éå»æ°å幎ã«ããã£ãŠãITæ¥çã¯ãã®éçºã«å€§ããªãã¬ãŒã¯ã¹ã«ãŒããããããŸãã-å€ãã®æ°ãããã¯ãããžãŒããµãŒãã¹ãããã°ã©ãã³ã°èšèªãªã©ãç»å ŽããŸããã ããããæãéèŠãªããšã¯ãITãã¯ãããžãŒã®ãŠãŒã¶ãŒã®æ°ã巚倧ãªèŠæš¡ã«æé·ããããšã§ãã ããã¯ç¹ã«ãã©ãã£ãã¯éã§é¡èã«ãªããŸãã-GoogleãFacebookãTwitterãªã©ã®å€§èŠæš¡ãªãµãŒãã¹ã¯ãã¿ãã€ãã®ãã©ãã£ãã¯ãåŠçããŸãã åæã«ã誰ããèªåã®ããŒã¿ã»ã³ã¿ãŒã®çš®é¡ãç¥ã£ãŠããŸãã ãã ããä»ã¯ã¯ã©ãŠããã¯ãããžãŒãšNoSQLãœãªã¥ãŒã·ã§ã³ã«ã€ããŠã¯èª¬æããŸããã ãã®ç¶æ³å
šäœãããäžæ¹ã®åŽãã€ãŸãã»ãã¥ãªãã£ã®èŠ³ç¹ããå°ãèŠãããšæããŸãã
ãã©ãã£ãã¯ããã倪ãç·ãæ¥ç¶ãããŠããããŒã¿ã»ã³ã¿ãŒããããšæ³åããŠãã ããã ããªãã«åãããã©ãã£ãã¯ã¯ã©ããããå®å
šã§ããïŒ ç§ã¯ããŸãçŽ æŽã§ã¯ãªãããããèšã£ãŠãããã§ãããã ã€ã³ã¿ãŒãããã«ã¯ããŠã€ã«ã¹ããããã¯ãŒã¯ã¯ãŒã ãDoSãDDoSã®äœææ¹æ³ã«é¢ããèšäºãå€ãããŸããã¹ã¯ãªããããã£ã®æ°ã¯ä»ãèŠæš¡ãè¶
ããŠãããããã®ã¯ã©ãã«ãŒãéãå¯èœæ§ã¯èª°ãé©ãããšã§ã¯ãããŸããã
ãã®æç¹ã§ããã®ãã¹ãŠã®ææãã身ãå®ãæ¹æ³ã«ã€ããŠèãå§ãããšãITã³ã³ãµã«ãã£ã³ã°ã®åæ¢ãªäººãã¡ãã次ã®ããã«èšãããŸãã䟵å
¥æ€ç¥ã·ã¹ãã ããã¡ã€ã¢ãŠã©ãŒã«ãIPSãã¢ã³ããŠã€ã«ã¹ãã©ãã«ã§ãã€ã³ã¹ããŒã«ããŸãã åççãªè³ªåãããããã®éšåã¯ã©ããããå¿
èŠã§ããïŒãã«ããã©ãã£ãã¯ã®ããã¯ã€ã€ã®å€ªãã«å¿ããŠã10/20/100/500ãšããæ°åãåŒã³åºããŸãã
ãããŠãããã§åé¡ãçºçããŸããããã«ã€ããŠã話ããããã®ã¯ããã©ãã£ãã¯ãä¿è·ããããã«ãã©ãã£ãã¯ã®åŠçã䞊ååããæ¹æ³ã§ãã ãã®è³ªåã¯ããã€ãã®çç±ã§éåžžã«éèŠã§ãã
1.ã»ãã¥ãªãã£ã¯ãã·ã¹ãã /ãµãŒãã¹/ãã®ä»ã®åºç€ãšãªãåºç€ã®äžå¯æ¬ ãªéšåã§ãã
2.ã»ãã¥ãªãã£ã¡ã«ããºã ã¯éåžžã«ãªãœãŒã¹ãæ¶è²»ããŸãïŒããŒã ã³ã³ãã¥ãŒã¿ãŒã®KasperskyãæãåºããŠãã ããïŒã
3.ãã£ãã·ã¥ãå®è¡äºæž¬ãªã©ã®å©ããåããŠããã»ãã¥ãªãã£ã¡ã«ããºã ãå éããããšã¯ã»ãšãã©ã§ããŸããã
äžæ¹ã§ãç§ãã¡ã®ç掻ãããè¯ãããããã«ãä¿è·å
·èªäœã®çç£æ§ãåäžãããæ°ããæ¹æ³ãèãåºãããšãã§ããŸãã äžæ¹ãã»ãã¥ãªãã£æ©èœãå°ãã ãåäœæããŠãã®ãŸãŸã«ããŠãããããããæ¹åãã代ããã«ãã»ãã¥ãªãã£æ©èœãåããåæ£ãã©ãã£ãã¯åŠçãç·šæããæ¹æ³ãèãåºãããšãã§ããŸãã
ãã®æç¹ã§ãç¹ã«ã€ã©ã€ã©ãã人ã
ã¯ãF5 Big-IPã®ãããªãã®ãæäŸããããšãææ¡ãå§ããŸããF5Big-IPã¯ãCheckpoint Security Gatewayã䜿çšããŠãµãŒããŒã«ãã©ãã£ãã¯ãåæ£ããŸãã ååãšããŠãè¯ã解決çã§ããã次ã®å Žåã«æ©èœããªããªããŸãã
â¢ã»ãã¥ãªãã£èšå®ãç°¡åãã€ç°¡åã«åæ§æãããïŒãã¡ã€ã¢ãŠã©ãŒã«ã®ã«ãŒã«ã®å€æŽãVPNãžã®IPã¢ãã¬ã¹ã®è¿œå ãªã©ïŒã
â¢ã»ãã¥ãªãã£ããŒã«ã®å¥ã®ã€ã³ã¹ã¿ã³ã¹ãæ
éã«è¿œå ããå Žåã
â¢ä¿è·å
·ã®èœäžã1ã€ãŸãã¯ããã«æªãå ŽåããããŸãã
ããã«ãæ¢åã®ä¿è·ãªãã·ã§ã³ã«ãã£ãŠãŸã å¶éãããŠããŸããç¬èªã®ãã®ãäœæãããå Žåã¯ã...ããŒã...ãã ç²ããããã§ãã
ããããæããããšã¯ãããŸãããç§ãã¡ã¯ããªããå©ããŸãïŒ äŒç€Ÿã«ã¯CrossbeamãšããçŽ æŽããããã®ããããŸãã ãããŠãããã ãã®äŸ¡å€ãããã ãã§ãªããä¿è·è£
眮ã®éçºãšç§»æ€ã®ããã«ç§ãã¡ã«ãã£ãŠç©æ¥µçã«äœ¿çšãããŠããŸãã ãããäœã§ãããç°¡åã«èª¬æããŸãã
Crossbeamã¯ãã»ãã¥ãªãã£æ©èœãåãããšã³ãããŒãšã³ãã®ãã©ãã£ãã¯åŠçåãã«èª¿æŽããããã©ãããã©ãŒã ã§ãã 以äžãæäŸããŸãã
â¢åŒ·åãªããŒããŠã§ã¢æ§æã
â¢ãã©ãã£ãã¯ã®åæ£ãšãã©ã³ã·ã³ã°ã®ã¡ã«ããºã ã
â¢ç¬èªã®ã¢ããªã±ãŒã·ã§ã³ãéçºããããã®ããŒã«ã
ãã©ãããã©ãŒã ã¯ã次ã®ã³ã³ããŒãã³ãã§æ§æãããŠããŸãã
1.ããŒããŠã§ã¢
1ïŒã·ã£ãŒã·
2ïŒé»æºãšææ°
3ïŒã¢ãžã¥ãŒã«ïŒ
iã ãããã¯ãŒã¯ïŒNPM-ãããã¯ãŒã¯åŠçã¢ãžã¥ãŒã«ïŒ
iiã ã¢ããªã±ãŒã·ã§ã³ïŒAPM-ã¢ããªã±ãŒã·ã§ã³åŠçã¢ãžã¥ãŒã«ïŒ
iiiã ã³ã³ãããŒã«ïŒCPM-ã³ã³ãããŒã«åŠçã¢ãžã¥ãŒã«ïŒ
2.ãœãããŠã§ã¢
1ïŒXOSãªãã¬ãŒãã£ã³ã°ã·ã¹ãã
2ïŒä»®æ³ã¢ããªã±ãŒã·ã§ã³ããã»ããµ-VAPïŒä»®æ³ã¢ããªã±ãŒã·ã§ã³ããã»ããµïŒ
3ïŒã¢ããªã±ãŒã·ã§ã³
ãã©ãã£ãã¯åŠçããã»ã¹ã¯ã次ã®ããã«è¡šãããšãã§ããŸãã
çä¿¡ãã©ãã£ãã¯ã¯ãããã¯ãŒã¯ã¢ãžã¥ãŒã«ããŒãïŒNPMïŒã«å°çããã¢ããªã±ãŒã·ã§ã³ã¢ãžã¥ãŒã«ïŒAPMïŒã«åé
ãããŸãã èŠããã«ãããã¯æ¬¡ã®ããã«è¡ãããŸãã
1. NPMã¯IPãã±ããããããŒã解æããŸãã
2.次ã®ããŒã¿ãããããŒããæœåºãããŸãã
aã éä¿¡å
IPã¢ãã¬ã¹
bã å®å
IP
cã éä¿¡å
TCPããŒã
dã å®å
TCPããŒã
ãããŠã¿ãã«ã«åœ¢æãããŸãã åãã¿ãã«ãæã€ãã¹ãŠã®ãã±ããã¯ããã©ãã£ãã¯ãããŒãšåŒã°ããŸãã
3.ããããã¿ãã«ã§ã®æ€çŽ¢ãå®è¡ãããŸãã ã¢ã¯ãã£ããªãããã¯ãŒã¯ãããŒã®ããŒãã«ïŒAFT-ã¢ã¯ãã£ããããŒããŒãã«ïŒã æ€çŽ¢çµæã¯ããã©ãã£ãã¯ãåŠçããããã«èšèšãããAPMçªå·ã§ãã
4.æ€çŽ¢ãæåããå Žåããã±ããã¯é©åãªAPMã«éä¿¡ãããŸãã
5.æ€çŽ¢ãæåããªãã£ãå ŽåãNPMã¯CPMã«åãæ¿ããŸããCPMã¯ãã©ãããã©ãŒã å
šäœã®æ§æãä¿åããAFTã«æ°ãããšã³ããªãè¿œå ããŸãã
ãã®ãããªã¢ã«ãŽãªãºã ã«ãããæåã«è¡šæãããåé¡ãã€ãŸããã©ãã£ãã¯ãä¿è·ããããã«ãã©ãã£ãã¯ã®åŠçã䞊ååããæ¹æ³ã解決ã§ããŸãã åæã«ããã®ãã©ãã£ãã¯åæ£æ¹æ³ã¯è² è·ã®ãã©ã³ã¹ããšãã®ã«ååéžæçã§ãããåæã«è€æ°ã®ã³ã³ãã¥ãŒãã£ã³ã°ããŒãéã§ãŠãŒã¶ãŒã»ãã·ã§ã³ããªããã³ã°ããããšã¯ã§ããŸããã
ããã«ããã©ãããã©ãŒã ããŒã«ã«ãã次ã®ããšãå¯èœã«ãªããŸãã
â¢ç°¡åã§æªæ§æã®ã»ãã¥ãªãã£èšå®ã ããã¯1ãæã§1åè¡ããããã¹ãŠã®ã€ã³ã¹ã¿ã³ã¹ã«é©çšãããŸãã
â¢ä¿è·è£
眮ã®1ã€ãŸãã¯è€æ°ã®ã€ã³ã¹ã¿ã³ã¹ãèœäžããå Žåãä¿è·è£
眮ã®ä»ã®ã€ã³ã¹ã¿ã³ã¹ïŒAPMïŒã®è² è·ãèªåçã«åé
åããŸãã
äžè¬ã«ãåªããæ©èœæ§ãåããéåžžã«èå³æ·±ãéçã§ãã
圌女ãç§ãã¡ã®ãšããã«æ¥ããšããç§ãã¡ã¯ãã®ãããªããšãæ ãã®ã¯ç¡äŸ¡å€ã§ãããšå€æããããå°çšã®æå·ã²ãŒããŠã§ã€ãéçºããŸããã ç§ãã¡ã®ç解ã§ã¯ãããã¯ãã®ãããªããã°ã©ã ã§ãããããŒã¿ã»ã³ã¿ãŒã®åã«çœ®ããã次ã®ãšããã§ãã
â¢ããŒã¿ã»ã³ã¿ãŒã«åãããã©ãã£ãã¯ã®ãã±ããã解èªãããªãœãŒã¹ã倧éã«æ¶è²»ããã³ã³ãã¥ãŒãã£ã³ã°ãããµãŒããŒãã¢ã³ããŒããã
â¢ããŒã¿ã»ã³ã¿ãŒããã®ãã©ãã£ãã¯ã®ãã±ãããæå·åããããšã«ãããã¯ã©ã€ã¢ã³ããžã®æ
å ±ã®å®å
šãªè»¢éãä¿èšŒããŸã
ããããããããããã«ãå³ã瀺ããŸã
ãã®ã²ãŒããŠã§ã€ã¯æ¬¡ã®ããšãè¡ããŸãã
â¢APMã«ãã£ãŠçä¿¡ãã©ãã£ãã¯ãã±ãããé
åžããŸãã
â¢GOST 28147-89ã®ã¢ã«ãŽãªãºã ã«åŸã£ãŠåãã±ããã®ã³ã³ãã³ããæå·åããŸãã
â¢ãã±ãããéä¿¡å
ã«éä¿¡ããŸãã
â¢éæ¹åã®ãã±ããã®å Žåãåãããšãè¡ããã³ã³ãã³ãã埩å·åããŸãã
åæã«ãåã¯ã©ã€ã¢ã³ãã¯ïŒå®éã«ã¯ãåIPã¢ãã¬ã¹ã«å¯ŸããŠïŒç¬èªã®ããŒãæã£ãŠããå¿
èŠããããŸãã
APMã§ã¹ãã³ããŠããã®ã¯ãRHELãåé€ããŠããããåœãŠããã®ã«ãããªããããéåžžã®CentOSã§éçºãéå§ããŸããã CentOSã§æå·ã²ãŒããŠã§ã€ãäœæããã³ãããã°ããåŸãCrossbeamãžã®è»¢éãéå§ããŸããã SDKãããã¥ã¡ã³ããCrossbeamèªäœã®éçºè
ãšã®ã³ãã¥ãã±ãŒã·ã§ã³ããããããçŽå幎ãè²»ãããŸããã 転éã®æ¬è³ªã¯ããã©ãããã©ãŒã ãšéä¿¡ããããã®ã€ã³ã¿ãŒãã§ã€ã¹ãã¢ããªã±ãŒã·ã§ã³ã«æžã蟌ã¿ããã©ãã£ãã¯ãåé
åžããå¯èœæ§ãèæ
®ããããšã§ãã
æåã«ééããåé¡ã¯ãããã°ã§ãã APMã«ã¯gdbããªããããæåã¯ãããã°ããæ¹æ³ãããããŸããã§ããã ããããAPMãæ
éã«æ³šææ·±ãæ€èšãããšãCOMããŒããèŠã€ãããŸããã ãã®åŸããœãªã¥ãŒã·ã§ã³ã¯éåžžã«è¿
éã«ç»å ŽããŸãã-COMããŒããä»ãããªã¢ãŒããããã°ã Linux APMã€ã¡ãŒãžã®ã«ãŒãã«ãã©ã¡ãŒã¿ãŒãèšå®ããprocã®kdbãä»ãããããã°ãå«ããŸããã ãšããã§ãååãããããã°ã«ã€ããŠèªãããšãã§ããŸãïŒhttp://habrahabr.ru/company/neobit/blog/141067ïŒ
2çªç®ã®åé¡ã¯ãããã»ããµã³ã¢å
šäœã®è² è·ã®åäžãªåæ£ã§ãã åœåãæå·ã²ãŒããŠã§ã€ã¯ãnetfilterãµãã·ã¹ãã ã«ããã¯ãèšå®ããã«ãŒãã«ã¢ãžã¥ãŒã«ã§ããã ãã©ãã£ãã¯ã®éä¿¡ãéå§ãããšããAPMã§äœ¿çšå¯èœãª16ã³ã¢ã®ãã¡ã1ã€ã99ïŒ
ããŒããããæ®ããã¢ã€ãã«ç¶æ
ã§ããããšãããããŸããã åæã«ããã±ããæ倱ã¯åã«å®¹èµŠãããŸããã§ããã ããã¯ããã«é¢é£ããŠããŸããã Linuxã«ãŒãã«ã®netfilterããã¯ãã³ãã©ãŒãžã®åŒã³åºãã¯ããããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ãœãããŠã§ã¢ã®å²ã蟌ã¿ã«ãã£ãŠè¡ãããŸãã / proc / interruptsã調ã¹ãŠããããã·ã¹ãã ã«åœãŠã¯ãŸããã©ããã確èªã§ããŸãã
ãã®åé¡ã解決ããããã®2ã€ã®ãªãã·ã§ã³ããããŸãã
1.ã«ãŒãã«ãã©ã¡ãŒã¿ãŒSMP_AFFINITYãæ§æããŸãã
2. CONFIG_HOTPLUG_CPUãã©ã¡ãŒã¿ãŒã䜿çšããŠLinuxã«ãŒãã«ãåæ§ç¯ããŸãïŒã«ãŒãã«ããŒãžã§ã³2.6.24.3以éïŒã
æåã®ã±ãŒã¹ã§ã¯ãããããã¹ã¯ããã¡ã€ã«
/ proc / irq / <å²ã蟌ã¿çªå·> / smp_affinityã«æžã蟌ãŸããŸãããã®ãŠãããã¯ããã®å²ã蟌ã¿ã®åŠçã«é¢äžããã«ãŒãã«ã«å¯Ÿå¿ããŠããŸãã ãã ããã»ãšãã©ã®å Žåããã®ãœãªã¥ãŒã·ã§ã³ã§ã¯ã1ã€ã®ã³ã¢ããå¥ã®ã³ã¢ã«è² è·ãååæ£ããããšããã§ããŸããã ã€ãŸã ãã¹ã¯4ïŒ000100ïŒãsmp_affinityã«æžã蟌ããšãå²ã蟌ã¿ã¯3çªç®ã®ã³ã¢ã§åŠçãããŸãã ãã ãããã¹ã¯7ïŒ000111ïŒãèšé²ããå Žåãå²ã蟌ã¿åŠçã¯æåã®ã³ã¢ã§ã®ã¿å®è¡ãããŸãã ãããã£ãŠããã®ãœãªã¥ãŒã·ã§ã³ã¯éåžžã«éãããããŒããŠã§ã¢ã»ããã«ã®ã¿é©çšã§ããŸãã 2çªç®ã®ãªãã·ã§ã³ã¯ããæ®éçã§ãããåžžã«é©çšã§ããããã§ã¯ãããŸãããå€ãã®ã¡ãŒã«ãŒã¯ãåæ§ç¯çšã®ãœãŒã¹ã³ãŒããæäŸããã«ãããŒããŠã§ã¢ã®Linuxã«ãŒãã«ã匷åã«å€æŽããŸãã ãããŠãããã®éã®ã¯ãã¹ããŒã ã Crossbeaméçºè
ããå°ãç§å¯ã®ç¥èãé©çšããå¿
èŠããããŸããã圌ãã¯ãããã±ãŒãžãLinuxã«ãŒãã«ã«å
¥ãåã§ãã£ãŠããã©ãã£ãã¯ã®åæåŠçãå®è¡ããCrossbeamã«åããããã©ã€ããŒãäœæããŸããã
ãã®çµæãé©ããããã©ãŒãã³ã¹ãéæããããšãã§ããŸãããGOST28147-89ã«ãããšã0.95 Gb / sã®é床ã§ã®æå·åã®ã¹ããªãŒãã³ã°ã§ãã 1ã€ã®APMã§ã ãããŠãããã¯ããã€ãã®çç±ã«ããéæãããŸãã第äžã«ããããã¯ãŒã¯ãã©ãã£ãã¯ã®åŠçã䞊ååããããšã第äºã«ã³ã¢å
šäœã«è² è·ãåæ£ããããšã第äžã«åŒ·åãªããŒããŠã§ã¢ãã©ãããã©ãŒã ã«ãããã®ã§ãã
ãã©ãã£ãã¯ã®äžŠååã®å¯èœæ§ãæãèµ·ããã°ãAPMã®è¿œå ã«ãã£ãŠæå·åé床ã¯ã»ãŒçŽç·çã«å¢å ãããšèšããŸãã ã€ãŸãã3 APMã®æ倧æ§æã§ã¢ããªã±ãŒã·ã§ã³ãå®è¡ãããšãã»ãŒ3 Gb / sã®é床ã§æå·åã§ããŸãã ããªããéæã¡ãªããããªãã¯æãã¯ãŒã«ãªã¢ãã«ã賌å
¥ãã10 Gb / sãŸã§äœãããšãã§ããŸãã æªããªãã§ããïŒ
ã¡ãªã¿ã«ããããã®æ°å€ã¯ãã»ãšãã©ã®ã¡ãŒã«ãŒãè¡ã£ãŠããããã«ãçè«çã«ã§ã¯ãªãå®éšçã«åŸããããã®ã§ãã 5 Gb / sã®è² è·ãçæããã¹ã¿ã³ããçµã¿ç«ãŠãŸããã ããã±ãŒãžã埩å·åããHTTPãµãŒããŒãšããŠãnginxãååŸãããã®èšå®ãLinuxãããã¯ãŒã¯ã¹ã¿ãã¯ã®èšå®ãå€æŽããnginxã«5 Gb / sã®é床ã§HTML-staticã匷å¶ããŸããã
èŠçŽãããšã次ã®çµè«ãå°ããããšæããŸãã ãã©ãã£ãã¯åŠçã®äžŠååã¯ããã«ããã¯ãå
æããããã®éåžžã«å¹æçãªã¢ãããŒãã§ãããããæè¿ã»ãã¥ãªãã£ããŒã«ã«ãã®ã¢ãããŒããé©çšããããã«ãªããGOSTã¢ã«ãŽãªãºã ã®æåã®1ã€ã«ãªããŸããã ç§ãã¡ã®ã¢ã€ãã¢ã¯ãå¥ã
ã®ãããŒã§ãããã¯ãŒã¯æ¥ç¶ãæå·åããè€æ°ã®ç¬ç«ããã³ã³ãã¥ãŒãã£ã³ã°ã¢ãžã¥ãŒã«äžã®å€æ°ã®ã³ã¢ã«èšç®ãåæ£ããããšã§ããã©ãã£ãã¯ãããŒã䞊ååããããšã§ããã åœç¶ãã»ãã¥ãªãã£æ©èœãã¢ããªã±ãŒã·ã§ã³ã·ã¹ãã ã®ããžãã¯ããåé¢ããããã»ã¹ã¯ç°¡åã§ã¯ãããŸããã§ããããå³ããæãããªããã«ãç§ãã¡ã®åªåã¯å®å
šã«æ£åœåãããŸããã