ç®æ¬¡
å®çŸ©
DNSïŒDomain Name ServiceïŒã¹ããŒãã£ã³ã°ãšã¯ãDNSãµãŒããŒã®ãšã³ããªããã€ãºãã³ã°ããæšçãšãªããŠãŒã¶ãŒãæ»æè ã®ã³ã³ãããŒã«äžã«ããæªæã®ãããŠã§ããµã€ãã«ãªãã€ã¬ã¯ããããããšã§ããDNSæ»æã¯ãéåžžãå ¬è¡ç¡ç·LANïŒWi-FiïŒç°å¢ã§çºçããŸãããæ»æè ãARPïŒAddress Resolution ProtocolïŒããŒãã«ããã€ãºãã³ã°ããæšçãšãªããŠãŒã¶ãŒããã€ã¹ã«ãç¹å®ã®ãŠã§ããµã€ãã®ãµãŒããŒãšããŠæ»æè ãã³ã³ãããŒã«ãããã·ã³ã䜿çšãããããšãã§ããå Žåãã©ã®ãããªç¶æ³ã§ãçºçããå¯èœæ§ããããŸãããã®æ»æã¯ãå ¬è¡ç¡ç·LANãå©çšããé«åºŠãªãã£ãã·ã³ã°æ»æã®æåã®ã¹ãããã§ããããŠãŒã¶ãŒãéšããŠããã€ã¹ã«ãã«ãŠã§ã¢ãã€ã³ã¹ããŒã«ãããããæ©å¯æ å ±ãæŒããããããããããšãå¯èœã§ãã
ç¡æãã©ã€ã¢ã«
ç¡æãã©ã€ã¢ã«ã®ãç³ãèŸŒã¿æé
- åŒç€Ÿã®ãµã€ããŒã»ãã¥ãªã㣠ãšãã¹ããŒãã貎瀟ã«äŒºããã»ãã¥ãªãã£ç°å¢ãè©äŸ¡ããŠãè åšãªã¹ã¯ã蚺æããŸãã
- 24 æé以å ã«æå°éã®æ§æã§ã30 æ¥éãå©çšããã ãããã«ãŒããã€ã³ãã®ãœãªã¥ãŒã·ã§ã³ãå°å ¥ããŸãã
- ãã«ãŒããã€ã³ãã®ãã¯ãããžãŒãå®éã«ãäœéšããã ããŸãã
- çµç¹ãæã€ã»ãã¥ãªãã£ã®è匱æ§ã«é¢ããã¬ããŒãããæäŸããŸãããã®ã¬ããŒãã¯ããµã€ããŒã»ãã¥ãªãã£æ»æã®å¯Ÿå¿ã«çŽã¡ã«ã掻çšããã ãããšãã§ããŸãã
ãã©ãŒã ã«å¿ èŠäºé ããå ¥åã®äžããç³èŸŒã¿ãã ããã远ã£ãŠãæ åœè ãããé£çµ¡ãããŠããã ããŸãã
Proofpointã®æ åœè ããŸããªããé£çµ¡ããããŸãã
DNSã¹ããŒãã£ã³ã°ã®ä»çµã¿
ã»ãšãã©ã®æ»æè ã¯ãDNSã¹ããŒãã£ã³ã°ãå®è¡ããããã«ããããããçšæãããããŒã«ã䜿çšããŸããäžéšã®è åšã¢ã¯ã¿ãŒã¯ç¬èªã«ããŒã«ãäœæããŸããããã®çš®ã®æ»æã«ã¯å¿ èŠãããŸãããç¡æã®å ¬å ±Wi-Fiãããå Žæãäž»ãªã¿ãŒã²ããã§ãããæ¥ç¶ãããããã€ã¹ãããå Žæã§ããã°ãã©ã®ãããªå Žæã§ãå®è¡ãå¯èœã§ããå®¶åºãäŒæ¥ã®ãããã¯ãŒã¯ããã®æ»æã«å¯ŸããŠè匱ã§ããå¯èœæ§ããããŸããããããã®å Žæã§ã¯éåžžãæªæã®ããæŽ»åãæ€åºããããã®ç£èŠãè¡ãããŠããŸããå ¬è¡ç¡ç·LANã¯ãèšå®ã«èª€ãããã£ãããã»ãã¥ãªãã£ãäžååã§ãã£ããããããšãå€ããããè åšã¢ã¯ã¿ãŒã«DNSã¹ããŒãã£ã³ã°ãå®è¡ããæ©äŒãå€ãäžããŠããŸãããã®ãããèªå® ã§ãå ¬å ±ã®å Žã§ããWi-Fiã®ã»ãã¥ãªãã£ã«ã€ããŠåžžã«èããŠããããšãæšå¥šãããŸãã
æ»æè ãæ Œå¥œã®å ¬è¡ç¡ç·LANãèŠã€ããå ŽåãDNSãã€ãºãã³ã°ã®åºæ¬çãªæé ã¯æ¬¡ã®ãšããã§ãã
- ã¹ããŒãã£ã³ã°ããŒã«ã§ããarpspoofã䜿çšããŠããŠãŒã¶ãŒããã©ãŠã¶ã«ãã¡ã€ã³ã¢ãã¬ã¹ãå ¥åãããšãã«ãã¿ãŒã²ãããšãªããŠãŒã¶ãŒã®ãã·ã³ãæ»æè ã®ãã·ã³ã«åããããã«ä»åããããšãã§ããŸãããã®ã¹ãããã¯ãæ¬è³ªçã«ãŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿äžã®è§£æ±ºãã£ãã·ã¥ããã€ãºãã³ã°ããŸãã
- å¥ã®arpspoofã³ãã³ããçºè¡ãããã¡ã€ã³WebãµãŒããŒã«ã¯ã©ã€ã¢ã³ãã®IPãæ»æè ã®ãã·ã³IPã§ãããšæãããŸãã
- æ»æè ã®ãã·ã³IPãã¿ãŒã²ãããŠã§ããµã€ãã«åããHOSTãã¡ã€ã«ãšã³ããªãäœæããŸãããã®HOSTãšã³ããªã¯ããŠãŒã¶ãŒããã¡ã€ã³åãèŠæ±ãããšãã«äœ¿çšãããŸãã
- ããŒã«ã«ã®æªæã®ããã³ã³ãã¥ãŒã¿ã«ããæ¬ç©ãã®ãŠã§ããµã€ããšåãå€èгã®ãã£ãã·ã³ã°ãµã€ããèšçœ®ããŸãã
- ãããã¯ãŒã¯äžã®ã¿ãŒã²ãããšãªã被害è ãéšããŠèªèšŒãããããåœè£ ããWebãµã€ãã®ããŒãžã«æ å ±ãå ¥åããããããŠãããŒã¿ãåéããŸãã
DNSã¹ããŒãã£ã³ã°ã®æå³
ãã®æ»æã«ããããã¹ããŒãã£ã³ã°ããšã¯ãè åšã¢ã¯ã¿ãŒãããŠãŒã¶ãŒãç¥ã£ãŠããå ¬åŒãµã€ãã«äŒŒããæªæã®ãããµã€ãã䜿çšããããšãæå³ããŸããDNSã¯ã€ã³ã¿ãŒãããéä¿¡ã®éèŠãªéšåã§ããããããšã³ããªã®ãã€ãºãã³ã°ã¯ãæ»æè ãæ©å¯ããŒã¿ãåéããããã®å®ç§ãªãã£ãã·ã³ã°ã·ããªãªãæäŸããŸããè åšã¢ã¯ã¿ãŒã¯ããã¹ã¯ãŒããéè¡æ å ±ãã¯ã¬ãžããã«ãŒãçªå·ãé£çµ¡å ãå°ççãªããŒã¿ãªã©ãåéããããšãã§ããŸãã
ãŠãŒã¶ãŒã¯ããã®ãµã€ããæ£åŒãªãã®ã ãšæãã®ã§ãæ»æè ã¯ãã£ãã·ã³ã°ãã£ã³ããŒã³ãæåãããããšãã§ããŸãããªãããŸããµã€ãã«ã¯ããŠãŒã¶ãŒãèªèã§ããèŠçŽ ãããããµã€ããåœç©ã§ããããšã瀺ãå±éºä¿¡å·ããªãããšãæãŸãããšãããŠããŸãããªãããŸããµã€ãã«ã¯æå³ããªãå±éºä¿¡å·ãååšããå¯èœæ§ããããŸããããŠãŒã¶ãŒãããã«æ°ã¥ãããšã¯ã»ãšãã©ãªããããã¹ããŒãã£ã³ã°ã¯å人æ å ±ãçãã®ã«æå¹ãªææ®µãšãªã£ãŠããŸãã
DNSã¹ããŒãã£ã³ã°ã®å±éºæ§
DNSã¹ããŒãã£ã³ã°æ»æã§ã¯ããŠãŒã¶ãŒããã£ãã·ã³ã°è¢«å®³ã«éãããšãå€ããããããŒã¿ã®ãã©ã€ãã·ãŒãè ããããšã«ãªããŸãããªãããŸããµã€ãã¯ãæ»æè ã®ç®çã«ãã£ãŠç°ãªããŸããäŸãã°ãæ»æè ãéè¡æ å ±ãçã¿ããå ŽåããŸãã人æ°ã®ããéè¡ãµã€ããèŠã€ããã³ãŒããšã¹ã¿ã€ãªã³ã°ãã¡ã€ã«ãããŠã³ããŒãããæ¥ç¶ããã€ãžã£ãã¯ããããã«äœ¿çšããæªæã®ãããã·ã³ã«ã¢ããããŒãããŸãã
æ£èŠã®ãµã€ããå©çšããå人ã¯ããã©ãŠã¶ã«éè¡ã®ãã¡ã€ã³ãå ¥åããŸããã代ããã«æªæã®ãããŠã§ããµã€ããéããŸããã»ãšãã©ã®æ»æè ã¯ããªãããŸããµã€ããããã§ããŠããããšããã¹ãããŠç¢ºèªããŸãããææãããã€ãã®å°ããªãšã©ãŒã§ãªãããŸããµã€ãããã¬ãŠããŸãããšããããŸããäŸãã°ãæªæã®ãããŠã§ããµã€ãã¯éåžžãæå·åèšŒææžãã€ã³ã¹ããŒã«ãããŠããªããããæ¥ç¶ã¯å¹³æã«ãªããŸããæå·åãããŠããªãæ¥ç¶ã¯ããã¹ããµã€ããéè¡ã®ãŠã§ããµã€ãã§ãªãããšã瀺ãæç¢ºãªå±éºä¿¡å·ã§ãããã©ãŠã¶ã¯ãæ¥ç¶ãæå·åãããŠããªãããšããŠãŒã¶ãŒã«èŠåããŸãããå€ãã®ãŠãŒã¶ãŒã¯ãã®èŠåãèŠéãããç¡èŠãããããŠããŠãŒã¶ãŒåãšãã¹ã¯ãŒããå ¥åããŠããŸããŸãã
ãŠãŒã¶ãŒããªãããŸããµã€ãã«ã¢ã¯ã»ã¹ããåŸããã¹ã¯ãŒãã瀟äŒä¿éçªå·ããã©ã€ããŒãã®é£çµ¡å ãªã©ããµã€ãã«å ¥åããããã¹ãŠã®æ å ±ãæ»æè ã«éä¿¡ãããŸããååãªæ å ±ãããã°ãæ»æè ã¯æšçãšãªã£ã被害è ã®ååã§ä»ã®ã¢ã«ãŠã³ããéèšããããæ£èŠã®ã¢ã«ãŠã³ãã«èªèšŒããŠããã«å€ãã®æ å ±ããéãçãã ãããããšãå¯èœã«ãªããŸãã
DNSã¹ããŒãã£ã³ã°å¯Ÿç
å ¬è¡ç¡ç·LANããã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ãããŠãŒã¶ãŒã¯ãDNSã¹ããŒãã£ã³ã°ã«å¯ŸããŠè匱æ§ããããŸããDNSã¹ããŒãã£ã³ã°ããä¿è·ããããã«ãã€ã³ã¿ãŒããããããã€ãã¯DNSSECïŒDNSã»ãã¥ãªãã£ïŒã䜿çšããããšãã§ããŸãããã¡ã€ã³ææè ãDNSãšã³ããªãèšå®ããéãDNSSECã¯ããªãŸã«ããDNSã«ãã¯ã¢ãããæ¬ç©ãšããŠåãå ¥ããåã«å¿ èŠãªãšã³ããªã«æå·å眲åã远å ããŸãã
æšæºçãªDNSã¯æå·åãããŠãããã倿Žã解決ãããã«ãã¯ã¢ãããæ£åœãªãµãŒããŒãšãŠãŒã¶ãŒããã®ãã®ã§ããããšã確èªããããã®ããã°ã©ã ããããŸãããDNSSECã¯ãæŽæ°ãæ€èšŒããããã»ã¹ã«çœ²åã³ã³ããŒãã³ãã远å ããDNSã¹ããŒãã£ã³ã°ã確å®ã«ãããã¯ããŸããDNSSECã¯ãDNSã¹ããŒãã£ã³ã°ãããããå ¬è¡ç¡ç·LANã§ãŠãŒã¶ãŒããŒã¿ã®ãã©ã€ãã·ãŒã䟵害ããæãããããããæè¿ããã人æ°ãéããŠããŸãã
DNSã¹ããŒãã£ã³ã°ãšDNSãã£ãã·ã¥ãã€ãºãã³ã°ã®éã
DNSã¹ããŒãã£ã³ã°ãšDNSãã€ãºãã³ã°ã¯é¡äŒŒããŠããŸãããäž¡è ã«ã¯åºå¥ã§ããç¹åŸŽããããŸããã©ã¡ãããŠãŒã¶ãŒãéšããŠæ©å¯ããŒã¿ãæµåºããããã®ã§ãããæšçãšãªã£ããŠãŒã¶ãŒãæªæã®ãããœãããŠã§ã¢ãã€ã³ã¹ããŒã«ããŠããŸãå¯èœæ§ããããŸããDNSã¹ããŒãã£ã³ã°ãšãã€ãºãã³ã°ã¯ã©ã¡ããããŠãŒã¶ãŒãå ¬è¡ç¡ç·LANäžã®ãµãŒããŒãšéä¿¡ããéã«ããŠãŒã¶ãŒã®ããŒã¿ãã©ã€ãã·ãŒãšãŠã§ããµã€ãæ¥ç¶ã®å®å šæ§ãè ããå±éºæ§ããããŸãã
DNSãã£ãã·ã¥ããã€ãºãã³ã°ããããšãIPã¢ãã¬ã¹ãæ ŒçŽãããŠãããªãŸã«ããŸãã¯DNSãµãŒããŒã®ãšã³ããªã倿ŽãããŸããã€ãŸããã€ã³ã¿ãŒãããäžã®ã©ã®å Žæã«ãããŠãŒã¶ãŒã§ãã£ãŠãããã€ãºãã³ã°ãããDNSãµãŒããŒã®ãšã³ããªã䜿çšããã°ãæªæã®ããæ»æè ã管çãããµã€ããžãªãã€ã¬ã¯ããããããšã«ãªãã®ã§ãããã€ãºãã³ã°ããããµãŒããŒã«ãã£ãŠã¯ãäžçäžã®ãŠãŒã¶ãŒã«åœ±é¿ãäžããå¯èœæ§ããããŸãã
DNSã¹ããŒãã£ã³ã°ãšã¯ãããåºãæå³ã§DNSã¬ã³ãŒãã«å¯Ÿããæ»æãæãèšèã§ããDNSã®ãšã³ããªã倿ŽãããŠãŒã¶ãŒã«æ»æè ã管çãããµã€ããžã®ã¢ã¯ã»ã¹ã匷å¶ããæ»æã¯ããšã³ããªã®ãã€ãºãã³ã°ãå«ããã¹ããŒãã£ã³ã°ãšã¿ãªãããŸããã¹ããŒãã£ã³ã°ãè¡ããããšãæ»æè ãè匱ãªãã·ã³ã®DNSã¬ã³ãŒãããã€ãºãã³ã°ããäŒæ¥ãå人ã®ãŠãŒã¶ãŒããããŒã¿ãçãããšãã§ããããŒã«ã«ãããã¯ãŒã¯ã«å¯ŸããããçŽæ¥çãªæ»æã«ã€ãªããå¯èœæ§ããããŸãã