Comments
Description
Transcript
待ち行列推定に基づくパケットロス攻撃検知の強度依 存性
Vol.2013-DPS-154 No.28 Vol.2013-CSEC-60 No.28 2013/3/14 ใॲཧֶձڀݚใࠂ IPSJ SIG Technical Report ͪߦྻਪఆʹͮ͘جύέοτϩε߈ܸݕͷڧґ ଘੑ ࡉҪ ୖ࿕1,a) দӜ װଠ1,b) ֓ཁɿωοτϫʔΫͷϧʔλΛͬऔͬͯ௨৴Λૢ࡞͢Δ߈ܸͷҰͭʹɼͦͷϧʔλΛ௨ա͢Δҙͷ ύέοτΛআ͠௨৴Λ͢Δɼύέοτϩε߈ܸ͕͋ΔɽʹΑΔ௨ৗͷύέοτഇ͕͋غΔதͰ ͜ͷύέοτϩε߈ܸΛߴਫ਼Ͱݕ͢Δํ͕ࣜ Mizrak ΒʹΑͬͯఏҊ͞Ε͕ͨɼͦͷੑೳධՁ·ͩ ཏ͞Ε͍ͯͳ͍ɽຊߘͰ൴ΒͷํࣜʹΑΔύέοτϩε߈ܸͷݕੑೳʹ͍ͭͯɼͷఔʹର͢ ΔґଘੑΛௐͨ݁ՌΛใࠂ͢Δɽ HOSOI Takurou1,a) 1. ͡Ίʹ Πϯλʔωοτͷ௨৴ɼωοτϫʔΫͷ݁અͰ͋Δ ϧʔλ͕ਖ਼͍͠ܦ࿏ʹಋ͘͜ͱͰΓཱ͍ͬͯΔɽωοτ Matsuura Kanta1,b) ज़ʹൺͯࠔͳʹͳ͍ͬͯΔɽ·ͨɼύέοτͷഇ ࣗغମɼΠϯλʔωοτϓϩτίϧͰ௨৴ͷࠞࡶʹର Ԡ͢ΔͨΊʹਖ਼ߦʹنΘΕΔɽύέοτϩε߈ܸ͜Εͱ ۠ผͯ͠ݕ͞Εͳ͚ΕͳΒͳ͍ɽ ϫʔΫʹଓ͞Εͨଞͷͱثػಉ༷ɼ͜ͷϧʔλωοτ ॳظͷݕํ๏ɼૹ৴ଆ͔ΒૹΒΕΔύέοτͷૹ৴ ϫʔΫΛ௨ͨ͡߈ܸΛड͚ɼͬऔΒΕΔ͜ͱ͕͋Δɽ߈ ͱ࣮ࡍʹड͚औͬͨύέοτͷҧ͍͔Βύέοτͷഇ ܸऀʹͬऔΒΕͨϧʔλɼͦ͜Λ௨ա͢ΔύέοτΛ غΛݕ͠ɼͦͷഇغύέοτ͕͋ΔᮢΛ͑ͨ߹ ૢ࡞͢Δ͜ͱͰɼωοτϫʔΫͷ௨৴߈ܸΛֻ͚Δ ʹ߈ܸͱஅ͢ΔͷͰ͋ͬͨɽ͜ͷํࣜదͳᮢͷ ͜ͱ͕Ͱ͖Δɽ͜ͷ߈ܸํ๏ʹେผͯ͠ɼωοτϫʔΫ ઃఆ͕͍͚ͩ͠Ͱͳ͘ɼ߈ܸऀ͜ͷᮢະຬͰ͋Ε ੍ޚ໘Ͱͷ߈ܸͱɼωοτϫʔΫσʔλ໘Ͱͷ߈ܸͷೋͭ ߈ܸͱͯ͠ݕ͞ΕͣʹύέοτΛআ͢Δ͜ͱ͕Ͱ͖ͯ ͕͋ΔɽલऀϧʔλͷϧʔςΟϯάςʔϒϧͷૢ࡞ͳ ͠·͏͕͋Δɽ ͲɼഁյతͳӨݒ͕ڹ೦͞ΕΔ߈ܸΛؚΉͨΊɼͦΕΒʹ ผͷରࡦઃํܭͱͯ͠ɼࠞࡶʹΑΔύέοτഇغͷϞ ର͢Δ͕͜ڀݚΕ·Ͱଟ͘ͳ͞Ε͖͍ͯͯΔɽҰํऀޙ σϧΛཱͯɼͦΕΛʹجਖ਼نͷύέοτഇܸ߈ͱغΛ۠ผ ɼαʔϏε߈ܸதؒऀ߈ܸɼϦϓϨΠ߈ܸͳͲΛ ͢Δํ๏͋Δɽ͔͠͠ɼ͜ͷํ๏Ͱ߈ܸݕʹेͳ ؚΉɽதͰ௨ա͢ΔҙͷύέοτΛআ͢Δύέοτ ਫ਼ͰࠞࡶʹΑΔύέοτഇغΛϞσϧԽ͢Δͷ͍͠ ϩε߈ܸɼબతʹߦ͏͜ͱͰআύέοτྔͷগͳ͞ ͱ͍͏͕͋ͬͨɽ ʹରͯ͠େ͖ͳඃΛ༩͑ΔೳྗΛ࣋ͭɽྫ͑ɼTCP ͷ ͦͷ ޙMizrak ΒʹΑͬͯɼϧʔλͷύέοτసૹͷ ίωΫγϣϯཱ֬ͷͨΊʹ·ͣग़͞ΕΔ TCP SYN ύέο ͪߦྻʢΩϡʔʣΛਪఆ͢Δ͜ͱͰɼߴ͍ݕੑೳΛ࣋ τΛ͋Δαʔόͷ͚ͩআ͢Δ͜ͱͰɼ͜ͷαʔόΛ ͭɼ࣮ݱతͳύέοτϩε߈ܸݕํ͕ࣜఏҊ͞Εͨ [1] ɽ ར༻͠Α͏ͱ͍ͯ͠ΔϢʔβʹλΠϜΞτ·Ͱͷൺֱత ͜ͷํࣜɼ͋Δϧʔλʹ͓͍ͯύέοτϩε߈ܸ͕ߦΘ ͍࣌ؒͨͤΔ͜ͱΛ͍ڧΔ߈ܸ͕Ͱ͖Δ [2] ɽ Ε͔ͨͲ͏͔Λɼ௨৴ࠞࡶʹΑΔਖ਼نͷύέοτഇ۠ͱغ ͜ͷύέοτϩε߈ܸΛݕ͢Δʹɼ͋Δͣͷύ ผͯ͠ݕ͢Δɽύέοτͷഇ͕غ௨৴ࠞࡶʹΑΔਖ਼نͷ έοτ͕ແ͍͜ͱΛݕ͢Δඞཁ͕͋Γɼଞͷ߈ܸݕٕ ͷ͔Ͳ͏͔ͷ۠ผɼྡ͢ΔϧʔλͰͷ௨৴ͷ؍ଌ ใ͔Βύέοτసૹͷͪߦྻͷ࠹͕Γ۩߹Λਪଌͨ݁͠ 1 a) b) ౦ژେֶ The University of Tokyo [email protected] [email protected] ⓒ 2013 Information Processing Society of Japan ՌΛ༻͍ͯɼ౷ֶܭతʹߦ͏ɽ ͜ͷͪߦྻਪఆʹͮ͘جύέοτϩε߈ܸݕํࣜ 1 Vol.2013-DPS-154 No.28 Vol.2013-CSEC-60 No.28 2013/3/14 ใॲཧֶձڀݚใࠂ IPSJ SIG Technical Report ରͱ͢Δϧʔλͷͪߦྻͷ༰ྔͳͲશͯͷϧʔλ͕ i ri ͍ͬͯΔͱԾఆ͢Δɽ rs1 s2 .. . Q - ri - - rdi i 2.2 ௨৴ͷ؍ଌใ ૹ৴ଆͷϧʔλ rs1 ɼrs2 ɼ. . . ɼrsn ͔Βɼड৴ଆͷ ϧʔλ rd ɼૹ৴ͨ͠ύέοτͷใ͕ҎԼͷͰૹΒ rsn ΕΔɽ ਤ 1 ωοτϫʔΫߏਤɽ ɼ࣮ࡍͷ௨৴ʹରͯ͠ϦΞϧλΠϜʹ࣮ߦՄೳͰ͋Δ͜ ͱ͕࣮࣮͔֬ͰݧΊΒΕ͓ͯΓɼগͳ͍௨৴ෛՙ૿ՃͰ ߴ͍ݕਫ਼Λࣔͨ͠ɽ͔࣮࣮͠͠ݧͷͨΊɼͦͷੑೳ ධՁ·ͩཏ͞Ε͍ͯͳ͍ɽ͜ͷํؚ͕ࣜΉௐՄೳͳ ύϥϝʔλ௨৴ڥΛද͢ύϥϝʔλʹର͢Δݕੑೳ ͷґଘੑͷௐࠪͷॳΊͱͯ͠ɼզʑจ[ ݙ3] Ͱ͔ͭزͷ ࢦඪʹ͍ͭͯͦͷݕੑೳͷӨڹΛ؆୯ʹௐͨɽͦͷ ݁Ռɼదʹਖ਼نͷύέοτഇ͕͋غΔ௨৴ঢ়گʢਖ਼نͷ ύέοτഇૹ͕غ৴ύέοτͷ% ∼ े% ఔʣͰ ɼ௨৴ଳҬ෯ͪߦྻͷ༰ྔΛมԽͤͯ͞ݕੑೳ େ͖͘มΘΒͳ͍͜ͱ͕͔ͬͨɽ͔࣮͠͠ࡍʹɼ௨ ৴ྔ͕গͳ͘ਖ਼نͷύέοτഇ͕غશ͘ແ͍ঢ়͔گΒ௨৴ աଟͷͨΊʹଟ͘ͷύέοτ͕ਖ਼ʹنഇ͞غΕΔঢ়Ͱ·گɼ ͞·͟·ͳ௨৴ঢ়͜ى͕گΓ͏Δɽͦ͜ͰຊߘͰɼ͜ͷ ݕํࣜʹΑΔύέοτϩε߈ܸͷݕੑೳʹ͍ͭͯɼ ͷఔʹର͢ΔґଘੑΛௐͨ݁ՌΛใࠂ͢Δɽ 2. ߈ܸݕํࣜ ຊઅͰɼMizrak ΒʹΑͬͯఏҊ͞Εͨͪߦྻਪఆ ʹͮ͘جύέοτϩε߈ܸݕํࣜ [1] ʹ͍ͭͯɼͦͷ߈ ܸݕํ๏Λେ·͔ʹઆ໌͢Δɽ 2.1 ωοτϫʔΫϞσϧ ύέοτϩε߈ܸΛߦ͍ͬͯΔ͔Ͳ͏͔ΛௐΔରͷ ϧʔλΛ r ͱ͢Δɽr ɼྡ͢Δϧʔλ rs1 ɼrs2 ɼ. . . ɼ rsn ͔Βɼྡ͢Δϧʔλ rd ύέοτΛసૹ͢Δʢਤ 1ʣɽసૹ͞ΕΔύέοτɼϧʔλ r ͷͪߦྻ Q ʹ Ұ୴ೖΕΒΕɼͦͷઌͷసૹ͕ՄೳʹͳΔͱɼॱʹऔΓ ग़͞Εɼϧʔλ rd ૹ৴͞ΕΔɽQ ͕ॱ൪Λ͍ͬͯΔ ύέοτͰຒ·͍ͬͯΔͱɼ৽ͨʹ౸ணͨ͠ύέοτೖ {ʢύέοτͷϑΟϯΨʔϓϦϯτʣ, ʢύέοτʣ ʢ , ൃ৴࣌ࠁʣ} ͜ͷ௨৴ใɼҰఆ࣌ؒຖʹ·ͱΊΒΕɼ֤ૹ৴ଆϧʔ λ͔Βଗͬͯ rd ૹΒΕΔɽ ͜ΕʹରԠͯ͠ɼड৴ଆͷϧʔλ rd Ͱಉ༷ʹ௨৴Λ ؍ଌ͠ɼૹ৴ଆͱಉ࣌͡ࠁʹಉ࣌ؒ͡ຖͰ·ͱΊ͓ͯ͘ɽ ͜ͷ߹ɼ(1) ࣜͷ࠷ʹޙʢड৴࣌ؒʣΛೖΕΔɽ ݩͷݕख๏Ͱɼ͜ΕΒͷ௨৴ใॺ໊ͳͲΛࢪ͠ ্ͨͰૹ৴͞ΕΔɽ͜ΕʹΑΓɼ͜ͷݕख๏ͷϓϩτί ϧʹैΘͳ͍ϧʔλ͕͋ͬͯɼͦΕΛωοτϫʔΫ੍ޚ ໘Ͱͷ߈ܸͱͯ͠ݕͰ͖ΔΑ͏ʹͳ͍ͬͯΔɽ͜ͷ෦ ௨৴ࠞࡶʹΑΔύέοτഇͱغύέοτϩε߈ܸͷ۠ผ ʹؔ͠ͳ͍ͨΊɼຊߘͰׂѪ͢Δɽ 2.3 ݕखॱ ड৴ଆͷϧʔλ rd Ͱૹ৴ଆͷ௨৴ใͱड৴ଆͷ௨৴ ใ͕ू·ͬͨͱ͜ΖͰɼ͜ͷ࣌ؒ۠ؒʹ͓͚Δड৴ଆͷ ϧʔλ r ͷͪߦྻ Q ͷύέοτͷग़ೖΓ͔ΒɼQ ʹཷ·͍ͬͯΔύέοτͷ૯ྔͷਪଌ qpred ΛҎԼͷख ॱͰॱ࣍͢ࢉܭΔɽ ( 1 ) ௨৴ใΛҰͭͷྻʹ·ͱΊɼૹड৴࣌ؒͷૣ͍ॱ ʹฒΔɽ ( 2 ) (1) ͷྻ͔ΒॱʹҰͭͣͭύέοτใΛऔΓग़͠ɼ ҎԼͷํ๏Ͱ qpred Λߋ৽͢Δɽ ( a ) ͜ͷύέοτใ͕ड৴ଆͷͷͳΒɼ qpred (tcurrent ) = qpred (tprior ) −ʢύέοτʣ ( b ) ͜ͷύέοτใ͕ૹ৴ଆͷͷͰɼड৴ଆʹ ରԠ͢Δύέοτใ͕͋ΔͳΒɼ qpred (tcurrent ) = qpred (tprior ) +ʢύέοτʣ ( c ) ͜ͷύέοτใ͕ૹ৴ଆͷͷͰɼड৴ଆʹ Δ͜ͱ͕Ͱ͖ͣɼഇ͞غΕΔʢࠞࡶʹΑΔύέοτഇغʣ ɽ ରԠ͢Δύέοτใ͕ͳ͍ͳΒɼ ֤ύέοτ্͕ྲྀଆͷϧʔλ rsx ͔Βதؒͷϧʔλ r Λ௨ qpred (tcurrent ) = qpred (tprior ) ΓԼྲྀଆͷϧʔλ rd ʹಧ͘·Ͱʹɼͪߦྻ Q Ͱͷॱ (1) ͜Ε͕ύέοτഇغͷݕʹ͋ͨΔɽ ൪ͪͰඅ࣌ؒ͢ͷଞʹɼதؒͷϧʔλͷૹड৴ॲཧͷ (2c) ͷύέοτഇ͕غ௨৴ࠞࡶʹΑΔਖ਼نͷͷ͔ɼύ ࣌ؒͱɼύέοτͱճઢͷଳҬ෯ʹԠͨ͡ɼ֤ϧʔλؒ έοτϩε߈ܸʹΑΔͷ͔ɼQ ͕ຬഋ͔Ͳ͏͔Λ qpred Ͱͷసૹֻ͕͔࣌ؒΔɽ Ͱਪଌͯ͠ఆ͢Δɽ͜Ε୯७ͳൺֱ ߈ܸݕҰఆ࣌ؒຖʹɼྡ͢ΔϧʔλͰͷ௨৴ͷ؍ ଌใΛরΒ͠߹Θͤͯߦ͏ɽͦͷͨΊɼ֤ϧʔλͷ࣌ܭ શͯಉ͍ͯ͠ظΔͱԾఆ͢Δɽ·ͨɼ֤ճઢͷଳҬ෯ ⓒ 2013 Information Processing Society of Japan ʢQ ͷ༰ྔʣ< qpred +ʢύέοτʣ (2) ͰఆͰ͖Δ͕ɼͦͷ߹ qpred ͷਪఆͷෆਖ਼͔֬͞Β 2 Vol.2013-DPS-154 No.28 Vol.2013-CSEC-60 No.28 2013/3/14 ใॲཧֶձڀݚใࠂ IPSJ SIG Technical Report དྷΔఆؒҧ͍͕ଟ͘ग़͖ͯͯ͠·͏ɽ͜ΕΛ͑Δͨ ϛϡϨʔγϣϯͰ؆୯ͷͨΊʹɼશͯͷύέοτಉҰ Ίɼจ[ ݙ1] Ͱ౷͍ͨͮجʹֶܭఆΛߦ͏ɽ ͷύέοτʢ1500 bytesʣΛ࣋ͭͷͱ͢Δɽ µ =ʢqpred ͷਅ͔ΒͷͣΕͷฏۉʣ (3) σ =ʢqpred ͷਅ͔ΒͷͣΕͷඪ४ภࠩʣ (4) ૹ৴ଆ͔Βͷύέοτͷૹ৴؆୯ͷͨΊɼຌͦҰఆؒ ִʢ୯Ґ࣌ؒͨΓ 1 ύέοτʣͰߦ͏͜ͱͱ͢Δɽͨͩ ͠ࢹରͱ͢Δϧʔλ r Ͱͷͪߦྻͷ࠹͕Γ۩߹ʹม ͜ͷ࣌ؒ۠ؒʹ n ݸͷύέοτഇ͢ͱ͔ͨͬͭݟ͕غ ԽΛ༩͑ΔͨΊɼ͜ͷִؒཚʹΑΓૹ৴ຖʹ͋Δఔ Δɽ֤ഇغύέοτʹ͍ͭͯɼҎԼͷํ๏Ͱͨ͠ࢉܭ৴པ ༳Β͕ͤΔɽ ͱ༧Ίઃఆͨ͠༗ҙਫ४ͷൺֱΛߦ͍ɼύέοτϩε߈ ܸ͔Ͳ͏͔Λఆ͢Δɽ ʢQ ͷ༰ྔʣ− qpred −ʢύέοτʣ− µ y= σ √ 1 + erf(y/ 2) c= 2 c < ssingle ͳΒɼࠞࡶʹΑΔഇغ c ≥ ssingle ͳΒɼύέοτϩε߈ܸ ௨৴ͷɼ௨৴ྔʹରͯ͠ճઢͷଳҬ෯ͷେ͖͕͞ খ͍͞߹ɼ·ͨ௨৴ͷʹରͯ͠ϧʔλͷॲཧೳྗ͕ খ͍͞߹ʹ͜ىΔɽճઢͷଳҬ෯Λখ͘͢͞Δͱύέο (5) (6) (7) (8) τసૹͷԆ͕૿͑ɼಉͯ͠ظಈ࡞͢Δ͜ͷݕํࣜʹ༨ ͳܭෆ߹Λ༩͑ΔɽͦͷͨΊຊߘͰɼதؒͷϧʔλ r ͷసૹॲཧೳྗʢ୯Ґ࣌ؒͨΓʹૹ৴Ͱ͖Δύέοτʣ Λม͑Δ͜ͱͰΛൃੜͤͨ͞ɽ ύέοτϩε߈ܸɼࢹରͱ͢Δϧʔλ r Ͱదٓద ݸʑͷഇغύέοτʹ͍ͭͯͷఆͰͯ͢߈ܸͰͳ͍ͱ ͳύέοτΛͦͷઌૹΒͣʹআ͢Δ͜ͱͰߦͬͨɽ ఆ͞Εͨ߹ɼͦΕʹଓ͚ͯɼ͜ͷ࣌ؒ۠ؒͷ n ݸ ௨৴ࠞࡶʹΑΔਖ਼نͷύέοτഇ۠ͱغผͯ͠ɼ͜ΕΛݟ ͷύέοτഇغશମʹ͍ͭͯύέοτϩε߈ܸʹΑΔύ ಀͣ͞ʹൃ͖ͰݟΕݕޭͱͳΔɽҰํɼ͜ΕΛݟ έοτআ͕·ؚΕ͍ͯΔ͔Ͳ͏͔Λఆ͢Δɽ͜͜Ͱ ಀ͢ͱِӄੑൃੜʹͳΔɽ·ͨɼ͜ΕҎ֎ͷՕॴΛ߈ܸͱ ҎԼͷํ๏Ͱ৴པΛ͠ࢉܭɼ͜Εͱ༧Ίઃఆͨ͠༗ҙਫ ͯ͠ఆ͢Δͱِཅੑͱͯ͑͠Δɽ γϛϡϨʔγϣϯͪߦྻ͕ۭͷঢ়ଶͰ࢝Ίɼݕͷ ४Λൺֱͯ͠߈ܸͷఆΛߦ͏ɽ ࣌ؒ۠ؒͰ 10 ۠ؒਐΊΔΛҰճͷ࣮ߦͱ͢ΔɽҰͭ ʢQ ͷ༰ྔʣ−ʢqpred ͷฏۉʣ −ʢύέοτͷฏۉʣ− µ √ σ n z= c= √ 1 + erf(z/ 2) 2 c < scomb (10) (11) ͳΒɼ ύέοτϩε߈ܸΛؚΉ ͯ͠ੑೳධՁΛߦ͏ɽ 4. ༧උ࣮ݧ ͜ͷύέοτϩεݕํࣜ౷ֶܭతͳݕํࣜͰ͋Γɼ ͳΒɼ શͯࠞࡶʹΑΔഇغ c ≥ scomb ͷύϥϝʔλઃఆʹ͖ 10 ճͷ࣮ߦΛߦͬͨ݁ՌΛूܭ (9) ͪߦྻ Q ͷਪఆ qpred ͷࠩޡͷͷඪ४ภࠩΛͬ ͯݕΛߦ͏ʢ(8) ࣜɼ(12) ࣜࢀরʣ ɽͦ͜ͰຊߘͰݕ ࣮ݧΛߦ͏લʹɼ͜ͷඪ४ภࠩͷΛ࣮ʹݧΑΓಋ͘ɽ (12) ͜ͷ࣮ݧɼύέοτϩε߈ܸݕ࣮ͱݧಉ͡γϛϡ ͜ΕʹΑΓɼ͜ͷ࣌ؒ۠ؒʹରͱ͢Δϧʔλ r ͕ύ Ϩʔγϣϯ࣮ݧΛύέοτϩε߈ܸ͕ແ͍ঢ়ଶͰ࣮ߦ͢Δ έοτϩε߈ܸΛ͓͜ͳ͔ͬͨͲ͏͔͕ఆͰ͖Δɽ ͜ͱͰߦ͢Δɽதؒͷϧʔλ r ͷసૹॲཧೳྗʢ୯Ґ࣌ 3. ௐࠪํ๏ จ[ ݙ1] ͰɼఏҊ͞Εͨͪߦྻਪఆʹͮ͘جύέο ؒͨΓʹૹ৴Ͱ͖Δύέοτʣ ɼݕͷ࣌ؒ۠ؒɼதؒ ͷϧʔλ r ͷͪߦྻͷ༰ྔΛม͑ͨͱ͖ͷ͜ͷඪ४ภࠩ ͷਤ 2 ɼਤ 3 ͷΑ͏ʹͳͬͨɽࠓճͷ࣮Ͱݧύέο τϩε߈ܸݕํࣜͷੑೳΛɼ࣮ػͷ࣮Λ࣮ͬͨݧ τ্ྲྀଆͷϧʔλҰͭʹ͖୯Ґ࣌ؒͨΓҰૹݸΒΕ ͰධՁ͍ͯͨ͠ɽ͜ͷධՁํ๏࣮࣌ؒͰͷॲཧͷ͕ূݕ ͯདྷΔɽ্ྲྀଆͷϧʔλೋͭ͋ΔͨΊɼ͜ΕΒͷਤʹ͓ ՄೳͰ͋ΔͳͲͷརΛ͕࣋ͭɼํؚ͕ࣜΉύϥϝʔλʹ ͍ͯԣ࣠ͷ͕ 2 Λ͑Δͱ΄΅ແ͘ͳΔɽҰํԣ ର͢ΔৼΔ͍Λ͢ূݕΔ͜ͱଟ͘ͷ߹ࠔͰ͋Δɽ ࣠ͷ͕ 2 ΛԼճΔͱඞͣ͜ىΔΑ͏ʹͳΔɽ ͦ͜ͰຊߘͰจ[ ݙ3] ͱಉ༷ʹγϛϡϨʔγϣϯ࣮ʹݧ ΑΓੑೳධՁΛߦ͏ɽ ωοτϫʔΫͷߏจ[ ݙ1] ͷ࣮࣮ʹݧ฿͍ɼਤ 1 ͷߏͰɼૹ৴ଆͷϧʔλΛೋͭͱͨ͠ɽ ͜ͷ࣮݁ݧՌͰɼͪߦྻͷ༰ྔ͕খ͍͞ʢύέοτ ͕ೋ͔͠ݸೖΒͳ͍ʣ߹ࠩޡͷඪ४ภࠩதؒͷ ϧʔλ r ͷసૹॲཧೳྗʹ͋·Γґଘ͠ͳ͍͕ɼͪߦྻ ͷ༰ྔ͕େ͖͍ʢύέοτ͕ 20 ݸҎ্ೖΔʣ߹ԣ࣠ จ[ ݙ1] ͷ࣮࣮͍͓ͯʹݧɼ௨৴ࠞࡶʹΑΔਖ਼نͷύ ͷ͕ 2 Λ͑Δͱ͜ΖͰ༰ྔ͕খ͍͞߹ͱಉ༷ͷ έοτഇغΛൃੜͤ͞ΔͨΊʹେ͖ͳσʔλͷμϯϩʔ ʹͳΓɼԣ࣠ͷ͕ 2 ΛԼճΔͱҰܻఔେ͖ͳʹͳͬ υΛओͳ௨৴ʹͨ͠ͱ͜Ζɼ΄ͱΜͲͷύέοτ͕࠷େύ ͍ͯΔɽ͜Ε͕͖ىଓ͚͍ͯΔ௨৴ঢ়Ͱگɼͪ έοτͷͷʹͳΔ͜ͱ͕͔ͬͨɽͦ͜Ͱࠓճͷγ ߦྻͰͨ͞ΕΔ͕࣌ؒ༰ྔͷେ͖͚ͩ͘͞ͳΓɼͪ ⓒ 2013 Information Processing Society of Japan 3 Vol.2013-DPS-154 No.28 Vol.2013-CSEC-60 No.28 2013/3/14 ใॲཧֶձڀݚใࠂ IPSJ SIG Technical Report ϯ࣮ݧΛߦͬͯௐͨɽγϛϡϨʔγϣϯͷҰճͷ࣮ߦ standard deviation interval = 10 unit time interval = 100 unit time interval = 1000 unit time ݕͷ࣌ؒ۠ؒ 10 ͔ݸΒΓɼҰͭͷύϥϝʔλઃఆʹ ͖ 10 ճͷ࣮ߦΛߦ͍ɼͦͷ݁ՌΛूͯ͠ܭੑೳධՁͱ 1000 ͨ͠ɽ ύέοτશͯ 1500 bytes ͱҰఆʹ͠ɼ্ྲྀଆͷೋ 100 ͭͷϧʔλ͔Β୯Ґ࣌ؒʹҰૹݸ৴ͨ͠ɽ͜ΕΛதؒ ͷϧʔλͰूΊɼԼྲྀଆͷϧʔλసૹ͢Δɽͦͷࡍɼύ 10 έοτϩε߈ܸͱͯ͠ೋͭͷ࣌ؒ۠ؒͰͦΕͧΕҰݸͷύ έοτΛআͨ͠ɽ 1 0 1 2 3 packets / unit time 4 5 ਤ 2 ͪߦྻਪఆͷࠩޡͷඪ४ภࠩʢ༰ྔ͕ 4000 bytes ͷ߹ʣ ɽ standard deviation interval = 10 unit time interval = 100 unit time interval = 1000 unit time ݕͷ࣌ؒ۠ؒ 100 ୯Ґ࣌ؒͱͨ͠ɽதؒͷϧʔλʹ ಧ͘ύέοτݕͷ࣌ؒ۠ؒͨΓ 200 ͳͱݸΔɽ ͪߦྻͷେ͖͞༧උ࣮ͱݧಉ͘͡ 4000 bytes ͱ 40000 bytes ͷೋ௨ΓͰ࣮ݧΛߦͬͨɽݕͷࡍʹ͏ͪߦྻ ਪఆͷࠩޡͷඪ४ภࠩʹ͍ͭͯɼ༧උ࣮ݧͷ݁Ռ͔ Β 12 ͱ 160 ͷೋͭͷʹ͍ͭͯͦΕͧΕ࣮ݧΛߦͬͨɽ 1000 ݕʹ༻͍Δೋͭͷ༗ҙਫ४จ[ ݙ1] ͱಉ͡ʹͨ͠ɽ 100 10 ssingle = 0.999 (13) scomb = 0.9 (14) தؒͷϧʔλͷసૹॲཧೳྗʢ୯Ґ࣌ؒͨΓʹ ૹ৴Ͱ͖ΔύέοτʣΛม͑Δ͜ͱͰൃੜͤͨ͞ɽ্ྲྀ 1 0 1 2 3 packets / unit time 4 5 ਤ 3 ͪߦྻਪఆͷࠩޡͷඪ४ภࠩʢ༰ྔ͕ 40000 bytes ͷ߹ʣ ɽ ଆ͔Β୯Ґ࣌ؒͨΓೋݸͷύέοτ͕ૹ৴͞ΕΔͷ Ͱɼ͜ͷసૹॲཧೳྗ͕୯Ґ࣌ؒͨΓ 2 ΛԼճΔͱ ͕ඞͣൃੜ͢Δɽ ௨৴ঢ়گ͕͋Δ߹ແ͍߹͋ΔͨΊɼݕੑ ද 1 ݕ݁Ռʢ༰ྔɿ 4000 bytes ɼඪ४ภࠩɿ 12.0 ʣ ɽ ύέοτసૹೳྗ 1.00 1.33 1.67 2.00 4.00 ʢݸʗ୯Ґ࣌ؒʣ ೳͷධՁ࣮Ͱݧ͜ͷ྆ํͷඪ४ภࠩͷʹ͍ͭͯͦΕͧ ૯ύέοτ 20030 19896 19972 20052 19961 Ε࣮ݧΛߦͬͨɽ ࠞࡶʹΑΔഇغ 10012 6551 3348 750 0 ߈ܸʹΑΔআ 20 20 20 20 20 100 100 100 100 100 20 20 20 20 20 ߦྻͷਪఆͷͣΕ͕େ͖͘ͳΔͨΊͱߟ͑ΒΕΔɽ࣮ࡍͷ ݕͷ࣌ؒ۠ؒͷ͕͘͞ͳΔͱɼͪߦྻਪఆͷޡ ࠩͷඪ४ภࠩͷখ͘͞ͳ͍ͬͯΔɽ͜Εඪຊ ૯۠ؒ ߈ܸݕޭ۠ؒ ͕૿͑Δ͜ͱͰฏۉʹऩଋ͍ͯ͘͜͠ͷछͷ؍ଌͷੑ ߈ܸແ͠ఆޭ۠ؒ 0 3 5 20 72 ࣭Λөͨ͠ͷͰ͋Δɽ ݕޡʢೞΕҥʣ۠ؒ 80 77 75 60 8 ݕޡʢݟಀ͠ʣ۠ؒ 0 0 0 0 0 ͜ͷ༧උ࣮͔ݧΒɼ͜ͷύϥϝʔλઃఆͷลΓͰ 100 ύέοτఔͷ௨৴͕ߦΘΕΕωοτϫʔΫͷঢ়گॆ ʹ҆ఆ͢Δ͜ͱ͕͔ͬͨɽͦ͜Ͱ࣮ݧͷखؒߟ͑ɼ ؒʹͯ͠ߦ͏͜ͱʹͨ͠ɽύέοτ্ྲྀଆϧʔλͷͦΕ ද 2 ݕ݁Ռʢ༰ྔɿ 40000 bytes ɼඪ४ภࠩɿ 160.0 ʣ ɽ ύέοτసૹೳྗ 1.00 1.33 1.67 2.00 4.00 ʢݸʗ୯Ґ࣌ؒʣ ͧΕ͔Β୯Ґ࣌ؒʹҰݸఔൃ৴͞ΕΔͷͰɼݕͷ֤࣌ ૯ύέοτ ݕੑೳͷධՁ࣮ݧݕͷ࣌ؒ۠ؒͷ͞Λ 100 ୯Ґ࣌ ؒ۠ؒʹ͓͍ͯதؒͷϧʔλ r ʹ 200 ݸఔͷύέοτ ͕ಧ͘ɽύέοτϩε߈ܸͷݕʹ͜ͷఔͷύέοτ 19733 19729 19695 19891 20024 ࠞࡶʹΑΔഇغ 9718 6384 3016 4 0 ߈ܸʹΑΔআ 20 20 20 20 20 100 100 100 100 100 20 20 20 20 20 ૯۠ؒ ͕͋ΕेͰ͋Δɽ·ͨ͜ͷ࣌ؒ۠ؒͷ͍͞΄ ߈ܸݕޭ۠ؒ ͏͕ɼݕΛૉૣ͘ɼ·ͨࡉ͔͘ߦ͏͜ͱ͕Ͱ͖ɼηΩϡ ߈ܸແ͠ఆޭ۠ؒ 0 0 0 5 78 ϦςΟٕज़ͱͯ͠߹͕ྑ͍ɽ ݕޡʢೞΕҥʣ۠ؒ 80 80 80 75 2 ݕޡʢݟಀ͠ʣ۠ؒ 0 0 0 0 0 5. ݁Ռ จ[ ݙ1] ͷݕํࣜʹΑΔύέοτϩε߈ܸͷݕੑೳ ͦΕͧΕͷ࣮݁ݧՌද 1 ɼද 2 ͷΑ͏ʹͳͬͨɽͳ ͕ͷఔʹΑΓͲΕ͚ͩมΘΔͷ͔ΛγϛϡϨʔγϣ ͓ɼͦΕͧΕͷύϥϝʔλઃఆͰඪ४ภࠩͷ͕ҟͳΔ࣮ ⓒ 2013 Information Processing Society of Japan 4 Vol.2013-DPS-154 No.28 Vol.2013-CSEC-60 No.28 2013/3/14 ใॲཧֶձڀݚใࠂ IPSJ SIG Technical Report ݧʢ༰ྔ͕ 4000 bytes Ͱඪ४ภࠩͷΛ 160.0 ͱͨ͠ ͷ࣌ؒ۠ؒͷඈͼӽ͕͑ൃੜ͠ɼͦΕ͕ݕޡʢೞΕҥʣ ͷͱɼ༰ྔ͕ 40000 bytes Ͱඪ४ภࠩͷΛ 12.0 ͱͨ͠ ʹ͕ܨΔͱ͍͏͕͔͍ͬͯΔɽ্هͷ՝ͷݪ ͷʣͷ݁ՌɼͦΕͧΕ͜ΕΒͷදͱશʹಉ͡ͷʹ Ҽ͕͜ͷʹ͋Δ߹ɼͦͷղফʹɼୈ 2.3 અͰઆ ͳͬͨɽ͜ΕࠓճͷੑೳධՁͷൣғͰ͜ͷఔͷඪ४ ໌ͨ͠ύέοτഇغͷݕʹ͓͍ͯྡ͢Δ࣌ؒ۠ؒͷύ ภࠩͷͷҧ͍͕ݕ݁ՌʹӨͱ͍͜ͳ͠ڹΛࣔ͢ɽຊདྷ έοτใར༻͢Δ͜ͱɼԼྲྀଆͷϧʔλͰͷ௨৴؍ Ͱ͋Εɼͪߦྻਪఆࠩޡͷඪ४ภࠩͷ͕Ұܻେ ଌใ࡞ͷࡍʹͪߦྻͰͷԆਖ਼֬ʹਪఆ͢Δͳ ͖͘ͳΔͱɼ༗ҙਫ४ͱͷൺֱʹ༻͍Δ৴པͷ͓ʹࢉܭ Ͳɼݕํࣜͷେ෯ͳվྑ͕ඞཁʹͳΔɽ ͍ͯؔࠩޡͷҾ͕Ұܻখ͘͞ͳΓɼͦΕʹରԠͯ͠৴ པ͕খ͘͞ͳΔɽͦͷͨΊݕͷͨΊͷఆ͕ͳ͘ ࢀߟจݙ Γɼݕޡʢݟಀ͠ʣ͕૿͑ΔͣͰ͋Δɽ͔͠͠ࠓճͷ [1] ࣮݁ݧՌͰશͯͷγϛϡϨʔγϣϯ࣮ߦʹ͓͍ͯݕޡ ʢݟಀ͠ʣແ͔ͬͨɽ͜ͷ৯͍ҧ͍ͷղ໌ͷͨΊʹ֤ [2] ఆΛৄࡉʹௐΔඞཁ͕͋Δɽ ͦΕͧΕͷݕ݁Ռʹ͍ͭͯɼ·ͣύέοτϩε߈ܸ ͕͋ͬͨશͯͷ࣌ؒ۠ؒΛਖ਼͘͠߈ܸͷ͋ͬͨ۠ؒͱఆ ͠ɼݕޡʢݟಀ͠ʣҰ݅ແ͔ͬͨɽ͜ͷ݁Ռͪ ߦྻͷ༰ྔύέοτͷసૹॲཧೳྗɼଈͪͷఔʹ ґଘ͠ͳ͍݁Ռͱͳͬͨɽ [3] A. Mizrak, S. Savage, and K. Marzullo, “Detecting Malicious Packet Losses”, In IEEE Transactions on Parallel and Distributed Systems, Vol.20, No.2 (February 2009). A. Kuzmanovic and E.W. Knightly, “Low-rate TCPtargeted Denial of Service Attacks: the Shrew versus the Mice and Elephants”, Proceedings of ACM SIGCOMM’03, pp.75-86 (August 2003) ࡉҪ ୖ࿕, দӜ װଠ, “ͪߦྻਪఆʹͮ͘جύέοτϩ ε߈ܸݕํࣜͷύϥϝʔλґଘੑʹ͍ͭͯ”, ίϯϐϡʔ ληΩϡϦςΟγϯϙδϜ 2012ʢCSS2012ʣจू, ൃ ද 2B3-1 ʢCD-ROMʣʢ2012 10 ݄ʣ ҰํɼݕޡʢೞΕҥʣͷ۠ؒύέοτͷసૹॲཧ ೳྗʢ୯Ґ࣌ؒͨΓʹૹ৴Ͱ͖Δύέοτʣɼ͕ 2 Λ ԼճͬͯԼ͕Δʹै͍େ͖͘ͳͬͨɽͦͷఔͪߦྻ ͷ༰ྔ͕େ͖͍΄͏͕ݦஶͰ͋ΔɽଈͪʹΑΓݕޡ ʢೞΕҥʣ͕ൃੜ͍ͯ͠Δ͜ͱ͕͔Δɽಛʹ͕͍ڧ ʢύέοτసૹೳྗ͕খ͍͞ʣͱύέοτϩε߈ܸ͕ແ͔ͬ ͨ࣌ؒ۠ؒΛશͯݕޡʢೞΕҥʣͯ͠͠·͍ͬͯΔɽ͜ ͷ෦Ͱɼ߈ܸ͕͋ͬͨ۠ؒਖ਼͘͠߈ܸͱͯ͠ݕ͞ Ε͍ͯΔ݁Ռ͔Βߟ͑Δͱɼ͕͍ͨڧΊ߈ܸͷ༗ແʹ ΘΒͣશͯͷ࣌ؒ۠ؒΛ߈ܸ͕͋ͬͨͷͱఆ͍ͯ͠ ΔΑ͏ʹ͑ݟΔɽ͜ΕΛ͔֬ΊΔʹɼҰ݅ʑʑͷఆ͕ ͲͷΑ͏ʹͳ͞Εͨͷ͔ৄࡉʹௐΔඞཁ͕͋Δɽ ͕ແ͘ɼݕޡʢೞΕҥʣ͕গͳ͑͘ΒΕ͍ͯΔ ࣮݁ݧՌ͔Βɼ͕ແ͍ͱ͜ΖͰ͜ͷݕํ͕ࣜਖ਼ ͘͠ಈ࡞͢Δ͜ͱ͕͔Δɽ 6. ·ͱΊ ຊߘͰɼจ[ ݙ1] ͰఏҊ͞Εͨͪߦྻਪఆʹͮ͘ج ύέοτϩε߈ܸݕํࣜʹ͍ͭͯɼͷఔʹର͢Δ ݕੑೳͷมԽΛௐͨɽͦͷ݁Ռɼͷ༗ແݕͷ ࡍͷఆࣜʹ༻͍Δͪߦྻਪఆࠩޡͷඪ४ภࠩͷ Λม͑Δ͕ͦͷൣғͰඪ४ภࠩͷΛม͑ͯݕ݁Ռ͕ มΘΒͳ͍͜ͱɼ߈ܸͷ͋Δ࣌ؒ۠ؒͷݕʹؔ ͳ͘ਖ਼͘͠ߦ͑Δ͜ͱɼ͕ແ͍ͱݕޡগͳ͍Ұํɼ ͕ੜ͡Δͱ߈ܸͷແ͍࣌ؒ۠ؒͷݕޡʢೞΕҥʣ͕ ଟ͘ൃੜ͢Δ͜ͱ͕͔ͬͨɽ ͕͘ڧશͯͷ࣌ؒ۠ؒΛ߈ܸ͋Γͱఆͯ͠͠·͏ ͜ͷͷղ໌ʹɼͦΕͧΕͷఆΛৄࡉʹௐΔඞཁ ͕͋Γɼࠓޙͷ՝ͱͯ͠Δɽจ[ ݙ3] Ͱͷ࣮͔ݧΒɼ ݕͷ࣌ؒ۠ؒͷڥքʹ͓͍ͯ௨৴ͷԆʹΑΔύέοτ ⓒ 2013 Information Processing Society of Japan 5