| 講演抄録/キーワード |
| 講演名 |
2014-03-07 10:20
動的パケットフィルタリングによる反射型DoS攻撃の遮断手法 ○首藤裕一・波戸邦夫(NTT) IN2013-181 |
| 抄録 |
(和) |
近年,反射型サービス妨害攻撃(反射型DoS攻撃)の脅威が高まっている.2013年3月にはトラヒック量が300Gbps以上の攻撃トラヒックが観測されるなど,反射型DoS攻撃では膨大な攻撃トラヒックによりネットワークの帯域が消費されるため,標的システムの運営者における対策は有効でなく,標的システムが属するAS(Autonomous System)による攻撃遮断対策が必要となる.本稿では,反射型DoS攻撃による攻撃パケットをAS側で遮断する手法を提案する.提案手法では,標的システムへの攻撃を検知すると,周囲のASから標的システム宛のパケットのうち,攻撃に利用されている種別のパケットを他ASとの境界ルータですべて遮断する.標的システムから正常なパケットが発生した場合には境界ルータの遮断設定を部分的に開放し,AS全体で仮想的に動的パケットフィルタリング機能を実現することで標的システムと外部との正規トラヒックの疎通性を保証する.提案手法により,標的システムの外部との疎通性を阻害することなく攻撃パケットをASの境界ルータで遮断することが可能となる. |
| (英) |
Recently, danger of reflective DoS attacks is growing. For example, attacking traffic more than 300 Gbps of reflective DoS attack is observed in Europa on March 2013. Since reflective DoS attacks consume a vast amount of network bandwidth, the operator of the target system cannot deal with the attack effectively. Instead, the autonomous system (AS) that the target system belongs to should deal with the attack. In this paper, we propose the method that an AS protects the target system from reflective DoS attacks by dropping the attacking packet at boundary routers. Specifically, the proposed method virtually realizes dynamic packet filtering by controlling the configuration of boundary and reception routers of the AS adequately. The proposed method never drop regular packets while it drops all of the attacking packets at any boundary routers of the AS. |
| キーワード |
(和) |
反射型DoS攻撃 / 動的パケットフィルタリング / DNSアンプ攻撃 / / / / / |
| (英) |
Reflective DoS Attack / Dynamic Packet Filter / DNS Amplification / / / / / |
| 文献情報 |
信学技報, vol. 113, no. 473, IN2013-181, pp. 223-228, 2014年3月. |
| 資料番号 |
IN2013-181 |
| 発行日 |
2014-02-27 (IN) |
| ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
著作権に ついて |
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
| PDFダウンロード |
IN2013-181 |