åãå«ãããã¹ãŠã®ã³ã³ãã³ããæå·åãããŠãã転éãããŸãããã®ããããã©ãã£ãã¯ãå¢ããã°å¢ããã»ã©ãWebãµãŒãã«äžããè² è·ãå¢å€§ããŸãã
æè¿ã§ã¯ãµã€ãå šäœã®å®å šæ§ã確ä¿ããããããã¹ãŠã®ããŒãžãSSLåãããåžžæSSLãã«èžã¿åããµã€ããå¢ããŠããŸããGoogleã2014幎8æã«ãSSLåãããWebãµã€ããSEOã®è©äŸ¡ãšããŠåªéããããšå ¬åŒã«çºè¡šããããšããåžžæSSLåãžã®åããåŸæŒãããŠãããšèšããŸããåžžæSSLåãé²ãã°ãåŠçè² è·ã®åé¡ã¯ããã«å€§ãããªãã§ãããã
WebãµãŒãã«ãããSSLã®æå·ååŠçè² è·ã¯ãæå·éµã®é·ããçãã£ãé ã¯ææ ¢ã§ããç¯å²ã®åŠçè² è·ã ã£ããšèšããŸããããã2004幎8æã«ãNIST(National Institute of Standards and Technology:ã¢ã¡ãªã«åœç«æšæºæè¡ç ç©¶æ)ã®ç€ºããã¬ã€ãã©ã€ã³ããç¶æ³ã倧ããå€åãããŸããã
ãã®å 容ã¯ãããããŸã§äœ¿çšãããŠããæå·éµã¯1024ãããã ã£ããã1024ãããã®ãŸãŸã§ã¯å®å šæ§ã確ä¿ããããšãé£ããã1024ãããã®æå·éµã¯äœ¿çšæéã2010幎ã«ãã¹ãããšãããã®ã§ããããã¯ãæå·ã¢ã«ãŽãªãºã ã®2010幎åé¡ããšåŒã°ããŠããŸãã
æå·éµã®2048ãããåã§é¡åšåããSSLã®ããã©ãŒãã³ã¹åé¡
NISTã«ããå§åãåããçŸåšã¯2048ãããã®æå·éµã«ããSSLãäžè¬çã«ãªã£ãŠããŸããã§ã¯ãæå·éµé·ã1024ããããã2048ãããã«ãªãããšã§ãåŠçè² è·ã¯ã©ãã ã倧ãããªãã®ã§ãããããããããæ°ã2åã ãããè² è·ã2åã«ãªãããšæããããããããŸããããå®ã¯ããã§ã¯ãããŸããã
| SSLããã©ãŒãã³ã¹ | ||
| äžè¬çãªããŒããŠã§ã¢ | ||
| éµé· | 32bit | 64bit |
|---|---|---|
| 1024 | 525 TPS | 1570 TPS |
| 2048 | 96 TPS | 273 TPS |
| 4096 | 15 TPS | 38 TPS |
äžã®è¡šã¯ã2010幎åé¡ãæ¹ããŠã¯ããŒãºã¢ããããã2011幎1æã«äœæããããã®ã§ããäžè¬çãª64ãããã»ãµãŒãã§SSLãåŠçããå Žåãæå·éµé·ã1024ãããã®ã±ãŒã¹ã§ã¯1570 TPS(Transactions Per Second)ã2048ãããã®ã±ãŒã¹ã§ã¯273 TPSã§ããããšã瀺ãããŠããŸããã€ãŸãæå·éµé·ã2åã«ãªãããšã§ãåŠçè² è·ã¯çŽ6åã«ãªã£ãŠããã®ã§ãã
ãã®è¡šãäœæãããŠããçŽ5幎ãçµéããŠãããCPUã®åŠçèœåãåäžããŠããŸããä»å¹Ž9æ2æ¥ã«ç¬ãã«ãªã³ã§éå¬ãããäžçæå€§çŽã®ã³ã³ã·ã¥ãŒã㌠ãšã¬ã¯ãããã¯ã¹ ã·ã§ãŒãIFA 2015ãã§ã€ã³ãã«ãè¡ã£ãçºè¡šã§ã¯ããã³ãããŒã¯ ã¹ã³ã¢ã¯ãã®5幎éã§ã2.5åã«ãªã£ãããšããã£ãŠããŸãããããããã®æ°åãå ã»ã©ã®è¡šãšç §ããåããããšãæå·éµã®2048ãããåã«äŒŽãåŠçè² æ å¢å ãããã®5幎éã§å®çŸããCPUæ§èœåäžã§ã¯ã«ããŒã§ããŠããªãããšã«ãªããŸãã
SSLã®æå·ååŠçãWebãµãŒãããšã«åŠçããã°ãæ¬æ¥ã®WebåŠçã«è²»ããã¹ããªãœãŒã¹ãSSLåŠçã«å²ãåœãŠãããããšã«ãªããããã©ãŒãã³ã¹ã¯äœäžããŸããåŠçé床ã®äœäžãè£ãã«ã¯ãããé«éãªãµãŒãã䜿çšãããããµãŒãã®å°æ°ãå¢ãããŠè² è·ã忣ãããããããŸãããã€ãŸããWebãµãŒãã§SSLãåŠçããããšã¯ãäžçµæžãªéžæãšããããšã«ãªãã®ã§ãã
WebãµãŒãã§ã®SSLåŠçã¯éçšé¢ã§ãäžçµæž
WebãµãŒãã«ããSSLåŠçã®äžçµæžæ§ã¯ãããã©ãŒãã³ã¹ã®äœäžã ãã§ã¯ãããŸããã
SSLåŠçãè¡ãã«ã¯SSLèšŒææžã®å®è£ ãå¿ èŠã§ããèšŒææžããã "眮ã"ã ãã§ã¯ãªããæå¹æéãé©åã«ç®¡çããäžã§ãå¿ èŠã«å¿ããŠæŽæ°ãããšããäœæ¥ãå¿ èŠã«ãªããŸãããããå€ãã®WebãµãŒãã§è¡ãã«ã¯ã倧ããªéçšè² æ ãšãªããèŠæš¡ãå¢å€§ããã»ã©ãè² æ ã环ç©çã«å¢å€§ããŸããããã«å ããŠãã·ã¹ãã ã«å®è£ ããæå·éµã®æ°ãå¢ããã°å¢ããã»ã©ã管çäžã®ã»ãã¥ãªãã£ç¢ºä¿ã«ãè² æ ãããããŸãã
1å°ã®ãµãŒãã§è€æ°ã®ãã¡ã€ã³ãéçšãããããŒãã£ã«ãã¹ããã§ã¯ãååãšããŠSSLã䜿ããªãããšã«ã泚æãå¿ èŠã§ããSSLã§ã¯HTTPããããæå·åãããŠããããããã¯ã©ã€ã¢ã³ããã©ã®ãã¹ãåãèŠæ±ããŠããã®ããã倿ã§ããŸããã
ãã®åé¡ã®è§£æ±ºçãšããŠã¯ãSSL/TLSã®æ¡åŒµä»æ§ã®1ã€ã§ããSNI(Server Name Indication)ãæŽ»çšããæ¹æ³ããããããŒãã£ã«ãµãŒãã§ãSSLã䜿ããããã«ãªããŸãã
ãã ããæ³šæãããã€ã³ããšããŠããSNIã䜿çšããå Žåã«ã¯WebãµãŒãåŽã ãã§ã¯ãªããWebãã©ãŠã¶åŽã®å¯Ÿå¿ãå¿ èŠããšããããšãæããããŸããSNIã¯æ¯èŒçæ°ããæ¡åŒµä»æ§ã®ããã察å¿ããŠããªãWebãã©ãŠã¶ãå°ãªããããŸããã
ã»ãã¥ãªãã£ãéã«äœäžããå±éºæ§ã
WebãµãŒãã®SSLåŠçã«ã€ããŠãäžçµæžæ§ã«äŒŽãããã©ãŒãã³ã¹ã®äœäžãéçšç®¡çé¢ã§ã®ãã¡ãªãããæããŸãããããã以å€ã«ãåé¡ç¹ããããŸãã
äŸãã°ãWebãµãŒããšã€ã³ã¿ãŒãããã®éã«ãIDSãIPSãªã©ã®ããããããã£ãŒã ãã±ãã ã€ã³ã¹ãã¯ã·ã§ã³ããè¡ããã»ãã¥ãªãã£ã»ã¢ãã©ã€ã¢ã³ã¹ãèšçœ®ããã±ãŒã¹ããããŸããããããSSLã®ãã©ãã£ãã¯ã¯æå·åãããŠããããããããã®ã¢ãã©ã€ã¢ã³ã¹ã§ã¯ãã±ããã®äžããã§ãã¯ã§ãããæ¬æ¥ã®æ©èœãæãããŸãããåæ§ã®çç±ãããã²ãŒããŠã§ã€åã®ã¢ã³ãã»ãŠã£ã«ã¹è£œåã§ããã«ãŠã§ã¢ã®æ€åºãäžå¯èœã«ãªããŸãã
解決çã¯ãããã¹ãŠã®WebãµãŒãã®æå·éµãã¢ãã©ã€ã¢ã³ã¹ã«å±éãããã©ãã£ãã¯ã®è§£èªãšåæå·åãã¢ãã©ã€ã¢ã³ã¹ã§è¡ãããšããæ¹æ³ãæããããŸãããåœç¶ãªããããã©ãŒãã³ã¹ã¯å€§å¹ ã«æªåããŠããŸããŸãã
åé¡ã«å¯Ÿããæ ¹æ¬çãªè§£æ±ºçãšã¯
ãããã®äžçµæžæ§ããªã¹ã¯ã¯ã©ã®ããã«åé¿ãã¹ããªã®ã§ãããããæ ¹æ¬çãªè§£æ±ºçã¯ãæãã€ã³ã¿ãŒãããã«è¿ãå¢çéšåã«ãSSLåŠçãéäžçã«è¡ãä»çµã¿ãèšçœ®ããããšã§ãã
ããã«ãããWebãµãŒãã®è² è·å¢å€§ãåé¿ã§ããæå·éµã®å±éã»æŽæ°ã«å¿ èŠãªéçšè² æ ã軜æžããããšãšãã«ãæå·éµãå¢ããããšã«ããã»ãã¥ãªãã£ã®ãªã¹ã¯ãåé¿ãããŸãã
ãŸãããã®ä»çµã¿ã®å åŽã«ãå ã»ã©æããã»ãã¥ãªãã£ã»ã¢ãã©ã€ã¢ã³ã¹ãèšçœ®ããã°ãæå·åã«ãã£ãŠãã±ãããé èœãããªããããæ¬æ¥ã®æ§èœãçºæ®ã§ããŸãã
ãSSLåŠçã¯WebãµãŒãã§è¡ããã®ããšãã"æã蟌ã¿"ã¯ãæ©ãæšãŠå»ãã¹ããªã®ã§ãã
èè ãããã£ãŒã«
äŒè€ æ çŽå€«(ããšã ããã)
UNIXãµãŒããŒãã¹ãã¬ãŒãžãã·ã³ã»ã¯ã©ã€ã¢ã³ããšãã£ãã€ã³ãã©ãšã³ãžãã¢ãçµãŠãF5ãããã¯ãŒã¯ã¹ãžã£ãã³ãž2012幎ã«å ¥ç€Ÿã
F5ãããã¯ãŒã¯ã¹ãžã£ãã³
ã»ãŒã«ã¹ãšã³ãžãã¢ãªã³ã°æ¬éš
ããªã»ãŒã«ã¹ã³ã³ãµã«ã¿ã³ã
çŸåšã¯ã»ãã¥ãªãã£ã»ã¯ã©ãŠããããŒã¯ãŒãã«ã€ãã³ãè¬æŒããã³ãºãªã³ã©ããè¡ããF5ãœãªã¥ãŒã·ã§ã³ã®åèæŽ»åã«å¥®éäžã
æè¿ã¯OpenStackãIoTãšãã£ãããŒã¯ãŒããäžå¿ã«é£æºãœãªã¥ãŒã·ã§ã³ã暡玢ããŠããã
