¡ÖHTTP/2¥é¥Ô¥Ã¥É¥ê¥»¥Ã¥È¹¶·â¡×¤ÇGoogle Cloud¤ËºÇÂç¤ÇËèÉÃ3²¯9800Ëü¥ê¥¯¥¨¥¹¥È¤ÎDDoS¹¶·â¤¬¤¢¤Ã¤¿¤³¤È¤¬È½ÌÀ
2023ǯ2·î¤ËCloudflare¤¬ËèÉÃ7100Ëü¥ê¥¯¥¨¥¹¥È¤ÎDDoS¹¶·â¤ò¼õ¤±¤Þ¤·¤¿¡£¤³¤ì¤Ï2022ǯ6·î¤ËGoogle Cloud¤¬¼õ¤±¤¿ËèÉÃ4600Ëü¥ê¥¯¥¨¥¹¥È¤òĶ¤¨¤ë¡¢»Ë¾åºÇÂ絬ÌϤÎHTTP DDoS¹¶·â¤Ç¤·¤¿¤¬¡¢¤½¤ì¤ò·å°ã¤¤¤Ë¾å²ó¤ëËèÉÃ3²¯9800Ëü¥ê¥¯¥¨¥¹¥È¤ËµÚ¤Ö¹¶·â¤¬¤¢¤Ã¤¿¤³¤È¤òGoogle Cloud¤¬Êó¹ð¤·¤Æ¤¤¤Þ¤¹¡£
Google Cloud mitigated largest DDoS attack, peaking above 398 million rps | Google Cloud Blog
How it works: The novel HTTP/2 ¡ÆRapid Reset¡Ç DDoS attack | Google Cloud Blog
https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack
HTTP/2 Zero-Day Vulnerability Results in Record-Breaking DDoS Attacks
https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/
How AWS protects customers from DDoS events | AWS Security Blog
https://aws.amazon.com/jp/blogs/security/how-aws-protects-customers-from-ddos-events/
¤³¤³¿ôǯ¡¢DDoS¹¶·â¤Îµ¬ÌϤϵ޷ã¤Ë³ÈÂ礷¤Æ¤¤¤Æ¡¢2022ǯ6·î¤ËCloudflare¤ËÂФ·¤Æ¹Ô¤ï¤ì¤¿¹¶·â¤ÏºÇÂç¤ÇËèÉÃ2600Ëü¥ê¥¯¥¨¥¹¥È¤Îµ¬ÌϤǤ·¤¿¤¬¡¢2022ǯ8·î¤ËGoogle Cloud¤ËÂФ·¤Æ¹Ô¤ï¤ì¤¿¹¶·â¤ÏºÇÂç¤ÇËèÉÃ4600Ëü¥ê¥¯¥¨¥¹¥È¤Ø¤È³ÈÂç¡£
2023ǯ¤ËÆþ¤ë¤È¡¢Cloudflare¤ËÂФ·¤ÆËèÉÃ7100Ëü¥ê¥¯¥¨¥¹¥È¤È¤¤¤¦DDoS¹¶·â¤¬Êó¹ð¤µ¤ì¤Æ¤¤¤Þ¤¹¡£
Cloudflare¤¬»Ë¾åºÇÂ絬ÌϤȤʤëËèÉÃ7100Ëü¥ê¥¯¥¨¥¹¥È¤Î¹¶·â¤ò¼õ¤±¤¿¤³¤È¤òÊó¹ð - GIGAZINE
¤½¤·¤Æ2023ǯ8·î¤Ë¿·¤¿¤Ê¹¶·â¤¬¹Ô¤ï¤ì¤¿¤È¤¤¤¦¤³¤È¤Ë¤Ê¤ê¤Þ¤¹¡¢º£²ó¤Î¹¶·â¤Ï¥Ô¡¼¥¯»þ¤ËËèÉÃ3²¯9800Ëü¥ê¥¯¥¨¥¹¥È¤Ë㤹¤ë¤â¤Î¤Ç¡¢µ¬ÌϤϰÊÁ°¤Î7.5Çܤ˳ÈÂ礷¤Æ¤¤¤Þ¤¹¡£Google¤Ë¤è¤ë¤È¹¶·â¤Ï2ʬ´Ö¤Ç¡¢¤½¤Îµ¬ÌϤÏ2023ǯ9·î¤Î1¥«·î´Ö¤ÎWikipedia¤ÎÁí±ÜÍ÷¿ô¤è¤ê¤â¿¤¤¤â¤Î¤À¤Ã¤¿¤½¤¦¤Ç¤¹¡£
Ʊ»þ´ü¤Ë¡¢Cloudflare¤Ç¥Ô¡¼¥¯»þ¤ËËèÉÃ2²¯1000Ëü¥ê¥¯¥¨¥¹¥È¤òĶ¤¨¤ë¹¶·â¤¬´Ñ¬¤µ¤ì¤Æ¤¤¤ë¤Û¤«¡¢AWS¤Ç¤âËèÉÃ1²¯5500Ëü¥ê¥¯¥¨¥¹¥È¤ò´Ñ¬¤·¤Æ¤¤¤Þ¤¹¡£
Google¤Ï¤³¤Î¹¶·â¤òËɤ¤¤À¤â¤Î¤Î¡¢8·î²¼½Ü°Ê¹ß¡¢¹¶·â¤Ï¤Ê¤ª¤âGoogle¤Î¥µ¡¼¥Ó¥¹¤äGoogle Cloud¤Î¥¤¥ó¥Õ¥é¡¢Google¤Î¸ÜµÒ¤ò´Þ¤à¥¤¥ó¥Õ¥é¥×¥í¥Ð¥¤¥À¤òÂоݤȤ·¤Æ³¤¤¤Æ¤¤¤ë¤È¤Î¤³¤È¡£
Google¡¢Cloudflare¡¢AWS¤Ï¤ª¸ß¤¤¤ËÂ絬ÌϹ¶·â¤¬È¯À¸¤·¤Æ¤¤¤ë¤³¤È¤ò³Îǧ¤·¡¢¹¶·â¤Î¸¶°ø¤¬HTTP/2¥×¥í¥È¥³¥ë¤Î°ìÉôµ¡Ç½¤È¥µ¡¼¥Ð¡¼¤Î¼ÂÁõ¤ò°ÍѤ¹¤ë¤³¤È¤Ç¹Ô¤ï¤ì¤Æ¤¤¤ë¤â¤Î¤Ç¤¢¤ë¤³¤È¤òÌÀ¤é¤«¤Ë¤·¤Æ¤¤¤Þ¤¹¡£¤³¤ÎÆâÍƤϡ¢ÀȼåÀ¡ÖCVE-2023-44487¡×¤È¤·¤ÆÊó¹ð¤µ¤ì¤Æ¤¤¤Þ¤¹¡£
NVD - CVE-2023-44487
https://nvd.nist.gov/vuln/detail/CVE-2023-44487
º£²ó¤Î¹¶·â¤Ï¡ÖHTTP/2¥é¥Ô¥Ã¥É¥ê¥»¥Ã¥È¹¶·â¡×¤Èɽ¸½¤µ¤ì¤Æ¤¤¤Þ¤¹¡£
HTTP/2¥×¥í¥È¥³¥ë¤Ç¤Ï¡¢¥¯¥é¥¤¥¢¥ó¥È¤Ï¡ÖRST_STREAM¡×¥Õ¥ì¡¼¥à¤òÁ÷¿®¤¹¤ë¤³¤È¤Ë¤è¤ê¡¢Á°¤Î¥¹¥È¥ê¡¼¥à¤ò¥¥ã¥ó¥»¥ë¤¹¤ëɬÍפ¬¤¢¤ë¤³¤È¤ò¥µ¡¼¥Ð¡¼¤ËÌÀ¼¨¤Ç¤¤Þ¤¹¡£¤³¤Î¤È¤¡¢¥µ¡¼¥Ð¡¼¤È¥¯¥é¥¤¥¢¥ó¥È¤Ï¥¥ã¥ó¥»¥ë¤ÎÄ´À°¤ò¤¹¤ëɬÍפ¬¤Ê¤¯¡¢¥¯¥é¥¤¥¢¥ó¥È¤Ë¤è¤ë°ìÊýŪ¤Ê¥¥ã¥ó¥»¥ë¤¬¹Ô¤¨¤Þ¤¹¡£¥µ¡¼¥Ð¡¼¤¬¡ÖRST_STREAM¡×¥Õ¥ì¡¼¥à¤ò¼õ¿®¤¹¤ì¤Ð¡¢¥¯¥é¥¤¥¢¥ó¥È¤Ï¾¤Î¥Ç¡¼¥¿¤¬½èÍý¤µ¤ì¤ëÁ°¤Ë¥¥ã¥ó¥»¥ë¤¬Â¨ºÂ¤Ë͸ú¤Ë¤Ê¤ë¤ÈÁÛÄꤷ¤Þ¤¹¡£
¤½¤³¤Ç¡¢¥¨¥ó¥É¥Ý¥¤¥ó¥È¤«¤éÊ£¿ô¤Î¥¹¥È¥ê¡¼¥à¤ò³«¤¡¢¥µ¡¼¥Ð¡¼¤ä¥×¥í¥¥·¤«¤é¤Î±þÅú¤òÂԤĤ³¤È¤Ê¤¯¤¿¤À¤Á¤Ë¥¹¥È¥ê¡¼¥à¤Î¥¥ã¥ó¥»¥ë¤ò¹Ô¤¤¡¢¤Þ¤¿¥¹¥È¥ê¡¼¥à¤ò³«¤¯¡¢¤È¤¤¤¦¤Î¤¬¡ÖHTTP/2 ¥é¥Ô¥Ã¥É¥ê¥»¥Ã¥È¹¶·â¡×¤Ç¤¹¡£¥¹¥È¥ê¡¼¥à¤¬Â¨ºÂ¤Ë¥¥ã¥ó¥»¥ë¤µ¤ì¤ë¤¿¤á¡¢¹¶·â¼Ô¤ÏƱ»þ¥ª¡¼¥×¥ó¥¹¥È¥ê¡¼¥à¤Î¿ô¤òĶ¤¨¤ë¤³¤È¤Ê¤¯¥ê¥¯¥¨¥¹¥È¤òÁ÷¤ê³¤±¤ë¤³¤È¤¬¤Ç¤¤ë¤È¤¤¤¦¤ï¤±¤Ç¤¹¡£
¤Ê¤ª¡¢¥í¡¼¥É¥Ð¥é¥ó¥µ¡¼¤ä¥×¥í¥¥·¥µ¡¼¥Ð¡¼¤È¤·¤ÆÆ°ºî¤¹¤ë¥ª¡¼¥×¥ó¥½¡¼¥¹¥½¥Õ¥È¥¦¥§¥¢¤ÎHAProxy¤Ï¡¢2018ǯ¤Ë¥ê¥ê¡¼¥¹¤µ¤ì¤¿¥Ð¡¼¥¸¥ç¥ó1.9¤Ç³«È¯¤µ¤ì¤¿¥³¡¼¥É¤Ë¤è¤êÅö³ºÀȼåÀ¤Ë¤¹¤Ç¤ËÂбþºÑ¤ß¤Ç¡¢±Æ¶Á¤Ï½Ð¤Ê¤¤¤³¤È¤òÌÀ¤é¤«¤Ë¤·¤Æ¤¤¤Þ¤¹¡£
HAProxy is not affected by the HTTP/2 Rapid Reset Attack (CVE-2023-44487)
https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487
¤Þ¤¿¡¢Web¥µ¡¼¥Ð¥·¥¹¥Æ¥à¤Î¡ÖNGINX¡×¤Ï¡¢¥Ñ¥Õ¥©¡¼¥Þ¥ó¥¹¤È¥ê¥½¡¼¥¹¾ÃÈñ¤òÍýͳ¤È¤·¤Æ¡¢½é´üÀßÄê¤ÇƱ»þ¥¹¥È¥ê¡¼¥à¿ô¤ò128¡¢HTTP¥¡¼¥×¥¢¥é¥¤¥Ö¤ò1000¤È¤·¤Æ¤ª¤ê¡¢¤³¤Î¤Þ¤Þ¤ÎÃͤDZ¿ÍѤ·¤Æ¤¤¤ë¤Ê¤éÌäÂê¤Ê¤¤¤ÈÀâÌÀ¤·¤Æ¤¤¤Þ¤¹¡£
HTTP/2 Rapid Reset Attack Impacting NGINX Products - NGINX
https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/