ããµãã¥ãŒã»ããå·¥ç§å€§åŠã è¬çŸ©ã³ãŒã¹6.858ã ãã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã®ã»ãã¥ãªãã£ãã ãã³ã©ã€ã»ãŒã«ããŽã£ããããžã§ãŒã ãºã»ãã±ã³ãºã 2014幎
ã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã»ãã¥ãªãã£ã¯ãå®å šãªã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã®éçºãšå®è£ ã«é¢ããã³ãŒã¹ã§ãã è¬çŸ©ã§ã¯ãè åšã¢ãã«ãã»ãã¥ãªãã£ãå±éºã«ãããæ»æãããã³æè¿ã®ç§åŠçç 究ã«åºã¥ããã»ãã¥ãªãã£æè¡ãæ±ããŸãã ãããã¯ã«ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ïŒOSïŒã»ãã¥ãªãã£ãæ©èœãæ å ±ãããŒç®¡çãèšèªã»ãã¥ãªãã£ããããã¯ãŒã¯ãããã³ã«ãããŒããŠã§ã¢ã»ãã¥ãªãã£ãããã³Webã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãå«ãŸããŸãã
è¬çŸ©1ïŒãã¯ããã«ïŒè åšã¢ãã«ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©2ïŒãããã«ãŒæ»æã®å¶åŸ¡ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©3ïŒããããã¡ãªãŒããŒãããŒïŒãšã¯ã¹ããã€ããšä¿è·ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©4ïŒãç¹æš©ã®å ±æã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©5ïŒãã»ãã¥ãªãã£ã·ã¹ãã ã¯ã©ãããæ¥ãã®ãïŒã ããŒã1 / ããŒã2
è¬çŸ©6ïŒãæ©äŒã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©7ïŒããã€ãã£ãã¯ã©ã€ã¢ã³ããµã³ãããã¯ã¹ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©8ïŒããããã¯ãŒã¯ã»ãã¥ãªãã£ã¢ãã«ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©9ïŒãWebã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©10ïŒãã·ã³ããªãã¯å®è¡ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©11ïŒãUr / Webããã°ã©ãã³ã°èšèªã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©12ïŒãããã¯ãŒã¯ã»ãã¥ãªãã£ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©13ïŒããããã¯ãŒã¯ãããã³ã«ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©14ïŒãSSLããã³HTTPSã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©15ïŒãå»çãœãããŠã§ã¢ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©16ïŒããµã€ããã£ãã«æ»æã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©17ïŒããŠãŒã¶ãŒèªèšŒã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©18ïŒãã€ã³ã¿ãŒãããã®ãã©ã€ããŒããã©ãŠãžã³ã°ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©19ïŒãå¿åãããã¯ãŒã¯ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©20ïŒãæºåž¯é»è©±ã®ã»ãã¥ãªãã£ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©21ïŒã远跡ããŒã¿ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©22ïŒãæ å ±ã»ãã¥ãªãã£MITã ããŒã1 / ããŒã2 / ããŒã3
ãã®ãããããã¯ãéåžžã«å€§èŠæš¡ãªæœèšã«å€æ°ã®ããã€ã¹ãåããããã4人ã®ããŒã ããããšããäºå®ã®åºæã§ããã ãããã£ãŠãå°ãªããšããã®ãµã€ãºã®ãããã¯ãŒã¯ã®å®å šæ§ã確ä¿ããããšããããã«ã¯ããã§ãã¬ãŒã·ã§ã³ããŒã¯ã®ã¹ããŒã¯ãæ¬åœã«å¿ èŠã§ãã
ç§ãã¡ã¯äººã ãšã³ãã¥ãã±ãŒã·ã§ã³ãåãããã£ã³ãã¹ã§åœŒããå©ããŸãã åœç€Ÿã®ããŒããã©ãªãªã¯ãã³ã³ãµã«ãã£ã³ã°ãµãŒãã¹ãã³ãã¥ããã£ã«æäŸãããµãŒãã¹ã䜿çšããããŒã«ã§æ§æãããŠããŸãã åœç€ŸãæäŸãããµãŒãã¹ã¯éåžžã«å€æ§ã§ãã
äžæ£è¡çºã®å ±å-ãªã³ã©ã€ã³ã§ã®äžæ£è¡çºã®å ±åããªãªãŒã¹ããŸãã éåžžããããã¯å€éšã®äžçããã®èŠæ ã«å¯Ÿããåçã§ããããã®å€§éšåã¯ç 究æã®ãããã¯ãŒã¯ã§ã®TorããŒãã®äœæã«é¢é£ããŠããŸãã ç§ãã¡ã¯ããããæã£ãŠããŸããç§ã¯ä»ã«äœãèšãããšãã§ããŸããïŒ ïŒèŠ³å®¢ã®ç¬ã声ïŒã
ãšã³ããã€ã³ãä¿è· ã倧åãã³ã³ãã¥ãŒã¿ãŒã«ã€ã³ã¹ããŒã«ããããŒã«ãšè£œåãããã€ããããŸããå¿ èŠã«å¿ããŠäœ¿çšã§ããŸãã ã»ãšãã©ã管çãªãœãŒã¹ã§ããMITãã¡ã€ã³ã«å±ããŠããå Žåããããã®è£œåã¯ã³ã³ãã¥ãŒã¿ãŒã«èªåçã«ã€ã³ã¹ããŒã«ãããŸãã
ãããã¯ãŒã¯ä¿è·ããŸãã¯ãããã¯ãŒã¯ä¿è·ã¯ãmit.netãããã¯ãŒã¯å šäœãšãã®å¢çã®äž¡æ¹ã«ããããŒã«ã®ã»ããã§ãã ç°åžžãæ€åºããããåæã®ããã«ãã©ãã£ãã¯ãããŒããŒã¿ãåéããŸãã ããŒã¿åæã¯ãããããã¹ãŠãæ¯èŒãããŸãšããæçšãªæ å ±ãååŸããã®ã«åœ¹ç«ã¡ãŸãã
ãã©ã¬ã³ãžãã¯-ã³ã³ãã¥ãŒã¿ãã©ã¬ã³ãžãã¯ã«ã€ããŠã¯ãããã«èª¬æããŸãã
ãªã¹ã¯ã®ç¹å®ããŸãã¯ãªã¹ã¯ã®ç¹å®ã¯ãäž»ã«Nessusãªã©ã®ãããã¯ãŒã¯æ€ç¥ããã³è©äŸ¡ããŒã«ã§ãã ããã«ã¯ãPIIãæ¢ããã®ïŒå人èå¥æ å ±ïŒãå«ãŸããŸããããã¯ãããµãã¥ãŒã»ããå·ã§ã¯å·201 CMR 17.00ã®åºæ¬æ³ã®æ°ããèŠåãžã®æºæ ã確ä¿ããå¿ èŠãããããã§ãã ããµãã¥ãŒã»ããå·ã®å± äœè ã«é¢ããå人æ å ±ãä¿åãŸãã¯äœ¿çšããæ©é¢ãŸãã¯äŒæ¥ã«ãå人æ å ±ä¿è·èšç»ãäœæãããã®æå¹æ§ãå®æçã«ç¢ºèªããããšãæ±ããŠããŸãã ãããã£ãŠããããã¯ãŒã¯å ã®ã©ãã«ãŠãŒã¶ãŒã®å人æ å ±ãããããå€æããå¿ èŠããããŸãã
ã¢ãŠããªãŒã/æè/ãã¬ãŒãã³ã°-æ å ±æäŸãšãã¬ãŒãã³ã°ãç§ã¯ããã«ã€ããŠè©±ããŸããã
ã³ã³ãã©ã€ã¢ã³ã¹ã®ããŒãºã¯äž»ã«PCI DSSã·ã¹ãã ã§ãã DSSãæã€ãã€ã¡ã³ãã«ãŒãæ¥çã§ããPCIã¯ãããŒã¿ã»ãã¥ãªãã£æšæºã§ãã ä¿¡ããããªããããããŸããããããµãã¥ãŒã»ããå·¥ç§å€§åŠã¯ã¯ã¬ãžããã«ãŒãã販売ããŠããŸãã ãã£ã³ãã¹ã«ã¯ãããã®æ¯æãæ¹æ³ã®ãããã€ããããã€ãããããããã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãPCI DSSäºæã§ããããšã確èªã§ããã¯ãã§ãã ãããã£ãŠããããã®ããŒãºãæºããããã®ã»ãã¥ãªãã£ç®¡çãšã»ãã¥ãªãã£ã³ã³ãã©ã€ã¢ã³ã¹ããããŒã ã®ä»äºã®äžéšã§ãã
æšæºãžã®6çªç®ã®äž»èŠãªæŽæ°ã§ããPCI 3.0ã¯1æ1æ¥ã«çºå¹ãããããã€ã³ãã©ã¹ãã©ã¯ãã£å šäœã確å®ã«æºããããã«ããŠããŸãã
ã¬ããŒã/ã¡ããªãã¯/ã¢ã©ãŒããã¬ããŒããã€ã³ãžã±ãŒã¿ã®æäŸãã¢ã©ãŒãã®çºè¡ãäœæ¥ã®äžéšã§ãã
次ã®ã¹ã©ã€ãã§ã¯ããšã³ããã€ã³ããä¿è·ããããã®å€ãã®è£œåã瀺ãããŠããŸãã ã¯ã·ãäžã«æãããŠããããã§ãã CrowdStrikeãšåŒã°ããããŒã«ããããçŸåšISïŒTéšéã§ãã¹ããããŠããŸãã äž»ã«ãã·ã¹ãã ã³ãŒã«ã®èŠ³ç¹ããç°åžžãªåäœã远跡ããŸãã
ããšãã°ãMS Wordã䜿çšããŠããŠãã·ã¹ãã ãã¢ã«ãŠã³ãããŒã¿ããŒã¹ãã·ã¹ãã ãŸãã¯ãã¹ã¯ãŒãã®æããèªã¿åãããšãããªã©ãããã°ã©ã ãå®è¡ãã¹ãã§ãªãããšãçªç¶éå§ããå ŽåãCrowdStrikeã¯ããã«ã€ããŠèŠåããã¢ã©ãŒã ãã©ã°ãã¹ããŒããŸãã ããã¯ã¯ã©ãŠãããŒã«ã§ããããã«ã€ããŠã¯åŸã§èª¬æããŸãã ãã®ããŒã¿ã¯ãã¹ãŠã»ã³ã¿ãŒã³ã³ãœãŒã«ã«éä¿¡ãããŸãããã¥ãŒãªã¹ãã£ãã¯ãªåäœã®èŠ³ç¹ããæãããªããã«ãã³ã³ãã¥ãŒã¿ãŒãæªæã®ããæäœãå®è¡ããããšãããšãã¬ãããã©ã°ã衚瀺ãããŸãã
GPO-ã°ã«ãŒãããªã·ãŒãªããžã§ã¯ãã¯ãã°ã«ãŒãã»ãã¥ãªãã£ããªã·ãŒãå®è£ ããã·ã¹ãã ã§ãã S-ãããã¯ãæªæã®ããã¢ããªã±ãŒã·ã§ã³ããŠã€ã«ã¹å¯Ÿçããšã³ããã€ã³ããä¿è·ããããã«è£œåãè³Œå ¥ããéã«æåŸ ããããã¹ãŠã®ãã®ããä¿è·ãããœãã©ã¹ã®ããããçš®é¡ã®ããã°ã©ã ã§ãã
PGPã¯ãæ©å¯ããŒã¿ãå«ããã£ã³ãã¹ã·ã¹ãã ã®ããŒããã©ã€ããæå·åããŸãã
ãããã®ããŒã«ã®äžéšã¯ãããé«åºŠãªããŒã«ã«çœ®ãæããããŠããŸãã æ¥çã§ã¯ãWindowsçšã®BitLockerãMacçšã®FileVaultãªã©ã®ãœãªã¥ãŒã·ã§ã³ã䜿çšãããã³ããŒäžç«ãªããªã·ãŒãžã®ç§»è¡ãé²ãã§ããããããã®ãªãã·ã§ã³ãæ€èšããŠããŸãã Casperã¯ãäž»ã«Mac OSã³ã³ãã¥ãŒã¿ãŒã®ã»ãã¥ãªãã£ããªã·ãŒã管çããŸãã
ãããã¯ãŒã¯ã»ãã¥ãªãã£ã«ã€ããŠã¯ããã®åéã§ã¢ã«ãã€ãšååããŠããŸããã¢ã«ãã€ã¯å®éã«MTIãéè·ããäŒç€Ÿã§ãããåæ¥çã®å€ããããã§åããŠããŸãã ãããã¯éåžžã«åªããã¡ã³ããã³ã¹ãæäŸãããããããããæäŸããå€ãã®ãµãŒãã¹ãå©çšããŸãã
åŸã§ãããã«ã€ããŠè©³ãã説æããŸãã
TippingPointã¯ããªã¹ã¯èå¥åã§ããäŸµå ¥æ€ç¥ã·ã¹ãã ã§ãã ç§ãèšã£ãããã«ããããã®ããŒã«ã®ããã€ãã¯çµ¶ããæ¹åãããŠãããTippingPointã¯äŸãšããŠåœ¹ç«ã¡ãŸãã 圌ã®ãããã§ãåœå¢ã«äŸµå ¥é²æ¢ã·ã¹ãã ããããŸãã å®éãç§ãã¡ã¯ããããé²æ¢ããã®ã§ã¯ãªããåã«ããããæ€åºããŸãã MITãããã¯ãŒã¯ã®ãšããžã§ã¯ãéåžžã«ã·ã³ãã«ã§åºãæ®åããŠããã¹ããŒãã£ã³ã°é²æ¢ã«ãŒã«ã䜿çšããŠäœããããã¯ããŸããã
Stealth Watchã¯ãNetFlowããŒã¿ãçæããããŒã«ããŸãã¯ããæ£ç¢ºã«ã¯NetFlowããŒã¿ãåéããããŒã«ã§ãã ã·ã¹ã³ã®ããã€ã¹ã䜿çšããŠããŸããããã¹ãŠã®ãããã¯ãŒã¯ããã€ã¹ã¯ã詳现ãéä¿¡ããã¹ããªãŒã ã®ã¡ã¿ããŒã¿ãéä¿¡å ããŒããå®å ããŒããéä¿¡å IPã¢ãã¬ã¹ãæçµIPã¢ãã¬ã¹ããããã³ã«ãªã©ãåŒãåºããŸãã StealthWatchã¯ãã®ããŒã¿ãåéããåºæ¬çãªã»ãã¥ãªãã£åæãå®è¡ããããã¹ããŒããªããšãè¡ãããã«äœ¿çšã§ããAPIãæäŸããŸãã
RSA Security Analyticsã¯ãã¹ããã€ãèå¥åãšããŠããŸããŸãªæ¹æ³ã§æ©èœããå¥ã®ããŒã«ã§ãã å®å šãªãã±ãããã£ããã£ãå®è¡ããããããèµ€ããã©ã°ãä»ããŠããå Žåã¯ãã®å 容ãèŠãããšãã§ããŸãã
ãªã¹ã¯èå¥ã®åéã§ã¯ãNessusã¯äžçš®ã®äºå®äžã®è匱æ§è©äŸ¡ããŒã«ã§ãã éåžžããªã³ããã³ãã§äœ¿çšããŸããã18/8ãããã¯ãŒã¯ã®ãµããã¡ã€ã³ã«å šäœãšããŠå±éããããšã¯ãããŸããã ãããããã£ã³ãã¹ãœãããŠã§ã¢çšã®DLCã¢ããªã³ãå ¥æããå ŽåãNessusã䜿çšããŠãããã®è匱æ§ãè©äŸ¡ããŸãã
Shodanã¯ã³ã³ãã¥ãŒã¿ãŒæ€çŽ¢ãšã³ãžã³ãšåŒã°ããŸãã åºæ¬çã«ãã€ã³ã¿ãŒãããå šäœãã¹ãã£ã³ãããã®ã»ãã¥ãªãã£ã«é¢ããå€ãã®æçšãªããŒã¿ãæäŸããŸãã ãã®ããšã³ãžã³ãã®ãµãã¹ã¯ãªãã·ã§ã³ãããããã®æ å ±ã䜿çšã§ããŸãã
Identity Finderã¯ãç»é²ããŒã¿ã®ä¿è·ã«é¢ããèŠåãé å®ããéèŠãªããŒã¿ãã©ãã«ãããã確èªããããã«ãPIIïŒæ©å¯å人æ å ±ïŒãããå Žæã§äœ¿çšããããŒã«ã§ãã
ã³ã³ãã¥ãŒã¿ãŒãã©ã¬ã³ãžãã¯ã¯ãç§ãã¡ãæã è¡ãåé¡ã§ã...ç§ãã¡ã¯å®æçã«ãããããªãã®ã§ãæ£ããèšèãèŠã€ããããšãã§ããŸããã ãã®ããã«ãããŒã«ã®ã»ããããããŸãã
EnCaseã¯ããã£ã¹ã¯ã€ã¡ãŒãžãååŸãããããã䜿çšããŠHDDã®å 容ã確èªã§ããããŒã«ã§ãã
FTKããŸãã¯ãã©ã¬ã³ãžãã¯ããŒã«ããã-ã³ã³ãã¥ãŒã¿ãŒãã©ã¬ã³ãžãã¯ã®åéã§èª¿æ»ãå®æœããããã®ããŒã«ã®ã»ããã ç¥ç財ç£ã®ç¢ºèªã®è«äºã®ããã±ãŒã¹ãæ€èšãããšãããŸãã¯OGC-ãŒãã©ã«ã«ãŠã³ã»ã«ã®äºåæãæ€èšããããã€ãã®ã±ãŒã¹ãæ€èšãããšãããã£ã¹ã¯ã€ã¡ãŒãžãæ®ãå¿ èŠããããšããæã ã¯ãã°ãã°é£çµ¡ãããŸãã ããã«å¿ èŠãªããŒã«ã¯ãã¹ãŠæã£ãŠããŸãã æ£çŽãªãšãããããã¯æ°žç¶çãªä»äºã§ã¯ãªããå®æçã«è¡šç€ºãããŸãã
ã§ã¯ããã®ããŒã¿ãã©ã®ããã«ãŸãšããŠåéããã®ã§ããããïŒ ããŒã¯ã®çžé¢é¢ä¿ã ã·ã¹ãã 管çã確å®ã«ããããã«ãã·ã¹ãã ãã°ãåŠçããŸãã NetFlowãã°ãäžéšã®DHCPãã°ãèå¥åãã°ãTouchstoneãã°ãããããšãããããŸãã
Splunkã¯ãçžé¢åŠçã®ã»ãšãã©ãå®è¡ããå¿ ãããæ£èŠåãããŠããªãããŒã¿ãåãåããããããæ£èŠåããããŸããŸãªãœãŒã¹ããã®ããŒã¿ãæ¯èŒããŠããããã€ã³ããªãžã§ã³ã¹ããååŸã§ããããŒã«ã§ãã ãããã£ãŠããã¹ãŠã®ãã°ã€ã³ãèšé²ãããããŒãžã衚瀺ããããã«GeoIPãé©çšããŠãã°ãªã³å Žæã衚瀺ã§ããŸãã
æ»æãã䜿çšããŠãããœãããŠã§ã¢ãããèå³æ·±ããã®ã«ã€ããŠè©±ããŸãããã æåã«ãéå»æ°å¹Žéã§æãäžè¬çãªãµãŒãã¹æåŠæ»æã«ã€ããŠèª¬æããŸãã ãŸããæ°å¹Žåã®ã¢ãŒãã³ã·ã¥ã¯ã«ãã®æ²åã®çµæãšããŠçºçããç¹å®ã®æ»æã«ã€ããŠã説æããŸãããããã¯ãåæ£DoSæ»æã«ãé¢é£ããŠããŸãã
次ã«ãABC DoSã玹ä»ããŸãã æåã®DoSæ»æã¯ãCIA Computer Security Triadã®æåAã察象ãšããŠããŸãã CIAã¯ãæ©å¯æ§-æ©å¯æ§ãæŽåæ§-æŽåæ§ãããã³å¯çšæ§-å¯çšæ§ã§æ§æãããç¥èªã§ãã ãããã£ãŠãDoSæ»æã®äž»ãªç®çã¯ãã¢ã¯ã»ã·ããªãã£ãå¯çšæ§ã§ãã æ»æè ã¯ãæ£åœãªãŠãŒã¶ãŒã䜿çšã§ããªãããã«ãªãœãŒã¹ãç¡å¹ã«ããããšããŠããŸãã
ããã¯ãããŒãžãæãªãå¯èœæ§ããããŸãã ãšãŠãç°¡åã§ãããïŒ ããžã¿ã«ã°ã©ãã£ãã£ã¯ããŒãžãåã«ç Žå£ããã ããªã®ã§ã誰ãèŠãããšãã§ããŸããã ããã¯å·šå€§ãªãªãœãŒã¹æ¶è²»ã«ãªãå¯èœæ§ããããæ»æã¯ã·ã¹ãã ã®ãã¹ãŠã®èšç®èœåãšãããã¯ãŒã¯åž¯åå¹ å šäœã䜿ãæãããŸãã ãã®æ»æã¯1人ã§å®è¡ã§ããŸãããããã«ãŒã¯å人ãæåŸ ããŠDDoSããŒãã£å šäœãã€ãŸãåæ£åãµãŒãã¹æåŠæ»æãä»æããå¯èœæ§ããããŸãã
çŸåšã®DDoSåŸåã¯ãArbor Networkã¬ããŒãã«ãªã¹ããããŠããŸãã ããã¯æ»æ察象é åã®æ¡åŒµã§ãããæãäžè¬çãªåæ©ä»ãã¯ãã¯ãã£ããºã ã§ããããã®ãããªæ»æã®æ倧40ïŒ ãå ããããã«39ïŒ ã®åæ©ä»ãã¯äžæã®ãŸãŸã§ãã å°ãªããšãæšå¹Žãæ»æã®åŒ·åºŠã¯100ã®ã¬ããã/ç§ã«éããŸããã 2012幎ã«ãSpamhausçµç¹ã§æ»æãçºçãã匷床ã¯300 Gb / sã«éããŸããã
DDoSæ»æãé·ããªããŸãã ãã®ãããç±³åœã®éèã»ã¯ã¿ãŒã«å¯Ÿããããã«ãŒæäœAbibalã¯æ°ã¶æç¶ããå®æçã«åŒ·åºŠã65ã®ã¬ããã/ç§ã«å¢ãããŸããã ããã«ã€ããŠèãããšããããã®æ»æã¯ã»ãŒç¶ç¶ããŠãããé»æ¢ã§ããªãã£ãããšãGoogleã§ç¢ºèªã§ããŸãã åŸã§ã圌ãããããã©ã®ããã«è¡ã£ããã«ã€ããŠã話ããŸãã
ããããæ£çŽã«èšããšã65 Gb / sãŸãã¯100 Gb / sã®å·®ã¯è¢«å®³è ã«ãšã£ãŠããã»ã©å€§ããã¯ãããŸãããäžçäžã®ã©ã®ã·ã¹ãã ãããã®èŠæš¡ã®é·æã«ãããæ»æã«èããããšã¯ãã£ãã«ãªãããã§ãã æè¿ããªãã¬ã¯ã·ã§ã³ãšã²ã€ã³æ»æãžã®ç§»è¡ããããŸããã ãããã¯ãå°ããªå ¥åä¿¡å·ãååŸããŠå€§ããªåºåä¿¡å·ã«å€æããæ»æã§ãã ããã¯æ°ããããšã§ã¯ãããŸãããICMPSmurfæ»æã«æ»ããŸãããã®æ»æã§ã¯ããããã¯ãŒã¯ã®ãããŒããã£ã¹ãã¢ãã¬ã¹ãšããã±ããã®éä¿¡è ã«å¿çãããããã¯ãŒã¯äžã®ãã¹ãŠã®ãã·ã³ã«pingãå®è¡ããŸãã ããšãã°ãMarkã®ãµããããŠããã®ã¯ã©ã¹ã®ãããŒããã£ã¹ãã¢ãã¬ã¹ã«ãã±ãããéä¿¡ããŸãã ãããŠãããªãã¯å šå¡ãããŒã¯ã«ãã±ããã§è¿ä¿¡ãå§ããããŒã¯ã圌ã«éä¿¡ãããšèããŸãã ãã®éãç§ã¯é ã«åº§ã£ãŠç¬ã£ãŠããŸãã åŠçãšããŠãã®æ¹æ³ã«ã€ããŠèªãã ã®ã§ãããã¯æ°ããããšã§ã¯ãããŸããã
ãããã£ãŠã次ã®ã¿ã€ãã®DDoSæ»æã¯UDPå¢å¹ ãã€ãŸããUDPå¢å¹ ãã§ãã UDPã¯ãŠãŒã¶ãŒããŒã¿ã°ã©ã ãããã³ã«ã®æžã蟌ã¿ãšå¿åŽã§ãã ããã¯TCPã§ã¯ãªããå®å šã«ä¿¡é Œæ§ãäœããå®å šãªæ¥ç¶ã®äœæã«çŠç¹ãåãããŠããŸããã åœé ã¯éåžžã«ç°¡åã§ãã éå»1幎éã«ç§ãã¡ãèŠããã®ã¯ãDNSãããŒã53ãUDPã®3ã€ã®ãããã³ã«ã®æ©èœã匷åããããã®ãšã¯ã¹ããã€ãã§ãã äžé©åã«æ§æããããµãŒããŒã«64ãã€ãã®ANYèŠæ±ãéä¿¡ãããšã512ãã€ãã®å¿çãçæãããæ»æã®è¢«å®³è ã«è¿ãããŸãã ããã¯8åã®ã²ã€ã³ã§ãããDoSæ»æã«ãšã£ãŠã¯æªããããŸããã
ãã®ã¿ã€ãã®æ»æã匷åããåŸåãçãããšããããããåæ¥éšéã®è¢«å®³è ã«å¯ŸããŠå€§éã«äœ¿çšãããåã«ãmit.netãããã¯ãŒã¯äžã§ããããç®æããŸããã çºä¿¡åž¯åå¹ ã«å€§ããªåœ±é¿ãäžãã12ã®ã¬ã®DNSå¢å¹ æ»æãèŠãŸããã ããªãé«ãã¹ã«ãŒãããããããŸããããã®ãããªéã®ããŒã¿ãåæ³çãªãã©ãã£ãã¯ã«è¿œå ãããšåé¡ãçºçããMarkãšç§ã¯ããã解決ããããåŸãŸããã§ããã
UDPããŒã161ãããã³ã«ã§ããSNMPã¯ãéåžžã«äŸ¿å©ãªç®¡çãããã³ã«ã§ãã get / setã¹ããŒãã¡ã³ãã䜿çšããŠããªã¢ãŒãã§ããŒã¿ãæäœã§ããŸãã ãããã¯ãŒã¯ããªã³ã¿ãŒãªã©ã®å€ãã®ããã€ã¹ã§ã¯ãèªèšŒãªãã§ã¢ã¯ã»ã¹ã§ããŸãã ãã ãããµã€ãºã64ãã€ãã®GetBulkRequestã¿ã€ãã®ãªã¯ãšã¹ãããæ£ããæ§æãããŠããªãããã€ã¹ã«éä¿¡ãããšãå¿çã被害è ã«éä¿¡ãããŸãããã®ãµã€ãºã¯ããªã¯ãšã¹ãã®ãµã€ãºã1000åè¶ ããŸãã ãããã£ãŠãããã¯ä»¥åã®ããŒãžã§ã³ãããããã«åªããŠããŸãã
éåžžãæ»æè ã¯æšçåæ»æãéžæããããããã£ã³ãã¹ãããã¯ãŒã¯ã«ããããªã³ã¿ãŒã«å¯Ÿãã倧èŠæš¡ãªæ»æãç®æããŠããŸãã éããŠããSNMPãšãŒãžã§ã³ããåããããªã³ã¿ãŒã䜿çšããŠãããã«ãŒã¯åœŒã«ãã±ãããéä¿¡ããå¿çã®ãµã€ãºã1000åã«å¢å ãããšãã€ã³ã¿ãŒããããããã¯ãŒã¯å šäœãæ±æãããŸããã
以äžã¯ãã¿ã€ã ãµãŒããŒãããã³ã«ããŸãã¯NTPãããã¯ãŒã¯ã¿ã€ã ãããã³ã«ã§ãã ããã䜿çšãããšãæ£ããæ§æãããŠããªããµãŒããŒããMONLISTããªã¯ãšã¹ãã«å¿çããŸãã ããã§ã¯ãæ»æã®åºç€ã¯å¢å¹ ã§ã¯ãªãã600åã®æè¿ã®NTPã¯ã©ã€ã¢ã³ãã®ãªã¹ãã®åœ¢åŒã§ã®monlistèŠæ±ãžã®å¿çã§ãã ãããã£ãŠãææããã³ã³ãã¥ãŒã¿ãŒããã®å°ããªãªã¯ãšã¹ãã¯ã倧ããªUDPãã©ãã£ãã¯ã被害è ã«éä¿¡ããŸãã
ããã¯éåžžã«äžè¬çãªã¿ã€ãã®æ»æã§ãããNTPã¢ã³ãªã¹ãã®èšå®ãæ£ãããªãããã倧ããªå€æŽãå ããããŸããã æåŸã«ããããã®æ»æã軜æžããããã«ããã€ãã®ããšãè¡ããŸããã ãã®ãããNTPåŽã§ã¯ãNTPãµãŒããŒã§monlistã³ãã³ããç¡å¹ã«ããŸãããããã«ããããã®ãã©ãã¯ã§æ»æãã殺ããããšãã§ããŸããã ããããç§ãã¡ã«ã¯åœå®¶æ©é¢ãããã®ã§ãç§ãã¡ã«ã¯é¢ä¿ããæš©å©ããªããã®ããããŸãããããã£ãŠãç§ãã¡ã¯åœå±ãèš±å¯ããéãã¢ã³ãªã¹ããç¡å¹ã«ããŸããã æçµçã«ã¯ãMITãããã¯ãŒã¯ã®ãšããžã§NTPã®é床ãå¶éããã ãã§ãå¿çããã·ã¹ãã ã®åœ±é¿ã軜æžãã1幎éããã€ãã¹ã®åœ±é¿ãªãã«ååšããŠããŸãã æ°ã¡ã¬ãããã®é床å¶éã¯ã以åã«ã€ã³ã¿ãŒãããã«éä¿¡ããã®ã¬ãã€ãããã確ãã«åªããŠããŸãã ããã¯è§£æ±ºå¯èœãªåé¡ã§ãã
DNSã»ãã¥ãªãã£ã®é¢åãèŠãã®ã¯ããå°ãè€éã§ãã eDNSãšåŒã°ããAkamaiãµãŒãã¹ã®äœ¿çšãéå§ããŸããã ã¢ã«ãã€ã¯ãã®ãµãŒãã¹ãå ±æãã¹ãã£ã³ã°ãŸãŒã³ãšããŠæäŸããŠãããããeDNAã䜿çšããŠãã·ã¹ãã ãã¡ã€ã³åã¹ããŒã¹ã§ããDNSã2å±€ã«åå²ããŸããã Akamaiã«å€éšãã¥ãŒã®å€éšå±€ãé 眮ããåžžã«MITã«ãµãŒãã¹ãæäŸãããµãŒããŒã«å éšå éšãã¥ãŒãé 眮ããŸããã MITã¯ã©ã€ã¢ã³ãã®ã¿ãå éšãµãŒããŒã«ã¢ã¯ã»ã¹ã§ããããã«å éšãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ããããã¯ãããã®ä»ã®å°åã¯ã¢ã«ãã€ã®ç®¡çäžã«çœ®ãããŸããã
Akamaiã®eDNSã®å©ç¹ã¯ãäžçäžã®ã€ã³ã¿ãŒãããäžã§é ä¿¡ãããã³ã³ãã³ãã§ããããã¯ãã¢ãžã¢ããšãŒããããåç±³ãæ±éšã西éšããã³ã³ãã³ããé ä¿¡ããå°ççã«åæ£ãããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã§ãã ããã«ãŒã¯ã¢ã«ãã€ãç Žå£ã§ããªããããDNSãåæ¢ããããšãå¿é ããå¿ èŠã¯ãããŸããã ããããã®åé¡ã®è§£æ±ºæ¹æ³ã§ãã
次ã®ãã¬ãŒã³ããŒã·ã§ã³ã®ã¹ã©ã€ãã¯ãDDoSæ»æãå®è¡ããæ¹æ³ã瀺ããŠããŸãã æåã®ãœãŒã¹é£èªåã¯ãæ»æè ã®å®éã®ã¢ãã¬ã¹ãé ãããšã§ãã ããã¯ãæ€åºãšèµ·èšŽãåé¿ããããã§ãã 詳现ã¯èª¬æããããã®ã¹ã©ã€ããã¹ãããããŸãã
DDoSæ»æãå®è£ ãã次ã®æ¹æ³ã¯ããããããããããã¯ãŒã¯ãäœæããããšã§ãã æ»æã®æå³ã¯ããããã䜿çšããŠæµã®ãããã¯ãŒã¯ãç Žå£ããããšã§ãã
ãããããããããã¯ãŒã¯ã¯çŸåšã巚倧ã§ãã «itsoknoproblembro» ( , , ) Ababil, . «brobot» Wordpress Joomla.
, , , , . , . , , , TCP SYN-ACK, , HTTP- GET POST.
DDoS- . â , .
, -, , Ragebooter. , , DDoS- . , , PayPal.
DDoS-. DNS- , Akamai. .
-, . , , MIT. «» -. , DNS. MIT. MIT Akamai, DNS, Akamai.
, MIT, CDN- Akamai, . - , , MIT Akamai, Akamai , . , , - - Akamai.
, NTP, . , brute-force, . , . , ?
, , ? , , , . ? , , .
BGP. BGP, , , . , ASN. ASN, BGP , , ASN.
123, . , , 11 , .
, , ASN123, â ASN789. ASE, .
BGP ASN, MIT. ASN456. « », . , 18.1.2.3.0/24 255 MIT , ASN456 .
, . AS Akamai. , .
, «», . , .
, , ?
: MIT, , .
: . MIT : External 1, External 2 External 3. MIT. , , . , 3 E1,2,3, . , . 3, , . .
, , BGP, . â , .
, , , 2 , MIT, . , .
. . , . , .
, E1,2,3, , , « ».
, 100 /, , . , «» . , . mit.net, .
. , , Patriots -. , - , . , .
, , ? . , IP- VPN. , . , .
: , ?
: , , . web.mit.edu. , DNS-. web.mit.edu -, . HTTP- GET/POST, , GET POST. , -, . , , . , , IP-. , , , , , «».
, . , - . , , , Akamai CDN. , MIT web.mit, 18.09.22 . C, , IP- Akamai.
mit.net, . www.mitããã³web.mit-ã³ã³ãã³ãã¯ãã®ç»åã«çœ®ãæããããŸãããWebãµãŒããŒã§è¿ éã«èšºæãè¡ããŸããããã¹ãŠãçŽ æŽãããèŠãããµãŒããŒã¯ãããã³ã°ãããŠããŸãããã€ãŸããããŒãžã¯å¥ã®æ¹æ³ã§ç ŽæããŠããŸããã
æçµçã«ãååãšDNSã®who_isæ å ±ãæ©èœããªãã£ãããšãããããŸããããã®ã¹ã©ã€ãã§ã¯ãããã«ãŒã«ããã管çé£çµ¡å ããããã¯ã®å€æŽã衚瀺ãããŸã-ãç§ã¯ããã管çããŸãã-ããµãã¥ãŒã»ããå·¥ç§å€§åŠããšãç Žå£ããããããã¯ãŒã¯æäœã®ã¢ãã¬ã¹-DESTROYEDãMA 02139-4307ã
æ»æè ã¯ç§ãã¡ãç¹ã«æšçã«ããŸãããããããã¯ãã¹ãŠ2ã€ã®CloudFlareãã¹ãã£ã³ã°ãããã€ããŒã«å§ä»»ãããŸããã
58:30å
MITã³ãŒã¹ãã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã®ã»ãã¥ãªãã£ãã è¬çŸ©22ïŒãæ å ±ã»ãã¥ãªãã£MITããããŒã3
ã³ãŒã¹ã®å®å šçã¯ãã¡ãããå ¥æã§ããŸã ã
ãæ»åšããã ãããããšãããããŸãã ç§ãã¡ã®èšäºã奜ãã§ããïŒ ããèå³æ·±ãè³æãèŠããã§ããïŒ æ³šæããããå人ã«æšèŠããããšã§ãç§ãã¡ããµããŒãããŸããç§ãã¡ãããªãã®ããã«çºæãããšã³ããªãŒã¬ãã«ã®ãµãŒããŒã®ãŠããŒã¯ãªã¢ããã°ã®HabrãŠãŒã¶ãŒã®ããã«30ïŒ ã®å²åŒïŒ VPSïŒKVMïŒE5-2650 v4ïŒ6ã³ã¢ïŒã«ã€ããŠã®çå®20ãã«ãŸãã¯ãµãŒããŒãåå²ããæ¹æ³ïŒ ïŒãªãã·ã§ã³ã¯RAID1ããã³RAID10ãæ倧24ã³ã¢ãæ倧40GB DDR4ã§å©çšå¯èœã§ãïŒã
VPSïŒKVMïŒE5-2650 v4ïŒ6ã³ã¢ïŒ10GB DDR4 240GB SSD 1GbpsãŸã§1ãæéç¡æã§6ãæã®æéããæ¯æãã®å Žåã¯ã ãã¡ãã§æ³šæã§ããŸã ã
Dell R730xdã¯2åå®ãã§ããïŒ ãªã©ã³ããšç±³åœã§249ãã«ããIntel Dodeca-Core Xeon E5-2650v4 128GB DDR4 6x480GB SSD 1Gbps 100 TVã2å°æã£ãŠããã ãã§ãïŒ ã€ã³ãã©ã¹ãã©ã¯ãã£ãã«ã®æ§ç¯æ¹æ³ã«ã€ããŠèªãã§ãã ããã ã¯ã©ã¹Rã¯ã1ç±³ãã«ã§9,000ãŠãŒãã®Dell R730xd E5-2650 v4ãµãŒããŒã䜿çšããŠããŸããïŒ