å æ¥ã®ãããµã2010ã§ã話ãã(デブサミ2010の資料"クラウドサービスAmazon EC2を活用した「SKIPaaS」構築事例"を公開します+α)ã®ã§ãããAmazon EC2ã®ãµã¼ãããã¡ã¼ã«ãéä¿¡ããã¨ãä¸é¨åã®å®å (ã¡ã¼ã«ãµã¼ã)ã§ã¯ãè¿·æã¡ã¼ã«(SPAM)æ±ããããçªãè¿ããã¡ããäºãããã¾ãã
ãããã©ã解決ãããã¨ãã話ã
Twitterãè¦ã¦ãã¦ãã¾ã ãã¡ãã¨ããæ
å ±ãã¾ã¨ã¾ã£ã¦ããªãæ°ãããã®ã§ãçµé¨è«ãã¾ã¨ãã¦ã¿ã¾ãã
課é¡
Amazon EC2ã®ãµã¼ããã¹ãã ã¡ã¼ã«éä¿¡ã«å©ç¨ãããã±ã¼ã¹ãå¢ãã¦ããããã§ãAmazon EC2ã§å©ç¨ããã¦ããIPã¢ãã¬ã¹ã®ã¬ã³ã¸(ãããã¯ã¼ã¯)ããã¹ãã ã¡ã¼ã«ã®ãã©ãã¯ãªã¹ãã«ã¾ãã£ã¨è¼ã£ã¦ãã¾ã£ã¦ãããããã¡ã¼ã«ãµã¼ãã«ãã£ã¦ã¯ãéåæãã«ããåä¿¡æå¦ã¨ãªãã±ã¼ã¹ãããã¾ãã
åèï¼
Amazon EC2ãæªç¨ããã»ãã¥ãªãã£æ»æã«ã¤ãã¦æ°äºæ°ã¯ããWebã¢ããªã±ã¼ã·ã§ã³ãçãæ»æãå¢ãã¦ãããè¿·æã¡ã¼ã«ã®è¸ã¿å°ã¨ãã¦å©ç¨å¯è½ãã©ããã調æ»ããæ´»åããã£ããã¨èª¬æãããã«å¯¾ãã¦ãä¸çæ大ã®è¿·æã¡ã¼ã«å¯¾ççµç¹ã¨è¨ããããSpamhausãããAmazon EC2ããã©ãã¯ãªã¹ãã¨ãã¦æå®ããåããè¦ãããã¨ããã
セキュリティにクラウドの闇、Amazon EC2悪用の総当たり攻撃も -INTERNET Watch Watch
é éã¡ã¼ã«ãSPAMæ±ããããªãããã«æä½éãããã¨
åºæ¬çãªãã¨ã®ã¿ã§ã足ãã¦ããªãå¯è½æ§ãããã¾ããã主ã«ä»¥ä¸ã®3ç¹ãå®æ½ããã¨ãããçªãè¿ããããã¨ãªããã¬ã¤ã«éä¿¡ã§ããããã«ãªãã¾ããã
- DNSéå¼ãè¨å®
- SPFã®è¨å®
- SPAMã¡ã¼ã«ã®ãã©ãã¯ãªã¹ãã«å¯¾ãã解é¤ç³è«
以ä¸ã§ãããããã詳ããç´¹ä»ãã¦ã¿ã¾ãã
EC2ã§ã®DNSéå¼ãè¨å®
ã¡ã¼ã«ãµã¼ãã«ãã£ã¦ã¯ãéä¿¡å
ã®ãã¹ãã§ãDNSéå¼ãè¨å®ããªãããããã¯æ£å¼ãã¨ã®è¨å®ã«å·®ç°ãããå ´åãSMTPæ¥ç¶ãæå¦ãããå ´åãããã¾ãã(ãã§ãã¯ããã¦ãã)
ãhttp://neta.ywcafe.net/000395.htmlãã®ã¨ã³ããªãèªãéãã§ã¯ããã®å¤å®ã¯å¾®å¦ãªã¨ããã§ã¯ããã¾ããã
åé¡ã¯ãAmazon EC2ã§ã¯ãDNSã®éå¼ãè¨å®ã«ã以ä¸ã®ãããªæ¢å®å¤ãè¨å®ããã¦ãã¦ãåºæ¬çã«ã¦ã¼ã¶ãèªç±ã«è¨å®ãããã¨ãã§ããªãç¹ã§ããã
IPã¢ãã¬ã¹ <=> FQDN xxx.xxx.xxx.xxx <=> ec2-xxx-xxx-xxx-xxx.compute-1.amazonaws.com
ã§ãããå®ã¯ã¾ã "Private Beta"æ±ãã§ã¯ããã¾ãããDNSã®éå¼ãè¨å®ããé¡ãããã¨ãAWSå´ã§è¨å®ãã¦ããããããã¾ãã(ä¸è¨URLåç
§)
- http://developer.amazonwebservices.com/connect/thread.jspa?messageID=155999#155999
- http://developer.amazonwebservices.com/connect/message.jspa?messageID=163245
詳細ã¯ä¸è¨URLã«è¨è¼ããã¦ãã¾ãããAWSã®ä¸ã®äººã«Developer Communityã®Forumã§ãPrivate Messageãéã£ã¦ãé¡ãããå½¢ã§ãã(è±èªã§ã®ããåãã«ãªãã¾ãã®ã§ãæ·å±
ã¯é«ãã§ãã...)
ãã®ãµã¼ãã¹ã¯ãpublic beta soon.ãã¨ã®ãã¨ã§ãã®ã§ãè¿ããã¡ã«ãµã¼ãã¹åãããã¨æãã¾ãã
3/24: 追è¨ï¼
æ£å¼ã«ãµã¼ãã¹åããã模æ§ã§ãï¼DNSéå¼ãè¨å®ã®ç³è«ã¯ä»¥ä¸ããï¼
SPFã®è¨å®
"SPF"ãä½ããè¨å®æ¹æ³ã«ã¤ãã¦ã¯ã以ä¸ã®ã¨ã³ããªãããªã詳ããããããã¡ãããèªã¿ãã ããã
ã¤ã¾ãã¯ã
SPF(Sender Policy Framework)ã¨ã¯ãã¡ã¼ã«ãéåºããMTAãæ£å½ãªMTAã§ãããã¨ã証æããããã®æè¡ã ã
今すぐSPFを書こう
ã¨ãããã¨ã§ãFromãã"@example.com"ã®ã¡ã¼ã«ã¯ã"xxx.xxx.xxx.xxx"ããéä¿¡ããã¦ãããã®ãæ¬ç©ã§ã£ããã¨ãã証æããã¡ã¤ã³ææè ãDNSè¨å®(TXTã¬ã³ã¼ã)ã§è¡ãã¨ãããã®ã
DNSã®è¨å®ã¯ã以ä¸ã®ãããªæãã§è¡ãã¾ãã
IN TXT "v=spf1 +ip4:***.***.***.*** -all"
SPAMã¡ã¼ã«ã®ãã©ãã¯ãªã¹ãã«å¯¾ãã解é¤ç³è«
Spamhausã¨maps(mail-abuse.com)ã§ç®¡çããã¦ããã¹ãã ã¡ã¼ã«éä¿¡å ã管çãããã©ãã¯ãªã¹ãã«Amazon EC2ã§ä½¿ããã¦ããIPã¢ãã¬ã¹ãé¨åçã«ç»é²ããã¦ãããã¨ã«ããã以ä¸ãã©ãã¯ãªã¹ãã§ã®ãã§ãã¯ãè¡ã£ã¦ããã¡ã¼ã«ãµã¼ãããæå¦ãããç¾è±¡ã¸ã®å¯¾çã¨ãã¦ããã©ãã¯ãªã¹ããã解é¤ç³è«ãè¡ãã¾ãã
ã¾ãã以ä¸ã®URLããå©ç¨ãã¦ããEC2ã®ãµã¼ãã®IPã¢ãã¬ã¹ããã©ãã¯ãªã¹ãã«å«ã¾ãã¦ãããã確èªãã¾ãã
ãã®å¾ã解é¤ç³è«ã®æç¶ããè¡ããã¨ã«ãªãã¨æãã¾ãããåé¡ãªãIPã¢ãã¬ã¹ã証æããæ段ã¨ãã¦ãå
ã»ã©æ¸ããéããDNSã®éå¼ãã¨æ£å¼ãã®çµæãä¸è´ããã¦ããå¿
è¦ãããããã§ãã
ç§ã®å¯¾å¦çµé¨ããã®æµããæ¸ãã¦ããã¨ããã
- æåã«ãSpamhausã®ã¹ãã ãªã¹ãã«å¼ã£ããã£ã¦ããäºã«æ°ä»ã
- DNSã®éå¼ããã§ãã¯ã§ã¯ãããã¦ããã¡ã¼ã«ãããã¤ã
- Elastic IPãä½åº¦ãåå¾/解æ¾ãç¹°ãè¿ããSpamhausã®ãã©ãã¯ãªã¹ãã«è¼ã£ã¦ããªãIPã¢ãã¬ã¹ã確ä¿
- ãã©ãã¯ãªã¹ãã«è¼ã£ã¦ããªãã¬ã³ã¸ãããã¤ãåå¨ãã¾ã
- Spamhausã®ãã§ãã¯ã¯passããããã«ãªã£ãããã ãã次ã¯ãmaps(mail-abuse.com)ã®ã¹ãã ãªã¹ãã«å¼ã£ããããã¨ã確èª
- AWSã¸åå¾æ¸ã¿ã®Elastic IPã«å¯¾ãã¦ãDNSéå¼ãè¨å®ãä¾é ¼
- ç§ã®ã¨ãã¯ã2ã3æ¥ã§åæ ãã¦ãããã¾ãã
- mapsã«ãã¹ãã ãªã¹ãããã®è§£é¤ç³è«ãè¡ãã
- DNSã®éå¼ãçµæãæ·»ãã¦ç³è«ãã©ã¼ã ãã軽ã説æã10åãããã§è§£é¤ã®è¿äºãã¡ã¼ã«ã§æ¥ã
- æ°æéå¾ã«ã¯ãç¡äºãæ£å¸¸ã«é éãããããã«ï¼
ããã§ãçªãè¿ãããå ´åã¯ã»ã»ã»ï¼
ç§ã¯ãSMTPã®ãµã¼ãã¹ã¨ãã¦ãããPostfixãå©ç¨ãã¦ãã¾ãããPostfixã§ã¯ã"fallback_relay"ã¨ããæ©è½ããããä½ããã®çç±ã§ã¡ã¼ã«é éã失æããã¨ãã«ãé éã代æ¿ãã¦ããããµã¼ããæå®ã§ãããã®ã§ãã
å©ç¨ãã¦ããã¡ã¼ã«(ãã¡ã¤ã³)ãGoogle Appsã§ç®¡çãã¦ããå ´åãªã©ã¯ãGmailã®SMTPãµã¼ãã¹ãå©ç¨ã§ããããããã¡ãã¸ãã©ã¼ã«ããã¯ãªã¬ã¼ãè¡ã£ã¦ããããã¨ã§ãEC2ãµã¼ãèªåSMTPãµã¼ãã¹ããã®éä¿¡ã§å¤±æãããã®ã¯ãGmailçµç±ã§éä¿¡ãããã¨ãã£ãææ³ãåããã¨ãå¯è½ã§ãã
ã¡ãªã¿ã«ããã®å ´åã®SFPã®è¨å®ã¯ä»¥ä¸ã®ãããªæãã§ãã
IN TXT "v=spf1 +ip4:xxx.xxx.xxx.xxx include:aspmx.googlemail.com ~all"
åèï¼ Amazon EC2ã§å©ç¨ããã¦ãããããªãã¯IPã¢ãã¬ã¹ä¸è¦§
ã¾ã¨ã
ã¯ã©ã¦ãAMAZON EC2/S3ã®ãã¹ã¦ (ITpro BOOKs)
- ä½è : 並河ç¥è²´,å®éè¼é,ITpro/æ¥çµSYSTEMS
- åºç社/ã¡ã¼ã«ã¼: æ¥çµBP社
- çºå£²æ¥: 2009/11/05
- ã¡ãã£ã¢: åè¡æ¬
- è³¼å ¥: 4人 ã¯ãªãã¯: 372å
- ãã®ååãå«ãããã° (18件) ãè¦ã