ã¢ã€ãã¢ãããããžã§ã¯ããž
ããã¯2003幎ã§ããïŒ1ãã«-30ãã€ã³ã¿ãŒããã-ã«ãŒãã§ãçªã®å€-7æããããŠMTVã§åœŒãã¯NumbãšIntheshadowsããã¬ã€ããŸããã YarSUã®æ å ±åŠç§ãåæ¥ããæ°äººã®åŠçãšåæ¥çã¯ã Demidovaã¯ãæ¬åœã«ã¯ãŒã«ã§ãæãéèŠãªããšã«å¿ èŠãªãã®ãå ±åã§äœæããããšã«ããŸãããåœæãç§ã¯å°å ã®ã€ã³ã¿ãŒããããããã€ããŒã§åããŠããã®ã§ãäœãã³ãŒãã£ã³ã°ãããã«ã€ããŠé·ãéèããå¿ èŠã¯ãããŸããã§ããã
ãã®ãããã€ããŒãšä»ã®ãã¹ãŠã®ãããã€ããŒã®ã¯ã©ã€ã¢ã³ãã¯ãæ¶è²»ããããã©ãã£ãã¯ã®éã«å¯ŸããŠæ¯æããè¡ããææ«ã«ãããã€ããŒãã¯ã©ã€ã¢ã³ãã«è«æ±æžãæåºãããšããããããããŠã³ããŒãããªãã£ãããªã©ãå€ãã®ç«¶åç¶æ³ãçºçã ãŸãããã ãããã¯ããããåãã¹ã€ããã«ã¶ãäžãã£ãŠããé£æ¥ãããªãã£ã¹ã§ãïŒã..ãåœæã®ç§ãã¡ã®ããã«ã顧客ããããã€ããŒã®ããŒã¿ããã§ãã¯ã§ãããœãããŠã§ã¢ã®å¯èœæ§ã¯çŽ æŽãããã£ãã§ãããããç§ãã¡ãããããšã§ãã
åæã«ããªãã£ã¹ã§ã®æ¶è²»ã«é¢ããããŒã¿ããããã€ããŒã®ããŒã¿ãšåæãããšãããã£ã¬ã¯ã¿ãŒã¯è¡ãæžæãã責任ãè² ã人ãæ¢ãå§ããŸããããã£ã¬ã¯ã¿ãŒãåã°ããããã«ãçµç¹å ã®ç¹å®ã®ãŠãŒã¶ãŒããšã«çµ±èšã衚瀺ã§ããããã«è£œåãæ¡åŒµãããã®åŸã...
IKSã圢ã«ãªããŸããäºåæãååŸ
åœåãéçºããŒã ã¯3人ã§æ§æããããã®ãã¡1人ã¯ãã¯ãã«ã«ãµããŒãæ©èœãå®è¡ããŠããŸããããã€ãŠã®ãœããšãç 究æã«äºåæãèŠã€ããŸããã 11éããã€ãã¹ã©ãŽãªã®çŸããæ¯è²ãæãéšå±ããããŸããã
圌ãã¯ããã«ã³ã³ãã¥ãŒã¿ãŒãæã£ãŠããŸãããæåã¯è³éããªããåããããªãã£ãã®ã§ãã³ã³ãã¥ãŒã¿ãŒã¯ç§ãã¡ã®ãã®ã§ããããã°ããã®éã1å°ã®i486ã³ã³ãã¥ãŒã¿ã§ããç§ãã¡ã®ãµãŒããŒã§ããã
21äžçŽåé ã«åäœã®å®å®æ§ãšä¿¡é Œæ§ãèªä¿¡ãæã£ãŠå®èšŒããæ°è£œåã®åºç€ãšããŠFreeBSDã·ã¹ãã ãæ¡çšããããšã決å®ãããŸããã
補åèªäœã¯æ¹¿ã£ãŠããŸããããç§ãã¡äžäººäžäººã¯ãæ°ãã顧客ã®1人ãšå€é ããŸã§ç°¡åã«åº§ããããã°ã©ã ããããã¯ãŒã¯ã«çµ±åãããšåæã«ã管çè ãšã®æ¶ãæ©ãç¯ããITå šè¬ãšè£œåã«å¯Ÿãã圌ãã®èŠæã«ã€ããŠè©±ãåãããšãã§ããŸãããç¹ã«ãã¡ãªã¿ã«ãç§ãã¡ã¯ãŸã åŸè ã«å°ãããICSãå¯èœãªéããŠãŒã¶ãŒãã¬ã³ããªãŒã«ããã客æ§ã®åžæãå®çŸããããšããŠããŸãã
21äžçŽã®åããããã¯äžè¬çã«èå³æ·±ããã®ã§ãããå人ã®å§ãã§æåã®ã¯ã©ã€ã¢ã³ãã®1人ã«ã€ã³ã¿ãŒãããå¶åŸ¡ãµãŒããŒã販売ããããã«ãªã£ãçµç·¯ãèŠããŠããŸãããªãã£ã¹ã«è¡ããç·æ§ãããŒãã«ã«åº§ã£ãŠãããã§2人ã®å€§ããªç·ã®åã§ãã圌ããœãã¡ã«ç§»åãã圌ãã圌ãšäžç·ã«ç§»åããäž¡åŽã«ãµã£ãããšåº§ã£ããšããç§ã¯ãã¯ãäœãèããã¹ããããããŸããã§ãããããããå人ã¯ãã¯ã©ã€ã¢ã³ãã®ããžãã¹ã¯éåžžã«ç«¶äºãæ¿ããã®ã§ã圌ãã¯ããã£ãŒã¬ãŒãã§ãããšèª¬æããŸãããããã£ãŒã¬ãŒãã¯æ¬åœãããããŸããããããã¯ãã¹ãŠç§ãã¡ã補åã®å質ãåäžãããåæ©ã«ãªããŸããïŒ
補åã®æ©èœæ§ãåäžãããããžã§ã¯ãã«æºããåŸæ¥å¡ãå¢ããŸããã2008幎ã«æ°ããåºã ãšãããªãã£ã¹ã«ç§»è»¢ããããšã¯ãA-Realã³ã³ãµã«ãã£ã³ã°ã®åœ¢æã«ãããéèŠãªæ®µéã«ãªããŸããã
åäžã®ã³ãŒãã§ã¯ãããŸãã
æ°åŠçãªèãæ¹ã«ãé¢ããããåµé æ§ãæ¬æ Œåããããããã€ã³ã¿ãŒãããã³ã³ãããŒã«ãµãŒããŒããšããé称ã«å ããŠã æ°ããããŒãžã§ã³ããšã«äžçš®ã®ãã¹ã³ãããååãæåã§å§ãŸãæ¶ç©ºã®ãå®ããèæ¡ããããšã«ããŸãããããã°ã©ã ããŒãžã§ã³ã®ã·ãªã¢ã«çªå·ã«å¯Ÿå¿ããŸãã
IKSã¯ãã³ãŒãããŒã ãArthur theAlienAstrologerãã§ããã¥ãŒããŸãã ãæåã®é¡§å®¢ïŒãã¡ãããå°å ã®äŒæ¥ããïŒãæåã®ãã°ãæåã®æ©èœã
åŸã ã«ã顧客ã¯ããå€ãã®æ©èœãæãã§ãããç§ãã¡ã¯ããå€ãã®é¡§å®¢ãæãã§ããããšãæããã«ãªããŸãããæ°ããããŒãžã§ã³ããšã«ãInternet ControlServerã¯ãŸããŸãå€æ©èœãªãœãªã¥ãŒã·ã§ã³ã«ãªããŸããã
ã¢ãŒãµãŒã¯ã«çœ®ãæããããŸãã ãBendertheBald Balalaikerããããã³IKSã¯ããã©ãŒãDHCPãããã€ããŒãªã©ã® RAIDã¢ã¬ã€ããµããŒãããããšãåŠã³ ããµã€ããã«ããŽãªã§ãã£ã«ã¿ãªã³ã°ããããšã§ããã©ãã·ã¥ãã£ã¹ã¯ããã®ã€ã³ã¹ããŒã«ãå¯èœã«ãªããŸããã 次ã®ããŒãžã§ã³ã®ãã¹ã³ãã㯠ãCheburashkatheCharmingCannibalãã§ãããé±æ¬¡ã¬ããŒãã¯ãã€ã³ã¿ãŒãããå¶åŸ¡ãµãŒããŒçµ±èšã¢ãžã¥ãŒã«ã«çµ±åãããŠããŸãããããã€ããŒã®åªå é äœãšãããã€ããŒéã®è² è·åæ£ã®ãµããŒããå®è£ ãããŸãã ãäŒè°æ©èœãåããWebãµãŒããŒãš jabberãµãŒããŒã®PHPãš MySQLã®ãµããŒããè¿œå ãããŸãã ã
ããŒãžã§ã³ã®æè¡é©æ°ã®äžã§ ãDrumbaçœå®³ããã€ããã ã£ãïŒã®ãµããŒã L2TPãš ã®Wi-FiãæäŸãOpenVPNã®ã¯ããã³ãã«ãæ¡åŒµã¡ãŒã«çµ±èš;ã«ãŒã«ãšãããã¡ã€ã«ã«è€æ°ã®æéç¯å²ãšææ¥ãèšå®ããæ©èœã ã ErictheEpic Elephantã
ã®ããŒãžã§ã³ã§ã¯ ã IKSã¯ããã€ãã®æ°ãã匷åãªã¢ãžã¥ãŒã«ãäžåºŠã«ååŸããŸãããSIPããã³ IAXãããã³ã«ããµããŒã ããIPãã¬ãã©ããŒã¢ãžã¥ãŒã« ãDLPã¢ãžã¥ãŒã« ã Layer7ãã£ã«ã¿ãªã³ã°ã KasperskyAnti-Spamã§ãããfail2banãµãŒãã¹ ãããã³SkyDNSãã©ãã£ãã¯ã«ããŽãª ã
å¶ç¶ã«ãã次ã®ããŒãžã§ã³ã®Internet Control Serverã¯ç¹å¥ãªèšå·ãªãã§æ®ãããŸããããããã°ã©ã èªäœã¯1ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ããã®è€æ°ã®ãµãŒããŒã®éäžç®¡çã®ãµããŒããå®è£ ã ããã©ãã£ãã¯ã«ããŽãªå¥ã®çµ±èšãšKasperskyWeb-Filteringã¢ãžã¥ãŒã«ãè¿œå ããŸãã ã Internet Control Serverã¯ãæ°ããæè¡ãã©ãããã©ãŒã ãšæ°ããæŽæ°ã·ã¹ãã ã«ç§»è¡ãããŸããã
圌ãã¯ãã¹ã³ãããªãã§ã¯é·çãã§ããªãã£ãã®ã§ã圌ãç»å Žããã®ã¯ ãFunnyFennecFoxãã§ãããããã°ã©ã ã®ããŒãžã§ã³6ã®ããŒããŒãããã«ããããã©ãã£ãã¯åŠçã¢ãžã¥ãŒã«ã®ããã©ãŒãã³ã¹ãåäžããICSã§èš±å¯ããããŠãŒã¶ãŒã®æš©éã®ããžãã¯ãå€æŽãããZFSãã¡ã€ã«ã·ã¹ãã ã§ã®äœæ¥ãæé©åã ãããã¬ãã©ããŒã¢ãžã¥ãŒã«ãžã®ãããªé話ã®ãµããŒããè¿œå ãããŸãã ã
2019幎ã®çµããã«ãæ°ããããŒãžã§ã³ã§ããIKS 7ïŒGalactic GuardianGooseããªãªãŒã¹ããŸãã ããã®äžã§ãxauthãŠãŒãã£ãªãã£ã®æ©èœãæ¡åŒµã ãã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ãè¿œå ããWebãã©ãŠã¶ãä»ããŠé»è©±ããããããšãã§ããWebãœãããã©ã³ã å®è£ ãã ãããªäŒè°ãéå¬ããŸããã
çŸæç¹ã§ã¯ãããŒãžã§ã³8ã®ã€ã³ã¿ãŒãããå¶åŸ¡ãµãŒããŒ-Harvey the Heavy metalHedgehogãé¢é£ããŠã ãŸããç¬èªã® ã¬ãŒããããã©ãã£ãã¯ã«ããŽãªãè¿œå ããOpenVPNãä»ãããªã¢ãŒãæ¥ç¶ã®ã»ãã¥ãªãã£ãåäžããã SSTPã«ãã®ã³ã°ãè¿œå ããŸããã
çŸä»£ã®ICS
çŸåšãç§ãã¡ã¯17幎以äžã«ããã£ãŠIKSã®ç¶ç¶çãªéçºãšãµããŒããè¡ã£ãŠããŸãããã®éãå°ããªå°åã®ITäŒæ¥ã«ãã£ãŠäœæããããã®è£œåã¯ããã·ã¢å šåã®å€ãã®äŒæ¥ã®äŒæ¥ãããã¯ãŒã¯ã§ãã®å°äœã確ç«ããŸããã çŸåšã®ç¶æ ã®
ã€ã³ã¿ãŒãããå¶åŸ¡ãµãŒããŒã¯ãç·æ¥ã®ITã¿ã¹ã¯ã®ã»ãšãã©ãã«ããŒã§ããå€æ©èœãœãªã¥ãŒã·ã§ã³ã§ã
ã1ã ãŠãããŒãµã«ã²ãŒããŠã§ã€
- ããŸããŸãªã¿ã€ãã®æ¥ç¶ã®ãµããŒãïŒã€ã³ã¿ãŒããããWi-Fiã3GãPPTPãPPPoEãL2TP
- è€æ°ã®ãããã€ããŒãšé£æºãã
- VLANãšDMZ
- IPSec / OpenVPN / GRE / IPIPãã³ãã«
- DHCPãDNSãNAT
2. ã¢ã¯ã»ã¹å¶åŸ¡
- ActiveDirectoryãšã®åæ
- åå/ãã¹ã¯ãŒããIPãMACãSMSãé話ãXauthã«ãããŠãŒã¶ãŒèªèšŒ
- Xauthããã³nDPIãä»ããã¢ããªã±ãŒã·ã§ã³å¶åŸ¡
- çŠæ¢ããã³èš±å®¹ã«ãŒã«
- L7ãã£ã«ã¿ãªã³ã°
3. ã³ã³ãã³ããã£ã«ã¿ãŒ
- æ³åçãGosnarkokontrolã®ãªã¹ãã«ãããã£ã«ã¿ãªã³ã°
- åŠæ ¡åãã®æ¢è£œã®ã«ãŒã«ã»ãããRBOS
- URLãããŒã¯ãŒãããã¿ãŒã³ãæ£èŠè¡šçŸã«ãããããã¯
- AdBlockã«ããŽãªã®éªéãªåºåããããã¯ãã
- è¿œå ã®ãã©ãã£ãã¯ã«ããŽãªSkyDNSããã³KWF
- ãŠãŒã¶ãŒã¢ã¯ã»ã¹ã®æè»ãªæ§æ
4. ãããã¯ãŒã¯ä¿è·
- ãã¡ã€ã¢ãŠã©ãŒã«ãšIDS / IPS Suricata
- Kaspersky Anti-Virusããã³Anti-SpamãClamAV
- ãããã·ãµãŒããŒ
- httpsãã£ã«ã¿ãªã³ã°
- ãã³ãã«æå·å
- NATä¿è·
5. ãªã¢ãŒãã¢ã¯ã»ã¹
- çµã¿èŸŒã¿VPNïŒSSTPãOpenVPNãL2TP / IPSecïŒãä»ããå®å šãªæ¥ç¶
- ç°ãªãã¢ã¯ã»ã¹ã«ãŒã«
- ãããã¯ãŒã¯äžã®ãŠãŒã¶ãŒã¢ã¯ã·ã§ã³ã«é¢ããçµ±èšã®åé
- ãªã¢ãŒãã§äœæ¥ãããšãã®äŒæ¥ãããã¯ãŒã¯ã®ä¿è·
- çµã¿èŸŒã¿ã®ip-telephonyã¢ãžã¥ãŒã«
6. ãã©ãã£ãã¯ã«ãŠã³ã¿ãŒ
- ãŠãŒã¶ãŒãã¢ãã¬ã¹ã°ã«ãŒããã€ã³ã¿ãŒãã§ã€ã¹ããµã€ãããã¡ã€ã«ããã¡ã€ã³ãæéã«ãããã©ãã£ãã¯ã«ãŠã³ã¿ãŒ
- NetFlowã«ããã·ã¹ã³ã·ã¹ãã ãºããã®åé
- ãŠãŒã¶ãŒããããã³ã«ãmimeã¿ã€ããå²ãåœãŠãIPã«é¢ããã¬ããŒã
- Syslog +ã¬ããŒããã¶ã€ããŒ
- ã¬ããŒãã®ãšã¯ã¹ããŒã
7. ãããã¯ãŒã¯ãµãŒãã¹
- KerberosèªèšŒãåãããããã·ãµãŒããŒ
- å èµVPNãµãŒããŒ
- ã¡ãŒã«-æå·åããã£ã«ã¿ãŒããªã¬ãŒãã¹ãã 察ç
- ãã¡ã€ã«ãFTPãWebããžã£ããŒãµãŒããŒ
- IPãã¬ãã©ããŒïŒé³å£°ããã³ãããªäŒè°ãWebãœãããã©ã³
8. éäžç®¡ç
- å°ççã«é¢ãããµãŒããŒã®çµ±å
- ãªã¢ãŒããµãŒããŒã®å®å šãªæ§æ
- 1ã€ã®ã€ã³ã¿ãŒãã§ãŒã¹ã«ããè€æ°ã®ãµãŒããŒã®ç®¡ç
å ¬åŒãŠã§ããµã€ãããé åžããããããŠã³ããŒãããããšã«ãããã€ã³ã¿ãŒãããå¶åŸ¡ãµãŒããŒããã¹ãã§ããŸã ããã©ã€ã¢ã«ã¯35æ¥éå©çšå¯èœã§ãããäœã«ãææãããŸãã;ïŒ
çµè«
ãã®èšäºã¯ã補åã®éçºã®æŽå²ãã©ã®ããã«å§ãŸã£ããããã®æ©èœãæéã®çµéãšãšãã«ã©ã®ããã«å€åããããä»æ¥ã®ICSã«ã€ããŠããå°ãåŠã¶ããšãã§ããããã«ãå°ããªæè¿ãšããŠæžããŸããã
å°æ¥çã«ã¯ãfreebsdãšãã®ã·ã¹ãã ãšããŸããŸãªæ©èœã¢ãžã¥ãŒã«ãšã®çµ±åã«é¢ããäžé£ã®èšäºãå ¬éããäºå®ã§ãã
çµéšã®å ±æ-ãã³ãã³ã°ã¹ãã«ïŒ
ã€ãŽãŒã«ã»ã¢ã¬ã¯ã»ã€ãšãã
A-å®ã³ã³ãµã«ãã£ã³ã°ã®åµæ¥è
ICSã®ã€ããªãã®ãŒINSPIRER