
ã€ã³ã¿ãŒãããã«ããµãŒããŒã眮ããããã«ã¯ãã»ãã¥ãªãã£ã«æ³šæããå¯èœãªéããµãŒããŒãžã®ã¢ã¯ã»ã¹ãå¶éããå¿ èŠãããããšã¯çãäœå°ããããŸããã DNSãããã³ã«ã¯ã被害è ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ïŒDNSãµãŒããŒããã£ãã«ïŒãžã®æ»æãšä»ç€Ÿãžã®æ»æã®äž¡æ¹ã«äœ¿çšã§ããŸãã éå»1幎éã§ããã®ãããªæ»æã®æ°ã¯å°ãªããšã2åã«å¢å ããŠããŸãã DDoSæ»æãèŠèŠåããdigitalattackmap.comã§ã¯ãWebæ»æïŒ80/443ïŒãšãšãã«DNSããªã¹ããã匷調衚瀺ãããŠããŸãã
DNSãµãŒãã¹ã¯ïŒäž»ã«ïŒUDPãããã³ã«ã§æ©èœããŸãããããã¯äºåæ¥ç¶ãæå³ãããã®ã§ã¯ãªããããç¹å¥ãªæºåãªãã§ä»ã®ãµãŒããŒãžã®æ»æïŒã¹ããŒãã£ã³ã°ïŒã«å¯ŸããŠåé¡ãªã䜿çšã§ããŸãã ããŸããŸãªãœãŒã¹ããã®æ å ±ã«ãããšãçŸåš800ã2,000äžDNSãµãŒããŒã®1.2ãååž°ã¯ãšãªã«å¿çããŠããŸãã ãããã¯ãäžæ£ã«æ§æãããä¿¡é Œã§ãããã£ãã·ã¥DNSãµãŒããŒããŸãã¯åçŽãªCPEã®ããããã§ãã
ãªãŒãã³ãªååž°DNSãµãŒããŒãç¶æããããšã¯ïŒèªåã«ãšã£ãŠãä»ã®äººã«ãšã£ãŠãïŒã©ãã»ã©å±éºãã«èå³ããã£ãã®ã§ãå°ã調æ»ããããšã«ããŸããã
åé¡ã®å£°æ
次ã®è³ªåãå®åŒåãããŸããããããã«çãããã§ãã
- ãªãŒãã³ãªååž°DNSãµãŒããŒãæ€åºããããŸã§ã®æéã
- ãã€éæ³ç®çã§ãµãŒããŒã䜿çšãå§ããŸããã
- ãµãŒããŒã®è² è·ïŒ1ç§ãããã®èŠæ±æ°ïŒã決å®ããŸãã
- ã©ã®çµç¹ã察象ã«ãªã£ãŠããããå€æããŠãã ããã
- 䟵害ãããïŒãã©ãã¯ãªã¹ãã«ç»é²ãããïŒãã¡ã€ã³ãIPã¢ãã¬ã¹ãèŠæ±ããããã©ããã
ãã¹ãã«ã¯ããã¥ã«ã³ãã«ã¯ãããããŒããŒã¿ã»ã³ã¿ãŒã«ã€ã³ã¹ããŒã«ããããµãŒããŒã䜿çšãããŸãã 以åã¯æš©éã®ããDNSãµãŒããŒããã®ãµãŒããŒã«ãããã¯ãšãªã®æ°ã¯1æ¥ããã200ãè¶ ããŠããŸããã§ããã ãµãŒããŒã®IPã¢ãã¬ã¹ïŒæ°ããåè³äŒç€Ÿãžã®ç§»è»¢ã«ããïŒã¯ã7æã«å€æŽãããŸããã ãã¡ã€ã³ããã§ãã¯ããããã«ãRPZïŒå¿çããªã·ãŒãŸãŒã³ïŒã¡ã«ããºã ãšInfobloxã®ãã©ãã¯ãªã¹ãã䜿çšãããŸãã ã
çè«ã®ããã
DNSãµãŒããŒãä»ããŠæ»æãå®è¡ããã«ã¯ã次ã®ååã䜿çšãããŸãã
- DNSã¯UDPäžã§æ©èœãããããæ»æè ã¯èªåã®IPã¢ãã¬ã¹ã被害è ã®ã¢ãã¬ã¹ã«å€æŽã§ããŸãã
- DNSã¯ãšãªã¯é察称ã§ãããå¿çãã©ãã£ãã¯ã¯çä¿¡ãæ°åè¶ ããããšããããŸãã
ãããã®ååã«åºã¥ããŠãDNSã䜿çšããŠæ¬¡ã®ã¿ã€ãã®æ»æãåºå¥ã§ããŸãã
- å¢å¹ æ»æïŒã²ã€ã³ã䌎ãæ»æïŒ-DNSãµãŒããŒã®çºä¿¡ãã£ãã«ã«éè² è·ããããããšãç®çãšããŠããŸãã ããã¯ãéåžžã«å€§ããªå¿çãååŸããããã«ç¹å¥ã«éžæããã倧éã®DNSã¯ãšãªã®éä¿¡ããå§ãŸããŸãããã®ãµã€ãºã¯ãã¯ãšãªã®ãµã€ãºã®æ倧70åã«ãªããDNSãµãŒããŒã®éä¿¡ãã£ãã«ã®éè² è·ã«ã€ãªãããæçµçã«ãµãŒãã¹æåŠïŒDoS ïŒ;
- ãªãã¬ã¯ã·ã§ã³æ»æ-ãµãŒãããŒãã£ã®DNSãµãŒããŒïŒç§ã®ãã®ãªã©ïŒã䜿çšããŠã倧éã®èŠæ±ãéä¿¡ããããšã§DoSãŸãã¯DDoSæ»æãäŒæããŸãã ãã®ãããªæ»æã§ã¯ãDNSã¯ãšãªã®éä¿¡å ã®ã¢ãã¬ã¹ã被害è ã®IPã¢ãã¬ã¹ã«çœ®ãæãããããªã¯ãšã¹ãã«ã¯æ»æè ã§ã¯ãªã被害è ã®ãµãŒããŒã®ããŒã¿ãå«ãŸããŸãã ãã®çµæãããŒã ãµãŒããŒã¯èŠæ±ãåä¿¡ãããšããã¹ãŠã®å¿çã被害è ã®IPã¢ãã¬ã¹ã«éä¿¡ããŸãã ãã®ãããªãåå°ããã©ãã£ãã¯ã倧éã«ãããšã被害è ã®ãµãŒããŒ/ãããã¯ãŒã¯ãç¡å¹ã«ãªãå¯èœæ§ããããŸãã
- åæ£åå°DoSïŒDrDoSïŒ-åå°æ»æãšå¢å¹ æ»æãçµã¿åãããŠã被害è ã®ãµãŒããŒãæ··ä¹±ããå¯èœæ§ãå€§å¹ ã«é«ããŸãã åæã«ãDNSå¿çãä¿è·ãããã£ãã·ã¥ãã€ãºãã³ã°ãé²æ¢ããããã«ç¹å¥ã«èšèšãããDNSSECã¯ãDNSã¡ãã»ãŒãžã®ãµã€ãºã倧ãããªãã«ã€ããŠããã®çš®ã®æ»æãããã«å¹æçã«ããããšãã§ããŸãã å¢å¹ ã¯æ倧100åã«éããå¯èœæ§ããããæ»æè ã¯ãããããããããã¯ãŒã¯ã䜿çšã§ããŸãã
ãªã¹ããããŠããå¯èœæ§ã®ããæ»æã®ãªã¹ãã¯å®å šã§ã¯ãããŸãããããã®èª¿æ»ã«ã¯ååã§ãã
調æ»çµæ
1é±éã®éã«ã1169ã®ã¯ã©ã€ã¢ã³ããã63ã®ãã¡ã€ã³ã«å¯ŸããŠåèš416åã®ãªã¯ãšã¹ããåä¿¡ãããŸãããããã¯ã調æ»ã®æåãšãã®ãããã¯ã®éèŠæ§ã瀺ããŠããŸãã
以äžã¯ãDNSãµãŒããŒãžã®1ç§ãããã®ã¯ãšãªæ°ã®ã°ã©ãã§ãã

ãŸããæèµ·ããã質åã«çããŸãã
- ãªãŒãã³ãªååž°DNSãµãŒããŒãæ€åºããããŸã§ã®æéã
æåã®ãªã¯ãšã¹ãã¯ããã¡ã€ã³www.google.itãžã®1æé20ååŸã«äžåœããæ¥ãŸããã - ãã€éæ³ç®çã§ãµãŒããŒã䜿çšãå§ããŸããã
1æ¥åŸïŒã°ã©ãã®æåã®å°ããªæ¥äžæïŒããµãŒããŒã¯æ»æã«å®æçã«äœ¿çšããå§ããŸããã 30åã§ãwebpanel.skãã¡ã€ã³ãžã®300件ã®ãªã¯ãšã¹ããåä¿¡ãããŸããã åŸã ã«ããªã¯ãšã¹ãã®æ°ãšæ»æã®æéãå¢å ããŸããã - ãµãŒããŒã®è² è·ïŒ1ç§ãããã®èŠæ±æ°ïŒã決å®ããŸãã
æ»æã®æç¹ã§ããµãŒããŒã¯1ç§ããã2ã4ãªã¯ãšã¹ãã®æå€§è² è·ãçµéšããŠããŸããã ãã¹ãã®æçµæ¥ã«ããªã¯ãšã¹ãã®æ°ã¯1ç§ããã20ãªã¯ãšã¹ãã«æ¥å¢ããŸããã DNSå¢å¹ æ»æã䜿çšããããããDNSãªãã¬ã¯ã·ã§ã³ãšçµã¿åãããããã©ãããå€æããããšã¯å°é£ã§ããã - ã©ã®çµç¹ã察象ã«ãªã£ãŠããããå€æããŠãã ããã
èŠæ±ããããã¡ã€ã³ã®æ°ã¯å°ãªããããæœåšçãªè¢«å®³è ãšæ»æå°çšã®ãã¡ã€ã³ãç¹å®ããã®ã¯ç°¡åã§ããã
-ç±³åœåŽåçã®ãã¡ã€ã³doleta.govã¯DNSSECã䜿çšããŠããããµãŒããŒã®å¿çã¯çŽ4 KBã127åã®èŠæ±ã§ãã 顧客ã«ãããªã¯ãšã¹ãæ°ã®ååžã¯ã»ãŒåçã§ãããTOP10ã¯äžçäžã®ããŸããŸãªåœïŒååã¢ã¡ãªã«ããªãŒã¹ãã©ãªã¢ããã¥ãŒãžãŒã©ã³ãããšãŒãããïŒã«ãããŸãã
-ãã¡ã€ã³webpanel.skã§ããã¹ãããã¢ã®äŒç€Ÿã¯DNSSECã䜿çšãããµãŒããŒã®å¿çã¯çŽ4 Kbã§ã-162åã®ãªã¯ãšã¹ãïŒã»ãšãã©ã®ãªã¯ãšã¹ãã¯èšäºãæžãããæ¥ã«æ¥ããã®ã§ãæ°ã¯çµ¶ããå¢å ããŠããŸãïŒã dnsamplificationattacks.blogspot.ruã¯ããã®ãã¡ã€ã³ãDNSå¢å¹ æ»æå°çšã«äœ¿çšãããŠãããšçã£ãŠããŸãã å®éããã®ãµãŒããŒããã®å¿çã¯ãDNSSECã䜿çšããä»ã®ãµãŒããŒãšå€ãããŸããã ãã€ãã®ãã¹ãã£ã³ã°ãµãŒããŒããã·ã¢ã®ã²ãŒã ãã¹ãã£ã³ã°ãããã³ç±³åœã®äžéšã®é¡§å®¢ããã®ãªã¯ãšã¹ããå€æ°ãããŸãã
-ç±³åœç°å¢ä¿è·åºã®ãã¡ã€ã³energystar.govã¯DNSSECã䜿çšãããµãŒããŒã®å¿çã¯çŽ4 KB-79äžãªã¯ãšã¹ãã§ãã åèšã§69ã®ã¯ã©ã€ã¢ã³ãããã¡ã€ã³ãèŠæ±ããŸãããããã®ã»ãšãã©ã¯ç±³åœã«ãããŸãã Royal Empireã²ãŒã ãµãŒããŒãã18,000件ã®ãªã¯ãšã¹ããåä¿¡ããŸããã ãµãŒããŒã«ã¯ãŠãŒã¶ãŒãããªããããããŒã¿çã2014幎7æ11æ¥ä»¥éãªã³ã©ã€ã³ã«ãªã£ãŠããããšããã¥ãŒã¹ã§ç€ºãããŠããããããã®ãµãŒããŒããããã³ã°ããããšæ³å®ã§ããŸãã Qwertyããã³Microsoftãããã¯ãŒã¯ããã®IPã¢ãã¬ã¹ã確èªãããŸããã
-FamiNetworkãfamicraft.comãã¡ã€ã³ã7.5åã®ãªã¯ãšã¹ãã ãã¡ã€ã³ã«ã¯ç¡æå³ãªTXTãwowowowãã¬ã³ãŒããå«ãŸããŠããããããµãŒããŒã®å¿çã¯4kbïŒ50åã®æ»æããŒã¹ãïŒã«éããŸããã èšäºãæžããŠããéçšã§ãfamicraft.comãµãŒããŒã®å¿çãå€æŽãããè åšã§ã¯ãªããªã£ãŠããããšãããããŸããã ãã¡ã€ã³ææè ããããã³ã°ãæ€åºããå¿ èŠãªä¿®æ£ãè¡ã£ãå¯èœæ§ããããŸãã ãªã¯ãšã¹ãã¯4ã€ã®ãµãŒããŒããéä¿¡ããããã®ãã¡2ã€ã¯Akamai Technologiesã«å±ããŠããŸãïŒ5000件ã®ãªã¯ãšã¹ãïŒã
-14ã®Akamai TechnologiesãµãŒããŒã¯ãäžèšã®ãã¹ãŠã®ãã¡ã€ã³ã§çãããã¢ã¯ãã£ããã£ã®çãããããŸããããã¯ãããããAkamaiã«å¯Ÿããæ»æãŸãã¯ãµãŒããŒããããã³ã°ãããããã§ãã
-çä¿¡ãªã¯ãšã¹ãæ°ïŒãªã¯ãšã¹ãç·æ°ã®30ïŒ ïŒã®TOP10ã«ã¯ããã€ãèªãã¹ãã£ã³ã°ïŒç®èã«ãDDoSä¿è·ãæäŸïŒãã²ãŒã ãã¹ãã£ã³ã°ïŒãã·ã¢èªïŒãã²ãŒã ãµãŒããŒã2å°ã®ã¢ã«ãã€ãµãŒããŒãå«ãŸããŸãã ã»ãšãã©ã®å Žåããããã®ãµãŒããŒã¯ãããã³ã°ãããæ®ãã®ã¯ã©ã€ã¢ã³ãã¯ããããããã«ãã°ã€ã³ããŠããŸãã - 䟵害ããããã¡ã€ã³ãèŠæ±ããããã©ããã
ãã ãã¹ãæéå šäœãéããŠãIPã¢ãã¬ã¹104.28.0.111ã§1ã€ã®ãã¡ã€ã³ïŒballsack.pwïŒã®ã¿ããããã¯ãããŸããã ãããã¯ã®çç±ã¯ãThreatStopãµãŒããŒïŒ http://threatstop.com/checkip ïŒã§ç¢ºèªã§ããŸãã ãããããã/ãã«ãŠã§ã¢ã¯å€éšã®ååž°DNSãµãŒããŒãä»ããŠæ»æããã³ã³ãããŒã«ã»ã³ã¿ãŒããã®ã³ãã³ãã®æ¥ç¶ãšåä¿¡ã¯åæåäžã«çºçãããããã€ããŒã¯ããã«ååž°DNSãµãŒããŒã䜿çšãããããååãšããŠè«ççã§ãã
ãã°ãã¡ã€ã«ã®åæäžã«ã次ã®ããšãæããã«ãªããŸããã
- DDoSæ»æã®ããã«äœæãŸãã¯ãããã³ã°ããããã¡ã€ã³ïŒ jerusalem.netfirms.com ïŒå€æ°ã®Aã¬ã³ãŒããæäŸïŒããã³famicraft.com ïŒäžèšïŒã ãããã®DNSãµãŒããŒããã®å¿çã¯4 Kbã§ããã€ãŸããããŒã¿ã䜿çšãããšãçºä¿¡ãã£ãã«ã®50åã®éè² è·ãéæã§ããŸãïŒã°ã©ãäžã®é»è²ïŒã
- ãªãŒãã³ãªååž°DNSãµãŒããŒãç©æ¥µçã«ç£èŠããçµç¹ïŒ
-www.openresolverproject.org;
-dnsscan.shadowserver.org;
-openresolvertest.netãã¡ã€ã³ã«å¯ŸããŠããã€ãã®ãªã¯ãšã¹ãããããŸãããããŠã§ããµã€ãã«ã¯æ å ±ããããŸããã
ãªãŒãã³ååž°DNSãµãŒããŒ
dnsscan.shadowserver.orgãµãŒãã¹ã«ã¯ã800äžã®ãªãŒãã³ãªååž°DNSãµãŒããŒããããŸãã ãããã®ã·ã¹ãã ã®ã»ãšãã©ã¯äžåœã«ããããã·ã¢ã¯6äœã«ãããŸãã
åœ | åèš |
äžåœ | 2,886,523 |
ç±³åœ | 662,593 |
éåœãå ±ååœ | 591,803 |
å°æ¹Ÿ | 449,752 |
ãã©ãžã« | 339,416 |
ãã·ã¢é£éŠ | 264,101 |
åœããšã®DNSãµãŒããŒã®ååžãããªãŒãã³ãªååž°çããã³æš©éã®ããäž¡æ¹ã§èå³æ·±ãã°ã©ãã£ã«ã«ãªè¡šçŸã

çµè«
åŸãããçµæã«åºã¥ããŠã次ã®æãããªçµè«ãåŒãåºãããšãã§ããŸãã
- ãã¹ãŠã®ãµãŒããŒãªãœãŒã¹ãç¹ã«ååž°DNSãµãŒããŒãžã®ã¢ã¯ã»ã¹ãå¶éããå¿ èŠããããŸãã
- DNSãµãŒããŒãšããŒã¿ãã£ãã«ã®è² è·ãåžžã«ç£èŠããå¿ èŠããããŸãã è² è·ã®æ¥æ¿ãªå¢å ã¯ãDDoSæ»æãšãµãŒããŒãããã³ã°ã®äž¡æ¹ã瀺ããŠããå¯èœæ§ããããŸãã
- DNSSECã䜿çšããå Žåãçä¿¡èŠæ±ã®æ°ãåççã«å¶éããå¿ èŠããããŸãïŒã¬ãŒãå¶éïŒã
- WANã€ã³ã¿ãŒãã§ã€ã¹ãä»ããDNSãžã®ã¢ã¯ã»ã¹ã«ã€ããŠã¯ãCPEã確èªããŠãã ããã
- ãããã€ããŒãã€ã³ã¿ãŒãããããååž°DNSãµãŒããŒã¯ã©ã€ã¢ã³ããžã®ã¢ã¯ã»ã¹ãå¶éããããšã¯çã«ããªã£ãŠããŸãã
æåã¯1é±éã§ãã¹ããå®äºããäºå®ã§ãããããã¹ãã®æçµæ¥ã®è² è·ã®å€§å¹ ãªå¢å ïŒ2ãã20 QPSïŒãèæ ®ããŠãç 究ãããã«1é±é延é·ããããšã«ããŸããã
ãœãŒã¹ã®ãªã¹ãïŒ
ïŒcïŒãŽã¡ãã£ã ãããã