1 2 3
(Domain Name System,DNS) IP ;,
u (Sponsored)1 4 u (Generic) 4 u (Genericrestricted)3 u 291 u 11 u.arpa; 5
1 0.9 0.8 0.7 0.6 0.5 0.4 0.3 0.2 0.1 0 95.43% 1.99% 1.52% 0.47% 0.23% 0.23% 0.12% 0.01% Series1 Series2 2011 6
TOP 10 JHSOFT simple DNS+ Runtop dsl/cable PowerDNS Yutaka Sato DeleGate DNS bboy MyDNS Microso; Windows DNS ISC BIND 0.48% 0.16% 0.18% 0.41% 0.47% 0.67% 2.44% 95.19% 0 0.2 0.4 0.6 0.8 1 2011 7
TOP 10 robtexviking DNS module vermicelli totd Runtop dsl/cable bboy MyDNS Nominum CNS MikroTk dsl/cable Microso; Windows DNS ISC BIND 0.54% 0.11% 0.17% 0.24% 0.45% 0.48% 1.73% 2.25% 94.03% 0 0.1 0.2 0.3 0.4 0.5 0.6 0.7 0.8 0.9 1 2011 8
u u 4%0.98% 9
2009 5 19 5.19 DNSPoD 6 2009 6 DNS 20 2009 8 Google, Microsoft, Yahoo, Coca-Cola 2009 10.se 2009 12 twitter 2009 12 UltraDNS DDoS 2010 1 2010 5 de de 2011 2 DNS DNS 2011 4DNS PowerDNS DDoS 2011 5 Microsoft BPOS DNS 10
DNS DDoS DNS DDoS
DNS DNSec NSEC DDoS ID DNS / DDoS
DNS DNS Cache Poisoning(DNS ) DNS
Spoof 2005 DNS DNS 60 512 8.5DNS EDNS EDNS DNS 512 DNS DNS 512UDP 60 4000 66 DNS Amplification IP spoof TCP/IP DNS
5 19 ISP 5 18 DNSPOD.org root.com.net DNSPOD 10G.verycd.com.baofeng.com.4399.com active.baofeng.com live.baofeng.com download.baofeng.com
5 19 DNS ISP 5 19 baofeng. com.org root.com.net DNSPOD 10G.verycd.com.baofeng.com.4399.com active.baofeng.com live.baofeng.com download.baofeng.com
5 19 ADS ISP 50 DNS.baofeng.com DNS baofeng. com.org root.com.net DNSPOD 10G.verycd.com.baofeng.com.4399.com active.baofeng.com live.baofeng.com download.baofeng.com
DNS DNS
DNS
DNSSEC DNSSEC u l l l SSL u l l u l l l u l UDP l u DDoS
u u u u u u u u u DNSSec
23
1 2 3
1cbc.com icbc.com. Fast-flux Domain-flux DDoS. DDNS(Dynamic Domain Name System) 25
u u u DNS u URL u u u u u u QQ u u 26
2011 Zeus, 3-12 3841 27
DNS IP IP 28
IRC HTTP P2P P2P Sdbot,Agobot,GT- Bot,Rbot Rustock,Clickbot, Naz, Zeus, Conficker,Torpig MegaD, Mariposa Phatbot Sinit, Nugache Koobface, Storm, Waledac 29
- - - - 2 3 4 1 5 - - - - 30
2011 4.7 IP 2010 22.1 2010 500 890 9528 IP 885 31
1 2 3
" DNS DNS DNS DNS DNS DNS
Dynamic DNS DDNS fast flux domain flux domain-flux botnet botnet Botnet Botnet Botnetmaster 1) initial infection 2) Secondary Injection 4) Malicious Command & Control 5) Maintenance & Update 3) Connection Vulnerable Host 4) Malicious Command & Control 5) Maintenance & Update C&C Servers
Domain Flux ip ip Ip Ip 202.xx.xx.2 67.xx.xx.3... * *... 220.xxx.xxx.86 * 220.xxx.xxx.85 * * * * * * * * * * * * * * * * * * 67.xx.xx.8 * Time Time
domain-flux botnet ip ip ip Sub domain 7axik9bu9vqh5leqr6qajk7ui5ovrp8rqlsha9n6qpxr5gx3.44.*****.com * 6kj5i8c8fv949gqnn77imp7vh9wu357bfm6nob5uak6e4e8n.44.*****.com * p63mqvj3tsba3kagxv9vt8rikepmknuo3ngwfpnc4wm52jn6.44.*****.com * 79por344x7nouwdn6rv9jcxso4ad7h8jim7gp4tfrv3dhek9.44.*****.com * qcqs6dbpalim35asivcdki5o562ee4gdlwjihtf97tmcja38.44.*****.com * l6bv4suaxuwmbvnkco23ocnasaqk239hugsd3qgfk3mmqdbe.44.*****.com * Time
5 / Domain Flux1000 20 u 50% u 10% u 20~30%
u URL u URL u u u DNS 39
u Domain Flux u u 41