å³ã¯ãDNSã²ã€ã³æ»æã¹ããŒã ã瀺ããŠããŸã
éå»æ°å¹Žéã§ãåæ£åãµãŒãã¹æåŠïŒDDoSïŒæ»æã¯ãæ¯èŒçåçŽãªïŒæŽªæ°ŽïŒæ»æããããªãè€éã§å€æ®µéã®æ»æãžãšé²åããŸããã ãµãŒããŒãéè² è·ã«ããããã«å€§éã®ãã©ãã£ãã¯ãéä¿¡ããåŸæ¥ã®é«ã¬ãã«ã®æ»æã«å ããŠãããžãã¹ãæšçåæ»æã«çŽé¢ããŠããŸãã 倧éã®ããŒã¿ãåŠçããã¢ããªã±ãŒã·ã§ã³ã察象ãšããæ¯èŒçå°éã®ãã©ãã£ãã¯ã䜿çšããŸãã ããã«ããããã®æ»æã¯ãåŸæ¥ã®DDoSä¿è·ãœãªã¥ãŒã·ã§ã³ã§ã¯æ€åºãããŸããã
ãžã¥ãããŒãããã¯ãŒã¯ã¹ã®DDoS Secureã¯ãDDoSæ»æãæ€åºããŠæéããããã®è¡åã¢ãããŒãã䜿çšããŠãã€ã³ã¿ãŒããããµãŒãã¹ã®å®å šã«èªååãããDDoSä¿è·ãæäŸããŸãã ãã®ãœãªã¥ãŒã·ã§ã³ã¯ãã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã§ã®ãäœéããªã©ã®é«åºŠãªæ»æã ãã§ãªããé«ã¬ãã«ã®æ»æã«å¯Ÿããä¿è·ãæäŸããŸãã å ¥åãªã¹ã¯ãšå¿çãé¢é£ä»ããããšã«ãããDDoS Secureã¯çœ²åããŒã¹ã®é²åŸ¡ã·ã¹ãã ããã€ãã¹ããããã«èšèšããããç®ã«èŠããªããæ»æãæ€åºã§ããŸãã ãã®ãœãªã¥ãŒã·ã§ã³ã®è©³çŽ°ã«ã€ããŠ
æåã«DDoSã«ã€ããŠ
æåã®åæ£åDDoSæ»æã¯2000幎ã«çºçããAmazonãeBayãããã³ãã®ä»ã®é»ååååŒãµã€ããæšçã«ããŸããã ããŒã«ãšããŠãå€ãã®PCããã®ããããããã䜿çšããŠèšå€§ãªæ°ã®ãªã¯ãšã¹ããçæããeã³ããŒã¹ããŒã¿ã«ã«ãµãŒãã¹ãæäŸãããµãŒããŒãããŒãããããããŠãŒã¶ãŒãªã¯ãšã¹ããåŠçã§ããªããªããŸããã æ»æã«ããç·è¢«å®³é¡ã¯çŽ17åãã«ãšæšå®ãããŠããŸãã
ãã以æ¥ãDDoSæ»æã¯éåžžã«é²åããŠããŸããããã©ãã£ãã¯ã®å€ãæ»æã䜿çšããŠWebãµãŒããŒãéè² è·ã«ããããªããã£ãããŒã«ãããæŠç¥çãªããžãã¹ãªãœãŒã¹ã«åœ±é¿ãäžããããã«èšèšãããè€éã§è€éãªã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®æ»æãŸã§ã§ãã 2012幎ã«ã¯ãéèè©æ¬ºãç®çãšããŠãéè¡æ¥çã«å¯ŸããŠäžé£ã®ããããæ»æãè¡ãããŸããã æè²ããã³é»ååååŒã»ã¯ã¿ãŒããµã€ããŒç¯çœªè ã®æšçã«ãããŠããŸãã
ã€ã³ã¿ãŒããããšãœãŒã·ã£ã«ãããã¯ãŒã¯ã¯ããŠãŒã¶ãŒã«å¯ŸããŠäœ¿çšã§ããæ å ±ã®æŠåšãäœããŸããã ã€ãŸãããµã€ããŒç¯çœªè ã¯ãå€ãã®äœã³ã¹ãããããããããäœè»éã€ãªã³ãã£ãã³ïŒLOICïŒãªã©ã®ããªãŒãœãããŠã§ã¢ã«ã¢ã¯ã»ã¹ã§ããŸããããããã¯äœ¿ãããããã»ãšãã©ã®äŒæ¥ã®ã¢ããªã±ãŒã·ã§ã³ã€ã³ãã©ã¹ãã©ã¯ãã£ãæå·ããå¯èœæ§ããããŸãã
DDoSæ»æã®1æéã®ã³ã¹ãã¯çŽ5ãã«ãç¶ç¶çãªDDoSæ»æã®é±ã¯çŽ260ãã«ãæã¯ããã900ãã«ã§ããïŒå³1ãåç §ïŒã
å³ 1ïŒDDoSæ»æã®ã³ã¹ã
DDoSã䜿çšããæ¹æ³ãšåæ©ãé²åããŠããŸãã ã¢ãããã¹ãªã©ã®ããã¯ãã£ãã¹ããã®ã°ã«ãŒãã¯ã瀟äŒçæè°ãçµç¹çãªç¯çœªè¡çºã«ãã®ã¿ã€ãã®æ»æãããé »ç¹ã«äœ¿çšãå§ããç¹å®ã®Webãµã€ããWebãµãŒãã¹ãžã®æ»æã«ããééçæ害ãåŒãèµ·ãããŸããã ããã«ãDDoSæ»æã¯ãã€ã³ã¿ãŒããããéèŠãªåœ¹å²ãæããçµç¹ã«å¯Ÿããé«åºŠãªãã€ããªããæ»æã§å€§ããªåœ¹å²ãæãããŸãã ãã€ããªããæ»æã§ã¯ãITããŒã ãšæ å ±ã»ãã¥ãªãã£ã¹ãã·ã£ãªã¹ãã®ããŒã ãæ··ä¹±ãããããè匱ãªã»ãã¥ãªãã£ã¹ãããããå¹æçã«æ³šæããããããã«ãDDoSæè¡ã䜿çšããŸãã
æŠè¡ã ãã§ãªããDDoSæ»æã®åæ©ãéå»æ°å¹Žã§ããç°ãªããããã¯ãã£ããºã ãããå§ãŸããééçæŸåãè©æ¬ºããããŠæ¿æ²»çåæ©ã«ããæ»æã瀟äŒçæè°æ»æã§çµãããŸããã äžéšã®å°é家ã¯ãDDoSæ»æã¯ãåžæ°çäžæåŸã®åã®äžã§åéãããããšããè¿°ã¹ãŠããŸãã
2013幎ã¯ãDDoSæ»æãæ°ããã¬ãã«ã«éããããã«å€ãã®ã¡ãã£ã¢ãžã®åç §ã«ã€ãªãã£ãããšã瀺ããŸããã å€ãã®äŒæ¥ã¯ãèªç€Ÿã®Webãµã€ããšã¢ããªã±ãŒã·ã§ã³ã€ã³ãã©ã¹ãã©ã¯ãã£ããµã€ããŒæ»æããé©åã«ä¿è·ãããŠãããšèãç¶ããŠããŸãããDDoSæ»æã®ããè€éãªæ§é ã«å¯Ÿããä¿è·ããã§ã«æºåããŠããäŒæ¥ããããŸãã ç¬ç«ãã調æ»ã«ãããšãITãããã§ãã·ã§ãã«ã®64ïŒ ïŒ10幎以äžã®çµéšïŒã¯ããµã€ããŒæ»æã®åšåãé«ãŸã£ãŠãããšçããé©åãªå¯Ÿçãè¬ããããšãã§ãããšçããã®ã¯25ïŒ ã ãã§ããã DDoSä¿è·ãæ¢ã«å®è£ ããŠããITææ決å®è ã¯ããã22ïŒ ã§ãã
DDoSè åšã®çµ¶ãéãªãå€åããç¶æ³
ãšã¹ã«ã¬ãŒãããã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®DDoSæ»æ
ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®DDoSæ»æã¯ãä»æ¥ã®æãäžè¬çã§ç Žå£çãªãµã€ããŒè åšã®1ã€ã§ãã 倧éã®ãã©ãã£ãã¯ã䌎ãåçŽãªDDoSæ»æã¯äŸç¶ãšããŠåé¡ãåŒãèµ·ãããŸãããç°¡åã«çºèŠã§ããŸãã é©åãªé²è¡çµç¹ãããã°ããããã®æ»æã®ãªã¹ã¯ã¯ãŒãã«ãªããŸãã ãã ãããäœéããšã³ãŒãåãä»ããããæ°ããã¿ã€ãã®ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®DDoSã¯ãæ€åºãšåçºãã¯ããã«å°é£ã§ãããããã¯ããžãã¹ã«å¯Ÿããçã®è åšã§ãã
2012幎ã«ã¯ãã¬ã€ã€ãŒ7ãªã©ã®DDoSæ»æãæ¥å¢ããŸããããããã®æ»æã¯ããã©ãã£ãã¯ãæ£åœãªãã®ãšããŠè»¢éãããããç®ç«ã¡ãŸããã ã¬ã€ã€ãŒ7ãŸãã¯ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®æ»æã¯ãæ£é¢æ»æã䜿çšããŠç®çã®çµæãéæããããããã¢ããªã±ãŒã·ã§ã³ã³ãŒãèªäœã®è匱æ§ãæšçã«ããå¯èœæ§ãé«ããªããŸãã ã»ãšãã©ã®ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®æ»æã®ç®æšã¯ãHTTPãHTTPSãDNSãããã³VoIPïŒã»ãã·ã§ã³éå§ãããã³ã«ãŸãã¯SIPïŒã䜿çšããæåãªãœãããŠã§ã¢ã§ãã ãã©ããæ»æãšåæ§ã«ãL7æ»æã«ã¯ãµã€ããŒç¯çœªè ã®ã³ã¹ãã¯ã»ãšãã©å¿ èŠãããŸããã 1å°ã®ã©ããããããã倧ããªWebãµã€ãã麻çºãããŠã1ç§ããã40ã60ã®åäžã®ãªã¯ãšã¹ãïŒPPSãŸãã¯1ç§ãããã®ãã±ããæ°ïŒãéä¿¡ããããšãã§ããŸãã åæã«ããã©ããæ»æã¯æ°çŸãŸãã¯æ°åã®PPSããæ°çŸäžã«éä¿¡ãããŸãã å€éšã®åæ³æ§ã¯ãL7æ»æãåºç¯ã«æ€åºãããããã¯ããããšãéåžžã«å°é£ã«ãããã®ã§ãã
å³ 2. DDoSæ»æã®åçŽãªãã®ããè€éãªãã®ãžã®é²å
ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®æ»æã¯ããããã¯ãŒã¯ãããŒã®åçãšãããå€æ¹åŒã䜿çšããæ€åºæè¡ã®åŒ±ç¹ãå©çšãããããã»ãã¥ãªãã£ã·ã¹ãã ã«ãã£ãŠæ€åºãããªãå ŽåããããŸãã RUDYïŒRU-Dead-YetïŒãšSlow Lorisã¯ãHTTPãããã³ã«ãæšçãšãã2ã€ã®ã¿ã€ãã®ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®æ»æã§ãã æ»æè ã¯å¯ŸåŠãå°é£ãªå€ãã®ã¯ãšãªãå®è¡ããããšããã¢ããªã±ãŒã·ã§ã³ã®ãªãœãŒã¹ã䜿ãæãããããã«Webãµã€ãã麻çºãããŸãã
å°ãåã«ãããã«ãŒã¯DNSã²ã€ã³ïŒãªãã¬ã¯ã·ã§ã³ïŒæ»æã䜿ãå§ããŸããã ãã®æ¬è³ªã¯ãããã«ãŒãè匱ãªDNSãµãŒããŒã«çããªã¯ãšã¹ããéä¿¡ããéåžžã«å€§ããªãã±ããã§å¿çãããšããäºå®ã«ãããŸãã èŠæ±ãéä¿¡ãããšãã«éä¿¡å IPã¢ãã¬ã¹ãšããŠè¢«å®³è ã®ã³ã³ãã¥ãŒã¿ãŒã®ã¢ãã¬ã¹ïŒIPã¹ããŒãã£ã³ã°ïŒã䜿çšãããšãè匱ãªDNSãµãŒããŒã¯ããã®æäœãå®å šã«éº»çºããããŸã§è¢«å®³è ã®ã³ã³ãã¥ãŒã¿ãŒã«å€§éã®äžèŠãªãã±ãããéä¿¡ããŸãã
DNSãµãŒããŒã¯ãéåžžéåžžã«å€§ããããããŒããã³ãã€ã³ã¿ãŒããããã£ãã«ã§åäœããããã»ã©ç°¡åã«ã¯ãã©ãã¯ãªã¹ãã«ç»é²ã§ããªããããé åçãªç²ç©ã§ãã
ããã«ãŒã¯ãå®å ã¢ãã¬ã¹ãã¹ããŒãã£ã³ã°ããDNSãµãŒããŒã«å°ããªã¯ãšãªãéä¿¡ããããšã§DNSã䜿çšããŸããDNSãµãŒããŒã¯ããããã®èª€ã£ãã¯ãšãªã«å€§éã®ãã©ãã£ãã¯ã®10ã1000åã§å¿çãã倧éã®ãã©ãã£ãã¯æ³¢ã§è¢«å®³è ãæ»æããŸãã åå¥ã«èããã°ããããã®DNSã¯ãšãªã¯æ£åœã§ãããå¿çããŒã¿ãåæ§ã§ãã ããããã«ã¢ãã©ãŒãžã¥ã«ãã£ãŠãæ»æè ã¯å¿åã®ãŸãŸã§ãäžè¬ã«ã¢ã¯ã»ã¹å¯èœãªDNSã管çããŠãæ»æãæéããæ»æåãé«ããããšãã§ããŸãã
2013幎ã«ãã®ãããªæ»ææ¹æ³ã䜿çšããŠãå°æ°ã®ç¯çœªè ã°ã«ãŒããå²äžæ倧ã®DDoSæ»æãçæãã300 Gbit / sã®ç¶ç¶çãªãã©ãã£ãã¯ãããŒã«å°éããããšãã§ããŸããã ããã«ãŒã¯ãã€ã³ã¿ãŒãããäžã§ã¹ãããŒã®ãã©ãã¯ãªã¹ããå ¬éããçµç¹ã§ããspamhaus.comãæ»æããŸããã
DNSæ»æã®å¥ã®åœ¢åŒã¯ãæè¿ã«ãªãã©ã«ãã¢å€§åŠãµã¯ã©ã¡ã³ãã§çŽ1,800件ã®ã¬ã³ãŒããçãŸãããšãã«çºçããã»ãã¥ãªãã£äŸµå®³ã«ã€ãªããå¯èœæ§ããããŸãã ããã«ãŒã¯å€§åŠã®DNSãµãŒããŒãã¯ã©ãã¯ããããšãã§ããŸããã ãããã倧åŠã ããå±éºã«ãããããŠããããã§ã¯ãããŸããã ã²ãŒã ãéèãå°å£²ãªã³ã©ã€ã³æ¥çããã®ãããªæ»æã«å¯ŸããŠè匱ã§ãã DNSã²ã€ã³æ»æã®æ§é ãå³2ã«ç€ºããŸã 3ã
DNSæ¡åŒµæ»æïŒNirlog.comããïŒ
å³ 3. DNSã²ã€ã³æ»æã®æ§é
æ°ãæ£ãDDoSæ»æã¯ãã¯ããã«æœãã§ããã¿ã€ãã®ãã«ããã¯ãã«æ»æã§ããã倧èŠæš¡ãªDDoSãæŠè¡çææ³ãšããŠäœ¿çšããŠITæ åœè ã®æ³šæããããããµã€ããŒç¯çœªè ãããŒã¿ãè³éãçã¿ãŸãã éè¡ãéèæ©é¢ã¯ããã®ã¿ã€ãã®æ»æãæãé »ç¹ã«çµéšããŸãã äžè¬çãªäŸãšããŠã¯ã2012幎12æã«Bank of the West4ã§çºçãããµã€ããŒæ»æããããŸããITããŒã ãäŒæã«ãªãããšãç¥ã£ãŠãããã«ãŒã¯ã¿ãŒã²ããã®æéãšã³ã³ããã¹ããæ£ããéžæããŸããã ãŸããéè¡ã¯DDoSæ»æãåããéè¡ã®åŸæ¥å¡ãšITã¹ã¿ããã¯ãµãŒããŒãžã®åŒ·åãªãã©ãã£ãã¯ãããŒãåæ¢ãããªã³ã©ã€ã³ãµãŒãã¹ã®å®å®æ§ãç¶æããããšããŸãããããµã€ããŒç¯çœªè ã¯$ 900,000ãçã¿ãŸããã
Bitcoin6ãªã³ã©ã€ã³é貚ã«å¯Ÿããæè¿ã®æ³šææ£æŒ«ãªDDoSæ»æã¯ãDDoSã®æ¬è³ªãåžžã«å€åããŠããããšã瀺ããŠããŸãã ãã®å Žåããµã€ããŒç¯çœªè ã¯DDoSæ»æãç å¹ãšããŠäœ¿çšããŠããããã³ã€ã³ã®DNSã¬ã³ãŒãã«å¯Ÿããæ»æãå®è£ ããŸããã ããã«ãŒã¯ããããã³ã€ã³ãªã³ã©ã€ã³ãã£ãããã©ãŒã©ã ã®çŸåšã®DNSã¬ã³ãŒãã«ç°ãªãIPã¢ãã¬ã¹ãäœæããããšãã§ããŸããã ãããã®æªæã®ãããã·ã³ã¢ãã¬ã¹ãéåžžã®æ¥åžžã®DNSã¡ã«ããºã ã«æ¿å ¥ããããšã«ãããããã«ãŒã¯ãŠãŒã¶ãŒãã©ãã£ãã¯ãæ»æè ã«å±ãããµãŒããŒã«ééçã«ãªãã€ã¬ã¯ãããŸãã ãŠãŒã¶ãŒããããã³ã°ããããã·ã³ã§ã¢ã«ãŠã³ãã«ãã°ã€ã³ãããšããã«ãããã«ãŒã¯èªåã®ã¢ã«ãŠã³ãåãšãã¹ã¯ãŒããæžãçããåŸã§ãã®ãŠãŒã¶ãŒã®ãŠã©ã¬ããã空ã«ããããã«äœ¿çšã§ããŸãã
BitcoinãŠãŒã¶ãŒã«å¯Ÿãããã¹ã¯ãŒããçãæ»æã¯æ€åºã§ããŸããããããã¯ãDNSã¬ã³ãŒããå€æŽãããŠããéã«ã¢ã¯ã»ã·ããªãã£ã䟵害ããDDoSæ»æã䜿çšããŠäœæããããç å¹ãã«ãã£ãŠé²æ¢ãããŸããã
ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®æ»æã¯ããªã³ã©ã€ã³ã¹ãã¢ã®ãªã³ã©ã€ã³ãã³ãã³ã°ã«ãŸããŸãåããããŠããŸãã ãããã®æ»æã¯æå·åãããïŒHTTPS / SSLïŒãã©ãã£ãã¯ã«é ãããŠããããšãå€ããåŸæ¥ã®ãœãªã¥ãŒã·ã§ã³ã«ã¯èŠããŸããã äžäŸãšããŠããã®ãããªæ»æã¯ãWebãµãŒããŒã®ã«ãŒããžã®è¿œå æ©èœã«ãã£ãŠéå§ãããã¢ããªã±ãŒã·ã§ã³ãåŠçã§ãããããå€ãã®ãã©ãã£ãã¯ãçæãããµã€ããéè² è·ã«ãããªã³ã©ã€ã³ã§è³Œå ¥ããããšããŠãããšã³ããŠãŒã¶ãŒã«å¯ŸããŠãšã©ãŒã¡ãã»ãŒãžãçæããŸãã ãããã®æ»æã¯ãæ£åœãªãã©ãã£ãã¯ãã£ãã«ã䜿çšããŠWebãµãŒããŒããã³ã¢ããªã±ãŒã·ã§ã³ã«äŸµå ¥ãããããæé ãã«ãªããŸã§æ€åºãããŸããã
ãŒããã€æ»æã¯ãããŒã¿ã倧éã«éä¿¡ããã®ã§ã¯ãªããWebã¢ããªã±ãŒã·ã§ã³ã§çºèŠãããææ°ã®è匱æ§ãæšçãšããDDoSã¡ã¬ãã¬ã³ãã§ãã ä»æ¥ãèšå€§ãªæ°ã®Webã¢ããªã±ãŒã·ã§ã³ãã¢ãã€ã«ããã€ã¹ã§å®è¡ãããŠããŸãïŒBYODãã¬ã³ããæãåºããŠãã ããïŒãããã«ãããäŒæ¥ã¯ãŒããã€DDoSæ»æã®å€§ããªãªã¹ã¯ã«ãããããŠããŸãã
ããžãã¹ãžã®åœ±é¿
çŸåšãITããã³æ å ±ã»ãã¥ãªãã£ã®å°é家ã®å€§å€æ°ã¯ããµã€ããŒæ»æã®ããžãã¹ãªã¹ã¯ãèªèããŠããŸãã åæã«ããããã¯é©åã«æºåãããŠããŸããã æšå¹Ž2æã«å®æœãããPonemon Instituteã®èª¿æ»7ã«ããã°ãITãããã§ãã·ã§ãã«ã®60ïŒ ãã¢ã³ã±ãŒãã§ãDDoSæ»æã¯äŒæ¥ãçµéšããæãæ·±å»ãªã¿ã€ãã®æ»æã§ãããšåçããŸããã DDoSæ»æã«ããæ害ã¯ãèŠæš¡ã«é¢ä¿ãªããããžãã¹ã«å€§ããªåœ±é¿ãäžããå¯èœæ§ããããŸãã
äŒæ¥ãã€ã³ã¿ãŒãããã§ã®ååšæãé«ããæ»æãå®è¡ã§ãããæåç·ããæ¡å€§ããã«ã€ããŠãDDoSæ»æã«ããWebãµãŒããŒãŸãã¯ã¢ããªã±ãŒã·ã§ã³ã®ããŠã³ã¿ã€ã ã¯çã®è åšã§ãã äŒæ¥ã¯ãWebãµãŒããŒãšã¢ããªã±ãŒã·ã§ã³ã®ç¶ç¶çãªå¯çšæ§ã«äŸåããŠãããããæ°æéã®ããŠã³ã¿ã€ã ãçœå®³ã«ã€ãªããå¯èœæ§ããããŸãã 24x7x365ã¢ãŒãã§äžæããããšãªããWebãµãŒãã¹ã®åäœãä¿èšŒããå¿ èŠããããŸãã ã¢ããªã±ãŒã·ã§ã³ã®å®å®æ§ã¯ããããã®ããžãã¹ã«ãšã£ãŠéèŠãªèŠä»¶ã§ãã
ããŠã³ã¿ã€ã ã¯ãæ倱ã«ã€ãªããã顧客ãæããããã ãã§ãªãããã©ã³ã䟡å€ãšè©å€ã«ãæªåœ±é¿ãåãŒããŸãã éèãµãŒãã¹æ¥çã§ã¯ããµã€ããŒç¯çœªè ã¯æ©å¯ããŒã¿ã®çé£ãšéèè©æ¬ºãå©çšããŠããŸãã æè²ãšå¥åº·ã®åéã§ã¯ãäž»ãªé¢å¿ã¯ãåŠçæ å ±ãé»åå»çèšé²ãããã³æ©å¯æ§ã®é«ãæ©å¯ããŒã¿ã®çé£ã§ããããã¯ãçé£ããã人ã ã«å€§ããªèšŽèšãšæ²æšãªçµæãããããå¯èœæ§ããããŸãã èªç©ºåžã®ãŠã§ããµã€ãããªã³ã©ã€ã³ã¹ãã¢ã®éå¶ã«å€±æãããšãå©çã®æžå°ãšè©å€ã®äœäžã«ã€ãªãããŸãã DDoSæ»æã«ç¶ããŠãå埩ãå°é£ãªçµæžçæ倱ãçºçããå¯èœæ§ããããŸãã
ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®DDoSæ»æã®çµ±èšæ å ±ã¯é©ãã¹ããã®ã§ãã ã¬ãŒãããŒã¯ããã¹ãŠã®è åšã®70ïŒ ãWebã¢ããªã±ãŒã·ã§ã³ã®ã¬ãã«ãæšçã«ããŠãããšæšå®ããŠããŸãã Ponemon Instituteã®èª¿æ»ã§ã¯ãDDoSæ»æã«ãã幎éå¹³å被害é¡ã¯350äžãã«ãšæšå®ãããŠããŸããå¥ã®æè¿ã®Forresterã®èª¿æ»ã§ã¯ãDDoSæ»æã«ãã4æéã®ããŠã³ã¿ã€ã ããšã«210äžãã«ã24æéã®ããŠã³ã¿ã€ã ã§2,700äžãã«ã®å¹³å財åã³ã¹ããèŠç©ããããŠããŸãã ã Forresterã¯ããã¹ãŠã®æ¥çã§ã®æ»æã®é »åºŠã¯æã«çŽ1åã§ããã®ã«å¯Ÿããéèæ¥çã§ã¯ãããé±ã«1åçºçããããšã瀺ããŠããŸãã æ»æãããçµç¹ã«ãã£ãŠæäŸãããå ¬éæ害æšå®å€ã«åºã¥ããŠãéèäŒç€Ÿã¯2012幎ã«ã€ã³ã·ãã³ãããšã«çŽ1700äžãã«ã®æ倱ã被ããŸããããããŠãéèæ©é¢ã¯ã»ãšãã©ã®å Žåæ»æããŸãããForresterã®èª¿æ»ã«ãããšãæ¿åºæ©é¢ã¯å¹³åããŠãããé·ãæ»æã®å¯Ÿè±¡ãšãªããŸãã ããã¯ãéèæ©é¢ããµã€ããŒæ»æã«å¯Ÿããä¿è·ã匷åããåŸåãããããã§ãã
ãããã®åä»ãªçµ±èšã«ããããããã25ïŒ æªæºã®äŒæ¥ãDDoSä¿è·ãœãªã¥ãŒã·ã§ã³ãå®è£ ããŠããŸã...
å°çšã®ããŒã«ã«DDoSãœãªã¥ãŒã·ã§ã³ã®å¿ èŠæ§
ã¬ãã«3ããã³4ã§ã®éªåŽ©æ»æã®åé¿ã¯ãåŸæ¥ããªã¿ãŒã³ãã©ãã£ãã¯ãæ€æ»ãããœãªã¥ãŒã·ã§ã³ã䜿çšããŠã¯ã©ãŠãã§å®è¡ãããŠããŸããã åºããã£ãã«ãå¿ èŠãšãããããã®æ»æã¯ããµãŒãã¹ãããã€ããŒã«ãã£ãŠç°¡åã«æ€åºãããæéãããŸãã å®éã顧客ã¯åé¡ã«æ°ä»ããªãããšãããããŸãã ãã ããäž»ã«ã»ãã¥ãªãã£äžã®çç±ãããããŒã¿ããã©ã€ããŒããããã¯ãŒã¯ãé¢ããããšãã§ããªãç°å¢ãæ°å€ããããŸãã ãŸããäœã¬ãã«ããã³äœéã®ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®æ»æã¯ã¯ã©ãŠãã«åæ ã§ããŸããããããã®æ»æã¯éåžžã倧éã®ãã©ãã£ãã¯ãæ¶è²»ãããæ£åœãªãã©ãã£ãã¯ã«é ãããŠããããã§ãã
ãããã®æ»æãåæ ããã«ã¯ãäŒæ¥ã®ããŒã¿ã»ã³ã¿ãŒã«åå¥ã®ããŒã«ã«ãœãªã¥ãŒã·ã§ã³ãå¿ èŠã§ãã å€ãã®çç±ãããå°çšã®DDoSãœãªã¥ãŒã·ã§ã³ãå¿ èŠã§ãã
â¢ãã¡ã€ã¢ãŠã©ãŒã«ãNGãã¡ã€ã¢ãŠã©ãŒã«ãããã³åå¥ã®äŸµå ¥é²æ¢ã·ã¹ãã ãå«ãå¢çä¿è·ã·ã¹ãã ã¯ãDDoSæ»æã«å¯Ÿããä¿è·ã«ã¯ããŸãé©ããŠããŸãããååã«èšç·Žãããæ»æã¯ãæ¥ç¶ã¹ããŒã¿ã¹ããŒãã«ãããã«å§åãããã¡ã€ã¢ãŠã©ãŒã«ãŸãã¯IPSã麻çºããããããã¯ãŒã¯å šäœãå±éºã«ãããå¯èœæ§ãããããã§ãã
â¢ãã¡ã€ã¢ãŠã©ãŒã«ãšIPSã·ã¹ãã èªäœããä¿è·ããå¿ èŠãšããããã§ã€ã«ãªãŒããŒãæ»æã®ã¿ãŒã²ããã«ãªãå¯èœæ§ããããŸãã
â¢ãã¡ã€ã¢ãŠã©ãŒã«ããã³IPSã·ã¹ãã ã¯ãã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã§ããé«åºŠãªæ»æã«èããããšãã§ããŸããããããã®ãœãªã¥ãŒã·ã§ã³ã¯ããããã®æ»æäžã«äœ¿çšããããããã³ã«ãå®å šã«ã¹ãããããããã«èšèšãããŠããããã§ãã ã»ãšãã©ã®ã·ã¹ãã ã¯WebãµãŒãã¹ãšéä¿¡ããããã«ãã®ã¢ã¯ã»ã¹ãå¿ èŠãšããããããã¹ãŠã®ããã«ãŒã¯ãã¡ã€ã¢ãŠã©ãŒã«ãéåžžHTTPããã³HTTPSãã©ãã£ãã¯ãééãããããšãç¥ã£ãŠããŸãã
åŸæ¥ã®DDoSæ»æã®å¶é
DDoSæ»æãæ€åºããããã®åŸæ¥ã®ãœãªã¥ãŒã·ã§ã³ã¯æ©èœãå¶éãããŠãããã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®å±æ§ãäŒéãããææ°ã®ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®æ»æãæ€åºãããšãã«å€§ããªã®ã£ãããæ®ããããã¯ãŒã¯ãããŒïŒnetflowïŒãªã©ã®ãããã¯ãŒã¯ãã¬ã¡ããªã®ã¿ãå¶åŸ¡ã§ããŸãã ããã«ãããããã¹ãŠã®ãœãªã¥ãŒã·ã§ã³ã¯ãã·ã°ããã£ããŒã¹ã®æ€åºãšããªã³ãã¬ãã¹ãã¢ãŒãã§ã®æ»æã®åæ ãæäŸããŸãããããã¯æªç¥ã®ãŒããã€æ»æã«å¯ŸããŠå¹æçã§ã¯ãããŸããã ããã«ããã®ãããªãœãªã¥ãŒã·ã§ã³ã¯ãã·ã°ããã£ã®è åšããŒã¿ããŒã¹ã«åºã¥ããŠçä¿¡ãã©ãã£ãã¯ã®ã¿ãè©äŸ¡ããæªæã®ãããã©ãã£ãã¯ãééããã»ãã¥ãªãã£ã®è匱æ§ãæ®ããŸãã 1ã€ã®äŸã¯ãDNSã²ã€ã³æ»æã§ãã
ããã«ãåŸæ¥ã®ãœãªã¥ãŒã·ã§ã³ã§ã¯ãæ£åœãªãã©ãã£ãã¯ãšçæããããã·ã³ïŒæªæã®ããïŒãã©ãã£ãã¯ãåºå¥ã§ããŸããã ãããã£ãŠãã·ã¹ãã ãæåã§æ§æããŠããã©ãã£ãã¯ããããã¯ããå¿ èŠãããé«/äž/äœãããå€ã決å®ããå¿ èŠããããŸãã ãã®ã¢ãããŒãã¯ãäœã誀æ€ç¥ãããå€ãšç©æ¥µçãªé²åŸ¡ãšã®éã®åŠ¥åã«ã€ãªãããŸãã
ãããå€ã®èšå®ãé«ããããšã誀æ€ç¥å¿çã®åé¡ãçºçãã倧éã®åæ³ãã©ãã£ãã¯ããããã¯ãããŸãã ãããå€ãéå°è©äŸ¡ããããšãæœåšçã«æªæã®ãããã©ãã£ãã¯ãèš±å¯ããããããã³ã°ã«ã€ãªãããŸãã ã¬ã€ã€ãŒ7ã¬ãã«ã®ã»ãã¥ãªãã£ããŒã«ããªããä¿è·ããããªãœãŒã¹ã®ç£èŠãå®è£ ã§ããªããããåŸæ¥ã®DDoSãœãªã¥ãŒã·ã§ã³ã¯ãã·ã°ããã£å¢çã®å€åŽã§å®è¡ãããçŸä»£ã®æ»æã«å¯ŸããŠç¡å¹ã«ãªããŸãã éçãããå€ãä¿è·èŠä»¶ãæºãããŠããŸããã ãŸããäžé£ã®çœ²åã®ãµããŒããšãããå€ã®æå調æŽã«é¢é£ãã管çäžã®åé¡ããããŸãã
èŠããã«ãææ°ã®DDoSæ»æã«å¯Ÿããå®å šãªä¿è·ãæäŸããã«ã¯ãããŒã¿ã»ã³ã¿ãŒã®åšèŸºã«ããŒã«ã«ã«é 眮ãããäœé 延ã®å¥ã®ãœãªã¥ãŒã·ã§ã³ãå¿ èŠã§ãããã®ãœãªã¥ãŒã·ã§ã³ã¯ãã¬ã€ã€ãŒ7ããå¯çšæ§ãä¿èšŒããããã«å¿ èŠãªãããã¯ãŒã¯ãªãœãŒã¹ãŸã§ãåã¢ããªã±ãŒã·ã§ã³ã®ããã©ãŒãã³ã¹ãè©äŸ¡ããçä¿¡ãã©ãã£ãã¯ãšçºä¿¡ãã©ãã£ãã¯ã®äž¡æ¹ãç£èŠããŸããããã¯ãæ£åœãªãã©ãã£ãã¯ãšæªæã®ãããã©ãã£ãã¯ãåºå¥ããæ¢ç¥ããã³æªç¥ã®æ»æãé²ãã誀æ€ç¥ãæå°éã«æããããã®æãå¹æçãªã¢ãããŒãã§ãããã®å Žåãä¿¡å·ãããå€ãæåã§èšå®ããå¿ èŠãããããŸãããããã¯åžžã«å¿ èŠã§ããããäžå®ã®åäœè² è·ãäœæãããã©ãã£ãã¯ãã¿ãŒã³ã®å®éã®å€æŽãšæ¯èŒããŠåžžã«é ããŸãããã®é©æ°çãªãã¥ãŒãªã¹ãã£ãã¯ã¢ãããŒãã«ã€ããŠã¯ã以äžã§è©³ãã説æããŸãã
ãžã¥ãããŒDDoSã»ãã¥ã¢-ããžãã¹ã¯ãªãã£ã«ã«ãªã¢ããªã±ãŒã·ã§ã³ã«å¯ŸããDDoSæ»æããã®ä¿è·
ãžã¥ãããŒãããã¯ãŒã¯ã¹ã¯DDoSã»ãã¥ã¢ãœãªã¥ãŒã·ã§ã³ããªãªãŒã¹ããŸããããã®ãœãªã¥ãŒã·ã§ã³ã¯ãããã«ãã¹ããã«åæ ŒããDDoSæ»æã®æ€åºãšæéã§é«ãçµæã瀺ããŸãããçŸåšãŸã§ã«ããã®è£œåã¯ãã¡ãã£ã¢ããªã³ã©ã€ã³å°å£²ããªã³ã©ã€ã³ã²ãŒã ãéèãæè²ãããã³æ¿åºã§åãäŒæ¥ã«çŽ600åãã«çžåœã®æ害ãåé¿ããã®ã«åœ¹ç«ã¡ãŸããã
åŸæ¥ã®ãœãªã¥ãŒã·ã§ã³ãšã¯å¯Ÿç §çã«ãDDoS Secureã¯é眲åæè¡ã䜿çšããŠãã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®æ»æãæ€åºããã³æéããŸãããã®ããã°ã©ã ã¯ãããŒã¿ã»ã³ã¿ãŒã®å¢çäžã®ãã¹ãŠã®çä¿¡ããã³çºä¿¡ãã©ãã£ãã¯ãæ€æ»ããåçä¿¡ã¯ã©ã€ã¢ã³ãèŠæ±ã§ã¢ããªã±ãŒã·ã§ã³ã®ããã©ãŒãã³ã¹ãç£èŠããŸãããããå€æ¹åŒãŸãã¯æ»æãæéããèšå®ã䜿çšããåã«ãDDoS Secureã¯ç¹å¥ãªã¢ã«ãŽãªãºã CHARMã䜿çšããŠãåæ¹åãã©ãã£ãã¯ã«é¢é£ãããªã¢ã«ã¿ã€ã ãªã¹ã¯ãå®éåããŸãã補åã¯ãã¿ãŒã²ããã¢ããªã±ãŒã·ã§ã³ãæ»æãåãããšãã«ã¿ãŒã²ããã¢ããªã±ãŒã·ã§ã³ã®ãªãœãŒã¹ãåæããŸããã¢ããªã±ãŒã·ã§ã³ãæ»æããããšãã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ããããã«å¿ èŠãªCHARMãããå€ãäžãããæãå±éºãªãã©ãã£ãã¯ããããã¯ãããŸããã€ã³ããŠã³ããªã¹ã¯ãšã¢ãŠãããŠã³ãã¬ã¹ãã³ã¹ãé¢é£ä»ããããšã«ãããDDoS Secureã¯ç®ã«èŠããªãæ»æãæ€åºã§ããŸããéåžžãåŸæ¥ã®DDoS眲åä¿è·ãœãªã¥ãŒã·ã§ã³ããã€ãã¹ããŸãã
é©æ°çãªDDoSã»ãã¥ã¢ã¢ãŒããã¯ãã£ã¯ãããã£ãŒãããã¯ãããã»ã¹ã䜿çšããŠãçä¿¡ãã±ããã®ãã«ãµã€ã¯ã«ãšãªã¯ãšã¹ã¿ãŒã«éãè¿ãããå¿çãåæããŸãã
DDoS Secureã¯èªå·±åŠç¿åã§ããããããå€ãèšå®ãŸãã¯æ±ºå®ããå¿ èŠã¯ãããŸãããã¢ããªã±ãŒã·ã§ã³ã®å¿çæ¹æ³ãç£èŠããåæ»æãåæããŸãããã®é©æ°çãªãã¥ãŒãªã¹ãã£ãã¯ã¢ãããŒãã«ããããã¯ãããžã¯ãã¢ããªã±ãŒã·ã§ã³ããã®éåžžã®ãã©ãã£ãã¯ãšéåžžã®å¿çã®å€èŠ³ã決å®ã§ããŸããæ°ããæ»æãçºçãããšãDDoS Secureã¯ã¢ã«ãŽãªãºã ãæŽæ°ããŠæ°ããæ»æã®ç¹æ§ãå«ããåçæŽæ°ãå«ãé«åºŠã«ã€ã³ããªãžã§ã³ããªDDoSé²åŸ¡ã·ã¹ãã ãäœæããŸãã DNSã²ã€ã³æ»æãçºçããå ŽåãDDoS Secureã¯ãDNSãµãŒããŒã麻çºãããåã«æ»æãæéããããã«ãDNSãªãœãŒã¹ã«å¯ŸããŠã€ã³ããªãžã§ã³ããªã¢ãããŒããåããŸããç¹å¥ãªDDoSã»ãã¥ã¢ãã£ã«ã¿ãŒã¯ãåãæ å ±ã«ã€ããŠå®æçã«ç¹°ãè¿ãããDNSã·ã¹ãã ã¯ãšãªãé€å€ããŸããããã«ãããDNSã²ã€ã³æ»æãé²ããæ»æè ã®ã¿ãŒã²ããããå¯çšæ§ã«åœ±é¿ããæªæã®ããã¯ãšãªããä¿ââè·ããŸãã
åºæ¬çã«ãã·ã¹ãã ã¯å®éã®ãŠãŒã¶ãŒãã©ãã£ãã¯ãšãã·ã³çæãã©ãã£ãã¯ãåºå¥ããŸãããã®ã¢ãããŒãã¯ãæ£åœãªãã©ãã£ãã¯ã®ééãä¿èšŒããæ»æãåŒãèµ·ããåã«æ»æããããã¯ããŸããããã¯ãã¯ãªã¹ãã¹äŒæãªã©ããµãŒããŒã«é«è² è·ãããã£ãŠããæéãã€ãŸãã誀æ€ç¥ã«ãããµãŒããŒãžã®ã¢ã¯ã»ã¹ã®äžæãå©çã®æžå°ã«ã€ãªããå¯èœæ§ããããšãã«éèŠã§ããä»æ¥ã®å€ãã®ãµã€ããŒç¯çœªè ã¯ããããã®æ°ããæŽç·ŽãããDDoSæ»æãšåŸæ¥ã®éªåŽ©æ»æãçµã¿åãããŠããŸããåæã«ãDDoS Secureã¯äž¡æ¹ã®ã¿ã€ãã®æ»æãæ€åºããã³é²æ¢ã§ããŸãã
DDoS Secureã¯ã1Uã®ç©çããã€ã¹ãŸãã¯ä»®æ³ãã·ã³ãšããŠã€ã³ã¹ããŒã«ã§ããŸãããã®ãœãªã¥ãŒã·ã§ã³ã¯ãäºåå®çŸ©ããããããå€ã䜿çšããã®ã§ã¯ãªãããªã¹ã¯è©äŸ¡ã®ããã«çä¿¡æ å ±ãšçºä¿¡æ å ±ãçžé¢ãããããã誀æ€ç¥ãå¶éããã管çãç°¡åãã€å®¹æã«å±éãããŸããããã«ãBGPçµ±åã«ããããœãªã¥ãŒã·ã§ã³ã¯ã¯ã©ãŠãããŒã¹ã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãšé£æºããŠã倧èŠæš¡ãªéªåŽ©æ»æã«å¯ŸåŠã§ããŸãã
å³4ïŒã¢ã³ãDDoSãœãªã¥ãŒã·ã§ã³ã®æ°ããããã³ãã£ã¢ã¯ãäŒæ¥ãããã¯ãŒã¯ã®ã»ãã¥ãªãã£ã€ã³ãã©ã¹ãã©ã¯ãã£ããã³åæã¢ãžã¥ãŒã«ãšçµ±åããã
Arbor Networks Pravail APSãšæ¯èŒããŠããžã¥ãããŒDDoSã»ãã¥ã¢æ»æãèå¥ããã³ãããã¯ããŸã
補åã®æ©èœ
| ãžã¥ãããŒDDoSã»ãã¥ã¢
| Arbor Networks Pravail APS 1
|
æ»ææ€åºããã³ãªãã¬ã¯ã·ã§ã³ãã¯ãããžãŒ
| ||
é眲åæ¹åŒ
| ã¯ã
| ãã
|
:
| ã¯ã
| ãã
|
« »,
| ã¯ã
| ãã
|
:
| ã¯ã
| ãã
|
| ã¯ã
| ãã
|
: ( )
| ã¯ã
| ãã
|
| ||
DNS
| ã¯ã
| ãã
|
HTTPS (SSL v3 TLS v1 & v2)
| ã¯ã
| ã¯ã
|
HTTP, VoIP/SIP
| ã¯ã
| ã¯ã
|
| ||
:
| ã¯ã
| ( )
|
, 160 /
| ã¯ã
| ãã
|
, DDoS,
| ã¯ã
| ãã
|
,
| ||
| ã¯ã
| ã¯ã
|
SIEM-
| ã¯ã
| ãã
|
,
| ||
DDoS Secure
| ã¯ã
| ãã
|
, (« »)
| ã¯ã
| ãã
|
,
| ã¯ã
| ãã
|
10-
| ã¯ã
| ãã
|
80% 10 ; 99,999% 6
| ã¯ã
| ãã
|
Juniper Networks , , , , , , , .
Juniper Networks
MUK-Service-ããããçš®é¡ã®ITä¿®çïŒä¿èšŒãéä¿èšŒä¿®çãã¹ãã¢ããŒãã®è²©å£²ãå¥çŽãµãŒãã¹