誰ã«å¯ŸããŠãååž°DNSãµãŒããŒãéããšããç§ã®å®éšã¯éåžžã«æåãããããã²ãŒã ã®ã«ãŒã«ãç·æ¥ã«å€æŽããå¿ èŠããããŸããã ååž°DNSãå®å šã«éãã代ããã«ãRPZïŒå¿çããªã·ãŒãŸãŒã³ïŒã¡ã«ããºã ã䜿çšããŠãæ»æãã¡ã€ã³ã§æã人æ°ã®ãããã¡ã€ã³ãžã®ã¢ã¯ã»ã¹ãå¶éããããšã«ããŸããã
RPZã¯ãã€ã³ãDNSãµãŒããŒã®æ©èœã§ãããé©åã«äœ¿çšããããšã§æ¬¡ã®åé¡ã解決ã§ããŸãã
- ã³ã³ãããŒã«ã»ã³ã¿ãŒïŒCïŒCïŒãšã®ããããããããã³ãã«ãŠã§ã¢éä¿¡ããããã¯ããŸãã
- ãã£ãã·ã³ã°DNSããã³éä¿¡ãã£ãã«ã®è² è·ã軜æžããŸãã
- ãçŠæ¢ããµã€ãã®ãªã¹ããžã®ã¢ã¯ã»ã¹ããããã¯ããŸãïŒäŒæ¥ãšãããã€ããŒã®äž¡æ¹ïŒã
- ãŠãŒã¶ãŒãããŒã«ã«ãªãœãŒã¹ã«ãªãã€ã¬ã¯ãããŸãã
ãããããããšãã«ãŠã§ã¢ã®éä¿¡ããããã¯ãã
å€ãã®ããããããããã³ãã«ãŠã§ã¢ã¯ã管çã»ã³ã¿ãŒïŒCïŒCïŒãšéä¿¡ããããã«DNSã䜿çšããŸããããã«ããããããããããèå¥ããŠå¯ŸåŠããããã»ã¹ãè€éã«ãªããŸãã ãã®ãããªæè¡ã®äŸã¯ãFastFluxïŒ2006幎11æ以æ¥ç¥ãããŠããïŒããã³DGAïŒãã¡ã€ã³çæã¢ã«ãŽãªãºã ïŒã§ãã
FastFlux-CïŒCãšã®éä¿¡ã«ã¯ãé »ç¹ã«å€æŽãããå€æ°ã®Aã¬ã³ãŒãïŒTTL-5åïŒãæã€ãã¡ã€ã³ã䜿çšãããŸãã ããè€éãªå®è£ ã§ã¯ããããã®ãšã³ããªã¯ããããã·ãšããŠæ©èœããææ/ãããã³ã°ããããµãŒããŒããã³ã³ã³ãã¥ãŒã¿ãŒãæãå ŽåããããŸãã IPãä»ãããã®ãããªãã«ãŠã§ã¢ã®éä¿¡ããããã¯ããããšã¯ããã®æ°ãå€ãé »ç¹ã«å€æŽãããããäžå¯èœã§ãã BredoLabã¯ãFastFluxãã¯ãããžãŒã䜿çšããæåãªããããããã®1ã€ã§ãã BredoLabã䜿çšãããŸãããä»ã®ãã«ãŠã§ã¢ïŒZbotå¥åZeusãSpyEyeãTDSSãHareBotãBlakkenå¥åBlack Energy 2ïŒãã³ã³ãã¥ãŒã¿ãŒã«ææãããã¹ãã ãéä¿¡ããŠæ»æãè¡ãããã«äœ¿çšãããŸããã BredoLabã®è©³çŽ°ã«ã€ããŠã¯ã ãã¡ããã芧ãã ãã ã |
DGAãã¯ãããžãŒã䜿çšããŠããã«ãŠã§ã¢ã¯ç¹å®ã®ã«ãŒã«ã«åŸã£ãŠå€æ°ïŒæ倧5äžïŒã®ãã¡ã€ã³ãçæããŸãããã®äžéšã¯æ¯æ¥ãã§ãã¯ãããCïŒCãšéä¿¡ããããã«æ¯æ¥äœ¿çšãããŸãã
Cryptolocker-ãããŸã§ã§æãæåãªã©ã³ãµã ãŠã§ã¢ããã°ã©ã ã®1ã€-ãã®ã¢ã«ãŽãªãºã ã䜿çšããŸããã ã³ã³ãã¥ãŒã¿ãŒãææããåŸãCryptolockerã¯CïŒCãžã®æ¥ç¶ãè©Šã¿ãæ¥ç¶ã«æåãããšãæå·åã«äœ¿çšãããå ¬éããŒãããŠã³ããŒãããŸããã lcxgidtthdjje.orgãkdavymybmdrew.bizãdhlfdoukwrhjc.co.ukãxodeaxjmnxvpv.ruã¯ãCryptolockerã䜿çšãããã¡ã€ã³ã®äŸã§ãã ãããã®è åšãé²ãããã«ãRPZã䜿çšããŠãCïŒCãšã®ãã«ãŠã§ã¢éä¿¡ããããã¯ã§ããŸãã ãã®ãããªè åšããä¿è·ããããã®RPZãŸãŒã³ã¯ãæåã§ïŒå°çšã®ãã©ãŒã©ã ãããã°ãWebãµã€ãã®ããŒã¿ã䜿çšããŠïŒç¶æãããããµãã¹ã¯ãªãã·ã§ã³ãµãŒãã¹ã䜿çšã§ããŸãã |
- SpamHaus-ãµãã¹ã¯ãªãã·ã§ã³ã®ã³ã¹ãã¯ãçµç¹ã®ã¿ã€ããšãŠãŒã¶ãŒæ°ã«ãã£ãŠç°ãªããŸãã
- Surbl-ãµãã¹ã¯ãªãã·ã§ã³ã®ã³ã¹ãã¯ãçµç¹ã®ã¿ã€ããšãŠãŒã¶ãŒæ°ã«ãã£ãŠç°ãªããŸãã
- InternetIdentity-ã³ã¹ãã¯æ確ã§ã¯ãããŸããã
- ThreatStop-ãã©ã³ãåDNS Firewallã§Infobloxã販売ãããµãã¹ã¯ãªãã·ã§ã³ã ã³ã¹ãã¯ããã€ã¹ã®ã¢ãã«ã«ãã£ãŠç°ãªããŸãã 9æ18æ¥ã«ãInfobloxã¯ãã®ãããã¯ã«é¢ãããã·ã¢èªã®ãŠã§ãããŒãéå¬ããŸã ã ããã§ç»é²ã§ããŸã ã
ãã£ãã·ã³ã°DNSããã³éä¿¡ãã£ãã«ã®è² è·ã軜æžãã
ãããããããšãŒãžã§ã³ãã®ã¢ã¯ãã£ããã£ã¯ããã£ãã·ã³ã°DNSããã³éä¿¡ãã£ãã«ã®è² è·ãå€§å¹ ã«å¢å ãããå¯èœæ§ããããŸãã ãã¹ãŠã®ãæ£ããã管çè ã¯ããã£ãã·ã³ã°DNSãµãŒããŒãžã®ã¢ã¯ã»ã¹ãå¶éãããã®ãã©ãã£ãã¯ã¯èš±å¯ãããã¯ã©ã€ã¢ã³ãããæ¥ãŸãã DNSãµãŒããŒã®ã¹ããªã¢ã¹è² è·ã¯ãäžå®ã®å Žåãšå®æçãªå ŽåããããŸãã
äžèšã®å³ã§ã¯ã2æéã§ãè² è·ã¯æšæºã®1ç§ããã15,000ãªã¯ãšã¹ããã43,000ãªã¯ãšã¹ãã«å¢å ããŸããã æ»æã§ã¯ãå¢å¹ ã䜿çšããããµãŒããŒã®å¿çïŒ4KïŒã¯èŠæ±ã60åè¶ ããŸããã ãããã£ãŠã1ç§ããã28,000ãªã¯ãšã¹ãã®è¿œå è² è·ã«ããã875 Mb / sã®çºä¿¡ãã©ãã£ãã¯ãçæãããŸããã
ãããã¯ãŒã¯ã®1ã€/ã¢ã¹ã¯ã¯ã®é»æ°éä¿¡äºæ¥è ïŒç§ãæ¥ç¶ããŠããïŒã®16ãã¹ãã£ã³ããŸããã å€æ¹ã«ã¯ãDNSã¯ãšãªã«å¿çããã€ã³ã¿ãŒãããããã¢ã¯ã»ã¹å¯èœãª69å°ã®ããã€ã¹ãèŠã€ãããŸããã ç§ã®ïŒãã©ã¡ãŒã¿ãŒã®å¹³åïŒLinksys EA3200ã«ãŒã¿ãŒã¯ãæ¯ç§1000ãªã¯ãšã¹ãïŒ4Kbãã±ãããµã€ãºïŒããæ¯ç§3500ãªã¯ãšã¹ãïŒå°ãããã±ãããµã€ãºïŒãŸã§åŠçã§ããŸãã ã€ãŸã ã 0.5Mb / sã®çä¿¡ãã©ãã£ãã¯ã§31Mb / sã®çºä¿¡ãã©ãã£ãã¯ãçæããŸãã ã€ãŸãã 69å°ã®æ€åºãããããã€ã¹ã2 Gb / sã®ã¹ããªãŒã ãçæã ããªãã¬ãŒã¿ãŒã®ãããã¯ãŒã¯ã«å€§å¹ ã«è² è·ããããããšãã§ããŸãã
ç§ã®ãªãŒãã³ååž°DNSïŒåã®èšäºãåç § ïŒäžã®ãã¹ãŠã®åœãã©ãã£ãã¯ã¯ãwebpanel.skãenergystar.govãããã³doleta.govã®3ã€ã®ãã¡ã€ã³ã®ã¿ã«ãã£ãŠçæãããŸããã
ãããã®ãã¡ã€ã³ãRPZã§ãããã¯ããããšã§ïŒçãã«NODATAã䜿çšããŸããïŒãèŠæ±ã®ãµã€ãºããµãŒããŒã®å¿çã®ãµã€ãºãšã»ãŒäžèŽããããããããã¯ãŒã¯ã®è² è·ãæžããããšãã§ããŸããã æ»æãè¡ãããšã¯ç¡æå³ã«ãªããŸããã
çŠæ¢ãµã€ãã®ãªã¹ããžã®ã¢ã¯ã»ã¹ããããã¯ãã
çŠæ¢ãµã€ãã®ãªã¹ããéããŠãã¡ã€ã³ãžã®ã¢ã¯ã»ã¹ããããã¯ããããšã¯ãäŒæ¥ãšã€ã³ã¿ãŒããããããã€ããŒã®äž¡æ¹ã«ãšã£ãŠäŸ¿å©ã§ãã äŒæ¥å ã®ã¢ã¯ã»ã¹ãå¶éãããŠããããããã¹ãŠãç°¡åã§ãããå®è£ ã«åé¡ã¯ãããŸããã ãããªãã¯DNSãžã®ãŠãŒã¶ãŒã¢ã¯ã»ã¹ããããã¯ããå¿ èŠãããããšãå¿ããªãã§ãã ããã
ãã¹ãŠã®äººãDPIãä»ããŠãã©ãã£ãã¯ãæž¡ãããšãã§ããããã§ã¯ãªãããããããã€ããŒã¯RPZã䜿çšããŠFZãå®è¡ã§ããŸãããŸããIPã«ããã¢ã¯ã»ã¹ã®ãããã¯ã«ã¯é¡§å®¢ãã€ã€ã«ãã£ã倱ãããŸãã ãã®å Žåãå¶éã¯æ¬¡ã®ããã«å®è£ ãããŸãã
- çŠæ¢ãµã€ãã®ã¬ãžã¹ããªã¯2ã€ã®ã°ã«ãŒãã«åããããŸãã
- ãã¡ã€ã³å šäœã«èª²ãããå¶éã
- ãµã€ãã®ç¹å®ã®ã»ã¯ã·ã§ã³ã«èª²ãããå¶éã
- ãã¡ã€ã³å šäœã®ãããã¯ã«è©²åœãããµã€ãã¯ãPRZãŸãŒã³ã«ç»é²ãããŠããŸãã
- æ®ãã®ãµã€ããžã®ã«ãŒãã£ã³ã°ã¯ããã±ãããDPIãŸãã¯ãããã·ãµãŒããŒãééããããã«èŠå®ãããŠããŸãã æåŸã®æ段ãšããŠãIPãä»ããŠããããã³ã°ãå®è¡ããããšãã§ããŸãã
ãŠãŒã¶ãŒãããŒã«ã«ãªãœãŒã¹ã«ãªãã€ã¬ã¯ããã
ãªãœãŒã¹ïŒNXDOMAINãNODATAãDROPïŒãžã®ã¢ã¯ã»ã¹ãåã«ãããã¯ããããšã«å ããŠãDNSãµãŒããŒã®å¿çãå€æŽã§ããŸãã ãã®ãããªåçã®å€æŽãå¿ èŠã«ãªãå ŽåããããŸããäŸïŒ
- èªåã®ã³ã³ãã¥ãŒã¿ãŒããã«ãŠã§ã¢ããããããããšãŒãžã§ã³ãã«ææããŠããããšããŸãã¯ãã«ãŠã§ã¢ãé åžãããµã€ãã«ã¢ã¯ã»ã¹ãããšãã«ãŠãŒã¶ãŒã«èŠåããããã ããã«ããããã€ããŒã¯ãŠã€ã«ã¹å¯Ÿçåºåã衚瀺ã§ãããšã³ã¿ãŒãã©ã€ãºç®¡çè ã¯ITãµãŒãã¹ã®é»è©±çªå·ãšé»åã¡ãŒã«ãæå®ã§ããŸãã
- ãã®ãªãœãŒã¹ããããã¯ãããŠããããšããŠãŒã¶ãŒã«èŠåããŸãã ãããã€ããŒã¯ãããã¯ã®çç±ã瀺ãããšãã§ãïŒé£éŠæ³ïŒãäŒæ¥ãŠãŒã¶ãŒã®å Žåã¯ããããã¯ããããã¡ã€ã³ã®ãªã¹ããšèªåã®èªç±æå¿ã®ãµã³ãã«ã¢ããªã±ãŒã·ã§ã³ã衚瀺ã§ããŸãïŒåæããªãå ŽåïŒã
- ãµãŒããŒã®ããŒã«ã«ãªãœãŒã¹ãŸãã¯ããŒã«ã«ïŒã°ã¬ãŒïŒIPã¢ãã¬ã¹ãžã®ãŠãŒã¶ãŒã®ãªãã€ã¬ã¯ãïŒ ãã® habr-articleã«äŸã瀺ããŸãïŒã
BIND 9.10ã§ã®RPZã®æ§æ
RPZãå¹æçã«äœ¿çšããã«ã¯ããã¹ãŠã®DNSã¯ãšãªãDNSã«ã®ã¿éä¿¡ãããå¿ èŠããããŸãã ããã¯ã次ã®2ã€ã®æ¹æ³ã§å®çŸã§ããŸãã
- ä»ã®DNSãžã®ã¢ã¯ã»ã¹ããããã¯ããŸãã
- RPZãæå¹ã«ããŠãã¹ãŠã®DNSã¯ãšãªãèªåçã«ãªãã€ã¬ã¯ãããŸãã
1.æåã«ãå¿çããªã·ãŒåŒã䜿çšããŠRZPãŸãŒã³ãšãã®ãã©ã¡ãŒã¿ãŒã®ãªã¹ããå®çŸ©ããå¿ èŠããããŸãã
response-policy {zone "whitelist" policy passthru; zone "badlist" policy disabled;};
ãã€ã³ãã¯ãresponce-policyã§å®çŸ©ããããŸãŒã³é åºã«åŸã£ãŠãRPZã®èŠæ±ããã§ãã¯ããŸãã æãéèŠãªã®ã¯è¿œå ã®ããªã·ãŒãã©ã¡ãŒã¿ã§ããããã«ããããŸãŒã³ã¬ãã«ã§æå®ãããèŠæ±ãåŠçããããã®ã«ãŒã«ãäžæžãã§ããŸãã ãã®ãã©ã¡ãŒã¿ãŒã¯ã次ã®å€ãåãããšãã§ããŸãã
- given-ãŸãŒã³ã§å®çŸ©ãããã¢ã¯ã·ã§ã³ãå®è¡ãããŸãïŒããã©ã«ãå€ïŒã
- ç¡å¹-ãŸãŒã³ã¯ç¡å¹ã§ãã
- passthru-DNSãµãŒããŒã®å¿çã¯å€æŽãããŸãããããŸãŒã³ã«å ¥ãããšã¯ãã°ãã¡ã€ã«ã«åæ ãããŸãã
- drop-ãµãŒããŒã¯èŠæ±ãç¡èŠããŸãïŒå¿çããŸããïŒã
- nxdomain-ãµãŒããŒã¯NXDOMAINïŒååšããªããã¡ã€ã³ïŒã§å¿çããŸãã
- nodata-ãµãŒããŒã¯NODATAïŒã¬ã³ãŒããªãïŒã§å¿çããŸãã
- tcp-only-åãæšãŠãããã¡ãã»ãŒãžãéä¿¡ãããŸããããã«ãããã¯ã©ã€ã¢ã³ãã¯TCPçµç±ã§èŠæ±ã匷å¶çã«å®è¡ããŸãïŒDrDoSã«å¯Ÿããä¿è·ïŒã
- cname domain-name-ãµãŒããŒã¯ãæå®ããããã¡ã€ã³ãžã®ãã¹ãŠã®å¿çãäžæžãããŸãã
2.次ã«ãæšæºåœ¢åŒã䜿çšããŠãŸãŒã³ã®ãªã¹ããå®çŸ©ããŸãã ããŒã«ã«ãŸãŒã³ã®å Žåã¯masterãšå ¥åããRPZãã£ãŒãã®å Žåã¯slaveãšå ¥åããŸãã
zone "badlist" {type master; file "master/badlist"; allow-query {none;}; };
3.ãŸãŒã³ãå®çŸ©ããŸãïŒããã¹ãã®åœ¢åŒã«é¢ããã³ã¡ã³ãïŒ
$TTL 1H @ SOA LOCALHOST. named-mgr.example.com (1 1h 15m 30d 2h) NS LOCALHOST. ; QNAME policy records. There are no periods (.) after the owner names. nxdomain.domain.com CNAME . ; (.) - NXDOMAIN *.nxdomain.domain.com CNAME . ; (.) - NXDOMAIN nodata.domain.com CNAME *. ; (*.) - NODATA *.nodata.domain.com CNAME *. ; (*.) - NODATA bad.domain.com A 10.0.0.1 ; AAAA 2001:2::1 bzone.domain.com CNAME garden.example.com. ok.domain.com CNAME rpz-passthru. ; ; x.bzone.domain.com x.bzone.domain.com.garden.example.com *.bzone.domain.com CNAME *.garden.example.com. ; IP 8.0.0.0.127.rpz-ip CNAME . 32.1.0.0.127.rpz-ip CNAME rpz-passthru. ; IP ns.domain.com.rpz-nsdname CNAME . 48.zz.2.2001.rpz-nsip CNAME . ; IP 112.zz.2001.rpz-client-ip CNAME rpz-drop. 8.0.0.0.127.rpz-client-ip CNAME rpz-drop. ; TCP 16.0.0.1.10.rpz-client-ip CNAME rpz-tcp-only. example.com CNAME rpz-tcp-only. *.example.com CNAME rpz-tcp-only.
RZPã¯ããããã¯ãŒã¯ã»ãã¥ãªãã£ã匷åãããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãå¶éããããã®äŸ¿å©ãªã¡ã«ããºã ã§ã ã
ãœãŒã¹ã®ãªã¹ã
- dnsrpz.info
- www.spamhaus.org/faq/section/ISP%2520Spam%2520Issues#164
- www.infosecurity.ru/cgi-bin/mart/arts.pl?a=101219
- www.bleepingcomputer.com/virus-removal/cryptolocker-ransomware-information
- www.infoblox.com/products/infrastructure-security/dns-firewall
- ftp.isc.org/isc/bind9/cur/9.10/doc/arm/Bv9ARM.ch06.html
- www.zytrax.com/books/dns/ch7/rpz.html
- www.zytrax.com/books/dns/ch9/rpz.html
ãŽã¡ãã£ã ã»ãããã
UPD1ïŒ
Infobloxã¯ãããã·ãDNSãã¡ã€ã¢ãŠã©ãŒã«ïŒRPZïŒ+ãã£ãŒããã¹ããæäŸããŸãã
次ã®ãªã³ã¯ã§ç»é²ããã³ã¢ã¯ã»ã¹ã§ããŸãïŒ www.infoblox.com/catchmalware
ã€ã³ã¹ããŒã«ã«ã¯ãVmWareããŒãžã§ã³5.0以éããã³vCenter Serverãå¿ èŠã§ãã