ãã¡ã€ã³ããŒã ãµãŒããŒïŒDNSïŒã¹ããŒãã£ã³ã°ã¯ãæ»æè ã被害è ã®ãã©ãã£ãã¯ãïŒæ£åœãªIPã¢ãã¬ã¹ã§ã¯ãªãïŒæªæã®ãããµã€ãã«èªå°ãããµã€ããŒæ»æã§ããæ»æè ã¯DNSãã£ãã·ã¥ãã€ãºãã³ã°ã䜿çšããŠã€ã³ã¿ãŒããããã©ãã£ãã¯ãååããè³æ Œæ å ±ãæ©å¯æ å ±ãçã¿ãŸãã DNSãã£ãã·ã¥ãã€ãºãã³ã°ãšDNSã¹ããŒãã£ã³ã°ã¯åãæŠå¿µã§ãããå€ãã®å Žåå矩èªãšããŠäœ¿çšãããŸããããã«ãŒã¯ããŠãŒã¶ãŒãã ãŸããŠå®å šã§ãªãWebãµã€ãã«å人æ å ±ãå ¥åãããããšèããŠããŸãã圌ã¯ã©ããã£ãŠãããéæããããšãã§ããŸããïŒ DNSãã£ãã·ã¥ããã€ãºãã³ã°ããããããè¡ãã«ã¯ãããã«ãŒã¯ç¹å®ã®ãµã€ãã®DNSããŒã¿ãã¹ããŒãã£ã³ã°ãŸãã¯çœ®æããŠããã被害è ãæ£åœãªãµãŒããŒã§ã¯ãªãæ»æè ã®ãµãŒããŒã«ãªãã€ã¬ã¯ãããŸãããããã£ãŠãããã«ãŒã¯åœŒã®ç®æšãéæããŸãããªããªãã圌ã®åã«å¹ åºãæ©äŒãéãããããã§ãã ãã£ãã·ã³ã°æ»æãå®è¡ããããããŒã¿ãçãã ãã被害è ã®ã·ã¹ãã ã«ãã«ãŠã§ã¢ãæ³šå ¥ãããããŸãã
DNSã¹ããŒãã£ã³ã°ãšãã£ãã·ã¥ãã€ãºãã³ã°ãšã¯äœã§ããïŒ
DNSãã£ãã·ã¥ãã€ãºãã³ã°ã«ã€ããŠèª¬æããåã«ããŸãDNSãšDNSãã£ãã·ã³ã°ãšã¯äœããèŠãŠã¿ãŸãããã DNSã¯ãIPã¢ãã¬ã¹ãšãã¡ã€ã³åã®äžççãªãã£ã¬ã¯ããªã§ããããã¯äžçš®ã®ã€ã³ã¿ãŒãããé»è©±åž³ãšèšããŸãã DNSã¯ãvaronis.comã®ãããªãŠãŒã¶ãŒãã¬ã³ããªãŒãªã¢ãã¬ã¹ã92.168.1.169ã®ãããªIPã¢ãã¬ã¹ã«å€æããŸããããã¯ãã³ã³ãã¥ãŒã¿ãŒããããã¯ãŒã¯äžã§åäœããããã«äœ¿çšããŸãã DNSãã£ãã·ã³ã°ã¯ãäžçäžã®DNSãµãŒããŒã«ã¢ãã¬ã¹ãä¿åããããã®ã·ã¹ãã ã§ãã DNSã¯ãšãªã®åŠçãé«éåããããã«ãéçºè ã¯åæ£DNSã·ã¹ãã ãäœæããŸãããåãµãŒããŒã¯ããã£ãã·ã¥ãšåŒã°ãããèªèããŠããDNSã¬ã³ãŒãã®ãªã¹ããä¿æããŠããŸããæå¯ãã®DNSãµãŒããŒã«ç®çã®IPã¢ãã¬ã¹ããªãå Žåã¯ãã¢ã¯ã»ã¹ããããšããŠããWebãµã€ãã®ã¢ãã¬ã¹ãèŠã€ãããŸã§ãã¢ããã¹ããªãŒã DNSãµãŒããŒã«ã¯ãšãªãå®è¡ããŸãã次ã«ãDNSãµãŒããŒã¯ãã®æ°ãããšã³ããªããã£ãã·ã¥ã«ä¿åããŠã次åã®å¿çãé«éåããŸãã
DNSãã£ãã·ã¥ãã€ãºãã³ã°ã®äŸãšçµæ
DNSã®æŠå¿µã¯ãçŸä»£ã®ã€ã³ã¿ãŒãããã®è©³çŽ°ã«åãããŠèª¿æŽãããŠããŸããããã¡ãããDNSã¯æéã®çµéãšãšãã«é²åããŠããŸããããä»ã§ã1ã€ã®èª€ã£ãŠæ§æãããDNSãµãŒããŒã䜿çšããŠãäœçŸäžãã®ãŠãŒã¶ãŒã«åœ±é¿ãæããããã ãã§ååã§ããäŸ-ãŠã£ããªãŒã¯ã¹ãžã®æ»æ æ»æè ãDNSãã£ãã·ã¥ãã€ãºãã³ã°ã䜿çšããŠãã©ãã£ãã¯ãååãããµã€ãã®ç¬èªã®ã¯ããŒã³ã«ãªãã€ã¬ã¯ãããå Žåããã®æ»æã®ç®çã¯ããã©ãã£ãã¯ããŠã£ããªãŒã¯ã¹ããè¿åãããããšã§ãããããçšåºŠã®æåãåããŸãããDNSãã£ãã·ã¥ãã€ãºãã³ã°ã¯ãäžè¬ãŠãŒã¶ãŒãæ€åºããã®ã¯ç°¡åã§ã¯ãããŸãããDNSã¯çŸåšä¿¡é Œã«åºã¥ããŠæ§ç¯ãããŠãããããã匱ç¹ã§ãã人ã ã¯DNSãä¿¡é ŒããããŠããã©ãŠã¶ã®ã¢ãã¬ã¹ãæ¬åœã«å¿ èŠãªãã®ãšäžèŽãããã©ããã決ããŠãã§ãã¯ããŸãããæ»æè ã¯ããã®äžæ³šæãšäžæ³šæãå©çšããŠãè³æ Œæ å ±ããã®ä»ã®éèŠãªæ å ±ãçã¿ãŸãã
DNSãã£ãã·ã¥ãã€ãºãã³ã°ã¯ã©ã®ããã«æ©èœããŸããïŒ
DNSãã£ãã·ã¥ããã€ãºãã³ã°ãããšããããšã¯ãããªãã«æãè¿ãDNSãµãŒããŒã«ãééã£ãã¢ãã¬ã¹ã«ããªããéãã¬ã³ãŒããå«ãŸããŠããããšãæå³ããŸããããã¯éåžžãæ»æè ã«ãã£ãŠå¶åŸ¡ãããŸããæ»æè ãDNSãã£ãã·ã¥ããã€ãºãã³ã°ããããã«äœ¿çšããææ³ã¯å€æ°ãããŸãã
ARPã¹ããŒãã£ã³ã°ã䜿çšããLANãã©ãã£ãã¯ã®åå
ããŒã«ã«ãããã¯ãŒã¯ãããã«è匱ã§ãããã«é©ãããããšã§ããããå€ãã®ç®¡çè ã¯ãèãããããã¹ãŠã®ã¢ã¯ã»ã¹ããããã¯ããŠããã®ã§å®å¿ã§ããŸããããåç¥ã®ããã«ã詳现ã«ã¯æªéãããŸãã
äžè¬çãªåé¡ã®1ã€ã¯ã ãªã¢ãŒãã§äœæ¥ããåŸæ¥å¡ã§ãã Wi-Fiãããã¯ãŒã¯ãä¿è·ãããŠããããšãã©ã®ããã«ç¢ºèªã§ããŸããïŒ ããã«ãŒã¯ã匱ãWi-Fiãã¹ã¯ãŒããæ°æéã§è§£èªã§ããŸãã
ãã1ã€ã®åé¡ã¯ãã€ãŒãµãããããŒããéããŠããããšã§ãã å»äžããããŒããã®ä»ã®å ¬å ±ã®å Žæã«ãããã¹ãŠã®äººãã¢ã¯ã»ã¹ã§ããŸããæ³åããŠã¿ãŠãã ããã蚪åè ã¯ããããŒãã£ã¹ãã¬ã€çšã®ããã€ã¹ã«ã€ãŒãµãããã±ãŒãã«ãæ¥ç¶ã§ããŸããããã«ãŒã¯ãäžèšã®ããããã®æ¹æ³ã§ååŸããããŒã«ã«ãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãã©ã®ããã«äœ¿çšã§ããŸããïŒãŸãã圌ã¯ãã£ãã·ã³ã°ããŒãžãäœæããŠãè³æ Œæ å ±ããã®ä»ã®è²Žéãªæ å ±ãåéã§ããããã«ãªããŸãã次ã«ãããŒã«ã«ãããã¯ãŒã¯ãŸãã¯ãªã¢ãŒããµãŒããŒã®ããããã§ãã®ãµã€ãããã¹ãã§ããŸãããã®ããã«å¿ èŠãªã®ã¯ã1è¡ã®Pythonã³ãŒãã ãã§ãããã®åŸãããã«ãŒã¯Betterrcapãªã©ã®ç¹å¥ãªããŒã«ã䜿çšããŠãããã¯ãŒã¯ãã¹ãã€ãå§ããããšãã§ããŸãããã®æç¹ã§ãããã«ãŒã¯ãããã¯ãŒã¯ã調ã¹ãŠåµå¯ãè¡ããŸããããã©ãã£ãã¯ã¯ãŸã ã«ãŒã¿ãŒãééããŠããŸããæ»æè ã¯ãã¢ãã¬ã¹è§£æ±ºãããã³ã«ïŒARPïŒãæ¹ããããŠããããã¯ãŒã¯ã®æ§é ãå éšããå€æŽããå¯èœæ§ããããŸãã ARPã¯ãããã€ã¹ã®MACã¢ãã¬ã¹ããããã¯ãŒã¯äžã®IPã¢ãã¬ã¹ã«é¢é£ä»ããããã«ãããã¯ãŒã¯ããã€ã¹ã«ãã£ãŠäœ¿çšãããŸãã Bettercapã¯ã¡ãã»ãŒãžãéä¿¡ãããããã¯ãŒã¯äžã®ãã¹ãŠã®ããã€ã¹ã«ããã«ãŒã®ã³ã³ãã¥ãŒã¿ãŒãã«ãŒã¿ãŒãšèŠãªãããã«åŒ·å¶ããŸãããã®ããªãã¯ã䜿çšãããšãããã«ãŒã¯ã«ãŒã¿ãŒãééãããã¹ãŠã®ãããã¯ãŒã¯ãã©ãã£ãã¯ãååã§ããããã«ãªããŸãããã©ãã£ãã¯ããªãã€ã¬ã¯ãããããšãæ»æè ã¯Bettercapã¢ãžã¥ãŒã«ãèµ·åããŠDNSãã¹ããŒãã£ã³ã°ã§ããŸãããã®ã¢ãžã¥ãŒã«ã¯ãã¿ãŒã²ãããã¡ã€ã³ãžã®èŠæ±ãæ€çŽ¢ãã被害è ã«èª€ã£ãå¿çãéä¿¡ããŸãã誀ã£ãå¿çã«ã¯ãæ»æè ã®ã³ã³ãã¥ãŒã¿ã®IPã¢ãã¬ã¹ãå«ãŸããŠãããã¿ãŒã²ãããµã€ããžã®ãã¹ãŠã®èŠæ±ããæ»æè ã«ãã£ãŠäœæããããã£ãã·ã³ã°ããŒãžã«ãªãã€ã¬ã¯ããããŸããããã«ãŒã¯ããããã¯ãŒã¯äžã®ä»ã®ããã€ã¹å®ãŠã®ãã©ãã£ãã¯ã確èªããŸããå ¥åãããè³æ Œæ å ±ãåéããæªæã®ããããŠã³ããŒããæ¿å ¥ããŸãã
ããã«ãŒãããŒã«ã«ãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ã§ããªãå Žåãããã«ãŒã¯æ¬¡ã®ããããã®æ»æã«èšŽããŸãã
èªçæ¥æ»æã§çããåœé ãã
DNSã¯ååž°ã¯ãšãªãžã®å¿çãèªèšŒããªããããæåã®å¿çããã£ãã·ã¥ãããŸããæ»æè ã¯ãããããèªçæ¥ã®ãã©ããã¯ã¹ã䜿çšããŠãåœã®å¿çãäºæž¬ããŠèŠæ±è ã«éä¿¡ããããšããŸããèªçæ¥æ»æã¯ãæ°åŠãšç¢ºçè«ã䜿çšããŠäºæž¬ã ãŸãããã®å Žåãæ»æè ã¯DNSèŠæ±ã®ãã©ã³ã¶ã¯ã·ã§ã³IDãæšæž¬ããããšããŸããæåããå Žåãæ£åœãªå¿çã®åã«åœã®DNSã¬ã³ãŒããããªãã«å±ããŸããèªçæ¥æ»æãæåããããšã¯ä¿èšŒãããŠããŸããããæçµçã«ã¯æ»æè ã¯åœã®å¿çããã£ãã·ã¥ããããšãã§ããŸããæ»æãæåãããšãããã«ãŒã¯åœã®DNSã¬ã³ãŒãããDNSã¬ã³ãŒãã®ã©ã€ããµã€ã¯ã«ïŒTTLïŒã®çµãããŸã§ã®ãã©ãã£ãã¯ã確èªã§ããããã« ãªããŸãã..ã
èªçæ¥æ»æã®ããªãšãŒã·ã§ã³ã§ãããã®è匱æ§ãçºèŠããDanKaminskyã¯ã2008幎ã®BlackHatã«ã³ãã¡ã¬ã³ã¹ã§æåã«çºè¡šããŸããããã®ãšã¯ã¹ããã€ãã®æ¬è³ªã¯ãããã«ãŒãæåã«ååšããªããã¡ã€ã³ïŒfake.varonis.comãªã©ïŒã«å¯ŸããŠDNSãªãŸã«ããŒèŠæ±ãéä¿¡ããããšã§ãããã®ãããªèŠæ±ãåä¿¡ããåŸãDNSãªãŸã«ããŒã¯ãããæš©éã®ããããŒã ãµãŒããŒã«ãªãã€ã¬ã¯ãããŠãåœã®ãµããã¡ã€ã³ã®IPã¢ãã¬ã¹ãååŸããŸãããã®æç¹ã§ãæ»æè ã¯ããããã®åœã®å¿çã®1ã€ãå ã®èŠæ±ã®ãã©ã³ã¶ã¯ã·ã§ã³IDãšäžèŽããããšãæåŸ ããŠãèšå€§ãªæ°ã®åœã®å¿çã§DNSãªãŸã«ããŒãå§åããŸããæåããå Žåãããã«ãŒã¯ãããšãã°varonis.comã®äŸã®ããã«ãDNSãµãŒããŒãã£ãã·ã¥å ã®IPã¢ãã¬ã¹ãã¹ããŒãã£ã³ã°ããŸãããªãŸã«ããŒã¯ãåœã®varonis.comIPã¢ãã¬ã¹ãæ¬ç©ã§ãããšãããã¹ãŠã®èŠæ±è ã«åŒãç¶ãå¿çããŸããDNSã¬ã³ãŒãã®æå¹æéãåãããŸã§ã
DNS?
DNSãã£ãã·ã¥ããã€ãºãã³ã°ãããŠãããã©ãããæ€åºããã«ã¯ã©ãããã°ããã§ããïŒãããè¡ãã«ã¯ãæ»æã®å¯èœæ§ã®å åããªããDNSãµãŒããŒãç£èŠããå¿ èŠããããŸãããã ãããã®ãããªå€§éã®DNSèŠæ±ãåŠçããããã®èšç®èœåã¯èª°ã«ããããŸãããæåã®è§£æ±ºçã¯ãããŒã¿ã»ãã¥ãªãã£åæãDNSç£èŠã«é©çšããããšã§ããããã«ãããéåžžã®DNSã®åäœãšæªæã®ããæ»æãåºå¥ãããŸãã
â¢1ã€ã®ãã¡ã€ã³ã«å¯Ÿãã1ã€ã®ãœãŒã¹ããã®DNSã¢ã¯ãã£ããã£ã®çªç¶ã®å¢å ã¯ãèªçæ¥æ»æã®å¯èœæ§ã瀺ããŠããŸãã
â¢ååž°ãªãã§DNSãµãŒããŒã«è€æ°ã®ãã¡ã€ã³åãç §äŒããåäžã®ãœãŒã¹ããã®DNSã¢ã¯ãã£ããã£ã®å¢å ã¯ãåŸç¶ã®ãã€ãºãã³ã°ã®ããã«ã¬ã³ãŒããéžæããããšããŠããããšã瀺ããŠããŸãã
ã«å ã㊠DNSç£èŠã§ã¯ãç°åžžãªã¢ã¯ãã£ããã£ãæéå ã«æ€åºããããã«ãActiveDirectoryã€ãã³ããšãã¡ã€ã«ã·ã¹ãã ã®åäœãç£èŠããå¿ èŠã ãããŸããããã«è¯ãããšã«ãåæã䜿çšããŠã3ã€ã®ãã¯ãã«ãã¹ãŠã®éã®é¢ä¿ãèŠã€ããŸããããã«ããããµã€ããŒã»ãã¥ãªãã£æŠç¥ã匷åããããã®è²Žéãªã³ã³ããã¹ãæ å ±ãæäŸãããŸãã
DNSãã£ãã·ã¥ãã€ãºãã³ã°ããä¿è·ããæ¹æ³
ç£èŠãšåæã«å ããŠãDNSãµãŒããŒã®èšå®ãå€æŽã§ããŸãã
- ååž°ã¯ãšãªãå¶éããŠãæœåšçãªã¿ãŒã²ãããã£ãã·ã¥ãã€ãºãã³ã°ãé²ããŸãã
- èŠæ±ããããã¡ã€ã³ã«é¢é£ããããŒã¿ã®ã¿ãä¿åããŸãã
- å¿çããèŠæ±ããããã¡ã€ã³ã«é¢é£ãããã®ã ãã«å¶éããŸãã
- ã¯ã©ã€ã¢ã³ãã«HTTPSãããã³ã«ã®äœ¿çšãèŠæ±ããŸãã
ææ°ã®BINDããã³DNSãœãããŠã§ã¢ã䜿çšããŠããããšã確èªããŠãã ãããããã«ãããææ°ã®è匱æ§ããã¹ãŠä¿®æ£ãããŸããå¯èœã§ããã°ãããšãã°ãªã¢ãŒãã¯ãŒã«ãŒã®å Žåã¯ããã¹ãŠã®ãªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒãVPNçµç±ã§æ¥ç¶ãããããã«èª¿æŽããŸããããã«ããããã©ãã£ãã¯ãšDNSèŠæ±ãããŒã«ã«ã§ã¹ããŒãã³ã°ãããã®ãé²ããŸããããã«ããªã¹ã¯ã軜æžããããã«ãWi-Fiãããã¯ãŒã¯çšã®åŒ·åãªãã¹ã¯ãŒããäœæããããåŸæ¥å¡ã«å¥šå±ããŠãã ããã
æåŸã«ãæå·åãããDNSã¯ãšãªã䜿çšããŸãã ãã¡ã€ã³ããŒã ãµãŒãã¹ã»ãã¥ãªãã£ã¢ãžã¥ãŒã«ïŒDNSSECïŒã¹ããŒãã£ã³ã°ãé²ãããã«çœ²åãããDNSã¯ãšãªã䜿çšããDNSãããã³ã«ã§ãã DNSSECã䜿çšããå ŽåãDNSãªãŸã«ããŒã¯æ¿èªãããDNSãµãŒããŒã§çœ²åãæ€èšŒããå¿ èŠããããŸããããã«ãããããã»ã¹å šäœã®é床ãäœäžããŸãããã®çµæãDNSSECã¯ãŸã åºãåãå ¥ããããŠããŸããã
DNS over HTTPSïŒDoHïŒããã³ DNS over TLSïŒDoTïŒã¯DNSã®æ¬¡ã®ããŒãžã§ã³ã®ç«¶åããä»æ§ã§ãããDNSSECãšã¯ç°ãªããé床ãç ç²ã«ããããšãªãDNSã¯ãšãªãä¿è·ããããã«èšèšãããŠããŸãããã ãããããã®ãœãªã¥ãŒã·ã§ã³ã¯ãDNSã®é床ãäœäžãããããããŒã«ã«ã§ã®ç£èŠãšåæãå®å šã«äžå¯èœã«ãããããå¯èœæ§ããããããçæ³çã§ã¯ãããŸããã DoHãšDoTã¯ããããã¯ãŒã¯ã«èšå®ãããŠãããã¢ã¬ã³ã¿ã«ã³ã³ãããŒã«ããã®ä»ã®DNSã¬ãã«ã®ãããã¯ããã€ãã¹ã§ããããšã«æ³šæããŠãã ããããšã«ãããCloudflareãQuad9ãããã³Googleã«ã¯ãDoTããµããŒããããããªãã¯DNSãµãŒããŒããããŸããå€ãã®æ°ããã¯ã©ã€ã¢ã³ãã¯ãããã®ææ°ã®æšæºããµããŒãããŠããŸããããµããŒãã¯ããã©ã«ãã§ç¡å¹ã«ãªã£ãŠããŸãã詳现ã«ã€ããŠã¯ãDNSã»ãã¥ãªãã£ã«é¢ããæçš¿ãã芧ãã ãã ã
DNSã¹ããŒãã£ã³ã°ã¯ããµã€ãã®æ£åœãªIPã¢ãã¬ã¹ãããã«ãŒã®ã³ã³ãã¥ãŒã¿ãŒã®IPã¢ãã¬ã¹ã«çœ®ãæããŸãããšã³ããŠãŒã¶ãŒã®èŠ³ç¹ããã圌ã¯ãã©ãŠã¶ã«å®å šã«éåžžã®Webãµã€ãã®ã¢ãã¬ã¹ãå ¥åããããã眮æãæ€åºããããšã¯éåžžã«å°é£ã§ããããã«ããããããããã®ãããªæ»æã¯æ¢ããããšãã§ããŸãããªã¹ã¯ã¯ãããšãã°Varonisããã®DNSç£èŠãããã³DNS over TLSïŒDoTïŒæå·åæšæºã䜿çšããããšã§è»œæžã§ããŸã ã
ãã£ãã·ã¥ãã€ãºãã³ã°ïŒãããã質å
äžè¬çãªDNSã¹ããŒãã£ã³ã°ã®è³ªåãšåçã確èªããŠãã ããã
DNSãã£ãã·ã¥ãã€ãºãã³ã°ãšDNSãã£ãã·ã¥ã¹ããŒãã£ã³ã°ïŒã¹ããŒãã£ã³ã°ïŒã¯åãã§ããïŒ
ã¯ããåãã¿ã€ãã®ãµã€ããŒæ»æã¯ããã£ãã·ã¥ãã€ãºãã³ã°ããã³ãã£ãã·ã¥ã¹ããŒãã£ã³ã°ãšåŒã°ããŸãã
DNSãã£ãã·ã¥ãã€ãºãã³ã°ã¯ã©ã®ããã«æ©èœããŸããïŒ
ãã£ãã·ã¥ãã€ãºãã³ã°ã¯ãDNSãµãŒããŒãã ãŸããŠåœã®DNSã¬ã³ãŒããæ ŒçŽãããŸãããã®åŸããã©ãã£ãã¯ã¯ããã«ãŒãéžæãããµãŒããŒã«ãªãã€ã¬ã¯ããããããã§ããŒã¿ãçãŸããŸãã
DNSãã£ãã·ã¥ãã€ãºãã³ã°ããä¿è·ããããã«ã©ã®ãããªã»ãã¥ãªãã£å¯Ÿçãé©çšã§ããŸããïŒ
ãµã€ãææè ã¯ãç£èŠãšåæãå®è¡ããŠDNSã¹ããŒãã£ã³ã°ãæ€åºã§ããŸãã DNSãµãŒããŒãæŽæ°ããŠããã¡ã€ã³ããŒã ã·ã¹ãã ã»ãã¥ãªãã£ã¢ãžã¥ãŒã«ïŒDNSSECïŒããDNS overHTTPSãDNSoverTLSãªã©ã®å¥ã®æå·åã·ã¹ãã ã䜿çšããããšãã§ããŸãã HTTPSãªã©ã®å®å šãªãšã³ãããŒãšã³ãæå·åãåºã䜿çšããããšã§ãDNSã¹ããŒãã£ã³ã°ãé²ãããšãã§ããŸããã¯ã©ãŠãã¢ã¯ã»ã¹ã»ãã¥ãªãã£ãããŒã«ãŒïŒCASBïŒã¯ããããã®ç®çã«éåžžã«åœ¹ç«ã¡ãŸãããšã³ããŠãŒã¶ãŒã¯ããã©ãŠã¶ã®DNSãã£ãã·ã¥ãå®æçã«ãã©ãã·ã¥ããããå®å šã§ãªããããã¯ãŒã¯ãŸãã¯ãããªãã¯ãããã¯ãŒã¯ã«æ¥ç¶ããåŸã«ããªãããŸãã®å¯èœæ§ã®ããDNSãã£ãã·ã¥ããã©ãã·ã¥ã§ããŸãã VPNã䜿çšãããšãããŒã«ã«ãããã¯ãŒã¯ã§ã®DNSã¹ããŒãã£ã³ã°ããä¿è·ã§ããŸããçããããªã³ã¯ã¯é¿ããŠãã ãããããã«ããããã©ãŠã¶ã®ãã£ãã·ã¥ãæ±æãããªã¹ã¯ãåé¿ã§ããŸãã
ãã£ãã·ã¥ãã€ãºãã³ã°æ»æã«èŠèããããã©ãããã©ã®ããã«ç¢ºèªã§ããŸããïŒ
DNSãã£ãã·ã¥ããã€ãºãã³ã°ããããšãæ€åºãå°é£ã«ãªããŸããããè¯ãæŠè¡ã¯ãããŒã¿ãç£èŠãããã«ãŠã§ã¢ããã·ã¹ãã ãä¿è·ããŠãDNSãã£ãã·ã¥ãã€ãºãã³ã°ã«ããããŒã¿æŒæŽ©ãã身ãå®ãããšã§ããã€ã³ã¿ã©ã¯ãã£ããªãµã€ããŒæ»æã©ãã«ã¢ã¯ã»ã¹ããŠã DNSã¢ãã¿ãªã³ã°ã䜿çšããŠå®éã®ãµã€ããŒã»ãã¥ãªãã£ã®è åšãæ€åºããæ¹æ³ã確èªããŠãã ããã
DNSéä¿¡ã¯ã©ã®ããã«æ©èœããŸããïŒ
ãšã³ããŠãŒã¶ãŒãVaronis.comãªã©ã®URLããã©ãŠã¶ãŒã«å ¥åãããšã次ã®ããšãçºçããŸãã
- ãã©ãŠã¶ã¯ãŸããããŒã«ã«ãã£ãã·ã¥ã§ãã§ã«ä¿åãããŠããDNSããŒã¿ã確èªããŸãã
- ãã®ããŒã¿ãæ¬ èœããŠããå Žåã¯ãã¢ããã¹ããªãŒã DNSãµãŒããŒïŒéåžžã¯ããŒã«ã«ãããã¯ãŒã¯äžã®ã«ãŒã¿ãŒïŒã«ã¯ãšãªãå®è¡ããŸãã
- DNS, , DNS, Google, Cloudflare Quad9.
- DNS- .
4.1. , DNS-, DNS « .com».
4.2. .com, « Varonis.com», URL.
4.3. « IP- Varonis.com», IP- . - DNSããŒã¿ã¯ããšã³ããŠãŒã¶ãŒã®ããã€ã¹ã«å°éãããŸã§ãã§ãŒã³ã®äžæµã«éãè¿ãããŸããã«ãŒãå šäœã«æ²¿ã£ãŠãåDNSãµãŒããŒã¯åä¿¡ããå¿çãç¬èªã®ãã£ãã·ã¥ã«æžã蟌ãã§ããã«äœ¿çšããŸãã
æ»æè ã¯ã©ã®ããã«ããŠDNSãã£ãã·ã¥ãæ±æããŸããïŒ
ãã£ãã·ã¥ããã€ãºãã³ã°ããæ¹æ³ã¯ãããããããŸãããæãäžè¬çãªæ¹æ³ã¯æ¬¡ã®ãšããã§ãã被害è ã«ãåã蟌ãŸããã³ãŒãã䜿çšããŠãŠãŒã¶ãŒã®ãã©ãŠã¶ã®DNSãã£ãã·ã¥ãå€æŽããæªæã®ãããªã³ã¯ãã¯ãªãã¯ãããããäžéè æ»æãã䜿çšããŠããŒã«ã«DNSãµãŒããŒããããã³ã°ãããåè¿°ã®ãäžéè æ»æãã¯ãã¢ãã¬ã¹è§£æ±ºãããã³ã«ïŒARPïŒã¹ããŒãã£ã³ã°ã䜿çšããŠãDNSèŠæ±ãæ»æè ãå¶åŸ¡ããDNSãµãŒããŒã«ãªãã€ã¬ã¯ãããŸãã
DNSãã£ãã·ã¥ãã€ãºãã³ã°ãšã¯äœã§ããïŒ
DNSãã£ãã·ã¥ãã€ãºãã³ã°ã¯ãDNSããŒã¿ããŒã¹ã®ãšã³ããªãIPã¢ãã¬ã¹ã«çœ®ãæããŠãæ»æè ã«ãã£ãŠå¶åŸ¡ãããæªæã®ãããµãŒããŒã«ã€ãªããè¡çºã§ãã
DNSã¹ããŒãã£ã³ã°ã¯ã©ã®ããã«å®è¡ãããŸããïŒ
ããã«ãŒã¯ãã¢ã¯ã»ã¹ãååŸããŠDNSãã£ãã·ã¥ãå€æŽããããDNSã¯ãšãªãèªåã®DNSãµãŒããŒã«ãªãã€ã¬ã¯ãããããšã«ãããDNSã¹ããŒãã£ã³ã°æ»æãå®è¡ããŸãã
DNSã¹ããŒãã£ã³ã°ãšã¯äœã§ããïŒ
DNSã¹ããŒãã£ã³ã°ãšã¯ããŠãŒã¶ãŒãvaronis.comãªã©ã®ãã©ãŠã¶ã«å ¥åããURLããå®éã«ã¯ãã®URLã«é¢é£ä»ããããæ£ããå ¬åŒIPã¢ãã¬ã¹ã«ã€ãªãã£ãŠããªãããšãæå³ããŸãã代ããã«ããŠãŒã¶ãŒã¯ããã«ãŒã«ãã£ãŠå¶åŸ¡ãããŠããæªæã®ãããµãŒããŒã«ãªãã€ã¬ã¯ããããŸãã
DNSã¹ããŒãã£ã³ã°ãå±éºãªã®ã¯ãªãã§ããïŒ
DNSã¹ããŒãã£ã³ã°ã¯ããã®æ§è³ªäžããã¡ã€ã³ããŒã ã·ã¹ãã ïŒDNSïŒãä¿¡é Œã§ãããšèããããŠããããå±éºã§ãããã®ãããDNSã¹ããŒãã£ã³ã°ã¯ããããªãçš®é¡ã®æå·åã«ãã£ãŠãä¿è·ãããŠããªãããšããããããŸããããã«ãããããã«ãŒã¯DNSãã£ãã·ã¥å ã®ã¬ã³ãŒããã¹ããŒãã£ã³ã°ããŠãããŒã¿ãããã«çã¿ããã«ãŠã§ã¢ãæ³šå ¥ãããã£ãã·ã³ã°ãè¡ããæŽæ°ããããã¯ããå¯èœæ§ããããŸãã
DNSã¹ããŒãã£ã³ã°æ»æã«ãã£ãŠåŒãèµ·ããããäž»ãªè åšã¯ããã£ãã·ã³ã°ããŒãžãä»ããããŒã¿ã®çé£ã§ããããã«ãæ¬ç©ã®ããã«èŠããããŠã³ããŒãå¯èœãªãã¡ã€ã«ãè£ ã£ãŠãã«ãŠã§ã¢ãå°å ¥ããããªã¹ã¯ããããŸãããŸããã·ã¹ãã ãã€ã³ã¿ãŒãããçµç±ã§æŽæ°ãããå Žåãæ»æè ã¯DNSã¬ã³ãŒããå€æŽããŠæŽæ°ããããã¯ããç®çã®ãµã€ãã«èªå°ãããªãããã«ããããšãã§ããŸãã