¡®Tsunami SYN Flood Attack¡¯ ÆÐŶ´ç 1000bytesÀÇ Æ®·¡ÇÈ À¯¹ß
ÀϹÝÀûÀÎ SYN ÆÐŶ 25¹è Å©±â·Î ÆÐŶ µ¥ÀÌÅ;ç Ãß°¡ÇØ °ø°Ý
[º¸¾È´º½º ¹Î¼¼¾Æ] ÃÖ±Ù µðµµ½º ¼Ö·ç¼Ç º¸¾È¾÷ü ¶óµå¿þ¾î¿¡¼ DDoS(Distributed Denial of Service) °ø°ÝÀÇ »õ·Î¿î À¯ÇüÀÎ ¡®Tsunami SYN Flood Attack¡¯À» ¹ß°ßÇß´Ù. ÀÌ ¾÷üÀÇ Emergency Response Team(ERT)´Â 48½Ã°£ µ¿¾È ´ë·®ÀÇ °ø°ÝÀ» ŽÁöÇß´Ù.
¡ã°ø°Ý´ë»óº° °ø°ÝºñÀ²
À̹ø Tsunami SYN-Flood AttackÀº ÁÖ·Î ISP³ª °ÔÀÓ È¸»çÀÇ µ¥ÀÌÅͼ¾Å͸¦ °ø°ÝÇßÀ¸¸ç 4~5GbpsÀÇ °ø°ÝÀÌ ¹ß»ýÇß´Ù. ±âÁ¸ SYN flood AttackÀº ÆÐŶ´ç 40~60bytesÀÇ Æ®·¡ÇÈÀ» À¯¹ßÇϴµ¥ ¹ÝÇØ Tsunami SYN-Flood AttackÀº ÆÐŶ´ç 1000bytesÀÇ Æ®·¡ÇÈÀ» À¯¹ßÇÑ´Ù.
ÀϹÝÀûÀ¸·Î SYN ÆÐŶÀº TCP 3way handshake °úÁ¤¿¡¼ »ý¼ºµÇ´Â ¸Þ½ÃÁöÀ̸ç ÇØÄ¿µéÀº ÀϹÝÀûÀÎ SYN ÆÐŶ¿¡ 25¹è(ÃÖ´ë 1000bytes)ÀÇ Å©±â·Î ÆÐŶ µ¥ÀÌÅ;çÀ» Ãß°¡ÇÏ´Â ¹æ½ÄÀ¸·Î °ø°ÝÀ» ¼öÇàÇÑ´Ù.
¶óµå¿þ¾î ¿µ±¹Áö»çÀÇ Crawley´Â ¡°°ø°ÝÀ» À§ÇØ º¿³Ý(Botnet)À» ÀÌ¿ëÇßÀ¸³ª °ø°ÝÀÚµéÀº Æ®·¡ÇÈÀÌ ¹ß»ýÇÏ´Â ±â°è¸¦ ¿Ïº®È÷ Á¦¾îÇÒ ¼ö ¾ø¾ú´Ù¡±¸ç, ¡°´õ ¸¹Àº º¿(bots)À» Æ®·¡ÇÈ¿¡ µ¡ºÙ¿© °ø°ÝÇÑ´Ù¡±°í ¼³¸íÇß´Ù.
ÀÌ¿Í °ü·Ã º¸´Ù ÀÚ¼¼ÇÑ »çÇ×Àº Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ È¨ÆäÀÌÁö¸¦ Âü°íÇϰųª ¾Æ·¡ÀÇ Ãâó¸¦ È®ÀÎÇÏ¸é µÈ´Ù.
[Ãâó]
1. http://itsecuritynews.info/2014/10/12/tsunami-syn-flood-ddos-attack-a-dangerous-trend/
2. http://securityaffairs.co/wordpress/29141/cyber-crime/tsunami-syn-flood-ddos.html
3. http://blog.radware.com/security/2014/10/tsunami-syn-flood-attack/
[¿ë¾îÁ¤¸®]
¡¤ISP(Internet Service Provider) : °³ÀÎÀ̳ª ±â¾÷¿¡ ÀÎÅÍ³Ý Á¢¼Ó ¼ºñ½º, À¥ »çÀÌÆ® ±¸Ãà µîÀ» Á¦°øÇϴ ȸ»ç
¡¤TCP 3way handshake : TCP/IPÇÁ·ÎÅäÄÝÀ» ÀÌ¿ëÇؼ Åë½ÅÀ» ÇÏ´Â ÀÀ¿ëÇÁ·Î±×·¥ÀÌ µ¥ÀÌÅ͸¦ Àü¼ÛÇϱâ Àü¿¡ ¸ÕÀú Á¤È®ÇÑ Àü¼ÛÀ» º¸ÀåÇϱâ À§ÇØ »ó´ë¹æ ÄÄÇ»ÅÍ¿Í »çÀü¿¡ ¼¼¼ÇÀ» ¼ö¸³ÇÏ´Â °úÁ¤
¡¤º¿³Ý(Botnet) : ½ºÆÔ¸ÞÀÏÀ̳ª ¾Ç¼ºÄÚµå µîÀ» ÀüÆÄÇϵµ·Ï ÇÏ´Â ¾Ç¼ºÄÚµå º¿(Bot)¿¡ °¨¿°µÇ¾î ÇØÄ¿°¡ ¸¶À½´ë·Î Á¦¾îÇÒ ¼ö ÀÖ´Â Á»ºñPCµé·Î ±¸¼ºµÈ ³×Æ®¿öÅ©
[¹Î¼¼¾Æ ±âÀÚ(boan5@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>