APC
¨¾°ôDDoS§ðÀ»¡A¤]­nÁקK¦¨¬°À°¥û 2013.06.11

¨¾°ôDDoS§ðÀ»¡A¤]­nÁקK¦¨¬°À°¥û

ªñ¨Óºô¸ô¥@¬Éµv·Ï¼u«B¡A±q¥_Áúºô­x§ðÀ»«nÁúºô¯¸¡B¤j³°ºô­x§ðÀ»¥xÆW¬F©²¡A¦Üªñ¤é¥x¡Bµáºô­xªº¬Û¤¬§ðÀ»¡A³Ì±`¨£ªº§ðÀ»¤âªk¡A²ö¹L©óDDoS§ðÀ»¡C«Â¼½¬ì§Þªí¥Ü¡ADDoS§ðÀ»¸g±`¦ñÀHBotnet(íL«Íºô¸ô)¶i¦æ¡A§ðÀ»ªÌ³z¹L¤j¶qªºíL«Í¹q¸£µo°e©R¥O¡A¨Ï¨ä¦P®É¶¡¹ï¯S©w¥Ø¼Ðµo°Ê§ðÀ»¡C¦]¦¹¡AµL½×¬O¬F©²©Î¥ø·~²Õ´¡A°£¤F¨¾°ôºô­xDDoS§ðÀ»¡A§ó­nÁקK·P¬VBotnet¡A¥H¨¾¤£ª¾¤£Ä±¦¨¬°ºô­xªºÀ°¥û¡C

«Â¼½¬ì§Þ²£«~³¡±M®×¸g²z¦¶·ç¨fªí¥Ü¡A¥Ñ©óDDoS§ðÀ»ÅܤƦhºÝ¡A¦]¦¹Àu²§ªºIPSÀ³±Ä¨ú¦h­«±¹¬I¥Hªý¾×§ðÀ»¡A¥]¬A¡G(1)¦Û°Ê²Î­p¨C­Ó¨Ó·½IPªº«Ê¥]¼Æ¥Ø¡A¦bªý¾×§ðÀ»®É¡A¤´¥iÅý¨ä¥L¥¿±`¦s¨úªº¨Ó·½IPÄ~Äò¨É¥Îºô¸ôªA°È¡F(2)§êºtSYN Proxy¨¤¦â¡A¶i¦Ó¥N´À¤ººô¥D¾÷±µ¦¬¥~¬Éµo°eªºTCP SYN«Ê¥]¡A¦b²Ä¤@®É¶¡©Ó¨üTCP SYN¬y¶q¡F(3)³z¹L¯S®íªº³æ¦ì®É¶¡²Î­p¤Î²Ä¤C¼h¯S¼x½X¾÷¨î¡A¨¾¿m²Ä¤C¼hDDoS§ðÀ»¡C¨Ã¥B¦bIPS°»´ú¨ìDDoS§ðÀ»®É¡A¥²¶·¦b²Ä¤@®É¶¡¶i¦æÄdªý¡B§Y®Éµo¥Xĵ§i¡A¦P®É©ú½T«ü¥X§ðÀ»ªÌ¦b¦ó®É¡B¨Ó¦Û©ó¨º­ÓIP¡B§ðÀ»¨º¨Ç¤º³¡¥D¾÷¡B¦óºØ§ðÀ»¤âªkµ¥¡A³o¨Ç¸ê°T±N¦³§U©ó¸ê°T¤H­û§@«áÄòªº³B²z¡C

¦¹¥~¡A«Â¼½¬ì§Þªí¥Ü¡A¥Ñ©óDDoS§ðÀ»¸g±`¦ñÀHBotnet¶i¦æ¡A¦ÓBotnetªºÁô°Î©Ê«D±`°ª¡A¨ã¦³¬Û·íªº«Â¯Ù©Ê¡A¦]¦¹À³¥ý±qBotnetªº¤J«I¡BÂX´²»P³sµ²µ¥¦æ¬°µÛ¤â¡A±q·½ÀY¨¾ªv¡A¤~¯à¸Ñ¨M¥ø·~²Õ´¤ºBotnet°ÝÃD¡C§ùµ´Botnet§ðÀ»ªº¤è¦¡¤§¤@¡A«K¬O±Ä¥Î¤º«ØBotnet¶Â¦W³æªºIPS¡A¥ç§Y³z¹L¯S¼x¤ñ¹ïªº¤è¦¡¡A¤ÁÂ_íL«Í¹q¸£»P«á¥x¦øªA¾¹ªºÁpô¡A¹F¨ì¦³®ÄªýÂ_DDoS§ðÀ»¤Î¸ê®Æ¥~¬ª¡C¦]¦¹IPS¤º«ØBotnet¸ê®Æ®wµ§¼Æ¡A«K¦¨¬°IPSªºµû¦ô­«ÂI¡C

«Â¼½¬ì§Þªí¥Ü¡A¥þ¥@¬É¦³ªñ¤T¤À¤§¤@ªº´c·Nµ{¦¡¨Ó¦Û¤¤°ê¤j³°¡A¤×¨ä¬O¬F©²³æ¦ì¤Î¾ÚÂI¤À§G©ó¨â©¤¤T¦aªº¥ø·~¥Î¤á¡A§óÀ³¦Ò¼{¿ï¾Ü¨ã³Æ¤j¤¤µØ°Ï±`¨£ªºBotnet¸ê®Æ®w¡A¹F¨ì¦³®Ä¨¾°ôÀb«È§ðÀ»ªº¨Æ¥óµo¥Í¡C

¡iÃö©ó«Â¼½¡j

«Â¼½¬ì§Þ(Broadweb)¦¨¥ß©ó1999¦~¡A­P¤O©ó°ª³tºô¸ô¬y¶q¿ëÃѤΥý¶iºô¸ô«Â¯Ù¨¾¿m§Þ³N¡A¬O¥þ²y¤Ö¼Æ´¿Àò±oNSS Labs¤ÎICSA Labs¤J«I¨¾¿m¨t²Î»{ÃÒªº¨ÑÀ³°Ó¡C¨ä¸ê¦w²£«~¥H³]³Æ¤Î³nÅé±ÂÅv¤§§Î¦¡¡A¦æ¾P©ó°ê¤º¥~¡A²×ºÝ¥Î¤á¶W¹L¦Ê¸U¡A¬°¥þ²y¤J«I¨¾¿m»â°ì³Ì¤jªºODM¼t°Ó¡C¨Ã©ó2012¦~¦¨¬°²Ä¤@®aNCC¦w¥þÀË´úªº¸ê¦w³]³Æ¼t°Ó¡C§ó¦h°T®§½Ð¦Üwww.broadweb.com.tw