Ȩ > DDoS´ëÀÀ¼¾ÅÍ > ¼ºñ½º¾È³»


Distribute Denial of Service attackÀÇ ¾àÀÚ·Î ¿ì¸®¸»·Î´Â 'ºÐ»ê ¼ºñ½º °ÅºÎ°ø°Ý'À̶ó°í ÇÕ´Ï´Ù.
´Ù¼öÀÇ PC¸¦ ÀÌ¿ëÇØ ƯÁ¤ ½Ã½ºÅÛÀ¸·Î ´ë·®ÀÇ À¯ÇØ Æ®·¡ÇÈÀ» Àü¼ÛÇÔÀ¸·Î½á ½Ã½ºÅÛ »ó¿¡ °úºÎÇϸ¦ ¹ß»ý½ÃÄÑ ÇØ´ç ½Ã½ºÅÛÀÇ Á¤»óÀûÀÎ ¼ºñ½º¸¦ ¹æÇØÇÏ´Â »çÀ̹ö °ø°ÝÀÔ´Ï´Ù.
À̸¦ À§ÇØ ÇØÄ¿´Â ´Ù¾çÇÑ ¹æ¹ýÀ¸·Î ÀϹݻç¿ëÀÚ PC¿¡ º¿À» °¨¿°½Ã۰í, º¿¿¡ °¨¿°µÈ PC¿¡ °ø°Ý¸í·ÉÀ» ÇÏ´ÞÇÏ¿© DDoS°ø°ÝÀ» ¼öÇàÇÏ°Ô µË´Ï´Ù.
[DDoS °ø°ÝÀÇ ±¸¼º¿ä¼Ò]
1. °ø°ÝÀÚ (Attacker) : °ø°ÝÀ» ÁÖµµÇÏ´Â ÇØÄ¿ÀÇ ÄÄÇ»ÅÍ
2. ¸¶½ºÅÍ (Master) : °ø°ÝÀÚ¿¡°Ô Á÷Á¢ ¸í·ÉÀ» ¹Þ´Â ½Ã½ºÅÛÀ¸·Î ¿©·¯ ´ëÀÇ ¿¡ÀÌÀüÆ®(Agent)¸¦ °ü¸®ÇÏ´Â ½Ã½ºÅÛ
3. ¿¡ÀÌÀüÆ® (Agent) : °ø°Ý´ë»ó(Target)¿¡ Á÷Á¢ÀûÀÎ °ø°ÝÀ» °¡ÇÏ´Â ½Ã½ºÅÛ
IDC¸¦ ±â¹ÝÀ¸·ÎÇÑ DDoSÀü¿ë Àåºñ¿Í ´ë¿ë·®ÀÇ ¹éº»À» ÅëÇØ DDoS°ø°Ý¿¡ ´ëÇØ ¿Ïº®ÇÑ ¹æ¾î
´ë¿ªÆø °ø°Ý Æ®·¡ÇÈ 5G, TCP, HTTP·¹º§ °ø°Ý 1G¸¦ ¹æ¾îÇÒ¼ö ÀÖµµ·Ï ¼³°èµÇ¾î ÀÖ½À´Ï´Ù.
ÃÖ°í°¡ÀÇ DDoS º¸¾È Àåºñ¸¦ ±¸¸Å ¶Ç´Â ÀÓ´ëÇÒ Çʿ䰡 ¾ø½À´Ï´Ù.
¿Â¶óÀÎ °áÁ¦ ½Ã½ºÅÛÀÌ ÀÌ·ç¾îÁö´Â ÀÎÅÍ³Ý ¼îÇθô »çÀÌÆ®
½Ç½Ã°£ ȸ¿ø Á¢¼Ó·® ¹× µ¥ÀÌÅÍ Àü¼ÛÀÌ ¸¹Àº µ¿¿µ»ó »çÀÌÆ®
¹æ´ëÇÑ ÄÁÅÙÃ÷¿Í ¸¹Àº ȸ¿øÀ» º¸À¯ÇÑ Æ÷ÅлçÀÌÆ®
°³ÀÎ ºí·Î°Å ¹× ºñÁî´Ï½º »çÀÌÆ®
Ãʱ⠰ø°Ý´ë»óÀº °ÔÀÓ, äÆÃ, ¼ºÀλçÀÌÆ® µîÀÇ ¼¹ö¿´À¸³ª ÃÖ±Ù¿¡´Â ÀÏ¹Ý À¥»çÀÌÆ®¿¡µµ ¹«ºÐº°ÇÏ°Ô °ø°ÝÇϰí ÀÖÀ¸¸ç °ø°ÝÀ» ¹«±â·Î ±ÝǰÀ» ¿ä±¸ÇÏ´Â »ç·Ê°¡ ºó¹øÇÏ°Ô ¹ß»ýÇϰí ÀÖ½À´Ï´Ù.
1. ÃÖ»óÀ§ IDC¹éº»¿¡¼ UDP, ICMP µîÀÇ bandwidth DDoS °ø°Ý¿¡ ´ëÇØ 1Â÷ Â÷´Ü
(Â÷´Ü Á¾·ù : UDP, ICMPÂ÷´Ü)
2. 5G ¹Ì¸¸ÀÇ Æ®·¡Çȸ¸ Korea IDC 10G HP ¶ó¿ìÅÍ¿¡ À¯ÀÔ À¯ÇØ Æ®·¡ÇÈ 2Â÷ Â÷´Ü
(Â÷´Ü Á¾·ù : UDP, ICMP, TCP, IGMP µîÀÇ ¸ðµç ÇÁ·ÎÅäÄÝ Â÷´Ü)
3. 1G ¹Ì¸¸ÀÇ Æ®·¡Çȸ¸ Korea IDC ¹æÈº®¿¡ À¯ÀԵǾî, Á¤»óÀûÀÎ Æ®·¡Çȸ¸ °í°´¼¹ö·Î Àü´Þ
(TCP ¼¼ºÎ°í°ÝÂ÷´Ü : floodign attack, cc attack µîÀÇ ¸ðµç tcp dos °ø°Ý·ùÂ÷´Ü)
|
- ¼ºñ½º ÀÌ¿ë½Ã IP°¡ º¯°æµÉ ¼öµµ ÀÖ½À´Ï´Ù.
- ¹«·á·Î Á¦°øµÇ´Â ¼ºñ½ºÀ̱⠶§¹®¿¡ Korea IDC ¹æÈº®¿¡¼ ¹æ¾îÇÏÁö ¸øÇÒ Á¤µµÀÇ °ø°ÝÀÌ ¹ß»ýµÇ¾î ¹æ¾îÇÏÁö ¸øÇÒ °æ¿ì
³Î ¶ó¿ìÆÃ ó¸® µÇ¾î ¼ºñ½ºÀÌ¿ëÀÌ ¾ÈµÉ ¼öµµ ÀÖ½À´Ï´Ù.
- µµ¹Ú, ¼ºÀλçÀÌÆ® µî ºÒ¹ýÀûÀÎ »çÀÌÆ®´Â ¼ºñ½º¸¦ Áö¿øÇÏÁö ¾Ê½À´Ï´Ù.
|
| ±¸ºÐ |
°ø°Ý |
Ư¡ | Áõ»ó |
| ³×Æ®¿öÅ© ·¹º§ |
º¯Á¶µÈ UDP Flooding °ø°Ý |
º¯Á¶ ¶Ç´Â ½ÇÁ¦IP¸¦ ÀÌ¿ëÇÏ¿© ´Ù·®ÀÇ UDP
ÆÐŶÀ» Àü¼ÛÇÏ¿© °ø°Ý |
´ë¿ªÆø °í°¥ |
| ICMP/IGMP Flooding °ø°Ý |
ICMP spoofed unreachable
Flood(smack/bloop/puke attack)
1000~1500byte Á¤µµÀÇ Å« ÆÐŶÀ» °ø°Ý ´ë»ó
¼¹ö(³×Æ®¿öÅ©)·Î Àü¼Û |
´ë¿ªÆø °í°¥ |
| Sumrf °ø°Ý |
ICMP broadcast"echo-reply"flood |
´ë¿ªÆø °í°¥ |
| Fraggle °ø°Ý |
´ë·®ÀÇ UDP/ICMP echo trafficÀ» ¹ß»ý½ÃÄÑ
¼¹öºÎÇÏ, UDP spoofed broadcast echo |
¼¹ö ºÎÇÏ |
| ¼ºñ½º ·¹º§ |
DNS º¯Á¶ |
UDP 53, DNS reflector attacks |
DNS ¼ºñ½º Àå¾Ö |
| SIP ¸Þ½ÃÁö °ø°Ý |
UDP 500 |
ÀÎÅÍ³Ý ÀüÈ Àå¾Ö |
RTP/RTCP Flood
During call |
VOIP ¼ºñ½º Àå¾Ö |
VOIP ¼ºñ½º Àå¾Ö |
| SMTP flood |
´ë·®ÀÇ ¸ÞÀÏÀ» ¹ß¼Û |
¸ÞÀÏ ¼ºñ½º Àå¾Ö |
| TCP ·¹º§ |
TCP Connection
Flooding |
½ÇÁ¦ IP¸¦ ÀÌ¿ëÇÏ¿© ´Ù·®ÀÇ TCP synÆÐŶÀ»
Àü¼ÛÇÏ´Â °ø°Ý |
¼¹ö ºÎÇÏ |
SYN/ACK/SYN-ACK/FIN
Flooding °ø°Ý |
¼¹ö·Î Áö¼ÓÀûÀÎ SYNÆÐŶ Àü¼ÛÇÏ¿© ¼¹öÀÇ
Ä¿³Ø¼Ç »óŸ¦ Half-connection »óÅ·Π¸¸µë |
¼¹öÀÇ ¸Þ¸ð¸® ´©¼ö
(½Ã½ºÅÛÀÇ ÇÊ¿äÇÏÁö
¾ÊÀº
¸Þ¸ð¸®´Â Á¡À¯Çϰí
µ¹·ÁÁÖÁö ¾Ê´Â »óÅÂ) |
| TCP Open Flooding °ø°Ý |
¿ÀÁ÷ TCP 3-way handshake¸¦ ÀÌ¿ëÇÏ¿© ¸ñÇ¥
½Ã½ºÅÛÀÇ TCP Connection ÇѰèÄ¡µµ´Þ |
Apache Ä¿³Ø¼Ç¼ö 600°³
ÀÌ»ó ¹ß»ý |
TCP Out-of-State
Packet Flooding |
º¯Á¶ ¶Ç´Â ½ÇÁ¦ IP¸¦ ÀÌ¿ë ´Ù·®ÀÇ ÆÐŶ
(ACK,SYN+ACK,FIN)¸¦ Àü¼ÛÇÏ´Â °ø°Ý |
¼¹ö ºÎÇÏ |
| HTTP ·¹º§ |
HTTP Get Flooding |
Çâ»óµÈ DDOS °ø°ÝÀ¸·Î °ø°Ý¸ñÇ¥·Î ÁöÁ¤µÈ
»çÀÌÆ®¿¡ ´Ù¼öÀÇ Á»ºñ È£½ºÆ®¸¦ ÀÌ¿ëÇØ TCP ConnectionÀ» ¿¬°áÈÄ µ¿½Ã ´Ù¹ßÀû GET Request¸¦ º¸³¿
¼¹ö¿¡ À̹ÌÁö ÆÄÀÏÀ» 1G·Î GETÀ» º¸³»¸é
¼¹ö ºÎÇϾøÀ¸³ª DBÄ¿³Ø¼Ç DB°úºÎÇÏ ¹ß»ý |
À¥ ¼ºñ½º Àå¾Ö |
| Page Refresh Flooding |
»õ·Î°íħ °ø°ÝÀ¸·Î TCP connection open°ú
Get requestÀÇ ¹«Çѹݺ¹À¸·Î ¼¹ö ½Ã½ºÅÛÀÇ
ÀÚ¿ø °í°¥
ÀϹÝÀûÀ¸·Î 10°³/ÃÊ´ç
µµ±¸ »ç¿ë½Ã 1000°³/ÃÊ´ç °ø°Ý°¡´É |
À¥ ¼ºñ½º Àå¾Ö |
| Cc °ø°Ý |
Cache control ¸í·ÉÀ» Á»ºñ PC°¡ ¼öÇà HTTP
user-agent Çì´õ¿¡ cache-control°ªÀ» Ãß°¡
Àü¼Û À¥¼¹öÀÇ Response Çì´õ¸¦ Ãß°¡ÇÏ´Â
ºñÁ¤»óÀûÀÎ Á¢¼Ó½Ãµµ Æ®·¡ÇÈ 50MB ÀÌÇÏ·Î
À¥¼¹ö ¹× DB¼¹ö ´Ù¿î Á»ºñ PC 100°³ ÀϹÝ
À¯Àú 30,000~50,000ÀÇ Á¢¼Ó¼ö |
À¥ ¼ºñ½º Àå¾Ö |
| http error 404 |
Á¸ÀçÇÏÁö ¾Ê´Â À¥ÆäÀÌÁö¿¡ ´ëÇÑ ¹Ýº¹ÀûÀÎ
¿äû °ø°Ý |
À¥ ¼ºñ½º Àå¾Ö |
|