ืžื–ืขื•ืจ ื”ืกื™ื›ื•ื ื™ื ื‘ืฉื™ืžื•ืฉ ื‘-DNS-over-TLS (DoT) ื•-DNS-over-HTTPS (DoH)

ืžื–ืขื•ืจ ื”ืกื™ื›ื•ื ื™ื ื‘ืฉื™ืžื•ืฉ ื‘-DNS-over-TLS (DoT) ื•-DNS-over-HTTPS (DoH)ืžื–ืขื•ืจ ื”ืกื™ื›ื•ื ื™ื ื‘ืฉื™ืžื•ืฉ ื‘-DoH ื•-DoT

ื”ื’ื ืช DoH ื•-DoT

ื”ืื ืืชื” ืฉื•ืœื˜ ื‘ืชืขื‘ื•ืจืช ื”-DNS ืฉืœืš? ืืจื’ื•ื ื™ื ืžืฉืงื™ืขื™ื ื”ืจื‘ื” ื–ืžืŸ, ื›ืกืฃ ื•ืžืืžืฅ ื‘ืื‘ื˜ื—ืช ื”ืจืฉืชื•ืช ืฉืœื”ื. ืขื ื–ืืช, ืชื—ื•ื ืื—ื“ ืฉืœืขืชื™ื ืงืจื•ื‘ื•ืช ืื™ื ื• ืžืงื‘ืœ ืžืกืคื™ืง ืชืฉื•ืžืช ืœื‘ ื”ื•ื DNS.

ืกืงื™ืจื” ื˜ื•ื‘ื” ืฉืœ ื”ืกื™ื›ื•ื ื™ื ืฉ-DNS ืžื‘ื™ื ื”ื™ื ืžืฆื’ืช ืฉืœ Verisign ื‘ื›ื ืก Infosecurity.

ืžื–ืขื•ืจ ื”ืกื™ื›ื•ื ื™ื ื‘ืฉื™ืžื•ืฉ ื‘-DNS-over-TLS (DoT) ื•-DNS-over-HTTPS (DoH)31% ืžืฉื™ืขื•ืจื™ ืชื•ื›ื ื•ืช ื”ื›ื•ืคืจ ืฉื ืกืงืจื• ื”ืฉืชืžืฉื• ื‘-DNS ืœื”ื—ืœืคืช ืžืคืชื—ื•ืช. ืžืžืฆืื™ ืžื—ืงืจ

31% ืžืฉื™ืขื•ืจื™ ืชื•ื›ื ื•ืช ื”ื›ื•ืคืจ ืฉื ืกืงืจื• ื”ืฉืชืžืฉื• ื‘-DNS ืœื”ื—ืœืคืช ืžืคืชื—ื•ืช.

ื”ื‘ืขื™ื” ื”ื™ื ื—ืžื•ืจื”. ืขืœ ืคื™ ืžืขื‘ื“ืช ื”ืžื—ืงืจ Palo Alto Networks Unit 42, ื›-85% ืžื”ืชื•ื›ื ื•ืช ื”ื–ื“ื•ื ื™ื•ืช ืžืฉืชืžืฉื•ืช ื‘-DNS ื›ื“ื™ ืœื™ืฆื•ืจ ืขืจื•ืฅ ืฉืœื™ื˜ื” ื•ื‘ืงืจื”, ืžื” ืฉืžืืคืฉืจ ืœืชื•ืงืคื™ื ืœื”ื—ื“ื™ืจ ื‘ืงืœื•ืช ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ืœืจืฉืช ืฉืœืš, ื›ืžื• ื’ื ืœื’ื ื•ื‘ ื ืชื•ื ื™ื. ืžืื– ื”ืงืžืชื”, ืชืขื‘ื•ืจืช DNS ื”ื™ื™ืชื” ื‘ืจื•ื‘ื” ืœื ืžื•ืฆืคื ืช ื•ื ื™ืชืŸ ืœื ืชื— ืื•ืชื” ื‘ืงืœื•ืช ืขืœ ื™ื“ื™ ืžื ื’ื ื•ื ื™ ืื‘ื˜ื—ื” ืฉืœ NGFW. 

ืคืจื•ื˜ื•ืงื•ืœื™ื ื—ื“ืฉื™ื ืขื‘ื•ืจ DNS ื”ื•ืคื™ืขื• ืฉืžื˜ืจืชื ืœื”ื’ื‘ื™ืจ ืืช ื”ืกื•ื“ื™ื•ืช ืฉืœ ื—ื™ื‘ื•ืจื™ DNS. ื”ื ื ืชืžื›ื™ื ื‘ืื•ืคืŸ ืคืขื™ืœ ืขืœ ื™ื“ื™ ืกืคืงื™ ื“ืคื“ืคื ื™ื ืžื•ื‘ื™ืœื™ื ื•ืกืคืงื™ ืชื•ื›ื ื” ืื—ืจื™ื. ืชืขื‘ื•ืจืช DNS ืžื•ืฆืคื ืช ืชืชื—ื™ืœ ื‘ืงืจื•ื‘ ืœื’ื“ื•ืœ ื‘ืจืฉืชื•ืช ืืจื’ื•ื ื™ื•ืช. ืชืขื‘ื•ืจืช DNS ืžื•ืฆืคื ืช ืฉืื™ื ื” ืžื ื•ืชื—ืช ื•ื ืคืชืจืช ื›ื”ืœื›ื” ืขืœ ื™ื“ื™ ื›ืœื™ื ืžื”ื•ื•ื” ืกื™ื›ื•ืŸ ืื‘ื˜ื—ื” ืœื—ื‘ืจื”. ืœื“ื•ื’ืžื”, ืื™ื•ื ื›ื–ื” ื”ื•ื cryptolockers ื”ืžืฉืชืžืฉื™ื ื‘-DNS ื›ื“ื™ ืœื”ื—ืœื™ืฃ ืžืคืชื—ื•ืช ื”ืฆืคื ื”. ื”ืชื•ืงืคื™ื ื“ื•ืจืฉื™ื ื›ืขืช ื›ื•ืคืจ ืฉืœ ื›ืžื” ืžื™ืœื™ื•ื ื™ ื“ื•ืœืจื™ื ื›ื“ื™ ืœื”ื—ื–ื™ืจ ืืช ื”ื’ื™ืฉื” ืœื ืชื•ื ื™ื ืฉืœืš. ื’ืจืžื™ืŸ, ืœืžืฉืœ, ืฉื™ืœืžื” 10 ืžื™ืœื™ื•ืŸ ื“ื•ืœืจ.

ื›ืฉื”ื ืžื•ื’ื“ืจื™ื ื›ืจืื•ื™, NGFWs ื™ื›ื•ืœื™ื ืœื”ื›ื—ื™ืฉ ืื• ืœื”ื’ืŸ ืขืœ ื”ืฉื™ืžื•ืฉ ื‘-DNS-over-TLS (DoT) ื•ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”ื ื›ื“ื™ ืœืžื ื•ืข ืืช ื”ืฉื™ืžื•ืฉ ื‘-DNS-over-HTTPS (DoH), ื•ืœืืคืฉืจ ืœื ืชื— ืืช ื›ืœ ืชืขื‘ื•ืจืช ื”-DNS ื‘ืจืฉืช ืฉืœืš.

ืžื”ื• DNS ืžื•ืฆืคืŸ?

ืžื” ื–ื” DNS

ืžืขืจื›ืช ืฉืžื•ืช ื”ื“ื•ืžื™ื™ืŸ (DNS) ืคื•ืชืจืช ืฉืžื•ืช ื“ื•ืžื™ื™ื ื™ื ื”ื ื™ืชื ื™ื ืœืงืจื™ืื” ืขืœ ื™ื“ื™ ืื“ื (ืœื“ื•ื’ืžื”, ื›ืชื•ื‘ืช www.paloaltonetworks.com ) ืœื›ืชื•ื‘ื•ืช IP (ืœื“ื•ื’ืžื”, 34.107.151.202). ื›ืืฉืจ ืžืฉืชืžืฉ ืžื–ื™ืŸ ืฉื ืชื—ื•ื ื‘ื“ืคื“ืคืŸ ืื™ื ื˜ืจื ื˜, ื”ื“ืคื“ืคืŸ ืฉื•ืœื— ืฉืื™ืœืชืช DNS ืœืฉืจืช ื”-DNS, ื•ืžื‘ืงืฉ ืืช ื›ืชื•ื‘ืช ื”-IP ื”ืžืฉื•ื™ื›ืช ืœืฉื ืชื—ื•ื ื–ื”. ื‘ืชื’ื•ื‘ื”, ืฉืจืช ื”-DNS ืžื—ื–ื™ืจ ืืช ื›ืชื•ื‘ืช ื”-IP ืฉื‘ื” ื™ืฉืชืžืฉ ื”ื“ืคื“ืคืŸ ื”ื–ื”.

ืฉืื™ืœืชื•ืช ื•ืชื’ื•ื‘ื•ืช DNS ื ืฉืœื—ื•ืช ื‘ืจื—ื‘ื™ ื”ืจืฉืช ื‘ื˜ืงืกื˜ ืจื’ื™ืœ, ืœื ืžื•ืฆืคืŸ, ืžื” ืฉื”ื•ืคืš ืื•ืชื” ืœืคื’ื™ืขื” ืœืจื™ื’ื•ืœ ืื• ืœืฉื™ื ื•ื™ ื”ืชื’ื•ื‘ื” ื•ื”ืคื ื™ื™ืช ื”ื“ืคื“ืคืŸ ืœืฉืจืชื™ื ื–ื“ื•ื ื™ื™ื. ื”ืฆืคื ืช DNS ืžืงืฉื” ืขืœ ืžืขืงื‘ ืื• ืฉื™ื ื•ื™ ืฉืœ ื‘ืงืฉื•ืช DNS ื‘ืžื”ืœืš ื”ืฉื™ื“ื•ืจ. ื”ืฆืคื ืช ื‘ืงืฉื•ืช ื•ืชื’ื•ื‘ื•ืช DNS ืžื’ื™ื ื” ืขืœื™ืš ืžืคื ื™ ื”ืชืงืคื•ืช Man-in-the-Middle ืชื•ืš ื‘ื™ืฆื•ืข ืื•ืชื” ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ื›ืžื• ืคืจื•ื˜ื•ืงื•ืœ ื”-DNS ื”ืจื’ื™ืœ (Domain Name System) ื”ืžืกื•ืจืชื™. 

ื‘ืžื”ืœืš ื”ืฉื ื™ื ื”ืื—ืจื•ื ื•ืช, ื”ื•ืฆื’ื• ืฉื ื™ ืคืจื•ื˜ื•ืงื•ืœื™ ื”ืฆืคื ืช DNS:

  1. DNS-over-HTTPS (DoH)

  2. DNS-over-TLS (DoT)

ืœืคืจื•ื˜ื•ืงื•ืœื™ื ื”ืœืœื• ื™ืฉ ื“ื‘ืจ ืื—ื“ ื‘ืžืฉื•ืชืฃ: ื”ื ืžืกืชื™ืจื™ื ื‘ื›ื•ื•ื ื” ื‘ืงืฉื•ืช DNS ืžื›ืœ ื™ื™ืจื•ื˜... ื•ื’ื ืžืžืื‘ื˜ื—ื™ ื”ืืจื’ื•ืŸ. ื”ืคืจื•ื˜ื•ืงื•ืœื™ื ืžืฉืชืžืฉื™ื ื‘ืขื™ืงืจ ื‘-TLS (Transport Layer Security) ื›ื“ื™ ืœื™ืฆื•ืจ ื—ื™ื‘ื•ืจ ืžื•ืฆืคืŸ ื‘ื™ืŸ ืœืงื•ื— ืฉืžื‘ืฆืข ืฉืื™ืœืชื•ืช ืœื‘ื™ืŸ ืฉืจืช ื”ืคื•ืชืจ ืฉืื™ืœืชื•ืช DNS ื“ืจืš ื™ืฆื™ืื” ืฉืื™ื ื” ืžืฉืžืฉืช ื‘ื“ืจืš ื›ืœืœ ืœืชืขื‘ื•ืจืช DNS.

ื”ืกื•ื“ื™ื•ืช ืฉืœ ืฉืื™ืœืชื•ืช DNS ื”ื™ื ื™ืชืจื•ืŸ ื’ื“ื•ืœ ืฉืœ ืคืจื•ื˜ื•ืงื•ืœื™ื ืืœื”. ืขื ื–ืืช, ื”ื ืžืฆื™ื‘ื™ื ื‘ืขื™ื•ืช ืœืžืื‘ื˜ื—ื™ื ืฉื—ื™ื™ื‘ื™ื ืœื ื˜ืจ ืืช ืชืขื‘ื•ืจืช ื”ืจืฉืช ื•ืœื–ื”ื•ืช ื•ืœื—ืกื•ื ื—ื™ื‘ื•ืจื™ื ื–ื“ื•ื ื™ื™ื. ืžื›ื™ื•ื•ืŸ ืฉื”ืคืจื•ื˜ื•ืงื•ืœื™ื ืฉื•ื ื™ื ื‘ื™ื™ืฉื•ื ืฉืœื”ื, ืฉื™ื˜ื•ืช ื”ื ื™ืชื•ื— ื™ื”ื™ื• ืฉื•ื ื•ืช ื‘ื™ืŸ DoH ืœ-DoT.

DNS ื‘ืืžืฆืขื•ืช HTTPS (DoH)

ืžื–ืขื•ืจ ื”ืกื™ื›ื•ื ื™ื ื‘ืฉื™ืžื•ืฉ ื‘-DNS-over-TLS (DoT) ื•-DNS-over-HTTPS (DoH)DNS ื‘ืชื•ืš HTTPS

DoH ืžืฉืชืžืฉ ื‘ื™ืฆื™ืื” ื”ื™ื“ื•ืขื” 443 ืขื‘ื•ืจ HTTPS, ืฉืขื‘ื•ืจื” ื”-RFC ืžืฆื™ื™ืŸ ื‘ืžืคื•ืจืฉ ื›ื™ ื”ื›ื•ื•ื ื” ื”ื™ื "ืœืขืจื‘ื‘ ืชืขื‘ื•ืจืช DoH ืขื ืชืขื‘ื•ืจืช HTTPS ืื—ืจืช ื‘ืื•ืชื• ื—ื™ื‘ื•ืจ", "ืœื”ืงืฉื•ืช ืขืœ ื ื™ืชื•ื— ืชืขื‘ื•ืจืช DNS" ื•ื‘ื›ืš ืœืขืงื•ืฃ ืืช ื”ื‘ืงืจื•ืช ื”ืืจื’ื•ื ื™ื•ืช ( RFC 8484 DoH ืกืขื™ืฃ 8.1 ). ืคืจื•ื˜ื•ืงื•ืœ DoH ืžืฉืชืžืฉ ื‘ื”ืฆืคื ืช TLS ื•ื‘ืชื—ื‘ื™ืจ ื”ื‘ืงืฉื•ืช ื”ืžืกื•ืคืง ืขืœ ื™ื“ื™ ืชืงื ื™ HTTPS ื•-HTTP/2 ื”ื ืคื•ืฆื™ื, ื•ืžื•ืกื™ืฃ ื‘ืงืฉื•ืช ื•ืชื’ื•ื‘ื•ืช DNS ืขืœ ื‘ืงืฉื•ืช HTTP ืกื˜ื ื“ืจื˜ื™ื•ืช.

ืกื™ื›ื•ื ื™ื ื”ืงืฉื•ืจื™ื ืœ-DoH

ืื ืื™ื ืš ื™ื›ื•ืœ ืœื”ื‘ื—ื™ืŸ ื‘ื™ืŸ ืชืขื‘ื•ืจืช HTTPS ืจื’ื™ืœื” ืœื‘ื™ืŸ ื‘ืงืฉื•ืช DoH, ืื–ื™ ื™ื™ืฉื•ืžื™ื ื‘ืชื•ืš ื”ืืจื’ื•ืŸ ืฉืœืš ื™ื›ื•ืœื™ื (ื•ื™ืขืฉื•) ืœืขืงื•ืฃ ื”ื’ื“ืจื•ืช DNS ืžืงื•ืžื™ื•ืช ืขืœ ื™ื“ื™ ื”ืคื ื™ื™ืช ื‘ืงืฉื•ืช ืœืฉืจืชื™ื ืฉืœ ืฆื“ ืฉืœื™ืฉื™ ื”ืžื’ื™ื‘ื™ื ืœื‘ืงืฉื•ืช DoH, ืžื” ืฉืขื•ืงืฃ ื›ืœ ื ื™ื˜ื•ืจ, ื›ืœื•ืžืจ ื”ื•ืจืก ืืช ื”ื™ื›ื•ืœืช ืœืฉืœื•ื˜ ื‘ืชืขื‘ื•ืจืช ื”-DNS. ื‘ืื•ืคืŸ ืื™ื“ื™ืืœื™, ืขืœื™ืš ืœืฉืœื•ื˜ ื‘-DoH ื‘ืืžืฆืขื•ืช ืคื•ื ืงืฆื™ื•ืช ืคืขื ื•ื— HTTPS. 

ะ˜ ื’ื•ื’ืœ ื•ืžื•ื–ื™ืœื” ื”ื˜ืžื™ืขื• ื™ื›ื•ืœื•ืช DoH ื‘ื’ืจืกื” ื”ืขื“ื›ื ื™ืช ื‘ื™ื•ืชืจ ืฉืœ ื”ื“ืคื“ืคื ื™ื ืฉืœื”ื, ื•ืฉืชื™ ื”ื—ื‘ืจื•ืช ืคื•ืขืœื•ืช ืœื”ืฉืชืžืฉ ื‘-DoH ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืขื‘ื•ืจ ื›ืœ ื‘ืงืฉื•ืช ื”-DNS. ืžื™ืงืจื•ืกื•ืคื˜ ื’ื ืžืคืชื—ืช ืชื•ื›ื ื™ื•ืช ืขืœ ืฉื™ืœื•ื‘ DoH ื‘ืžืขืจื›ื•ืช ื”ื”ืคืขืœื” ืฉืœื”ื. ื”ื—ื™ืกืจื•ืŸ ื”ื•ื ืฉืœื ืจืง ื—ื‘ืจื•ืช ืชื•ื›ื ื” ืžื•ื›ืจื•ืช, ืืœื ื’ื ืชื•ืงืคื™ื ื”ื—ืœื• ืœื”ืฉืชืžืฉ ื‘-DoH ื›ืืžืฆืขื™ ืœืขืงื•ืฃ ืืžืฆืขื™ ื—ื•ืžืช ืืฉ ืืจื’ื•ื ื™ื™ื ืžืกื•ืจืชื™ื™ื. (ืœื“ื•ื’ืžื”, ืขื™ื™ืŸ ื‘ืžืืžืจื™ื ื”ื‘ืื™ื: PsiXBot ืžืฉืชืžืฉ ื›ืขืช ื‘-Google DoH , PsiXBot ืžืžืฉื™ืš ืœื”ืชืคืชื— ืขื ืชืฉืชื™ืช DNS ืžืขื•ื“ื›ื ืช ะธ ื ื™ืชื•ื— ื“ืœืช ืื—ื•ืจื™ืช ืฉืœ Godlua .) ื‘ื›ืœ ืžืงืจื”, ืชืขื‘ื•ืจืช DoH ื˜ื•ื‘ื” ื•ื’ื ื–ื“ื•ื ื™ืช ืœื ืชื–ื•ื”ื”, ื•ืชื•ืชื™ืจ ืืช ื”ืืจื’ื•ืŸ ืขื™ื•ื•ืจ ืœืฉื™ืžื•ืฉ ื–ื“ื•ื ื™ ื‘-DoH ื›ืฆื™ื ื•ืจ ืœืฉืœื™ื˜ื” ื‘ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช (C2) ื•ื’ื ื™ื‘ืช ื ืชื•ื ื™ื ืจื’ื™ืฉื™ื.

ื”ื‘ื˜ื—ืช ื ืจืื•ืช ื•ืฉืœื™ื˜ื” ื‘ืชื ื•ืขืช DoH

ื›ืคืชืจื•ืŸ ื”ื˜ื•ื‘ ื‘ื™ื•ืชืจ ืœื‘ืงืจืช DoH, ืื ื• ืžืžืœื™ืฆื™ื ืœื”ื’ื“ื™ืจ ืืช NGFW ืœืคืขื ื•ื— ืชืขื‘ื•ืจืช HTTPS ื•ืœื—ืกื•ื ืชืขื‘ื•ืจืช DoH (ืฉื ืืคืœื™ืงืฆื™ื”: dns-over-https). 

ืจืืฉื™ืช, ื•ื“ื ืฉ-NGFW ืžื•ื’ื“ืจ ืœืคืขื ื•ื— HTTPS, ืœืคื™ ืžื“ืจื™ืš ืœื˜ื›ื ื™ืงื•ืช ื”ืคืขื ื•ื— ื”ื˜ื•ื‘ื•ืช ื‘ื™ื•ืชืจ.

ืฉื ื™ืช, ืฆื•ืจ ื›ืœืœ ืœืชืขื‘ื•ืจืช ื™ื™ืฉื•ืžื™ื "dns-over-https" ื›ืคื™ ืฉืžื•ืฆื’ ืœื”ืœืŸ:

ืžื–ืขื•ืจ ื”ืกื™ื›ื•ื ื™ื ื‘ืฉื™ืžื•ืฉ ื‘-DNS-over-TLS (DoT) ื•-DNS-over-HTTPS (DoH)ื›ืœืœ NGFW ืฉืœ Palo Alto Networks ืœื—ืกื™ืžืช DNS-over-HTTPS

ื›ื—ืœื•ืคื” ื‘ื™ื ื™ื™ื (ืื ื”ืืจื’ื•ืŸ ืฉืœืš ืœื ื™ื™ืฉื ืืช ืคืขื ื•ื— HTTPS ื‘ืžืœื•ืื•), ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ืืช NGFW ืœื”ื—ื™ืœ ืคืขื•ืœืช "ื”ื›ื—ืฉื”" ืขืœ ืžื–ื”ื” ื”ื™ื™ืฉื•ื "dns-over-https", ืืš ื”ื”ืฉืคืขื” ืชื”ื™ื” ืžื•ื’ื‘ืœืช ืœื—ืกื™ืžืช ืžืงื•ืจื•ืช ืžืกื•ื™ืžื™ื ืฉืจืชื™ DoH ื™ื“ื•ืขื™ื ืœืคื™ ืฉื ื”ื“ื•ืžื™ื™ืŸ ืฉืœื”ื, ืื– ืื™ืš ืœืœื ืคืขื ื•ื— HTTPS, ืœื ื ื™ืชืŸ ืœื‘ื“ื•ืง ืืช ืชืขื‘ื•ืจืช DoH ื‘ืžืœื•ืื” (ืจืื”  Applipedia ืžื‘ื™ืช Palo Alto Networks   ื•ื—ืคืฉ ืืช "dns-over-https").

DNS ืขืœ TLS (DoT)

ืžื–ืขื•ืจ ื”ืกื™ื›ื•ื ื™ื ื‘ืฉื™ืžื•ืฉ ื‘-DNS-over-TLS (DoT) ื•-DNS-over-HTTPS (DoH)DNS ื‘ืชื•ืš TLS

ื‘ืขื•ื“ ืฉืคืจื•ื˜ื•ืงื•ืœ DoH ื ื•ื˜ื” ืœื”ืชืขืจื‘ื‘ ืขื ืชืขื‘ื•ืจื” ืื—ืจืช ื‘ืื•ืชื” ื™ืฆื™ืื”, DoT ื‘ืžืงื•ื ื–ืืช ืžืฉืชืžืฉ ื‘ื™ืฆื™ืื” ืžื™ื•ื—ื“ืช ืฉืฉืžื•ืจื” ืœืžื˜ืจื” ื”ื‘ืœืขื“ื™ืช ื”ื–ื•, ืืคื™ืœื• ืœื ืžืืคืฉืจ ืฉื™ืžื•ืฉ ื‘ืื•ืชื” ื™ืฆื™ืื” ืขืœ ื™ื“ื™ ืชืขื‘ื•ืจืช DNS ืžืกื•ืจืชื™ืช ืœื ืžื•ืฆืคื ืช ( RFC 7858, ืกืขื™ืฃ 3.1 ).

ืคืจื•ื˜ื•ืงื•ืœ DoT ืžืฉืชืžืฉ ื‘-TLS ื›ื“ื™ ืœืกืคืง ื”ืฆืคื ื” ื”ืžืงื•ืคืœืช ืฉืื™ืœืชื•ืช ืคืจื•ื˜ื•ืงื•ืœ DNS ืกื˜ื ื“ืจื˜ื™ื•ืช, ืขื ืชืขื‘ื•ืจื” ื‘ืืžืฆืขื•ืช ื”ื™ืฆื™ืื” ื”ื™ื“ื•ืขื” 853 ( RFC 7858 ืกืขื™ืฃ 6 ). ืคืจื•ื˜ื•ืงื•ืœ ื”-DoT ืชื•ื›ื ืŸ ื›ื“ื™ ืœื”ืงืœ ืขืœ ืืจื’ื•ื ื™ื ืœื—ืกื•ื ืชืขื‘ื•ืจื” ื‘ืคื•ืจื˜, ืื• ืœืงื‘ืœ ืชืขื‘ื•ืจื” ืืš ืœืืคืฉืจ ืคืขื ื•ื— ื‘ื™ืฆื™ืื” ื–ื•.

ืกื™ื›ื•ื ื™ื ื”ืงืฉื•ืจื™ื ืœ-DoT

ื’ื•ื’ืœ ื”ื˜ืžื™ืขื” DoT ื‘ืœืงื•ื— ืฉืœื” Android 9 Pie ื•ืื™ืœืš , ืขื ื”ื’ื“ืจืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืœืฉื™ืžื•ืฉ ืื•ื˜ื•ืžื˜ื™ ื‘-DoT ืื ื–ืžื™ืŸ. ืื ื”ืขืจื›ืช ืืช ื”ืกื™ื›ื•ื ื™ื ื•ืืชื” ืžื•ื›ืŸ ืœื”ืฉืชืžืฉ ื‘-DoT ื‘ืจืžื” ื”ืืจื’ื•ื ื™ืช, ืื– ืืชื” ืฆืจื™ืš ืฉืžื ื”ืœื™ ืจืฉืช ื™ืืคืฉืจื• ื‘ืžืคื•ืจืฉ ืชืขื‘ื•ืจื” ื™ื•ืฆืืช ื‘ื™ืฆื™ืื” 853 ื“ืจืš ื”ื”ื™ืงืฃ ืฉืœื”ื ืขื‘ื•ืจ ืคืจื•ื˜ื•ืงื•ืœ ื—ื“ืฉ ื–ื”.

ื”ื‘ื˜ื—ืช ื ืจืื•ืช ื•ืฉืœื™ื˜ื” ื‘ืชืขื‘ื•ืจืช DoT

ื›ืฉื™ื˜ื•ืช ืขื‘ื•ื“ื” ืžื•ืžืœืฆื•ืช ืœื‘ืงืจืช DoT, ืื ื• ืžืžืœื™ืฆื™ื ืขืœ ื›ืœ ืื—ื“ ืžื”ืืคืฉืจื•ื™ื•ืช ืœืขื™ืœ, ื‘ื”ืชื‘ืกืก ืขืœ ื”ื“ืจื™ืฉื•ืช ืฉืœ ื”ืืจื’ื•ืŸ ืฉืœืš:

  • ื”ื’ื“ืจ ืืช NGFW ื›ื“ื™ ืœืคืขื ื— ืืช ื›ืœ ื”ืชืขื‘ื•ืจื” ืขื‘ื•ืจ ื™ืฆื™ืืช ื™ืขื“ 853. ืขืœ ื™ื“ื™ ืคืขื ื•ื— ืชืขื‘ื•ืจื”, DoT ื™ื•ืคื™ืข ื›ื™ื™ืฉื•ื DNS ืฉืขืœื™ื• ืชื•ื›ืœ ืœื”ื—ื™ืœ ื›ืœ ืคืขื•ืœื”, ื›ื’ื•ืŸ ื”ืคืขืœืช ืžื ื•ื™ ืื‘ื˜ื—ืช DNS ืฉืœ Palo Alto Networks ืœืฉืœื•ื˜ ื‘ื“ื•ืžื™ื™ื ื™ื DGA ืื• ืงื™ื™ื DNS Sinkholing ื•ืื ื˜ื™ ืชื•ื›ื ื•ืช ืจื™ื’ื•ืœ.

  • ื—ืœื•ืคื” ื”ื™ื ืฉื”ืžื ื•ืข App-ID ื™ื—ืกื•ื ืœื—ืœื•ื˜ื™ืŸ ืืช ืชืขื‘ื•ืจืช 'dns-over-tls' ื‘ื™ืฆื™ืื” 853. ื–ื” ื‘ื“ืจืš ื›ืœืœ ื—ืกื•ื ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืื™ืŸ ืฆื•ืจืš ื‘ืคืขื•ืœื” (ืืœื ืื ืืชื” ืžืชื™ืจ ืกืคืฆื™ืคื™ืช ื™ื™ืฉื•ื 'dns-over-tls' ืื• ืชืขื‘ื•ืจืช ื™ืฆื™ืื” 853).

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”