Microsoft Azure¡¢Outlook¡¡OneDrive¥¢¥¯¥»¥¹¾ã³²¡¢¥µ¥¤¥Ð¡¼¹¶·â¤¬¸¶°ø
Microsoft¤Ï¤³¤Î¤Û¤É¡¢¡ÖMicrosoft Response to Layer 7 Distributed Denial of Service (DDoS) Attacks¡ÃMSRC Blog¡ÃMicrosoft Security Response Center¡×¤Ë¤ª¤¤¤Æ¡¢2023ǯ6·î¾å½Ü¤Ë°ìÉô¤ÎMicrosoft¥µ¡¼¥Ó¥¹¤ÇȯÀ¸¤·¤¿²ÄÍÑÀ¤ÎÄã²¼¤Î¸¶°ø¤òȯɽ¤·¤¿¡£¶¼°Ò¼Ô¤Ë¤è¤Ã¤Æ°ú¤µ¯¤³¤µ¤ì¤¿Ê¬»¶·¿¥µ¡¼¥Ó¥¹µñÈݹ¶·â(DDoS: Distributed Denial of Service attack)¤Ë¤è¤ë¤â¤Î¤ÈÊó¹ð¤µ¤ì¤Æ¤¤¤ë¡£
Microsoft Response to Layer 7 Distributed Denial of Service (DDoS) Attacks¡ÃMSRC Blog¡ÃMicrosoft Security Response Center
¡ÖStorm-1359¡×¤È¤·¤ÆÄÉÀפµ¤ì¤Æ¤¤¤ë¶¼°Ò¥¢¥¯¥¿¡¼¤¬¡¢Microsoft¥µ¡¼¥Ó¥¹(Outlook¡¢OneDrive¡¢Azure¤Ê¤É)¤ËÂФ·¡¢DDoS¹¶·â¤ò¹Ô¤Ã¤Æ¤¤¤¿¤³¤È¤¬ÌÀ¤é¤«¤Ë¤Ê¤Ã¤¿¡£Ê£¿ô¤Î¥¿¥¤¥×¤ÎDDoS¹¶·â¤¬³Îǧ¤µ¤ì¤Æ¤¤¤ë¡£¼ç¤Ê¹¶·â¤ÎÆâÍƤϼ¡¤Î¤È¤ª¤ê¡£
HTTP(S)¥Õ¥é¥Ã¥Ç¥£¥ó¥°¹¶·â - SSL/TLS¥Ï¥ó¥É¥·¥§¥¤¥¯¤ÈHTTP(S)¥ê¥¯¥¨¥¹¥È½èÍý¤Î¹âÉé²Ù¤Ë¤è¤Ã¤Æ¡¢¥·¥¹¥Æ¥à¥ê¥½¡¼¥¹¤ò»È¤¤²Ì¤¿¤¹¤³¤È¤òÌÜŪ¤È¤·¤Æ¹¶·â¤È¤µ¤ì¤Æ¤¤¤ë¡£°Û¤Ê¤ëIP¤«¤éÀ¤³¦Ãæ¤Ëʬ»¶¤·¤¿¹âÉé²Ù¤ÎHTTP(S)¥ê¥¯¥¨¥¹¥È¤òÁ÷¿®¤·¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¥Ð¥Ã¥¯¥¨¥ó¥É¤Î¥ê¥½¡¼¥¹¤òɯÇ÷¤µ¤»¤Æ¤¤¤¿
¥¥ã¥Ã¥·¥å²óÈò - ¥³¥ó¥Æ¥ó¥Ä¥Ç¥ê¥Ð¥ê¥Í¥Ã¥È¥ï¡¼¥¯(CDN: Content Delivery Network)¥ì¥¤¥ä¤ò¥Ð¥¤¥Ñ¥¹¤·¤è¤¦¤È¤¹¤ë¹¶·â¤È¤µ¤ì¤Æ¤¤¤ë¡£À¸À®¤µ¤ì¤¿URL¤ËÂФ·¤Æ°ìÏ¢¤Î¥¯¥¨¥ê¤òÁ÷¿®¤¹¤ë¤³¤È¤Ç¥Õ¥í¥ó¥È¥¨¥ó¥ÉÁؤ˥¥ã¥Ã¥·¥å¤µ¤ì¤¿¥³¥ó¥Æ¥ó¥Ä¤«¤éÄ󶡤¹¤ë¤Î¤Ç¤Ï¤Ê¤¯¡¢¤¹¤Ù¤Æ¤Î¥ê¥¯¥¨¥¹¥È¤ò¥ª¥ê¥¸¥ó¤ËžÁ÷¤¹¤ë¤è¤¦¶¯À©¤·¤Æ¤¤¤¿
Slowloris¹¶·â - ʬ»¶·¿¥µ¡¼¥Ó¥¹µñÈݹ¶·âÍѤΥġ¼¥ë¤Ç¤¢¤ëSlowloris¤Ë¤è¤ë¹¶·â¡£¤½¤ÎÆâÍƤϡ¢¥¯¥é¥¤¥¢¥ó¥È¤«¤é¥ê¥½¡¼¥¹(²èÁü¤Ê¤É)¤òÍ׵᤹¤ë¤¿¤á¤ËWeb¥µ¡¼¥Ð¤ØÀܳ¤·¤¿ºÝ¤Ë¡¢¥À¥¦¥ó¥í¡¼¥É¤Î³Îǧ¤Ë»þ´Ö¤ò¤«¤±¤ë¤³¤È¤ÇÀܳ¤ò²Äǽ¤Ê¸Â¤ê³«¤¤¤¿¤Þ¤Þ¤Ë¤µ¤»¤ë¤È¤¤¤¦¤â¤Î¡£·ë²Ì¡¢Í׵ᤵ¤ì¤¿¥ê¥½¡¼¥¹¤¬Ä¹¤¯¥á¥â¥ê¤ËÊÝ»ý¤µ¤ì¤ë¤³¤È¤Ë¤Ê¤ê¡¢¥á¥â¥êÉÔ¤¬È¯À¸¤¹¤ë
DDoS¹¶·â¤ËÂФ·¡¢Azure Web¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¥Õ¥¡¥¤¥¢¥¦¥©¡¼¥ë(WAF: Web Application Firewall)¤Ê¤É¤ò³èÍѤ·¤Æ¡¢Web¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤òÊݸ¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£Azure Web¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¥Õ¥¡¥¤¥¢¥¦¥©¡¼¥ë¤ò»ÈÍѤ¹¤ë¾ì¹ç¡¢¥Ü¥Ã¥ÈÊݸî¥Þ¥Í¡¼¥¸¥É¥ë¡¼¥ë¥»¥Ã¥È¤ò͸ú²½¤·¤Æ´ûÃΤΰ¼Á¤Ê¥Ü¥Ã¥È¤«¤é¤Î¹¶·â¤ò¥Ö¥í¥Ã¥¯¤¹¤ë¤³¤È¡¢°°Õ¤Î¤¢¤ëIP¥¢¥É¥ì¥¹¤äÈϰϤò¥Ö¥í¥Ã¥¯¤¹¤ë¤¿¤á¤Ë¥«¥¹¥¿¥à¥ë¡¼¥ë¤òºîÀ®¤¹¤ë¤³¤È¡¢ÆÃÄê¤ÎÃϰ褫¤é¤Î¥È¥é¥Õ¥£¥Ã¥¯¤ÎÀ©¸Â¤¹¤ë¤Ê¤É¤Î´ËϺö¤ò¸¡Æ¤¤¹¤ë¤³¤È¤¬´«¤á¤é¤ì¤Æ¤¤¤ë¡£
Storm-1359¤ÏDDoS¹¶·â¤ò°ú¤µ¯¤³¤¹¤³¤È¤¬¤Ç¤¤ë¥ê¥½¡¼¥¹¤Ø¤Î¥¢¥¯¥»¥¹¤òÊÝ»ý¤·¤Æ¤¤¤ë²ÄǽÀ¤¬¤¢¤ê¡¢º£¸å¤âÎà»÷¤Î¥µ¥¤¥Ð¡¼¹¶·â¤¬¼Â»Ü¤µ¤ì¤ë²ÄǽÀ¤¬¤¢¤ë¡£
¡ÖStorm-1359¡×¤È¤·¤ÆÄÉÀפµ¤ì¤Æ¤¤¤ë¶¼°Ò¥¢¥¯¥¿¡¼¤¬¡¢Microsoft¥µ¡¼¥Ó¥¹(Outlook¡¢OneDrive¡¢Azure¤Ê¤É)¤ËÂФ·¡¢DDoS¹¶·â¤ò¹Ô¤Ã¤Æ¤¤¤¿¤³¤È¤¬ÌÀ¤é¤«¤Ë¤Ê¤Ã¤¿¡£Ê£¿ô¤Î¥¿¥¤¥×¤ÎDDoS¹¶·â¤¬³Îǧ¤µ¤ì¤Æ¤¤¤ë¡£¼ç¤Ê¹¶·â¤ÎÆâÍƤϼ¡¤Î¤È¤ª¤ê¡£
HTTP(S)¥Õ¥é¥Ã¥Ç¥£¥ó¥°¹¶·â - SSL/TLS¥Ï¥ó¥É¥·¥§¥¤¥¯¤ÈHTTP(S)¥ê¥¯¥¨¥¹¥È½èÍý¤Î¹âÉé²Ù¤Ë¤è¤Ã¤Æ¡¢¥·¥¹¥Æ¥à¥ê¥½¡¼¥¹¤ò»È¤¤²Ì¤¿¤¹¤³¤È¤òÌÜŪ¤È¤·¤Æ¹¶·â¤È¤µ¤ì¤Æ¤¤¤ë¡£°Û¤Ê¤ëIP¤«¤éÀ¤³¦Ãæ¤Ëʬ»¶¤·¤¿¹âÉé²Ù¤ÎHTTP(S)¥ê¥¯¥¨¥¹¥È¤òÁ÷¿®¤·¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¥Ð¥Ã¥¯¥¨¥ó¥É¤Î¥ê¥½¡¼¥¹¤òɯÇ÷¤µ¤»¤Æ¤¤¤¿
¥¥ã¥Ã¥·¥å²óÈò - ¥³¥ó¥Æ¥ó¥Ä¥Ç¥ê¥Ð¥ê¥Í¥Ã¥È¥ï¡¼¥¯(CDN: Content Delivery Network)¥ì¥¤¥ä¤ò¥Ð¥¤¥Ñ¥¹¤·¤è¤¦¤È¤¹¤ë¹¶·â¤È¤µ¤ì¤Æ¤¤¤ë¡£À¸À®¤µ¤ì¤¿URL¤ËÂФ·¤Æ°ìÏ¢¤Î¥¯¥¨¥ê¤òÁ÷¿®¤¹¤ë¤³¤È¤Ç¥Õ¥í¥ó¥È¥¨¥ó¥ÉÁؤ˥¥ã¥Ã¥·¥å¤µ¤ì¤¿¥³¥ó¥Æ¥ó¥Ä¤«¤éÄ󶡤¹¤ë¤Î¤Ç¤Ï¤Ê¤¯¡¢¤¹¤Ù¤Æ¤Î¥ê¥¯¥¨¥¹¥È¤ò¥ª¥ê¥¸¥ó¤ËžÁ÷¤¹¤ë¤è¤¦¶¯À©¤·¤Æ¤¤¤¿
Slowloris¹¶·â - ʬ»¶·¿¥µ¡¼¥Ó¥¹µñÈݹ¶·âÍѤΥġ¼¥ë¤Ç¤¢¤ëSlowloris¤Ë¤è¤ë¹¶·â¡£¤½¤ÎÆâÍƤϡ¢¥¯¥é¥¤¥¢¥ó¥È¤«¤é¥ê¥½¡¼¥¹(²èÁü¤Ê¤É)¤òÍ׵᤹¤ë¤¿¤á¤ËWeb¥µ¡¼¥Ð¤ØÀܳ¤·¤¿ºÝ¤Ë¡¢¥À¥¦¥ó¥í¡¼¥É¤Î³Îǧ¤Ë»þ´Ö¤ò¤«¤±¤ë¤³¤È¤ÇÀܳ¤ò²Äǽ¤Ê¸Â¤ê³«¤¤¤¿¤Þ¤Þ¤Ë¤µ¤»¤ë¤È¤¤¤¦¤â¤Î¡£·ë²Ì¡¢Í׵ᤵ¤ì¤¿¥ê¥½¡¼¥¹¤¬Ä¹¤¯¥á¥â¥ê¤ËÊÝ»ý¤µ¤ì¤ë¤³¤È¤Ë¤Ê¤ê¡¢¥á¥â¥êÉÔ¤¬È¯À¸¤¹¤ë
DDoS¹¶·â¤ËÂФ·¡¢Azure Web¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¥Õ¥¡¥¤¥¢¥¦¥©¡¼¥ë(WAF: Web Application Firewall)¤Ê¤É¤ò³èÍѤ·¤Æ¡¢Web¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤òÊݸ¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£Azure Web¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¥Õ¥¡¥¤¥¢¥¦¥©¡¼¥ë¤ò»ÈÍѤ¹¤ë¾ì¹ç¡¢¥Ü¥Ã¥ÈÊݸî¥Þ¥Í¡¼¥¸¥É¥ë¡¼¥ë¥»¥Ã¥È¤ò͸ú²½¤·¤Æ´ûÃΤΰ¼Á¤Ê¥Ü¥Ã¥È¤«¤é¤Î¹¶·â¤ò¥Ö¥í¥Ã¥¯¤¹¤ë¤³¤È¡¢°°Õ¤Î¤¢¤ëIP¥¢¥É¥ì¥¹¤äÈϰϤò¥Ö¥í¥Ã¥¯¤¹¤ë¤¿¤á¤Ë¥«¥¹¥¿¥à¥ë¡¼¥ë¤òºîÀ®¤¹¤ë¤³¤È¡¢ÆÃÄê¤ÎÃϰ褫¤é¤Î¥È¥é¥Õ¥£¥Ã¥¯¤ÎÀ©¸Â¤¹¤ë¤Ê¤É¤Î´ËϺö¤ò¸¡Æ¤¤¹¤ë¤³¤È¤¬´«¤á¤é¤ì¤Æ¤¤¤ë¡£
Storm-1359¤ÏDDoS¹¶·â¤ò°ú¤µ¯¤³¤¹¤³¤È¤¬¤Ç¤¤ë¥ê¥½¡¼¥¹¤Ø¤Î¥¢¥¯¥»¥¹¤òÊÝ»ý¤·¤Æ¤¤¤ë²ÄǽÀ¤¬¤¢¤ê¡¢º£¸å¤âÎà»÷¤Î¥µ¥¤¥Ð¡¼¹¶·â¤¬¼Â»Ü¤µ¤ì¤ë²ÄǽÀ¤¬¤¢¤ë¡£