±à¼ÍƼö: |
ÖØµãÁÄÁÄÁíÒ»ÖÖ³£¼ûµÄDNS¹¥»÷DNS reply flood¡£Ê×ÏÈDNS reply
floodÊÇʲô£¬½Ó׎²½âDNS·´Éä¹¥»÷¡£
±¾ÎÄÀ´×ÔÓÚ»ªÎªÆóÒµ»¥¶¯ÉçÇø£¬ÓÉ»ðÁú¹ûÈí¼þAnna±à¼¡¢ÍƼö¡£
|
|
0x01 DNS Reply Flood
DNSÐÒéµÄ»ù´¡ÖªÊ¶ÎÒÃDZ¾Æª¾Í²»Öظ´½éÉÜÁË£¬´ó¼Ò¿ÉÒÔ¿´ÉÏһƪµÄ½éÉÜ¡£½ñÌìÎÒÃÇÖ±½Ó´ÓDNS reply
floodµÄ¹¥»÷ÔÀíÈëÊÖ¡£Ç°ÃæÎÒÃÇÒ²½²¹ý£¬DNS²éѯ¹ý³Ìͨ³£¶¼ÊÇ»ùÓÚUDPÐÒéµÄ£¬UDPÐÒéÊÇÎÞÁ¬½Ó״̬µÄ¡£ËùÒÔÕâÒ»ÈõµãºÜÈÝÒ×±»ºÚ¿ÍËùÀûÓã¬DNS·þÎñÆ÷ÊÕµ½DNS
reply±¨ÎÄʱ£¬²»¹Ü×Ô¼ºÓÐûÓз¢³öÈ¥¹ý½âÎöÇëÇ󣬶¼»á¶ÔÕâЩDNS reply±¨ÎĽøÐд¦Àí¡£DNS
reply flood¾ÍÊǺڿͷ¢ËÍ´óÁ¿µÄDNS reply±¨Îĵ½DNS»º´æ·þÎñÆ÷£¬µ¼Ö»º´æ·þÎñÆ÷ÒòΪ´¦ÀíÕâЩDNS
reply±¨ÎĶø×ÊÔ´ºÄ¾¡£¬Ó°ÏìÕý³£ÒµÎñ¡£

DNS reply flood´ó¶à¶¼ÊÇÐé¼ÙÔ´¹¥»÷£¬ºÚ¿Í¿ØÖƽ©Ê¬Ö÷»ú·¢³öµÄDNS reply±¨ÎĵÄÔ´IPµØÖ·Í¨³£¶¼ÊÇαÔìµÄ£¬ÊDz»´æÔڵġ£ËùÒÔÔÚ·ÀÓùµÄʱºò£¬¾Í¿ÉÒÔ´Ó»ØÓ¦Ô´IPµØÖ·µÄÕæ¼ÙÐÔÈëÊÖ£¬Åж¨Õâ¸öÔ´IPÊÇ·ñÊÇÕæÊµÔ´¡£
Õë¶ÔÕâÖÖ¹¥»÷ÐÐΪ£¬Anti-DDoSϵͳһ°ã¿ÉʹÓÃÔ´ÈÏÖ¤·½Ê½½øÐзÀÓù¡£Ô´ÈÏÖ¤µÄ·½·¨¾ÍÊǹ¹ÔìÒ»¸öDNS
request±¨ÎÄ£¬¿´¿Í»§¶ËÊÇ·ñÄÜÕý³£»ØÓ¦¡£

1¡¢Anti-DDoSϵͳ²¿ÊðÔÚ·À»¤Ä¿±êǰ£¬²¢¶Ôµ½´ï·À»¤Ä¿±êµÄDNS reply±¨ÎĽøÐÐͳ¼Æ¡£µ±µ½´ï·À»¤Ä¿±êµÄDNS
reply±¨Îij¬¹ý¸æ¾¯ãÐֵʱ£¬Anti-DDoSϵͳÆô¶¯·ÀÓù¡£
2¡¢Anti-DDoSϵͳÊÕµ½Ä³¸öÔ´IPµØÖ··¢À´µÄDNS reply±¨Îĺ󣬻áÖØÐ¹¹ÔìÒ»¸öеÄDNS
request±¨ÎÄ£¬È»ºó¼Ç¼¹¹Ôì²éѯ±¨ÎĵÄQuery IDºÍÔ´¶Ë¿ÚºÅ¡£
3¡¢Èç¹ûÊÇÐé¼ÙÔ´£¬Ôò²»»á¶ÔÕâ¸öDNS request±¨ÎĽøÐлØÓ¦£¬ÈÏÖ¤²»Í¨¹ý¡£
4¡¢Èç¹ûÊÇÕæÊµDNSÊÚȨ·þÎñÆ÷£¬Ôò»áÖØÐ»ØÓ¦DNS reply±¨ÎÄ¡£
5¡¢Anti-DDoSϵͳÊÕµ½DNS reply±¨Îĺ󣬻áÓë֮ǰ¼Ç¼µÄQuery IDºÍÔ´¶Ë¿ÚºÅ½øÐÐÆ¥Åä¡£Èç¹ûÍêȫһÖ£¬ÔòÅж¨´ËDNS
reply±¨ÎľÍÊÇ·´µ¯DNS request±¨ÎĵĻØÓ¦£¬Ô´ÈÏÖ¤³É¹¦£¬¼ÓÈë°×Ãûµ¥¡£
6¡¢ºóÐøÕâ¸öÔ´ÔÙ·¢Ë͵ÄDNS reply±¨ÎÄ£¬Ö±½Óͨ¹ý£¬Ö±µ½°×Ãûµ¥ÀÏ»¯¡£
½ü¼¸Ä꣬»¹ÓÐÒ»ÖÖÉý¼¶°æµÄDNS reply flood¹¥»÷£¬ÒòΪɱÉËÁ¦¾Þ´ó£¬¶ø±¸Êܰ²È«½çµÄ¹Ø×¢£¬ÄǾÍÊÇDNS·´Éä¹¥»÷¡£
0x02 DNS·´Éä¹¥»÷
DNS·´Éä¹¥»÷ÊÇDNS reply floodµÄÒ»ÖÖ±äÒ죬ÊÇÒ»ÖÖ¸ü¸ß¼¶µÄDNS reply flood¡£
DNS·þÎñÆ÷ÊÇ»¥ÁªÍø×î»ù´¡µÄÉèʩ֮һ£¬ÍøÂçÖÐÓкܶ࿪·ÅµÄÃâ·ÑDNS·þÎñÆ÷¡£DNS·´Éä¹¥»÷ÕýÊÇÀûÓÃÕâЩ¿ª·ÅµÄDNS·þÎñÆ÷ÖÆÔìµÄ¹¥»÷¡£ÕâÖÖDNS·´Éä¹¥»÷ͨ³£±ÈÆÕͨµÄDNS
reply flood¹¥»÷ÐÔ¸üÇ¿£¬×·×ÙËÝÔ´À§ÄÑ£¬¸üÉÆÓÚαװ¡£

´ÓͼÖÐÎÒÃÇ¿ÉÒÔ¿´µ½£¬ºÚ¿Í½«×Ô¼ºµÄÔ´IPµØÖ·Î±Ôì³É±»¹¥»÷Ä¿±êµÄIPµØÖ·£¬È»ºóÏòһϵÁÐÍøÂçÖпª·ÅµÄDNS·þÎñÆ÷·¢ËÍ´óÁ¿µÄ²éѯÇëÇó¡£Í¨¹ýαÔìDNSÇëÇó±¨ÎĵÄÔ´IPµØÖ·£¬¿ØÖÆDNS»ØÓ¦±¨ÎĵÄÁ÷Ïò£¬ÕâЩDNS»ØÓ¦±¨Îľͻᶼ±»Òýµ¼µ½±»¹¥»÷Ä¿±ê£¬µ¼Ö±»¹¥»÷Ä¿±êµÄÍøÂçÓµÈû£¬¾Ü¾ø·þÎñ¡£¶ø¿ª·ÅʽµÄDNS·þÎñÆ÷ÔÚÈ«ÇòÓг¬¹ý¼¸Ç§Íǫ̀£¬ÕâЩ·þÎñÆ÷½ÓÈë´ø¿íÍùÍù¶¼±È½Ï¸ß£¬¶øÇÒ£¬DNS
reply±¨ÎÄ´óСͨ³£Ò²ÊÇDNS request±¨Îĵ¶ÉõÖÁ¼¸Ê®±¶£¬»¹¿É´ïµ½·Å´ó¹¥»÷µÄЧ¹û¡£¶ÔÓÚ¿ØÖƳÉǧÉÏÍǫ̀½©Ê¬Ö÷»úµÄºÚ¿ÍÀ´Ëµ£¬ÖÆÔ켸GÄËÖÁÊýÊ®GµÄDNS¹¥»÷Á÷Á¿²¢²»Ì«À§ÄÑ¡£
DNS·´Éä¹¥»÷ºÍÇ°Ãæ½éÉܵĴ«Í³DNS reply floodÓÐÁ½µã±¾ÖʵIJ»Í¬£º
1¡¢´«Í³DNS reply floodÒ»°ã¹¥»÷Ä¿±êÊÇDNS»º´æ·þÎñÆ÷£»¶øDNS·´Éä¹¥»÷Ò»°ã¹¥»÷Ä¿±êÊǿͻ§¶Ë¡£
2¡¢´«Í³DNS reply flood´ó¶àÊÇÐé¼ÙÔ´¹¥»÷£¬¶øDNS·´Éä¹¥»÷ÖУ¬DNSÇëÇóÊÇÕæÊµµÄ£¬ËùÒÔDNS»ØÓ¦±¨ÎÄÒ²¶¼ÊÇÕæÊµµÄ£¬ÊÇÓÉÍøÂçÖÐÕæÊµµÄDNS·þÎñÆ÷·¢³öµÄ£¬ÊôÓÚÕæÊµÔ´¹¥»÷¡£ÕâÖÖÇé¿öÏ£¬ÔÙʹÓÃÇ°Ãæ¸Õ½²¹ýµÄÔ´ÈÏÖ¤·½Ê½£¬¶ÔÓÚDNS·´Éä¹¥»÷¾Í²»ÊÊÓÃÁË¡£
ÄÇÊDz»ÊǾÍûÓа취·ÀÓùÁËÄØ£¿
µ±È»²»ÊÇ£¬Ä§¸ßÒ»³ß£¬µÀ¸ßÒ»ÕÉ¡£ÎÒÃÇ¿´¿´Anti-DDoSϵͳÊÇÔõô´¦ÀíÕâÖÖ¹¥»÷µÄ¡£
Anti-DDoSϵͳ½è¼ø·À»ðǽµÄ»á»°±í»úÖÆ£¬ÀûÓÃDNS½»»¥½»»¥¹ý³ÌÖУ¬DNS request±¨ÎÄÊ×°ü½¨»á»°µÄ»úÖÆ£¬·ÀÓùDNS·´Éä·Å´ó¹¥»÷¡£

Anti-DDoSϵͳ¶ÔDNS·´Éä¹¥»÷²ÉÓõķÀÓùÊֶξÍÊǻỰ¼ì²é¡£»á»°±íÎåÔª×éÐÅÏ¢°üº¬£ºÔ´IPµØÖ·¡¢Ä¿µÄIPµØÖ·¡¢Ô´¶Ë¿Ú¡¢Ä¿µÄ¶Ë¿ÚºÍÐÒé¡£µ±DNS
request±¨Îľ¹ýAnti-DDoSϵͳʱ£¬Anti-DDoSϵͳ»á´´½¨Ò»ÕŻỰ±í£¬¼Ç¼DNSÇëÇó±¨ÎĵÄÕâÎåÔª×éÐÅÏ¢¡£µ±Anti-DDoSϵͳÔÙÊÕµ½DNS
reply±¨ÎÄʱ£¬¾Í»á²é»á»°±í£º
Èç¹ûÆ¥Åä»á»°±í£¬¾ÍÅж¨ÊÇÕæÊµµÄDNS reply±¨ÎÄ£¬ÔÊÐíͨ¹ý¡£
Èç¹ûûÓÐÆ¥Åä»á»°±í£¬ÔòÅж¨Õâ¸öDNS reply±¨ÎÄΪ¹¥»÷±¨ÎÄ£¬½ûֹͨ¹ý¡£
³ýÁËÔ´ÈÏÖ¤ºÍ»á»°¼ì²éÒÔÍ⣬¶ÔÓÚDNS flood¹¥»÷»¹¿ÉÒÔͨ¹ýÏÞËٵķ½Ê½½øÐзÀÓù¡£DNSÏÞËÙÓÐÁ½ÖÖ£¬Õë¶ÔDNS
requestºÍDNS reply±¨ÎͼÉúЧ¡£
ÓòÃûÏÞËÙ
Èç¹ûij¸öÓòÃûµÄDNSÇëÇó»ò»ØÓ¦±¨ÎÄËÙÂʹý¸ß£¬¿ÉÒÔÕë¶ÔÕâ¸öÓòÃû½øÐÐÏÞËÙ¡£Í¨³£Ä³¸öÓòÃûÔÚ¹¥»÷ǰ·ÃÎÊÁ¿²¢²»Ëã¸ß£¬Í»È»ÓÐÒ»Ìì·ÃÎÊÁ¿ÊÇÆ½Ê±µÄºÃ¶à±¶£¬ÄÇÕâ¸öÓòÃû¿ÉÄܾÍÊÇÊܹ¥»÷ÁË¡£Õâ¾ÍºÃ±È³¬ÊÐÂô¶«Î÷£¬Æ½Ê±Ò»Ì쳬ÊпÉÄÜÂô200°üʳÑΣ¬Í»È»ÓÐÒ»Ì죬À´Á˺öàÈËÂòÑΣ¬³¬ÊвֿⶼÂô¿ÕÁË£¬ÄÇÕâ¾Í²»Õý³£ÁË¡£ÓòÃûÏÞËÙ¾ÍÊÇÖ¸×ÊÔ´ÓÐÏÞµÄÇé¿öÏ£¬Ã¿Ìì¾Í¶¨Á¿ÌṩÕâô¶àµÄ×ÊÔ´£¬
Ïȵ½Ïȵá£ÓòÃûÏÞËÙ¿ÉÒÔÓÐÕë¶ÔÐԵĶÔij¸öÌØ¶¨ÓòÃû½øÐÐÏÞÖÆ£¬¶ø²»Ó°ÏìÆäËûÓòÃûµÄÕý³£ÇëÇó¡£

Ô´IPµØÖ·ÏÞËÙ
Ô´IPµØÖ·ÏÞËÙºÍÓòÃûÏÞËÙÏà±È£¬ÊôÓÚÁíÒ»¸öά¶ÈµÄÏÞÖÆ¡£Èç¹ûij¸öÔ´IPµØÖ·ÓòÃû½âÎöµÄËÙÂʹý´ó£¬¾Í¿ÉÒÔÓÐÕë¶ÔÐԵĶÔÕâ¸öÔ´IPµØÖ·½øÐÐÏÞÖÆ£¬ÕâÑùÒ²²»»á¶ÔÆäËûÔ´ÓÐÓ°Ïì¡£
ÏÖÔÚ£¬ÕâÖÖÀûÓÃÍøÂç»ù´¡¼Ü¹¹·¢¶¯µÄ¹¥»÷Ô½À´Ô½¶à£¬±ÈÈç֮ǰµÄ±©·çÓ°Òô¡¢±¾½ÚµÄDNS·´Éä¹¥»÷£¬»¹ÓкóÐøÎÒÃǼ´½«Òª½éÉܵÄDNS»º´æÍ¶¶¾¹¥»÷¡¢HTTP¹¥»÷¡£×÷Ϊ»¥ÁªÍøµÄ»ù´¡ÉèÊ©£¬DNS·þÎñÆ÷ºÍÆäËû¸÷ÖÖ·þÎñÆ÷µÄ°²È«Îȶ¨ÔËÐÐÒ²ÖÁ¹ØÖØÒª£¬Ò²ÊÇÍøÂ繤³ÌʦÔÚ²¿ÊðÍøÂçÉ豸ʱÐèÒªÖØµã¿¼ÂǵÄÎÊÌâ¡£
ͨ¹ýÕâÁ½ÆªÌû×Ó£¬´ó¼Ò¶ÔDNS request floodºÍDNS reply flood¹¥»÷µÄ·ÀÓù¶¼ÓÐÁËȫеÄÁ˽â°É£¬µ«ÊÇDNS¹¥»÷¿É²»Ö¹ÕâЩ£¬³ýÁËÕâЩ´«Í³¹¥»÷ÊÖ¶ÎÍ⣬ºÚ¿ÍÀûÓô۸ÄÓòÃûºÍIPµØÖ·Ó³Éä¹ØÏµµÄÊÖ¶ÎÖÆÔìµÄ¹¥»÷£¬ÔÚ½ü¼¸ÄêÆµÆµ·¢Éú¡£ÏÂÒ»½Ú£¬ÎÒÃǾÍΪ´ó¼Ò¼ÌÐø½éÉÜDNS»º´æÍ¶¶¾¹¥»÷¡£
|