©Kivshenko Alexeyã1880ãã®èšäºã§ã¯ãã€ã³ã¿ãŒãããããäŒæ¥ãããã¯ãŒã¯ãµãŒãã¹ãžã®ã¢ã¯ã»ã¹ãæŽçããåé¡ã解決ããããã®
5ã€ã®ãªãã·ã§ã³ã®æŠèŠã説æããŸãã ãã®ã¬ãã¥ãŒã¯ãå®å
šæ§ãšå®çŸå¯èœæ§ã®ãªãã·ã§ã³ã®åæãæäŸããŸããããã¯ãåé¡ã®æ¬è³ªãç解ããåå¿è
ã®å°é家ãšçµéšè±å¯ãªå°é家ã®äž¡æ¹ã«ç¥èãæŽæ°ããã³äœç³»åããã®ã«åœ¹ç«ã¡ãŸãã èšäºã®è³æã䜿çšããŠãèšèšäžã®æ±ºå®ãæ£åœåã§ããŸãã
ãªãã·ã§ã³ãæ€èšãããšãã¯ãäŸãšããŠå
¬éãããããã¯ãŒã¯ãåãäžããŸãã
- äŒæ¥ã¡ãŒã«ãµãŒããŒïŒWebã¡ãŒã«ïŒã
- ãšã³ã¿ãŒãã©ã€ãºã¿ãŒããã«ãµãŒããŒïŒRDPïŒã
- è«è² æ¥è
åãã®ãšã¯ã¹ãã©ããããµãŒãã¹ïŒWeb-APIïŒã
ãªãã·ã§ã³1.ãã©ãããããã¯ãŒã¯
ãã®ãªãã·ã§ã³ã§ã¯ãäŒæ¥ãããã¯ãŒã¯ã®ãã¹ãŠã®ããŒãã¯ããã¹ãŠã«å
±éã®1ã€ã®ãããã¯ãŒã¯ïŒãå
éšãããã¯ãŒã¯ãïŒã«å«ãŸããããŒãéã®éä¿¡ã¯å¶éãããŸããã ãããã¯ãŒã¯ã¯ããšããžã«ãŒã¿ãŒ/ãã¡ã€ã¢ãŠã©ãŒã«ïŒä»¥äž
-IFW ïŒãä»ããŠã€ã³ã¿ãŒãããã«æ¥ç¶ãããŠããŸãã
ã€ã³ã¿ãŒããããžã®ãã¹ãã¢ã¯ã»ã¹ã¯
NATãä»ããŠè¡ãããã€ã³ã¿ãŒãããããã®ãµãŒãã¹ãžã®ã¢ã¯ã»ã¹ã¯
ããŒã転éãä»ããŠè¡ãããŸãã
ãªãã·ã§ã³ã®ãã©ã¹ ïŒ
- IFWæ©èœã®æå°èŠä»¶ïŒã»ãšãã©ãã¹ãŠã®ããŒã ã«ãŒã¿ãŒã§ãå®è¡ã§ããŸãïŒã
- ãªãã·ã§ã³ãå®è£
ããå°é家ã®ç¥èã«é¢ããæå°èŠä»¶ã
ãªãã·ã§ã³ã®çæ ïŒ
- ã»ãã¥ãªãã£ã®æå°ã¬ãã«ã 䟵å
¥è
ãã€ã³ã¿ãŒãããäžã§å
¬éãããŠãããµãŒããŒã®1ã€ãå¶åŸ¡ããããã¯ãçºçããå ŽåãäŒæ¥ãããã¯ãŒã¯ã®ä»ã®ãã¹ãŠã®ããŒããšéä¿¡ãã£ãã«ã¯ã䟵å
¥è
ããããªãæ»æã«å©çšã§ããããã«ãªããŸãã
å®ç掻ã®é¡æšåæ§ã®ãããã¯ãŒã¯ããã¹ã¿ãããšé¡§å®¢ãåãå
±éã®éšå±ïŒãªãŒãã³ã¹ããŒã¹ïŒã«ããäŒç€Ÿãšæ¯èŒã§ããŸãã
©hrmaximum.ruãªãã·ã§ã³2. DMZ
åè¿°ã®æ¬ ç¹ã解æ¶ããããã«ãã€ã³ã¿ãŒãããããã¢ã¯ã»ã¹å¯èœãªãããã¯ãŒã¯ããŒãã¯ãç¹å¥ã«å²ãåœãŠãããã»ã°ã¡ã³ãïŒéæŠè£
å°åž¯ïŒDMZïŒïŒã«é
眮ãããŸãã DMZã¯ãã€ã³ã¿ãŒãããïŒ
IFW ïŒããã³å
éšãããã¯ãŒã¯ïŒ
DFW ïŒããåé¢ãããã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããŠç·šæãããŸãã
ãã®å Žåããã¡ã€ã¢ãŠã©ãŒã«ããã£ã«ã¿ãªã³ã°ããããã®ã«ãŒã«ã¯æ¬¡ã®ãšããã§ãã
- å
éšãããã¯ãŒã¯ãããDMZããã³WANïŒã¯ã€ããšãªã¢ãããã¯ãŒã¯ïŒã§æ¥ç¶ãéå§ã§ããŸãã
- DMZãããWANã§æ¥ç¶ãéå§ã§ããŸãã
- WANãããDMZã§æ¥ç¶ãéå§ã§ããŸãã
- WANããã³DMZããå
éšãããã¯ãŒã¯ãžã®æ¥ç¶ã®éå§ã¯çŠæ¢ãããŠããŸãã
ãªãã·ã§ã³ã®ãã©ã¹ïŒ- åã
ã®ãµãŒãã¹ã®ãããã³ã°ã«å¯Ÿãããããã¯ãŒã¯ã»ãã¥ãªãã£ã®åŒ·åã ãµãŒããŒã®1ã€ããããã³ã°ãããå Žåã§ãã䟵å
¥è
ã¯å
éšãããã¯ãŒã¯ã«ãããªãœãŒã¹ïŒãããã¯ãŒã¯ããªã³ã¿ãŒããããªç£èŠã·ã¹ãã ãªã©ïŒã«ã¢ã¯ã»ã¹ã§ããŸããã
ãªãã·ã§ã³ã®çæïŒ- DMZå
ã®ãµãŒããŒãåã«åé€ããŠããã»ãã¥ãªãã£ã¯åäžããŸããã
- DMZãå
éšãããã¯ãŒã¯ããåé¢ããã«ã¯ãè¿œå ã®MEãå¿
èŠã§ãã
å®ç掻ã®é¡æšãã®ããŒãžã§ã³ã®ãããã¯ãŒã¯ã¢ãŒããã¯ãã£ã¯ã顧客ãã¯ã©ã€ã¢ã³ããšãªã¢ã«ãããããããã¹ã¿ãããã¯ã©ã€ã¢ã³ããšãªã¢ãšã¯ãŒã¯ãšãªã¢ã®äž¡æ¹ã«ããããšãã§ããäŒç€Ÿã®ã¯ãŒãã³ã°ãšãªã¢ãšã¯ã©ã€ã¢ã³ããšãªã¢ã®çµç¹ã«äŒŒãŠããŸãã DMZã»ã°ã¡ã³ãã¯ããŸãã«ã¯ã©ã€ã¢ã³ãé åã«é¡äŒŒããŠããŸãã
©autobam.ruãªãã·ã§ã³3.ããã³ããšã³ããšããã¯ãšã³ãã§ã®ãµãŒãã¹ã®åé¢
åè¿°ã®ããã«ãDMZã§ãµãŒããŒããã¹ãããŠãããµãŒãã¹èªäœã®ã»ãã¥ãªãã£ã¯ãŸã£ããåäžããŸããã ç¶æ³ãæ¹åããæ¹æ³ã®1ã€ã¯ããµãŒãã¹æ©èœã2ã€ã®éšåã
ããã³ããšã³ããšããã¯ãšã³ãã«åå²ããããšã§ãã ããã«ãåéšåã¯å¥ã
ã®ãµãŒããŒã«é
眮ããããããã®éã§ãããã¯ãŒã¯ã®çžäºäœçšãç·šæãããŸãã ã€ã³ã¿ãŒãããäžã«ããã¯ã©ã€ã¢ã³ããšå¯Ÿè©±ããæ©èœãå®è£
ããããã³ããšã³ããµãŒããŒã¯DMZã«é
眮ãããæ®ãã®æ©èœãå®è£
ããããã¯ãšã³ããµãŒããŒã¯å
éšãããã¯ãŒã¯ã«æ®ãããŸãã ãããã®éã§çžäºäœçšããããã«ãããã³ããšã³ãããããã¯ãšã³ããžã®æ¥ç¶ã®éå§ãèš±å¯ããã«ãŒã«ã
DFWäžã«äœæãããŸãã
äŸãšããŠããããã¯ãŒã¯å
ãšã€ã³ã¿ãŒãããã®äž¡æ¹ããã¯ã©ã€ã¢ã³ãã«ãµãŒãã¹ãæäŸããäŒæ¥ã®ã¡ãŒã«ãµãŒãã¹ãèããŸãã ã¯ã©ã€ã¢ã³ãã¯å
éšã§POP3 / SMTPã䜿çšããã€ã³ã¿ãŒãããããã®ã¯ã©ã€ã¢ã³ãã¯Webã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠæ©èœããŸãã éåžžãå®è£
段éã§ã¯ãäŒæ¥ã¯ãµãŒãã¹ãå±éããæãç°¡åãªæ¹æ³ãéžæãããã®ãã¹ãŠã®ã³ã³ããŒãã³ãã1ã€ã®ãµãŒããŒã«é
眮ããŸãã 次ã«ãæ
å ±ã»ãã¥ãªãã£ã®å¿
èŠæ§ãèªèããããšããµãŒãã¹ã®æ©èœãéšåã«åå²ãããã€ã³ã¿ãŒãããïŒããã³ããšã³ãïŒããã¯ã©ã€ã¢ã³ããžã®ãµãŒãã¹ãæ
åœããéšåããæ®ãã®æ©èœãå®è£
ãããµãŒããŒãšãããã¯ãŒã¯äžã§ããåãããå¥ã®ãµãŒããŒã«è»¢éãããŸãïŒæ»ã-çµäºïŒã ãã®å Žåãããã³ããšã³ãã¯DMZã«é
眮ãããããã¯ãšã³ãã¯å
éšã»ã°ã¡ã³ãã«æ®ããŸãã
DFWã®ããã³ããšã³ããšããã¯ãšã³ãéã®æ¥ç¶ã®å Žåãããã³ããšã³ãããããã¯ãšã³ããžã®æ¥ç¶ã®éå§ãèš±å¯ããã«ãŒã«ãäœæãããŸãã
ãªãã·ã§ã³ã®ãã©ã¹ïŒ- äžè¬çãªã±ãŒã¹ã§ã¯ãä¿è·ããããµãŒãã¹ã«å¯Ÿããæ»æã¯ããã³ããšã³ãã§ãã€ãŸãããå¯èœæ§ããããæœåšçãªæ害ãäžåãŸãã¯å€§å¹
ã«åæžããŸãã ããšãã°ã TCP SYNãã©ããããµãŒãã¹ãç®çãšããé
ãhttpèªã¿åããªã©ã®æ»æã«ãããããã³ããšã³ããµãŒããŒã¯äœ¿çšã§ããªããªããŸãããããã¯ãšã³ãã¯åŒãç¶ãæ£åžžã«æ©èœãããŠãŒã¶ãŒã«ãµãŒãã¹ãæäŸããŸãã
- äžè¬çã«ãããã¯ãšã³ããµãŒããŒã¯ã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ã§ããªãå¯èœæ§ãããããããã³ã°ãããå ŽåïŒããšãã°ãæªæã®ããããŒã«ã«ã§èµ·åãããã³ãŒãã«ãã£ãŠïŒãã€ã³ã¿ãŒããããããªã¢ãŒãã§å¶åŸ¡ããããšãå°é£ã«ãªããŸãã
- ããã³ããšã³ãã¯ãã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®ãã¡ã€ã¢ãŠã©ãŒã«ïŒWebã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ãªã©ïŒãŸãã¯äŸµå
¥é²æ¢ã·ã¹ãã ïŒIPSãSnortãªã©ïŒã®ãã¹ãã«é©ããŠããŸãã
ãªãã·ã§ã³ã®çæïŒ- DFWã®ããã³ããšã³ããšããã¯ãšã³ãã®éã§éä¿¡ããããã«ãDMZããå
éšãããã¯ãŒã¯ãžã®æ¥ç¶ãéå§ã§ããã«ãŒã«ãäœæãããŸããããã«ãããDMZã®ä»ã®ããŒãã«ãããã®ã«ãŒã«ã®äœ¿çšã«é¢é£ããè
åšãäœæãããŸãïŒããšãã°ãIPã¹ããŒãã£ã³ã°ãARPæ»æãå®è£
ããããšã«ããïŒäžæ¯ãªã©ïŒ
- ãã¹ãŠã®ãµãŒãã¹ãããã³ããšã³ããšããã¯ãšã³ãã«åå²ã§ããããã§ã¯ãããŸããã
- äŒç€Ÿã¯ããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãæŽæ°ããããã®ããžãã¹ããã»ã¹ãå®è£
ããå¿
èŠããããŸãã
- äŒç€Ÿã¯ãDMZå
ã®ãµãŒããŒã«ã¢ã¯ã»ã¹ããéåè
ã«ããæ»æã«å¯Ÿããä¿è·ã¡ã«ããºã ãå®è£
ããå¿
èŠããããŸãã
泚é- å®éã«ã¯ããµãŒããŒãããã³ããšã³ããšããã¯ãšã³ãã«åå²ããªããŠããDMZããã®ãµãŒããŒã¯å
éšãããã¯ãŒã¯ã«ãããµãŒããŒã«ã¢ã¯ã»ã¹ããå¿
èŠãããããšãéåžžã«å€ãããããã®ãªãã·ã§ã³ã®äžèšã®æ¬ ç¹ã¯åã®ãªãã·ã§ã³ã«ãåœãŠã¯ãŸããŸãã
- ãµãŒããŒãããã³ããšã³ããšããã¯ãšã³ãã®æ©èœã®åé¢ããµããŒãããŠããªãå Žåã§ããWebã€ã³ã¿ãŒãã§ãŒã¹ãä»ããŠå®è¡ããã¢ããªã±ãŒã·ã§ã³ã®ä¿è·ãæ€èšããå Žåãããã³ããšã³ããšããŠhttpãªããŒã¹ãããã·ãµãŒããŒïŒnginxãªã©ïŒã䜿çšãããšãæ»æã«äŒŽããªã¹ã¯ãæå°éã«æããããšãã§ããŸããµãŒãã¹æåŠã ããšãã°ãSYNãã©ãããªã©ã®æ»æã«ãããHTTPãªããŒã¹ãããã·ã«ã¢ã¯ã»ã¹ã§ããªããªããŸãããããã¯ãšã³ãã¯åŒãç¶ãæ©èœããŸãã
å®ç掻ã®é¡æšãã®ãªãã·ã§ã³ã¯ãåŽåè
ã®çµç¹ã«æ¬è³ªçã«äŒŒãŠããŸãããã®çµç¹ã§ã¯ãã¢ã·ã¹ã¿ã³ã-ç§æžãè² è·ã®é«ãåŸæ¥å¡ã«äœ¿çšãããŸãã ãã®å Žåãããã¯ãšã³ãã¯å¿ããåŸæ¥å¡ã®é¡äŒŒç©ã«ãªããããã³ããšã³ãã¯ç§æžã®é¡äŒŒç©ã«ãªããŸãã
©mln.kzãªãã·ã§ã³4.ä¿è·ãããDMZ
DMZã¯ãã€ã³ã¿ãŒãããããã¢ã¯ã»ã¹å¯èœãªãããã¯ãŒã¯ã®äžéšã§ããããã®çµæãããŒãã䟵害ããããªã¹ã¯ãæ倧ã«ãªããŸãã DMZã®èšèšãšããã«äœ¿çšãããã¢ãããŒãã¯ã䟵å
¥è
ãDMZå
ã®ããŒãã®1ã€ã«å¯Ÿããå¶åŸ¡ãç²åŸãããšãã®æ¡ä»¶ã§æ倧ã®çåæ§ã確ä¿ããå¿
èŠããããŸãã èããããæ»æãšããŠãããã©ã«ãèšå®ã§åäœããã»ãšãã©ãã¹ãŠã®æ
å ±ã·ã¹ãã ã«åœ±é¿ãäžããæ»æãæ€èšããŠãã ããã
- ã«ã ããŒãã«ã®ãªãŒããŒãããŒ
- ARPãã€ãºãã³ã°
- äžæ£ãªDHCPãµãŒããŒ
- DHCPã®æ¯æž
- VLANãããã³ã°
- MACãã©ãã
- UDPãã©ãã
- TCP SYNãã©ãã
- TCPã»ãã·ã§ã³ãã€ãžã£ãã¯
- TCPãªã»ãã
- Webã¢ããªã±ãŒã·ã§ã³ãžã®æ»æ
- æ£åœãªãŠãŒã¶ãŒã«ä»£ãã£ãŠèªèšŒããŒã«ãšæ¿èªããã€ãã¹ããæ»æïŒãã¹ã¯ãŒãã®æšæž¬ãPSKãªã©ïŒ
- ãããã¯ãŒã¯ãµãŒãã¹ã®è匱æ§ã«å¯Ÿããæ»æãããšãã°ïŒ
ãããã®æ»æã®å€§éšåïŒå°ãªããšã1ã10ïŒã¯ããããã¯ãŒã¯ãã±ããå
ã®MACããã³IPã¢ãã¬ã¹ãåœé ãã䟵å
¥è
ã®èœåãå«ããææ°ã®ã€ãŒãµããã/ IPãããã¯ãŒã¯ã®ã¢ãŒããã¯ãã£ã®è匱æ§ã«åºã¥ããŠããŸãã ãããã®è匱æ§ã®æªçšã¯ãæã«ã¯å¥ã®çš®é¡ã®æ»æã«åé¢ãããŸãã
- MACã¹ããŒãã£ã³ã° ;
- IPã¹ããŒãã£ã³ã° ã
ãããã£ãŠãIPããã³MACã¹ããŒãã£ã³ã°ããä¿è·ããæ¹æ³ãæ€èšããããšã«ãããDMZä¿è·ã·ã¹ãã ã®æ§ç¯ãéå§ããŸãã
ã泚æãããã®æ»æã«å¯Ÿãã次ã®ä¿è·æ¹æ³ã¯ãå¯äžå¯èœãªæ¹æ³ã§ã¯ãããŸããã ä»ã®æ¹æ³ããããŸãã
MACã¹ããŒãã£ã³ã°ä¿è·
æŠç¥çã«ãMACã¢ãã¬ã¹ã¹ããŒãã£ã³ã°ã«é¢é£ããæ»æã¯æ¬¡ã®ããã«èª¬æã§ããŸãã
ãã®æ»æã¯ãã¹ã€ããããŒãã§MACã¢ãã¬ã¹ããã£ã«ã¿ãªã³ã°ããããšã§ç¡å¹åã§ããŸãã ããšãã°ãããŒã3ã®ãã©ãã£ãã¯ã¯ãéä¿¡å
ã¢ãã¬ã¹ãŸãã¯å®å
ã¢ãã¬ã¹ã«MACã¢ãã¬ã¹DEïŒADïŒBEïŒAFïŒDEïŒADãŸãã¯ãããŒããã£ã¹ãã¢ãã¬ã¹ïŒå Žåã«ãã£ãŠïŒãå«ãŸããŠããå Žåã«ã®ã¿ééããå¿
èŠããããŸãã
IPã¹ããŒãã£ã³ã°ä¿è·
IPã¹ããŒãã£ã³ã°æ»æã¹ããŒã ã¯ã䟵å
¥è
ãMACã§ã¯ãªãIPã¢ãã¬ã¹ãåœé ããããšãé€ããŠãåã®ã¹ããŒã ãšäŒŒãŠããŸãã IPã¹ããŒãã£ã³ã°ä¿è·ãå®è£
ããã«ã¯ãDMZ IPãããã¯ãŒã¯ãããå°ããªIPãµããããã«åå²ããå
ã«æ€èšããMACãã£ã«ã¿ãªã³ã°ãšåæ§ã«ãã«ãŒã¿ãŒã€ã³ã¿ãŒãã§ã€ã¹äžã®ãã©ãã£ãã¯ãããã«ãã£ã«ã¿ãªã³ã°ããŸãã 以äžã¯ããã®ååãå®è£
ããDMZèšèšã®äŸã§ãã
DMZã«ã¯3ã€ã®ããŒãããããŸãã
- ã¿ãŒããã«ãµãŒããŒïŒ192.168.100.2ïŒ
- ã¡ãŒã«ãµãŒããŒïŒ192.168.100.5ïŒ
- ãšã¯ã¹ãã©ããããµãŒããŒïŒ192.168.100.9ïŒ
IPãããã¯ãŒã¯192.168.100.0/24ãDMZã«å²ãåœãŠããã3ã€ã®IPãµããããããã®ãããã¯ãŒã¯ã«å²ãåœãŠãããŸãïŒãµãŒããŒã®æ°ã«å¿ããŠïŒã
ãµãããã1-ã¿ãŒããã«ãµãŒããŒã®192.168.100.0/30ïŒ192.168.100.2ïŒ
ãµãããã2-ã¡ãŒã«ãµãŒããŒã®192.168.100.4/30ïŒ192.168.100.5ïŒ
ãµãããã3-ã¡ãŒã«ãµãŒããŒçšã®192.168.100.8/30ïŒ192.168.100.9ïŒ
å®éã«ã¯ããã®ãããªãµãããããžã®ãããã¯ãŒã¯åé¢ã¯ãVLANãã¯ãããžãŒã䜿çšããŠå®è£
ãããŸãã ãã ãããã®é©çšã«ã¯ãªã¹ã¯ããããããããä¿è·ãæ€èšããŸãã
VLANãããã³ã°ä¿è·
ãã®æ»æããä¿è·ãããã
ã« ãã¹ã€ããã¯èªåçã«ããŒãã¿ã€ãïŒ
trunk / access ïŒãããŽã·ãšãŒãããæ©èœãç¡å¹ã«ãã管çè
ãæåã§ã¿ã€ããå²ãåœãŠãŸãã ããã«ãçµç¹çãªå¯Ÿçã«ããããããã
ãã€ãã£ãVLANã®äœ¿çšãçŠæ¢ãããŠã
ãŸã ã
DHCPæ»æã«å¯Ÿããä¿è·
DHCPã¯ã¯ãŒã¯ã¹ããŒã·ã§ã³ã®IPã¢ãã¬ã¹ã®æ§æãèªååããããã«èšèšãããŠãããšããäºå®ã«ãããããããäžéšã®äŒæ¥ã§ã¯ãµãŒããŒã®IPã¢ãã¬ã¹ãDHCPãä»ããŠçºè¡ãããå ŽåããããŸãããããã¯ããªãæªãç¿æ
£ã§ãã ãããã£ãŠã
äžæ£ãªDHCPãµãŒã㌠ã
DHCPã®æ¯æžããä¿è·ããã«ã¯ãDMZã§DHCPãå®å
šã«æåŠããããšããå§ãããŸãã
MACãã©ããæ»æä¿è·
MACãã©ããããä¿è·ããããã«ããããŒããã£ã¹ããã©ãã£ãã¯ã®æ倧匷床ãå¶éããããã«ã¹ã€ããããŒãã§æ§æãããŸãïŒãããŒããã£ã¹ãæ»æã¯éåžžãããã®æ»æäžã«çæãããããïŒã ç¹å®ã®ïŒãŠããã£ã¹ãïŒãããã¯ãŒã¯ã¢ãã¬ã¹ã®äœ¿çšã䌎ãæ»æã¯ãåã«æ€èšããMACãã£ã«ã¿ãªã³ã°ã«ãã£ãŠãããã¯ãããŸãã
UDPãã©ããä¿è·
ãã®ã¿ã€ãã®æ»æã«å¯Ÿããä¿è·ã¯ããã£ã«ã¿ãªã³ã°ãIPïŒL3ïŒã¬ãã«ã§å®è¡ãããããšãé€ããŠãMACãã©ããããã®ä¿è·ã«äŒŒãŠããŸãã
TCP SYNãã©ããæ»æä¿è·
ãã®æ»æããä¿è·ããããã«ã次ã®ãªãã·ã§ã³ãå¯èœã§ãã
- TCP SYN Cookieãã¯ãããžãŒã䜿çšãããã¹ãä¿è·ã
- TCP SYNèŠæ±ãå«ããã©ãã£ãã¯ã®åŒ·åºŠãå¶éããããšã«ããããã¡ã€ã¢ãŠã©ãŒã«ã¬ãã«ã§ã®ä¿è·ïŒDMZããµããããã«åå²ãããŠãããšä»®å®ïŒã
ãããã¯ãŒã¯ãµãŒãã¹ããã³Webã¢ããªã±ãŒã·ã§ã³ãžã®æ»æã«å¯Ÿããä¿è·
ãã®åé¡ã«å¯Ÿããæ®éçãªè§£æ±ºçã¯ãããŸãããã確ç«ããããã©ã¯ãã£ã¹ã¯ããœãããŠã§ã¢ã®è匱æ§ç®¡çããã»ã¹ïŒããšãã°ã
ãã®ãããªãããã®èå¥ãã€ã³ã¹ããŒã«ãªã©ïŒãå®è£
ãã䟵å
¥æ€ç¥ããã³é²æ¢ã·ã¹ãã ïŒIDS / IPSïŒã䜿çšããããšã§ãã
èªèšŒãã€ãã¹æ»æä¿è·
åã®ã±ãŒã¹ã«é¢ããŠã¯ããã®åé¡ã«å¯Ÿããæ®éçãªè§£æ±ºçã¯ãããŸããã
éåžžãå€æ°ã®å€±æããèªèšŒè©Šè¡ã®å ŽåãèªèšŒããŒã¿ã®éžæïŒãã¹ã¯ãŒããªã©ïŒãåé¿ããããã«ã¢ã«ãŠã³ãããããã¯ãããŸãã ãããããã®ãããªã¢ãããŒãã¯éåžžã«è°è«ã®äœå°ãããããã®çç±ã¯æ¬¡ã®ãšããã§ãã
ãŸãã䟵å
¥è
ã¯ã¢ã«ãŠã³ãã®ãããã¯ã«ã€ãªãããªã匷床ã®èªèšŒæ
å ±ãéžæã§ããŸãïŒãã¹ã¯ãŒããæ°ã¶æééžæãããè©Šè¡ééãæ°ååã«ãªãå ŽåããããŸãïŒã
第äºã«ããã®æ©èœã¯ãµãŒãã¹æåŠæ»æã«äœ¿çšã§ããŸãããã®æ»æã§ã¯ã䟵å
¥è
ãã¢ã«ãŠã³ãããããã¯ããããã«å€æ°ã®èš±å¯è©Šè¡ãæ
æã«å®è¡ããŸãã
ãã®ã¯ã©ã¹ã®æ»æã®æãå¹æçãªãªãã·ã§ã³ã¯ãIDS / IPSã·ã¹ãã ã®äœ¿çšã§ããããã¯ããã¹ã¯ãŒãã解èªããããšãããšãã¢ã«ãŠã³ãã§ã¯ãªãããã®éžæãçºçãããœãŒã¹ããããã¯ããŸãïŒããšãã°ã䟵å
¥è
ã®IPã¢ãã¬ã¹ããããã¯ããŸãïŒã
ãã®ãªãã·ã§ã³ã®ä¿è·å¯Ÿçã®æçµãªã¹ãïŒ
- DMZã¯ãåããŒãã®åå¥ã®ãµããããã«åºã¥ããŠIPãµããããã«åå²ãããŸãã
- IPã¢ãã¬ã¹ã¯ã管çè
ãæåã§å²ãåœãŠãŸãã DHCPã¯äœ¿çšãããŸããã
- DMZããŒããæ¥ç¶ãããŠãããããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã§ã¯ãMACããã³IPãã£ã«ã¿ãªã³ã°ãã¢ã¯ãã£ãã«ãªãããããŒããã£ã¹ããã©ãã£ãã¯ããã³TCP SYNèŠæ±ãå«ããã©ãã£ãã¯ã®åŒ·åºŠãå¶éãããŸãã
- ã¹ã€ããã§ã¯ãèªåããŒãã¿ã€ãããŽã·ãšãŒã·ã§ã³ãç¡å¹ã«ãªã£ãŠããããã€ãã£ãVLANã¯çŠæ¢ãããŠããŸãã
- DMZããŒãããã³ãããã®ããŒããæ¥ç¶ãããŠããå
éšãããã¯ãŒã¯ãµãŒããŒã§ãTCP SYN Cookieãæ§æãããŸãã
- DMZããŒãïŒããã³ã§ããã°ãããã¯ãŒã¯ã®æ®ãã®éšåïŒã«å¯ŸããŠããœãããŠã§ã¢è匱æ§ç®¡çãå®è£
ãããŸãã
- IDS / IPS䟵å
¥æ€ç¥ããã³é²æ¢ã·ã¹ãã ãDMZã»ã°ã¡ã³ãã«å°å
¥ãããŠããŸãã
ãªãã·ã§ã³ã®ãã©ã¹ïŒ- é«ãã»ãã¥ãªãã£ã
ãªãã·ã§ã³ã®çæïŒ- æ©åšã®æ©èœã«å¯ŸããèŠä»¶ã®å¢å ã
- å®è£
ãšãµããŒãã®äººä»¶è²»ã
å®ç掻ã®é¡æšä»¥åã«ãœãã¡ãšãªãããã³ãåããã¯ã©ã€ã¢ã³ããšãªã¢ãšDMZãæ¯èŒããå Žåãä¿è·ãããDMZã¯è£
ç²ãã£ãã·ã¥ãã¹ã¯ã®ããã«ãªããŸãã
©valmax.com.uaãªãã·ã§ã³5.ããã¯ã³ãã¯ã
åã®ããŒãžã§ã³ã§èª¬æããã»ãã¥ãªãã£å¯Ÿçã¯ããããã¯ãŒã¯å
ã«ããããå®è£
ã§ããããã€ã¹ïŒã¹ã€ãã/ã«ãŒã¿ãŒ/ãã¡ã€ã¢ãŠã©ãŒã«ïŒããã£ããšããäºå®ã«åºã¥ããŠããŸããã ããããå®éã«ã¯ãããšãã°ãä»®æ³ã€ã³ãã©ã¹ãã©ã¯ãã£ã䜿çšããå ŽåïŒä»®æ³ã¹ã€ããã®æ©èœã¯éåžžã«éãããŠããããšãå€ãïŒããã®ãããªããã€ã¹ã¯ååšããªãå ŽåããããŸãã
ãããã®æ¡ä»¶äžã§ã¯ã以åã«èæ
®ãããæ»æã®å€ãã䟵å
¥è
ã«å©çšå¯èœã«ãªããŸãããæãå±éºãªãã®ã¯æ¬¡ã®ãšããã§ãã
- ãã©ãã£ãã¯ãååããã³å€æŽã§ããæ»æïŒARPãã€ãºãã³ã°ãCAMããŒãã«ãªãŒããŒãããŒ+ TCPã»ãã·ã§ã³ãã€ãžã£ãã¯ãªã©ïŒ;
- DMZããã®æ¥ç¶ãéå§ã§ããå
éšãããã¯ãŒã¯ãµãŒããŒã®è匱æ§ã®æªçšã«é¢é£ããæ»æïŒIPããã³MACã¹ããŒãã£ã³ã°ã«ããDFWãã£ã«ã¿ãªã³ã°ã«ãŒã«ãåé¿ããããšã«ããå¯èœïŒã
ãããŸã§æ€èšããããšã®ãªã次ã®éèŠãªæ©èœã¯ãããããããã»ã©éèŠã§ã¯ãªããªãããšã¯ãããŸãããããŠãŒã¶ãŒã®èªåã¯ãŒã¯ã¹ããŒã·ã§ã³ïŒAWPïŒã¯ããµãŒããŒãžã®æ害ãªåœ±é¿ã®ãœãŒã¹ïŒããšãã°ããŠã€ã«ã¹ãããã€ã®æšéŠ¬ã«ææããå ŽåïŒã«ããªãåŸãããšã§ãã
ãããã£ãŠãDMZãšå
éšãããã¯ãŒã¯ã®äž¡æ¹ããã®äŸµå
¥è
æ»æããå
éšãããã¯ãŒã¯ãµãŒããŒãä¿è·ãããšãã課é¡ã«çŽé¢ããŠããŸãïŒããã€ã®æšéŠ¬ææã¯ãå
éšãããã¯ãŒã¯ããã®äŸµå
¥è
ã®ã¢ã¯ã·ã§ã³ãšããŠè§£éãããå¯èœæ§ããããŸãïŒã
以äžã«ææ¡ããã¢ãããŒãã¯ã䟵å
¥è
ããµãŒããŒãæ»æã§ãããã£ãã«ã®æ°ãæžããããšãç®çãšããŠããããã®ãããªãã£ãã«ãå°ãªããšã2ã€ãããŸãã 1ã€ç®ã¯ãDMZããå
éšãããã¯ãŒã¯ãµãŒããŒãžã®ã¢ã¯ã»ã¹ãèš±å¯ãã
DFWã®ã«ãŒã«ã§ãïŒIPã¢ãã¬ã¹ã®å¶éã¯ãããŸããïŒã2ã€ç®ã¯ãæ¥ç¶èŠæ±ãäºæ³ããããµãŒããŒã§éããŠãããããã¯ãŒã¯ããŒãã§ãã
å
éšãããã¯ãŒã¯ãµãŒããŒãDMZèªäœã§ãµãŒããŒãžã®æ¥ç¶ãæ§ç¯ããæå·åãããå®å
šãªãããã¯ãŒã¯ãããã³ã«ã䜿çšããŠãããè¡ãå Žåããããã®ãã£ãã«ãéããããšãã§ããŸãã ãã®åŸããªãŒãã³ããŒãã
DFWã®ã«ãŒã«ããªããªããŸãã
ãããåé¡ã¯ãéåžžã®ãµãŒããŒãµãŒãã¹ããã®æ¹æ³ã§åäœããæ¹æ³ãç¥ããªãããšã§ããããã®ã¢ãããŒããå®è£
ããã«ã¯ãããšãã°SSHãŸãã¯VPNã䜿çšããŠå®è£
ããããããã¯ãŒã¯ãã³ããªã³ã°ã䜿çšããDMZå
ã®ãµãŒããŒãããã³ãã«å
ã®å
éšãããã¯ãŒã¯äžã®ãµãŒããŒãžã®ãã³ãã«ãæ¢ã«èš±å¯ããå¿
èŠããããŸãã
ãã®ãªãã·ã§ã³ã®äžè¬çãªã¹ããŒã ã¯æ¬¡ã®ãšããã§ãã
- SSH / VPNãµãŒããŒã¯DMZå
ã®ãµãŒããŒã«ã€ã³ã¹ããŒã«ãããSSH / VPNã¯ã©ã€ã¢ã³ãã¯å
éšãããã¯ãŒã¯äžã®ãµãŒããŒã«ã€ã³ã¹ããŒã«ãããŸãã
- å
éšãããã¯ãŒã¯ãµãŒããŒã¯ãDMZå
ã®ãµãŒããŒãžã®ãããã¯ãŒã¯ãã³ãã«ã®æ§ç¯ãéå§ããŸãã ãã³ãã«ã¯ãã¯ã©ã€ã¢ã³ããšãµãŒããŒã®çžäºèªèšŒã§æ§ç¯ãããŸãã
- æ§ç¯ããããã³ãã«ã®ãã¬ãŒã ã¯ãŒã¯å
ã®DMZããã®ãµãŒããŒã¯ãå
éšãããã¯ãŒã¯å
ã®ãµãŒããŒãžã®æ¥ç¶ãéå§ãããããéããŠä¿è·ãããããŒã¿ãéä¿¡ãããŸãã
- å
éšãã¡ã€ã¢ãŠã©ãŒã«ã§ããŒã«ã«ãã¡ã€ã¢ãŠã©ãŒã«ãæ§æããããã³ãã«ãééãããã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ãããŸãã
ãã®ãªãã·ã§ã³ãå®éã«äœ¿çšãããšã
OpenVPNã䜿çšããŠãããã¯ãŒã¯ãã³ãã«ãæ§ç¯ããã®ã䟿å©ã§ããããšã瀺ãããŸãããããã¯ã次ã®éèŠãªããããã£ãããããã§ãã
- ã¯ãã¹ãã©ãããã©ãŒã ã ç°ãªããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ãµãŒããŒã§éä¿¡ãæŽçã§ããŸãã
- ã¯ã©ã€ã¢ã³ããšãµãŒããŒã®çžäºèªèšŒã䜿çšããŠãã³ãã«ãæ§ç¯ããæ©èœã
- 蚌æãããæå·ã䜿çšããæ©èœã
äžèŠãããšããã®ã¹ããŒã ã¯äžå¿
èŠã«è€éã§ãå
éšãããã¯ãŒã¯ãµãŒããŒã«ããŒã«ã«ãã¡ã€ã¢ãŠã©ãŒã«ãã€ã³ã¹ããŒã«ããå¿
èŠããããããéåžžã©ããDMZãããµãŒããŒãå
éšãããã¯ãŒã¯ãµãŒããŒã«æ¥ç¶ããæ¹ãç°¡åã§ãããæå·åãããæ¥ç¶ã å®éããã®ãªãã·ã§ã³ã¯å€ãã®åé¡ã解決ããŸãããäž»ãªãã®ãæäŸããããšã¯ã§ããŸãã-IPããã³MACã¹ããŒãã£ã³ã°ã䜿çšããŠãã¡ã€ã¢ãŠã©ãŒã«ããã€ãã¹ããããšã«ãã£ãŠè¡ãããå
éšãããã¯ãŒã¯ãµãŒããŒã®è匱æ§ã«å¯Ÿããæ»æã«å¯Ÿããä¿è·ã
ãªãã·ã§ã³ã®ãã©ã¹ïŒ- å
éšãããã¯ãŒã¯ã®ä¿è·ããããµãŒããŒã«å¯Ÿããæ»æãã¯ãã«ã®æ°ã®ã¢ãŒããã¯ãã£äžã®åæžã
- ãããã¯ãŒã¯ãã©ãã£ãã¯ã®ãã£ã«ã¿ãªã³ã°ããªãå Žåã®ã»ãã¥ãªãã£ã®ç¢ºä¿ã
- ãããã¯ãŒã¯çµç±ã§éä¿¡ãããããŒã¿ãäžæ£ãªé²èŠ§ãæ¹ããããä¿è·ããŸãã
- ãµãŒãã¹ã®ã»ãã¥ãªãã£ã¬ãã«ãéžæçã«é«ããæ©èœã
- äºéåè·¯ä¿è·ã·ã¹ãã ãå®è£
ããå¯èœæ§ãæåã®åè·¯ã¯ãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããŠæäŸããã2çªç®ã®åè·¯ã¯ãã®ãªãã·ã§ã³ã«åºã¥ããŠç·šæãããŸãã
ãªãã·ã§ã³ã®çæïŒ- ãã®ä¿è·ãªãã·ã§ã³ã®å®è£
ãšä¿å®ã«ã¯ãè¿œå ã®äººä»¶è²»ãå¿
èŠã§ãã
- 䟵å
¥ã®æ€åºããã³é²æ¢ã®ãããã¯ãŒã¯ã·ã¹ãã ãšã®éäºææ§ïŒIDS / IPSïŒã
- ãµãŒããŒã®è¿œå ã®ã³ã³ãã¥ãŒãã£ã³ã°è² è·ã
å®ç掻ã®é¡æšãã®ãªãã·ã§ã³ã®äž»ãªç¹ã¯ãåèšè
ãä¿¡é Œã§ããªããšã®é¢ä¿ã確ç«ããããšã§ããããã¯ãããŒã³ãçºè¡ãããšãã«ãéè¡èªèº«ãããŒã¿ãæ€èšŒããããã«æœåšçãªåãæã«ã³ãŒã«ããã¯ããç¶æ³ã«äŒŒãŠããŸãã
©comfoson.890m.comãããã«
ããã§ãã€ã³ã¿ãŒãããããäŒæ¥ãããã¯ãŒã¯ãµãŒãã¹ãžã®ã¢ã¯ã»ã¹ãæŽçããããã«å®£èšããã5ã€ã®ãªãã·ã§ã³ãã¹ãŠãæ€èšããŸããã æçµçã«ã¯ãä¿è·ããå¿
èŠãããæ
å ±ãšäŒæ¥ãä¿è·ããããã«æã£ãŠãããªãœãŒã¹ã«äŸåããŠãããããã©ã¡ããåªããŠããããæªãããèšãã®ã¯å°é£ã§ãã ãªãœãŒã¹ãç¥èããªãå Žåãæåã®ãªãã·ã§ã³ãæé©ã§ãã æ
å ±ãéåžžã«äŸ¡å€ãããå Žåã4çªç®ãš5çªç®ã®ãªãã·ã§ã³ãçµã¿åãããããšã«ãããä»ã«é¡ãèŠãªãã¬ãã«ã®ã»ãã¥ãªãã£ãæäŸãããŸãã