Linux Information
 
ÃÑ °Ô½Ã¹° 125°Ç, ÃÖ±Ù 0 °Ç
   
TCP SYN FLOOD
±Û¾´ÀÌ : ½Å¿µÃ¶ ³¯Â¥ : 2013-01-18 (±Ý) 13:26 Á¶È¸ : 20107

TCP SYN FLOOD

ÃÖ±Ù µÎÁ¾·ùÀÇ ÁöÇÏ ÀâÁö¿¡ "¹Ý¸¸ ¿­¸°" TCP ¿¬°áµéÀ» »ý¼ºÇÏ¹Ç·Î½á ¼­ºñ½º°ÅºÎ°ø°ÝÀ» ÇÏ´Â Äڵ尡 ¹ßÇ¥µÇ¾ú´Ù. ÀÎÅͳݿ¡ ¿¬°áµÇ¾î TCP ±â¹ÝÀÇ ¼­ºñ½º(¿¹¸¦ µé¸é, À¥¼­¹ö, FTP¼­¹ö, ¶Ç´Â ¸ÞÀϼ­¹ö µî)¸¦ Á¦°øÇÏ´Â ¸ðµç ½Ã½ºÅÛµéÀÌ ÀÌ °ø°Ý¿¡ ³ëÃâµÇ¾î ÀÖÀ¸¸ç, °ø°ÝÀÇ °á°ú´Â ½Ã½ºÅÛ¿¡ µû¶ó ´Ù¸£´Ù. ±×·¯³ª ÀÌ ¹®Á¦¿¡ ´ëÇÑ ¿Ïº®ÇÑ ÇØ°áÃ¥Àº ¾øÀ¸¸ç ´ÜÁö ¿µÇâÀ» °¨¼Ò½ÃŰ´Â ¹æ¹ýµé¸¸ÀÌ ¾Ë·ÁÁ® ÀÖ´Ù.


¾î¶² ½Ã½ºÅÛ(Ŭ¶óÀ̾ðÆ®)ÀÌ ¼­ºñ½º¸¦ Á¦°øÇÏ´Â ½Ã½ºÅÛ(¼­¹ö)¿¡ TCP ¿¬°áÀ» ½ÃµµÇÒ ¶§, Ŭ¶óÀÌ¾ðÆ®¿Í ¼­¹ö´Â ´ÙÀ½°ú °°ÀÌ ÀÏ·ÃÀÇ ¸Þ½ÃÁöµéÀ» ±³È¯ÇÑ´Ù. ¸ÕÀú Ŭ¶óÀÌ¾ðÆ® ½Ã½ºÅÛÀº ¼­¹ö¿¡ SYN ¸Þ½ÃÁö¸¦ º¸³»¸ç, ¼­¹ö´Â SYN-ACK ¸Þ½ÃÁö¸¦ Ŭ¶óÀÌ¾ðÆ®¿¡ Àü¼ÛÇϹǷνá Á¢¼öµÈ SYN ¸Þ½ÃÁö¿¡ ´ëÇØ È®ÀÎÇÑ´Ù. Ŭ¶óÀÌ¾ðÆ®´Â ´Ù½Ã ACK ¸Þ½ÃÁö¸¦ Àü¼ÛÇϹǷνá Á¢¼Ó ¼³Á¤À» ¿Ï·áÇÑ´Ù. ÀÌ·¸°Ô ÇϹǷνá Ŭ¶óÀÌ¾ðÆ®¿Í ¼­¹ö »çÀÌÀÇ Á¢¼ÓÀÌ ¿­¸®°Ô µÇ°í, Ŭ¶óÀÌ¾ðÆ®¿Í ¼­¹ö»çÀÌ¿¡ ¼­ºñ½º¿¡ °íÀ¯ÇÑ ÀÚ·áµéÀ» ±³È¯ÇÒ ¼ö ÀְԵȴÙ. ÀÌ·¯ÇÑ Á¢¼Ó¹æ¹ýÀº ¸ðµç TCP ¿¬°á(ÅÚ³Ý, ÀüÀÚ¿ìÆí, À¥ µî) ¿¡ ´ëÇØ Àû¿ëµÈ´Ù.


°ø°ÝÀÇ °¡´É¼ºÀº ¹Ù·Î ¼­¹ö°¡ Ŭ¶óÀÌ¾ðÆ®¿¡ È®ÀÎ ¸Þ½ÃÁö(ACK-SYN)À» º¸³½ ÈÄ Å¬¶óÀÌ¾ðÆ®·Î ºÎÅÍ ´Ù½Ã È®ÀÎ ¸Þ½ÃÁö(ACK)¸¦ ¹Þ±â ÀÌÀüÀÇ ½ÃÁ¡¿¡¼­ ¹ß»ýÇÑ´Ù. ÀÌ »óŰ¡ ¹Ù·Î "¹Ý¸¸ ¿­¸°" ¿¬°áÀ̶ó°í ºÒ¸°´Ù. ¼­¹ö´Â ¸ðµç ÁøÇàÁßÀÎ ¿¬°á¿¡ ´ëÇÑ Á¤º¸¸¦ ÀúÀåÇϱâ À§ÇØ ½Ã½ºÅÛ ¸Þ¸ð¸®¿¡ ÀڷᱸÁ¶¸¦ ±¸ÃàÇϸç ÀÌ ÀڷᱸÁ¶´Â ±× Å©±â°¡ Á¦ÇѵǾî ÀÖ´Ù. µû¶ó¼­ °è¼ÓÇÏ¿© "¹Ý ¸¸ ¿­¸°" ¿¬°áÀ» »ý¼ºÇϹǷνá ÀÌ ÀڷᱸÁ¶¸¦ ³ÑÄ¡°Ô ÇÒ ¼ö ÀÖ´Ù.


¹Ý¸¸ ¿­¸° ¿¬°áÀº IP ¼ÓÀ̱⸦ ÀÌ¿ëÇÏ¸é ¼Õ½±°Ô »ý¼ºÇÒ ¼ö ÀÖ´Ù. °ø°ÝÀÚ ½Ã½ºÅÛ¿¡¼­ Çǰø°Ý ¼­¹ö¿¡ Àû¹ýÇÏ°Ô º¸ÀÌÁö¸¸ ½ÇÁ¦·Î´Â ACK-SYN¿¡ ´ëÇØ ÀÀ´äÇÒ ¼ö ¾ø´Â Ŭ¶óÀÌ¾ðÆ®¸¦ ÂüÁ¶ÇÏ´Â SYN ¸Þ½ÃÁö¸¦ ¹ß¼ÛÇÑ´Ù. µû¶ó¼­ Çǰø°Ý ¼­¹ö´Â ÃÖÁ¾ SYN ¸Þ½ÃÁö¸¦ ¹Þ À» ¼ö ¾ø°ÔµÈ´Ù. ¸¶Ä§³» Çǰø°Ý ¼­¹öÃøÀÇ "¹Ý¸¸ ¿­¸°" ¿¬°áÀ» À§ÇÑ ÀÚ·á ±¸Á¶°¡ °¡µæÂ÷°Ô µÇ°í ÀÌ ÀÚ·á ±¸Á¶°¡ ºñ¿ö Áú ¶§±îÁö Çǰø°Ý ¼­¹ö´Â »õ·Î¿î ¿¬°á ¿ä±¸¿¡ ´ëÇØ ÀÀ´äÇÒ ¼ö ¾ø°Ô µÈ´Ù. ÀϹÝÀûÀ¸·Î ¹Ý¸¸ ¿­¸° ¿¬°á¿¡ ´ëÇØ¼­´Â ŸÀӾƿô °ªÀÌ ¼³Á¤µÇ¾î ÀÖ¾î ÀÏÁ¤ ½Ã°£ÀÌ °æ°úÇϸé ÀÚµ¿ÀûÀ¸·Î Ãë¼ÒµÇ°Ô µÇ¹Ç·Î »õ·Î¿î ¿¬°á¿¡ ´ëÇØ ÀÀ´äÇÒ ¼ö ÀÖ°Ô µÈ´Ù. ±×·¯³ª À̿Ͱ°Àº º¹±¸¿¡ ¼Ò¿äµÇ´Â ½Ã°£º¸´Ù ºü¸£°Ô °ø°ÝÀÚ ½Ã½ºÅÛÀÌ ¹Ýº¹ÀûÀ¸·Î ¼ÓÀÓ¿ë IP ÆÐŶÀ» Àü¼ÛÇÒ ¼ö ÀÖ´Ù.


´ëºÎºÐÀÇ °æ¿ì, ÀÌ·¯ÇÑ °ø°ÝÀÇ ÇÇÇØ ½Ã½ºÅÛÀº »õ·Î¿î ³×Æ®¿öÅ© ¿¬°á ¿äûÀ» ¹Þ¾Æ µéÀ̴µ¥ °ï¶õÀ» °Þ°Ô µÇ¸ç ¼­ºñ½ºÁ¦°ø ´É·ÂÀÇ ÀúÇϸ¦ °¡Á®¿Â´Ù. ±×·¯³ª ±âÁ¸ÀÇ ¿ÜºÎ·Î ºÎÅÍÀÇ ¿¬°áÀ̳ª, ¿ÜºÎ·ÎÀÇ »õ·Î¿î Á¢¼Ó ¿äû Àü¼Û¿¡´Â ¿µÇâÀ» ¹ÞÁö ¾Ê´Â´Ù. ±×·¯³ª Ưº°ÇÑ °æ¿ì, ½Ã½ºÅÛÀÇ ¸Þ¸ð¸®°¡ °í°¥µÇ°Å³ª, ÆÄ±«µÇ°Å³ª, ¶Ç´Â ÀÛµ¿ºÒ°¡´ÉÇÏ°Ô µÉ ¼öµµ ÀÖ´Ù.


SYN ÆÐŶÀÇ ±Ù¿øÁö ÁÖ¼Ò°¡ °¡Â¥À̹ǷΠ°ø°ÝÀÇ ±Ù¿øÀ» ¾Ë¾Æ³»´Â °ÍÀº ¾î·Á¿ì¸ç ÆÐŶÀÌ Çǰø°Ý ¼­¹ö¿¡ µµÂøÇÑ µÚ¿¡ ±Ù¿øÀ» ¾Ë¾Æ³»´Â °ÍÀº ºÒ°¡´ÉÇÏ´Ù. ³×Æ®¿öÅ©´Â ÆÐŶÀ» ¸ñÀûÁö ÁÖ¼Ò¸¸À» ÀÌ¿ëÇÏ¿© Àü´ÞÇϹǷΠ±Ù¿øÀ» °ËÁõÇÏ´Â À¯ÀÏÇÑ ¹æ¹ýÀº ÀÔ·Â ¼Ò½º ÇÊÅ͸µÀ» ÀÌ¿ëÇÏ´Â °Í »ÓÀÌ´Ù.


ÇöÀçÀÇ IP ÇÁ·ÎÅäÄÝ ±â¼ú·Î´Â IP ¼ÓÀÓ ÆÐŶÀ» Á¦°ÅÇÏ´Â °ÍÀÌ ºÒ°¡´ÉÇϹǷΠÇöÀç·Î¼­´Â ÀÌ ¹®Á¦¿¡ ´ëÇÑ ¿ÏÀüÇÑ ÇØ°áÃ¥ÀÌ ¾ø´Â »óÅÂÀÌ´Ù. ±×·¯³ª °ü¸®Çϰí ÀÖ´Â ³×Æ®¿öÅ©·Î À¯ÀԵǰųª À̷κÎÅÍ À¯ÃâµÇ´Â IP ¼ÓÀÓ ÆÐŶÀ» °¨¼Ò½Ãų ¼ö ÀÖ´Â ¹æ¹ýÀÌ ÀÖ´Ù. Áï, ¶ó¿ìÅ͸¦ ÀûÀýÈ÷ ±¸¼ºÇÏ¹Ç·Î½á °ø°Ý´çÇÒ °¡´É¼ºÀ» ÁÙÀ̰ųª, ÇØ´ç »çÀÌÆ®³»ÀÇ ½Ã½ºÅÛÀÌ °ø°ÝÀÇ ±Ù¿øÀÌ µÉ ¼ö ÀÖ´Â °¡´É¼ºÀ» °¨ ¼Ò½Ãų ¼ö´Â ÀÖ´Ù.


ÇöÀç·Î¼­ÀÇ ÃÖ»óÀÇ ÇØ°áÃ¥Àº ¿ÜºÎ Á¢¼Ó¿ë ÀÎÅÍÆäÀ̽º·ÎÀÇ À¯ÀÔÀ» Á¦ÇÑÇÏ´Â ÇÊÅ͸µ ¶ó¿ìÅÍ(ÀÔ·Â ÇÊÅͶó°í ºÎ¸§)¸¦ ¼³Ä¡ÇÏ¿© ±Ù¿øÀÌ ³»ºÎ ³×Å©¿öÅ©ÀÎ ¸ðµç ÆÐŶÀÇ À¯ÀÔÀ» ±ÝÁö½ÃŰ´Â °ÍÀÌ´Ù. ÀÌ¿¡ ´õÇÏ¿© ±Ù¿øÀÌ ³»ºÎ ³×Æ®¿öÅ©°¡ ¾Æ´Ñ ¸ðµç ÆÐŶÀÇ À¯ÃâÀ» ±ÝÁö½ÃÄÑ °ü¸®ÇÏÀÇ »çÀÌÆ®·Î ºÎÅÍ IP ¼ÓÀÓ °ø°ÝÀÌ ¹ß»ýµÇ´Â °ÍÀ» ¹æÁöÇÒ ¼ö ÀÖ´Ù. ±×·¯³ª ÀÌ·¯ÇÑ ¹æ¹ýµµ ¿ÜºÎ °ø°ÝÀÚ°¡ ´Ù¸¥ ÀÓÀÇÀÇ ¿ÜºÎ ÁÖ¼Ò¸¦ ÀÌ¿ëÇϰųª, ³»ºÎÀÇ °ø°ÝÀÚ°¡ ³»ºÎÀÇ ÁÖ¼Ò¸¦ ÀÌ¿ëÇÏ¿© °ø°ÝÇÏ´Â °Í¿¡ ´ëÇØ¼­´Â ¹æ¾îÇÏÁö ¸øÇÑ´Ù.




Patches from BSDI Co.


PATCH:

K210-021


SUMMARY:

This patch adds two networking features that can help defeat and detect some types of denial of service attacks.


The first feature is a limit on the number of fragmented IP packets in the IP reassembly queue. The default limit is 200 and can be changed with the sysctl(8) variable "net.inet.ip.maxfragpackets". To change the limit of the n umber of packets on the IP reassembly queue add a command like the following to the end of /etc/netstart. This example would reduce the limit on outstanding fragments to 100:


sysctl -w net.inet.ip.maxfragpackets=100


The second feature is an optional test to insure that packets are received on the expected interface. This feature lo oks up the route back to the source of received IP packets. If there is no route to the source available, or the packet did not arrive on the expected interface the packet is discarded. The expected interface is the one that would be used to send a packet back to the reported source of the packet.


IP source address verification should not be used when concurrent alternate paths exist from the BSD/OS system where t his feature is enabled, as this may cause valid packets to be discarded. For example, a small ISP that has one connecti on to a backbone network and one connection to each of it's clients could enable this feature. If the same ISP has two connections to a backbone network, or one connection to each of two backbone networks they should not enable this featur e.


IP source address verification is an valuable tool for protecting against some forms of IP-spoofing as described in CE RT advisory CA 96.21, "TCP SYN Flooding and IP Spoofing Attacks". The full text of this advisory is available as ftp://info.cert.org/pub/cert_advisories/CA-96.21.tcp_syn_flooding.


If you are a service provider, using IP source verification will protect your customers against attacks from the Inter net which appear to be coming from your customers' networks, and it will ensure that packets sent from your customers' n etworks have a source address on your customers' networks (preventing them from spoofing source addresses and/or attacki ng others).


This feature is enabled via the "net.inet.ip.sourcecheck" sysctl(8) variable or by adding the "IPSOURCE CHECK" option when building a kernel. For example, to enable IP source address verification, add the following com mand to the end of /etc/netstart:


sysctl -w net.inet.ip.sourcecheck=1


The IP source address verification code will log a message when discarding a packet. To prevent a large number of the se packets from using an excessive amount of disk space log messages are limited to one per IP address per time interval . The time interval defaults to five seconds and may be configured with the "net.inet.ip.sourcecheck_logint" sysctl(8) variable. A value of zero disables the time interval.


This patch requires U210-025 which provides new copies of sysctl(8) and netstat(1) for configuration and monitoring of these new features.


===================================================================

PATCH:

K210-022


SUMMARY:

This patch adds a TCP SYN cache which reduces and/or eliminates the effects of SYN-type denial of service attacks such as those discussed in CERT advisory CA 96.21. When a large number of SYN packets arrive for the same TCP port, the old code would drop the excess SYN packets, assuming that they will be retransmitted and that the current 1/2 open connecti ons will soon be completed and removed from the queue.


However, due to one-way and/or long paths, or malicious intent, the queue can become clogged with 1/2 open connections that will never complete, preventing any valid connections from being established.


With the SYN cache, when the accept queue overflows a minimal amount of state is stored in the SYN cache, and a SYN,AC K response is sent. If a valid ACK comes back, a complete connection is created. If there is no route or a TCP RST or ICMP Unreachable comes back, the entry is deleted. Otherwise, the entries will just time out.


There are several new sysctl entries. Note that they should not be changed unless there is evidence that the default values are not adequate.

o net.inet.tcp.syn_cache_limit

This specifies the maximum number of entries that may be held into the SYN cache.

o net.inet.tcp.syn_bucket_limit

This specifies the maximum number of entries that may be held in any individual hash bucket of the SYN cache.

o net.inet.tcp.syn_cache_interval

This specifies in 0.5 second increments, how often the timeout routine for the SYN cache should be run.


The default maximum cache size is 10255, with a hash table size of 293 and a maximum per bucket limit of 105 (10255 = 293*35, 105 = 3*35). If INET_SERVER is defined, the default maximum cache size is 34895, a hash table size of 997, and a per bucket limit of 105 (34895 = 997*35, 105 = 3*35).

½Å¿µÃ¶ ´ÔÀÇ Linux ÃÖ½Å±Û [´õº¸±â]


   

 

naver.com daum.net nate.com google.co.kr youtube.com


Copyright ¨Ï www.pronice.com. All rights reserved.