ããŸããŸãªäŒæ¥ã«ãã£ãŠçºè¡ãããDDoSæ»æã«å¯Ÿããä¿è·ã«é¢ããããŒã±ãã£ã³ã°è³æã§ã¯ãåãèšç»ã®ãšã©ãŒãç¹°ãè¿ãçºèŠãããŠããŸãã ã€ãŸãã誰ãã®ã¬ããŒãããåããããããšãã°400 Gbit / sã®éã®èšé²ãããæ»æã«é¢ããããŒã¿ã¯ããã¹ãŠãæªããäœããç·æ¥ã«è¡ãå¿ èŠããããšçµè«ä»ããããŸãããåæã«ãæäŸããããµãŒãã¹ã®ç¹æ§ã¯ããã£ã«ã¿ãªã³ã°ãããæ»æã®éã®äžéã瀺ããŸã10 Gb / s㧠ãããŠããã®ãããªççŸã¯é »ç¹ã«çºçããŸãã
ããã¯ããµãŒãã¹èªäœãäœæããå°é家ãããã®ãããªåŒ·åãªæ»æãå®éã«ååšãããšã¯ãŸã£ããä¿¡ããŠããªãããã«çºçããŸãã ãããã®å°é家èªèº«ãã圌ããç¥ã£ãŠãã誰ããã®ãããªæ»æã«çŽé¢ããªãã£ãããã§ãã ãããã£ãŠãeã³ããŒã¹ã«é¢é£ãã質åãçºçããŸããçŸåšã©ã®è åšãå®éã«é¢é£ããŠãããã©ã®è åšã¯ããã§ã¯ãªãã®ã§ããããã ãªã¹ã¯ãè©äŸ¡ããã«ã¯ïŒ ããããã¹ãŠãšãã以äžã®ããšã¯ã Bitrix Summer Festã«ã³ãã¡ã¬ã³ã¹ã§ã®Artyom Gavrichenkovã®ã¬ããŒãã§èª¬æãããŠããŸãã
æ»æã®åé¡
æåã«ãã©ããªçš®é¡ã®æ»æã«ã€ããŠè©±ããŸãããã åé¡ã®åºæºãšããŠãæ»æã®å¯Ÿè±¡ãã€ãŸãããŸã£ããç¡å¹ã«ãªã£ãŠãããã®ãåãäžããŸãã ãã®å ŽåãOSIã¢ãã«ã«åŸã£ãŠããŸããŸãªã¬ãã«ã§å®è¡ããã4ã€ã®äž»èŠãªæ»æã¯ã©ã¹ãåºå¥ã§ããŸãã
æåã®ã¯ã©ã¹ïŒL2ïŒ -ãã£ãã«ã®ãç®è©°ãŸããã ãããã¯ããã£ãã«å®¹éã®æ¯æžã«ããå€éšãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ã奪ãããšãç®çãšããæ»æã§ãã ã©ãã§ãããã§ã ååãšããŠããäœã§ãã-å¢å¹ ã¿ã€ãã®å€§èŠæš¡ãªããã©ãã£ãã¯ã®èŠ³ç¹ãããæ»æããã®ç®çã«äœ¿çšãããŸãïŒNTP-ãDNS-ãRIP- ...å¢å¹ ã¯ä»»æã§ããããªã¹ãããããšã¯æå³ããããŸããïŒã äžè¬ã«ãICMPãã©ãããªã©ããã¹ãŠã®çš®é¡ã®ãã©ããã¯ãã®ã¯ã©ã¹ã®æ»æã«å±ããŸããäž»ãªã¿ã¹ã¯ã¯ãããšãã°1ã®ã¬ããã/ç§ã®ãã£ãã«ã«å°ãªããšã1.1ã®ã¬ããã/ç§ãæºããããšã§ãã ããã§ã¢ã¯ã»ã¹ãçµäºã§ããŸãã
2çªç®ã®ã¯ã©ã¹ïŒL3ïŒã¯ããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã®æ©èœã®éåã§ãã ãã®ã¯ã©ã¹ã«ã¯ããšãããããããã¯ãŒã¯ã¢ããŠã³ã¹ã¡ã³ãïŒãã€ãžã£ãã¯ïŒã䌎ãBGPãããã³ã«ã®ãã¬ãŒã ã¯ãŒã¯å ã§ã«ãŒãã£ã³ã°ã®åé¡ãåŒãèµ·ããæ»æããŸãã¯äžç¶ãããã¯ãŒã¯æ©åšã§åé¡ãåŒãèµ·ããæ»æïŒæ¥ç¶è¿œè·¡ããŒãã«ã®ãªãŒããŒãããŒãªã©ïŒãå«ãŸããŸãã ãã®ã¯ã©ã¹ã®æ»æã¯éåžžã«å€æ§ã§ãã
3çªç®ã®ã¯ã©ã¹ïŒL4ïŒã¯ãTCPã¹ã¿ãã¯ã®åŒ±ç¹ãã€ãŸããã©ã³ã¹ããŒãã¬ãã«ã§ã®æ»æã®æªçšã§ãã HTTPããã³ä»ã®å€ãã®ãããã³ã«ã®åºç€ãšãªããã®ãã©ã³ã¹ããŒããããã³ã«ã¯ãéåžžã«è€éã§ãã ããšãã°ãéããŠããæ¥ç¶ã®å€§ããªããŒãã«ã䜿çšããŸããåããŒãã«ã¯ãå®éã«ã¯ã¹ããŒããã·ã³ã§ãã ãããŠããã®ãã·ã³ã«å¯Ÿããæ»æã¯ãDDoSæ»æã®3çªç®ã®ã¯ã©ã¹ãæ§æããŠããŸãã SYN Floodã¿ã€ãæ»æã¯ãåã®2ã€ã®ã¬ãã«ã§æå·ãåŒãèµ·ãããããµãŒããŒèªäœã«å°éãããã®çµæãTCPã¹ã¿ãã¯ã«å¯Ÿããã¢ããªãªãªæ»æã§ããå Žåã3çªç®ã®ã¯ã©ã¹ã«èµ·å ããå¯èœæ§ããããŸãã ãŸããããã«ã¯ãå€æ°ã®æ¥ç¶ã®ãªãŒãã³ïŒTCPæ¥ç¶ãã©ããïŒãå«ãŸãããããã³ã«ããŒãã«ã®ãªãŒããŒãããŒã«ã€ãªãããŸãã ååãšããŠã3çªç®ã®ã¯ã©ã¹ã«ã¯ã SlowLorisãSlow POSTãªã©ã®ããŒã«ã®äœ¿çšãå«ãŸããŸãã
4幎çïŒL7ïŒ-Webã¢ããªã±ãŒã·ã§ã³ã®å£åã ããã«ã¯ãäžè¬çãªGET / POST / HTTP FloodããããµãŒããŒããªãœãŒã¹ã䜿ãæãããŸã§ããŒã¿ããŒã¹ãã¡ã¢ãªããŸãã¯ãã£ã¹ã¯ããç¹å®ã®æ å ±ãç¹°ãè¿ãæ€çŽ¢ããã³ååŸããããšãç®çãšããæ»æã«è³ããããããçš®é¡ã®ãã«ã¹ã¿ã ãæ»æãå«ãŸããŸãã
æ»æãã®ã¬ãããã§è©äŸ¡ããããšã¯ãäž»ã«æäœã¬ãã«ïŒL2ïŒã§æå³ãããããšã«æ³šæããŠãã ããã ããšãã°ããã¹ãŠã®è£œåã§é«åºŠãªæ€çŽ¢ã䜿çšããMySQLãç¡å¹ã«ããã«ã¯ãå€ãã®ã®ã¬ããããå¿ãå¿ èŠãããŸããã 5000åã®ãããããç©æ¥µçã«æ€çŽ¢ãèŠæ±ããŠããŒãžãæŽæ°ããå Žåã«ãã£ãŠã¯åããã®ïŒè¢«å®³è ã®ãµãŒããŒã®ãã£ãã·ã¥èšå®ã«å¿ããŠïŒãæŽæ°ããã ãã§ååã§ãã ãã®ãããªæ»æã§ã¯ãå€ãã®äººãåé¡ãæ±ããŠããŸãã 50,000åã®ãããã®æ»æäžã«èª°ãããæ²ã¿ããæãå®å®ããã·ã¹ãã ã¯æ倧100,000åã®ãããã®æ»æã«èããŸãã æšå¹Žåææã«ãåææ»æãããã®æ倧ç»é²æ°ã¯419,000ã«éããŸããã
æ»æããã®ä¿è·
äžèšã®åã¬ãã«ã§å¯Ÿæ¯ã§ãããã®ãèŠãŠã¿ãŸãããã
L2 å¥ã®ã¹ã¯ã©ããã«å ããŠãã¹ã¯ã©ããã«å¯Ÿããå容ã¯ãããŸããã æ»æ垯åã100ã®ã¬ããã/ç§ãè¶ ããå Žåããããã®ã®ã¬ãããã¯ãããšãã°ãããã€ããŒãŸãã¯ããŒã¿ã»ã³ã¿ãŒã®åŽãªã©ã®ã©ããã§åŠçããå¿ èŠããããåé¡ã¯åžžã«ãã©ã¹ããã€ã«ãã«ãããŸãã BGP Flow Specãã¯ãããžãŒã䜿çšãããšããã±ããã·ã°ããã£ã«ãã£ãŠæ»æã®äžéšããã£ã«ã¿ãªã³ã°ã§ããŸããããšãã°ããœãŒã¹ããŒãã«ãã£ãŠå¢å¹ ãç°¡åã«é®æã§ããŸãã ãã ãããã®æ¹æ³ã¯éåžžã«é«äŸ¡ã§ããããã¹ãŠã«å¯ŸããŠä¿è·ããããšã¯ã§ããŸããã
L3 L3ã§ã¯ããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã ãã§ãªãããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ãåæããå¿ èŠããããŸãã å žåçãªäŸ-2008幎ãããã¹ã¿ã³ã¯ç¬èªã®èª€ãã«ãããBGPãã€ãžã£ãã¯ã䜿çšããŠYouTubeãã¬ãã£ãã¯ã¹ãååããŸããã ã€ãŸãããã®ãããªãã¹ãã£ã³ã°ã®ãã©ãã£ãã¯ã®å€§éšåã¯ããã¹ã¿ã³ã«ãªãã€ã¬ã¯ããããŸããã æ®å¿µãªããããã®ãããªäžå¹žãèªåçã«åŠçããããšã¯äžå¯èœã§ããããã¹ãŠãæåã§è¡ãå¿ èŠããããŸãã ããããæŠããå§ãŸãåã«ããã®åé¡ïŒãã¬ãã£ãã¯ã¹ã®çé£ïŒãçºçããããšãå€æããå¿ èŠããããŸãã ãããçºçããå Žåã¯ããããã¯ãŒã¯ãªãã¬ãŒã¿ãŒãããŒã¿ã»ã³ã¿ãŒã®ç®¡çè ããã¹ãã£ã³ã°äºæ¥è ãªã©ã«é£çµ¡ããå¿ èŠããããŸãã åé¡ã®è§£æ±ºã«åœ¹ç«ã¡ãŸãã ããããããã«ã¯ãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã®é«åºŠãªåæãå¿ èŠã§ãããªããªãããã€ãžã£ãã¯ã®å åã¯ãäžè¬çãªå Žåãããæç¹ããã€ã³ã¿ãŒãããäžã§ã®ãã®ãããã¯ãŒã¯ã®ã¢ããŠã³ã¹ããéå®åãã§ããã以åãšã¯ç°ãªãããã§ããã®åã«ã ãããã£ãŠãã¿ã€ã ãªãŒã«æ€åºããã«ã¯ãå°ãªããšãã¢ããŠã³ã¹ã®å±¥æŽãå¿ èŠã§ãã
ç¬èªã®èªåŸã·ã¹ãã ïŒASïŒããªãå Žåããã®ã¬ãã«ã§ã®æŠéæ»æã¯ããŒã¿ã»ã³ã¿ãŒïŒãŸãã¯ãããã€ããŒïŒã®çŸ©åã§ãããšèŠãªãããšãã§ããŸãã ãã ããéåžžã1ã€ãŸãã¯å¥ã®ããŒã¿ã»ã³ã¿ãŒããã®åé¡ã«ã©ã®çšåºŠçå£ã«åãçµãã§ããããäºåã«èšãããšã¯ã§ããŸããã
L4 第4ã¬ãã«ã®æ»æããä¿è·ããã«ã¯ãTCPã¯ã©ã€ã¢ã³ãã®åäœããµãŒããŒäžã®TCPãã±ãããããã³ãã¥ãŒãªã¹ãã£ãã¯åæãåæããå¿ èŠããããŸãã
L7 L7ã§ã¯ãè¡åãçžé¢åæãç£èŠãè¡ãå¿ èŠããããŸãã åæãšç£èŠã®ããã®ããŒã«ããªããã°ãåãNginxã䜿çšããŠæ»æãæéããããšã¯äžå¯èœã§ãããæ»æãšã®æŠãã¯ãããã«ããæäœæ¥ã«å€ãããŸãã
ãªã¹ã¯è©äŸ¡
ããã§ãçä¿¡HTTPãªã¯ãšã¹ããã©ãã§åãå ¥ããŠåŠçããŸããã
- è³Œå ¥ãŸãã¯ãªãŒã¹ãããç©çãµãŒããŒ
- ã¯ã©ãŠããã¹ãã£ã³ã°
- CDN
ãªã¹ã¯ãè©äŸ¡ããã«ã¯ãProbabilityïŒImpact Matrixãªã©ã®äŸ¿å©ãªããŒã«ã䜿çšã§ããŸãã
暪軞ã«ã¯ãç¹å®ã®ã€ãã³ãã®çµæã®é倧床ãããããããã瞊軞ã«ã¯ãã®ç¢ºçããããããããŸãã ãã®å Žåã®çœããã¬ãŒã ã¯ãDDoSæ»æã®ãªã¹ã¯ã®çŸåšã®ã¬ãã«ã瀺ããŠããŸãã
æ»æã®ç¢ºçã決å®ãããã®ã¯äœã§ããïŒ ãŸã第äžã«ãæ»æã¯ç«¶äºã®æ段ã§ãã åžå Žã»ã°ã¡ã³ããå€å°èœã¡çããŠããå Žåãã»ãšãã©ã®å Žåãé·æéæ»æã¯ãããŸããã ãããã競äºãæ¿åããå Žåã¯ãä¿è·ã®æºåãããå¿ èŠããããçœããã¬ãŒã ã軞ã«æ²¿ã£ãŠç§»åããå¿ èŠããããŸãã
ããããDDoSæ»æã§ææªãªã®ã¯åœ±é¿ã§ãã æ»æãããªãã®ãã¹ãã£ã³ã°äºæ¥è ã«ãããšããŸãããã çŸæç¹ã§ããªããã¢ã³ãDDoSãœãªã¥ãŒã·ã§ã³ã®ãããã€ããŒã«é Œã£ããšããŠãã圌ãå©ããããšãã§ãããšããäºå®ã§ã¯ãããŸããã åé¡ã¯ãWebãµãŒããŒããããŒã¿ããŒã¹ããã®ä»ã®éèŠãªã³ã³ããŒãã³ããŸã§ãããã¹ãŠãã眮ãããŠããIPã¢ãã¬ã¹ãæ»æè ã«æ¢ã«ç¥ãããŠããããšã§ãã ãŸããDNSã§ä»ã®ã¢ãã¬ã¹ãæå®ããŠããäžå®ã®ç¢ºçã§ããã¯äœã®åœ¹å²ãæããããæ»æã¯çŽæ¥ç¶è¡ãããŸãã æè¯ã®å Žåããã®ãã¹ãã£ã³ã°ãã移åããå¿ èŠããããŸãã ãŸãããã®å Žåãå¶æ¥æéäžã«æºåãæŽã£ãŠããªããµã€ãã«ç§»åãããµãŒããŒã暪ããã£ãŠããããããITãããžã§ã¯ãã«ãšã£ãŠæªãããšãæãä»ãããšãé£ãããããåé¡ã¯ãéåžžã«æ·±å»ããšè©äŸ¡ã§ããŸãã ãŸããããããã ããŒãã³ã®ããã -ã¯ããããã¯ééããªãæªãã§ã:)
åããã¹ãã£ã³ã°ã§IPãå€æŽããã ãã§ã¯äžååãªã®ã¯ãªãã§ããïŒ æ°ããã¢ãã¬ã¹ã¯åãèªåŸã·ã¹ãã ïŒASïŒããã®ãã®ã ããã§ãã ä»æ¥ãæ»æè ã¯ãã§ã«èªåŸã·ã¹ãã ã®ãã¬ãã£ãã¯ã¹ã®ãªã¹ããèŠãããšãã§ããŸãã ãããã£ãŠãæ°ããã¢ãã¬ã¹ã§ããªããèŠã€ããããšã¯é£ãããããŸãã;èªåŸã·ã¹ãã ã®ãã¹ãŠã®ã¢ãã¬ã¹ãæ»æããã®ã«ååã§ãã
ç¹å®ã®ãããã¯ãŒã¯ãªãœãŒã¹ãã1ã€ãŸãã¯å¥ã®ãããã¯ãŒã¯ã¬ãã«ã®æ»æã®åœ±é¿ãåããããçšåºŠãè©äŸ¡ããŠã¿ãŸãããã
ãã¹ãã£ã³ã° ã»ãšãã©ã®ãã¹ãã£ã³ã°äŒç€Ÿã¯ããã©ãã£ãã¯ã100 Gb / sãå€§å¹ ã«è¶ ãã匷åãªæ»æãé€å€ã§ããŸããã ãµãŒããŒãžã®æåŸã®ãã€ã«ãå«ã¿ãŸãã ãããã£ãŠãæ¥ã措氎ã®ãã¹ãŠããŸãã¯ã»ãšãã©ãã¹ãŠãç¬ç«ããŠåŠçããå¿ èŠããããŸãã ãããŠã第7ã¬ãã«ã§ã¯ãããããµãŒããŒã§ããåé¡ã§ãããããåæãèªåã§è¡ãå¿ èŠããããŸãã
L3ã§ã¯ãã»ãšãã©ã®å ŽåããªãœãŒã¹ã®ããã«ãã¹ãã£ã³ã°å šäœãããã¬ãã£ãã¯ã¹ãçãããšã¯ãªããããå±éºæ§ã¯ããã»ã©é«ããããŸããã ããã¯ãæ»æè ã«ãšã£ãŠéåžžã«æéãšè²»çšãããããŸãã ããã¯å®è¡ã§ããŸãããéåžžã«æ£åœãªçç±ãå¿ èŠã§ãã ãã¡ãããç¹ã«ãã¹ãã£ã³ã°ãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ããã©ãŒãã³ã¹ã®åé¡ãããå Žåã¯ããã¹ãŠã®ã©ã€ãã«ãŒã«ã«äŸå€ããããŸãã
éèŠãªç¹ããããŸããå€ãã®ãã³ããŒã¯ãã©ãã¯ã«èšçœ®ããããµãŒããŒã«ã€ãªããã¢ãããªã³ã¯ãšããŠã³ãªã³ã¯ãå«ãé«äŸ¡ãªä¿è·æ©åšãæäŸããŠããŸãã åé¡ã¯æ¬¡ã®ãšããã§ãã䜿çšããŠããæ©åšãå«ãããããã¯ãŒã¯ã¯ã©ã¹ããã€ã«ãããå®å®ããŠããŸããã ãããã«ãããã©ãã·ã¥ã¢ã¯ãŒã®éã«ããã»ããµã®è² è·ã100ïŒ ã«è¿ããªããªãããã«ãããã©ãŒãã³ã¹ã«äœè£ãæãããŠãã ããã ããããªããšãå°ããªãžã£ã³ãã倱æããå¯èœæ§ããããŸãã æ»æè ãçµéšãæµ ããèªåã§å¯ŸåŠã§ããå Žåã¯ããªã¯ãšã¹ãã®èª¿æ»ãã¢ãŠãããŒã³ã®ã¹ã¯ãªããã®äœæãfail2banã®æ§æãªã©ã«å®å šæ§ã®äœè£ãå¿ èŠã§ãã
ãŸããä¿è·ãããŠããªããªãœãŒã¹ã«ç©ççã«é 眮ãããŠããå Žåã¯ãæ倧30ïŒ ã®ç¢ºçã§DNSãå€æŽããŠã圹ã«ç«ããªãããšã«æ³šæããŠãã ããã ããã¯ãæè¿ã®ã¢ã¡ãªã«ã®éèäŒç€Ÿã«å¯Ÿããæ»æã®çµéšãããæããã§ãã ãã®ãããéåžžã«èªä¿¡ãæã£ãŠãã»ãã¥ãªãã£ã§ä¿è·ãããŠããªããã¹ãã£ã³ã°ããè¿ éã«ç§»è¡ããå¿ èŠããããšèšããŸãã
ã¯ã©ãŠã ã ã¯ã©ãŠãã«ã¯ãšããŒãã£ã¹ããããã¯ãŒã¯ãå¿ èŠã§ããã€ãŸããåããã¬ãã£ãã¯ã¹ãäžçäžã®å€ãã®å Žæããã¢ããŠã³ã¹ãããå¿ èŠããããŸãã 1ãæã§ã¯æ°çŸã®ã¬ãããã®æ»æãæ¶åããããšãã§ããã1幎ã§ãã©ãããæ»æãäºæ³ãããããã§ãã åæ£æ§é ã®ããããã£ãã«ã«å¯Ÿããæ»æã®ãªã¹ã¯ã¯å€§å¹ ã«åæžãããŸãã ãããããšããŒãã£ã¹ããããã¯ãŒã¯ã§ããæ¯ç§400ã500ã®ã¬ãããã®æ»æã倧éã«çºçããŸãã ããã«åããå¿ èŠããããŸããã誰ããããããããã§ã¯ãããŸããã
æ»æè ãã€ã³ãã©ã¹ãã©ã¯ãã£ãæªçšã§ããªãããã«ããããã¯ãŒã¯ãåæ£ããå¿ èŠããããŸãã ããŒã¿ããŒã¹ã«ã¢ã¯ã»ã¹ããéã®åé¡ã®æªçšãããªãœãŒã¹ãç¯çŽããããšã¯ã§ããªããããçç£æ§ã®ããŒãžã³ãå¿ èŠã§ãïŒ2åãæãŸããïŒã
ãããŠæåŸã«ãæããé¢çœããããšã¯ãã¯ã©ãŠããå€ãã®ãŠãŒã¶ãŒãã©ãã£ãã¯ãæ¶åã§ããããšã§ãããããã«å¯ŸããŠè²»çšãæ¯æãå¿ èŠããããŸãã éå»1ãæã§ã¢ã«ãŠã³ããæ°äžãã«ã«éãããšãæºåž¯é»è©±ã®åæãéå§ãããããç Žç£ã«ããåçŽã«ãªãã«ãªããŸãã ãã®ãããã¯ã©ãŠãã«ãšã©ãŸãããšã§ãæ»æã«å¯Ÿããä¿è·ã®åé¡ãå®å šã«è§£æ±ºã§ããããã§ã¯ãããŸããã ããã¯ããªããä¿è·ãããåã«å埩åãé«ããã ãã§ãã
Cdn ã CDNã¯å€§éã®ãã©ãã£ãã¯ãåŠçããããã«èšèšãããŠããããããéçãïŒç»åãCSSãªã©ïŒã«ç°¡åã«å¯ŸåŠã§ããŸãã ãã£ãã«å®¹éã䜿çšãããšããã¹ãŠãã¯ã©ãŠããšåãã«ãªããŸãã ããããã€ã³ãã©ã¹ãã©ã¯ãã£ã¬ãã«ã§ã¯ã¯ããã«èå³æ·±ããã®ã§ãã CDNã«ã¯ããã¹ãŠã®ãªãœãŒã¹ãµãŒãã¹ãé¢é£ä»ããããŠããDNSãµãŒããŒãåžžã«ãããŸãã ã¯ã©ãŠãã®å Žåããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ãåçŽãªãšããŒãã£ã¹ãã®èåŸã«é ãããšãã§ããå Žåã99.9ïŒ ã®CDNã§ããŠãŒã¶ãŒãCDNäžã®æãè¿ããã€ã³ãã«ãªãã€ã¬ã¯ãããDNSã«ãŒã¿ãŒã衚瀺ãããŸãã ããã«ãCDNã«ã¯ãAnycastããã³ãã®ãããã¯ãŒã¯ãããã€ã³ããåãåºããããŠãŒã¶ãŒã«è¿ãå€éšãããã¯ãŒã¯ã«é 眮ãããŸãã ãããã£ãŠãããã©ã«ãã§ã¯ä¿è·ãããŸããã ãããã¯åã«ä¿è·ããããšã¯äžå¯èœã§ãã ããã§ã¯ãCDNã®DNSãã©ãã ãå®å šã§ãããããããã¯ãŒã¯ããæ»æãããããŒããç·æ¥ã·ã£ããããŠã³ããæºåãã©ã®çšåºŠã§ãããã«ããã£ãŠããŸãã ããããããã¯äžè¬çã§ã¯ãããŸããã å°åããšã«ãŠãŒã¶ãŒãåæ£ãããDNSãµãŒããŒã¯ãä¿è·ãããå®å®ããèãæãããªããã°ãªããŸããã
äžè¬çãªãããã¯ãŒã¯ã¢ãŒããã¯ãã£ã®ãã³ã
- ãšããŒãã£ã¹ãã¢ãã¬ã¹ã¯éåžžã«äŸ¿å©ã§ãã ãããŠæãéèŠãªããšã¯ããããã¬ã³ã¿ã«ããããšãã§ããŸãã ãšããŒãã£ã¹ãã«ãŒã¿ãŒã䜿çšãããã©ã³ã·ã³ã°ãšåé·æ§ã¯ãDNSãã©ã³ã·ã³ã°ãããã¯ããã«ä¿¡é Œæ§ããããŸãã
- IPv4ãçµäºããŠããããšã«æ³šæããŠãã ãããçŸåšã倧èŠæš¡ãªçµç¹ã®å Žåã¯ããã®ã¢ãã¬ã¹ã¹ããŒã¹ã®æåŸã®éšåãååŸã§ããŸãã å°æ¥çã«ã¯IPv6ã®ã¿ãååŸãããã®ã¹ããŒã¹ã«ã¯å€ãã®ãŠãŒã¶ãŒãããªããããããã䜿çšããå¿ èŠããããŸãã
- ç©çãµãŒããŒããã¢ããªã±ãŒã·ã§ã³ãåãé¢ãããšããå§ãããŸãã ãDockerããšããèšèã¯èšèªãèŠæ±ããŸãããããã§ã¯ç¹å®ã®ãã¯ãããžãŒã«å·çããããããŸããã ã¢ããªã±ãŒã·ã§ã³ãã©ããã§ãã¹ãããå Žåãããã¥ã¡ã³ããã€ã³ã¹ããŒã«ã¹ã¯ãªããã®ã»ãããçšæããå±éãšæ§æãèªååããŸããäžè¬ã«ãåãããŒã¿ããŒã¹ã䜿çšããŠåãã¢ããªã±ãŒã·ã§ã³ãå¥ã®ãµã€ãã®ãµãŒããŒã«å±éããæºåãæŽããŸãã ãªããªããåé¡ã¯ããªãã ãã§ãªããããªããšã¯ç¡é¢ä¿ã«ãããªããåãå ¥ããããŠãã人ã ãããå§ãŸãããã§ãã ããã¯ããªãäžè¬çãªç¶æ³ã§ãã
çŸåšãŸã§ãè åšã®å¹³åã¬ãã«ã¯ãåç¬ã§å¯ŸåŠããããšãéåžžã«å°é£ãªã¬ãã«ã«éããŸããã æ»æè ãæ»æãçµç¹ããããšã¯ã被害è ãé²åŸ¡ãããããã¯ããã«ç°¡åã§ãã ãããŠã2æ¥éäŒç ããåŸãã·ã¹ãã 管çè ã¯çµ¶å¯Ÿã«æ»æè ã«å¯Ÿæã§ããªããªããŸãã ãã®ããã1C-Bitrixã¯ã©ã€ã¢ã³ãåãã®æ°ãããµãŒãã¹ãéå§ããŸããã1幎ã«10æ¥éç¡æã§ãå©çšããã ããŸãã æ»æãåããŠããã®ã§ãã£ãŠãæ»æãåããŠããã®ã§ã¯ãããŸãã-é¢ä¿ãããŸããã åé¡ãçºçããå Žåã¯ããµã€ãã®ã³ã³ãããŒã«ããã«ã«ããææ°ããŒãžã§ã³ã®ã1C-BitrixïŒSite Managementãã«å€§åãªãã¿ã³ããããŸããã¯ãªãã¯ããŠãã ãããæ¥ããããããªãã§ãã ããã