ãã»ãã¥ãªãã£ããšäžå£ã«èšã£ãŠããã»ãã¥ãªãã£ãã³ããŒã ãã§ã¯ãªããããŸããŸãªãã³ããŒããDoSæ»æãããã«ãŠã§ã¢ã«ããæ»æãŸã§ãããŸããŸãªãµã€ããŒæ»æãžã®å¯Ÿçãè¡ã£ãŠããŸãããã®é£èŒã§ã¯ããããã¯ãŒã¯ãã³ããŒããèŠãã»ãã¥ãªãã£ã®çŸç¶ãã解説ããŠãããŸãã
ã»ãã¥ãªãã£ãèªãäžã§å€ããªã"ãããã·"
ãããã¯ãŒã¯äžã«ãããŠãããããã·ãã¯è峿·±ã"ããã€ã¹"ã®1ã€ã§ãããããã·ã¯ãã£ãã·ã³ã°ãè² è·åæ£ãã¢ããªã±ãŒã·ã§ã³ ã»ãã¥ãªãã£ããããŠãã¢ããªã±ãŒã·ã§ã³ã®ããã®ã¢ã¯ã»ã©ã¬ãŒã·ã§ã³ ãµãŒãã¹ãŸã§ã®åºç€ãšãªã£ãŠããŸããéçºãšéçšãšãããã¯ãŒã¯ãæ©æž¡ãããååšã§ãããããã倧åã®ããŒã¿ã»ã³ã¿ãŒ ã¢ãŒããã¯ãã£ã§ã¯ãããã3ã€ã®ã°ã«ãŒããã¹ãŠã§ãé »ç¹ã«äœ¿çšãããŠããŸãã
ãããããããã·ã®ãã¹ãŠãåãã¢ãŒããã¯ãã£çæ¹éã«åºã¥ããŠæ§ç¯ãããŠããããã§ãªãããã¹ãŠã®ãããã·ãåãã§ã¯ãããŸããããããã·ã®å€ãã¯ããŒããããã·ã§ãããããŒããããã·ããäžæ¹ã®ãã«ãããã·ã§ãããã«ãã£ãŠããäœãè¡ããããã¯ç°ãªããŸãã
ãã«ãããã·ã§ã¯ãåŸæ¥ã®å€ããããã·ã§ã¯è¡ããªãã£ããéåžžã«éèŠãªã3ã€ã®æ©èœããæããããšãå¯èœã«ãªããŸããããã3ã€ã®æ©èœã«ã€ããŠæ€èšããåã«ããŸãã¯ãããŒããããã·ãšãã«ãããã·ã®éãã«ã€ããŠã説æããããšæããŸãã
ããŒããããã·
ããŒããããã·ãšã¯ããããã·ã"ãªããŒã¹"ãš"ãã©ã¯ãŒã"ã®ããããã«ãããŠãæ¥ç¶ãã©ã®ããã«åŠçããããè¡šãæŠå¿µã§ããåºæ¬çã«ã¯ããããã·ãã¯ã©ã€ã¢ã³ãåŽã«ãããŠã®ã¿æ¥ç¶ã仲ä»ãããããšãæå³ããŸãã
ãããã£ãŠãã¯ã©ã€ã¢ã³ããšã¢ããªã±ãŒã·ã§ã³éã®ã³ãã¥ãã±ãŒã·ã§ã³ã®ãã¡ãããŒããããã·ã¯ãã®åå(ããŒã)ã ããåŠçããŸããããŒããããã·ã«ã€ããŠæãéèŠãªããšã¯ããã¯ã©ã€ã¢ã³ããšãµãŒãã®åæ¹ã§å ±æãããããã¯ãŒã¯ ã¹ã¿ãã¯ã¯1ã€ã®ã¿ãã§ããããšã§ãã
ãã«ãããã·
ããã«å¯ŸããŠãã«ãããã·ã¯ãã¯ã©ã€ã¢ã³ãåŽãšã¢ããªã±ãŒã·ã§ã³åŽã§ç°ãªã2ã€ã®ãããã¯ãŒã¯ ã¹ã¿ãã¯ãç¶æããäž¡æ¹ã®åŽã«ã€ããŠãã«ã«ãããã·åŠçãè¡ããŸãããã«ãããã·ãšããåç§°ã¯ããã®åœ¹å²ããåããããã®ã§ãã
ãã«ãããã·ã¯ãããŒããããã·ãšåæ§ã«åäœèšå®ã§ããŸãããæ¬æ¥ã®äŸ¡å€ã¯ãã¯ã©ã€ã¢ã³ããšãµãŒãã®äž¡æ¹ã«ãããããåå¥ã«æ¥ç¶ã§ããããšããã«ãããŸãã
ãã®ãã¥ã¢ã«ã¹ã¿ãã¯ã«ããææ³ããããããã¯ãŒã¯ ã¹ã¿ãã¯ã1ã€ã ãã§ããããŒããããã·ã§ã¯äžå¯èœãªæ©èœãããã«ãããã·ãå®çŸã§ããçç±ã§ãã
3ã€ã®éèŠãªæ©èœ
ãã«ãããã·ã¯ã察象ãšãããããã³ã«ããã¹ãŠçè§£ã§ããŸãããŸãããã«ãããã·èªèº«ããããã³ã«ãšæ¥ç¶ã®ãšã³ããã€ã³ãã§ãããæ¥ç¶ãè¡ãã¯ã©ã€ã¢ã³ãã§ããããŸãã
ããã¯ãŸãããã«ãããã·ããããã¡ãªã³ã°ãåéä¿¡ãTCPãªãã·ã§ã³ãªã©ã®ãããã¯ãŒã¯ ã¹ã¿ãã¯ããšã«ãèªãã®TCPæ¥ç¶ãµããŸããæã€ããšãã§ããããšãæå³ããŸãããã«ãããã·ã䜿çšããå Žåã«ã¯ãããããã®æ¥ç¶ããèªãã®TCPæ¥ç¶ãµããŸããæã£ãç¬èªã®ãã®ãšãªããŸãã
ãã«ãããã·ã«å¯ŸããŠæ¥ç¶ããã¯ã©ã€ã¢ã³ãã¯ããã«ãããã·ããµãŒããŒã«å¯ŸããŠè¡ãæ¥ç¶ãšã¯ç°ãªãéä¿¡ãè¡ãããšãæå³ããŸãããã«ãããã·ã¯ãªã¯ãšã¹ããšã¬ã¹ãã³ã¹ã®äž¡æ¹ããã§ãã¯ãããœãªã¥ãŒã·ã§ã³ãèš±å¯ããå Žåã«ã¯ããã®äž¡æ¹ãæäœã§ããŸãã
ãã®1:ã¯ã©ã€ã¢ã³ãåŽãšãµãŒãåŽãæé©å
ãã«ãããã·ã¯ãããã¯ãŒã¯ ã¹ã¿ãã¯ãšç¹æ§ãåå¥ã«ç¶æã§ãããããããããã®åŽã«ã€ããŠããããã®ããŒãºã«åãããæé©åãè¡ããŸãã
ã¯ã©ã€ã¢ã³ãåŽã«ããããç¹ã«ã¢ãã€ã«æ©åšã察象ãšããå Žåã®äœéãé«ã¬ã€ãã³ã·ã®ãããã¯ãŒã¯æ¥ç¶ãæé©åããããã®TCPèšå®ã¯ããµãŒãåŽã«äœ¿çšããããé«éãäœã¬ã€ãã³ã·ã®ããŒã¿ã»ã³ã¿ãŒãžã®ãããã¯ãŒã¯æ¥ç¶ãæé©åããããã®èšå®ãšã¯å€§ããç°ãªããšæãããŸãã
ãã«ãããã·ã¯ãã®äž¡æ¹ãåæã«æé©åã§ããããããç¶æ³ã«ãããŠå¯èœãªéãæé«ã®ããã©ãŒãã³ã¹ãå®çŸããŸãããããã¯ãŒã¯ ã¹ã¿ãã¯ã1ã€ããæããªãããŒããããã·ã§ã¯ãå¹³åçãªæ¥ç¶ã察象ãšããŠæé©åããããåŸãªããããã»ãšãã©ã®å Žåã©ã¡ããäžæ¹ã®ããã©ãŒãã³ã¹ãæé©ãšã¯èšããªãç¶æ ã«ãªããŸãã
ãã®2:ãããã³ã« ã²ãŒããŠã§ã€ãšããŠæ©èœ
ãããã³ã« ã²ãŒããŠã§ã€ã¯ãç¹ã«ã¢ããªã±ãŒã·ã§ã³ ãããã³ã«ã®ããŒãžã§ã³ãå€ããå Žåãããšãã°HTTP/1ããHTTP/2ãŸãã¯SPDYã«ç§»è¡ããå Žåãªã©ã«ãããŠãã¢ãŒããã¯ãã«ãšã£ãŠéèŠãªããŒã«ãšãªããŸãããã«ãããã·ã¯2çš®é¡ã®äºãã«ç°ãªãæ¥ç¶ãããããç¶æãããããã¯ã©ã€ã¢ã³ãåŽã§ã¯HTTP/2ãããµãŒã(ã¢ããªã±ãŒã·ã§ã³)åŽã§ã¯HTTP/1ãåãå ¥ããããšãã§ããŸãã
ããã¯ããã«ãããã·ãã¯ã©ã€ã¢ã³ãåŽã®æ¥ç¶ãçµç«¯ã(ãããã·ããµãŒããšãªã)ããµãŒãã«å¯ŸããŠã¯å¥ã®æ¥ç¶ãéå§ãã(ãããã·ãã¯ã©ã€ã¢ã³ããšãªã)ããã§ããã¯ã©ã€ã¢ã³ãåŽã«ã©ã®ãããã³ã«ã䜿çšãããã«ãã£ãŠããµãŒãåŽã®ãããã³ã«éžæãå¶çŽãããããšã¯ãããŸããã
çŸå®çã«ãã«ãããã·ã¯ãã©ã®ãããªæå³ã®ãã(ãããã¯æå³ã®ãªã)ãããã³ã«å€æŽã«ã察å¿å¯èœã§ããããã°ã©ã å¯èœãªãã«ãããã·ã䜿ãã°ããããä»®ã«äžè¬çã§ã¯ãªã(ãããã£ãŠåºããµããŒããããŠã¯ããªã)ãã®ã§ãã£ãŠãã²ãŒããŠã§ã€æ§ç¯ãè¡ãããšãã§ãããã®éã«ãããã·ãšããæŠå¿µã«ã€ããŠåããã®ãäžããäœãå¿ èŠããããŸããã
ãã®3:SSL/TLSãçµç«¯
ããã¯æè¡çã«èŠãã°ãããã³ã« ã²ãŒããŠã§ã€ã®ç¹æ®ãªã±ãŒã¹ã§ãããHTTP/Sãæ¯é çã§ããããš(ããã³SSL EverywhereãšEncrypt All The Thingsã®éèŠæ§)ãèæ ®ããã°ãåç¬ã®ã±ãŒã¹ãšããŠæ±ãã¹ãã ãšæããŸããåºæ¬çã«ã¯SSL/TLSã®çµç«¯ã¯ãææ°ããã³ä»åŸã®ã¢ãŒããã¯ãã£ã«ãããŠããããŠéèŠãªæ©èœã®1ã€ãšãªã£ãŠããŸãã
ãªããªãHTTPãããã³ã«å ã®æ å ±ã«åºã¥ããŠHTTPããŒã¹ã®ãã©ãã£ãã¯(ããšãã°REST APIã³ãŒã«)ãæ€èšŒãããã®è¡ãå ãæ±ºå®ããªããã°ãããŸãããããããã·ãªãã§ã¯æå·åã®ãããã®æ å ±ã®ååŸãé»ãŸããŠããŸãããã§ããSSL/TLSãçµç«¯ããæ©èœã¯ããããã·ããã¯ã©ã€ã¢ã³ããæ¥ç¶ãã(ãã€æçµçã«ã¯ä¿¡é Œãã)å®å šãªãšã³ããã€ã³ããšãªãããšãæå³ããŸãã
ãŸãçµç«¯ãšã¯ããããã·ãæå·åãããèŠæ±ãè§£èªããå¿çãæå·åãã圹å²ãæããããšã§ããã€ãŸãã¡ãã»ãŒãžã®å éšããèŠãŠãããã®ããŒã¿ãã«ãŒã決å®ãè² è·åæ£ã®å€æã«äœ¿çšããããšãæå³ããŸãã
ãã«ãããã·ã§ãªããã°ãæ°ããããŸãæ°ãã«ç»å Žããã¢ããªã±ãŒã·ã§ã³ ã¢ãŒããã¯ãã£ã«åããŠãããã·ãæäŸããæ©èœãšãã®ã¡ãªããã®æŽ»çšã¯éããããã®ãšãªã£ãŠããŸããŸãããããã·ã«ã€ããŠã¯ãããããã«ãããã·ãåŠãã確èªããããã«ããŠãã ããã
èè ãããã£ãŒã«
äŒè€ æ çŽå€«(ããšã ããã)
UNIXãµãŒããã¹ãã¬ãŒãžãã·ã³ã»ã¯ã©ã€ã¢ã³ããšãã£ãã€ã³ãã©ãšã³ãžãã¢ãçµãŠãF5ãããã¯ãŒã¯ã¹ãžã£ãã³ãž2012幎ã«å ¥ç€Ÿã
F5ãããã¯ãŒã¯ã¹ãžã£ãã³
ã»ãŒã«ã¹ãšã³ãžãã¢ãªã³ã°æ¬éš
ããªã»ãŒã«ã¹ã³ã³ãµã«ã¿ã³ã
çŸåšã¯ã»ãã¥ãªãã£ã»ã¯ã©ãŠããããŒã¯ãŒãã«ã€ãã³ãè¬æŒããã³ãºãªã³ã©ããè¡ããF5ãœãªã¥ãŒã·ã§ã³ã®åèæŽ»åã«å¥®éäžã
æè¿ã¯OpenStackãIoTãšãã£ãããŒã¯ãŒããäžå¿ã«é£æºãœãªã¥ãŒã·ã§ã³ã暡玢ããŠããã
