æåã®èšåã¯2003幎7æã«é¡ããŸãã åæããŒãžã§ã³ã§ã¯ãSalityã¯UPXã䜿çšããŠããã±ãŒãžåãããç¬èªã®ã³ãŒããè¿œå ããããšã«ãããå®è¡å¯èœãã¡ã€ã«ã«ææããŸããã ããŒãã¬ãŒã¯ãã€ããŒããšããŠæ©èœããååãããããŒã¿ã¯ãSMTPãä»ããŠãã·ã¢ã«ãããµãŒããŒã®1ã€ã«éä¿¡ãããŸããã ãã®ååã¯ãéœåžã®è±èªå-ããµã©ããåžãïŒãµã©ããããã·ã³ã«ãã¹ã¿ã³å ±ååœïŒãã掟çããŠããŸãã ãããããéçºè ã®ããã¯ããŒã -ã»ã¯ã¿ãŒ-ã¯ãDr.Webã®åé¡ã§ååãä»ããããŸããã åœæãSalityã¯æè¡çã«èå³æ·±ããã®ã§ã¯ãªããèè ã¯ããªãåå§çãªã¡ã«ããºã ã䜿çšããŠããŸãã-ãã¡ã€ã«ææè ã¯åœæã®ä»ã®ãã«ãŠã§ã¢ãµã³ãã«ãšæ¯èŒããŠæ¯èŒçåçŽã§ãSMTPãµãŒããŒã¢ãã¬ã¹ã¯ã³ãŒãå ã«ããŒãã³ãŒããããŠããŠãå€æŽã§ããŸããã§ãããã€ããŒããå€æŽãããŸããã
2004幎ãã2008幎ãŸã§ãèè ã¯Salityã®æ¹åã«äžçæžåœåãçµã¿ãŸããã æææ¹æ³ã¯å€§ããå€åãããŠã€ã«ã¹ã¯ãšã³ããªãã€ã³ããå€æŽããã«å€åã«ãªãïŒãšã³ããªãã€ã³ããäžæçã«ããæè¡ïŒãæ€åºãšåŠçã®ããã»ã¹ãè€éã«ããŸãã æªæã®ããæ©èœã¯åå¥ã®ã¢ãžã¥ãŒã«ã«åé¢ãããã³ãŒãã«ããŒãã³ãŒãã£ã³ã°ãããå€æ°ã®URLããè¿œå ã§èªã¿èŸŒãŸããå¯èœæ§ããããŸããã ä¿è·ã¡ã«ããºã ã«å¯Ÿæããæé ãå«ãŸããŠããŸããïŒãã¡ã€ã¢ãŠã©ãŒã«ããŠãŒãã£ãªãã£ãããã³ãŠã€ã«ã¹å¯Ÿçããã°ã©ã ããããã¯ãŸãã¯ç¡å¹ã«ããŸãã 2008幎ïŒãããã2007幎æ«ïŒä»¥éãèè ã¯ãŠã€ã«ã¹å¯ŸçäŒç€Ÿã«ãã£ãŠç°¡åã«ãããã¯ãããå®çŸ©æžã¿ã¢ãã¬ã¹ã®ä»£ããã«ãé åžã¹ããŒã ãæ ¹æ¬çã«å€æŽããã¢ãžã¥ãŒã«ãæŽæ°ãããã®åŸã®èµ·åã®ããã«ãµãŒãããŒãã£ã®ãã«ãŠã§ã¢ãããŠã³ããŒãããããã®ãã¢ããŒãã¢ã¡ã«ããºã ãå®è£ ããŸããã
建ç¯
以äžã§ã¯ãSalityã®ææ°ããŒãžã§ã³ïŒ2008幎以éïŒã®1ã€ã®æäœã«ã€ããŠèª¬æããŸãã ãã¹ãŠã®ã³ã³ããŒãã³ãã¯ç¬ç«ããŠãããå¥ã ã®ã¹ã¬ããã§å®è¡ãããŸãã
ã€ã³ãžã§ã¯ã·ã§ã³ã¢ãžã¥ãŒã«ïŒå¥ã®ããã»ã¹ã®ã¢ãã¬ã¹ç©ºéã§ã®å®è£ ïŒ
Salityã¯ãã¢ã«ãŠã³ããã·ã¹ãã ãããããŒã«ã«ãµãŒãã¹ããããããã¯ãŒã¯ãµãŒãã¹ãã«ä»£ãã£ãŠå®è¡ãããããã»ã¹ãé€ããå®è¡äžã®ãã¹ãŠã®ããã»ã¹ã«ã³ããŒãåã蟌ã¿ãŸãã ç¹æš©ããã»ã¹ã®å Žåããããã°ç¹æš©ãå ¬éããååºŠäŸµå ¥ãè©Šã¿ãŸãã åå®è£ ãé€å€ããã«ã¯ãã¢ããªã±ãŒã·ã§ã³åã§ãã¥ãŒããã¯ã¹ã䜿çšããŸãã ããã¯ãã³ã³ãã¥ãŒã¿ãŒææã®å åã®1ã€ã§ãã
ä¿è·ã¢ãžã¥ãŒã«
ãã®ã¢ãžã¥ãŒã«ã¯ãSalityããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ããä¿è·ããŸãã OSãã»ãŒãããŒãã¢ãŒãã§èªã¿èŸŒãŸããªãããã«ããŠã€ã«ã¹ã¯æ¬¡ã®ãã©ã³ãã®ã¬ãžã¹ããªããããŒãšå€ãåé€ããŸãïŒãHKEY_CURRENT_USER \ System \ CurrentControlSet \ Control \ SafeBootãããã³ãHKEY_LOCAL_MACHINE \ System \ CurrentControlSet \ Control \ SafeBootã
å€ãã®ãŠã€ã«ã¹å¯Ÿçããã°ã©ã ã®ãµãŒãã¹ããããã¯ãããŠããŸãã Salityã®ä»¥åã®ããŒãžã§ã³ã¯ããã«æ»æçã§ãã·ã¹ãã ãããããã®ãµãŒãã¹ãåã«åé€ããŠããŸããã
ãã®ãŠã€ã«ã¹ã¯ãã«ãŒãã«ãã©ã€ããŒãå°å ¥ããŸãã ãã®ãã©ã€ããŒã¯ãïŒ SystemïŒ \ driversãã©ã«ããŒã®ç䌌ã©ã³ãã åã§è¿œå ãããŸãã ãamsint32ããšããååã®ãµãŒãã¹ãäœæãããŸãã ãã©ã€ããŒã¯3ã€ã®ç°ãªãæ©èœãå®è¡ããŸãã
- ããã»ã¹ã®ããã©ãŒãïŒããã»ã¹ãã©ãŒïŒ-Salityã¯å®è¡äžã®ããã»ã¹ãç¶ç¶çã«ã¹ãã£ã³ããããã»ã¹åãã»ãã¥ãªãã£ãœãããŠã§ã¢ã®ãªã¹ãã«å«ãŸããŠããå Žåããã®ãããªããã»ã¹ã¯åæ¢ããŸãã ãªã¹ãèªäœã¯ã³ãŒãã§ããŒãã³ãŒãã£ã³ã°ãããŠããŸãã ã¢ã³ããŠã€ã«ã¹ã®èªå·±é²è¡ããã€ãã¹ããããã«ããã¹ãŠã®ããã»ã¹ã¯ãã©ã€ããŒã«ãã£ãŠã«ãŒãã«ã¬ãã«ã§ç Žæ£ãããŸãã
- ãã±ãããã£ã«ã¿-ãã©ã€ãã¯ãIPCTLãã©ã€ãã«IOCTL_PF_SET_EXTENSION_POINTERå¶åŸ¡èŠæ±ãéä¿¡ããããšã«ããããIPFilterã³ãŒã«ããã¯ã«ãŒãã³ãé¢æ°ãç»é²ããŸãïŒãã®é¢æ°ã¯Windows XP / 2003/2000ã§æ©èœããŸããããVista以éã®ããŒãžã§ã³ã§ã¯äœ¿çšãããŸããïŒã ãã®æ©èœã®ãããã§ãSalityã¯ãŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ãã³ããŒã®ãµã€ãã®ã¢ãã¬ã¹ãã¿ãŒã³ã«å¯Ÿå¿ããIPãã±ãããç Žæ£ã§ããŸããã ãã®çµæããŠãŒã¶ãŒã¯Symantec.comãªã©ã«ã¢ã¯ã»ã¹ã§ããŸããã§ããã
- çä¿¡ããã³çºä¿¡SMTPãã©ãã£ãã¯ã®ãããã«ãŒïŒãããã«ãŒïŒã ãã®æ©èœã¯ããŠãŒã¶ãŒã¢ãŒãã§åäœããã¢ãžã¥ãŒã«ã«ãã£ãŠå®è£ ããããããããããªãã¬ãŒã¿ãŒããã®ã³ãã³ãã§èµ·åãããŸããã 以éã®ããŒãžã§ã³ã§ã¯ããã®ã¢ãžã¥ãŒã«ã¯äœ¿çšãããŸããã§ãããããã®ã³ãŒãã¯ä¿åãããŠããŸããã
ææã¢ãžã¥ãŒã«
ãªããžã§ã¯ãã以äžã®ããã«ãææã¢ãžã¥ãŒã«ã¯ãŠã€ã«ã¹ã®è€è£œãæ åœããŸãã
- ã¬ãžã¹ããªãã©ã³ããHKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ ShellNoRoam \ MUICacheãã«ãªã¹ããããŠãããã¡ã€ã«ã ãã®ãã©ã³ãã«ã¯ãã¿ã¹ã¯ããŒã®ã¢ã€ã³ã³ãã°ã«ãŒãåãããšãã«Explorerã䜿çšããã¢ããªã±ãŒã·ã§ã³ã®ååãå«ãŸããŠããŸãã å¯äœçšãšããŠ-MUICacheã¯ãã·ã¹ãã ã«ã€ã³ã¹ããŒã«ãããã»ãŒãã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ã®ãªããžããªã§ãã
- ãHKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Runãããã³ãHKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Runããã©ã³ãã®å®è¡ããŒå ã®ãã¡ã€ã«ã
- ããŠã³ãããããã©ã€ãäžã®exeããã³scrãã¡ã€ã«ãBããZã«ã¹ãã£ã³ïŒåæïŒããŸãã
- WindowsããŒãã£ã·ã§ã³ä»¥å€ã®ãã£ã¹ã¯ã®ã«ãŒããã£ã¬ã¯ããªã¯ãé»åãŸãã¯ãã€ã³ã¹ã€ãŒãããã°ã©ã ã®ææã³ããŒãäœæããããšã«ããææããŸãã ãã¡ã€ã«ã¯ãä»»æã®ååãšæ¡åŒµåã®exeãcmdããŸãã¯pifã§äœæãããŸãã autorun.infãã¡ã€ã«ãäœæãŸãã¯å€æŽããããã£ã¹ã¯ã®ããŠã³ãæã«äœæãããææãã¡ã€ã«ãèªåçã«èµ·åãããŸãã ãã®ãããªãã¡ã€ã«ãéå§ãããšã察å¿ããããã°ã©ã ïŒãCalculatorããŸãã¯ãMinesweeperãïŒãéå§ãã代ããã«ããšã¯ã¹ãããŒã©ãŒãŠã£ã³ããŠãéããŸãã
- ãããã¯ãŒã¯ãªãœãŒã¹ã®å®è¡å¯èœãã¡ã€ã«ãã¹ãã£ã³ãããŸãã
ãŠã€ã«ã¹å¯Ÿçãã¡ã€ã«ïŒãªã¹ãããïŒã®å Žåãææã®ä»£ããã«ããšã³ããªãã€ã³ãã³ãŒãããã€ãããã§æžãæããããšããŸãïŒint 3ããã³retã®æé ãç¹°ãè¿ããŸãïŒã ãã®æäœã倱æãããšãSalityã¯ãã¡ã€ã«ãåé€ããããšããŸãã ãŸããææã¢ãžã¥ãŒã«ã¯ãã£ã¬ã¯ããªãã¹ãã£ã³ããæ¡åŒµåãvdbãŸãã¯avcïŒãŠã€ã«ã¹å¯ŸçäŒç€Ÿã®ã·ãã³ããã¯ããã³ã«ã¹ãã«ã¹ããŒã®çœ²åïŒã®ãã¡ã€ã«ãåé€ããŸãã
ææã¢ãžã¥ãŒã«ã®èå³æ·±ãæ©èœïŒãã¢ãªã¹ãã空ã®å Žåãæææé ã¯ç¡å¹ã«ãªããŸãã ããã¯ç¬ç¹ã®é åžæŠç¥ãåæ ããŠããŸããP2Pãããã¯ãŒã¯ãžã®æ¥ç¶ããªããè¿œå ã®æªæã®ããã¢ãžã¥ãŒã«ãããŠã³ããŒãã§ããªãå Žåããã¡ã€ã«ã«ææããå¿ èŠã¯ãããŸããã
ææã«ã¯ãEPOïŒentry-point obscuringïŒæè¡ã䜿çšãããŸãã
- ãšã³ããªãã€ã³ãã¯å€æŽãããŸããã
- ãŠã€ã«ã¹ã³ãŒãã«åãæ¿ããããã®jmpã³ãã³ãã¯å ¥åã¢ãã¬ã¹ã«èšé²ãããã³ãŒãã¯æåŸã®ã»ã¯ã·ã§ã³ã®æåŸã«ãããŸããããã¯ãã®ããã«ç¹ã«æ¡åŒµãããŠããŸãã ã»ã¯ã·ã§ã³ãã©ã°ã«å ããŠãæžã蟌ã¿ãšå®è¡ã®èš±å¯ãè¿œå ãããŸããã
- 埩å·åã®åŸãjmpã³ãã³ãã§åé€ããããã¡ã€ã«ã®å 容ã埩å ãããã¡ã€ã³ãŠã€ã«ã¹ã³ãŒããå¥ã®ã¹ããªãŒã ã§èµ·åãããå¶åŸ¡ãå ã®ãšã³ããªãã€ã³ãã«è»¢éãããŸãã
Salityã¯ããªãã·ã§ã³ããšã«ç°ãªãç¹å®ã®ãã¥ãŒããã¯ã¹ã®ã·ã¹ãã å ã§ã®ååšããã§ãã¯ããŸãã ãã£ã¹ã¯ã®ã«ãŒããã£ã¬ã¯ããªããèµ·åãããšããšã¯ã¹ãããŒã©ãŒãŠã£ã³ããŠãéããŸãã
ããŠã³ããŒãã¢ãžã¥ãŒã«
ããŠã³ããŒãã¢ãžã¥ãŒã«ã¯ããã¢ããŒãã¢ã¢ãžã¥ãŒã«ã«ãã£ãŠåä¿¡ãããURLããè¿œå ã®æªæã®ããã¢ãžã¥ãŒã«ãããŠã³ããŒãããŠèµ·åãã圹å²ãæãããŸãã ããŠã³ããŒãããããã¡ã€ã«ã¯RC4æå·ã§ãšã³ã³ãŒãããããã®ããŒã¯ã³ãŒãã«ç»é²ãããŠããŸãã Salityãšãã®æªæã®ããã¢ãžã¥ãŒã«ãåãäœæè ã«ãã£ãŠäœæãããå¯èœæ§ãæãé«ãã§ãã ãã ããæªæã®ããã¢ãžã¥ãŒã«ã¯åŸæ¥ã®æ¹æ³ã§åäœããäžçäžã«ãã管çãµãŒããŒã«æ¥ç¶ããŸãã
Salityã«ãã£ãŠé åžãããæªæã®ããã¢ãžã¥ãŒã«ã®ãªã¹ãïŒ
ã¹ãã ãžã§ãã¬ãŒã¿ãŒãšã¹ãã ãªã¬ãŒ;ã¹ãã ã³ã³ãã³ãã¯éåžžãã«ãžãåºåãŸãã¯å»è¬åã«é¢é£ä»ããããŠããŸãã
HTTPãããã·ã¯ããããã¯ãŒã¯ã¢ã¯ãã£ããã£ããã¹ã¯ããå¿åæ§ãå®çŸããããã«äœ¿çšãããŸãã
æ å ±ã³ã¬ã¯ã¿ãŒ ããã¹ã¯ãŒããã¢ã«ãŠã³ããããã³Webãã©ãŒã ïŒInternet Explorerã§ã®å®è£ ïŒããã®ããŒã¿ãå«ãå人ããŒã¿ãåéããŸãã
ãŠã§ããµã€ãææã ãã®æªæã®ããã¢ãžã¥ãŒã«ã¯ãFTPã¢ã«ãŠã³ããã€ã³ã¿ãŒã»ããããFTPããŒã¿ã«æ¥ç¶ããŠHTMLãã¡ã€ã«ã«ææããŸãã ææã¯ããµãŒãããŒãã£ã®ãªãœãŒã¹ãæãIFRAMEãåã蟌ããããµãŒããŒåŽã§å®è¡ãããã¹ã¯ãªããã䜿çšããŠçºçããŸãã ãã®ãããªææã®ç®çã¯ããã©ã€ããã€ããŠã³ããŒãããŠãŒã¶ãŒã³ã³ãã¥ãŒã¿ãŒã®ææããã¹ãã ã¡ãŒã«ã«ãŸã§åã³ãŸãã
åæ£ãããã³ã°ã·ã¹ãã ã2011幎2æã«ãCïŒCãµãŒããŒã³ãã³ãã«å¿ããŠããã€ãã®ã¢ãŒãã§åäœããã¢ãžã¥ãŒã«ãé åžãããŸããã
- SIPããã³HTTPãµãŒããŒã®æ€åºïŒCïŒCã¯ãã¹ãã£ã³ããIPã¢ãã¬ã¹ã®ãªã¹ããã¢ãžã¥ãŒã«ã«éä¿¡ããŸãã ã¹ãã£ã³çµæã¯CïŒCãµãŒããŒã«å ±åãããŸãã
- ã¿ãŒã²ãããµãŒããŒäžã®ã¢ã«ãŠã³ãã®ç»é²ïŒæ©èœã¯å®å šã«ã¯å®è£ ãããŠããŸããïŒ;
- ã¢ã«ãŠã³ãã®ãããã³ã°ïŒCïŒCã¯ã¢ãžã¥ãŒã«ã«ã¢ã«ãŠã³ãã®ãªã¹ããšåæçšã®ãã¹ã¯ãŒãã®ãªã¹ããéä¿¡ããŸãã æ€åºãããæå¹ãªãã°ã€ã³ãã¹ã¯ãŒãã®ãã¢ã¯ãCïŒCãµãŒããŒã«éãè¿ãããŸãã
- åã®æé ã§èŠã€ãã£ãããŸãã¯ä»ã®ãœãŒã¹ããååŸããAsterisk FreePBXããµãŒããŒãªã¹ãããã¹ã¯ãŒããªã¹ãã®ãããã³ã°ã¯ãAsterisk FreePBXãµãŒããŒã®ãã¹ã¯ãŒãã®æ€åºãšéžæã«äœ¿çšãããŸãã ãã®çš®ã®æ»æã®ç®çã¯éåžžãééçã§ãã ææçªå·ãç»é²ããæ€åºãããåSIPã¢ã«ãŠã³ããããã®çªå·ã«é»è©±ããããããšãã§ããŸãã FreePBXããããã³ã°ãããšãããã«æ·±å»ãªçµæãæãå¯èœæ§ããããŸããæ»æè ããŠãŒã¶ãŒã®èªèšŒãšèª²éãããã³é話ã«ãŒãã£ã³ã°ãå¶åŸ¡ã§ããããã§ãã
å®éšã¢ãžã¥ãŒã« ãä»æ¥ã§ã¯2ã€ã®å®éšã¢ãžã¥ãŒã«ã®ã¿ãç¥ãããŠãããæããã«ãã®æè¡ããã¹ãããããã«çºå£²ãããŸããã æåã®ã¢ãžã¥ãŒã«ã¯ãFacebookã¢ããªã±ãŒã·ã§ã³ãèªåçã«ç»é²ããããã®ã¹ã¯ãªããã§ãã ãã®ã¢ãžã¥ãŒã«ã¯ãæšæºã®COMã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠInternet Explorerã«å®è£ ãããæ å ±ã³ã¬ã¯ã¿ãŒã§ãããWebãã©ãŒã ããç»é²ããŒã¿ãåéããCïŒCãµãŒããŒã«éä¿¡ããŠãæå·åããã圢åŒã§ããŒã«ã«ã«ä¿åããŸãã å®éšã¢ãžã¥ãŒã«ã¯ã次ã®äžé£ã®ã¢ã¯ã·ã§ã³ã§ã¹ã¯ãªãããå®è¡ããŸãïŒInternet Explorerãå¯èŠïŒïŒïŒãŠã£ã³ããŠã¢ãŒãã§éããfacebook.comã«ã¢ã¯ã»ã¹ããã€ã³ã¿ãŒã»ãããããç»é²ããŒã¿ã䜿çšããŠãã°ã€ã³ããVIOTã¹ãããã¢ããªã±ãŒã·ã§ã³ããŒãžã«ç§»åãïŒïŒ11908467418ïŒãã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ããŸããéãããŠã£ã³ããŠã ã¢ããªã±ãŒã·ã§ã³ã¯ããåºæ¬æ å ±ãã®ã¬ãã«ã§ã¢ã¯ã»ã¹ã䜿çšããŸã-ååãæ§å¥ãåçãåéãªã¹ãã çŸæç¹ã§ã¯ããã®ã¢ãžã¥ãŒã«ã¯æªæã®ããã¢ã¯ã·ã§ã³ãçæããŸããïŒãããå®éšçãšåŒã°ããçç±ã§ãïŒãããã®çš®ã®ã¢ã¯ãã£ããã£ã®å¯èœæ§ãéåžžã«é«ããããæ»æè ã¯ãããã³ã°ãããFacebookã¢ã«ãŠã³ãã䜿çšããŠã¹ãã ïŒæçš¿ïŒãé åžããããä»®æ³ããŒã³ãååŸãããã§ããŸãã
Salityã«ãã£ãŠé åžãããå¥ã®ã¹ã¯ãªããã¯ã次ã®ã¢ã¯ã·ã§ã³ãå®è¡ããŸãããInternetExplorerãé衚瀺ã¢ãŒãã§èµ·åããgoogle.comã«ã¢ã¯ã»ã¹ããŸãã æååãauto Insurance bidsãã®æ€çŽ¢ãå®è¡ããŸãã ãŠã£ã³ããŠãéããŸãã ãã®ã¹ã¯ãªããã¯å®éšçãªç®çãæãããGoogleãã¬ã³ãã®ç¹å®ã®ãããã¯ã宣äŒã§ããŸãã
ãã¢ããŒãã¢ã¢ãžã¥ãŒã«
ãã¢ããŒãã¢ã¢ãžã¥ãŒã«ã¯ãæªæã®ããã¢ãžã¥ãŒã«ãžã®URLãªã³ã¯ã®é åžãæ åœããŸãã P2Pãããã¯ãŒã¯ã«ã¯åºå®CïŒCãµãŒããŒããããŸããã Salityã®å Žåãããããããã®ãããã¯ãŒã¯ããããã¯ããããšãããšããã¹ãŠã®ã¹ãŒããŒãã¢ããããã¯ããå¿ èŠããããŸããããã¯çè«çã«ã¯å¯èœã§ãããå®è£ ãå°é£ã§ãã ãããã¯ãŒã¯ãžã®æåã®æ¥ç¶ã¯ãææãããã¡ã€ã«ã«å«ãŸãããã¢ã®ããŒãã¹ãã©ãããªã¹ããä»ããŠè¡ãããå€æ°ã®æ¢åã®ãã¢ã®ãããªãã¯IPãšããŒããå«ãŸããŸãã ãŠã€ã«ã¹ã®ãã¹ãŠã®ããªãšãŒã·ã§ã³ã§ããªã¹ãã®ãµã€ãºã¯1000ãšã³ããªã«å¶éãããŠããŸãã
Salityãæåã«èµ·åãããæç¹ã§ãåæãªã¹ãã®ããŒã«ã«ã³ããŒãWindowsã¬ãžã¹ããªïŒç䌌ã©ã³ãã åã®äžã®HKEY_CURRENT_USERãã©ã³ãïŒã«äœæããããã®ããŒã«ã«ãªã¹ããæ°ããã¢ã¯ãã£ããã¢ã®è¿œå ãšéã¢ã¯ãã£ããã¢ã®åé€ã«ãã£ãŠæŽæ°ãããŸãã
å°ãªããšã4ã€ã®ãããã³ã«ããŒãžã§ã³ããããŸãã
- ãããã³ã«ããŒãžã§ã³V1ã®å®è£ ã®ã€ã³ã¹ã¿ã³ã¹ã¯æ€åºãããŸããã§ããã
- V2ã¯2008幎åé ã«åããŠçºèŠãããŸããããçŸåšã¯äœ¿çšãããŠããŸããã
- V3ãããã³ã«ã®ããŒãžã§ã³ãšããã«åºã¥ããããã¯ãŒã¯ã¯ãæãäžè¬çã§åå²ããŠãããã®ã§ãã ãã®ãããã³ã«ã®æåã®èšåã¯ã2009幎以éã§ãã
- V4ãããã³ã«ã«åºã¥ããããã¯ãŒã¯ã¯ãV3ãããã¯ãŒã¯ãããèããå°ãããªããŸãã 2010幎æ«ã«åããŠçºèŠãããŸããã
ãããã³ã«ããŒãžã§ã³V2ãšV3ã®éãã¯ãããããã§ãã åææãã¡ã€ã«ã«ã¯URLãªã³ã¯ã®ãªã¹ãã確èªããããã«äœ¿çšãããå ¬éããŒãå«ãŸããŠããããããããã³ã«ã®æ°ããããŒãžã§ã³ããšã«æ°ããããŒã䜿çšããå¿ èŠããããŸãã ããŒãžã§ã³V2ããV3ãžã®ç§»è¡ã¯ãURLã®ãªã¹ãã«çœ²åããããã«äœ¿çšãããç§å¯ããŒã䟵害ããããšããäºå®ã«ãã£ãŠæ±ºå®ããããšæ³å®ã§ããŸãã
3çªç®ã®ããŒãžã§ã³ã®ãããã³ã«ã«ã¯ãæäœã¢ã«ãŽãªãºã ã«æœåšçãªè匱æ§ããããããããããïŒã¢ã³ããŠã€ã«ã¹äŒæ¥ãŸãã¯ãã®ä»ã®äŸµå ¥è ïŒãå¶åŸ¡ããããšãã§ããŸãã-URLã®ãªã¹ããããŠã³ããŒãããŠç¢ºèªããåŸãã¢ãã¬ã¹èªäœãŸãã¯ããããããŠã³ããŒããããã¡ã€ã«ã«å¯ŸããŠä»ã®ãã§ãã¯ã¯å®è¡ãããŸããã ã€ãŸããDNSã¬ã³ãŒããå€æŽããããã¢ãžã¥ãŒã«ãã¡ã€ã«ãç¬èªã®ãã®ã«çœ®ãæãããããŠãå¶åŸ¡ãååããå¯èœæ§ããããŸãã ãããããããç Žå£ããããã®ãã®å¯èœæ§ã«é¢ããæ å ±ã¯ãæ³ãéµå®ããåžæ°ïŒæ³ãéµå®ããåžæ°ïŒã®åœåã®äžã§æªç¥ã®äººç©ã«ãã£ãŠå ¬éãããŸããã3çªç®ã®ããŒãžã§ã³ã®ææããã匱ç¹ãæé€ããããã«ãèè ã¯ããŠã³ããŒãããããã¹ãŠã®ãã¡ã€ã«ãå«ã4çªç®ã®ããŒãžã§ã³ãéçºããããã§ãããžã¿ã«çœ²åãå«ãŸããŠããå¿ èŠãããã2048ãããé·ã®RSAå ¬ééµã®äœ¿çšãéå§ããåã«æ€èšŒãããŸãã
ç§ãã¡ã®æ¥ã
çŸåšãSalityã¯åŒãç¶ãäžçã§æãäžè¬çãªãã«ãŠã§ã¢ã®1ã€ã§ãã ã«ãªãã©ã«ãã¢å€§åŠãµã³ãã£ãšãŽæ ¡ãšãããªå€§åŠïŒã€ã¿ãªã¢ïŒã®2012幎10æã®ç 究è ã°ã«ãŒãã¯ãSality掻åã®åæãå«ãã¬ããŒã ïŒpdfãengïŒãçºè¡ããŸããã æ å ±ã¯ãããã·ããã©ãã£ãã¯ç£èŠã·ã¹ãã UCSD Network Telescopeã䜿çšããŠåéãããŸããã ç 究è ã«ãããšã2011幎2æã®12æ¥éã§ãSIPæ¥ç¶ãéå§ããããã«300äžåã®IPã¢ãã¬ã¹ãããã±ãããéä¿¡ãããŸããã ã¬ããŒãã®äœæè ã«ãããšãããããããã®ææè ã¯ãç¡æã®é»è©±ãå¿åé話ãè©æ¬ºãªã©ã«äœ¿çšããããã«ãSIPãµãŒããŒãç·åœããæ»æããŠåœã®ã¢ã«ãŠã³ããäœæããããšããŸããã
èå³æ·±ãããšã«ãå¯èœãªéãã¹ãã£ã³ããã¹ã¯ããããã«å€ãã®ææ³ã䜿çšãããŸããã ããšãã°ã100äžåã®IPã¢ãã¬ã¹ãããæ¥ç¶ãåæåããããã«1ã€ã®ãã±ããã®ã¿ãéä¿¡ãããå Žåããããã®ã¢ãã¬ã¹ã¯äœ¿çšãããŸããã§ããã ã¹ãã£ã³ãããIPã¢ãã¬ã¹ã®ç¯å²ã¯ããã«ãã«ããã©ã¯ã¿ã«æ²ç·ã«æ²¿ã£ãŠå€åããã¹ãã£ã³ã®äºå®ãæ€åºããããšãå°é£ã«ããŸããã ç 究è ã¯ãIPv4ã®å šç¯å²ãã€ãŸãã€ã³ã¿ãŒãããå šäœãã¹ãã£ã³ããããšèããŠããŸããããªã¯ãšã¹ãã¯ç°ãªãIPããéä¿¡ããããããè åšæ€åºã·ã¹ãã ã¯ãã®ãã©ãã£ãã¯ãæ€åºã§ããŸããã§ããã ãããã®äºå®ã¯ãSalityããããããã®ç¯å²ãç解ããäœæè ã®ç¥çèœåãè©äŸ¡ããã®ã«åœ¹ç«ã¡ãŸãã
ãã®ããã¹ãã¯ãSymantec ã®ã¬ããŒããSalityïŒStory of a Peer-to-Peer Viral Networkã ã verã1 ã2011幎7æïŒpdfãengïŒã®äžå®å šãªãã·ã¢èªèš³ã§ãã