0x00 BGPïŒRFC 1771ãRFC
4271ïŒå®çŸ©ã®ãã«ããŒã ã¯ããŒããŒã²ãŒããŠã§ã€ã§ã
äžåœèªã«å¯Ÿå¿ãããããã³ã«ã¯Border Gateway Protocolã§ãããææ°ããŒãžã§ã³ã¯BGPV4ã§ãã BGPã¯ãã€ã³ã¿ãŒãããäžã®ã³ã¢ã€ã³ã¿ãŒãããã®åæ£åèªåŸçãªã«ãŒãã£ã³ã°ãããã³ã«ã§ãããã®ã¹ããŒã¿ã¹ã¯äžæ žã§ãããçŸåšãæµ·ãéžã空æ°ã7ã€ã®å€§éžãš4ã€ã®æµ·ãã€ãªãå¯äžã®å€éšã«ãŒãã£ã³ã°ãããã³ã«ã§ãããšèšãã®ã¯èªåŒµã§ã¯ãããŸããã BGPã¯ãã¢ããªã±ãŒã·ã§ã³ã¬ã€ã€ãŒãããã³ã«ã«å±ããæãè€éãªã«ãŒãã£ã³ã°ãããã³ã«ã§ããããã®ãã©ã³ã¹ããŒãã¬ã€ã€ãŒã¯TCPã䜿çšããããã©ã«ãã®ããŒãçªå·ã¯179ã§ããã¢ããªã±ãŒã·ã§ã³ã¬ã€ã€ãŒãããã³ã«ã§ãããããæ¥ç¶ã¯ä¿¡é Œã§ãããšèããããšãã§ããæçã確èªãåéä¿¡ãªã©ãBGPã®ã¿ãfragmentã確èªãåéä¿¡ãªã©ãåºç€ãšãªãäœæ¥ãæ€èšããå¿ èŠã¯ãããŸããããããã³ã«ã茞éå±€ã«å°éã§ããªãå ŽåããããŸãã
1ãé¢é£ããéèŠãªæŠå¿µ
ASïŒèªåŸã·ã¹ãã ïŒ:èªåŸã·ã¹ãã ã¯ãã€ã³ã¿ãŒãããäžã§å ±éã®ã«ãŒãã£ã³ã°ããªã·ãŒãå®è¡ãã1ã€ïŒæã«ã¯è€æ°ã®ïŒçµç¹ã®ç®¡èœäžã«ããIPãããã¯ãŒã¯å šäœãšã«ãŒã¿ãŒå šäœãæããŸããèšãæããã°ãã€ã³ã¿ãŒãããã®å ŽåãASã¯ç¬ç«ããå šäœçãªãããã¯ãŒã¯ã§ãããããããç¬èªã®æ°åãæã£ãŠããŸããéåžžãèªåŸã·ã¹ãã ã¯ãASNç¯å²:1-65535ãåããã°ããŒãã«ã«äžæã®16æ¡ã®æ°å€ãå²ãåœãŠãŸãã 1-64511å ¬å ±ã®ASNã«å±ããäžæ¹ããã©ã€ããŒãASN:64512-65535ã
Path:ã«ãŒãã£ã³ã°ã¯ãããããã®Asç¯å²ã®ã¬ã³ãŒããçæããŸãã ïŒã«ãŒãã£ã³ã°ãªã³ã°äºé²ã¡ã«ããºã ïŒã
EBGP:å€éšBGPãããã³ã«ïŒEBGPïŒã®äž»ãªæ©èœã¯ãå€éšã«ãŒã¿ãŒãŸãã¯ASã«ããå€ãã®æ å ±ãæäŸããããšã§ãã
IBGP:å éšBGPãããã³ã«ïŒIBGPïŒã®äž»ãªæ©èœã¯ãASå éšã«ãŒã¿ãŒã«ããå€ãã®æ å ±ãæäŸããããšã§ãã
2.3 BGP
ã®è¡šAdjancy TableïŒAdjancy TableïŒ:ã¯ããã¹ãŠã®BGP飿¥æ å ±ãä¿åããŸãã
bgpããŒãã«ïŒè»¢éïŒ
ããŒã¿ããŒã¹ïŒ:åè¿é£ããåŠãã ã«ãŒãã£ã³ã°æ å ±ãä¿åããŸãã
ã«ãŒãã£ã³ã°ããŒãã«ïŒã«ãŒãã£ã³ã°ããŒãã«ïŒ:bgpã¯ãããã©ã«ãã§ã¯è² è·åæ£ãè¡ããŸããã BGPããŒãã«ããåã¿ãŒã²ãããããã¯ãŒã¯ã«å°éããã«ãŒããéžæããä¿åããããã«ã«ãŒãã£ã³ã°ããŒãã«ã«é
眮ããŸããã«ãŒã¿ãŒã¯ãã«ãŒãã£ã³ã°ããŒãã«ã«ä¿åãããŠããã«ãŒããšã³ããªã«åŸã£ãŠããŒã¿ã転éããã ãã§ãã
3ã BGPã«ãŒã¿ãŒã®ããžãã¹ããŒã«ã«ã€ããŠ
çµæžçå©çã®èæ ®ãããåªããŠããããã«
æåã«Customerasããã«ãŒããéžæããæ¬¡ã«ç¶ããŸã
PeerasãšProviderasãèšãæããã°ãã»ãšãã©ã®ãããã¯ãŒã¯ã§äœ¿çšãããã«ãŒãã£ã³ã°ããªã·ãŒã«ãŒã«ã¯æ¬¡ã®ãšããã§ãã
1. Customerasããã®ã«ãŒãã§ã¯ã顧客ããã¢ããããã€ããŒã«æž¡ãããšãã§ããŸãã
2ã宣èšãããPeerasããã®ã«ãŒãã¯ãé¡§å®¢ã«æž¡ãããšãèš±å¯ããŸãã
ä»ã®ä»²éããããã€ããŒã«å®£äŒããããšã¯èš±å¯ãããŠããŸããã
3ã宣èšãããProviderasããã®ã«ãŒãã£ã³ã°ã¯ãã«æž¡ãããšãã§ããŸã
顧客ãä»ã®ä»²éã«å®£äŒããããšã¯èš±å¯ãããŠããŸãã
ãããã€ããŒã次ã®è¡šïŒ
0x01 5ã¯ã©ã·ãã¯BGPã»ãã¥ãªãã£ã€ãã³ã
1. BGPãããã¯ãŒã¯ã®ããŒããããã°ã©ãã³éšåã¯ã2003幎5æã«æªæãæã£ãŠæªçšãããŸããïŒ2003ïŒ
äžçã§3çªç®ã«å€§ããè»äºã¡ãŒã«ãŒã§ãã£ãã°ã©ãã³ã¯ãäžçæå€§ã®ã¬ãŒããŒã¡ãŒã«ãŒã§ãããæµ·è»è¹ã®æå€§ã®ã¡ãŒã«ãŒã§ããïŒã¯ããããã¯ãŒã¯ã®ã»ã°ã¡ã³ãããŸã 䜿çšããŠããŸããã§ããããŸããã¹ãã ãã£ã«ã¿ãªã³ã°ã·ã¹ãã ãé¿ããããã«ã倧éã®ã¹ãã ãéä¿¡ããããã«äœ¿çšãããŸããæçµçã«ãæŠåšè«è² æ¥è ã¯ããããã®IPã¢ãã¬ã¹ã®æææš©ã2ãæéå宣èšããåœéçãªã€ã³ã¿ãŒãããã§Rogue RouteãããŒããã£ã¹ãããããã¯ããŸãããåæã«ãã¹ãã ã¢ãã¬ã¹ã®ãã©ãã¯ãªã¹ããé »ç¹ã«è¡ãããããããã¹ãŠã®Northrop Grummanã®IPã¢ãã¬ã¹ã¯çŠæ¢ãããŠããŸãã
2ãããã¹ã¿ã³ãã¬ã³ã ã®YouTubeïŒ2008ïŒã®åæ¢2008幎2æãããã¹ã¿ã³æ¿åºã¯ããããªWebãµã€ãã®YouTubeã«åãšãã³ã³ãã³ãããããšããçç±ã§YouTubeããããã¯ããããã«ã€ã³ã¿ãŒããããµãŒãã¹ãããã€ããŒã«åœããŸãããããã¹ã¿ã³ã®éä¿¡
TelecomïŒããŒã«ã«ãŠãŒã¶ãŒã¢ã¯ã»ã¹ãå¶éããããšããŸã
YouTubeãBGPãä»ããŠéŠæž¯ãã¬ã³ã ã€ã³ã±ïŒPCCWïŒã«æ°ããã«ãŒãã£ã³ã°æ å ±ïŒãšã©ãŒä»ãïŒãéä¿¡ããŸãã PCCWã¯ããã®ééã£ãã«ãŒãã£ã³ã°æ å ±ãåœéçãªã€ã³ã¿ãŒãããã«ãããŒããã£ã¹ãããŸããåœæãããã¹ã¿ã³ãã¬ã³ã ã¯ã«ãŒã¿ãŒãžã®éçã«ãŒãã远å ããŠã208.65.153.0/24ãååŸããŸããã
null0ã€ã³ã¿ãŒãã§ã€ã¹ïŒãã©ãã¯ããŒã«ã«ãŒãã£ã³ã°ïŒ; BAãã¬ã³ã ãšã³ãžãã¢ã¯æãšéçã«éããŸãã
ã«ãŒãååé ïŒCiscoã«ãŒã¿ãŒäžã®ç°ãªããããã³ã«ã®ã«ãŒãã£ã³ã°ããŒãã«ãåæããæ¹æ³ïŒã¯BGPã«ãªããŸããã€ãŸããã«ãŒã¿ãŒã®éçã«ãŒãã£ã³ã°ããŒãã«ãBGPã«ãŒãã£ã³ã°ããŒãã«ã«è¿œå ãããä»ã®ã«ãŒãã£ã³ã°ããŒãã«ã«åæããéçã«ãŒãã£ã³ã°ã®åªå å€ã¯æé«ã®ãã®ã§ãã
BGPã¯ããã®ã«ãŒããä»ã®ãã¢ãžã®ã«ãŒã¿ãŒãšããŠåæããŸãããæåã®ãã®ã¯éŠæž¯ã®PCCWã§ããããããããå šäžçã«åŸã ã«åæãããŸããããã®æç¹ã§ãã€ã³ã¿ãŒãããã®ã»ãšãã©ã®ãŠãŒã¶ãŒã¯è¡ããããšæã£ãŠããŸã
YouTubeã®ãšãããã±ããã¯ããã¹ã¿ã³ã®ã«ãŒã¿ãŒã®ãã«ã€ã³ã¿ãŒãã§ã€ã¹ã«ã¹ããŒãããŸãããããã¡ããéãããšã¯äžå¯èœã§ããã
3ããããã³ã°ããŒã ã¯BGPã䜿çšããŸã
Hijackã¯ãBGPãã€ãžã£ãã¯ãã¯ãããžãŒã䜿çšããŠã¿ãŒã²ãããããã¯ãŒã¯ãªã³ã¯ããŒã¿ããã€ãžã£ãã¯ããã€ã¿ãªã¢ã®ããã«ãŒã°ã«ãŒãïŒ2015ïŒã®æ»æãæ¯æŽããAdobe Flash 0dayããã³ãã®ä»ã®æè¡çææ®µã䜿çšããŠRCãã¿ãŒã²ãããããã¯ãŒã¯ã«é ä¿¡/æç€ºããŠãé·æç£èŠãå®äºããŸãã
4. Googleãšã³ãžãã¢ã®æ§æãšã©ãŒã«ããã800äžäººã®æ¥æ¬äººãŠãŒã¶ãŒã1æéåæãããŸããïŒ2017ïŒGoogleãšã³ãžãã¢æ§æãšã©ãŒã«ãããNTT Communications Co.Ltdãã®ãã©ãã£ãã¯ã誀ã£ãŠãã€ãžã£ãã¯ãããŸããã ïŒNTTã¯æ¥æ¬ã®äž»èŠãªISPã§ããã2ã€ã®å°ããªISPãOCNãšKDDIããµããŒãããŠããŸãã
æ¥æ¬ã§ã¯ãNTTã¯767äžäººã®äœå® ãŠãŒã¶ãŒãš480,000瀟ã«ã€ã³ã¿ãŒããããµãŒãã¹ãæäŸããŠããŸãïŒãããã«ãããæ¥æ¬ã¯çŽ40åéã€ã³ã¿ãŒãããããåæãããæ¥æ¬ã§ã¯ããªãã®ãããã¯ãçºçããŸãããå°å ã®æ¥æ¬ã®ã¡ãã£ã¢ã®å ±éã«ãããšãæ¥æ¬ã®å åçãšæ¥èŠã®çã¯ãã®åé¡ã®èª¿æ»ãéå§ããISPã«è©³çްãªå ±åãæäŸããããæ±ããŸããã Googleã®ã¹ããŒã¯ã¹ãã³ã¯ãããã圌ãã®ééãã§ããããšãèªããŠå£°æãçºè¡šããŸãããã¹ããŒã¯ã¹ãã³ã¯ãGoogleãã€ã³ã¿ãŒãããäžã§ãšã©ãŒã¡ãã»ãŒãžãèšå®ããäžäŸ¿ãšãããã¯ãåŒãèµ·ããããããšãè¬çœªããããšãAsahi Shimbunã«èªã£ãã忢äºä»¶ãçºçããåŸãGoogleã¯8å以å ã«æ å ±ãä¿®æ£ããŸããã
ãªãæ¥æ¬ã¯ãããªã«æ·±å»ãªåœ±é¿ãäžããŠããã®ã§ããïŒä»åã¯GoogleããªãŒã¯ãã160,000ã«ãŒãã®ãã¡ã25,000ãè¶ ããã«ãŒããNTTã«å±ããã«ãŒãã¢ãã¬ã¹ã»ã°ã¡ã³ãã§ãã圱é¿ãåãããã¹ãŠã®ãããã¯ãŒã¯ã§ã¯ãNTTãå«ãã«ãŒãã®æ°ãæå€§ã§ããå®éã«ã¯ã
ãã®ã«ãŒãã£ã³ã°ãªãŒã¯ã«ã¯ãKDDIã®ã«ãŒãã£ã³ã°ã¢ãã¬ã¹ã»ã°ã¡ã³ãã¯å«ãŸããŸããããããããªãKDDIã¯ãã®çœå®³ã«èŠããã ã®ã§ããããïŒ
KDDIã¯Verizonã®ã€ã³ã¿ãŒããã転éã§ããããïŒIPïŒ
TransitïŒé¡§å®¢ãã€ãŸããKDDIã¯Verizonã®ã€ã³ã¿ãŒããããã©ã³ãžãããµãŒãã¹ãè³Œå ¥ããŸããã KDDIã¯ãVerizonãã95,000ãè¶ ãããªãŒã¯ãããã«ãŒããã¬ãã£ãã¯ã¹ãåãå ¥ããŸããå¥ã®æ¥æ¬ã®éä¿¡äºæ¥è ã§ããIIJããVerizonãã97,000以äžã®ãªãŒã¯ã«ãŒããã¬ãã£ãã¯ã¹ãåãåããŸããã
ãããã£ãŠãKDDIãŸãã¯IIJããNTTãžã®ã€ã³ã¿ãŒããããã©ãã£ãã¯ã
ãã¹ãŠãæåã«ã·ã«ãŽã®Googleã®ããŒã¿ã»ã³ã¿ãŒã«è»¢éãããŸããã NTTãKDDIãSoftBank BBãIIJã¯ãæ¥æ¬ã®ããã4ã®äž»èŠãªã€ã³ã¿ãŒãããããã¯ããŒã³ãããã¯ãŒã¯ã§ããããã®çžäºæ¥ç¶ãšãã©ãã£ãã¯ã¯èšå€§ã§ãã
ãã®BGPã«ãŒãã£ã³ã°äºæ ã«ããã倪平æŽãè¶ããæ¥æ¬ãšç±³åœã®éã®å€ãã®åœéæœæ°ŽèŠã±ãŒãã«ã·ã¹ãã ãééãã3ã€ã®äž»èŠãªãªãã¬ãŒã¿ãŒéã®åœå 亀éãåœéåãããŸããã
ç±³åœã®ã·ã«ãŽããŒã¿ã»ã³ã¿ãŒã¯Googleã«æµããŸãããã®å Žåãæ¥æ¬ãšç±³åœã®éã®åœéæœæ°ŽèŠã±ãŒãã«ã®åž¯åå¹ ãå ã ååã ã£ããšããŠããæ¥æ¬ã«ããã¯ãã®å 岿代ã®ã€ã³ã¿ãŒãããã®æµããéã¶ããšãã§ãããæ¥æ¬ãšã¢ã¡ãªã«ã®ã€ã³ã¿ãŒãããé«ééè·¯ã®æ·±å»ãªæ··éããããããŸããã
ã€ã³ã¿ãŒããããã©ãã£ãã¯ã¯ããŸãã«ãé·ãåæ ŒãããŠããããã®çµæã壿» çãªã€ã³ã¿ãŒãããããŒã¿ã®æå€±ãçºçããæ¥æ¬ã®ã€ã³ã¿ãŒãããã®äžæãçããŠããŸãã
5ãAmazonã¯BGPã«ãã€ãžã£ãã¯ããã4æ24æ¥ã®æã«1730äžç±³ãã«ïŒ2018幎ïŒã«çžåœããçé£ETHã«ãªããAmazonã®æš©åšãããã¡ã€ã³åãµãŒããŒã¯BGPã«ãŒãã£ã³ã°ãã€ãžã£ãã¯ã«ãã£ãŠæ»æãããŸãããæ»æè ã®ç®çã¯ãDNSãšBGPã®åºæã®ã»ãã¥ãªãã£ã®åŒ±ç¹ãæªçšããŠãæå·é貚ãçãããšã§ãããã€ãžã£ãã¯ã¯ããªãŒã¹ãã©ãªã¢ãç±³åœããã®ä»ã®å°åã«åœ±é¿ãäžããŠããŸãããã®äºä»¶ã§ã¯ã
ãŠã§ããµã€ããžã®ãã¹ãŠã®ãŠãŒã¶ãŒã®ã¢ã¯ã»ã¹ãã©ãã£ãã¯ã¯ããã·ã¢ã®ISPãæäŸããéæ³ãªãŠã§ããµã€ãã«ãã€ãžã£ãã¯ãããŸããã
MyetherWalletã¯ãå€ãã®ãŠãŒã¶ãŒãæ»æã®ç ç²è ã«ãªã£ããšãã声æãçºè¡šããŸããã
0x02ãããã®ã»ãã¥ãªãã£ã®æ¬ é¥/bgp
ã®è匱æ§
1. BGPã®3ã€ã®åå
1ãBGPã«ãŒãã飿¥ããæ¥ç¶ã確ç«ããåŸãäºãã¯é£äººã«ã«ãŒããšã³ããªãéä¿¡ããŸãã
2ãå®å ãããã¯ãŒã¯ã決å®ããããšãæçã®AS_PATHãã¹ãã«ãŒãã£ã³ã°ã®åªå é äœãæã£ãŠããŸã
3ãå®å ãããã¯ãŒã¯ã決å®ããããšããããã¯ãŒã¯åºåã¢ãã¬ã¹ïŒãã¹ã¯ãé·ããªãã»ã©ïŒãããå ·äœçã«å ·äœçã§ãããããã«ãŒãã®åªå 床ãšã«ãŒãã®åªå 床ãé«ããªããŸãã
2.bgp hijack
2.1ã¢ã€ãã«
å€ã®äžçãžã®å®£èšã¯èªåèªèº«ã®ãã®ã§ã¯ãªããä»ã®æ©é¢ã«ãã£ãŠåæ³ã§å®£èšãããŠããªããããã¯ãŒã¯ã«å±ããŸãã
æ»æåïŒ
AS1ã¯ããããã¯ãŒã¯1.1.1.1/18ããã³1.1.2.2/18ã®ææè ã§ãã
ãã ãã1.1.1.1/18ã®ã¿ã䜿çšããããã1.1.1.1/18ã宣èšããŸãã
宣èšãªã1.1.2.2/18ãäžã®å³ã«ç€ºãããã«ïŒ
æ»æã®åŸïŒ
AS5ã«ã¯ãããã¯ãŒã¯5.5.5.5/16ããããŸãã
圌ã¯ãAS1ã1.1.2.2/18ããã³1.1.2.2/18ãååšããåæ³ã§ãããšå®£èšããªãã£ãããšãçºèŠããŸããã AS5ã¯ã1.1.2.2/18ããã¹ãŠã®ãã©ãã£ãã¯ã1.1.2.2/1ã«AS5ã«éä¿¡ããããã«ãªã£ãããšãçºè¡šããŸãããäžã®å³ã«ç€ºãããã«ïŒ
2.1éç¥ãšããŠæãè¿ãé£äºº
ç©ççãªå Žæã®è¿æ¥æ©èœã䜿çšããŠãããªãã«å±ããªããããã¯ãŒã¯ãè¿ãã®é£æ¥ãããããã¯ãŒã¯ãªã³ã¯ããã€ãžã£ãã¯ããããšã宣èšããŸããæ»æåïŒ
æ»æã®åŸïŒ
2.2é·ããã¹ã¯ã°ã©ãïŒã€ãªãã¹å¹æïŒç¹å¥ãªãã¬ãã£ãã¯ã¹ãã€ãžã£ãã¯
BGPãã¹éžæãã³ã°ãã¹ã¯åªå æ©èœã䜿çšããŠãå°éå¯èœãªãããã¯ãŒã¯ã»ã°ã¡ã³ãã®å®å šãªãã©ãã£ãã¯ããã€ãžã£ãã¯ããŸããæ»æåïŒ
æ»æã®åŸïŒ
2.2 AS_Path HijackïŒSardine FishingïŒ
AS_Path Prependã䜿çšãããšãèªç±ã«å€æŽã§ããASãä»ããŠAS_Pathã®æ°ãå¢ããããšã§ã«ãŒãã£ã³ã°ã®åªå é äœãæå¶ããŸãã
ã¿ãŒã²ãããããã¯ãŒã¯ã«åãã£ãŠããŒã¿ãé§åããŸãããããã¯ãŒã¯ãã©ãã£ãã¯ãå¶åŸ¡ããç®çãéæããŸãã
æ»æåïŒ
æ»æã®åŸïŒ
2.3ã«ãŒããªãŒã¯
BGPã«ãŒãã£ã³ã°ãªãŒã¯ïŒ
BGPã«ãŒãã£ã³ã°ãšã³ããªã¯ãç°ãªã圹å²ã§åççãªåºåç¯å²ãæã£ãŠããŸãã BGPã«ãŒãã£ã³ã°éç¥ãåœåã®äºæ³ãããåºåç¯å²å€ã«åºãããšãã«ãŒãã£ã³ã°ãªãŒã¯ãšåŒã°ããŸãã
ãããŠãããã¯äºæž¬äžå¯èœãªçµæããããããŸããæŒãã«ãã£ãŠåŒãèµ·ããããçµæã«ãããšãããã¯æ¬¡ã®3ã€ã®ã¿ã€ãã«å€§ãŸãã«åå²ã§ããŸãã ÃãœãŒã¹ãããã¯ãŒã¯ãšå°ã£ããããã¯ãŒã¯ã®äžæãåŒãèµ·ãããŸãã Ãæ è¡/ISPæ è¡/MITMããã³ãã®ä»ã®åé¡ãšããŠåŒãèµ·ãããŸã
AS1ã«ãŒãã£ã³ã°ãªãŒã¯ãçºçããåã«ãAS1ãAS2ãAS3ãAS4ãããã³AS5ã¯æ£åžžã«éä¿¡ã§ããŸããäžã®å³ã«ç€ºãããã«ïŒ
2.4 BGP TTL ModifyïŒé£äºåŸã®ãã¶ãŒãïŒ
ASãšASã®éã®å¢çã«ãŒã¿ãŒã§EBGPãå®è¡ãããŸããããã©ã«ãã§ã¯ãçŽæ¥æ¥ç¶ãŸãã¯éçã«ãŒãã£ã³ã°ãå¿ èŠã§ããçŽæ¥æ¥ç¶ã§ãªãå Žåã¯ãè€æ°ã®EBGPãåç §ããå¿ èŠããããŸãããã以å€ã®å Žåãé£äººã®é¢ä¿ã確ç«ã§ããŸããããã®åé¡ã解決ããããã«ãEBGP-Multihop屿§ã¯ããããã®åé¡ãä¿®æ£ããããã«å®çŸ©ãããŸãã EBGPã§è¿é£ã確ç«ããå Žåãããã©ã«ãã®TTLå€ã¯1ã§ããEBGP-Multihopã倿Žããªãå Žåãéæ¹åæ§ã«æ¥ç¶ãããEBGPãã€ããŒã飿¥é¢ä¿ã確ç«ã§ããªãããã«ãªããŸãïŒãããEBGPã¢ã³ããªã³ã°æž¬å®å€ã§ãïŒãæ¬è³ªã¯ããã®å±æ§ãä»ããã¢ãŠãããŠã³ãã«ãŒãã®TTL屿§å€ã倿Žããããšã§ãã
BGP TTLå€ã¯ã«ã¹ã¿ã ã®å€æŽããµããŒããããããMITMãå®è¡ã§ããŸãïŒBGPã«ãŒãã£ã³ã°TTLå€ã®å€ã¯ãåæ Œãããã³ã«1æžå°ããŸãïŒ
æ»æãšåæã«ãæŠç¥ãçå®ããTTLå€ã倿ŽããŸãïŒå¯Ÿå¿ãããããã«ãŠã³ãã®TTLå€ãå¢ãããŸãïŒ
ãããã«ãŠã³ããäŸå€ã®ãªãããã«èŠããŸããç¹å®ã®é ããã广ãéæã§ããŸãã
switchïŒconfigïŒïŒã«ãŒã¿ãŒBGP 1.1
switchïŒconfig-routerïŒïŒneighbor 192.0.2.1 remote-as 1.2
switchïŒconfig-route-neighborïŒebgp-multihop 2ïŒ1-255ïŒ
以åã®BGPãã€ãžã£ãã¯ãš
2.5 BGPãã¬ã€ã¯https
ã䜿çšããŸãããã§ãHTTPSãã©ãã£ãã¯ã埩å·åããããã«æ³çTLSèšŒææžãååŸããå¿ èŠããããŸãã ÃTLSCAãä»ããŠãŠãŒã¶ãŒåãã«TLSèšŒææžãååŸããããã»ã¹ã¯æ¬¡ã®ãšããã§ãã
1.æåã«CA WebããŒãžã§ã¢ã«ãŠã³ããç³è«ããŸãã
2ãèªèšŒãã°ã€ã³ãªã¯ãšã¹ãCSRïŒèšŒææžïŒ
眲åãªã¯ãšã¹ãïŒäœæãšããŒãã¯éèŠã§ãããäžéšã®CAã¯ãã®æé ãã¹ãããããŠCAããçŽæ¥ç§å¯ããŒãååŸããããšããèš±å¯ããŸãã
3ãCAã¯ã次ã®3ã€ã®éèŠãªé ç®ãå«ãããŠãŒã¶ãŒãèªèšŒããããã«å€ãã®éžæè¢ãæäŸããŸãã
â¢whois recordãç §äŒããŸã
â¢ç¹å®ã®HTMLãããŒãããŠãç¹å®ã®URLã§èªèšŒãæž¡ã
â¢ãŠãŒã¶ãŒã¯DNSããŒãã«ã«ã«ã¹ã¿ã ããŒã¯ã³ãäœæããŸã
äžèšã®ç¢ºèªã®åŸãç³è«è ã¯æ¯æããè¡ããæ¯æããå®äºããCAã¯TLSæ³çèªå®ãçºè¡ããŸããæ¬¡ã«ããã®TLSèšŒææžã䜿çšããŠãWeb蚪åè ã«IDã®åæ³æ§ã蚌æã§ããŸãã ïŒããã¯ç¢ºãã«åæ³ã§ãããäžçäžã§æå¹ã§ãïŒ
ãã€ãžã£ãã¯CAïŒèšŒææžåœå±ïŒèšŒææžïŒäžèšã®ããã»ã¹ããã3ã®3ã€ã®æ¡ä»¶ãåæ Œããããšãä¿èšŒãããŠããéããæ³çTLSèšŒææžãé©çšã§ããããšãããããŸããé©åãªCAãéžæããå ŽåãBGPãã€ãžã£ãã¯ã¯CASéã®åŒã³åºããäžæããŸããããã®ãããªæ»æãå®è£ ããã«ã¯2ã€ã®ããšã ããå¿ èŠã§ãã
1.å¶åŸ¡å¯èœãªå¢çã«ãŒãã£ã³ã°
2ãBGPããŒãã®æ å ±ïŒé¡§å®¢ããããã€ããŒãããŒãæ å ±ãããã³å ¬å ±ãµãŒãã¹ã¯ãQrator RadarãŸãã¯BGPã¢ãã¿ãªã³ã°ã«äŒŒãŠããŸãããããã®åºæ¬æ å ±ãAS_PATH远跡ã«ãŒããªã©ã確èªããŸãã
ããããïŒ
BGPãã€ãžã£ãã¯ãã¯ãããžãŒã䜿çšããŠãWhiosãURL ServerãDNS TXTãDNSã
ããŒã¯ã³ã®å¯Ÿå¿ããã¢ãã¬ã¹ã¯ãæ§ç¯ãã3çš®é¡ã®ãµãŒããŒãæããŸãã
whois recordãã¯ãšãªããŸã
ïŒãã¬ãŒã³ããã¹ãã®éä¿¡ã¯åœé ã§ããŸãïŒ
ç¹å®ã®HTMLãããŒãããŠãç¹å®ã®URLã§èªèšŒãæž¡ã
ïŒãã¬ãŒã³ããã¹ãã®éä¿¡ã¯åœé ã§ããŸãïŒ
ãŠãŒã¶ãŒã¯ãDNSããŒãã«ã«ã«ã¹ã¿ã ããŒã¯ã³ãäœæããŸã
ïŒãã¬ãŒã³ããã¹ãã®éä¿¡ã¯åœé ã§ããŸãïŒ
次ã«ãã¹ããã4ã«é²ã¿ãTLSèšŒææžã¢ããªã±ãŒã·ã§ã³ãå®äºããŸãã
0x03æ€åºé²åŸ¡
1.BGPã«ãŒãã¢ãããïŒæ€åºïŒ
TTLé¢é£æ å ±ã衚瀺ããéåžžã®ç¶æ³ãšæ¯èŒããããã«Tracerouteã³ãã³ãã䜿çšããŸãã
ã»ãšãã©ã®å Žåããã€ãžã£ãã¯ã¯TTLå€ãå¢ãããASãã¹ãééããããšã«ããæ±ºå®ãããŸããã«ãŒããã€ãžã£ãã¯ãçºçããªãå Žåã
äžã®å³ã«ç€ºãããã«ïŒ
ã«ãŒããã€ãžã£ãã¯ãçºçãããšãã«ãŒãã:AS40-AS10-100ãè¿åããããšãããããŸããäžã®å³ã«ç€ºãããã«ïŒ
èªå·±æ§ç¯ããããã©ãããã©ãŒã ã¯ãã°ããŒãã«ãªæš©åšããçµç¹ããã³çµç¹ã®å®å šãªBGPã«ãŒãã£ã³ã°ããŒãã«ããªã¢ã«ã¿ã€ã ã§åæããããããããŒã«ã«ã«åéããBGPãšæ¯èŒããŸããäŸå€ãèŠã€ãããã¢ã©ãŒãã¯ãªã¢ã«ã¿ã€ã ã§äœæãããŸããäžã®å³ã«ç€ºãããã«ãRouteviewsãªã©ã®ããã€ãã®ãªãŒãã³ãœãŒã¹ãããžã§ã¯ãïŒ
åççãªååŸæéãéžæããæéäžã«éåžžã®BGPã¹ããŒã¿ã¹ã®äžã§ã«ãŒãæŽæ°ãšã³ããªã®æ°ãã«ãŠã³ãããŸããæŽæ°ãšã³ããªã®ç·æ°ã«å¯ŸããŠåççãªãããå€ç¯å²ãéžæããAS ASã®BGPã«ãŒãã£ã³ã°ãšã³ããªã®æŽæ°ã®æ°ããªã¢ã«ã¿ã€ã ã§ç£èŠããç°åžžãèŠã€ãã£ããšãã«ãªã¢ã«ã¿ã€ã ã§èŠåããŸãã Ãã³ããŒã·ã£ã«BGPã«ãŒãã£ã³ã°ã¢ãã¿ãªã³ã°ãšã¢ã©ãŒã ãã©ãããã©ãŒã ã䜿çšããŸã
â¢IARïŒã€ã³ã¿ãŒããã
ã¢ã©ãŒãã¬ãžã¹ããªïŒ
â¢PHASïŒãã¬ãã£ãã¯ã¹
ãã€ãžã£ãã¯ã¢ã©ãŒãã·ã¹ãã ïŒ
â¢çããNCC
myasnãµãŒãã¹
â¢BGPMON
â¢watchmy.net
â¢Renesys
Intelligã®ã«ãŒãã£ã³ã°
2ãã«ãŒãã£ã³ã°éç¥ã¹ã³ãŒãïŒé²åŸ¡ïŒ
ããã£ã«ã¿ãªã³ã°ããã³å¶éããŸãÃã³ã¬ã¯ã·ã§ã³ã®ã«ãŒãã£ã³ã°åºåã¯ãASç¯å²å ã®BGPããã³IGPã°ããŒãã«ã«ãŒãã£ã³ã°ããªã·ãŒã§èš±å¯ãããŠããŸãã
çŠæ¢ãããŠããŸãããŸããACLãã«ãŒããããããŸãã¯BGP Prefxãã£ã«ã¿ãªã³ã°ãåççã«äœ¿çšããŠãã«ãŒãã®çºè¡šãšäŒæç¯å²ãå¶åŸ¡ããŸãã Ãoperatorã
ãµãŒãã¹ãããã€ããŒã¯ã以äžã®ååã«åŸã£ãŠãç°ãªãããžãã¹ããŒã«ãæã€ã«ãŒã¿ãŒã§ã«ãŒãã£ã³ã°ã¢ããŠã³ã¹ã宿œãã詳现ãªBGP PrefXãã£ã«ã¿ãªã³ã°ã確ç«ããããããæå¹ã«ãããã®ãšããŸããäžã®å³ã«ç€ºãããã«ïŒ
3ãã¢ã«ãŽãªãºã ã¢ãã«ïŒæ€åº---å€éšåŒçšïŒ
3.1ãã¡ã€ã³éã«ãŒãã£ã³ã°ã®ããã®äžéæ»æã¢ãã«
ãã¡ã€ã³éã«ãŒãã£ã³ã°ã®äžéæ»æã¯éåžžããã¬ãã£ãã¯ã¹ãã€ãžã£ãã¯ã«åºã¥ããŠå®è£ ãããŸããæ¥é èŸãã€ãžã£ãã¯ã¯ã被害è ãããã¯ãŒã¯ãžã®ãã©ãã£ãã¯ããã€ãžã£ãã¯ããããã«åœã®ã«ãŒãã宣èšããŸãããå žåçãªãã¬ãã£ãã¯ã¹ã®ãã€ãžã£ãã¯ãå³ã«ç€ºããŸãã AS6ã¯ãAS1ã®ãã¬ãã£ãã¯ã¹10.1.16.1/22ãå€ã®äžçã«éæ³ã«å®£èšããŸãã
ããã«ãããAS4ãšAS5ã¯éé ã«ãŒãã«ãã£ãŠæ±æãããŸããããã«ã圌ãã¯è¢«å®³è ãããã¯ãŒã¯ã«å°éããŸãã
AS1ãã©ãã£ãã¯ãAS6ã«ãã€ãžã£ãã¯ãããŸããäžã®å³ã«ç€ºãããã«ãâ¢AS1ã¯ãããã¯ãŒã¯10.1.16.1/22ã®å®éã®ææè ã§ãã3:FãšããŠããŒã¯ãããŠããŸãã
:XãšããŠããŒã¯ããŸãã
â¢æ»æãéå§ãããåã®yããfãžã®as_pathã¯æ¬¡ã®ãšããã§ãã
æ»æãçºçããåŸãyããfãžã®as_pathã¯ïŒas6 as2ã§ã
AS1ãå³:
3.2ãã¡ã€ã³éã«ãŒãã£ã³ã°ã®äžéæ»æã®ç°åžžç¹æ§
æåã«ãã»ã¯ã·ã§ã³ã§è¿°ã¹ãããã«ããã¡ã€ã³éã«ãŒãã£ã³ã°ã®äžéæ»æã®æåã®ã¹ãããã¯ããã¬ãã£ãã¯ã¹ãã€ãžã£ãã¯ãå®è£ ããããšã§ããã¬ãã¥ãŒ