2001001217-2.PDF



Similar documents
2

perimeter gateway

橡C16.PDF

- 1 -

集中講義 インターネットテクノロジー 第5回

IW2002-B5 1 Internet Week ( ) 9:30 12:30 ( ) Copyright 2002 All Rights Reserved, by Seiji Kumagai ADSL FTTH 24 IP LAN

1. 2. ( ) Secure Secure Shell ssh 5. (xinetd TCP wrappers) 6. (IPsec) 7. Firewall 2

目次

2004 SYN/ACK SYN Flood G01P014-6

IP Windows Word Excel Web Web Word Excel XHTML CSS Web Windows Word Excel Web XHTML CSS


お客様システムにおけるセキュリティ施策

SRT/RTX/RT設定例集

設定例集_Rev.8.03, Rev.9.00, Rev.10.01対応

untitled

Mac OS X Server QuickTime Streaming Server 5.0 の管理(バージョン 10.3 以降用)

1 Linux UNIX-PC LAN. UNIX. LAN. UNIX. 1.1 UNIX LAN. 1.2 Linux PC Linux. 1.3 studenta odd kumabari studentb even kumabari studentc odd kumabari student

橡不正アクセス環境別詳細対策集.PDF

main.dvi

内閣官房情報セキュリティセンター(NISC)

UCE DOS ( )

NATディスクリプタ機能

インターネット利用ソリューション

guide.PDF

PDF

WIDE 1

untitled

橡sirahasi.PDF

TCP/IP Internet Week 2002 [2002/12/17] Japan Registry Service Co., Ltd. No.3 Internet Week 2002 [2002/12/17] Japan Registry Service Co., Ltd. No.4 2

FirePass Edge Client TM Edge Client LAN Edge Client 7.0 Edge Client Edge Client Edge Client Edge Client Edge Client Edge Client LAN Edge Client VPN Wi

橡C22.PDF

shibasaki(印刷用)

1-index.PDF

untitled

はじめに

untitled

スタートアップガイド《YSシリーズ》

A/B WWW MTA/MSP sendmail POP/IMAP apache WWW 1 1 sendmail uw imap apache WWW host host subnet1: /24 IF1: router & server mail and

ヤマハ ルーター ファイアウォール機能~説明資料~

Si-R30取扱説明書

atama.dvi

e164.arpa DNSSEC Version JPRS JPRS e164.arpa DNSSEC DNSSEC DNS DNSSEC (DNSSEC ) DNSSEC DNSSEC DNS ( ) % # (root)

Microsoft Word - マニュアル4.1J

IW2001-B2 1 Internet Week 2001 ( ) Copyright 2001 All Rights Reserved, by Seiji Kumagai IW2001-B2 2 CodeRed Copyright 2001 All Rights

第1章 調査の概要

10/ / /30 3. ( ) 11/ 6 4. UNIX + C socket 11/13 5. ( ) C 11/20 6. http, CGI Perl 11/27 7. ( ) Perl 12/ 4 8. Windows Winsock 12/11 9. JAV

LAN

i TCP/IP NIC Intel 3com NIC TCP/IP *1 20 IPv4 IPv6 IPv6 TCP/IP TCP/IP *1 3

0 TOSHIBA TEC CORPORATION All rights reserved

DNS DNS(Domain Name System) named(bind), tinydns(djbdns), MicrosoftDNS(Windows), etc 3 2 (1) ( ) IP IP DNS 4

BIND 9 BIND 9 IPv6 BIND 9 view lwres

使用説明書

VNSTProductDes3.0-1_jp.pdf

johokiso-internet

untitled

SCREENOS NAT ScreenOS J-Series(JUNOS9.5 ) NAT ScreenOS J-Series(JUNOS9.5 ) NAT : Destination NAT Zone NAT Pool DIP IF NAT Pool Egress IF Loopback Grou

PowerPoint プレゼンテーション

untitled

RouteMagic Controller RMC-MP200 / MP Version

ルータ(IPv6)掲示用池田.PDF

RouteMagic Controller RMC-MP200 / MP Version

2.

untitled

worm hoihoi

Si-R30取扱説明書

Microsoft PowerPoint - 情報システム pptx

untitled

Northern Lights Server

ScreenOS 5.0 ScreenOS 5.0 Deep Inspection VLAN NetScreen-25/-50/-204/-208 HA NetScreen-25 HA Lite NetScreen-25 NetScreen-50) ALG(Application Layer Gat

1. 2

IT講習会

ネットワーク監視による不正アクセス発見手法

AirMac ネットワーク for Windows

fusion.PDF

FileMaker Server Getting Started Guide

Mac OS X Server Windows NTからの移行

untitled

Testing XML Performance

08+11Extra

RouteMagic Controller( RMC ) 3.6 RMC RouteMagic RouteMagic Controller RouteMagic Controller MP1200 / MP200 Version 3.6 RouteMagic Controller Version 3

GA-1200J

Microsoft Windows, Windows CE, Microsoft Corporation Citrix ICA Citrix Presentation Server Citrix Systems, Inc IBM IBM Corporation

KASPERSKY ENDPOINT SECURITY FOR BUSINESS IT IT IT IT IT Kaspersky Endpoint Security for Business IT IT IT IT 2013 NAC Advanced 2013 Select Select Work

橡C12電子メール最新技術動向revisd.PDF

(O) (N) (V) (N) kuins-pptp (N) 2

ヤマハ ルーター ファイアウォール機能~説明資料~

AirMac ネットワーク構成の手引き

2 1: OSI OSI,,,,,,,,, 4 TCP/IP TCP/IP, TCP, IP 2,, IP, IP. IP, ICMP, TCP, UDP, TELNET, FTP, HTTP TCP IP

untitled

FileMaker Server Getting Started Guide

クララパンフレット2011冬1P-P40

InterSafe Personal_v2.3 ユーザーズガイド_初版

rec-lan1.PDF

konicaminolta.co.jp PageScope Net Care

wide94.dvi

<834E C F D E657073>

設定例集

IP IP DHCP..

Mac OS X Server メールサービスの管理(バージョン 10.3 以降用)

PowerPoint プレゼンテーション

Transcription:

120000 (2001/12/6-16) 10 100000 80000 60000 40000 20000 0 12/6 12/7 12/8 12/9 12/10 12/11 12/12 12/13 12/14 12/15 12/16 :SPAM 120000 100000 80000 60000 40000 20000 ddos_ddos-shaft-synflood-incoming INFO - Possible Squid Scan SCAN Proxy attempt web-misc_http-cgi-space-wildcard netbios_netbios-name-query rpc_tcp_traffic_contains_bin_sh TCP ******S* scan Concept-Nimda(root.exe) Concept-Nimda 3 10 SPAM RBL(Realtime Blackhole List) RBL : 3 0 12/6 12/7 12/8 12/9 12/10 12/11 12/12 12/13 12/14 12/15 12/16 : : Cracker ls ps : OS FTP 1

:Nimda : Web Nimda Web Nimda IIS : Nimda Personal Firewall (1/3) (2/3) 100% (3/3) 2

? W97.Melissa.A Worm W32.Sircam.Worm@mm, W32.Badtrans.B@mm OS HTML PREVIEW HTML JavaScript Java 3

CPU http://www.trendmicro.co.jp http://www.symantec.com OS fmlvirus_check.pl Windows!? (1/3) : OS (2/3) (3/3) : Redhat Linux: /sbin/chconfig del FreeBSD: /etc/rc.conf Windows NT/2000/XP inetd /etc/inetd.conf netstat na 4

(1/2) (2/2) : IIS wu-ftpd Script kiddies C : http://www.jpcert.or.jp/ http://www.cert.org/ http://www.ipa.go.jp/security/ 3 Firewall Firewall Firewall = Firewall Internet / Firewall Firewall ActiveX Java Web Firewall Web /PHS ISP ( 2 ) Firewall 5

Firewall (1/2) / IP IP Proxy (2/2) NAT Network Address Translation RFC1631:The IP Network Address : IP / Translation IP 203.178.142.133 203.178.142.133 IP 11 Filter IP 133.27.4.121 NAPT 1 IP 133.4..34.39 IP Masquerade NAT NAT 192.168.0.2 192.168.0.3 192.168.0.4 192.168.0.5 End-to-End IP 133.27.24.254 192.168.0.1 Internet NAT IMIRC VoIP P2P 6

http, pop, smtp Proxy http proxy, ftp proxy Web/Mail Firewall application transport website website network datalink physical VPN VPN - IPSec IP PPTP, L2F, L2TP /Firewall / VPN TCP Wrapper / Network A Network B (1/2) 3 SPAM ( CNS ) POP before SMTP: POP SMTP AUTH: 7

(2/2) DNS (1/2) APOP / POP over TLS Slave BIND: allow transfer MIME DNSSEC DNS (2/2) Web (1/2) CGI DNS CGI DNS Web CGI DNS PHP/ASP/JSP Web (2/2) Index Apache.htaccess Options Indexes Cookie 3 8

(1/3) (2/3) Ethernet Ethernet : A D ARP HUB Switch A B C D E A B C D E ftp operation hogehoge pop http telnet ftp apop https ssh ssh(scp/sftp) SSH Port Forwarding IPsec 9

(3/3) (4/4) Ingress Filtering Web IP ( ) Firewall IP ( ) IP Directed broadcast (IDS) (IDS) Intrusion Detection System 10

IDS HIDS ( IDS) IDS NIDS ( IDS) IDS Worm Excel E-mail W32.Badtrans.B@mm W32.Nimda.A@mm W32.Sircam.Worm@mm Worm MicrosoftOutlookExpress HTML HTML deamonroot Ex.>telnet ftp /etc/inetd.conf /etc/rc.conf /etc/defaults/rc.conf (FreeBSD) 11

/etc/rc.conf(freebsd) apm_enable="yes" hostname= hoge.sfc.wide.ad.jp" inetd_enable="no" kern_securelevel_enable="no" keymap="jp.106" linux_enable="yes" moused_enable="yes" sendmail_enable="no" sshd_enable="yes" usbd_enable="yes" ipfilter_enable="yes" ipfilter_rules="/etc/ipf.rules" ipfilter_flags="" ipmon_enable="yes" ipmon_flags="-d /var/log/ipflag" /etc/hosts.allow allow deny /etc/hosts.allow ALL : localhost 127.0.0.1 : allow ALL :.sfc.keio.ac.jp : allow ALL :.sfc.wide.ad.jp : allow ALL :.ht.sfc.keio.ac.jp : allow in.ftpd: 10.11.7. #10.11.7.* FTP ALL :.hoge.com EXCEPT terminal.hoge.com #terminal.hoge.com hoge.com /etc/hosts.deny FreeBSD /etc/hosts.allow last /etc/hosts.deny /var/log/messages ALL:ALL OS /etc/hosts.allow /var/log/wtmp /var/log/maillog 12

Solaris /var/adm/messages OS /var/log/syslog System log sendmail /var/adm/lastlog /var/adm/sulog su (1/2) : (2/2) Third-Party Mail Relay SPAM RAID sendmail FD,CD-R,MO,DVD, etc.. sendmail8.8.5 CD-R sendmail sendmail.cf DNSSEC DNS Ex.> DNS dnssec-keygen a hmac-md5 b 128 n ZONE sample-k named.conf hmac-md5 128bitZONE zone hoge.com { sample-k allow transfer { 192.168.30.4; localhost } } Ksample-k+157+02663.key( ) #ns.hoge.com 192.168.1.4 Ksample+155+02663.privat( ) 13

DNS SSI Server Side Include named.conf options{ allow-recursion{192.168.30.0/24;localhost;} } CGI CGI Ex.> NCSA httpdphf test-cgi nph-test-cgi CGI SSI CGISSI chrootcgi Index Ex.>http://www.sfc.keio.ac.jp/~hoge/ ~hoge httpd.conf <Directory /> Options Indexes FollowSymLinks </Directory> Indexes 14