äŒæ¥ãäœãããã«ããŠããã»ãã¥ãªãã£ã¯
æ»æè ãçµç¹ã® DNS ãå¶åŸ¡ã§ããããã«ãªããšã次ã®ããšãç°¡åã«å®è¡ã§ããŸãã
- å ±æãªãœãŒã¹ãèªåã§å¶åŸ¡ã§ããããã«ãã
- åä¿¡ã¡ãŒã«ãWeb ãªã¯ãšã¹ããèªèšŒè©Šè¡ããªãã€ã¬ã¯ãããŸãã
- SSL/TLS 蚌ææžãäœæããã³æ€èšŒãã
ãã®ã¬ã€ãã§ã¯ãDNS ã»ãã¥ãªãã£ã XNUMX ã€ã®è§åºŠããèå¯ããŸãã
- DNS ãä»ããç¶ç¶çãªç£èŠãšå¶åŸ¡ã®å®è¡
- DNSSECãDOHãDoT ãªã©ã®æ°ãã DNS ãããã³ã«ãéä¿¡ããã DNS ãªã¯ãšã¹ãã®æŽåæ§ãšæ©å¯æ§ãä¿è·ããæ¹æ³
DNSã»ãã¥ãªãã£ãšã¯äœã§ãã?
DNS ã»ãã¥ãªãã£ã®æŠå¿µã«ã¯ã次㮠XNUMX ã€ã®éèŠãªã³ã³ããŒãã³ããå«ãŸããŠããŸãã
- ãã¹ãåã IP ã¢ãã¬ã¹ã«è§£æ±ºãã DNS ãµãŒãã¹ã®å šäœçãªæŽåæ§ãšå¯çšæ§ã確ä¿ãã
- DNS ã¢ã¯ãã£ããã£ãç£èŠããŠããããã¯ãŒã¯äžã®ããããå Žæã§çºçããå¯èœæ§ã®ããã»ãã¥ãªãã£åé¡ãç¹å®ããŸã
DNS ãæ»æã«å¯ŸããŠè匱ãªã®ã¯ãªãã§ãã?
DNS ãã¯ãããžãŒã¯ããããã¯ãŒã¯ ã»ãã¥ãªãã£ã«ã€ããŠèª°ããèãå§ãããã£ãšåã®ãã€ã³ã¿ãŒãããã®åæã«äœæãããŸããã DNS ã¯èªèšŒãæå·åãè¡ããã«åäœãããŠãŒã¶ãŒããã®ãªã¯ãšã¹ããç²ç®çã«åŠçããŸãã
ãã®ããããŠãŒã¶ãŒã欺ããååãã IP ã¢ãã¬ã¹ãžã®è§£æ±ºãå®éã«è¡ãããå Žæã«é¢ããæ å ±ãæ¹ããããããŸããŸãªæ¹æ³ãååšããŸãã
DNS ã»ãã¥ãªãã£: åé¡ãšã³ã³ããŒãã³ã
DNS ã»ãã¥ãªãã£ã¯ããã€ãã®åºæ¬çãªèŠçŽ ã§æ§æãããŸã ã³ã³ããŒãã³ãå®å
šãªä¿è·ã確ä¿ããã«ã¯ããããããèæ
®ããå¿
èŠããããŸãã
- ãµãŒããŒã®ã»ãã¥ãªãã£ãšç®¡çæé ã®åŒ·å: ãµãŒããŒã»ãã¥ãªãã£ã®ã¬ãã«ãé«ããæšæºã®ã³ããã·ã§ãã³ã°ãã³ãã¬ãŒããäœæããŸã
- ãããã³ã«ã®æ¹å: DNSSECãDoTããŸã㯠DoH ãå®è£ ãã
- åæãšã¬ããŒã: ã€ã³ã·ãã³ãã調æ»ããéã«è¿œå ã®ã³ã³ããã¹ããåŸãããã«ãDNS ã€ãã³ã ãã°ã SIEM ã·ã¹ãã ã«è¿œå ããŸãã
- ãµã€ããŒã€ã³ããªãžã§ã³ã¹ãšè åšã®æ€åº: ã¢ã¯ãã£ããªè åšã€ã³ããªãžã§ã³ã¹ ãã£ãŒãã賌èªãã
- ãªãŒãã¡ãŒã·ã§ã³ïŒ ããã»ã¹ãèªååããããã«ã§ããã ãå€ãã®ã¹ã¯ãªãããäœæãã
äžèšã®é«ã¬ãã«ã®ã³ã³ããŒãã³ãã¯ãDNS ã»ãã¥ãªãã£ã®æ°·å±±ã®äžè§ã«ãããŸããã 次ã®ã»ã¯ã·ã§ã³ã§ã¯ãç¥ã£ãŠããã¹ãããå ·äœçãªäœ¿çšäŸãšãã¹ã ãã©ã¯ãã£ã¹ã«ã€ããŠè©³ãã説æããŸãã
DNSæ»æ
DNSã¹ããŒãã£ã³ã°ãŸãã¯ãã£ãã·ã¥ãã€ãºãã³ã° : ã·ã¹ãã ã®è匱æ§ãæªçšã㊠DNS ãã£ãã·ã¥ãæäœãããŠãŒã¶ãŒãå¥ã®å Žæã«ãªãã€ã¬ã¯ãããDNSãã³ããªã³ã° : äž»ã«ãªã¢ãŒãæ¥ç¶ä¿è·ããã€ãã¹ããããã«äœ¿çšãããŸã- DNSãã€ãžã£ãã¯: ãã¡ã€ã³ ã¬ãžã¹ãã©ãå€æŽããããšã«ãããéåžžã® DNS ãã©ãã£ãã¯ãå¥ã®ã¿ãŒã²ãã DNS ãµãŒããŒã«ãªãã€ã¬ã¯ããã
- NXDOMAIN æ»æ: 匷å¶çãªå¿çãååŸããããã«äžæ£ãªãã¡ã€ã³ ã¯ãšãªãéä¿¡ããããšã«ãããæš©åšãã DNS ãµãŒããŒã«å¯Ÿã㊠DDoS æ»æãå®è¡ãã
- ãã¡ã³ãã ãã¡ã€ã³: DNS ãªãŸã«ããŒãååšããªããã¡ã€ã³ããã®å¿çãåŸ æ©ããããšã«ãªããããã©ãŒãã³ã¹ãäœäžããŸãã
- ã©ã³ãã ãªãµããã¡ã€ã³ãžã®æ»æ: 䟵害ããããã¹ããšããããããã¯æå¹ãªãã¡ã€ã³ã«å¯Ÿã㊠DDoS æ»æãéå§ããŸãããæ»æã®çŠç¹ãåœã®ãµããã¡ã€ã³ã«éäžãããŠãDNS ãµãŒããŒã«ã¬ã³ãŒãã®æ€çŽ¢ã匷å¶ãããµãŒãã¹ã®å¶åŸ¡ãåŒãç¶ããŸãã
- ãã¡ã€ã³ã®ãããã¯: DNS ãµãŒã㌠ãªãœãŒã¹ããããã¯ããããã«è€æ°ã®ã¹ãã å¿çãéä¿¡ããŠããŸã
- å å ¥è æ©åšããã®ããããããæ»æ: ç¹å®ã® Web ãµã€ãã«ã³ã³ãã¥ãŒãã£ã³ã°èœåãéäžãããŠãã©ãã£ãã¯èŠæ±ã§éè² è·ã«ãããã³ã³ãã¥ãŒã¿ãŒãã¢ãã ãã«ãŒã¿ãŒããã®ä»ã®ããã€ã¹ã®éå
DNSæ»æ
äœããã®æ¹æ³ã§ DNS ã䜿çšããŠä»ã®ã·ã¹ãã ãæ»æããæ»æ (ã€ãŸããDNS ã¬ã³ãŒãã®å€æŽãæçµç®æšã§ã¯ãããŸãã):
- ãã¡ã¹ããã©ãã¯ã¹
- ã·ã³ã°ã«ãã©ãã¯ã¹ãããã¯ãŒã¯
- ããã«ãã©ãã¯ã¹ãããã¯ãŒã¯
DNSãã³ããªã³ã°
DNSæ»æ
æ»æè ãå¿ èŠãšãã IP ã¢ãã¬ã¹ã DNS ãµãŒããŒããè¿ãããæ»æ:
- DNSã¹ããŒãã£ã³ã°ãŸãã¯ãã£ãã·ã¥ãã€ãºãã³ã°
- DNSãã€ãžã£ãã¯
DNSSECãšã¯äœã§ãã?
DNSSEC (ãã¡ã€ã³ ããŒã ãµãŒãã¹ ã»ãã¥ãªã㣠ãšã³ãžã³) ã¯ãç¹å®ã® DNS èŠæ±ããšã«äžè¬çãªæ
å ±ãç¥ãå¿
èŠããªããDNS ã¬ã³ãŒããæ€èšŒããããã«äœ¿çšãããŸãã
DNSSEC ã¯ãããžã¿ã«çœ²åã㌠(PKI) ã䜿çšããŠããã¡ã€ã³åã¯ãšãªã®çµæãæå¹ãªãœãŒã¹ããã®ãã®ã§ãããã©ãããæ€èšŒããŸãã
DNSSEC ã®å®è£
ã¯æ¥çã®ãã¹ã ãã©ã¯ãã£ã¹ã§ããã ãã§ãªããã»ãšãã©ã® DNS æ»æãåé¿ããã®ã«ãå¹æçã§ãã
DNSSEC ã®ä»çµã¿
DNSSEC 㯠TLS/HTTPS ãšåæ§ã«æ©èœããå ¬éããŒãšç§å¯ããŒã®ãã¢ã䜿çšã㊠DNS ã¬ã³ãŒãã«ããžã¿ã«çœ²åããŸãã ããã»ã¹ã®äžè¬çãªæŠèŠ:
- DNS ã¬ã³ãŒãã¯ç§å¯éµãšç§å¯éµã®ãã¢ã§çœ²åãããŸã
- DNSSEC ã¯ãšãªã«å¯Ÿããå¿çã«ã¯ãèŠæ±ãããã¬ã³ãŒãã眲åãå ¬éããŒãå«ãŸããŸãã
- ãã®åŸ
å ¬ééµ èšé²ãšçœ²åã®ä¿¡é Œæ§ãæ¯èŒããããã«äœ¿çšãããŸã
DNS ãš DNSSEC ã®ã»ãã¥ãªãã£
DNSSEC ã¯ãDNS ã¯ãšãªã®æŽåæ§ããã§ãã¯ããããã®ããŒã«ã§ãã DNS ãã©ã€ãã·ãŒã«ã¯åœ±é¿ããŸããã èšãæããã°ãDNSSEC ã䜿çšãããšãDNS ã¯ãšãªã«å¯Ÿããçããæ¹ãããããŠããªããšãã確信ãåŸãããŸãããæ»æè
ã¯éä¿¡ãããçµæã誰ã§ãèŠãããšãã§ããŸãã
DoT - DNS over TLS
Transport Layer Security (TLS) ã¯ããããã¯ãŒã¯æ¥ç¶ãä»ããŠéä¿¡ãããæ å ±ãä¿è·ããããã®æå·åãããã³ã«ã§ãã ã¯ã©ã€ã¢ã³ããšãµãŒããŒéã§å®å šãª TLS æ¥ç¶ã確ç«ããããšãéä¿¡ãããããŒã¿ã¯æå·åããã仲ä»è ã¯ãã®ããŒã¿ãèŠãããšãã§ããªããªããŸãã
DNS-over-TLS (DNS over TLSãDoT) ã¯ãTLS ãããã³ã«ã䜿çšããŠãéåžžã® DNS èŠæ±ã® UDP ãã©ãã£ãã¯ãæå·åããŸãã
ãããã®ãªã¯ãšã¹ãããã¬ãŒã³ ããã¹ãã§æå·åãããšããªã¯ãšã¹ããè¡ããŠãŒã¶ãŒãã¢ããªã±ãŒã·ã§ã³ãããŸããŸãªæ»æããä¿è·ã§ããŸãã
- MitMããŸãã¯ãäžéè ã: æå·åãè¡ããªããšãã¯ã©ã€ã¢ã³ããšæš©åš DNS ãµãŒããŒã®éã®äžéã·ã¹ãã ãããªã¯ãšã¹ãã«å¿ããŠèª€ã£ãæ å ±ãå±éºãªæ å ±ãã¯ã©ã€ã¢ã³ãã«éä¿¡ããå¯èœæ§ããããŸãã
- ã¹ãã€æŽ»åãšè¿œè·¡: ãªã¯ãšã¹ããæå·åããªããšãããã«ãŠã§ã¢ ã·ã¹ãã ã¯ç¹å®ã®ãŠãŒã¶ãŒãŸãã¯ã¢ããªã±ãŒã·ã§ã³ãã©ã®ãµã€ãã«ã¢ã¯ã»ã¹ããŠããããç°¡åã«ç¢ºèªã§ããŸãã DNS ã ãã§ã¯ Web ãµã€ãäžã§ã¢ã¯ã»ã¹ãããŠããç¹å®ã®ããŒãžãæããã«ããããšã¯ã§ããŸããããèŠæ±ããããã¡ã€ã³ãç¥ãã ãã§ãã·ã¹ãã ãŸãã¯å人ã®ãããã¡ã€ã«ãäœæããã®ã«ååã§ãã
åºæïŒ
DoH - DNS over HTTPS
DNS-over-HTTPS (DNS over HTTPSãDoH) ã¯ãMozilla ãš Google ãå ±åã§æšé²ããå®éšçãªãããã³ã«ã§ãã ãã®ç®æšã¯ DoT ãããã³ã«ãšäŒŒãŠãããDNS ãªã¯ãšã¹ããšå¿çãæå·åããããšã§ãªã³ã©ã€ã³ã§ã®äººã ã®ãã©ã€ãã·ãŒã匷åããŸãã
æšæºã® DNS ã¯ãšãªã¯ UDP çµç±ã§éä¿¡ãããŸãã ãªã¯ãšã¹ããšã¬ã¹ãã³ã¹ã¯ã次ã®ãããªããŒã«ã䜿çšããŠè¿œè·¡ã§ããŸãã
DoH ã¯ç°ãªãã¢ãããŒããæ¡çšããæå·åããããã¹ãå解決ãªã¯ãšã¹ãã HTTPS æ¥ç¶çµç±ã§éä¿¡ããŸããããã¯ããããã¯ãŒã¯äžã®ä»ã® Web ãªã¯ãšã¹ããšåãããã«èŠããŸãã
ãã®éãã¯ãã·ã¹ãã 管çè ãšåå解決ã®å°æ¥ã®äž¡æ¹ã«ãšã£ãŠéåžžã«éèŠãªæå³ãæã¡ãŸãã
- DNS ãã£ã«ã¿ãªã³ã°ã¯ãäŒæ¥ãããã¯ãŒã¯äžã®ãã£ãã·ã³ã°æ»æããã«ãŠã§ã¢ãé åžãããµã€ãããŸãã¯ãã®ä»ã®æœåšçã«æ害ãªã€ã³ã¿ãŒããã掻åãããŠãŒã¶ãŒãä¿è·ããããã«ãWeb ãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ããäžè¬çãªæ¹æ³ã§ãã DoH ãããã³ã«ã¯ãããã®ãã£ã«ã¿ãŒããã€ãã¹ããããããŠãŒã¶ãŒãšãããã¯ãŒã¯ããã倧ããªãªã¹ã¯ã«ãããããå¯èœæ§ããããŸãã
- çŸåšã®åå解決ã¢ãã«ã§ã¯ããããã¯ãŒã¯äžã®ãã¹ãŠã®ããã€ã¹ãå€ããå°ãªããåãå Žæ (æå®ããã DNS ãµãŒããŒ) ãã DNS ã¯ãšãªãåä¿¡ããŸãã DoHãç¹ã« Firefox ã®å®è£ ã¯ããããå°æ¥å€æŽãããå¯èœæ§ãããããšã瀺ããŠããŸãã ã³ã³ãã¥ãŒã¿ãŒäžã®åã¢ããªã±ãŒã·ã§ã³ã¯ããŸããŸãª DNS ãœãŒã¹ããããŒã¿ãåä¿¡ããå¯èœæ§ãããããããã©ãã«ã·ã¥ãŒãã£ã³ã°ãã»ãã¥ãªãã£ããªã¹ã¯ ã¢ããªã³ã°ãã¯ããã«è€éã«ãªããŸãã
åºæïŒ
DNS over TLS ãš DNS over HTTPS ã®éãã¯äœã§ãã?
DNS over TLS (DoT) ããå§ããŸãããã ããã§ã®éèŠãªç¹ã¯ãå ã® DNS ãããã³ã«ã¯å€æŽããããå®å šãªãã£ãã«ãéããŠå®å šã«éä¿¡ãããã ãã§ãããšããããšã§ãã äžæ¹ãDoH ã¯ããªã¯ãšã¹ããè¡ãåã« DNS ã HTTP 圢åŒã«å€æããŸãã
DNSç£èŠã¢ã©ãŒã
ãããã¯ãŒã¯äžã® DNS ãã©ãã£ãã¯ãå¹æçã«ç£èŠããŠçãããç°åžžããªãã確èªããæ©èœã¯ã䟵害ãæ©æã«æ€åºããããã«éèŠã§ãã Varonis Edge ã®ãããªããŒã«ã䜿çšãããšããã¹ãŠã®éèŠãªã¡ããªã¯ã¹ãåžžã«ææ¡ãããããã¯ãŒã¯äžã®ãã¹ãŠã®ã¢ã«ãŠã³ãã®ãããã¡ã€ã«ãäœæã§ããŸãã ç¹å®ã®æéã«çºçããã¢ã¯ã·ã§ã³ã®çµã¿åããã®çµæãšããŠã¢ã©ãŒããçæãããããã«æ§æã§ããŸãã
DNS ã®å€æŽãã¢ã«ãŠã³ãã®å Žæãæ©å¯ããŒã¿ãžã®åå䜿çšãšã¢ã¯ã»ã¹ãå¶æ¥æéå€ã®ã¢ã¯ãã£ããã£ã®ã¢ãã¿ãªã³ã°ã¯ãããåºç¯ãªæ€åºç¶æ³ãæ§ç¯ããããã«çžäºã«é¢é£ä»ããããšãã§ããææšã®ã»ãã®äžéšã§ãã
åºæïŒ habr.com