ããã¯ãã¡ã¼ã« Advent Calendar 2018ãã®ããã«æ¸ãããã¨ã³ããªã§ãã
å
ãã¿ã¯ä»å¹´ã®6æã«éãããNSEGã¨ããé·éã®åå¼·ä¼ã§çºè¡¨ããå
容ã§ãã
åå¼·ä¼ã®åç»ãä¸ãã£ã¦ã¾ãã®ã§è峿ãããæ¹ã¯ãã¡ãããã²ã
NSEG åå¼·ä¼ #101 / ã¡ã¼ã«ã¨ã³ãã¥ãã±ã¼ã·ã§ã³ãã¼ã« - connpass
ã¹ãã 対çãçãä¸ã
ä»åç£æ¥
- botnetããéãããã¹ãã ãæ¿æ¸ãã
- SMTPã»ãã·ã§ã³ãã£ã«ã¿ã§ã®ã¹ãã 対çã¯ä¸è¦ã«ãªãã¤ã¤ãã
- 諸è¡ç¡å¸¸
ã¯ããã«
èªåã¯2006å¹´é ãã taRgrey ã¨ããã¹ãã å¯¾çææ³ãææ¡ãã¦ãã¾ãã
taRgrey - S25R + tarpitting + greylisting (tarpit + greylist policy server)
ããã¯SMTPã»ãã·ã§ã³ä¸ã®ã¯ã©ã¤ã¢ã³ãã®ç¹å¾´ãå©ç¨ãããã£ã«ã¿ãããã¤ãçµã¿åãããææ³ã§ã S25R 㨠tarpitting 㨠greylisting ãçµã¿åããã¦ã誤æ¤åºãå¯ä½ç¨ããªãã¹ãå°ãªããããã¨ãçã£ããã®ã§ãã
ãã ãè¿å¹´ã¹ãã ã®æ°ãå¾ã ã«æ¸ã£ã¦ãã¦ãããã¾ãå¾ã ã«å¹æãå°ãªããªã£ã¦ããã¨æãã¦ãã¾ããã
ããã§SMTPã»ãã·ã§ã³ãã£ã«ã¿ãã©ã®ç¨åº¦å¹æãåºã¦ããã®ãã2010å¹´ãã2018å¹´ã«ããã¦ã®æ¨ç§»ã確èªãã¾ããã
2010年彿ã®ã¹ãã ç¶æ³
2010年彿ã¯ã¾ã ã¹ãã å
¨çæã§ã¾ã å¢ãã¦ããæããããã¾ããã
ç¹ã«botnetã¨ããã¦ã¤ã«ã¹ã«ææããPCã大éã«é éã§æä½ãããããã大éã«ã¹ãã ãåºãã®ãä¸»ãªææ³ã§ããã
ãã ãOP25Bã®åºã¾ããSNSçã®ä»ã®é£çµ¡ææ®µã®æ®åããããå¾ã
ã«å¤åãèµ·ããã¤ã¤ãã£ãç¶æ³ã§ããã
- ã¹ãã ç70%ï½80%ç¨åº¦ã¨ããæãã§å¹´ã å¢ãã¦ãã
- 97%åå¾ãbotnetããåºãããã¹ãã ã ã£ã
- æ¥æ¬çºã®ã¹ãã ã¯OP25Bã«ããæ¿æ¸ãã¦ãã
ä¸è¨è¡¨ã¯ã2010年彿ã®å®æ¸¬ã¹ãã æ¯çã¨ãS25Rã®ãããçâbotããã®ã¹ãã éä¿¡çãtarpitting(é
å»¶)ãæããå ´åã®ã¹ãã é§é¤ï¼ããããã¦åæãããï¼çãåtaRgreyã§ã®é§é¤çã§ãã
ï¼å²ä»¥ä¸ãbotããåºããã¦ããããã®ããbotã«å¯¾ãã¦ã®ã¹ãã å¤å®ããã¾ãããã°é«ãæ¯çã§å¯¾çã¨ãªã£ã¦ãããã¨ããããã¾ãã
ç | |
---|---|
ã¹ãã ç | 69% |
S25Rã®ã¹ãã ãããç | 93% |
tarpittingã§ã®é§é¤ç | 91% |
taRgreyã§ã®é§é¤ç | 85% |
2012ï½2018å¹´ã®ç¶æ³æ¨ç§»
ããã¡ã¼ã«ãµã¼ãã§ãã¡ã¼ã«ã®åä¿¡æ°ãåã¹ãã ãã£ã«ã¿ã§ã®ã¹ãã å¤å®æ°ãããbotããã®ã¹ãã ã¡ã¼ã«éä¿¡æ°æ¨ç§»ãå®ç¹è¦³æ¸¬ãã¾ããã
ã¡ã¼ã«ç·æ°ã¨ã¹ãã æ°
ã¾ãåºæ¬ã¨ãªãã¡ã¼ã«ç·æ°ã¨ã¹ãã æ°ã®æ¨ç§»ã§ãã1ã¡ã¼ã«ã¢ãã¬ã¹ãããã®æå¹³ååä¿¡æ°ã§ãã
ã¹ãã ãæ¸ã£ã¦ãããããã¡ã¼ã«ç·æ°ãæ¸ã£ã¦ãããã¨ããããã¾ãã
ã¢ã«ã¦ã³ãããã | 2014å¹´ã¾ã§ | 2018å¹´ç¾å¨ |
---|---|---|
ã¡ã¼ã«æ° | 2,500é/æã»ã© | 1,000é/æå¼± |
ã¹ãã æ° | 2,000é/æã»ã© | 500é/æã»ã© |
ã¹ãã ç
ã¹ãã æ¯çã®æ¨ç§»ãã°ã©ãã«ãã¾ããã
ããæ°å¹´ã§ä¸æ°ã«ã¹ãã æ¯çãå°ãªããªã£ããã¨ããããã¾ããï¼ã¨è¨ã£ã¦ãã¾ã ååãã¹ãã ã§ããï¼
- 2014å¹´ãããã¾ã§ãã£ã¨75%ãããã ã£ã
- ãã®å¾å¾ã ã«ä½ä¸ã2018å¹´ã«ã¯50%ãåã
ã¡ã¼ã«ç·æ°ã¨ãã æ°
æ£å¸¸ãªã¡ã¼ã«ï¼ãã ï¼ã®æ°ã¯æå¤ã«æ¸ã£ã¦ããããæ¨ªã°ãã§ã»ã¼å¤ãã£ã¦ããªããã¨ããããã¾ãã
ã¡ã¼ã«ãã¬ã¸ã³ãªã©ãDMã®éè¦ã¯ã¾ã æ¸ã£ã¦ããªãã®ã ããã¨æããã¾ãã
æ¸ã£ãã¹ãã ã®ç¨®é¡
ã¹ãã ã¯ãã3,4å¹´ã§å¤§ããæ¸ã£ã¦ãããæå¤ã«æ®éã®ã¡ã¼ã«æµéã¯æ¸ã£ã¦ããªããã¨ããããã¾ããã
ããã§ã¯ã©ããªã¹ãã ãæ¸ã£ãã®ã§ããããã
åçIPããã¨æ¨æ¸¬ãããæ¥ç¶æ¨ç§»
S25Rã«å¼ã£ããããããªãéå¼ãåãåçIPã£ã½ãæ¥ç¶ã¯botããã§ããå¯è½æ§ãé«ãã¨æ¨æ¸¬ã§ãããããbotããã¨æãããæ¥ç¶ã¯ããæ°å¹´ã§æ¿æ¸ãã¦ãããã¨ããããã¾ãã
ã¾ãtarpittingã§åæãããä»¶æ°ãåæ§ã«æ¸å°ãã¦ãã¾ãã
- S25Rã«æããæ¥ç¶å ã¯70%æ¸ç¨åº¦ã«æ¿æ¸
- tarpittingã§åæãããã¡ã¼ã«æ°ãåããã¦æ¸å°
tarpittingã§ã®åæçæ¨ç§»
åçIPããã¨æãããæ¥ç¶ã§tarpittingã§åæãããçãæ¥æ¿ã«æ¸å°ãã¦ãã¾ãã
- 2014å¹´ãããã¾ã§ãã£ã¨80%ç¨åº¦ã ã£ã
- ãã®å¾2018å¹´ã«ã¯30%ã«ã¾ã§æ¥æ¿ã«ä½ä¸
S25Rã«å¼ã£ããããã®ãã¹ã¦ãbotãªããã§ã¯ãªããã¡ã¼ã«ãã¬ã¸ã³ã®å¤§éçºä¿¡ãã¯ã©ã¦ããµã¼ãããåºããã¦ãããã®ã誤æ¤åºãã¦ããå ´åãããã¾ãã
ãããã¯tarpittingãæãããããbotãæ¸ã£ããã¨ã§ç¸å¯¾çã«ãã¡ãã®æ¯çãããããåæçãä¸ãã£ãã®ã§ã¯ãªããã¨èãããã¾ãã
tarpittingãæãããªãã£ããã®ã ããbotã¨èããã¨ãbotããã®æ¥ç¶ã¯æçæãã10%ç¨åº¦ã«ã¾ã§æ¸ã£ãã¨èãããã¾ãã
SMTPã»ãã·ã§ã³ãã£ã«ã¿ã®æå¹åº¦æ¨ç§»
ãã®ãµã¼ãã§ã¯ã¡ã¼ã«ã®ä¸èº«ã§å¤å®ããã³ã³ãã³ããã£ã«ã¿ãå©ç¨ã§ãããã®å ´åã¯SMTPã»ãã·ã§ã³ãã£ã«ã¿ãæãã¦ãããã®ããã£ã«ã¿ãã¦ãã¾ãã
ã©ã¡ãã®ãã£ã«ã¿ã§ã©ãã ãã¹ãã ãè½ã¨ããããã§ãåãã£ã«ã¿ã®æå¹æ§ãã©ãæ¨ç§»ãã¦ããããè¦ã¦ã¿ã¾ãã
ã³ã³ãã³ããã£ã«ã¿ã¨SMTPã»ãã·ã§ã³ãã£ã«ã¿ã®å¹ææ¨ç§»
- ã³ã³ãã³ããã£ã«ã¿ã¯30%æ¸ç¨
- tarpittingã¯85ï¼ ãæ¿æ¸
tarpittingã®1次ãã£ã«ã¿ã®å¹æ
- 2015å¹´é ã¾ã§ã¯ãã£ã¨70%ï½80%ç¶æ
- 以鿥æ¿ã«ä½ä¸ãã¤ãã«30%ç¨åº¦ã«
SMTPã»ãã·ã§ã³ã¬ãã«ã§ã®ãã£ã«ã¿ã®å¹æãæ¸å°ãã¦ãã¾ãæå³ããªããªããªã£ã¦ãããã¨ããããã¾ãã
çµè«
botnetããã®éä¿¡ã大å¹
ã«æ¸ã£ããããbotã®ã¯ã»ãå©ç¨ãã¦ã¹ãã ãæé¤ããSMTPã»ãã·ã§ã³ãã£ã«ã¿ã广ããªããªããªãã¤ã¤ãããã¨ããããã¾ããã
ã¹ãã (botnet)ã¯ãã§ã«ã¡ã¼ã«ã§ã¯ãªãããã广ã®é«ãSNSãªã©ãçã£ãããã¡ã¼ã«ã使ãå ´åã§ãããå¹çã®é«ããã£ãã·ã³ã°ãªã©ã«ä½¿ãããããã«ãªã£ãã¨èãããã¾ãã
ãã®ãã¨ãããtaRgreyã¯ããå°å
¥ããæå³ããªãã¨ããã¾ããããã¯greylistingãªã©ä»ã®SMTPã»ãã·ã§ã³ãã£ã«ã¿ãåæ§ã§ãã
èæ¡è
ã¨ãã¦ã¯è¤éãªå¿å¢ã§ãããããããã¹ãã ããªããã°ã¹ãã ãã£ã«ã¿ã¯ä¸è¦ãªããã§ãã ããåã¶ã¹ã話ã ã¨æãã¾ãã