ç»åïŒ
DoS æ»æã¯ãçŸä»£ã®ã€ã³ã¿ãŒãããã«ãããæ å ±ã»ãã¥ãªãã£ã«å¯Ÿããæ倧ã®è åšã® XNUMX ã€ã§ãã æ»æè ããã®ãããªæ»æãå®è¡ããããã«ã¬ã³ã¿ã«ããããããããã¯æ°åãããŸãã
ãµã³ãã£ãšãŽå€§åŠã®ç§åŠè
ã¯ããã«: DoS 察çããŒã«ãšããŠã®ãããã·
åæ§ã®å®éšã¯ããŸããŸãªåœã®ç 究è ã«ãã£ãŠå®æçã«å®æœãããŠããŸãããå ±éã®åé¡ã¯ãçŸå®ã«è¿ãæ»æãã·ãã¥ã¬ãŒãããããã®ãªãœãŒã¹ãäžè¶³ããŠããããšã§ãã å°èŠæš¡ãªãã³ãã§ã®ãã¹ãã§ã¯ããããã·ãè€éãªãããã¯ãŒã¯ã§ã®æ»æã«ã©ã®çšåºŠããŸãæµæã§ãããã被害ãæå°éã«æããèœåã«ãããŠã©ã®ãã©ã¡ãŒã¿ãéèŠãªåœ¹å²ãæããããªã©ã«ã€ããŠã®è³ªåã«çããããšã¯ã§ããŸããã
å®éšã®ããã«ãç§åŠè ãã¡ã¯ãé»ååååŒãµãŒãã¹ãªã©ã®å žåç㪠Web ã¢ããªã±ãŒã·ã§ã³ã®ã¢ãã«ãäœæããŸããã ããã¯ãµãŒããŒã®ã¯ã©ã¹ã¿ãŒã®å©ããåããŠæ©èœãããŠãŒã¶ãŒã¯å°ççã«ç°ãªãå Žæã«åæ£ããã€ã³ã¿ãŒãããã䜿çšããŠãµãŒãã¹ã«ã¢ã¯ã»ã¹ããŸãã ãã®ã¢ãã«ã§ã¯ãã€ã³ã¿ãŒãããã¯ãµãŒãã¹ãšãŠãŒã¶ãŒéã®éä¿¡æ段ãšããŠæ©èœããŸããããããæ€çŽ¢ãšã³ãžã³ãããªã³ã©ã€ã³ ãã³ãã³ã° ããŒã«ã«è³ã Web ãµãŒãã¹ã®ä»çµã¿ã§ãã
DoS æ»æã«ããããµãŒãã¹ãšãŠãŒã¶ãŒéã®éåžžã®å¯Ÿè©±ãäžå¯èœã«ãªããŸãã DoS ã«ã¯ãã¢ããªã±ãŒã·ã§ã³å±€æ»æãšã€ã³ãã©ã¹ãã©ã¯ãã£å±€æ»æã® XNUMX çš®é¡ããããŸãã åŸè
ã®å Žåãæ»æè
ã¯ãããã¯ãŒã¯ãšãµãŒãã¹ãå®è¡ãããŠãããã¹ããçŽæ¥æ»æããŸã (ããšãã°ããã©ãã ãã©ãã£ãã¯ã§ãããã¯ãŒã¯åž¯åå¹
å
šäœããã©ããã£ã³ã°ããŸã)ã ã¢ããªã±ãŒã·ã§ã³ ã¬ãã«ã®æ»æã®å Žåãæ»æè
ã®ã¿ãŒã²ããã¯ãŠãŒã¶ãŒ ã€ã³ã¿ã©ã¯ã·ã§ã³ ã€ã³ã¿ãŒãã§ã€ã¹ã§ãããã®ãããã¢ããªã±ãŒã·ã§ã³ãã¯ã©ãã·ã¥ãããããã«èšå€§ãªæ°ã®ãªã¯ãšã¹ããéä¿¡ãããŸãã 説æãããå®éšã¯ãã€ã³ãã©ã¹ãã©ã¯ã㣠ã¬ãã«ã§ã®æ»æã«é¢ãããã®ã§ããã
ãããã· ãããã¯ãŒã¯ã¯ãDoS æ»æã«ãã被害ãæå°éã«æããããŒã«ã® XNUMX ã€ã§ãã ãããã·ã䜿çšããå ŽåããŠãŒã¶ãŒãããµãŒãã¹ãžã®ãã¹ãŠã®ãªã¯ãšã¹ããšããã«å¯Ÿããå¿çã¯çŽæ¥éä¿¡ããããäžéãµãŒããŒãä»ããŠéä¿¡ãããŸãã ãŠãŒã¶ãŒãšã¢ããªã±ãŒã·ã§ã³ã¯äž¡æ¹ãšããäºããçŽæ¥ãèªèãããããããã· ã¢ãã¬ã¹ã®ã¿ã䜿çšã§ããŸãã ãã®çµæãã¢ããªã±ãŒã·ã§ã³ãçŽæ¥æ»æããããšã¯äžå¯èœã«ãªããŸãã ãããã¯ãŒã¯ã®ãšããžã«ã¯ããããããšããž ãããã·ãã€ãŸãå©çšå¯èœãª IP ã¢ãã¬ã¹ãæã€å€éšãããã·ããããæ¥ç¶ã¯æåã«ãããã«æ¥ç¶ãããŸãã
DoS æ»æã«ããŸãæµæããã«ã¯ããããã· ãããã¯ãŒã¯ã«ã¯ XNUMX ã€ã®éèŠãªæ©èœãå¿
èŠã§ãã ãŸãããã®ãããªäžéãããã¯ãŒã¯ã¯ä»²ä»è
ã®åœ¹å²ãæããå¿
èŠããããŸããã€ãŸãããããä»ããŠã®ã¿ã¢ããªã±ãŒã·ã§ã³ã«ãå°éãã§ããŸãã ããã«ããããµãŒãã¹ã«å¯ŸããçŽæ¥æ»æã®å¯èœæ§ãæé€ãããŸãã 次ã«ããããã· ãããã¯ãŒã¯ã¯ãæ»æäžã§ãã£ãŠããŠãŒã¶ãŒãã¢ããªã±ãŒã·ã§ã³ãæäœã§ããããã«ããå¿
èŠããããŸãã
å®éšã€ã³ãã©
ãã®èª¿æ»ã§ã¯ã次㮠XNUMX ã€ã®äž»èŠãªèŠçŽ ã䜿çšãããŸããã
- ãããã·ãããã¯ãŒã¯ã®å®è£ ã
- Apache WebãµãŒããŒ
- Webãã¹ãããŒã«
å å² ; - æ»æããŒã«
ããªã㌠.
ã·ãã¥ã¬ãŒã·ã§ã³ã¯ MicroGrid ç°å¢ã§å®è¡ãããŸãããMicroGrid ç°å¢ã䜿çšãããšãTier-20 ãªãã¬ãŒã¿ãŒã®ãããã¯ãŒã¯ã«å¹æµãã 1 å°ã®ã«ãŒã¿ãŒãåãããããã¯ãŒã¯ãã·ãã¥ã¬ãŒãã§ããŸãã
äžè¬ç㪠Trinoo ãããã¯ãŒã¯ã¯ãããã°ã©ã ã®ããŒã¢ã³ãå®è¡ãã䟵害ããããã¹ãã®ã»ããã§æ§æãããŸãã ãããã¯ãŒã¯ãå¶åŸ¡ããDoS æ»æãæ瀺ããç£èŠãœãããŠã§ã¢ããããŸãã IP ã¢ãã¬ã¹ã®ãªã¹ããäžãããããšãTrinoo ããŒã¢ã³ã¯æå®ãããæå»ã« UDP ãã±ãããã¿ãŒã²ããã«éä¿¡ããŸãã
å®éšäžã16 ã€ã®ã¯ã©ã¹ã¿ãŒã䜿çšãããŸããã MicroGrid ã·ãã¥ã¬ãŒã¿ãŒã¯ã2.4Gbps ã€ãŒãµããã ããçµç±ã§æ¥ç¶ããã 1 ããŒã (ãã·ã³ããã 1GB ã®ã¡ã¢ãªãåãã 24GHz ãµãŒããŒ) ãããªã Xeon Linux ã¯ã©ã¹ã¿ãŒäžã§å®è¡ãããŸããã ä»ã®ãœãããŠã§ã¢ ã³ã³ããŒãã³ãã¯ã450Mbps ã€ãŒãµããã ããã§æ¥ç¶ããã 1 ããŒã (ãã·ã³ããã 100 GB ã®ã¡ã¢ãªãåãã 1MHz PII Linux-cthdths) ã®ã¯ã©ã¹ã¿ãŒå ã«é 眮ãããŸããã XNUMX ã€ã®ã¯ã©ã¹ã¿ãŒã¯ XNUMXGbps ãã£ãã«ã§æ¥ç¶ãããŸããã
ãããã· ãããã¯ãŒã¯ã¯ã1000 å°ã®ãã¹ãã®ããŒã«ã§ãã¹ããããŸãã ãšããž ãããã·ã¯ããªãœãŒã¹ ããŒã«å šäœã«åçã«åæ£ãããŸãã ã¢ããªã±ãŒã·ã§ã³ãæäœããããã®ãããã·ã¯ããã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã«è¿ããã¹ãäžã«é 眮ãããŸãã æ®ãã®ãããã·ã¯ããšããž ãããã·ãšã¢ããªã±ãŒã·ã§ã³ ãããã·ã®éã§åçã«åæ£ãããŸãã
ã·ãã¥ã¬ãŒã·ã§ã³çšãããã¯ãŒã¯
DoS æ»æã«å¯ŸæããããŒã«ãšããŠã®ãããã·ã®æå¹æ§ãç 究ããããã«ãç 究è ãã¯ãå€éšåœ±é¿ã®ããŸããŸãªã·ããªãªã®äžã§ã¢ããªã±ãŒã·ã§ã³ã®çç£æ§ã枬å®ããŸããã ãããã· ãããã¯ãŒã¯ã«ã¯åèš 192 ã®ãããã·ããããŸãã (ãã®ãã¡ 64 ã¯å¢çã®ãããã·ã§ãã)ã æ»æãå®è¡ããããã«ã100 äœã®æªéãå«ãããªã㌠ãããã¯ãŒã¯ãäœæãããŸããã åããŒã¢ã³ã«ã¯ 100Mbps ãã£ãã«ããããŸããã ããã¯ã10 å°ã®ããŒã ã«ãŒã¿ãŒã®ããããããã«çžåœããŸãã
ã¢ããªã±ãŒã·ã§ã³ãšãããã· ãããã¯ãŒã¯ã«å¯Ÿãã DoS æ»æã®åœ±é¿ã枬å®ãããŸããã å®éšçãªæ§æã§ã¯ãã¢ããªã±ãŒã·ã§ã³ã®ã€ã³ã¿ãŒããã ãã£ãã«ã¯ 250 Mbpsãåå¢çãããã·ã®é床㯠100 Mbps ã§ããã
å®éšçµæ
åæã®çµæã250Mbpsãžã®æ»æã«ããã¢ããªã±ãŒã·ã§ã³ã®å¿çæéãå€§å¹ ã«ïŒçŽXNUMXåïŒå¢å ãããã®çµæãã¢ããªã±ãŒã·ã§ã³ã䜿çšã§ããªããªãããšãå€æããŸããã ãã ãããããã· ãããã¯ãŒã¯ã䜿çšããå Žåãæ»æã¯ããã©ãŒãã³ã¹ã«å€§ããªåœ±é¿ãäžããããŠãŒã¶ãŒ ãšã¯ã¹ããªãšã³ã¹ãäœäžãããŸããã ããã¯ããšããž ãããã·ãæ»æã®å¹æã匱ãããããã· ãããã¯ãŒã¯ã®ç·ãªãœãŒã¹ãã¢ããªã±ãŒã·ã§ã³èªäœã®ãªãœãŒã¹ããã倧ããããã§ãã
çµ±èšã«ãããšãæ»æåã 6.0 Gbps ãè¶ ããªãå Žå (ããŒã㌠ãããã· ãã£ãã«ã®åèšåž¯åå¹ ãããã 6.4 Gbps ã§ããã«ãããããã)ã95% ã®ãŠãŒã¶ãŒã¯ç®ç«ã£ãããã©ãŒãã³ã¹ã®äœäžãçµéšããŸããã åæã«ã6.4Gbpsãè¶ ããéåžžã«åŒ·åãªæ»æã®å Žåããããã·ãããã¯ãŒã¯ã䜿çšããŠããšã³ããŠãŒã¶ãŒãžã®ãµãŒãã¹ã¬ãã«ã®äœäžã¯é¿ããããŸããã
éäžæ»æã®å Žåãæ»æã®åãã©ã³ãã ãªãšããž ãããã·ã®ã»ããã«éäžããŸãã ãã®å Žåãæ»æã«ãããããã· ãããã¯ãŒã¯ã®äžéšãè©°ãŸããããããªãã®éšåã®ãŠãŒã¶ãŒãããã©ãŒãã³ã¹ã®äœäžã«æ°ã¥ãããšã«ãªããŸãã
æèŠ
å®éšã®çµæã¯ããããã· ãããã¯ãŒã¯ã TCP ã¢ããªã±ãŒã·ã§ã³ã®ããã©ãŒãã³ã¹ãåäžãããDoS æ»æãçºçããå Žåã§ããŠãŒã¶ãŒã«äœ¿ãæ £ããã¬ãã«ã®ãµãŒãã¹ãæäŸã§ããããšã瀺åããŠããŸãã åŸãããããŒã¿ã«ãããšããããã¯ãŒã¯ ãããã·ã¯æ»æã®åœ±é¿ãæå°éã«æããå¹æçãªæ¹æ³ã§ãããå®éšäžã« 90% 以äžã®ãŠãŒã¶ãŒããµãŒãã¹å質ã®äœäžãæããŸããã§ããã ããã«ãç 究è ãã¯ããããã· ãããã¯ãŒã¯ã®ãµã€ãºãå¢å ããã«ã€ããŠãèãããã DoS æ»æã®èŠæš¡ãã»ãŒçŽç·çã«å¢å ããããšãçºèŠããŸããã ãããã£ãŠããããã¯ãŒã¯ã倧èŠæš¡ã§ããã°ããã»ã©ãDoS ã«å¹æçã«å¯ŸåŠã§ããŸãã
ããã®åœ¹ç«ã€ãªã³ã¯ãšè³æ ã€ã³ãã¡ãã£ã« :
ç 究: ã²ãŒã çè«ã䜿çšãããããã¯èæ§ã®ãããããã· ãµãŒãã¹ã®äœæ æ€é²ãšã®æŠãã®æŽå²: MIT ãšã¹ã¿ã³ãã©ãŒãã®ç§åŠè ã«ãã£ãŠäœæããããã©ãã·ã¥ ãããã·ææ³ãã©ã®ããã«æ©èœããã ãããã·ãåãã€ããŠããå Žåãç解ããæ¹æ³: ã¢ã¯ãã£ããªå°çäœçœ®æ å ±ã¢ã«ãŽãªãºã ã䜿çšãããããã¯ãŒã¯ ãããã·ã®ç©ççãªäœçœ®ã®æ€èšŒ ã€ã³ã¿ãŒãããäžã§èªåãåœè£ ããæ¹æ³: ãµãŒã㌠ãããã·ãšäœå® çšãããã·ã®æ¯èŒ
åºå ž: www.habr.com