Äú¿ÉÒÔ¾èÖú£¬Ö§³ÖÎÒÃǵĹ«ÒæÊÂÒµ¡£

1Ôª 10Ôª 50Ôª





ÈÏÖ¤Â룺  ÑéÖ¤Âë,¿´²»Çå³þ?Çëµã»÷Ë¢ÐÂÑéÖ¤Âë ±ØÌî



  ÇóÖª ÎÄÕ ÎÄ¿â Lib ÊÓÆµ iPerson ¿Î³Ì ÈÏÖ¤ ×Éѯ ¹¤¾ß ½²×ù Model Center   Code  
»áÔ±   
   
 
     
   
 ¶©ÔÄ
  ¾èÖú
»ª°²½âÃÜÖ®DDoS¹¥·À-03 DNSÔ­ÀíÆª DNS Reply Flood
 
×÷Õߣº»ª°²
  4142  次浏览      28
2020-8-27 
 
±à¼­ÍƼö:
ÖØµãÁÄÁÄÁíÒ»ÖÖ³£¼ûµÄDNS¹¥»÷DNS reply flood¡£Ê×ÏÈDNS reply floodÊÇʲô£¬½Ó׎²½âDNS·´Éä¹¥»÷¡£

±¾ÎÄÀ´×ÔÓÚ»ªÎªÆóÒµ»¥¶¯ÉçÇø£¬ÓÉ»ðÁú¹ûÈí¼þAnna±à¼­¡¢ÍƼö¡£

0x01 DNS Reply Flood

DNSЭÒéµÄ»ù´¡ÖªÊ¶ÎÒÃDZ¾Æª¾Í²»Öظ´½éÉÜÁË£¬´ó¼Ò¿ÉÒÔ¿´ÉÏһƪµÄ½éÉÜ¡£½ñÌìÎÒÃÇÖ±½Ó´ÓDNS reply floodµÄ¹¥»÷Ô­ÀíÈëÊÖ¡£Ç°ÃæÎÒÃÇÒ²½²¹ý£¬DNS²éѯ¹ý³Ìͨ³£¶¼ÊÇ»ùÓÚUDPЭÒéµÄ£¬UDPЭÒéÊÇÎÞÁ¬½Ó״̬µÄ¡£ËùÒÔÕâÒ»ÈõµãºÜÈÝÒ×±»ºÚ¿ÍËùÀûÓã¬DNS·þÎñÆ÷ÊÕµ½DNS reply±¨ÎÄʱ£¬²»¹Ü×Ô¼ºÓÐûÓз¢³öÈ¥¹ý½âÎöÇëÇ󣬶¼»á¶ÔÕâЩDNS reply±¨ÎĽøÐд¦Àí¡£DNS reply flood¾ÍÊǺڿͷ¢ËÍ´óÁ¿µÄDNS reply±¨Îĵ½DNS»º´æ·þÎñÆ÷£¬µ¼Ö»º´æ·þÎñÆ÷ÒòΪ´¦ÀíÕâЩDNS reply±¨ÎĶø×ÊÔ´ºÄ¾¡£¬Ó°ÏìÕý³£ÒµÎñ¡£

DNS reply flood´ó¶à¶¼ÊÇÐé¼ÙÔ´¹¥»÷£¬ºÚ¿Í¿ØÖƽ©Ê¬Ö÷»ú·¢³öµÄDNS reply±¨ÎĵÄÔ´IPµØÖ·Í¨³£¶¼ÊÇαÔìµÄ£¬ÊDz»´æÔڵġ£ËùÒÔÔÚ·ÀÓùµÄʱºò£¬¾Í¿ÉÒÔ´Ó»ØÓ¦Ô´IPµØÖ·µÄÕæ¼ÙÐÔÈëÊÖ£¬Åж¨Õâ¸öÔ´IPÊÇ·ñÊÇÕæÊµÔ´¡£

Õë¶ÔÕâÖÖ¹¥»÷ÐÐΪ£¬Anti-DDoSϵͳһ°ã¿ÉʹÓÃÔ´ÈÏÖ¤·½Ê½½øÐзÀÓù¡£Ô´ÈÏÖ¤µÄ·½·¨¾ÍÊǹ¹ÔìÒ»¸öDNS request±¨ÎÄ£¬¿´¿Í»§¶ËÊÇ·ñÄÜÕý³£»ØÓ¦¡£

1¡¢Anti-DDoSϵͳ²¿ÊðÔÚ·À»¤Ä¿±êǰ£¬²¢¶Ôµ½´ï·À»¤Ä¿±êµÄDNS reply±¨ÎĽøÐÐͳ¼Æ¡£µ±µ½´ï·À»¤Ä¿±êµÄDNS reply±¨Îij¬¹ý¸æ¾¯ãÐֵʱ£¬Anti-DDoSϵͳÆô¶¯·ÀÓù¡£

2¡¢Anti-DDoSϵͳÊÕµ½Ä³¸öÔ´IPµØÖ··¢À´µÄDNS reply±¨Îĺ󣬻áÖØÐ¹¹ÔìÒ»¸öеÄDNS request±¨ÎÄ£¬È»ºó¼Ç¼¹¹Ôì²éѯ±¨ÎĵÄQuery IDºÍÔ´¶Ë¿ÚºÅ¡£

3¡¢Èç¹ûÊÇÐé¼ÙÔ´£¬Ôò²»»á¶ÔÕâ¸öDNS request±¨ÎĽøÐлØÓ¦£¬ÈÏÖ¤²»Í¨¹ý¡£

4¡¢Èç¹ûÊÇÕæÊµDNSÊÚȨ·þÎñÆ÷£¬Ôò»áÖØÐ»ØÓ¦DNS reply±¨ÎÄ¡£

5¡¢Anti-DDoSϵͳÊÕµ½DNS reply±¨Îĺ󣬻áÓë֮ǰ¼Ç¼µÄQuery IDºÍÔ´¶Ë¿ÚºÅ½øÐÐÆ¥Åä¡£Èç¹ûÍêȫһÖ£¬ÔòÅж¨´ËDNS reply±¨ÎľÍÊÇ·´µ¯DNS request±¨ÎĵĻØÓ¦£¬Ô´ÈÏÖ¤³É¹¦£¬¼ÓÈë°×Ãûµ¥¡£

6¡¢ºóÐøÕâ¸öÔ´ÔÙ·¢Ë͵ÄDNS reply±¨ÎÄ£¬Ö±½Óͨ¹ý£¬Ö±µ½°×Ãûµ¥ÀÏ»¯¡£

½ü¼¸Ä꣬»¹ÓÐÒ»ÖÖÉý¼¶°æµÄDNS reply flood¹¥»÷£¬ÒòΪɱÉËÁ¦¾Þ´ó£¬¶ø±¸Êܰ²È«½çµÄ¹Ø×¢£¬ÄǾÍÊÇDNS·´Éä¹¥»÷¡£

0x02 DNS·´Éä¹¥»÷

DNS·´Éä¹¥»÷ÊÇDNS reply floodµÄÒ»ÖÖ±äÒ죬ÊÇÒ»ÖÖ¸ü¸ß¼¶µÄDNS reply flood¡£

DNS·þÎñÆ÷ÊÇ»¥ÁªÍø×î»ù´¡µÄÉèʩ֮һ£¬ÍøÂçÖÐÓкܶ࿪·ÅµÄÃâ·ÑDNS·þÎñÆ÷¡£DNS·´Éä¹¥»÷ÕýÊÇÀûÓÃÕâЩ¿ª·ÅµÄDNS·þÎñÆ÷ÖÆÔìµÄ¹¥»÷¡£ÕâÖÖDNS·´Éä¹¥»÷ͨ³£±ÈÆÕͨµÄDNS reply flood¹¥»÷ÐÔ¸üÇ¿£¬×·×ÙËÝÔ´À§ÄÑ£¬¸üÉÆÓÚαװ¡£

´ÓͼÖÐÎÒÃÇ¿ÉÒÔ¿´µ½£¬ºÚ¿Í½«×Ô¼ºµÄÔ´IPµØÖ·Î±Ôì³É±»¹¥»÷Ä¿±êµÄIPµØÖ·£¬È»ºóÏòһϵÁÐÍøÂçÖпª·ÅµÄDNS·þÎñÆ÷·¢ËÍ´óÁ¿µÄ²éѯÇëÇó¡£Í¨¹ýαÔìDNSÇëÇó±¨ÎĵÄÔ´IPµØÖ·£¬¿ØÖÆDNS»ØÓ¦±¨ÎĵÄÁ÷Ïò£¬ÕâЩDNS»ØÓ¦±¨Îľͻᶼ±»Òýµ¼µ½±»¹¥»÷Ä¿±ê£¬µ¼Ö±»¹¥»÷Ä¿±êµÄÍøÂçÓµÈû£¬¾Ü¾ø·þÎñ¡£¶ø¿ª·ÅʽµÄDNS·þÎñÆ÷ÔÚÈ«ÇòÓг¬¹ý¼¸Ç§Íǫ̀£¬ÕâЩ·þÎñÆ÷½ÓÈë´ø¿íÍùÍù¶¼±È½Ï¸ß£¬¶øÇÒ£¬DNS reply±¨ÎÄ´óСͨ³£Ò²ÊÇDNS request±¨Îĵ¶ÉõÖÁ¼¸Ê®±¶£¬»¹¿É´ïµ½·Å´ó¹¥»÷µÄЧ¹û¡£¶ÔÓÚ¿ØÖƳÉǧÉÏÍǫ̀½©Ê¬Ö÷»úµÄºÚ¿ÍÀ´Ëµ£¬ÖÆÔ켸GÄËÖÁÊýÊ®GµÄDNS¹¥»÷Á÷Á¿²¢²»Ì«À§ÄÑ¡£

DNS·´Éä¹¥»÷ºÍÇ°Ãæ½éÉܵĴ«Í³DNS reply floodÓÐÁ½µã±¾ÖʵIJ»Í¬£º

1¡¢´«Í³DNS reply floodÒ»°ã¹¥»÷Ä¿±êÊÇDNS»º´æ·þÎñÆ÷£»¶øDNS·´Éä¹¥»÷Ò»°ã¹¥»÷Ä¿±êÊǿͻ§¶Ë¡£

2¡¢´«Í³DNS reply flood´ó¶àÊÇÐé¼ÙÔ´¹¥»÷£¬¶øDNS·´Éä¹¥»÷ÖУ¬DNSÇëÇóÊÇÕæÊµµÄ£¬ËùÒÔDNS»ØÓ¦±¨ÎÄÒ²¶¼ÊÇÕæÊµµÄ£¬ÊÇÓÉÍøÂçÖÐÕæÊµµÄDNS·þÎñÆ÷·¢³öµÄ£¬ÊôÓÚÕæÊµÔ´¹¥»÷¡£ÕâÖÖÇé¿öÏ£¬ÔÙʹÓÃÇ°Ãæ¸Õ½²¹ýµÄÔ´ÈÏÖ¤·½Ê½£¬¶ÔÓÚDNS·´Éä¹¥»÷¾Í²»ÊÊÓÃÁË¡£

ÄÇÊDz»ÊǾÍûÓа취·ÀÓùÁËÄØ£¿

µ±È»²»ÊÇ£¬Ä§¸ßÒ»³ß£¬µÀ¸ßÒ»ÕÉ¡£ÎÒÃÇ¿´¿´Anti-DDoSϵͳÊÇÔõô´¦ÀíÕâÖÖ¹¥»÷µÄ¡£

Anti-DDoSϵͳ½è¼ø·À»ðǽµÄ»á»°±í»úÖÆ£¬ÀûÓÃDNS½»»¥½»»¥¹ý³ÌÖУ¬DNS request±¨ÎÄÊ×°ü½¨»á»°µÄ»úÖÆ£¬·ÀÓùDNS·´Éä·Å´ó¹¥»÷¡£

Anti-DDoSϵͳ¶ÔDNS·´Éä¹¥»÷²ÉÓõķÀÓùÊֶξÍÊǻỰ¼ì²é¡£»á»°±íÎåÔª×éÐÅÏ¢°üº¬£ºÔ´IPµØÖ·¡¢Ä¿µÄIPµØÖ·¡¢Ô´¶Ë¿Ú¡¢Ä¿µÄ¶Ë¿ÚºÍЭÒé¡£µ±DNS request±¨Îľ­¹ýAnti-DDoSϵͳʱ£¬Anti-DDoSϵͳ»á´´½¨Ò»ÕŻỰ±í£¬¼Ç¼DNSÇëÇó±¨ÎĵÄÕâÎåÔª×éÐÅÏ¢¡£µ±Anti-DDoSϵͳÔÙÊÕµ½DNS reply±¨ÎÄʱ£¬¾Í»á²é»á»°±í£º

Èç¹ûÆ¥Åä»á»°±í£¬¾ÍÅж¨ÊÇÕæÊµµÄDNS reply±¨ÎÄ£¬ÔÊÐíͨ¹ý¡£

Èç¹ûûÓÐÆ¥Åä»á»°±í£¬ÔòÅж¨Õâ¸öDNS reply±¨ÎÄΪ¹¥»÷±¨ÎÄ£¬½ûֹͨ¹ý¡£

³ýÁËÔ´ÈÏÖ¤ºÍ»á»°¼ì²éÒÔÍ⣬¶ÔÓÚDNS flood¹¥»÷»¹¿ÉÒÔͨ¹ýÏÞËٵķ½Ê½½øÐзÀÓù¡£DNSÏÞËÙÓÐÁ½ÖÖ£¬Õë¶ÔDNS requestºÍDNS reply±¨ÎͼÉúЧ¡£

ÓòÃûÏÞËÙ

Èç¹ûij¸öÓòÃûµÄDNSÇëÇó»ò»ØÓ¦±¨ÎÄËÙÂʹý¸ß£¬¿ÉÒÔÕë¶ÔÕâ¸öÓòÃû½øÐÐÏÞËÙ¡£Í¨³£Ä³¸öÓòÃûÔÚ¹¥»÷ǰ·ÃÎÊÁ¿²¢²»Ëã¸ß£¬Í»È»ÓÐÒ»Ìì·ÃÎÊÁ¿ÊÇÆ½Ê±µÄºÃ¶à±¶£¬ÄÇÕâ¸öÓòÃû¿ÉÄܾÍÊÇÊܹ¥»÷ÁË¡£Õâ¾ÍºÃ±È³¬ÊÐÂô¶«Î÷£¬Æ½Ê±Ò»Ì쳬ÊпÉÄÜÂô200°üʳÑΣ¬Í»È»ÓÐÒ»Ì죬À´Á˺öàÈËÂòÑΣ¬³¬ÊвֿⶼÂô¿ÕÁË£¬ÄÇÕâ¾Í²»Õý³£ÁË¡£ÓòÃûÏÞËÙ¾ÍÊÇÖ¸×ÊÔ´ÓÐÏÞµÄÇé¿öÏ£¬Ã¿Ìì¾Í¶¨Á¿ÌṩÕâô¶àµÄ×ÊÔ´£¬ Ïȵ½Ïȵá£ÓòÃûÏÞËÙ¿ÉÒÔÓÐÕë¶ÔÐԵĶÔij¸öÌØ¶¨ÓòÃû½øÐÐÏÞÖÆ£¬¶ø²»Ó°ÏìÆäËûÓòÃûµÄÕý³£ÇëÇó¡£

Ô´IPµØÖ·ÏÞËÙ

Ô´IPµØÖ·ÏÞËÙºÍÓòÃûÏÞËÙÏà±È£¬ÊôÓÚÁíÒ»¸öά¶ÈµÄÏÞÖÆ¡£Èç¹ûij¸öÔ´IPµØÖ·ÓòÃû½âÎöµÄËÙÂʹý´ó£¬¾Í¿ÉÒÔÓÐÕë¶ÔÐԵĶÔÕâ¸öÔ´IPµØÖ·½øÐÐÏÞÖÆ£¬ÕâÑùÒ²²»»á¶ÔÆäËûÔ´ÓÐÓ°Ïì¡£

ÏÖÔÚ£¬ÕâÖÖÀûÓÃÍøÂç»ù´¡¼Ü¹¹·¢¶¯µÄ¹¥»÷Ô½À´Ô½¶à£¬±ÈÈç֮ǰµÄ±©·çÓ°Òô¡¢±¾½ÚµÄDNS·´Éä¹¥»÷£¬»¹ÓкóÐøÎÒÃǼ´½«Òª½éÉܵÄDNS»º´æÍ¶¶¾¹¥»÷¡¢HTTP¹¥»÷¡£×÷Ϊ»¥ÁªÍøµÄ»ù´¡ÉèÊ©£¬DNS·þÎñÆ÷ºÍÆäËû¸÷ÖÖ·þÎñÆ÷µÄ°²È«Îȶ¨ÔËÐÐÒ²ÖÁ¹ØÖØÒª£¬Ò²ÊÇÍøÂ繤³ÌʦÔÚ²¿ÊðÍøÂçÉ豸ʱÐèÒªÖØµã¿¼ÂǵÄÎÊÌâ¡£

ͨ¹ýÕâÁ½ÆªÌû×Ó£¬´ó¼Ò¶ÔDNS request floodºÍDNS reply flood¹¥»÷µÄ·ÀÓù¶¼ÓÐÁËȫеÄÁ˽â°É£¬µ«ÊÇDNS¹¥»÷¿É²»Ö¹ÕâЩ£¬³ýÁËÕâЩ´«Í³¹¥»÷ÊÖ¶ÎÍ⣬ºÚ¿ÍÀûÓô۸ÄÓòÃûºÍIPµØÖ·Ó³Éä¹ØÏµµÄÊÖ¶ÎÖÆÔìµÄ¹¥»÷£¬ÔÚ½ü¼¸ÄêÆµÆµ·¢Éú¡£ÏÂÒ»½Ú£¬ÎÒÃǾÍΪ´ó¼Ò¼ÌÐø½éÉÜDNS»º´æÍ¶¶¾¹¥»÷¡£

   
4142 ´Îä¯ÀÀ       28
 
Ïà¹ØÎÄÕÂ

iOSÓ¦Óð²È«¿ª·¢£¬Äã²»ÖªµÀµÄÄÇЩÊÂÊõ
Web°²È«Ö®SQL×¢Èë¹¥»÷
ÒÆ¶¯APP°²È«ÔÚÉøÍ¸²âÊÔÖеÄÓ¦ÓÃ
´ÓGoogle±¸·Ý»¥ÁªÍø¿´¡°Êý¾Ý°²È«¡±
 
Ïà¹ØÎĵµ

web°²È«Éè¼ÆÓë·À»¤
»¥ÁªÍøº£Á¿ÄÚÈݰ²È«´¦Àí¼¼Êõ
ºÚ¿Í¹¥»÷Óë·À·¶¼¼Êõ
WEBºÚºÐ°²È«¼ì²â
 
Ïà¹Ø¿Î³Ì

WEBÍøÕ¾ÓëÓ¦Óð²È«Ô­ÀíÓëʵ¼ù
webÓ¦Óð²È«¼Ü¹¹Éè¼Æ
´´½¨°²È«µÄJ2EE WebÓ¦ÓôúÂë
ÐÅÏ¢°²È«ÎÊÌâÓë·À·¶
×îл¼Æ»®
DeepSeekÔÚÈí¼þ²âÊÔÓ¦ÓÃʵ¼ù 4-12[ÔÚÏß]
DeepSeek´óÄ£ÐÍÓ¦Óÿª·¢Êµ¼ù 4-19[ÔÚÏß]
UAF¼Ü¹¹ÌåϵÓëʵ¼ù 4-11[±±¾©]
AIÖÇÄÜ»¯Èí¼þ²âÊÔ·½·¨Óëʵ¼ù 5-23[ÉϺ£]
»ùÓÚ UML ºÍEA½øÐзÖÎöÉè¼Æ 4-26[±±¾©]
ÒµÎñ¼Ü¹¹Éè¼ÆÓ뽨ģ 4-18[±±¾©]
 
×îÐÂÎÄÕÂ
ÎïÁªÍø°²È«¸ÅÊö
Ê·ÉÏ×îÏêϸµÄÇø¿éÁ´¼¼Êõ¼Ü¹¹·ÖÎö
Ò»ÎĶÁ¶®Çø¿éÁ´ÕûÌå¼Ü¹¹¼°Ó¦Óð¸Àý
Çø¿éÁ´¼¼Êõ¼Ü¹¹
°²È«¼Ü¹¹ÆÀÉóʵս
×îпγÌ
WebÓ¦Óð²È«¼Ü¹¹¡¢ÈëÇÖ¼ì²âÓë·À»¤
ÎïÁªÍø¹Ø¼ü¼¼Êõ¡¢°²È«Óë±ßÔµ¼ÆËã
Çø¿éÁ´°²È«¼¼Êõʵ¼ùÖ¸ÄÏ
ÔÆ·þÎñÓ밲ȫ¼Ü¹¹
»¥ÁªÍø°²È«¿ª·¢·½·¨Óëʵ¼ù
³É¹¦°¸Àý
ÖйúÒøÐÐ ÐÅÏ¢°²È«¼¼Êõ¼°Éî¶È·ÀÓù
±±¾© WebÓ¦Óð²È«¼Ü¹¹¡¢ÈëÇÖ¼ì²âÓë·À»¤
ij²ÆË°ÁìÓòÖªÃûIT·þÎñÉÌ Web°²È«²âÊÔ
ÆÕÈð¿Ë˹ web°²È«Éè¼Æ¡¢²âÊÔÓëÓÅ»¯
±±¾©ºÍÀûʱ ÐÔÄܺͰ²È«ÐÔ²âÊÔ