ืžื” ื–ื” ืžื” ื•ืžื™ ื–ื” ืžื™ ื‘ืฉื•ืง ื”ื’ื ืช DDoS

"ื”ื‘ื—ื•ืจ ืฉื™ืฆืจ ืืช ื”ืืชืจ ืฉืœื ื• ื›ื‘ืจ ื”ื’ื“ื™ืจ ื”ื’ื ืช DDoS."
"ื™ืฉ ืœื ื• ื”ื’ื ืช DDoS, ืœืžื” ื”ืืชืจ ื ืคืœ?"
"ื›ืžื” ืืœืคื™ื ืจื•ืฆื” Qrator?"

ืขืœ ืžื ืช ืœืขื ื•ืช ื‘ืฆื•ืจื” ื ื›ื•ื ื” ืขืœ ืฉืืœื•ืช ื›ืืœื• ืžื”ืœืงื•ื—/ื”ื‘ื•ืก, ื™ื”ื™ื” ื ื—ืžื“ ืœื“ืขืช ืžื” ืžืกืชืชืจ ืžืื—ื•ืจื™ ื”ืฉื "ื”ื’ื ืช DDoS". ื‘ื—ื™ืจืช ืฉื™ืจื•ืชื™ ืื‘ื˜ื—ื” ื“ื•ืžื” ื™ื•ืชืจ ืœื‘ื—ื™ืจืช ืชืจื•ืคื” ืžืจื•ืคื ืžืืฉืจ ื‘ื—ื™ืจืช ืฉื•ืœื—ืŸ ื‘ืื™ืงืื”.

ืื ื™ ืชื•ืžืš ื‘ืืชืจื™ื ื›ื‘ืจ 11 ืฉื ื™ื, ืฉืจื“ืชื™ ืžืื•ืช ื”ืชืงืคื•ืช ืขืœ ื”ืฉื™ืจื•ืชื™ื ืฉื‘ื”ื ืื ื™ ืชื•ืžืš, ื•ืขื›ืฉื™ื• ืืกืคืจ ืœื›ื ืงืฆืช ืขืœ ืคืขื•ืœืช ื”ื”ื’ื ื” ื”ืคื ื™ืžื™ืช.
ืžื” ื–ื” ืžื” ื•ืžื™ ื–ื” ืžื™ ื‘ืฉื•ืง ื”ื’ื ืช DDoS
ื”ืชืงืคื•ืช ืงื‘ื•ืขื•ืช. ืกื”"ื› 350 ื“ืจื™ืฉื•ืช, 52 ื“ืจื™ืฉื•ืช ืœื’ื™ื˜ื™ืžื™ื•ืช

ื”ื”ืชืงืคื•ืช ื”ืจืืฉื•ื ื•ืช ื”ื•ืคื™ืขื• ื›ืžืขื˜ ื‘ืžืงื‘ื™ืœ ืœืื™ื ื˜ืจื ื˜. DDoS ื›ืชื•ืคืขื” ื”ืคื›ื” ืœื ืคื•ืฆื” ืžืื– ืกื•ืฃ ืฉื ื•ืช ื”-2000 (ื‘ื“ื•ืง www.cloudflare.com/learning/ddos/famous-ddos-attacks).
ืžืื– 2015-2016 ื‘ืขืจืš, ื›ืžืขื˜ ื›ืœ ืกืคืงื™ ื”ืื—ืกื•ืŸ ื”ื™ื• ืžื•ื’ื ื™ื ืžืคื ื™ ื”ืชืงืคื•ืช DDoS, ื•ื›ืš ื’ื ื”ืืชืจื™ื ื”ื‘ื•ืœื˜ื™ื ื‘ืื–ื•ืจื™ื ืชื—ืจื•ืชื™ื™ื (ืชืขืฉื” whois ืœืคื™ IP ืฉืœ ื”ืืชืจื™ื eldorado.ru, leroymerlin.ru, tilda.ws, ืชืจืื” ืืช ื”ืจืฉืชื•ืช ืฉืœ ืžืคืขื™ืœื™ ื”ื’ื ื”).

ืื ืœืคื ื™ 10-20 ืฉื ื” ื ื™ืชืŸ ื”ื™ื” ืœื”ื“ื•ืฃ ืืช ืจื•ื‘ ื”ื”ืชืงืคื•ืช ื‘ืฉืจืช ืขืฆืžื• (ื”ืขืจืš ืืช ื”ื”ืžืœืฆื•ืช ืฉืœ ืžื ื”ืœ ื”ืžืขืจื›ืช Lenta.ru ืžืงืกื™ื ืžื•ืฉืงื•ื‘ ืžืฉื ื•ืช ื”-90: lib.ru/WEBMASTER/sowetywww2.txt_with-big-pictures.html#10), ืืš ื›ืขืช ืžืฉื™ืžื•ืช ื”ื”ื’ื ื” ื”ืคื›ื• ืœืงืฉื•ืช ื™ื•ืชืจ.

ืกื•ื’ื™ ื”ืชืงืคื•ืช DDoS ืžื ืงื•ื“ืช ืžื‘ื˜ ืฉืœ ื‘ื—ื™ืจืช ืžืคืขื™ืœ ื”ื’ื ื”

ื”ืชืงืคื•ืช ื‘ืจืžืช L3/L4 (ืœืคื™ ื“ื’ื OSI)

- ื”ืฆืคืช UDP ืžืจืฉืช ื‘ื•ื˜ (ื‘ืงืฉื•ืช ืจื‘ื•ืช ื ืฉืœื—ื•ืช ื™ืฉื™ืจื•ืช ืžืžื›ืฉื™ืจื™ื ื ื’ื•ืขื™ื ืœืฉื™ืจื•ืช ื”ืžื•ืชืงืฃ, ื”ืฉืจืชื™ื ื—ืกื•ืžื™ื ื‘ืขืจื•ืฅ);
โ€” ื”ื’ื‘ืจืช DNS/NTP/ื•ื›ื•' (ื‘ืงืฉื•ืช ืจื‘ื•ืช ื ืฉืœื—ื•ืช ืžืžื›ืฉื™ืจื™ื ื ื’ื•ืขื™ื ืœ-DNS/NTP/ื•ื›ื•' ืคื’ื™ืข, ื›ืชื•ื‘ืช ื”ืฉื•ืœื— ืžื–ื•ื™ืคืช, ืขื ืŸ ืฉืœ ืžื ื•ืช ื”ืžื’ื™ื‘ื•ืช ืœื‘ืงืฉื•ืช ืžืฆื™ืฃ ืืช ื”ืขืจื•ืฅ ืฉืœ ื”ืื“ื ื”ืžื•ืชืงืฃ; ื›ืš ื”ื›ื™ ื”ืจื‘ื” ืžืชืงืคื•ืช ืžืกื™ื‘ื™ื•ืช ืžืชื‘ืฆืขื•ืช ื‘ืื™ื ื˜ืจื ื˜ ื”ืžื•ื“ืจื ื™);
- SYN / ACK ื”ืฆืคื” (ื‘ืงืฉื•ืช ืจื‘ื•ืช ืœื™ืฆื™ืจืช ื—ื™ื‘ื•ืจ ื ืฉืœื—ื•ืช ืœืฉืจืชื™ื ื”ืžื•ืชืงืคื™ื, ืชื•ืจ ื”ื—ื™ื‘ื•ืจ ืขื•ืœื” ืขืœ ื’ื“ื•ืชื™ื•);
- ื”ืชืงืคื•ืช ืขื ืคื™ืฆื•ืœ ืžื ื•ืช, ping of death, ping flood (ื’ื•ื’ืœ ื‘ื‘ืงืฉื”);
- ื•ื›ื•ืœื™.

ื”ืชืงืคื•ืช ืืœื• ืžื˜ืจืชืŸ "ืœืกืชื•ื" ืืช ืขืจื•ืฅ ื”ืฉืจืช ืื• "ืœื”ืจื•ื’" ืืช ื™ื›ื•ืœืชื• ืœืงื‘ืœ ืชืขื‘ื•ืจื” ื—ื“ืฉื”.
ืœืžืจื•ืช ื”ื”ืฆืคื” ื•ื”ื”ื’ื‘ืจื” ืฉืœ SYN/ACK ืฉื•ื ื™ื ืžืื•ื“, ื—ื‘ืจื•ืช ืจื‘ื•ืช ื ืœื—ืžื•ืช ื‘ื”ื ื‘ืื•ืชื” ืžื™ื“ื”. ืžืชืขื•ืจืจื•ืช ื‘ืขื™ื•ืช ื‘ื”ืชืงืคื•ืช ืžื”ืงื‘ื•ืฆื” ื”ื‘ืื”.

ื”ืชืงืคื•ืช ืขืœ L7 (ืฉื›ื‘ืช ืืคืœื™ืงืฆื™ื”)

- http flood (ืื ืืชืจ ืื™ื ื˜ืจื ื˜ ืื• http API ืžื•ืชืงืฃ);
- ื”ืชืงืคื” ืขืœ ืื–ื•ืจื™ื ืคื’ื™ืขื™ื ื‘ืืชืจ (ื›ืืœื” ืฉืื™ืŸ ืœื”ื ืžื˜ืžื•ืŸ, ืฉืžืขืžื™ืกื™ื ืืช ื”ืืชืจ ื‘ื›ื‘ื“ื•ืช ื•ื›ื•').

ื”ืžื˜ืจื” ื”ื™ื ืœื’ืจื•ื ืœืฉืจืช "ืœืขื‘ื•ื“ ืงืฉื”", ืœืขื‘ื“ ื”ืจื‘ื” "ื‘ืงืฉื•ืช ืืžื™ืชื™ื•ืช ืœื›ืื•ืจื”" ื•ืœื”ื™ืฉืืจ ืœืœื ืžืฉืื‘ื™ื ืœื‘ืงืฉื•ืช ืืžื™ืชื™ื•ืช.

ืœืžืจื•ืช ืฉื™ืฉื ืŸ ื”ืชืงืคื•ืช ืื—ืจื•ืช, ืืœื• ื”ืŸ ื”ื ืคื•ืฆื•ืช ื‘ื™ื•ืชืจ.

ื”ืชืงืคื•ืช ืจืฆื™ื ื™ื•ืช ื‘ืจืžืช L7 ื ื•ืฆืจื•ืช ื‘ืฆื•ืจื” ื™ื™ื—ื•ื“ื™ืช ืขื‘ื•ืจ ื›ืœ ืคืจื•ื™ืงื˜ ืฉืžื•ืชืงืฃ.

ืœืžื” 2 ืงื‘ื•ืฆื•ืช?
ื›ื™ ื™ืฉ ืจื‘ื™ื ืฉื™ื•ื“ืขื™ื ืœื”ื“ื•ืฃ ื”ืชืงืคื•ืช ื˜ื•ื‘ ื‘ืจืžืช L3/L4, ืื‘ืœ ืื• ืฉืœื ืชื•ืคืกื™ื ื”ื’ื ื” ื‘ืจืžืช ื”ืืคืœื™ืงืฆื™ื” (L7) ื‘ื›ืœืœ, ืื• ืฉืขื“ื™ื™ืŸ ื—ืœืฉื™ื ื™ื•ืชืจ ืžื—ืœื•ืคื•ืช ื‘ื”ืชืžื•ื“ื“ื•ืช ืื™ืชืŸ.

ืžื™ ื–ื” ืžื™ ื‘ืฉื•ืง ื”ื’ื ืช DDoS

(ื“ืขืชื™ ื”ืื™ืฉื™ืช)

ื”ื’ื ื” ื‘ืจืžืช L3/L4

ื›ื“ื™ ืœื”ื“ื•ืฃ ื”ืชืงืคื•ืช ื‘ืืžืฆืขื•ืช ื”ื’ื‘ืจื” ("ื—ืกื™ืžื”" ืฉืœ ืขืจื•ืฅ ื”ืฉืจืช), ื™ืฉ ืžืกืคื™ืง ืขืจื•ืฆื™ื ืจื—ื‘ื™ื (ืจื‘ื™ื ืžืฉื™ืจื•ืชื™ ื”ื”ื’ื ื” ืžืชื—ื‘ืจื™ื ืœืจื•ื‘ ืกืคืงื™ ืขืžื•ื“ ื”ืฉื“ืจื” ื”ื’ื“ื•ืœื™ื ื‘ืจื•ืกื™ื” ื•ื™ืฉ ืœื”ื ืขืจื•ืฆื™ื ื‘ืขืœื™ ืงื™ื‘ื•ืœืช ืชื™ืื•ืจื˜ื™ืช ืฉืœ ื™ื•ืชืจ ืž-1 Tbit). ืืœ ืชืฉื›ื— ืฉื”ืชืงืคื™ ื”ื’ื‘ืจื” ื ื“ื™ืจื™ื ืžืื•ื“ ื ืžืฉื›ื™ื ื™ื•ืชืจ ืžืฉืขื”. ืื ืืชื” Spamhaus ื•ื›ื•ืœื ืœื ืื•ื”ื‘ื™ื ืื•ืชืš, ื›ืŸ, ื”ื ืขืฉื•ื™ื™ื ืœื ืกื•ืช ืœืกื’ื•ืจ ืืช ื”ืขืจื•ืฆื™ื ืฉืœืš ืœืžืกืคืจ ื™ืžื™ื, ืืคื™ืœื• ืชื•ืš ืกื™ื›ื•ืŸ ืฉืœ ื”ื™ืฉืจื“ื•ืช ื ื•ืกืคืช ืฉืœ ืจืฉืช ื”ื‘ื•ื˜ ื”ื’ืœื•ื‘ืœื™ืช ื‘ืฉื™ืžื•ืฉ. ืื ื™ืฉ ืœืš ืจืง ื—ื ื•ืช ืžืงื•ื•ื ืช, ื’ื ืื ื”ื™ื mvideo.ru, ืœื ืชืจืื” 1 Tbit ื‘ืชื•ืš ื›ืžื” ื™ืžื™ื ื‘ืงืจื•ื‘ ืžืื•ื“ (ืื ื™ ืžืงื•ื•ื”).

ื›ื“ื™ ืœื”ื“ื•ืฃ ื”ืชืงืคื•ืช ืขื ื”ืฆืคื” SYN/ACK, ืคื™ืฆื•ืœ ืžื ื•ืช ื•ื›ื•', ืืชื” ืฆืจื™ืš ืฆื™ื•ื“ ืื• ืžืขืจื›ื•ืช ืชื•ื›ื ื” ื›ื“ื™ ืœื–ื”ื•ืช ื•ืœืขืฆื•ืจ ื”ืชืงืคื•ืช ื›ืืœื”.
ืื ืฉื™ื ืจื‘ื™ื ืžื™ื™ืฆืจื™ื ืฆื™ื•ื“ ื›ื–ื” (ืืจื‘ื•ืจ, ื™ืฉ ืคืชืจื•ื ื•ืช ืฉืœ ืกื™ืกืงื•, Huawei, ื”ื˜ืžืขื•ืช ืชื•ื›ื ื” ืฉืœ Wanguard ื•ื›ื•'), ืžืคืขื™ืœื™ ืขืžื•ื“ ืฉื“ืจื” ืจื‘ื™ื ื›ื‘ืจ ื”ืชืงื™ื ื• ืื•ืชื• ื•ืžื•ื›ืจื™ื ืฉื™ืจื•ืชื™ ื”ื’ื ืช DDoS (ืื ื™ ื™ื•ื“ืข ืขืœ ื”ืชืงื ื•ืช ืฉืœ Rostelecom, Megafon, TTK, MTS , ืœืžืขืฉื”, ื›ืœ ื”ืกืคืงื™ื ื”ื’ื“ื•ืœื™ื ืขื•ืฉื™ื ืืช ืื•ืชื• ื”ื“ื‘ืจ ืขื ืžืืจื—ื™ื ืขื ื”ื’ื ื” ืžืฉืœื”ื a-la OVH.com, Hetzner.de, ืื ื™ ืขืฆืžื™ ื ืชืงืœืชื™ ื‘ื”ื’ื ื” ื‘-ihor.ru). ื—ืœืง ืžื”ื—ื‘ืจื•ืช ืžืคืชื—ื•ืช ืคืชืจื•ื ื•ืช ืชื•ื›ื ื” ืžืฉืœื”ืŸ (ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ื›ืžื• DPDK ืžืืคืฉืจื•ืช ืœืš ืœืขื‘ื“ ืขืฉืจื•ืช ื’ื™ื’ื”-ื‘ื™ื˜ ืฉืœ ืชืขื‘ื•ืจื” ืขืœ ืžื—ืฉื‘ x86 ืคื™ื–ื™ ืื—ื“).

ืžื‘ื™ืŸ ื”ืฉื—ืงื ื™ื ื”ืžื•ื›ืจื™ื, ื›ื•ืœื ื™ื›ื•ืœื™ื ืœื”ื™ืœื—ื ื‘-L3/L4 DDoS ื‘ืฆื•ืจื” ื™ืขื™ืœื” ืคื—ื•ืช ืื• ื™ื•ืชืจ. ืขื›ืฉื™ื• ืื ื™ ืœื ืื’ื™ื“ ืœืžื™ ื™ืฉ ืืช ืงื™ื‘ื•ืœืช ื”ืขืจื•ืฅ ื”ืžืงืกื™ืžืœื™ืช ื”ื’ื“ื•ืœื” ื™ื•ืชืจ (ื–ื”ื• ืžื™ื“ืข ืคื ื™ืžื™), ืื‘ืœ ื‘ื“ืจืš ื›ืœืœ ื–ื” ืœื ื›ืœ ื›ืš ื—ืฉื•ื‘, ื•ื”ื”ื‘ื“ืœ ื”ื™ื—ื™ื“ ื”ื•ื ื‘ืื™ื–ื• ืžื”ื™ืจื•ืช ื”ื”ื’ื ื” ืžื•ืคืขืœืช (ืžื™ื™ื“ื™ืช ืื• ืื—ืจื™ ื›ืžื” ื“ืงื•ืช ืฉืœ ื”ืฉื‘ืชื” ืฉืœ ื”ืคืจื•ื™ืงื˜, ื›ืžื• ื‘ื”ืฆื ืจ).
ื”ืฉืืœื” ื”ื™ื ืขื“ ื›ืžื” ื–ื” ื ืขืฉื”: ืžืชืงืคืช ื”ื’ื‘ืจื” ื™ื›ื•ืœื” ืœื”ื“ื•ืฃ ืขืœ ื™ื“ื™ ื—ืกื™ืžืช ืชืขื‘ื•ืจื” ืžืžื“ื™ื ื•ืช ืขื ื›ืžื•ืช ื”ืชืขื‘ื•ืจื” ื”ืžื–ื™ืงื” ื”ื’ื“ื•ืœื” ื‘ื™ื•ืชืจ, ืื• ืฉืจืง ืชืขื‘ื•ืจื” ืžื™ื•ืชืจืช ื‘ืืžืช ื™ื›ื•ืœื” ืœื”ื™ืคื˜ืจ.
ืื‘ืœ ื™ื—ื“ ืขื ื–ืืช, ืขืœ ืกืžืš ื”ื ื™ืกื™ื•ืŸ ืฉืœื™, ื›ืœ ืฉื—ืงื ื™ ื”ืฉื•ืง ื”ืจืฆื™ื ื™ื™ื ืžืชืžื•ื“ื“ื™ื ืขื ื–ื” ืœืœื ื‘ืขื™ื•ืช: Qrator, DDoS-Guard, Kaspersky, G-Core Labs (ืœืฉืขื‘ืจ SkyParkCDN), ServicePipe, Stormwall, Voxility ื•ื›ื•'.
ืœื ื ืชืงืœืชื™ ื‘ื”ื’ื ื” ืžืคื ื™ ืžืคืขื™ืœื™ื ื›ืžื• Rostelecom, Megafon, TTK, Beeline; ืœืคื™ ื‘ื™ืงื•ืจื•ืช ืฉืœ ืขืžื™ืชื™ื, ื”ื ืžืกืคืงื™ื ืืช ื”ืฉื™ืจื•ืชื™ื ื”ืืœื” ื“ื™ ื˜ื•ื‘, ืื‘ืœ ืขื“ ื›ื” ื—ื•ืกืจ ื”ื ื™ืกื™ื•ืŸ ืžืฉืคื™ืข ืžืขืช ืœืขืช: ืœืคืขืžื™ื ืืชื” ืฆืจื™ืš ืœืฆื‘ื•ื˜ ืžืฉื”ื• ื“ืจืš ื”ืชืžื™ื›ื” ืฉืœ ืžืคืขื™ืœ ื”ืžื™ื’ื•ืŸ.
ืœื—ืœืง ืžื”ืžืคืขื™ืœื™ื ื™ืฉ ืฉื™ืจื•ืช ื ืคืจื“ "ื”ื’ื ื” ืžืคื ื™ ื”ืชืงืคื•ืช ื‘ืจืžืช L3/L4", ืื• "ื”ื’ื ื” ืขืœ ืขืจื•ืฅ"; ื–ื” ืขื•ืœื” ื”ืจื‘ื” ืคื—ื•ืช ืžื”ื’ื ื” ื‘ื›ืœ ื”ืจืžื•ืช.

ืžื“ื•ืข ืกืคืง ืขืžื•ื“ ื”ืฉื“ืจื” ืื™ื ื• ื“ื•ื—ื” ื”ืชืงืคื•ืช ืฉืœ ืžืื•ืช Gbits, ืžื›ื™ื•ื•ืŸ ืฉืื™ืŸ ืœื” ืขืจื•ืฆื™ื ืžืฉืœื”?ืžืคืขื™ืœ ื”ื”ื’ื ื” ื™ื›ื•ืœ ืœื”ืชื—ื‘ืจ ืœื›ืœ ืื—ื“ ืžื”ืกืคืงื™ื ื”ื’ื“ื•ืœื™ื ื•ืœื”ื“ื•ืฃ ื”ืชืงืคื•ืช "ืขืœ ื—ืฉื‘ื•ื ื•". ืชืฆื˜ืจืš ืœืฉืœื ืขื‘ื•ืจ ื”ืขืจื•ืฅ, ืื‘ืœ ื›ืœ ืžืื•ืช ื”-Gbits ื”ืืœื” ืœื ืชืžื™ื“ ื™ื ื•ืฆืœื•; ื™ืฉ ืืคืฉืจื•ื™ื•ืช ืœื”ื•ื–ื™ืœ ืžืฉืžืขื•ืชื™ืช ืืช ืขืœื•ืช ื”ืขืจื•ืฆื™ื ื‘ืžืงืจื” ื–ื”, ื›ืš ืฉื”ืชื•ื›ื ื™ืช ื ืฉืืจืช ื‘ืจ-ื‘ื™ืฆื•ืข.
ืžื” ื–ื” ืžื” ื•ืžื™ ื–ื” ืžื™ ื‘ืฉื•ืง ื”ื’ื ืช DDoS
ืืœื• ื”ื“ื™ื•ื•ื—ื™ื ืฉืงื™ื‘ืœืชื™ ื‘ืื•ืคืŸ ืงื‘ื•ืข ืžื”ื’ื ื” ื‘ืจืžื” ื’ื‘ื•ื”ื” ื™ื•ืชืจ ืฉืœ L3/L4 ืชื•ืš ืชืžื™ื›ื” ื‘ืžืขืจื›ื•ืช ืฉืœ ืกืคืง ื”ืื™ืจื•ื—.

ื”ื’ื ื” ื‘ืจืžืช L7 (ืจืžืช ืืคืœื™ืงืฆื™ื”)

ื”ืชืงืคื•ืช ื‘ืจืžืช L7 (ืจืžืช ื™ื™ืฉื•ื) ืžืกื•ื’ืœื•ืช ืœื”ื“ื•ืฃ ื™ื—ื™ื“ื•ืช ื‘ืื•ืคืŸ ืขืงื‘ื™ ื•ื™ืขื™ืœ.
ื™ืฉ ืœื™ ื“ื™ ื”ืจื‘ื” ื ื™ืกื™ื•ืŸ ืืžื™ืชื™ ืขื
- Qrator.net;
- DDoS-Guard;
- ืžืขื‘ื“ื•ืช G-Core;
- ืงืกืคืจืกืงื™.

ื”ื ื’ื•ื‘ื™ื ืขื‘ื•ืจ ื›ืœ ืžื’ื”-ื‘ื™ื˜ ืฉืœ ืชืขื‘ื•ืจื” ื˜ื”ื•ืจื”, ืžื’ื”-ื‘ื™ื˜ ืขื•ืœื” ื‘ืขืจืš ื›ืžื” ืืœืคื™ ืจื•ื‘ืœ. ืื ื™ืฉ ืœืš ืœืคื—ื•ืช 100 Mbps ืฉืœ ืชืขื‘ื•ืจื” ื˜ื”ื•ืจื” - ื”ื•. ื”ื’ื ื” ื™ืงืจื” ืžืื•ื“. ืื ื™ ื™ื›ื•ืœ ืœืกืคืจ ืœื›ื ื‘ืžืืžืจื™ื ื”ื‘ืื™ื ื›ื™ืฆื“ ืœืขืฆื‘ ืืคืœื™ืงืฆื™ื•ืช ืขืœ ืžื ืช ืœื—ืกื•ืš ื”ืจื‘ื” ื‘ืงื™ื‘ื•ืœืช ืฉืœ ืขืจื•ืฆื™ ืื‘ื˜ื—ื”.
"ืžืœืš ื”ื’ื‘ืขื”" ื”ืืžื™ืชื™ ื”ื•ื Qrator.net, ื”ืฉืืจ ืžืคื’ืจื™ื ืžืื—ื•ืจื™ื”ื. Qrator ื”ื ืขื“ ื›ื” ื”ื™ื—ื™ื“ื™ื ืžื ื™ืกื™ื•ื ื™ ืฉื ื•ืชื ื™ื ืื—ื•ื– ื—ื™ื•ื‘ื™ ื›ื•ื–ื‘ ืงืจื•ื‘ ืœืืคืก, ืืš ื™ื—ื“ ืขื ื–ืืช ื”ื ื™ืงืจื™ื ืคื™ ื›ืžื” ืžืฉืืจ ื”ืฉื—ืงื ื™ื ื‘ืฉื•ืง.

ื’ื ืžืคืขื™ืœื™ื ืื—ืจื™ื ืžืกืคืงื™ื ื”ื’ื ื” ืื™ื›ื•ืชื™ืช ื•ื™ืฆื™ื‘ื”. ืฉื™ืจื•ืชื™ื ืจื‘ื™ื ื”ื ืชืžื›ื™ื ืขืœ ื™ื“ื™ื ื• (ื›ื•ืœืœ ืžื•ื›ืจื™ื ืžืื•ื“ ื‘ืืจืฅ!) ืžื•ื’ื ื™ื ืžืคื ื™ DDoS-Guard, G-Core Labs, ื•ื“ื™ ืžืจื•ืฆื™ื ืžื”ืชื•ืฆืื•ืช ืฉื”ืชืงื‘ืœื•.
ืžื” ื–ื” ืžื” ื•ืžื™ ื–ื” ืžื™ ื‘ืฉื•ืง ื”ื’ื ืช DDoS
ื”ืชืงืคื•ืช ื ื”ื“ืคื• ืขืœ ื™ื“ื™ Qrator

ื™ืฉ ืœื™ ื’ื ื ื™ืกื™ื•ืŸ ืขื ืžืคืขื™ืœื™ ืื‘ื˜ื—ื” ืงื˜ื ื™ื ื›ืžื• cloud-shield.ru, ddosa.net, ืืœืคื™ื ืžื”ื. ืื ื™ ื‘ื”ื—ืœื˜ ืœื ืืžืœื™ืฅ ืขืœื™ื•, ื›ื™... ืื™ืŸ ืœื™ ื”ืจื‘ื” ื ื™ืกื™ื•ืŸ, ืื‘ืœ ืื ื™ ืืกืคืจ ืœื›ื ืขืœ ืขืงืจื•ื ื•ืช ื”ืขื‘ื•ื“ื” ืฉืœื”ื. ืขืœื•ืช ื”ื”ื’ื ื” ืฉืœื”ื ื ืžื•ื›ื” ื‘-1-2 ืกื“ืจื™ ื’ื•ื“ืœ ืžื–ื• ืฉืœ ื”ืฉื—ืงื ื™ื ื”ื’ื“ื•ืœื™ื. ื›ื›ืœืœ, ื”ื ืงื•ื ื™ื ืฉื™ืจื•ืช ื”ื’ื ื” ื—ืœืงื™ืช (L3/L4) ืžืื—ื“ ื”ืฉื—ืงื ื™ื ื”ื’ื“ื•ืœื™ื + ืขื•ืฉื™ื ื”ื’ื ื” ืžืฉืœื”ื ืžืคื ื™ ื”ืชืงืคื•ืช ื‘ืจืžื•ืช ื’ื‘ื•ื”ื•ืช ื™ื•ืชืจ. ื–ื” ื™ื›ื•ืœ ืœื”ื™ื•ืช ื“ื™ ื™ืขื™ืœ + ื ื™ืชืŸ ืœืงื‘ืœ ืฉื™ืจื•ืช ื˜ื•ื‘ ื‘ืคื—ื•ืช ื›ืกืฃ, ืื‘ืœ ืขื“ื™ื™ืŸ ืžื“ื•ื‘ืจ ื‘ื—ื‘ืจื•ืช ืงื˜ื ื•ืช ืขื ืฆื•ื•ืช ืงื˜ืŸ, ืื ื ืงื—ื• ื–ืืช ื‘ื—ืฉื‘ื•ืŸ.

ืžื” ื”ืงื•ืฉื™ ืœื”ื“ื•ืฃ ื”ืชืงืคื•ืช ื‘ืจืžืช L7?

ื›ืœ ื”ืืคืœื™ืงืฆื™ื•ืช ื”ืŸ ื™ื™ื—ื•ื“ื™ื•ืช, ื•ืืชื” ืฆืจื™ืš ืœืืคืฉืจ ืชืขื‘ื•ืจื” ืฉื™ืžื•ืฉื™ืช ืขื‘ื•ืจืŸ ื•ืœื—ืกื•ื ืžื–ื™ืงื™ื. ืœื ืชืžื™ื“ ื ื™ืชืŸ ืœื ื›ื•ืช ื‘ื•ื˜ื™ื ื‘ืื•ืคืŸ ื—ื“ ืžืฉืžืขื™, ืื– ืืชื” ืฆืจื™ืš ืœื”ืฉืชืžืฉ ื‘ื”ืจื‘ื” ืžืื•ื“ ื“ืจื’ื•ืช ืฉืœ ื˜ื™ื”ื•ืจ ืชื ื•ืขื”.

ืคืขื, ืžื•ื“ื•ืœ nginx-testcookie ื”ืกืคื™ืง (https://github.com/kyprizel/testcookie-nginx-module), ื•ื–ื” ืขื“ื™ื™ืŸ ืžืกืคื™ืง ื›ื“ื™ ืœื”ื“ื•ืฃ ืžืกืคืจ ืจื‘ ืฉืœ ื”ืชืงืคื•ืช. ื›ืฉืขื‘ื“ืชื™ ื‘ืชืขืฉื™ื™ืช ื”ืื™ืจื•ื—, ื”ื’ื ืช L7 ื”ืชื‘ืกืกื” ืขืœ nginx-testcookie.
ืœืžืจื‘ื” ื”ืฆืขืจ, ื”ืชืงืคื•ืช ื”ืคื›ื• ืœืงืฉื•ืช ื™ื•ืชืจ. testcookie ืžืฉืชืžืฉ ื‘ื‘ื“ื™ืงื•ืช ื‘ื•ื˜ื™ื ืžื‘ื•ืกืกื•ืช JS, ื•ื‘ื•ื˜ื™ื ืžื•ื“ืจื ื™ื™ื ืจื‘ื™ื ื™ื›ื•ืœื™ื ืœืขื‘ื•ืจ ืื•ืชื ื‘ื”ืฆืœื—ื”.

ืจืฉืชื•ืช ืชืงื™ืคื” ื”ืŸ ื’ื ื™ื™ื—ื•ื“ื™ื•ืช, ื•ื™ืฉ ืœืงื—ืช ื‘ื—ืฉื‘ื•ืŸ ืืช ื”ืžืืคื™ื™ื ื™ื ืฉืœ ื›ืœ ื‘ื•ื˜ื ื˜ ื’ื“ื•ืœ.
ื”ื’ื‘ืจื”, ื”ืฆืคื” ื™ืฉื™ืจื” ืžื‘ื•ื˜ื ื˜, ืกื™ื ื•ืŸ ืชืขื‘ื•ืจื” ืžืžื“ื™ื ื•ืช ืฉื•ื ื•ืช (ืกื™ื ื•ืŸ ืฉื•ื ื” ืœืžื“ื™ื ื•ืช ืฉื•ื ื•ืช), ื”ืฆืคื” SYN/ACK, ืคื™ืฆื•ืœ ืžื ื•ืช, ICMP, ื”ืฆืคื” http, ื›ืืฉืจ ื‘ืจืžืช ื”ืืคืœื™ืงืฆื™ื”/http ื ื™ืชืŸ ืœื”ื’ื™ืข ืœืžืกืคืจ ื‘ืœืชื™ ืžื•ื’ื‘ืœ ืฉืœ ื”ืชืงืคื•ืช ืฉื•ื ื•ืช.
ื‘ืกืš ื”ื›ืœ, ื‘ืจืžืช ื”ื’ื ืช ืขืจื•ืฆื™ื, ืฆื™ื•ื“ ื™ื™ืขื•ื“ื™ ืœื ื™ืงื•ื™ ืชืขื‘ื•ืจื”, ืชื•ื›ื ื” ืžื™ื•ื—ื“ืช, ื”ื’ื“ืจื•ืช ืกื™ื ื•ืŸ ื ื•ืกืคื•ืช ืœื›ืœ ืœืงื•ื— ื™ื›ื•ืœื•ืช ืœื”ื™ื•ืช ืขืฉืจื•ืช ื•ืžืื•ืช ืจืžื•ืช ืกื™ื ื•ืŸ.
ื›ื“ื™ ืœื ื”ืœ ืืช ื–ื” ื›ืจืื•ื™ ื•ืœื›ื•ื•ืŸ ื ื›ื•ืŸ ืืช ื”ื’ื“ืจื•ืช ื”ืกื™ื ื•ืŸ ืขื‘ื•ืจ ืžืฉืชืžืฉื™ื ืฉื•ื ื™ื, ืืชื” ืฆืจื™ืš ื ื™ืกื™ื•ืŸ ืจื‘ ื•ืฆื•ื•ืช ืžื•ืกืžืš. ืืคื™ืœื• ืžืคืขื™ืœ ื’ื“ื•ืœ ืฉื”ื—ืœื™ื˜ ืœืกืคืง ืฉื™ืจื•ืชื™ ื”ื’ื ื” ืœื ื™ื›ื•ืœ "ืœื–ืจื•ืง ื›ืกืฃ ื‘ื˜ื™ืคืฉื•ืช ืขืœ ื”ื‘ืขื™ื”": ื™ื”ื™ื” ืฆื•ืจืš ืœืฆื‘ื•ืจ ื ื™ืกื™ื•ืŸ ืžืืชืจื™ื ืฉืงืจื™ื ื•ืชื•ืฆืื•ืช ื›ื•ื–ื‘ื•ืช ืขืœ ืชื ื•ืขื” ืœื’ื™ื˜ื™ืžื™ืช.
ืื™ืŸ ื›ืคืชื•ืจ "ื“ื—ื™ DDoS" ืœืžืคืขื™ืœ ื”ืื‘ื˜ื—ื”; ื™ืฉ ืžืกืคืจ ืจื‘ ืฉืœ ื›ืœื™ื, ื•ืืชื” ืฆืจื™ืš ืœื“ืขืช ืื™ืš ืœื”ืฉืชืžืฉ ื‘ื”ื.

ื•ืขื•ื“ ื“ื•ื’ืžื ื ื•ืกืคืช ืœื‘ื•ื ื•ืก.
ืžื” ื–ื” ืžื” ื•ืžื™ ื–ื” ืžื™ ื‘ืฉื•ืง ื”ื’ื ืช DDoS
ืฉืจืช ืœื ืžื•ื’ืŸ ื ื—ืกื ืขืœ ื™ื“ื™ ื”ืžืืจื— ื‘ืžื”ืœืš ื”ืชืงืคื” ื‘ืงื™ื‘ื•ืœืช ืฉืœ 600 Mbit
("ืื•ื‘ื“ืŸ" ื”ืชื ื•ืขื” ืื™ื ื• ืžื•ืจื’ืฉ, ื›ื™ ืจืง ืืชืจ ืื—ื“ ื”ื•ืชืงืฃ, ื”ื•ื ื”ื•ืกืจ ื–ืžื ื™ืช ืžื”ืฉืจืช ื•ื”ื—ืกื™ืžื” ื”ื•ืกืจื” ืชื•ืš ืฉืขื”).
ืžื” ื–ื” ืžื” ื•ืžื™ ื–ื” ืžื™ ื‘ืฉื•ืง ื”ื’ื ืช DDoS
ืื•ืชื• ืฉืจืช ืžื•ื’ืŸ. ื”ืชื•ืงืคื™ื "ื ื›ื ืขื•" ืœืื—ืจ ื™ื•ื ืฉืœ ืคื™ื’ื•ืขื™ื ื ื”ื“ืคื™ื. ื”ื”ืชืงืคื” ืขืฆืžื” ืœื ื”ื™ื™ืชื” ื”ื—ื–ืงื” ื‘ื™ื•ืชืจ.

ื”ื”ืชืงืคื” ื•ื”ื”ื’ื ื” ืฉืœ L3/L4 ื”ืŸ ื˜ืจื™ื•ื•ื™ืืœื™ื•ืช ื™ื•ืชืจ; ื”ืŸ ืชืœื•ื™ื•ืช ื‘ืขื™ืงืจ ื‘ืขื•ื‘ื™ ื”ืขืจื•ืฆื™ื, ื‘ืืœื’ื•ืจื™ืชืžื™ ื–ื™ื”ื•ื™ ื•ืกื™ื ื•ืŸ ืœื”ืชืงืคื•ืช.
ื”ืชืงืคื•ืช L7 ืžื•ืจื›ื‘ื•ืช ื•ืžืงื•ืจื™ื•ืช ื™ื•ืชืจ; ื”ืŸ ืชืœื•ื™ื•ืช ื‘ืืคืœื™ืงืฆื™ื” ื”ืžื•ืชืงืคืช, ื‘ื™ื›ื•ืœื•ืช ื•ื‘ื“ืžื™ื•ืŸ ืฉืœ ื”ืชื•ืงืคื™ื. ื”ื’ื ื” ืžืคื ื™ื”ื ื“ื•ืจืฉืช ื™ื“ืข ื•ื ื™ืกื™ื•ืŸ ืจื‘, ื•ื™ื™ืชื›ืŸ ืฉื”ืชื•ืฆืื” ืœื ืชื”ื™ื” ืžื™ื™ื“ื™ืช ื•ืœื ืžืื” ืื—ื•ื–. ืขื“ ืฉื’ื•ื’ืœ ื”ืขืœืชื” ืจืฉืช ืขืฆื‘ื™ืช ื ื•ืกืคืช ืœื”ื’ื ื”.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”