¹C«È:  µù¥U | µn¿ý | ·j¯Á | À°§U | VIPÃÙ§U¥»¯¸ | ¥ZµnÃÙ§U¼s§i | ³]¬°­º­¶ | ¥[¤J¦¬Âà | ÁcÅ餤¤å

 

your gf Ú»­ø¨ì¤ù ¥î¼äóa ¤£¯à³X°ÝSOPCAST­¶­± ¶Â¦â­I´º ¤ÑÀs¤K³¡·tª÷Ä_ ¸Ý¥Ponline©xºô ¤p¤t¬ü ½u¤WH°Êµe §K¶O§Y®É³ø»ù ªá¼Ë¤Ö¦~¤Ö¤k¢ê¢ü ¤Ó»×¥ß§Ó¶Ç ¤H¶¡¤¿¾¹º©µe Hebe·s¾v«¬ Media calssic I miss you³¯¬f¦t seed H LostPlanet¯}¸Ñ ¤Ñ°ó¨pªA³Ü¤ôµ{¦¡ ¤Ñ¥~2 online ¯]®ü®á®³¤p©j¥þ®M

 




·j¯Á¿ï¶µ ¯Á¤Þ¨t²Î¤u¨ãµ¡
 
¼ÐÃD: ²`¤JÁA¸ÑDDOS»PDDOS°lÂÜ
http://manyway.net ÃÙ§Uºô¯¸¸ü¤J¤¤...
chan0006
ºaÅA²z¨Æ
Rank: 7Rank: 7Rank: 7Rank: 7Rank: 7Rank: 7Rank: 7
¹q¸£¦a±a°Ï¥D

ºaÅA¾±³¹ ¥Ø«e¨S¦³¾±³¹

UID¡G 460360

©Ê§O¡G ¨k

ºëµØ¡G 3 ½g

¿n¤À¡G 2593 ÂI

©«¤l¡G 1863 ½g

  ¤j ¤¤ ¤p
µoªí©ó 2007-6-10 21:37  ¸ê®Æ  ­Ó¤HªÅ¶¡  ¥D­¶ µu®ø®§  ¥[¬°¦n¤Í  ²K¥[ chan0006 ¬°MSN¦n¤Í ³q¹LMSN©M chan0006 ¥æ½Í QQ

²`¤JÁA¸ÑDDOS»PDDOS°lÂÜ ±z¬O²Ä 364­ÓÂsÄýªÌ

Ãì¯Å´ú¸Õ (Link Testing)

¦h¼Æªº°lÂܧ޳N³£¬O±q³Ì±µªñvictimªº¸ô¥Ñ¾¹¶}©l¡AµM«á¶}©lÀˬd¤W¬y¸ê®ÆÃì¡Aª½¨ì§ä¨ì§ðÀ»¬y¶qµo°_·½¡C²z·Q±¡ªp¤U¡A³oºØ¹Lµ{¥i¥H»¼°j°õ¦æª½¨ì§ä¨ì§ðÀ»·½ÀY¡C³oºØ§Þ³N°²³]§ðÀ»¤@ª½«O«ù¬¡°Êª½¨ì§¹¦¨°lÂÜ¡A¦]¦¹«ÜÃø¦b§ðÀ»µ²§ô«á¡B¶¡·²©Ê§ðÀ»©Î¹ï°lÂܶi¦æ§ðÀ»½Õ¾ãµ¥±¡ªp¶i¦æ°lÂÜ¡C¥]¬A¤U­±¨âºØÃì¯Å´ú¸Õ¡G

1¡BInput debugging

«Ü¦h¸ô¥Ñ¾¹³£´£¨ÑInput debugging¯S©Ê¡A³o¯àÅýºÞ²z­û¦b¤@¨Ç¥X¤fºÝ¹LÂo¯S©wªº¸ê®Æ¥]¡A¦Ó¥B¯à¨M©w¥i¥H¹F¨ì¨º¨Ç¤J¤f¡C³oºØ¯S©Ê´N³Q¥Î¨Ó§@traceback¡G­º¥ý¡Avictim¦b½T©w³Q§ðÀ»®É¡A­n±q©Ò¦³ªº¸ê®Æ¥]¤¤´y­z¥X§ðÀ»¥]¼Ð»x¡C³q¹L³o¨Ç¼Ð»x¡AºÞ²z­û¦b¤W¬yªº¥X¤fºÝ°t¸m¦X¾AªºInput debugging¡C³o­Ó¹LÂo·|Åé²{¥X¬ÛÃöªºinput°ð¡A³o­Ó¹LÂo¹Lµ{¥i¥H¤@ª½´Â¤W¬y¶i¦æ¡Aª½¨ì¯à°÷¨ì¹F³Ìªìªº·½ÀY¡C·íµM³oºØ¤u§@«Ü¦h¨Ì¾a¤â¤u¡A¤@¨Ç°ê¥~ªºISPÁp¦X¶}µoªº¤u¨ã¯à°÷¦b¥¦­Ìªººô¸ô¤¤¶i¦æ¦Û°Êªº°lÂÜ¡C
¦ý¬O³oºØ¿ìªk³Ì¤jªº°ÝÃD´N¬OºÞ²zªá¶O¡CÁpô¦h­ÓISP¨Ã¦P¥L­Ì¦X§@»Ý­n®É¶¡¡C¦]¦¹³oºØ¿ìªk»Ý­n¤j¶qªº®É¶¡¡A¦Ó¥B´X¥G¤£¥i¯à§¹¦¨¡C

2¡BControlled flooding

Burch©M Cheswick´£¥Xªº¤èªk¡C³oºØ¤èªk¹ê»Ú¤W´N¬O»s³yflood§ðÀ»¡A³q¹LÆ[¹î¸ô¥Ñ¾¹ªºª¬ºA¨Ó§PÂ_§ðÀ»¸ô®|¡C­º¥ýÀ³¸Ó¦³¤@±i¤W´åªº¸ô®|¹Ï¡A·í¨ü¨ì§ðÀ»ªº®É­Ô¡A¥i¥H±qvictimªº¤W¯Å¸ô¥Ñ¾¹¶}©l¨Ì·Ó¸ô®|¹Ï¹ï¤W´åªº¸ô¥Ñ¾¹¶i¦æ±±¨îªºflood¡A¦]¬°³o¨Ç¸ê®Æ¥]¦P§ðÀ»ªÌµo°_ªº¸ê®Æ¥]¦P®É¦@¥Î¤F¸ô¥Ñ¾¹¡A¦]¦¹¼W¥[¤F¸ô¥Ñ¾¹¥á¥]ªº¥i¯à©Ê¡C³q¹L³oºØªu¸ô®|¹Ï¤£Â_¦V¤W¶i¦æ¡A´N¯à°÷±µªñ§ðÀ»µo°_ªº·½ÀY¡C

³oºØ·Qªk«Ü¦³¿W³Ð©Ê¦Ó¥B¤]«Ü¹ê»Ú¡A¦ý¬O¦³´X­Ó¯ÊÂI©M­­¨î¡C³Ì¤jªº¯ÊÂI´N¬O³oºØ¿ìªk¥»¨­´N¬O¤@ºØDOS§ðÀ»¡A·|¹ï¤@¨Ç«H¥ô¸ô®|¤]¶i¦æDOS¡A³o­Ó¯ÊÂI¤]«ÜÃø¥Îµ{¦¡¹ê¬I¡C¦Ó¥B¡AControlled flooding­n¨D¦³¤@­Ó´X¥GÂл\¾ã­Óºô¸ôªº©Ý¼³¹Ï¡CBurch©M Cheswick¤]«ü¥X¡A³oºØ¿ìªk«ÜÃø¥Î©óDDOS§ðÀ»ªº°lÂÜ¡C³oºØ¤èªk¤]¥u¯à¹ï¥¿¦b¶i¦æ§ðÀ»ªº±¡ªp¦³®Ä¡C

²{¦bCISCOªº¸ô¥Ñ¾¹ªºCEF¡]Cisco Express Forwarding¡^¹ê»Ú¤W´N¬O¤@ºØÃì¯Å´ú¸Õ¡A¤]´N¬O»¡¡A­n¥ÎCEF°lÂܨì³Ì²×·½ÀYªº¸Ü¡A¨º»ò¾ã­ÓÃì¸ô¤Wªº¸ô¥Ñ¾¹³£±o¨Ï¥ÎCISCOªº¸ô¥Ñ¾¹¡A¦Ó¥B¤ä´©CEF¡C´N±o­nCisco 12000©ÎªÌ7500¨t¦Cªº¸ô¥Ñ¾¹¤F¡C¡]¤£ª¾¹D²{¦b«ç»ò¼Ë¡A¨S¬d³Ì·sªºCISCO¤åÀÉ¡^¡A¦ý¬O­n¥Î³o­Ó¥\¯à¬O«Ü¶O¸ê·½ªº¡C

¦bCISCO¸ô¥Ñ¾¹¡]¤ä«ùip source-trackªº¸ô¥Ñ¾¹¡^¤WIP·½°lÂÜ¥H¤UÄѪº¨BÆJ¹ê²{¡G

1¡B·íµo²{¥Øªº³Q§ðÀ»¡A¥´¶}¾ã­Ó¸ô¥Ñ¾¹¤W¹ï¥Øªº¦a§}ªº°lÂÜ¡A¿é¤J©R¥O ip source-track¡C

2¡B¨C­ÓLine Card¬°­n°lÂܪº¥Øªº¦a§}³Ð«Ø¯S©wªºCEF¦î¦C¡C¹ï©óline card©ÎªÌ°ð¾A°t¾¹¥Î¯S©wªºASIC§@¥]Âà´«¡ACEF¦î¦C¥Î©ó±N¥]¸m¤Jline card©ÎªÌport adapterªºCPU¡C

3¡B¨C­Óline card CPU¦¬¶°Ãö©ó­n°lÂܥتºªº³q°T¸ê°T¡C

4¡B©Ò²£¥Íªº¸ê®Æ©w®É¾É¥X¨ì¸ô¥Ñ¾¹¡C­n²{¹ê³o¨Ç¬y¸ê°TªººK­n¡A¿é¤J©R¥O¡Gshow ip source-track summary¡C­nÅã¥Ü¨C­Ó¿é¤J¤¶­±ªº§ó¦hªº²Ó¸`¸ê°T¡A¿é¤J©R¥Oshow ip source-track¡C

5¡B²Î­p³Q°lÂܪºIP¦ì§}ªº²Ó¥Øªí¡C³o¥i¥Î¤_¤W´å¸ô¥Ñ¾¹Ä~Äò¤ÀªR¡C¥i¥H¦b·í«e¸ô¥Ñ¾¹¤WÃö³¬IP source tracker¡A¿é¤J©R¥O¡Gno ip source-track¡CµM«á¦b¤W´å¸ô¥Ñ¾¹¤W¦A¥´¶}³o­Ó¥\¯à¡C

6¡B­«½Æ¨BÆJ1¨ì5¡Aª½¨ì§ä¨ì§ðÀ»·½¡C

Logging

³oºØ¤èªk³q¹L¦b¥D¸ô¥Ñ¾¹¤W°O¿ý¸ê®Æ¥]¡AµM«á³q¹L¸ê®ÆÀò¨ú§Þ³N¨Ó¨M©w³o¨Ç¸ê®Æ¥]ªº¬ï¶V¸ô®|¡CÁöµM³oºØ¿ìªk¥i¥H¥Î©ó¹ï§ðÀ»«áªº¸ê®Æ¶i¦æ°lÂÜ¡A¥¦¤]¦³«Ü©úÅ㪺¯ÊÂI¡A¤ñ¦p¥i¯à­n¨D¤j¶qªº¸ê·½¡]©ÎªÌ¨ú¼Ë¡^¡A¨Ã¥B¹ï¥I¤j¶q¸ê®Æªººî¦X°ÝÃD¡C

ICMP°lÂÜ

³oºØ¤èªk¥D­n¨Ì¾a¸ô¥Ñ¾¹¦Û¨­²£¥ÍªºICMP¸òÂÜ®ø®§¡C¨C­Ó¸ô¥Ñ¾¹³£¦³«Ü§Cªº·§²v¡]¤ñ¦p¡G1/200000¡^¡A¸ê®Æ¥]¥i¯à·|§â¤º®e½Æ»s¨ì¤@­ÓICMP®ø®§¥]¤¤¡A¨Ã¥B¥]§t¤F¨ìÁ{ªñ·½¦ì§}ªº¸ô¥Ñ¾¹¸ê°T¡C·íflood§ðÀ»¶}©lªº®É­Ô¡Avictim´N¥i¥H§Q¥Î³o¨ÇICMP®ø®§¨Ó­«·sºc³y§ðÀ»ªÌªº¸ô®|¡C³oºØ¤è¦¡¦P¤W­±¤¶²Ðªº¤ñ¸û¡A¦³«Ü¦hÀuÂI¡A¦ý¬O¤]¦³¤@¨Ç¯ÊÂI¡C¤ñ¦p¡GICMP¥i¯à³Q±q´¶³q¬y¶q¤¤¹LÂo±¼¡A¨Ã¥B¡AICMP°lÂÜ®ø®§ÁÙ­n¦Pinput debugging¯S©Ê¡]±N¸ê®Æ¥]¦P¸ê®Æ¥]input°ð©M/©ÎªÌ­n¨ì¹FªºMAC¦ì§}ÃöÁpªº¯à¤O¡^¬ÛÃö¡A¦ý¬O¡A¥i¯à¤@¨Ç¸ô¥Ñ¾¹´N¨S¦³³o¼Ëªº¥\¯à¡C¦P®É¡A³oºØ¿ìªkÁÙ¥²¶·¦³¤@ºØ¿ìªk¨Ó³B²z§ðÀ»ªÌ¥i¯àµo°eªº°°³yICMP Traceback®ø®§¡C¤]´N¬O»¡¡A§Ú­Ì¥i¥H§â³oºØ¤è¦¡¦P¨ä¥L¿ìªk¤@°_¨Ï¥Î¨ÓÅý¸òÂܾ÷¨î§ó¦³®Ä¡C(IETF iTrace)

³o´N¬Oyawl»¡ªºIETFªº¤u§@²Õ¬ã¨sªº¤º®e¡A·í®É§Úµ¹Bellovin´£¥X¤@¨Ç·N¨£¡A¦ý¬O¨S¦³±o¨ìµª®×¡C¤ñ¦p¡G

1¡B¾¨ºÞ¬OÀH¾÷1/20000µo°e°lÂÜ¥]¡A¦ý¬O¡A¹ï©ó°°³yTRACEBACKªº¥]±¡ªp¤U¡A¹ï¸ô¥Ñ¾¹ªº®Ä²v±N¦³¤@©wªº¼vÅT¡C

2¡B°lÂÜ¥]ªº»{ÃҨ䣯à¸Ñ¨M°°³y°ÝÃD¡C¦]¬°­n§P§O¬O§_¬O°°³y¥]¡A¨º»ò¥²¶·¥h»{ÃÒ¡A¥[¤j¤F¤u§@¶q¡C

3¡B§Y«K¨Ï¥ÎNULL »{ÃÒ¡A¦P¼Ë¯à°÷¹F¨ì¥Øªº¡]¦³»{ÃÒªº±¡ªp¤U¡^¡C¦Ó¥B¤]¤£·|¦³¤Ó¤j¼vÅT¡C

4¡BItraceªº¥»¨Ó¥Øªº¬O¥h¹ï¥IDOSªº´ÛÄF·½°ÝÃD¡A¦ý¬O²{¦bªº³]­p¥é¦òÅý§Ú­Ì§óÃö¤ßªº¬O¸ô®|¦Ó¤£¬O·½ÀY¡CÃø¹D¸ô®|¤ñ·½ÀY§ó¹ï§Ú­Ì¸Ñ¨MDOS°ÝÃD¦³¥Î»ò¡H
µ¥µ¥¡AÁÙ¦³¤@°ï°ÝÃD¡A³£¬O§Úı±oiTrace±N·|­±Á{ªº«ÜÃø³B²zªº°ÝÃD¡C

¸ê®Æ¥]¼Ð°O

³oºØ§Þ³Nºc·Q¡]¦]¬°²{¦b¨S¦³¹ê¥Î¡^´N¬O­n¦b²{¦³¨óijªº°ò¦¤W¶i¦æ­×§ï¡A¦Ó¥B­×§ï«Ü¤p¡A¤£¶HiTraceªº·Qªk¡A­Ó¤H»{¬°¤ñiTrace§ó¦n¤@¨Ç¡C

³oºØ°lÂܧ޳N¦³«Ü¦h²Ó¸`¬ã¨s¡A§Î¦¨¦hºØ¼Ð°Oºtºâªk¡A¦ý¬O³Ì¦nªºÁÙ¬O¸g¹LÀ£ÁYªºÃä½t¨ú¼Ëºtºâªk¡C

³oºØ§Þ³N­ì²z´N¬O­×§ïIPÀY¤¤¡A­«¸ü¨ä¤¤ªºidentification°ì¡C¤]´N¬O¦pªG¨S¦³¨Ï¥Î¨ìidentification°ìªº¸Ü¡A±N³o­Ó°ì©w¸q¬°¼Ð°O¡C

±N16bitªºidnetification¤À¦¨¡G3bitªºoffset¡]¥i¤¹³\8¦¸¤À¤ù¡^,5bitªºdistance¡A¥H¤Î8bitªºÃä½t¤À¤ù¡C5bitªºdistance¥i¥H¤¹³\31¯Å¸ô¥Ñ¡A³o¹ï©ó¥Ø«eªººô¸ô¨Ó»¡¤w¸g¨¬°÷¤F¡C

¼Ð°O©M­«ºc¸ô®|ªººtºâªk¬O¡G


Marking procedure at router R: let R' = BitIntereave(R, Hash(R)) let k be the number of
none-overlappling fragments in R' for

each packet w let x be a random number from [0..1) if xlet o be a random integer from
[0..k-1] let f be the fragment of R' at

offset o write f into w.frag write 0 into w.distance wirte o into w.offset else if
w.distance=0 then let f be the fragment of

R' at offset w.offset write f?w.frag into w.frag increment w.distance Path reconstruction
procedure at victim v: let FragTbl

be a table of tuples(frag,offset,distance) let G be a tree with root v let edges in G be
tuples(start,end,distance) let

maxd:=0 let last:=v for each packet w from attacker FragTbl.Insert
(w.frag,w.offset,w.distance) if w.distance>maxd then

maxd:=w.distance for d:=0 to maxd for all ordered combinations of fragments at distance d
construct edge z if d!=0 then z:=

z?last if Hash(EvenBits(z))=OddBits(z) then insert edge(z,EvenBits(z),d) into G
last:=EvenBits(z); remove any edge(x,y,d)

with d!=distance from x to v in G extract path(Ri..Rj) by enumerating acyclic paths in G



¹êÅç«Ç±¡ªp¤U³oºØ¼Ð°O§Þ³N¥u»Ý­nvictim¯à°÷§ì¨ì1000¨ì2500­Ó¥]´N¯à°÷­«ºc¾ã­Ó¸ô®|¤F¡AÀ³¸Ó»¡µ²ªG¬O«Ü¦nªº¡A¦ý¬O¨S¦³§ë¤J¨ì¹ê¥Î¤¤¡A¥D­n¬O»Ý­n¸ô¥Ñ¾¹¼t°Ó©MISP¤ä«ù¡C

®t¤£¦hip tracebackªº¤w¸g¹ê¥Îªº§Þ³N©M¹êÅç«Ç§Þ³N¡A©ÎªÌ¤w¸g¦º±¼ªº¡A´N¥D­n¬O³o¨Ç¡AÁöµMÁÙ¦³¨ä¥Lªº¤@¨Ç¡C

¤w¸g«Üªø®É¶¡¨S¦³·dDDOS¨¾½d³o¤@¶ô¤F¡A°ê¤º¤]¦³¶Â¬}³o¼Ëªº²£«~¡A¥H«e¤]ÁA¸Ñ¤@¨Ç°ê¥~ªº¡A¤ñ¦pfloodguard¡Btoplayer¡Bradwareµ¥¡C¨üsecuritytest´£¥Ü¡A¤SÁA¸Ñ¨ìriverheadªº¡A§Ú´N¥ß¨è¬Ý¤F¬Ý¥L­Ìªº¥Õ¥Ö®Ñ¡C

¦]¬°«e­±bigfoot´£¥Xªº¥D­n¬Oip tracebackªºÃD¥Ø¡Asecuritytest¤]¤S¨ì¨¾¿mªº°ÝÃD¡C°w¹ïDDOSªº°ÝÃDip traceback©MMitigation¬O¤£¤@¼Ëªº¡Aip traceback¥D­n¬O¶i¦æ°lÂÜ¡A¦]¬°DDOS¥D­n¬Ospoof¡A¦Ó«ÜÃø§P§O¨ì¯u¥¿ªº§ðÀ»·½¡A¦Ó¥B¦pªG¯à°÷«Ü®e©ö§ä¨ì¯u¥¿ªº§ðÀ»·½¡A¤£¶È¶È¹ï¥IDDOS¡A¹ï¥I¨ä¥Lªº§ðÀ»¤]«Ü¦³À°§U¡A¤ñ¦pªk«ß°ÝÃDµ¥¡C¦ÓMitigation¬O±q¨ü®`ªÌªº¨¤«×¡A¦]¬°victim¤@¯ë¬O¨S¦³¯à¤O¥h½Õ¬d¾ã­Óºô¸ô¡A§ä¥Xsource¡A¦Ó¥B¡A§Y«K¯à°÷§ä¨ìsource¡A¤]±o¦³ªk«ß©ÎªÌ¤@¨Ç·¾³qªº¤â¬q¨ÓÅýsource°±¤U¨Ó¡]§ðÀ»ªºsource¨Ã¤£¬Osourceªº§ðÀ»ªÌ¡^¡A³oºØ·N¨ýµÛ¤j¶qªº·¾³q¡B¸óISP¡B¸ó¹Lµ¥Ãþ¦üªº«D§Þ³N°ÝÃD¡A©Ò¥H¡A³q±`«ÜÃø³B²z¡C¦ý¬O±qvictimªº¨¤«×¨Ó»¡¡A¥²¶·±o¦³©Ò¸Ñ¨M¿ìªk¡A©Ò¥H´N»Ý­nMitigation¡C ³o¤S¥¿¦n¬O§Ú¥H«e¬ã¨sªº½d³ò¡A©Ò¥H¡A¤S·|»¡¥X¤@¤j°ï¡C¹ï©óMitigation¡A¨ä¹ê¡A§Þ³Nªº®Ú¥»´N¬O­n¯à±q²³¦hªº¬y¶q¤¤±N§ðÀ»¥]©M¦Xªk¥]¤ÀÂ÷¥X¨Ó¡A§â§ðÀ»¥]©ß±ó±¼¡AÅý¦Xªk¥]³q¹L´N©Ê¤F¡C³o´N¬O®Ú¥»¡A©Ò¥H¹ê»Ú¹B¥Îªº§Þ³N´N¬O­n¦p¦óºÉ¥i¯àÃѧO¥X§ðÀ»¥]¡A¦Ó¤SºÉ¥i¯à¤p¦a¼vÅT¥¿±`¥]¡C³o¤S±o¨Ó¤ÀªRDDOS¡]¬Æ¦ÜDOS¡^ªº¤è¦¡©M­ì²z¡C°ò¥»¤S¤U­±´XºØ§Î¦¡¡G
1¡B¨t²Îº|¬}§Î¦¨ªºDOS¡C³oºØ¯S¼x©T©w¡AÀË´ú©M¨¾¿m¤]®e©ö¡C

2¡B¨ó©w§ðÀ»¡]¤@¨Ç¸ò¨t²Î³B²z¬ÛÃö¡A¤@¨Ç¸ò¨óij¬ÛÃö¡^¡C¤ñ¦pSYN FLOOD¡A¸H¤ùµ¥¡C¯S¼xÁÙ¦nÃѧO¡AÀË´ú©M¨¾¿m¬Û¹ï®e©ö¡C¤ñ¦pSYN COOKIE¡BSYN CACHE¡A¸H¤ù¥i¥H©ß±ó¡C¤ñ¦pland§ðÀ»¡Bsmurf¡Bteardropµ¥¡C

3¡Bbandwidth FLOOD¡C©U§£¬y¶q°ô¶ë±a¼e¡A¯S¼x¤£¦nÃѧO¡A¨¾¿m¤£®e©ö¡C

4¡B°ò¥»¦XªkªºFLOOD¡C¤ñ3§óÃø¤F¡A¤ñ¦p¤À§GªºSlashdot¡C

¹ê»ÚªºDDOS¡A¤@¯ë³£¬O¦hºØ¤è¦¡µ²¦Xªº¡C¤ñ¦pSYNFLOOD¡A¥i¯à¦P®É¬Obandwidth FLOOD¡C

¼vÅT¨¾¿mªº¥D­n¦]¯À´N¬O¬Ý¯S¼x¬O§_¯à±o¨ì¡A¤ñ¦p1¡B2´N¬Û¹ï¦n¸Ñ¨M¡A¤@¨Ç°ò¥»¤£¼vÅTªº¨Ï¥ÎªºFLOOD¡A«h¥i¥H«Ü¦n³Q©ß±ó¡A¤ñ¦pICMP FLOOD¡C

¦ý¬O¡A§ðÀ»µo¥]¤u¨ã¦pªG±N¸ê®Æ¥]§ó¯à°°¸Ë¦¨¦Xªk¥]¡A¨º»ò´N«ÜÃøÃѧO¥X¨Ó¤F¡C

¤@¯ëªºMitigation¤èªk¤]´N¬O¡G

1¡BFilter¡C¹ï©ó¯S¼x©úÅ㪺¡A¤ñ¦p¤@¨ÇįÂA¦b¸ô¥Ñ¾¹¤W´N¥i¥H·d©w¡C·íµM¡A¹LÂo¬O³Ì²×¸Ñ¨M¿ìªk¡A¥u­nÃѧO¥X¤F§ðÀ»¥]¡A´N¬O­n§â³o¨Ç¥]¹LÂo±¼¡C

2¡BÀH¾÷¥á¥]¡C¸òÀH¾÷ºtºâªk¬ÛÃö¡A¦nªººtºâªk¥i¥HÅý¦Xªk¥]¨ü¨ì§ó¤p¼vÅT¡C

3¡BSYN COOKIE¡BSYN CACHEµ¥¯S©w¨¾¿m¿ìªk¡C°w¹ï¤@¨Ç©T©wªº§ðÀ»¤â¬q¨Ó¨¾¿m©M¹LÂo¡C¤ñ¦pICMP FLOOD¡BUDP FLOOD¡CSYN COOKIEµ¥³£¬OÁ×§Kspoof°ÝÃD¡A¦Ü¤ÖTCPÁÙ¦³¤T¦¸´¤¤â¡A©Ò¥HÁÙ¦n§PÂ_SPOOF¡C

4¡B³Q°Ê®ø·¥©¿²¤¡C¥i¥H»¡¤]¬O¤@ºØ½T»{¬O§_³Q´ÛÄFªº¿ìªk¡C¤@¯ë¥¿±`³s±µ¥¢±Ñ·|­«·s¹Á¸Õ¡A¦ý¬O§ðÀ»ªÌ¤@¯ë¤£·|¹Á¸Õªº¡C©Ò¥H¥i¥HÁ{®É©ß±ó²Ä¤@¦¸³s±µ½Ð¨D¦Ó±µ¨ü²Ä¤G¦¸©ÎªÌ²Ä¤T¦¸³s±µ½Ð¨D¡C

5¡B¥D°Êµo°eRST¡C¹ï¥ISYN FLOODªº¡A¤ñ¦p¤@¨ÇIDS¤W¡C·íµM¡A¹ê»Ú¤£¬O¦³®Äªº¡C

6¡B²Î­p¤ÀªR©M«ü¯¾¡C³o¥»¨Ó¬O¬ã¨sªº¥D­n¤º®e¡A¦ý¬O³Ì«á³´¤J¤Fºtºâªk¤û¨¤¦y¡A¦]¬°¥D­n¬O¤@­Óºtºâªk°ÝÃD¡C³q¹L²Î­p¤ÀªRªº¨¤«×¨Ó±o¨ì«ü¯¾¡AµM«á®Ú¾Ú«ü¯¾¨Ó©ß±ó§ðÀ»¥]¡A¤]¬O¤@ºØ²§±`ÀË´úªº§Þ³N¡C»¡±o«Ü²³æ¡A¦ý¬O­n¤£¼vÅT¦Xªk¥]¤]¤£®e©ö¡A¤£¦Ü©óÅܦ¨¤FÀH¾÷¥á¥]¡C¡]¨ä¹ê·í®É¦Ò¼{¤Ó¹L½ÆÂø¡A«D±o­n¸Ô²Ó¤ÀªR¥X§ðÀ»¥]©M¦Xªk¥]¡A¹ê»Ú¤£»Ý­n¡A¥u­n¹LÂo±¼¨¬°÷ªº§ðÀ»¥]¡A§Y«KÅý§ðÀ»¥]³q¹L¡A¦ý¥u­n¤£³y¦¨DOS´N¥i¥H¤F¡C¡^³o¤]¬O«Ü¦h¬ã¨sªÌ¬ã¨sªº¥D­n½ÒÃD¡A¥Øªº¤]´N¬OÃѧO§ðÀ»¥]¡C

²{¦b¦b¦^¨ìsecuritytest´£¨ìªºriverhead¡CÃö©óriverheadªº§Þ³N¡A§Ú³£¥u¬O±q¥L­Ìªº¥Õ¥Ö®Ñ¤WÁA¸Ñ¨ìªº¡A¦ý®Ú¾Ú§Úªº¤ÀªR§Þ³N¤èªk³£¨S¦³¶W¥X¤W­±´£¨ìªº½d³ò¡C

Riverheadªº®Ö¤ß¤è®×´N¬OÀË´ú Detection¡BÂಾ Diversion ©M ½w¸Ñ Mitigation¡A¤]´N¬OÀË´ú¨ì§ðÀ»¡AµM«á±N¬y¶qÂಾ¨ì¥L­Ìªº²£«~guard¤W¡AµM«á³q¹Lguard¶i¦æMitigation¡C

¥¦ªº¹ê²{¨BÆJ¡A´N¬O¡G
¦]¬°¨S¦³¹Ï¡A©Ò¥H¥ý©w¸q¤@¤U¡A¤~¯à»¡²M·¡¡G


#¾aªñ¤À´²¦¡©Úµ´ªA°È·½ÀYªº¸ô¥Ñ¾¹¬° »·ºÝ¸ô¥Ñ¾¹
#¾aªñ¨ü®`ªÌªº¸ô¥Ñ¾¹¬° ªñºÝ¸ô¥Ñ¾¹
#RiverheadªºGuard³]³ÆªþÄݦw¸Ëªº¸ô¥Ñ¾¹¬° ªþÄݸô¥Ñ¾¹



¨¾¿mªº¨BÆJ

1¡B­º¥ýÀË´ú¨ì¦³DDOSµo¥Í¡A¨ÃÁA¸Ñ¨ìvictim¡C

2¡BGuardµo°eBGP³q§i¨ì»·ºÝ¸ô¥Ñ¾¹¡]¦bvictimªºBGP³q§i³]¸m­º½X¡A¨Ã±o¨ì¤ñ­ì©lBGP³q§i§ó°ªªºÀu¥ýÅv¡^¡Aªí¥Ü±q»·ºÝ¸ô¥Ñ¾¹¨ìvictim¦³·sªº¸ô¥Ñ¡A¨Ã¥B¸ô¥Ñ¨ìGuardªºloopback interface¡A©Ò¦³¨ìvictimªº³£¸g¹LªþÄݸô¥Ñ¾¹Âಾ¨ì¤FGuard¤W¡C

3¡BGuardÀˬd¬y¶q¡A¨Ã¥B²M°£¨ä¤¤ªº§ðÀ»¬y¶q¡AµM«á§â¦w¥þªº¬y¶qÂàµo¨ìªþÄݸô¥Ñ¾¹¤W¡A¦b¦^¨ìvictim¨ä¤¤®Ö¤ß´N¬OGuard¡A§Þ³N´N¬O¥Õ¥Ö®Ñ¤¤´y­zªºMVP¬[ºc¡]Multi-Verification Process¡^¡A¤]´N¬O¤U­±5­Ó¼h¦¸¹LÂo(Filtering) ¡G³o­Ó¼Ò²Õ¥]§tÀRºA©M°ÊºAªºDDOS¹LÂo¡CÀRºA¹LÂo¡AÄdºInon-esse ntial¬y¶q¡A¥i¥H¬O¥Î¤á©w¸qªº¡A©ÎªÌ¬OriverheadÀq»{´£¨Ñªº¡C°ÊºA¹LÂo«h°ò©ó¦æ¬°¤ÀªR©M¬y¶qªº²Ó¸`¤ÀªR¡A³q¹L¼W¥[¹ï¥iºÃ¬y¶qªº½T»{©ÎÄdºI¤w¸g½T»{ªº´c·N¬y¶q¡A¨Ó¶i¦æ§Y®É§ó·s¤Ï´ÛÄF(Anti-Spoofing)¡G³o­Ó¼Ò²ÕÅçÃÒ¶i¤J¨t²Îªº¸ê®Æ¥]¬O§_³Q´ÛÄFªº¡CGuard¨Ï¥Î¤F¿W¦³ªº¡B¦³±M§Qªº·½ÅçÃÒ¾÷¨î¨ÓÁ×§K´ÛÄF¡C¤]³q¹L¤@¨Ç¾÷¨î¨Ó½T»{¦Xªk¬y¶q¡A®ø°£¦Xªk¸ê®Æ¥]³Q©ß±ó²§±`ÀË´ú¡]Anomaly Recognition¡^¡G¸Ó¼Ò²ÕºÊµø©Ò¦³¨S¦³³Q¹LÂo©M¤Ï´ÛÄF¼Ò²Õ©ß±óªº¬y¶q¡A±N¬y¶q¦P¥­±`¬ö¿ýªº°ò½u¦æ¬°¶i¦æ¤ñ¸û¡Aµo²{²§±`¡C°ò¥»­ì²z´N¬O³q¹L¼Ò¦¡¤Ç°t¡A°Ï§O¨Ó¦Ûblack-hat©M¦Xªk³q°T¤§¶¡ªº¤£¦P¡C¸Ó­ì²z¥Î¨ÓÃѧO§ðÀ»·½©MÃþ«¬¡A¦Ó¥B´£¥XÄdºI³oÃþ¬y¶qªº«ü«n¡C

²§±`ÀË´ú¥]¬A¡G §ðÀ»¬y¶q³t²v¤j¤p ¥]¤j¤p©M°ðªº¤À§G ¥]¨ì¹F®É¶¡ªº¤À§G ¨Öµo¬y¶q¼Æ °ª¯Å¨ó©w¯S¼x ¥X¡B¤Jªº³t²v ¬y¶q¤ÀÃþ¡G ·½IP ·½°ð ¥Øªº°ð ¨ó©wÃþ«¬ ³s±µ¶q¡]¨C¤Ñ¡B¨C¶g¡^ ¨ó©w¤ÀªR¡]Protocol Analysis¡^¡G¥»¼Ò²Õ³B²z²§±`ÀË´ú¤¤µo²{ªº¥iºÃªºÀ³¥Î¤è­±ªº§ðÀ»¡A¤ñ¦phttp§ðÀ»¡C¨ó©w¤ÀªR¤]ÀË´ú¤@¨Ç¨ó©w¿ù»~¦æ¬°¡C

¬y¶q­­¨î¡]Rate Limiting¡^¡G¥D­n¬O³B²z¨º¨Ç®ø¯Ó¤Ó¦h¸ê·½ªº·½ÀY¬y¶q¡C

©Ò¥H¡A¹ê»Ú¤W³Ì¥D­nªº¤º®e´N¬O²§±`ÀË´ú¤¤ªº²Î­p¤ÀªR¡A¦ý¬O±q¤W­±¬Ý¦ü¥G¨S¦³¦h¤Ö¯S§Oªº¦a¤è¡A¦ý¬O¡A¤@©w¦³«Ü¦nªººtºâªk¡C¤ñ¦pFILTER¡A¹ê»Ú¬O¹ï¥I¤@¨Ç«Ü¼ô±xªº¦³©úÅã¯S¼xªº§ðÀ»¡A¤Ï´ÛÄF¡A´N¬O¹ï¥Isyn flood³o¼Ëªº¡A»¡¤£©w¤]¬O¤@­Ósyn cookie¼Ò²Õ¡A¡A¦ý¤]³\¦³§ó±M§Qªº§Þ³N¡C

¨óij¤ÀªR¨ä¹êÀ³¸Ó¨Ó»¡´N¤ñ¸û®z¤F¡A¦ý¥i¥H°w¹ï¤@¨Ç±`¨£¨óij¤¤ªº¯S©w§ðÀ»¡AÀË´úÃѧO¤@¨Ç¨ó©w¿ù»~¦æ¬°¥u¬O¨ó©w®ÕÅç¡A³o­Ó«Ü²³æ¡C¬y¶q­­¨î«h´N¬O¤@ºØÀH¾÷¥á¥]¡A³ÌµL©`ªº¿ìªk¡A©Ò¥H¤]¬O³Ì«á¤@­Ó¼h¦¸¤F¡C

¦]¬°³o­Ó²£«~¥D­n¬O§@Mitigationªº¡A¦Ó¤£¬Oip traceback¡C¦ý¬O¥i¥H§P©wÁÙ¬O¦³­«­nªº°ÝÃD¡A¤ñ¦p¡G

1¡B¦p¦ó¹ï¥I¯u¥¿ªºbandwidth flood¡C¦pªG¸ô¥Ñ¾¹¬O¤d¥üªº¡A¦ý¬O¡A§ðÀ»¬y¶q¤w¸g¥e¤F90%¡A¥u¬y¤U10%Åý¦Xªk¨Ï¥Î¡A¸ô¥Ñ¾¹¤w¸g¥ý»PGuard¶}©l¶i¦æÀH¾÷¥á¥]¤F¡C¡]¨S¿ìªk¡A³o¬O©Ò¦³¨¾¿m§Þ³Nªº²~ÀV¡^

2¡B¯u¥¿ªº§ðÀ»¡C¯u¥¿ªº§ðÀ»¬O«ÜÃø©ÎªÌµLªkÃѧOªº¡C¤ñ¦p¡A°ò¥»¸ò¥¿±`§Î¦¡¤@¼Ëªº¡A¦pªG©M²Î­p¸ê®Æ«Ü±µªñ¡A¨º»ò«ÜÃø°Ï§O¥X¨Ó¡CÁÙ¦³¤@¨Ç§ðÀ»¡A¤ñ¦p¤Ï®g¦¡ªº¶l¥ó§ðÀ»µ¥¡A³o¬O§¹¥þ¦Xªkªº¡A¦ý¬O«ÜÃø¤ÀÃþ¥X¨Ó¡C





〓¤¤°ê¶Â«ÈÁp·ù¡]CHU¡^〓«e®Ö¤ß¦¨­û¡A²{¬°ºaÅA·|­û
〓¤¤°ê¶Â«ÈÁp·ù¡]CHU¡^〓ºôµ¸¹q¤lÂø»x¡m¯x°}¡n½s¿è
­·°ó§Þ³N¤u§@«Ç
³»³¡

 



¥»¯¸³]³Æ¾¹§÷¥Ñ Many Way (HK) Limited ÃÙ§U´£¨Ñ
·í«e®É°Ï GMT+8, ²{¦b®É¶¡¬O 2008-10-11 17:47

Advertisting Agency

Audit and Analytics

Partner Companies

Powered by Discuz! 5.5.0¢x0.068443 (s), 7 queries, Copyright © 2008 HK-PUB.COM All Rights Reserved. ¥»¯¸Án©ú - ¼s§i¬d¸ß - ²M°£ Cookies - Ápô§Ú­Ì - ¤j²³½×¾Â - Archiver - WAP