/ Flickr / m1try / CC
æ»æã¿ã€ãã«ã€ããŠ
IaaSãããã€ããŒãšã»ãã¥ãªãã£ã®åé¡
ãã®èšäºã§ã¯ãã¯ã©ãŠããããã€ããŒãããã©ãŒãã³ã¹ãšã¹ã±ãŒã©ããªãã£ã«å¯ŸããéèŠã®é«ãŸãã«çŽé¢ããŠãããããçš®é¡ã®è åšããèªèº«ãšé¡§å®¢ãä¿è·ããæ¹æ³ã«ã€ããŠèª¬æããŸãã
ããžãã¹åãã¯ã©ãŠããµãŒãã¹ãšDDoSä¿è·
ç§ãã¡ã¯ãããåœã®DDoSã«å¯Ÿããä¿è·ã®ç¶æ³ãåæããŸãã ã©ã®çµç¹ããã·ã¢åžå Žã§è£œåãçºè¡šããŠããŸããã
ããžãã¹ã®å±æçãªã»ãã¥ãªãã£åé¡ãšããŠã®DDoS
DDoSæ»æãåããŠã®äººã®ããã«ãPentestitã¯åæ£åãµãŒãã¹æåŠæ»æã«é¢ããç°¡åãªèª¬æãçšæããŸããã
Artrator GavrichenkovãQrator-DDoSæ»æ[ãããªè¬çŸ©]
DDoSæ»æãšã®æŠãã§äžçããªãŒãããäŒæ¥ã®1ã€ã§ããQrator Labsã®CTOã§ããArtem GavrichenkovããDDoSæ»æãšã¯äœãããããã¯äœãããããŠãããã«å¯ŸåŠããæ¹æ³ã説æããŸãã
DDoSãšã¯ïŒMakeUseOfã®èª¬æ
DDoSæ»æã¯äœãããã©ã®ããã«æ©èœããã¿ãŒã²ããã·ã¹ãã ã«ã©ã®ãããªåœ±é¿ãäžããŸããã èè ã¯ãŸããæãäžè¬çãªã¿ã€ãã®æ»æïŒåçä»ãïŒã®ããã€ããåæããŸãã
DDoSãšã¯ïŒIGNã®èª¬æ
DDoSæ»æãšã¯äœã§ããããŸããããã¯ã²ãŒã ãµãŒãã¹ã«ã©ã®ãããªåœ±é¿ãäžããŸããã
DDoSæ»æã®çš®é¡ïŒã€ã³ãã©ã°ã©ãã£ãã¯
GlobalDotsã¹ãã·ã£ãªã¹ãã¯ãDDoSæ»æã®çš®é¡ã«é¢é£ããæãäžè¬çãªè³ªåã1ã€ã®å€§ããªã€ã³ãã©ã°ã©ãã£ãã¯ã«ãŸãšããŸããã
35çš®é¡ã®DDoSæ»æ
DDoSæ»æã®çš®é¡ã®å¥ã®ãªã¹ãã
JSã«å¯ŸããDDoSæ»æã®ä»çµã¿
CloudFlareã®åŸæ¥å¡ã¯ãJavaScript DDoSãã©ã®ããã«æ©èœããã®ãããªããã®çš®ã®æ»æãã€ã³ã¿ãŒãããäžã®äž»èŠãªåé¡ã®1ã€ã§ããã®ãã説æããŸãã
DDoSïŒUDPæ»æã®ä»çµã¿
ããã¯ãæãäžè¬çãªã¿ã€ãã®DDoSæ»æã®1ã€ã§ãã èè ã¯ããããã©ã®ããã«æ©èœãããªãããã«å¯ŸããŠé²åŸ¡ããããšããšãŠãé£ããã®ãã説æããŸãã
DDoSä¿è·æ¹æ³
DDoSæ»æã®çš®é¡ãšä¿è·æ¹æ³ã«ã€ããŠå°ã
調æ»ã«ãããšãDDoSæ»æã®èŠæš¡ã¯éå»æ°å¹Žéã§çŽ50åã«æ¡å€§ããŠããŸãã VAS Expertsã®å°é家ã¯ããã®èšäºã®ããŸããŸãªã¿ã€ãã®DDoSæ»æãããã³ãããã«å¯Ÿããé²åŸ¡æ¹æ³ãæ€èšããŸãã
å±éºãšå®å š-ä»®æ³è»æ¡ç«¶äº
ãã®çŸå®ã®æ¬è³ªã¯ãäžçã«ã¯åžžã«å¯Ÿç«ããããã»ã¹ã競äºãæŠäºããããšããããšã§ãã ãµã€ããŒè»æ¡ç«¶äºã¯é·ãéç¶ããŠããŸãã ãã®èšäºã®èè ã¯ãäžçã§æã泚ç®ãéããŠããDDoSæ»æãããã³çŸä»£äžçã®ã¢ãã®ã€ã³ã¿ãŒãããã®å¯èœæ§ãšå±éºæ§ã«ã€ããŠèªã£ãŠããŸãã
DDoSä¿è·ãµãŒãã¹ãããŽã·ãšãŒãããªããã®ããŸãã¯ä¿è·ãæ©èœããªãçç±
ãã®èšäºã®çç±ã¯ãããã€ã³ã¿ãŒããããããžã§ã¯ãã§ã®ã»ãã¥ãªãã£ç£æ»ã§ããã èè ã¯ã顧客ãã»ãã¥ãªãã£ã·ã¹ãã ã«å¯ŸåŠãããã®ä¿¡é Œæ§ã確èªããããã«äŸé Œãããšãã®ç¶æ³ã«ã€ããŠè©±ããŸãã çµå±ã®ãšããã顧客ã¯å®å šã«ä¿è·ãããŠããŸããã§ããã
ITããžãã¹ã€ã³ãã©ã¹ãã©ã¯ãã£ãä¿è·ããããã®ããŸãç¥ãããŠããªããœãªã¥ãŒã·ã§ã³
ä»æ¥ã®ãã·ã¢ã®ããžãã¹ã®å€å žçãªã¢ãããŒãã¯ããã¡ã€ã¢ãŠã©ãŒã«ãã€ã³ã¹ããŒã«ããæšçåæ»æã®æåã®è©Šã¿ã®åŸãäŸµå ¥é²åŸ¡ã·ã¹ãã ãã€ã³ã¹ããŒã«ããããšã§ãã ãã ããå®éã«ã¯ãå€å°ãªããšãæ·±å»ãªè åšããããããå€å žçãªæ段以äžã®ãã®ãå¿ èŠã§ãã
DNS DDoSãä¹ãåãæ¹æ³
DNSãããã€ããŒã«å¯Ÿãã倧èŠæš¡ãªDDoSæ»æãåããŠããéãäŒæ¥ã¯ã©ã®ããã«æ¥åãç¶ç¶ããŸããïŒ 1ã€ã®éžæè¢ã¯ãè€æ°ã®DNSãããã€ããŒãšé£æºããããšã§ãã
DDoSãåãæ±ããŠ
DNSå¢å¹ æ»æãšNTPå¢å¹ æ»æã«ã€ããŠå€ãã®äººãèããŠããŸãã ããã2çš®é¡ã®UDPæ»æã«ã€ããŠå€ãã®ããšãæžãããŠããŸãã ããããå¢å¹ ã«äœ¿çšã§ããä»ã®ãããã³ã«ã¯äœã§ããïŒ ãã®èšäºã§ã¯ãtftpãããã³ã«ã«ã€ããŠèª¬æããŸãã
DoS / DDoSæ»æãç£èŠããããã®FastNetMon 1.1.2ãªãŒãã³ãœãªã¥ãŒã·ã§ã³ããªãªãŒã¹
ããã°ã©ã å€æŽã®å®å šãªãªã¹ãããµããŒããããŠãããã©ââãããã©ãŒã ãšãã€ããªããã±ãŒãžã®ãªã¹ãïŒããã³èªåã€ã³ã¹ããŒã©ãŒïŒã
1ç§ããã3åãã±ãããçãæ®ãæ¹æ³
DDoS被害軜æžæ©åšã®ç¶æ³ã¯ã©ããªã£ãŠããŸããïŒ
NGINXããã³NGINX Plusã§DDoSæ»æã«æµæããæ¹æ³
2015幎ã®å€ã«ãNGINXãããžã§ã¯ãã®ããã°ã«ãDDoSæ»æã«å¯Ÿæããããã«ãããã©ã®ããã«äœ¿çšã§ãããã«é¢ããè³æãæ²èŒãããŸããã ãã€ã©ã€ãã¯æ¬¡ã®ãšããã§ãã
DDoSæ»æã«å¯Ÿããä¿è·ã®ããã«æ©æ¢°åŠç¿ã䜿çšããæ©èœ
ãã®æçš¿ã¯ãQrator Labsã®Konstantin Ignatovã«ãã1C-BitrixããŒãããŒäŒè°ã§ã®ãã¬ãŒã³ããŒã·ã§ã³ã«åºã¥ããŠããŸãã ããã§ã¯ãDDoSæ»æããµã€ãã§éå§ãããããšã確èªããæ¹æ³ã«é¢ãã次ã®è³ªåã«ã€ããŠèª¬æããŸãã ã»ãã¥ãªãã£ã·ã¹ãã ã¯ãæ»æãããããšãã©ã®ããã«å€æããŸããïŒ ä¿è·ããæ¹æ³ã¯äœã§ããïŒ
Qratorããã€ãã¹ããDDoSæ»æã èªåãå®ãæ¹æ³ã¯ïŒ
DDoSæ»æããç§ãã¡ãä¿è·ãããµãŒãã¹ããããŸãã 圌ãã¯ããããã·ã®ååã«åºã¥ããŠåäœããŸãã IPãé衚瀺ã«ããIPãããã·ãããã¯ã¿ãŒã®ã¿ãæäŸããããšã匷ããå§ãããŸãã é²åŸ¡ãæåãããã®ã«ååãªãå®å šã«å ç¢ãªã¢ãããŒãã ããããèè ã¯ããã§äœã«ç©Žãéããããšãã§ãããããããŠããããèªåãå®ãæ¹æ³ã«ã€ããŠè©±ããŸãã
ãªã©ã¯ã«ãžã®æ»æã Oracle DBã®æ»æãã¯ãã«ã«é¢ãã詳现ãªã¬ã€ã
å€éšããããŒã¹ã®åŒ±ç¹ãæ¢ããå éšã«è¶³ããããç²åŸããæ¹æ³ã ããã«ãç¹æ®ãªãœãããŠã§ã¢ã䜿çšããŠããããã¹ãŠãèªååããæ¹æ³ã
nginxã§DDoSã«å¯Ÿæããããã®CSFãšã®Fail2bançµ±å
CSFããã³Fail2banãœãªã¥ãŒã·ã§ã³ã¯ãiptablesã«ãŒã«ã®åŠçæ¹æ³ãç°ãªããããåããµãŒããŒå ã§çžäºäœçšããŸããã ãã®èšäºã§ã¯ãèè ã¯Linux Debian v7.XX amd64 OSãäŸãšããŠäœ¿çšããŠãã®åé¡ã解決ããäž¡æ¹ã®ããŒã«ã®æ©èœãæ倧éã«æŽ»çšããŠããŸãã äŸãšããŠãNGINXã«å¯ŸããDDoSæ»æã«å¯Ÿããä¿è·ãç·šæãããŠããŸãã
èªåããçªæ¯ãããªããæ¹æ³
ã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿããæ倧ã®è åšã¯ããµãŒãããŒãã£ãšå€éšèŠå ã ãã§ãªãããœãŒã¹ã³ãŒãèªäœãããçºçããŸãã Googleã®ãšã³ãžãã¢ã¯ã建ç¯èšèšã«ããã3ã€ã®å€§ããªééããšããããåé¿ããæ¹æ³ãæããŠããŸãã
DDoSä¿è·ã¬ã€ã
ProtonMailãDDoSä¿è·ãè¿œå ããæ¹æ³ã
ããããããã«ã€ããŠå°ã
æšæºãã¹ã¯ãŒãã¯ãã»ãŒ400,000ã®IoTããã€ã¹ã®ããããããã®äœæã«åœ¹ç«ã¡ãŸãã
10æäžæ¬ããããã¯ãŒã¯ã¯å€§èŠæš¡ãªMirai IoTããããããã®ã³ã³ããŒãã³ãã®ã³ãŒããå ¬éããŸããã ããããããã«ã¯äž»ã«ãããªã«ã¡ã©ãDVRãªã©ã®IoTããã€ã¹ãå«ãŸããŠãããããŒã¯æã®åèšãµã€ãºã¯ã»ãŒ400,000ã«éããæ»æè ã¯éåžžã«åŒ·åãªDDoSæ»æãå®è¡ã§ãããšå ±åãããŸããã
ã€ã³ã¿ãŒãããããç Žã£ããããããããã¯ã©ãã«ãè¡ããŸãã
Miraiãããããããšããªãç Žå£ããã®ãããã»ã©é£ããã®ãã«ã€ããŠãããå°ã説æããŸãã
Threat AdvisoryïŒMiraiã«åºã¥ããããããã
Miraiã³ãŒãã®å ¬éååŸã«çºçããã€ãã³ãã«é¢ããæ å ±ãåéããããã¥ã¡ã³ãã
Bittorrent DHTããã³ãã®ä»ã®P2Pãããã¯ãŒã¯ã§ãããã«ãªããªãæ¹æ³
Bittorrent DHTãããã¯ãŒã¯ã§ã¯ããã°ããããªã³ã¯ããã·ã¥ããããã·ã¥ãœãŒã¹ãèŠã€ããããšãã§ããŸãã ãããã¯ãŒã¯ã¯ãBittorentã¯ã©ã€ã¢ã³ããŸãã¯ãããã¯ãŒã¯ã®éåžžã®åäœã劚ããæªæã®ããããã°ã©ã ã®ããããã§ããå¯èœæ§ã®ããããŒãã§æ§æãããŸãã èè ã¯ãP2Pãããã¯ãŒã¯çšã®ããå¹ççã§å®å šãªã¯ã©ã€ã¢ã³ããäœæã§ããããã«ããäžé£ã®èããšãœãªã¥ãŒã·ã§ã³ãæäŸããŸãã
DDoSç¬å ïŒ2人ã®ããã«ãŒãMiraiã«åºã¥ããŠ100äžå°ã®ããã€ã¹ã®ãããããããäœæ
æšå¹ŽãTwitterãSpotifyãªã©ã®å€§èŠæš¡ãµã€ãã§æ»æãéå§ãããäžæçã«ç¡å¹ã«ãããŸããã ãã®ããã«ãMiraiããããããã䜿çšãããŸããã 2人ã®ããã«ãŒããããããããå¶åŸ¡ããæ°ããããŒãžã§ã³ãäœæããããšã«æåããŸããã
BASHLITEã¯ãŒã ã«ææããDDoSæ»æã«äœ¿çšããã100äžã®Webã«ã¡ã©
ãã¥ãŒã¹ïŒ100äžå°ä»¥äžã®ã€ã³ã¿ãŒãããã«æ¥ç¶ããããããªã«ã¡ã©ãšDVRã䟵害ãããŠãããäœæè ãDDoSæ»æãè¡ãããã«äœ¿çšããããããããã®äžéšã§ãã
éå€
ããžãã¹ã®å©çã®ããã«Roskomnadzorã®èŠä»¶ãã©ã®ããã«é å®ããã
IT-GRADäŒç€ŸããDDoSã«å¯Ÿããã¯ã©ã€ã¢ã³ãä¿è·æ©èœãåæã«å®è£ ããªããããéããŒãã®ã«ãŠã³ãã«é¢ããILVèŠä»¶ãã©ã®ããã«æºããããã«ã€ããŠã®ã¹ããŒãªãŒã
ããžãã¹åãIaaSïŒãã·ã¢ã®ããžãã¹ãã¯ã©ãŠãã«ç§»è¡ããæ¹æ³
ä»æ¥ãå€ãã®äŒæ¥ã¯å€ãã®ã¿ã¹ã¯ã®è§£æ±ºãšæé©åã«åœ¹ç«ã€ãããã¯ã©ãŠããã¯ãããžãŒãžã®åãæ¿ãã決å®ããŠããŸãã ãã·ã¢ã®ããžãã¹ã«åããŠæºåããŠããã¯ã©ãŠããã¯ãããžãŒã
ç¡æã®éçºè ããŒã«ã®éžæ
çã«é«å質ã®ãããžã§ã¯ããäœæã§ããéçºè åãã®é©å¿ããŒã«ïŒã¯ã©ãŠããå«ãïŒã CDNãæŽçããDDoSããä¿è·ããããã®ãœãªã¥ãŒã·ã§ã³ããããŸãã
éå»ããã®ææïŒRIPv1 DDoSæ»æããŸãã¯å€ãã«ãŒã¿ãŒ
ãã¥ãŒã¹ïŒæ代é ãã®RIPv1ã«ãŒãã£ã³ã°ãããã³ã«ã䜿çšããæ»æãã1幎以äžãå¿ããããŠãã2015幎5æ16æ¥ããåã³èŠãããŸããã ãããã¯æåã«ã¢ã«ãã€ã«ãã£ãŠèšé²ãããæ°æ¥åŸã«DDoS-GUARDã«ãã£ãŠèšé²ãããŸããã
Linux DDoSããã€ã®æšéŠ¬ã¯çµã¿èŸŒã¿ã®ã«ãŒããããã®åŸãã«é ããŸã
ãŠã€ã«ã¹å¯ŸçäŒç€ŸAvastã®ããã°ã®èšäºãã«ãŒãããããåã蟌ãŸããLinux DDoSããã€ã®æšéŠ¬ãã®ç¿»èš³ã
ã²ãŒã çšã®UDPïŒæå·åããã³DDoSä¿è·ïŒ
ããã¯ããã«ããã¬ã€ã€ãŒãªã³ã©ã€ã³ã²ãŒã ã®éçºãšå±éã®æ¬ã®ç« ã§ãã èè ã¯ããªã³ã©ã€ã³ã²ãŒã ãéçºãããšãã«æå·åã䜿çšãã䟡å€ãããçç±ã説æããŠããŸãã
2017幎ã«ç§ãã¡ãåŸ ã£ãŠããæ倧ã®ã»ãã¥ãªãã£è åš
æ¥å¹Žã«ç§ãã¡ãåŸ ã£ãŠãããã®ã Wiredã®äœè ã¯ãäžçã®ãã¥ãŒã¹ã«åºã¥ããŠä»®èª¬ãç«ãŠãŠããŸãã
DDoSæ»æããµã€ããŒæŠäºã®è¡çºãšãªã£ãæ¹æ³
ãµã€ããŒæŠäºãããããå°é£ãš2012幎9æ12æ¥ã®åºæ¥äºã«ã€ããŠã
å°ããªDDoSæ»æã®åœ±é¿ã調æ»ããŸã
ã¯ãªã¹ããã¡ãŒC.ãŠã§ã«ãºã¯ãè·å Žã®1ã€ã«å¯ŸããDDoSæ»æã®æ§è³ªãç解ããŠããŸãã 圌ã¯ã³ã¡ã³ããšãšãã«ãã°ã®åæãæäŸããŸãã
PSãŸããIaaSãITã€ã³ãã©ã¹ãã©ã¯ãã£ãã¯ã©ãŠããã¯ãããžãŒã®ãããã¯ã«é¢ããæçšãªãœãŒã¹ã®éžæã«æ³šæãæãããšããå§ãããŸãã