¾ÅÓÎÀÏ¸ç¿Æ¼¼ÁõÎÄí®RSACÖ÷ÌâÑݽ²:ÎïÁªÍøÖлùÓÚUDPµÄDDoSÐÂÐÍ·´Éä¹¥»÷Ñо¿
2021-05-20
RSA×÷ΪȫÇò¹æÄ£×î´óµÄÍøÂçÇå¾²ÐÐÒµ¾Û»á£¬Æù½ñÒѾÙÐÐ30½ì£¬Ò»Ö±×ÅÑÛÓÚÍÆ¶¯È«ÇòÍøÂçÇå¾²½çµÄ¹²Ïí¡¢Á¢ÒìÓëǰ½ø¡£2021ÄêRSA´ó»á£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍÑÓ±¶ø³ö£¬ÔÚÎïÁªÍøÇå¾²ÂÛ̳½ÒÏþÌâΪ¡¶ÎïÁªÍøÖлùÓÚUDPµÄDDoSÐÂÐÍ·´Éä¹¥»÷Ñо¿¡·£¨Research on New Vectors of UDP-Based DDoS Amplification Attacks of IoT£¬[SAT-M19]£©µÄÖ÷ÌâÑݽ²£¬ÕâÊÇÖйúÇå¾²³§ÉÌÊ״εÇÉÏRSAC´ó»áµÄÖ÷ÌâÑݽ²Îę̀¡£¾ÅÓÎÀÏ¸ç¿Æ¼¼Á¢ÒìÖÐÐÄ×ܼàÁõÎÄí®²©Ê¿´ú±í¾ÅÓÎÀÏ¸ç¿Æ¼¼µÄÎïÁªÍøÇå¾²Ñо¿ÍŶӾÙÐÐÁËÖ÷ÌâÑݽ²¡£

ÏÂÃæ£¬¾ÅÓÎÀϸç¾ýÓë¸÷ÈËÒ»ÆðÀ´Ñ§Ï°¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÚRSA2021´ó»áÉÏ·ÖÏíÓ¢»ª£º

1. È«ÇòÎïÁªÍø×ʲú̻¶ÇéÐÎ
Ëæ×ÅÔ½À´Ô½¶àµÄÎïÁªÍø×°±¸½ÓÈ뻥ÁªÍø£¬ÎïÁªÍøÁªÍøÊýÌìÌì¶¼ÔÚÔöÌí¡£Í¨¹ý¶Ô»¥ÁªÍøÉÏ×°±¸¾ÙÐÐɨÃ裬ÎÒÃÇ·¢Ã÷È«ÇòÁè¼Ý70000¸ö¿ª·ÅWS-Discovery¡¢OpenVPNºÍCoAPÐÒéµÄÎïÁªÍø·þÎñ¡£
²»µ«Çå¾²³§ÉÌ¿ÉÒÔ·¢Ã÷ÕâЩÎïÁªÍøÌ»Â¶×ʲú£¬¹¥»÷ÕßÒ²Äܹ»·¢Ã÷ÕâЩ×ʲú¡£Í¨¹ýɨÃèÆ÷¡¢½©Ê¬ÍøÂç»òÈκοÉÒÔʹÓõŤ¾ß·¢Ã÷ÎïÁªÍø×ʲúºó£¬ÕâЩ×ʲú»áÈÝÒ×Ôâµ½¹¥»÷£¬ÒÔ¼°±»Ê¹ÓÃÀ´¾ÙÐÐÌᳫ¹¥»÷¡£

2. ÃÀ¹úÊÇÔâÊÜ·Å´ó·´ÉäDDoS¹¥»÷Ó°Ïì×î´óµÄ¹ú¼Ò
ͨ¹ýÎïÁªÍøÃÛ¹Þ²¶»ñºÍÍøÂçÊܺ¦ÕßµÄIPµØµã£¬ÔÚÅÌËãÄ¿µÄIPµØµãµÄµØÀíλÖú󣬿ÉÒÔ¿´µ½ÃÀ¹úÊÜ·Å´ó·´ÉäDDoS¹¥»÷µÄÓ°Ïì×î´ó¡£
ÎÞÂÛÊÇÀÕË÷Èí¼þÕÕ¾ÉDDoS¹¥»÷£¬¶¼¿ÉÒÔ×÷ΪһÖÖºÚ²ú·þÎñ£¬´ËǰÒѾÔÚ°µÍøÉÏ·ºÆðÃ÷Âë±ê¼ÛÌṩ×âÓÃDDoS·þÎñ£¬¶øÌ»Â¶µÄųÈõÎïÁªÍø×°±¸³ÉΪÁ˺ڲúDZÔڵĹ¥»÷ÎäÆ÷¡£Ë¼Á¿µ½ÃÀ¹úÖØ´óµÄÉÌÒµºÍIT¹¤Òµ£¬Ëü³ÉΪÁËÍøÂç·¸·¨µÄ×î´óÄ¿µÄ¡£

3. WS-DiscoveryÐÒéÏÈÈÝ
WS-DiscoveryÊÇ»ùÓÚUDPµÄ¡¢ÓÃÓÚWeb·þÎñ·¢Ã÷µÄµ¥²¥ÐÒé¡£ÆäÊÂÇéÔÀíÊǿͻ§¶Ë·¢ËÍUDP̽²âÐÂÎÅËÑË÷·þÎñ£¬È»ºóÆÚ´ýÓ¦´ð¡£¸ÃÐÒéÏêϸ±»ÀÄÓõÄÇéÐÎÊÇ£º¹¥»÷Õß·¢ËÍÒ»¸ö3×Ö½ÚµÄÇëÇó£º3c¡¢aa¡¢3e£¬²¢Ð¯´øÒ»¸öÓÕÆµÄÔ´µØµã£¬·þÎñ»á»Ø¸´Ò»¸ö1590×Ö½ÚµÄÏìÓ¦¡£
ÕâÀïʹÓÃÁËBAF(bandwidth amplification factor)´ø¿í·Å´óϵͳµÄ¿´·¨£¬×îÔçÔÚ2014ÄêNDSSµÄһƪÂÛÎÄ¡¶Amplification Hell: Revisiting Network Protocols for DDoS Abuse¡·ÖÐÌáµ½µÄ¡£ÎªÁËÅÌËãBAF£¬¿ÉÒÔ½«ÓÐÓøºÔØ·¢Ë͸øÊ¹ÓÃÕæÊµÔ´µØµã¹ûÕæµÄËùÓзþÎñ£¬ÑéÖ¤»ñµÃµÄÏìӦЧ¹ûÊý¾Ý¡£¾ÓɲâÊÔ£¬·¢Ë͵ÄÇëÇóµÄ³¤¶È3×Ö½Úʱ£¬ÊÕµ½µÄÏìÓ¦µÄƽ¾ù³¤¶ÈÊÇ1330£¬ÅÌËã³öBAFÊýÖµÊÇ443¡£Ê¹ÓøÃÐÒéÎó²î£¬Í¨¹ýWS-Discovery¿ÉÒÔ±¬·¢±ÈÇëÇóÁ÷Á¿´ó400¶à±¶ÒÔÉϵĶñÒâÁ÷Á¿¡£

4. ADDP×ÊÖú¹¥»÷ÕßÕÒµ½±£´æRipple20Îó²îµÄ×°±¸
ADDPÊǸ߼¶×°±¸·¢Ã÷ÐÒé(Advanced Device Discovery Protocol)£¬ÊÇDigi International¹«Ë¾¿ª·¢µÄ»ùÓÚUDPµÄ¶à²¥ÐÒé¡£½èÖúADDP£¬ÎÞÂÛÍøÂçÔõÑùÉèÖã¬×°±¸¶¼¿ÉÒÔÔÚÍâµØÍøÂçÉÏ·¢Ã÷ÆäËû×°±¸¡£¾ÓÉÈ«ÍøÉ¨Ãè²âÊÔ£¬ÎÒÃÇ·¢Ë͵ÄÇëÇóµÄ³¤¶ÈÊÇ14×Ö½Ú£¬¶øÊÕµ½µÄÏìÓ¦µÄƽ¾ù³¤¶ÈÊÇ141.7×Ö½Ú£¬¶ÔÓ¦µÄBAFÊÇ10.1¡£
ÊÂʵÉÏ£¬ADDP±»Ðí´ó¶¼ÂëÍøÂç×°±¸Ê¹Ó㬴ó×ÚÕâЩװ±¸¿ÉÄܱ£´æRipple20Îó²î¡£Òò¶ø£¬¹¥»÷Õß¿ÉÒÔͨ¹ý·¢Ã÷̻¶µÄADDP·þÎñ£¬ÔÙÑéÖ¤Ripple20Îó²î£¬Ôò¿ÉÒÔÌᳫһЩ¹¥»÷¡£

³ýÁËWS-Discovery¡¢ADDPÖ®Í⣬±¨¸æ»¹ÆÊÎöÁËOpenVPNÐÒéµÄųÈõÐÔ£¬±ðµÄ¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÚ2018¡¢2019ºÍ2020ÄêÐû²¼µÄ¡¶ÎïÁªÍøÇå¾²Ä걨¡·ÖÐÆÊÎöÁËSSDP¡¢DHDiscover¡¢UbiquitiµÈÐÒ飬ÕâЩÎïÁªÍøÐÒé¶¼±£´æÏàËÆµÄųÈõÐÔ£º»ùÓÚUDP¡¢Ö§³Öµ¥²¥¡¢ÏìÓ¦Ô¶´óÓÚÇëÇ󳤶ȣ¬Òò¶øÈÝÒ×±»Ê¹Ó÷¢¶¯DDoS¹¥»÷¡£ÊÂʵÉÏ£¬ÔÚ2017Äêºó£¬Ê¹ÓÃÎïÁªÍøÐÒé·¢¶¯DDoS¹¥»÷ٲȻ³ÉΪÁ˹¥»÷ÕßµÄÖ÷ҪѡÔñ¡£
5. һЩ½¨æÅºÍ¿´·¨
¸øÎïÁªÍø³§É̽¨Ò飺
Ê×ÏÈÉèÖÃÊ×ϯÇå¾²¹Ù£¬×齨Çå¾²ÍŶӡ£Æä´ÎÔÚÉè¼Æ»·½Ú£¬Ä¬ÈϽûÓ÷þÎñ/×°±¸·¢Ã÷¹¦Ð§£¬·Ç¶à²¥²»ÏìÓ¦£¬·ÇÄÚÍø²»ÏìÓ¦¡£×îºóÔÚÔËÓª»·½Ú£¬½¨ÉèÓ¦¼±ÏìÓ¦Á÷³Ì²¢ÊµÊ±Ðû²¼Çå¾²²¹¶¡¡£
¸ø×îÖÕÓû§ºÍ»ú¹¹µÄ½¨Ò飺
ʶ±ð×ÔÓеÄÎïÁªÍø×°±¸£¬¼ì²éÉèÖᢻá¼û¿ØÖÆÕ½ÂÔ£»Ò»Á¬µØÊ¹ÓÃÍøÂç¿Õ¼ä²â»æÊÖÒÕ¼à¿ØÌ»Â¶×ʲú£»¹¹½¨Ê¶±ð-ÆÀ¹À-ÖÎÀíµÄÇå¾²ÔËÓª±Õ»·£¬½«ÎïÁªÍøÇå¾²ÈÚÈ뵽ͳһµÄÇå¾²ÔËӪϵͳÄÚ¡£
¸øÎïÁªÍø¿Í»§µÄ½â¾ö¼Æ»®£º
¹Ø×¢¶¼»á¡¢ÆóÒµÎïÁªÍøÇå¾²Òþ»¼£¬ ×ÛºÏչʾÎïÁªÍø¸÷±ÊÖ±ÁìÓòΣº¦Ì¬ÊÆ£¬¸÷µØÇø¡¢²¿·ÖÍþвÇéÐΣ¬Ê¹ÓþÅÓÎÀϸçÎïÁªÍø±£»¤É¡½â¾ö¼Æ»®£¬Í¨¹ýÖÕ¶ËSDK¡¢¹Ì¼þ¼ì²â¡¢×¼ÈëÍø¹Ø¡¢ÎïÁª¿¨ÆÊÎö¡¢ÎïÁªÍøÇå¾²²âÆÀµÈ¶à¸öϵͳµÄÊý¾Ý£¬Ö§³ÖÎïÁªÍøÇå¾²Ì¬ÊÆ¡£

δÀ´Ò»¶Îʱ¼äÄÚ£¬¸ü¶àÎïÁªÍøÐæÅºÍ×°±¸µÄÎó²î»áÒ»Ö±·ºÆð£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼Í¨¹ýÁ¢ÒìÖÐÐÄ¡¢¸ñÎïʵÑéÊÒ¡¢ÎïÁªÍøÇå¾²²úÆ·²¿µÄÍŽᣬÆðµ½ÁËÑС¢²ú¡¢ÓõÄÍŽᣬͨ¹ýÎïÁªÍø±£»¤É¡½â¾ö¼Æ»®£¬Îª¿í´óÎïÁªÍøÇå¾²³¡¾°¿Í»§Ìṩ±£¼Ý»¤º½¡£
¾ÅÓÎÀÏ¸ç¿Æ¼¼ºã¾ÃÖÂÁ¦ÓÚÎïÁªÍøÇå¾²Ñо¿£¬ÔÚÎïÁªÍøsdk¡¢³µÁªÍøÇå¾²µÈ·½ÃæÈ¡µÃÁËÏÔÖøµÄÑо¿Ð§¹û¡£
¾ÅÓÎÀÏ¸ç¿Æ¼¼³µÂ·ÐÍ¬ÍøÂçÇå¾²ÊÖÒռƻ®£¬ ×ÅÑÛÓÚ¹æÄ£»¯³µÂ·ÐͬӦÓ㬽ÓÄÉÁ˳µÔØ¿ÉÐż¶Çå¾²SDK+·²àÖÇÄÜÇå¾²Íø¹Ø+Çå¾²ÔËӪƽ̨¶Ëµ½¶ËµÄÇå¾²Áª¶¯¼Ü¹¹Ä£Ê½£¬¹¹½¨¼à²â¡¢¼ì²â¡¢Ô¤¾¯¡¢·ÀÓù¡¢ÏìÓ¦ÓëÓ¦¼±´¦Öóͷ£Çå¾²ÄÜÁ¦£¬ÖÜÈ«ÁýÕÖ¸ÐÖª²à¡¢´«Êä²à¡¢Æ½Ì¨/Ó¦Óòà·À»¤³¡¾°£¬ÎªÖÇÄܽ»Í¨ÁìÓòµÄÍøÂçÇå¾²±£¼Ý»¤º½¡£

ͨ¹ý³µÁªÍøÖն˼°Æ½Ì¨Ì½Õë°²ÅÅ¡¢ÍþвÇ鱨ÊÕÂ޵ȣ¬ÍøÂ糵·ÐÍ¬Í¨Ñ¶ÍøÄÚÇå¾²Êý¾ÝÐÅÏ¢£¬²¢»ùÓÚ´óÊý¾Ý¹ØÁªÆÊÎö´¦Öóͷ££¬ÐγÉÁË×Ô¶¯Ì½²â¡¢±»¶¯ÓÕ²¶¡¢Á÷Á¿ÆÊÎö¡¢½©Ä¾Èä¡¢DDoS¹¥»÷¡¢APT¼ì²âµÈÇå¾²¼à²â¡¢¼ì²â¡¢Ô¤¾¯¡¢·ÀÓù¡¢ÏìÓ¦ÓëÓ¦¼±´¦Öóͷ£Çå¾²ÄÜÁ¦£¬ÍŽáÇå¾²×Éѯ¡¢ÉøÍ¸²âÊÔ¡¢È«ÉúÃüÖÜÆÚÇå¾²·ç¿ØµÈÇå¾²·þÎñ£¬¹¹½¨³µÂ·ÐͬÇå¾²ÔËӪϵͳ£»´Ó¼Æ»®¼ÛÖµ¿´£¬Äܹ»Öª×㳵·ÐͬÇå¾²ºÏ¹æ¼°Ð»ù½¨ÍøÂçÇå¾²½¨ÉèÇå¾²ÆÈÇÐÐèÇ󣬽øÒ»²½°ü¹ÜÕû¸ö³µÂ·ÐͬӦÓÃÇå¾²¡¢¿É¿Ø¡¢¿µ½¡Éú³¤¡£
ÔÚ¾ÅÓÎÀÏ¸ç¿Æ¼¼¹Ù·½Î¢Ðźǫ́»Ø¸´“RSAÑݽ²PPT”£¬¼´¿ÉÏÂÔØÔ¢Ä¿ÁõÎÄí®²©Ê¿Ñݽ²½ºÆ¬¡£

¾ÅÓÎÀϸçÔÆ







