ããã·ã¥ãã¼ãã«å®è£ ã«å¯¾ããæ»æã¨ã¯
ãæ¨å¹´12ææ«ã«ãã¤ãã§éå¬ãããCCCï¼Chaos Communication Congressï¼ã«ããã¦ã"Effective Denial of Service attacks against web application platforms"ï¼Webã¢ããªã±ã¼ã·ã§ã³ã«å¯¾ããå¹ççãªDoSæ»æï¼ã¨é¡ããçºè¡¨ãè¡ããã¾ãããã¿ã¤ãã«ã«ãWebã¢ããªã±ã¼ã·ã§ã³ãã¨ã¤ãã¦ã¯ãã¾ããããã®åé¡ã¯Webã¢ããªã±ã¼ã·ã§ã³ã«éã£ããã®ã§ã¯ããã¾ããã以ä¸ã®ä¸ã¤ã®æ¡ä»¶ãæã£ãã¢ããªã±ã¼ã·ã§ã³ã§ããã°ä¾å¤ãªããDoSæ»æã®é¤é£ã¨ãªãå±éºãããã¾ãã
- ããã·ã¥ãã¼ãã«ã¨ãããã¼ã¿æ§é ã使ã£ã¦ãã
- ããã·ã¥å¤ãè¨ç®ããã¢ã«ã´ãªãºã ããèå¼±ãã§ãã
- ããã·ã¥ãã¼ãã«ã«ç»é²ãããã¼ã¿ãããã°ã©ã å¤é¨ããæå®ã§ãã
ããã·ã¥ãã¼ãã«ã¨ãã®åé¡
ãWikipediaï¼æ¥æ¬èªçï¼ã§ã¯ããã·ã¥ãã¼ãã«ã«ã¤ãã¦ä»¥ä¸ã®ããã«èª¬æãã¦ãã¾ã:
ï¼ãããã·ã¥ãã¼ãã«ãæ¦è¦ããå¼ç¨ï¼
ããã·ã¥ãã¼ãã«ã¯ãã¼ããã¨ã«çæãããããã·ã¥å¤ãæ·»ãåã¨ããé åã§ããã é常ãé åã®æ·»ãåã«ã¯éè² æ´æ°ããæ±ããªããããã§ããã¼ãè¦ç´ããå¤ã§ããããã·ã¥å¤ãæ·»ãåã¨ãã¦å¤ã管çãããã¨ã§ãæ¤ç´¢ã追å ãè¦ç´ æ°ã«ãããå®æ°æéO(1)ã§å®ç¾ããããããããã·ã¥é¢æ°ã®é¸ã³æ¹ï¼ä¾ãã°ãç°ãªããã¼ããé »ç¹ã«åãããã·ã¥å¤ãçæãããå ´åï¼ã«ãã£ã¦ã¯ãæ§è½ãå£åãã¦ææªã®å ´åO(n)ã¨ãªã£ã¦ãã¾ãã
ãããã·ã¥ãã¼ãã«ã¯ã大éã®ãã¼ã¿ãå¹çãã管çãããå ´åã«ä½¿ããã¾ããPerlãawkãªã©ã®é£æ³é åã®å®è£ ã«ãããã·ã¥ãã¼ãã«ã¯æ´»ç¨ããã¦ãã¾ãã
ãã¾ããJavaã§ããã·ã¥ãã¼ãã«ã¨ããã°ãæ¨æºAPIã¨ãã¦Hashtableã¯ã©ã¹ãHashMapã¯ã©ã¹ãªã©ãæä¾ããã¦ãã¾ãã
ãWikipediaã®èª¬æã«ãããããã«ãããã·ã¥ãã¼ãã«ã¯ãå ¥åãã¼ã¿ã«ãã£ã¦ã¯å¦çã®å¹çãæªããªãå ´åããããã¨ã«æ³¨æãå¿ è¦ã§ããWikipediaã®èª¬æã§ã¯ãç°ãªããã¼ããé »ç¹ã«åãããã·ã¥å¤ãçæãããå ´åãã¨æ¸ããã¦ãã¾ããç°ãªããã¼ãåãããã·ã¥å¤ãæã¤ã¨ãããã¨ã¯ãç°ãªããã¼ã«å¯¾å¿ããå¤ããããã·ã¥ãã¼ãã«ã®ãåããä½ç½®ã«ç½®ããã¨ã«ãªãã¾ãã
ããã®ããã«è¤æ°ã®ãã¼ã¿ã®ããã·ã¥å¤ãåãã«ãªã£ãå ´åã®å¯¾å¦æ¹æ³ã¯ããã¤ãããã¾ãããåç´ãªããæ¹ã¨ãã¦ã¯ä¾ãã°ããã¼ãã«ã®åã¨ã³ããªãç·å½¢ãªã¹ãã¨ãã¦ç¨æãã¦ãããåãããã·ã¥å¤ãæã¤ãã¼ã¿ã¯è©²å½ããã¨ã³ããªä½ç½®ã®ç·å½¢ãªã¹ãã§ç®¡çãã¾ããJDKã®Hashtableã¯ã©ã¹ããã®ãããªå®è£ ã«ãªã£ã¦ãã¾ãã
ãåä¸ã®ããã·ã¥å¤ãæã¤ãã¼ã¿ãå¤ããªãã»ã©ç·å½¢ãªã¹ãã辿ãå ´é¢ãå¤ããªããç»é²ãæ¤ç´¢ã®å¹çã¯æªããªãã¾ããç»é²ãããã¼ã¿ã®ã»ã¼å ¨ã¦ã®ããã·ã¥å¤ãåä¸ã§ãã£ãå ´åãå¦çã®ã»ã¨ãã©ã¯ç·å½¢ãªã¹ãã®æä½ã¨ãªããå¹çã®å¤§å¹ ãªä½ä¸ãæãã¾ããæ»æè ã¨ãã¦ã¯ããã®ãããªãã¼ã¿ãä¸ãããã¨ãã§ããã°ãDoSæ»æãè¡ããã¨ãå¯è½ã«ãªããã¨ããããã§ãã
ããã®æ»æææ³ã¯2003å¹´ã®USENIX Security Symposiumã§æåã«çºè¡¨ããã¾ããã2011å¹´æ«ã®CCCã«ãããçºè¡¨ã¯ããã®ææ³ããä»ç¾å¨åºã使ããã¦ããã¢ããªã±ã¼ã·ã§ã³ããã¬ã¼ã ã¯ã¼ã¯ã«ãé©ç¨å¯è½ã§ãããã¨ã示ãããã®ã§ãã
ãJPCERTã³ã¼ãã£ãã¼ã·ã§ã³ã»ã³ã¿ã¼ã®è¬å¸«é£ã«ãããAndroidã»ãã¥ã¢ã³ã¼ãã£ã³ã°ã»ããã¼ãã2012å¹´3æ14æ¥ã«éå¬ãã¾ãï¼ä¸»å¬ï¼ç¿æ³³ç¤¾ï¼CodeZineï¼ã詳ããã¯ç¹è¨ãã¼ã¸ã¾ã§ï¼