ืžืชืงืคืช CPDoS ืฉื”ื•ืคื›ืช ื“ืคื™ื ื”ืžื•ื’ืฉื™ื ื“ืจืš CDN ืœืœื ื ื’ื™ืฉื™ื

ื—ื•ืงืจื™ื ืžืื•ื ื™ื‘ืจืกื™ื˜ืื•ืช ื”ืžื‘ื•ืจื’ ื•ืงืœืŸ
ืžืคื•ืชื— ื˜ื›ื ื™ืงืช ื”ืชืงืคื” ื—ื“ืฉื” ืขืœ ืจืฉืชื•ืช ืืกืคืงืช ืชื•ื›ืŸ ื•ืคืจื•ืงืกื™ ืžื˜ืžื•ืŸ - CPDoS (ืžื ื™ืขืช ืฉื™ืจื•ืช ืžื•ืจืขืœืช ื‘ืžื˜ืžื•ืŸ). ื”ืžืชืงืคื” ืžืืคืฉืจืช ืœืžื ื•ืข ื’ื™ืฉื” ืœื“ืฃ ื‘ืืžืฆืขื•ืช ื”ืจืขืœืช ืžื˜ืžื•ืŸ.

ื”ื‘ืขื™ื” ื ื•ื‘ืขืช ืžื”ืขื•ื‘ื“ื” ืฉ-CDN ืžืื—ืกืŸ ืœื ืจืง ื‘ืงืฉื•ืช ืฉื”ื•ืฉืœืžื• ื‘ื”ืฆืœื—ื”, ืืœื ื’ื ืžืžืฆื‘ื™ื ืฉื‘ื”ื ืฉืจืช ื”-http ืžื—ื–ื™ืจ ืฉื’ื™ืื”. ื›ื›ืœืœ, ืื ื™ืฉ ื‘ืขื™ื•ืช ื‘ื™ืฆื™ืจืช ื‘ืงืฉื•ืช, ื”ืฉืจืช ืžื ืคื™ืง ืฉื’ื™ืืช 400 (ื‘ืงืฉื” ื’ืจื•ืขื”); ื”ื™ื•ืฆื ืžืŸ ื”ื›ืœืœ ื”ื™ื—ื™ื“ ื”ื•ื IIS, ืฉืžื ืคื™ืง ืฉื’ื™ืืช 404 (ืœื ื ืžืฆื) ืขื‘ื•ืจ ื›ื•ืชืจื•ืช ื’ื“ื•ืœื•ืช ืžื“ื™. ื”ืชืงืŸ ืžืืคืฉืจ ืœืฉืžื•ืจ ืจืง ืฉื’ื™ืื•ืช ืขื ืงื•ื“ื™ื 404 (ืœื ื ืžืฆื), 405 (ืฉื™ื˜ื” ืœื ืžื•ืชืจืช), 410 (ื ืขืœืžื”) ื•-501 (ืœื ืžื™ื•ืฉื), ืื‘ืœ ื—ืœืง ืžื”-CDN ื’ื ืžืื—ืกื ื™ื ืชื’ื•ื‘ื•ืช ืขื ืงื•ื“ 400 (ื‘ืงืฉื” ื’ืจื•ืขื”), ืฉืชืœื•ื™ ืขืœ ื”ื‘ืงืฉื” ืฉื ืฉืœื—ื”.

ืชื•ืงืคื™ื ื™ื›ื•ืœื™ื ืœื’ืจื•ื ืœืžืฉืื‘ ื”ืžืงื•ืจื™ ืœื”ื—ื–ื™ืจ ืฉื’ื™ืืช "400 Bad Request" ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉื” ืขื ื›ื•ืชืจื•ืช HTTP ืžืขื•ืฆื‘ื•ืช ื‘ืฆื•ืจื” ืžืกื•ื™ืžืช. ื›ื•ืชืจื•ืช ืืœื• ืื™ื ืŸ ื ืœืงื—ื•ืช ื‘ื—ืฉื‘ื•ืŸ ืขืœ ื™ื“ื™ ื”-CDN, ื›ืš ืฉืžื™ื“ืข ืขืœ ื—ื•ืกืจ ื”ื™ื›ื•ืœืช ืœื’ืฉืช ืœื“ืฃ ื™ื™ืฉืžืจ ื‘ืžื˜ืžื•ืŸ, ื•ื›ืœ ืฉืืจ ื‘ืงืฉื•ืช ื”ืžืฉืชืžืฉ ื”ืชืงืคื•ืช ืœืคื ื™ ืคืงื™ืขืช ื”ื–ืžืŸ ื”ืงืฆื•ื‘ ืขืœื•ืœื•ืช ืœื’ืจื•ื ืœืฉื’ื™ืื”, ืœืžืจื•ืช ื”ืขื•ื‘ื“ื” ืฉื”ืืชืจ ื”ืžืงื•ืจื™ ืžืฉืจืช ืืช ื”ืชื•ื›ืŸ ื‘ืœื™ ืฉื•ื ื‘ืขื™ื•ืช.

ืฉืœื•ืฉ ืืคืฉืจื•ื™ื•ืช ืชืงื™ืคื” ื”ื•ืฆืขื• ื›ื“ื™ ืœืืœืฅ ืืช ืฉืจืช ื”-HTTP ืœื”ื—ื–ื™ืจ ืฉื’ื™ืื”:

  • HMO (HTTP Method Override) - ืชื•ืงืฃ ื™ื›ื•ืœ ืœืขืงื•ืฃ ืืช ืฉื™ื˜ืช ื”ื‘ืงืฉื” ื”ืžืงื•ืจื™ืช ื‘ืืžืฆืขื•ืช ื”ื›ื•ืชืจื•ืช "X-HTTP-Method-Override", "X-HTTP-Method" ืื• "X-Method-Override", ื”ื ืชืžื›ื•ืช ืขืœ ื™ื“ื™ ืฉืจืชื™ื ืžืกื•ื™ืžื™ื, ืืš ืœื ื ืœืงื— ื‘ื—ืฉื‘ื•ืŸ ื‘-CDN. ืœื“ื•ื’ืžื”, ืืชื” ื™ื›ื•ืœ ืœืฉื ื•ืช ืืช ืฉื™ื˜ืช "GET" ื”ืžืงื•ืจื™ืช ืœืฉื™ื˜ืช "DELETE", ื”ืืกื•ืจื” ื‘ืฉืจืช, ืื• ืืช ืฉื™ื˜ืช "POST", ืฉืื™ื ื” ื™ืฉื™ืžื” ืขื‘ื•ืจ ืกื˜ื˜ื™ืงื”;

    ืžืชืงืคืช CPDoS ืฉื”ื•ืคื›ืช ื“ืคื™ื ื”ืžื•ื’ืฉื™ื ื“ืจืš CDN ืœืœื ื ื’ื™ืฉื™ื

  • HHO (HTTP Header Oversize) - ืชื•ืงืฃ ื™ื›ื•ืœ ืœื‘ื—ื•ืจ ืืช ื’ื•ื“ืœ ื”ื›ื•ืชืจืช ื›ืš ืฉื”ื•ื ื™ื—ืจื•ื’ ืžื”ืžื’ื‘ืœื” ืฉืœ ืฉืจืช ื”ืžืงื•ืจ, ืืš ืœื ื™ื™ื›ื ืก ืœืžื’ื‘ืœื•ืช ื”-CDN. ืœื“ื•ื’ืžื”, Apache httpd ืžื’ื‘ื™ืœ ืืช ื’ื•ื“ืœ ื”ื›ื•ืชืจืช ืœ-8 KB, ื•ืืžื–ื•ืŸ Cloudfront CDN ืžืืคืฉืจ ื›ื•ืชืจื•ืช ืฉืœ ืขื“ 20 KB;
    ืžืชืงืคืช CPDoS ืฉื”ื•ืคื›ืช ื“ืคื™ื ื”ืžื•ื’ืฉื™ื ื“ืจืš CDN ืœืœื ื ื’ื™ืฉื™ื

  • HMC (HTTP Meta Character) - ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ื›ื ื™ืก ืœื‘ืงืฉื” ืชื•ื•ื™ื ืžื™ื•ื—ื“ื™ื (\n, \r, \a), ื”ื ื—ืฉื‘ื™ื ืœื ื—ื•ืงื™ื™ื ื‘ืฉืจืช ื”ืžืงื•ืจ, ืืš ืžืชืขืœืžื™ื ืžื”ื ื‘-CDN.

    ืžืชืงืคืช CPDoS ืฉื”ื•ืคื›ืช ื“ืคื™ื ื”ืžื•ื’ืฉื™ื ื“ืจืš CDN ืœืœื ื ื’ื™ืฉื™ื

ื”ืจื’ื™ืฉ ื‘ื™ื•ืชืจ ืœื”ืชืงืคื” ื”ื™ื” ื”-CloudFront CDN ื”ืžืฉืžืฉ ืืช ืฉื™ืจื•ืชื™ ื”ืื™ื ื˜ืจื ื˜ ืฉืœ ืืžื–ื•ืŸ (AWS). ืืžื–ื•ืŸ ืชื™ืงื ื” ื›ืขืช ืืช ื”ื‘ืขื™ื” ืขืœ ื™ื“ื™ ื”ืฉื‘ืชืช ืฉืžื™ืจื” ื‘ืžื˜ืžื•ืŸ ืฉืœ ืฉื’ื™ืื•ืช, ืืš ืœืงื— ืœื—ื•ืงืจื™ื ื™ื•ืชืจ ืžืฉืœื•ืฉื” ื—ื•ื“ืฉื™ื ืœื”ื•ืกื™ืฃ ื”ื’ื ื”. ื”ื‘ืขื™ื” ื”ืฉืคื™ืขื” ื’ื ืขืœ Cloudflare, Varnish, Akamai, CDN77 ื•
ืžื”ืจ, ืื‘ืœ ื”ื”ืชืงืคื” ื“ืจื›ื ืžื•ื’ื‘ืœืช ืœืฉืจืชื™ ื™ืขื“ ื”ืžืฉืชืžืฉื™ื ื‘- IIS, ASP.NET, ื‘ืงื‘ื•ืง ะธ ืฉื—ืง 1. ื–ื” ืžืฆื•ื™ืŸ, ืฉ-11% ืžื”ื“ื•ืžื™ื™ื ื™ื ืฉืœ ืžืฉืจื“ ื”ื”ื’ื ื” ื”ืืžืจื™ืงืื™, 16% ืžื›ืชื•ื‘ื•ืช ื”ืืชืจื™ื ืžืžืกื“ ื”ื ืชื•ื ื™ื ืฉืœ HTTP Archive ื•ื›-30% ืž-500 ื”ืืชืจื™ื ื”ื’ื“ื•ืœื™ื ื‘ื™ื•ืชืจ ื”ืžื“ื•ืจื’ื™ื ืขืœ ื™ื“ื™ ืืœืงืกื” ืขืœื•ืœื™ื ืœื”ื™ื•ืช ื ืชื•ื ื™ื ืœื”ืชืงืคื”.

ื›ื“ืจืš ืœืขืงื™ืคืช ื”ื‘ืขื™ื” ืœื—ืกื™ืžืช ื”ืชืงืคื” ื‘ืฆื“ ื”ืืชืจ, ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ื›ื•ืชืจืช "Cache-Control: no-store", ื”ืื•ืกืจืช ืขืœ ืฉืžื™ืจืช ืชื’ื•ื‘ื•ืช ื‘ืžื˜ืžื•ืŸ. ื‘ื—ืœืง ืžื”-CDNs, ืœืžืฉืœ.
CloudFront ื•-Akamai, ืืชื” ื™ื›ื•ืœ ืœื‘ื˜ืœ ืืช ืื—ืกื•ืŸ ื”ืฉื’ื™ืื•ืช ื‘ืžื˜ืžื•ืŸ ื‘ืจืžืช ื”ื’ื“ืจื•ืช ื”ืคืจื•ืคื™ืœ. ืœื”ื’ื ื”, ืืชื” ื™ื›ื•ืœ ื’ื ืœื”ืฉืชืžืฉ ื‘ื—ื•ืžืช ืืฉ ืฉืœ ื™ื™ืฉื•ืžื™ ืื™ื ื˜ืจื ื˜ (WAF, Web Application Firewall), ืืš ื™ืฉ ืœื™ื™ืฉื ืื•ืชื ื‘ืฆื“ ื”-CDN ืžื•ืœ ื”ืžืืจื—ื™ื ื”ืžืื•ื—ืกื ื™ื ื‘ืžื˜ืžื•ืŸ.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”