
æåã®èšäºã§ã¯ãèªè ã«åºæ¬çãªæŠå¿µã玹ä»ããããšããŸãã ãã®èšäºã¯ãããŒã¿ããŒã¹ã®ãããã¯ãŒã¯ãã¯ãããžãŒãç解ããŠããããDDoSä¿è·ã®ããã®ç£æ¥çšãœãªã¥ãŒã·ã§ã³ã«åºäŒã£ãããšã®ãªãåå¿è ã察象ãšããŠããŸãããã®è³æã«èå³ãããå Žåã¯ã次ã®äžé£ã®èšäºã§æè¡çãªè©³çŽ°ã詳现ã«é瀺ããŸãã
éä¿¡äºæ¥è ã®DDoSæ»æã«å¯Ÿããä¿è·ã®ç¹åŸŽã¯äœã§ããïŒ
ãã©ãã£ãã¯åæçšã®ãœãªã¥ãŒã·ã§ã³ãæ§ç¯ããéä¿¡äºæ¥è ã®DDoSæ»æãç¹å®ããããšã®ç¹æ§ã¯ããããã¯ãŒã¯æ§ç¯ã®ã¢ãŒããã¯ãã£ããã³ãããã¯ãŒã¯æ©åšã®æ©èœãšå¯æ¥ã«é¢é£ããŠããŸãã ãããäŸãšããŠèŠãŠã¿ãŸããããç°¡åãªæ¹æ³ã§ãRostelecomïŒAS12389ïŒã®IP / MPLSããã¯ããŒã³ãããã¯ãŒã¯ã®ã¢ãŒããã¯ãã£ã¯æ¬¡ã®ãšããã§ãã

ããã§ã ã¢ããã¹ããªãŒã ã¯åªããéä¿¡äºæ¥è ã§ããã ãã¢ã¯ãã¢éä¿¡äºæ¥è ãŸãã¯å€§èŠæš¡ã³ã³ãã³ããžã§ãã¬ãŒã¿ã§ããã 顧客ã¯ã¯ã©ã€ã¢ã³ãAS12389ã§ãã
ããã§ããããã¯ãŒã¯èšèšãå°ççã«å°ççã«ã·ããããŠã¿ãŸãããã

æåŸã«ãæ°åã§ãã¢ããã¹ããªãŒã /ãã¢/顧客ãšã®é¢ä¿ã®æ°ã瀺ããŸãïŒ https://radar.qrator.net ïŒ

ãããã£ãŠããªãã¬ãŒã¿ãŒãããã¯ãŒã¯ã®èšèšãéçšãæ±ãããšã¯ãã€ãŠãªãããšãç解ããã®ã¯ç°¡åã§ãããããã¯ãŒã¯ã«ã¯å€ãã®æ¥ç¶ãšæ¥ç¶ãããããã©ãã£ãã¯ã«ãŒãã£ã³ã°ã®æ§è³ªã¯é察称ã§ããã€ãŸããIPãã¬ãã£ãã¯ã¹ãšã®éã®ãã©ãã£ãã¯ã¯ç°ãªããŸããã«ãŒãã ããŒã¿ã»ã³ã¿ãŒãäŒæ¥ãããã¯ãŒã¯ãšã¯ç°ãªããé»æ°éä¿¡äºæ¥è ã«ã¯å€å žçãªæå³ã§ã®å¢çç·ããªããå¢çç·äžã®1ã€ãŸãã¯è€æ°ã®ãã€ã³ãã«åæããŒã«ãé 眮ããããšã¯ã§ããŸããã ãããã£ãŠã2ã€ã®ãµãã·ã¹ãã ã§æ§æãããAntiDDoSã·ã¹ãã ãæ§ç¯ããããšã¯ãã¢ãŒããã¯ãã£çã«å¹æçã§ãã
- ç°åžžæ€åºãµãã·ã¹ãã ïŒãã©ãã£ãã¯ããŒã¿ãåéããã³åæããŸãã
- ãã£ã«ã¿ãªã³ã°ãµãã·ã¹ãã ïŒåœã®ãã©ãã£ãã¯ããããã¯ããŸãã
DDoSæ»æã¯ã©ã®ããã«æ€åºãããŸããïŒ
ãã©ãã£ãã¯ãåæããIPã¢ãã¬ã¹ïŒæå±ãçŽæ¥æ¥ç¶ããŸãã¯AS12389çµç±ã®è»¢éïŒã«é¢é£ããç°åžžãæ€åºã§ããããã«ããã«ã¯ããã¹ãŠã®ãã©ãã£ãã¯ïŒåã«ãŒã¿ãŒãåIPã€ã³ã¿ãŒãã§ã€ã¹ïŒãåæããå¿ èŠããããŸãã ïŒçµæžç芳ç¹ããïŒãã®åé¡ãå¹æçã«è§£æ±ºããããã«ããããã¯ãŒã¯ãã¬ã¡ããªãããã³ã«ïŒ J-Flow v5 / 9 ã Netstream ã IPFIX ïŒã䜿çšããŠãã©ãã£ãã¯æ å ±ãåéããŸãã ããã«ãç°¡åã«ããããã«ããããã®ãããã³ã«ã®ãã¡ããªå šäœãNetFlowãšåŒã³ãŸãã ãããã®ãããã³ã«ã¯ãã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®æ å ±ã®åæãèš±å¯ãããOSIã¢ãã«ã®ç¬¬4ã¬ãã«ãŸã§ã®æ å ±ãéä¿¡ããŸããããšãã°ãJ-Flow v5ã®ããããŒæ§é ã¯æ¬¡ã®ãšããã§ãã

ããã§ïŒ
- éä¿¡å
IPã¢ãã¬ã¹
- å®å
IPã¢ãã¬ã¹
- ãã¯ã¹ããããIPã¢ãã¬ã¹-ãããã¯ãŒã¯ã¹ããªãŒã ã®éä¿¡å
ãšãªã次ã®ã«ãŒã¿ãŒã®IPã¢ãã¬ã¹ã
- å
¥åifIndex-ã«ãŒã¿ãŒããããŒãåä¿¡ããã€ã³ã¿ãŒãã§ãŒã¹ã®SNMPã€ã³ããã¯ã¹
- åºåifIndex-ã«ãŒã¿ãŒããããŒãééãããã€ã³ã¿ãŒãã§ãŒã¹ã®SNMPã€ã³ããã¯ã¹
- ãã±ãã-ãããŒå
ã§åä¿¡ãããã±ããã®ç·æ°
- ãã€ã-ã¹ããªãŒã å
ã§åä¿¡ãããã€ãã®ç·æ°
- ãããŒã®éå§æé-ãããŒã®éå§æé
- ãããŒã®çµäºæé-ãããŒã®çµäºæé
- éä¿¡å
ããŒã
- å®å
ããŒã
- TCPãã©ã°-TCPãã©ã°
- IPãããã³ã«-IPãããã³ã«çªå·
- ToS-ãµãŒãã¹ã®çš®é¡
- ãœãŒã¹AS-IPèªåŸã·ã¹ãã çªå·
- å®å
AS-èªåŸå®å
IPã·ã¹ãã çªå·
- ãœãŒã¹ãã¹ã¯-IPãœãŒã¹ãããã¯ãŒã¯ãã¹ã¯
- å®å
ãã¹ã¯-å®å
IPãããã¯ãŒã¯ãã¹ã¯
- ããã£ã³ã°-ããããŒã®å
šé·ãå¹ççã«äœ¿çšããããã®ããã£ã³ã°
J-Flow v9ããã³IPFIXã¯ãããã«ä»¥äžã«é¢ããæ å ±ãè¿œå ããŸãã
- ICMPã¿ã€ã/ã³ãŒã
- IPv6
- MPLS
- BGPãã¢AS
ãã ããv9ãšv5ã®IPFIXã®äž»ãªéãã¯ããã³ãã¬ãŒããäœæããããšã§ããŠãŒã¶ãŒèªèº«ãåæãããã£ãŒã«ãã決å®ã§ããããšã§ãã æ¬çªã·ã¹ãã ã§ã¯NetStreamã䜿çšããŠããŸããããè¿ãå°æ¥è¿œå ããäºå®ã§ãã
çŸåšãAS12389ã¯300ãè¶ ããã«ãŒã¿ãŒã§ãããããNetFlowãåéããããã«ãé«éã§ããŒã¿ããŒã¹ãåä¿¡ãåŠçãããã³æžã蟌ã¿ã§ããã³ã¬ã¯ã¿ã€ã³ãã©ã¹ãã©ã¯ãã£ãå±éãããŠããŸãã æ¯ç§ãã©ãããããããã¯ãŒã¯ãä»ããŠéä¿¡ãããããšãèæ ®ãããšãé«ä¿æ°ã®ãµã³ããªã³ã°ã¡ã«ããºã ïŒ> 4kïŒã䜿çšããŠããå Žåã§ããã«ãŒã¿ãŒã¯æ¯ç§30äžãè¶ ããNetFlowã¬ã³ãŒããçæããŸãã ãµã³ããªã³ã°ã䜿çšãããšãã«ãŒã¿ãŒãééãããã¹ãŠã®ãã±ãããåæããã®ã§ã¯ãªãããã³ããŒãèªç€Ÿã®æ©åšã«å®è£ ããç¬èªã®ã¢ã«ãŽãªãºã ã«åŸã£ãŠéžæçã«åæã§ãããããã³ã³ãããŒã«ãã¬ãŒã³ãŸãã¯ã«ãŒã¿ãŒã®ãµãŒãã¹ã«ãŒãã®è² è·ã軜æžãããŸãã

ã³ã¬ã¯ã¿ãŒã§ã¯ãããããããã³ã°ããŒãã«ãäœæãããNetFlowãåéãããä¿è·ãªããžã§ã¯ãã®çµ±èšãåéãããŸãã ä¿è·ã®ç®çã«ãããã·ã¹ãã ã®æ¬è³ªãç解ããŸããããã¯ã次ã®ããããã®å åã«ãã£ãŠèª¬æãããŸãã
- IPãã¬ãã£ãã¯ã¹ãªã¹ãïŒCIDRãããã¯ããã³ã°ã«ãŒãïŒ
- AS-Pathããã³ã³ãã¥ããã£å±æ§ãèšå®ããæ©èœãå«ãASN
- ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ãŒã¹
- ãããŒãã£ã«ã¿ã¯ãIPãã£ãŒã«ããšãã©ã³ã¹ããŒãããããŒã®ããŸããŸãªãã©ã¡ãŒã¿ãŒãšçµã¿åãããèšè¿°ããè«çåŒã§ãã ããšãã°ãã dst host 1.1.1.1ããã³proto tcpããã³dst port 80 ãã
å©çšå¯èœãªãã£ãŒã«ãã®ãªã¹ãïŒ
- å¹³åãã±ããé·
- å®å
ã¢ãã¬ã¹
- å®å
ããŒã
- ICMPã³ãŒã
- ICMPã¿ã€ã
- ãããã³ã«
- éä¿¡å
ã¢ãã¬ã¹
- éä¿¡å
ããŒã
- TCPãã©ã°
- ãã¹ããã
- å¹³åãã±ããé·
ååŸããçµ±èšã«åºã¥ããŠãã·ã¹ãã ã¯ä¿è·ãªããžã§ã¯ãã®éåžžã®ãã©ãã£ãã¯åäœã®åçãããã¡ã€ã«ã圢æããŸãã ãŸããæãäžè¬çãªæ»æã·ã°ããã£ã®ãããå€ã®åœ¢åŒã§éçãããã¡ã€ã«ãæåã§èšå®ããããšãã§ããŸãã ããšãã°ãã»ãšãã©ã®å¢å¹ ã¿ã€ãã®DDoSæ»æïŒNTPãDNSãChargenãSSDPãªã©ïŒã¯ããã®æ¹æ³ã§å®å šã«æ€åºãããŸãã ãã©ãã£ãã¯ããããå€ããéžè±ãããšãã·ã¹ãã ã¯ç°åžžã¡ãã»ãŒãžãçæããŸãã
ãããå€ãè¶ ããå²åã«å¿ããŠãç°åžžã¯ãé倧床ã®ã¬ãã«ã«å¿ããŠãäœãäžãé«ã®3ã€ã®ã¿ã€ãã«åé¡ãããŸãã ã»ãšãã©ã®å Žåãäœç°åžžã¯ãæ£åœãªãã©ãã£ãã¯ã®æ¥å¢ã«ãã£ãŠç¹åŸŽä»ããããŸããããšãã°ãããŒã±ãã£ã³ã°äŒç€Ÿã®éå¶ãªã©ãéåžžãããå€ãã®ãŠãŒã¶ãŒãä¿è·ãããWebãµã€ãã«ã¢ã¯ã»ã¹ããŸããã ãããã£ãŠãå€åã·ããã®å°é家ã¯ãäžããã³é«ã®ç°åžžãããå³å¯ã«ç£èŠããŸãã
DDoSæ»æã®ãã£ã«ã¿ãªã³ã°ã¯ã©ã®ããã«è¡ãããŸããïŒ
ã·ã¹ãã ãä¿è·ããããªãœãŒã¹ã«é¢é£ããç°åžžãæ€åºããåŸããã®ãã©ãã£ãã¯ãæåã¢ãŒããŸãã¯èªåã¢ãŒãã®ãã£ã«ã¿ãªã³ã°ã«ãªãã€ã¬ã¯ãã§ããŸãã
ããã€ãã®ãã£ã«ã¿ãªã³ã°æ¹æ³ããããŸãã
- ãããŒä»æ§ãã£ã«ã¿ãŒã
- ãã©ãã¯ããŒã«ã«ãŒãã£ã³ã°-AntiDDoSãµãŒãã¹ãæäŸãããšãã¯äœ¿çšããŸããããã®ããããã®èšäºã§ã¯ã»ãšãã©ã¹ããŒã¹ãå²ãåœãŠãŸããã
- ãã©ãã£ãã¯ã¯ãªãŒãã³ã°ã»ã³ã¿ãŒïŒCTCïŒã®ã€ã³ããªãžã§ã³ããã£ã«ã¿ãªã³ã°ã
åèšã§ã2ã€ã®å°ççã«åé·ãªDHCãåãµã€ãïŒGR + HAïŒã®ãã§ã€ã«ã»ãŒãããŒãžã§ã³ã§ãããã¯ãŒã¯ã«å±éãããŸãã

ãªãã€ã¬ã¯ãã¯ãAS12389å ã§DHCãä»ããä¿è·ãªããžã§ã¯ããžã®ããå ·äœçãªã«ãŒããçºè¡šããããšã«ããå®è¡ãããŸãã ããã«ãããã¹ããªã¢ã¹ãã©ãã£ãã¯ãå«ããã¹ãŠã®ãã©ãã£ãã¯ãã»ã³ãã©ã«ããŒãã£ã³ã°ã»ã³ã¿ãŒã«éããããããã§ãã£ã«ã¿ãªã³ã°ããããã¯ãªãŒã³ããªãã©ãã£ãã¯ãã¯ã©ã€ã¢ã³ãã®ãããã¯ãŒã¯ã«é ä¿¡ãããŸãã ã«ãŒãã£ã³ã°ã«ãŒããåé¿ããããã«ãMPLSãä»ããŠãã©ãã£ãã¯ãé ä¿¡ããã¡ã«ããºã ã䜿çšããBGPã©ãã«ä»ããŠããã£ã¹ããä»ããŠã«ãŒãã©ãã«ãæž¡ããŸãïŒã¯ãªã¢ããããã©ãã£ãã¯ãé ä¿¡ããã¡ã«ããºã ã«ã€ããŠã¯å¥ã®èšäºã§èª¬æããŸãïŒã ãã®æ¹æ³ãéžæããæ©åšãäžåºŠã»ããã¢ããããã ãã§ãã¯ã©ã€ã¢ã³ãåŽã§è¿œå èšå®ãè¡ãå¿ èŠããªããªããŸãã ãã®ããã«ããŠãAS12389ã«æ¥ç¶ããŠãã人ãä¿è·ã§ããŸãã ã¯ã©ã€ã¢ã³ãããã®å¿çãã©ãã£ãã¯ã¯ãæé©ãã¹ã«æ²¿ã£ãŠã«ãŒãã£ã³ã°ãããŸãã ã«ãŒãã£ã³ã°ãå€æŽããããããã£ãŠDHCã«åé¡ãããŸããã ãããã£ãŠãç¡æ¡ä»¶ã®é察称æ§ã圢æãããŸããããã«ã¯ãæ¬ ç¹ïŒç¹å®ã®å¯Ÿçãšã¢ããªã±ãŒã·ã§ã³å¿çã®åæã䜿çšããèœåïŒãšå©ç¹ïŒå¿çãã©ãã£ãã¯ã®é 延ãå¢å ããªãïŒã®äž¡æ¹ããããŸãã
ãã©ãã£ãã¯é ä¿¡ã®æ¹æ³ã®é察称æ§ã¯ãèããããäžé£ã®å¯ŸçïŒãã£ã«ã¿ãªã³ã°ã«ãŒã«ïŒã«åœ±é¿ããŸããã·ã¹ãã éçºè ã¯ãçä¿¡ãã©ãã£ãã¯ã®ã¿ã«åºã¥ãã¹ããªã¢ã¹ãã©ãã£ãã¯ããã³ãããã決å®ããããã®ãªãã·ã§ã³ãæ¢ãå¿ èŠããããŸãã
æ»æã®æ€åºã«ã¯ã¢ããªã±ãŒã·ã§ã³å±€ãå«ãŸããªããšããäºå®ã«ããããããããã©ãã£ãã¯ãã£ã«ã¿ãªã³ã°ã¯ãã·ã°ããã£ã¡ãœãããšåäœã¡ãœããã®äž¡æ¹ã䜿çšããŠãOSIã¢ãã«ã®L7ã¬ãã«ãŸã§è¡ãããŸãã
ã»ã³ãã©ã«ããŒãã£ã³ã°ã»ã³ã¿ãŒã¯ã ATCAãã©ãããã©ãŒã ã«åºã¥ãç¹æ®ãªæ©åšã§æ§ç¯ãããŠããã1ã€ã®ã·ã£ãŒã·ã§é«ããéæ§èœïŒã¢ããªã±ãŒã·ã§ã³ã¬ãã«ãå«ãïŒãå®çŸã§ããŸãã è¿å¹ŽãIntel DPDK ã HyperScan ã10Gããã³40Gãããã¯ââãŒã¯ã«ãŒããªã©ã®ãã¯ãããžãŒã®åºçŸãããã³CPUã³ã¢ã®æ°ã®å¢å ã«ããããããã¯ãŒã¯ãããŒã®åŠçãéåžžã«å¹ççã«äžŠååããããšãå¯èœã«ãªã£ããããè¿ãå°æ¥ãATCAãx86ã¢ãŒããã¯ãã£ãµãŒããŒã«æ®ãäºå®ã§ãã
ããã§ã¯ããªãFlow Specificationãå¿ èŠãªã®ã§ããããïŒ
ææ°ã®ãã¹ãŠã®ãã£ãªã¢ã°ã¬ãŒãã®ã«ãŒã¿ãŒã«ã¯ãL4 OSIãŸã§ã®ãã£ã«ã¿ãªã³ã°ã¡ã«ããºã ãçµã¿èŸŒãŸããŠããŸããããã¯ã¡ãŒã«ãŒã«ãã£ãŠç°ãªãå ŽåããããŸãããäžè¬çã«ã¯ã¢ã¯ã»ã¹ã³ã³ãããŒã«ãªã¹ãïŒACLïŒãšåŒã°ããŸãã ACLã¯ã©ã€ã³ã«ãŒãã®ããŒããŠã§ã¢ã«å®è£ ãããŠãããäžç¶ãã±ãããšã«ãŒã¿ãŒèªäœçšã«èšèšããããã±ããã®äž¡æ¹ããã£ãã«é床ãŸãã¯ããã«è¿ãé床ïŒã©ã€ã³ã¬ãŒãïŒã§ãã£ã«ã¿ãªã³ã°ã§ããŸããããã«ãããåœã®ãã©ãã£ãã¯ãã«ããããå¿ èŠãããå Žåã«ãã®æè¡ãéåžžã«åœ¹ç«ã¡ãŸãæ»æã®çºä¿¡å ã«è¿ããã€ãŸã ç§ãã¡ã®ãããã¯ãŒã¯ã®ç«¯ã«ã ããããä»¥æ¥ ACLã¯åã«ãŒã¿ãŒã§ããŒã«ã«ã«æ§æãããŠãããåè¿°ã®ããã«300ãè¶ ããŠããŸããæ»æãçºçããå Žåããã£ã«ã¿ãŒã®éçšäžã®äœ¿çšã¯äžå¯èœã«ãªããŸãã ACLãäžå 管çïŒäœæãåé€ïŒããããã«ã BGP Flow Specificationãããã³ã«ïŒRFC 5575ïŒãéçºãããŸããã
äžéšã®éä¿¡äºæ¥è ã¯FlowSpecã顧客ã«ãµãŒãã¹ãšããŠæäŸããŠããŸãããRostelecomã¯ãŸã æäŸããŠããŸããã ç¬èªã®ç®çã§ç©æ¥µçã«äœ¿çšããŠããŸãããã«ãŒã¿ãŒã§ãµããŒããããŠããã«ãŒã«ã®æ°ã¯ãŸã ååã§ã¯ãããŸããã ãªãã¬ãŒã¿ã«é£çµ¡ããŠããã®ãããªãµãŒãã¹ã®å¯çšæ§ã«ã€ããŠèª¿ã¹ãããšããå§ãããŸãã FlowSpecã¯ExaBGPãªã©ã®ãããžã§ã¯ãã«å®è£ ãããŠããããªãã¬ãŒã¿ãŒã®ãããã¯ãŒã¯ã«ãã£ã«ã¿ãŒãã€ã³ã¹ããŒã«ããé«äŸ¡ãªãµãŒãã¹ãè³Œå ¥ããããšãªããã£ã³ãã«ã«åããããæ»æãã身ãå®ãæé ãªäŸ¡æ Œã®ããŒã«ãå ¥æã§ããŸãã ãã®ä¿è·ãªãã·ã§ã³ã¯ãã¹ãŠã®äººã«é©ããŠããããã§ã¯ãããŸããããæ¬æ ŒçãªAntiDDoSãµãŒãã¹ã«ä»£ããååãã€å®äŸ¡ãªéžæè¢ã«ãªãããšããããŸãã
ç§ãã¡ã䜿çšããã·ã¹ãã ã§ã¯ããããã®ãã£ã«ã¿ãŒãWebã€ã³ã¿ãŒãã§ãŒã¹ããçŽæ¥é åžã§ããŸãã ãããã£ãŠãããªã¬ãŒãæ§æããã·ã¹ãã ã«ãã£ãŠèªåçã«æ€åºãããç°åžžãããã£ã«ã¿ãªã³ã°ã¿ã¹ã¯ãäœæã§ããŸãã
ãããã¯ãŒã¯æ©åšã®ããŸããŸãªã¡ãŒã«ãŒãããã³ãããã®ã¡ãŒã«ãŒã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ããŸããŸãªããŒãžã§ã³ã¯ããããã®ãã£ã«ã¿ãŒããã¹ãŠã®ã€ã³ã¿ãŒãã§ã€ã¹ãŸãã¯éžæããã€ã³ã¿ãŒãã§ã€ã¹ã«é©çšã§ãããããã«ãŒã«ã®ãã§ãŒã³ãéããŠåã€ã³ã¿ãŒãã§ã€ã¹ããåãã±ãããå®è¡ããããšãªããæ©åšã®è² è·ã軜æžã§ããŸãã
äž»ã«FlowSpecã䜿çšããŠãL4ãŸã§ã®ãã³ãã¬ãŒãåã«é©ããæ»æã®ãã£ã«ã¿ãªã³ã°ã®æåã®æ®µéãšããŠäœ¿çšããŸããã»ãŒãã¹ãŠã®UDPããŒã¹ã®å¢å¹ æ»æãããã«å®å šã«é©åããŸãã ããã«ãããã»ã³ãã©ã«ããŒãã£ã³ã°ã»ã³ã¿ãŒã«åœã®ãã©ãã£ãã¯ãèªå°ããã®ã§ã¯ãªããå¯èœãªéãæ©æã«é®æããæ®ãã®ãã©ãã£ãã¯ã«å¯ŸããŠãã·ã³ãã¯ãªãŒãã³ã°ãå®è¡ã§ããŸãã
ãã©ãã¯ããŒã«ã®å Žæã¯ãããŸããïŒ
æãåºæ¬çãªã±ãŒã¹ã§ã¯ãã¹ããªã¢ã¹ãã©ãã£ãã¯ãäœãå ¬éãããŠããªããªãœãŒã¹ã«åããããå ŽåïŒããã³ãããçºçããŸãïŒããªãã¬ãŒã¿ãŒã¯ãã¹ãŠã®ãã©ãã£ãã¯ãBlackholeã®ãã®ãªãœãŒã¹ã«éä¿¡ã§ããŸãã ãããè¡ãã«ã¯ãåã«ãŒã¿ãŒã«ã«ãŒããèšå®ããŸãããã®ã«ãŒã¿ãŒã®æ¬¡ã®ãããã¯ç Žæ£ãã€ãŸã ãã©ãã£ãã¯ã¯åã«ãã³ããããŸãã Blackholeã®éäžé ä¿¡ãå¿ èŠãªå Žåãã«ãŒããªãã¬ã¯ã¿ãŒã®ã·ã¹ãã ã䜿çšãããã¬ãã£ãã¯ã¹ãžã®ãã©ãã£ãã¯ããããã®1ã€ã«ç»é²ãããããããã¹ãŠã®ã«ãŒã¿ãŒããã®ã«ãŒããåä¿¡ããŸãã
Blackholeã³ãã¥ããã£ã¯ã©ãã§ããïŒ
ãªãã¬ãŒã¿ã«ãšã£ãŠã®ãããŒã¯ããã©ãã£ãã¯ã管çããã¯ã©ã€ã¢ã³ãã®æ©èœã«ããŸããŸãªBGP CommunitiesAttributeã䜿çšããããšã§ãã ãã®ãããªã³ãã¥ããã£ã®1ã€ãBlackholeã³ãã¥ããã£ã§ãã éåžžããã®æ å ±ã¯ããªãã¬ãŒã¿ãŒã«ãã£ãŠèªåŸã·ã¹ãã ãžã®ã«ãŒãã£ã³ã°æ å ±ã®ããŒã¿ããŒã¹ïŒããšãã°ã RIPEïŒã®ã³ã¡ã³ãã§å ¬éãããŸãã Rostelecomã®å Žåãã³ãã¥ããã£ããŒã¿ã¯12389ïŒ55555ã§ãã ãã®ã³ãã¥ããã£ã®ãã¬ãã£ãã¯ã¹ã¯/ 32ãŸã§åãå ¥ããããŸãããä»ã®ãã¬ãã£ãã¯ã¹ã¯/ 24ããå ·äœçã§ã¯ãããŸããã
ãªãã¬ãŒã¿ãŒã¯ãDDoSæ»æã«å¯Ÿããä¿è·ã®èŠ³ç¹ããçžäºã«äœçšããŸããïŒ
ããã€ãã®åé¡ã§ã¯-ã¯ããããã¯äž»ã«ãã®æ¥åéšã«BGP FlowSpecãå«ããããšã«é¢ä¿ããŠããŸããã ãã°ã¯ããã³ããŒã®æ©åšã§ã®ãããã³ã«ã®å®è£ ã§å®æçã«æ€åºãããŸãã ãã以å€ã®å Žåã DDoSæ»æã«å¯Ÿããä¿è·ã¯ãŸã åçšã§ãã競åã®ãããæ»æã«é¢ããæ å ±ïŒ IoCãªã©ïŒã亀æããããã®æè¡çããã³çµç¹çãªæ¹æ³ã¯ãããŸããã
DDoSæ»æãæ€åºããŠä¿è·ããããã®ãªãã¬ãŒã¿ãŒã·ã¹ãã ãæ§ç¯ããããã«äœ¿çšããããœãªã¥ãŒã·ã§ã³ã¯äœã§ããïŒ
ãã·ã¢ã§ã¯ã次ã®ãœãªã¥ãŒã·ã§ã³ãæã人æ°ããããŸããã
- Arbor Networksã SP ãããã³ã TMS ã
- ã©ããŠã§ã¢ã DefensePro ã
- MFIãœããã å¢ç ã
- Inventika Technologies " InvGuard "
- NSFocus " ADS "ããã³ "NTA"
- Huawei " AntiDDoS8000 / 10000 "
ãã ããäžèšã®ã¡ãŒã«ãŒã®ãã¹ãŠããšã³ãããŒãšã³ããœãªã¥ãŒã·ã§ã³ïŒãã©ãã£ãã¯åæããã³ãã£ã«ã¿ãªã³ã°ããã€ã¹çšã®NetFlowã³ã¬ã¯ã¿ãŒïŒãåããŠããããã§ã¯ãªããããšãã°ãGenie Networks " GenieATM "ãªã©ã®å¥ã®ãã³ããŒãšãã¢ã«ãªã£ãŠããããšããããããŸãã ãŸããäžéšã¯ããŸããŸãªNetFlowã³ã¬ã¯ã·ã§ã³ãœãªã¥ãŒã·ã§ã³ããµããŒãããŠããŸãã æ瀺ããããœãªã¥ãŒã·ã§ã³ã®æ¯èŒã¯å¥ã®èšäºã«å€ãããããããããã«ã€ããŠè©³ãã説æããããšã¯ããŸããã
ãªãã¬ãŒã¿ãŒã¯ã¯ã©ãŠããµãŒãã¹ãšã©ãéãã®ã§ããïŒ
éä¿¡äºæ¥è ã¯ããããã¯ãŒã¯ã«ç©ççã«æ¥ç¶ãããŠããã¯ã©ã€ã¢ã³ãã«ã®ã¿ãµãŒãã¹ãæäŸããŸããæ¢ã«ç解ããŠããããã«ãäºæ¥è ã¯ãã©ãã£ãã¯çµ±èšãåéãããããã¯ãŒã¯å ã®ã»ã³ãã©ã«ããŒãã£ã³ã°ãããã¯ãŒã¯ã§ã®ã¿ãã£ã«ã¿ãªã³ã°ã«ãªãã€ã¬ã¯ãã§ããããã§ãã DDoSæ»æããä¿è·ããããã®ãµãŒãã¹ãžã®æ¥ç¶ã«ã¯ãã¯ã©ã€ã¢ã³ãåŽã§ã®ã¢ã¯ã·ã§ã³ã¯å¿ èŠãããŸããïŒãã®å ŽåïŒã ãŸãããªãã¬ãŒã¿ãŒã¯åã ã®ã¢ããªã±ãŒã·ã§ã³ããµãŒãã¹ã§ã¯ãªãããã£ãã«å šäœãä¿è·ãããããITã€ã³ãã©ã¹ãã©ã¯ãã£å šäœãå®å šã«ä¿è·ã§ããŸãã
éçºã®åæ段éã§ã¯ãã¯ã©ãŠããµãŒãã¹ã¯Webãµã€ãã®ã¿ãä¿è·ããŠããŸããã DNSã®Aã¬ã³ãŒããã¯ã©ãŠãã®IPããŒã«ã®IPã¢ãã¬ã¹ã«å€æŽããããšã«ããããã©ãã£ãã¯ããªãã€ã¬ã¯ããããŸããã ã¯ã©ã€ã¢ã³ããžã®ç²Ÿè£œããããã©ãã£ãã¯ã¯ããªããŒã¹ãããã·æ¹åŒã䜿çšããŠé ä¿¡ãããŸããã ãªãã€ã¬ã¯ããšé ä¿¡ã®ãã®æ¹æ³ã¯äŸç¶ãšããŠé¢é£ããŠãããæãäžè¬çã§ãã ãã ãã顧客ãWebãµã€ãã«å ããŠãä¿è·ããå¿ èŠãããä»ã®éèŠãªãªãœãŒã¹ïŒDNSãã¡ãŒã«ãµãŒããŒãªã©ïŒãæã£ãŠããå Žåããã®æ¹æ³ã§ã¯ãã¹ãŠã®ãã©ãã£ãã¯ãã¯ã©ãŠãã«ãªãã€ã¬ã¯ãã§ããŸããã§ããã ãã®åŸãã¯ã©ãŠããµãŒãã¹ã顧客ã®ãããã¯ãŒã¯ãVPNçµç±ã§æ¥ç¶ãå§ããŸãããããã«ãããæ¬è³ªçã«ã€ã³ã¿ãŒããããããã€ããŒããªãŒããŒã¬ã€ãããã¢ããªã±ãŒã·ã§ã³å šäœã§ã¯ãªããã£ãã«å šäœããã£ã«ã¿ãªã³ã°ãããŸããã
æè¿ãéä¿¡äºæ¥è ã¯ãããã¯ãŒã¯äžã«ãªããŒã¹ãããã·ããã³WAFã¯ã©ã¹ã¿ãŒã®å±éãéå§ããŸãããããã«ããããããã¯ãŒã¯å€ã®ã¯ã©ã€ã¢ã³ããä¿è·äžã«çœ®ãããšãã§ããŸãã ãããã£ãŠããªãã¬ãŒã¿ãŒãšã¯ã©ãŠããµãŒãã¹ã®éã®æ¡ä»¶ä»ãå¢çããããŸãã«ãªãå§ããããšãããããŸãã
ãããããçç¶æŒç®åãçç¶é²ãšæ¯èŒããããšã¯ããŸãæå³ããããŸããã åŸè ã§ãå€§å¹ ã«ç°ãªãå ŽåããããŸãã ããšãã°ãäžéšã¯ç¬èªã«ã·ã¹ãã ãéçºãã2ã€ç®ã¯ããŸããŸãªãã³ããŒã®æ¢è£œã®ç£æ¥çšãœãªã¥ãŒã·ã§ã³ã«åºã¥ããŠæ§ç¯ãã3ã€ç®ã¯ããŸããŸãªã¢ããã¹ããªãŒã ãªãã¬ãŒã¿ãŒã«æ¥ç¶ãããDHCã®äžççãªåæ£ãããã¯ãŒã¯ãæã¡ã4ã€ç®ã¯1ã€ã®åœã®å°åã«1ã€ä»¥äžã®DHCãæã¡ãããŒã«ã«ãã¬ã³ã ãªãã¬ãŒã¿ãŒã®1ã€ã«æ¥ç¶ãã 5ã€ç®ã¯é¡§å®¢ã®ãµã€ãã«ã»ã³ãµãŒãå¿ èŠã§ã6ã€ã¯Webãã©ãã£ãã¯å°çšã§ãã ãã®ãããã¯ã¯ä»åŸã®èšäºã§å ¬éããäºå®ã§ãã
èŠçŽãããšãäžã§èŠãããã«ã次ã®æ©èœã¯éä¿¡äºæ¥è ã®ç¹åŸŽã§ãã
- ãã®ãµã€ãºã«ãããéä¿¡äºæ¥è
ã¯ãã£ã«ã¿ãªã³ã°ã®ããã«å€§éã®ãã©ãã£ãã¯ããåä¿¡ãããããšãã§ããŸãã
- 倧èŠæš¡ãªé»æ°éä¿¡äºæ¥è
ã«ãšã£ãŠããã®ã¢ãŒããã¯ãã£ã¯ãããã¯ãŒã¯ãžã®å
¥ãå£ã§ã®ãã£ã«ã¿ãªã³ã°ãå¯èœã«ããŸãã
- æåã®ãã£ã«ã¿ãªã³ã°ã®åŸããããŒãã£ããã©ãã£ãã¯ã®ãããŒã¯ã¯ããã«å°ãªããªãããã§ã«COTã§åæã§ããŸãã
- ãéå質ã¯å€ãã®ãã©ã¡ãŒã¿ã«äŸåããŸããããã®äž»ãªãã®ã¯ãéã·ã¹ãã ã®æ©èœãšNOC / SOCã®çµéšã§ãã
- ã¯ã©ã€ã¢ã³ããæ¢ã«ãµãŒãã¹ã䜿çšããŠããå Žåãå€ãã®å Žåãã¯ã©ã€ã¢ã³ããä¿è·ã«æ¥ç¶ããŠãã©ãã£ãã¯ã®ãã£ã«ã¿ãªã³ã°ãéå§ããæ¹ãç°¡åãã€è¿
éã§ãã
çµè«ãšããŠã2008幎以æ¥ãåœç€Ÿã¯ãã©ãã£ãã¯ãåæããDDoSæ»æããä¿è·ããããã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãéçºããŠããŸãããããã®éãåæã®åéããã©ãã£ãã¯ã®ãã£ã«ã¿ãªã³ã°ãã¯ãªã¢ããããã©ãã£ãã¯ã®é ä¿¡ãããã³è¿œå ã®å®è£ ã«é¢ããŠãæ°åè¿ä»£åãè¡ã£ãŠããŸããCloudSignalingã®ãããªãªãã·ã§ã³ã ç§ãã¡ã䜿çšããŠããæè¡ã«ã€ããŠè©±ããŠãã以äžã®èšäºã§ã¯ãééããªãå顧å±ã瀺ããéçºãã¹ãéžæããäžã§ç§ãã¡ãæ¯é ããçç±ãæããã«ããŸãã