cNotes ¸¡º÷ °ìÍ÷ ¥«¥Æ¥´¥ê

tarpit¤Çspam¤ò»ß¤á¤ë

Published: 2007/10/24

¥Ü¥Ã¥È¤òÍøÍѤ·¤¿spamÁ÷¿®¤ÎÆÃħ¤È¤·¤Æ°Ê²¼¤Î¤è¤¦¤Ê¤â¤Î¤¬¤è¤¯Ê¹¤«¤ì¤ë¡£

  • °ìÅÙ¶¯À©ÀÚÃǤµ¤ì¤ì¤ÐºÆÁ÷¤·¤è¤¦¤È¤·¤Ê¤¤
  • timeout»þ´Ö¤¬Ã»¤¤

¼ÂºÝ¤Ï¤É¤¦¤Ê¤Î¤«¡©ÅÔ»ÔÅÁÀâ¤Ê¤Î¤«¡©¤³¤³¤Ç¤ÏHoneyPot¤È²¾ÁÛMTA¥·¥¹¥Æ¥à¤Ë¤è¤ê¡¢¼ÂºÝ¤Î¥æ¡¼¥¶¡¼¤äMTA¤ËÌÂÏǤò¤«¤±¤ë¤³¤È¤Ê¤¯spammer¤òµ½¤¤¤Æbot·Ðͳ¤ÎspamÁ÷¿®¤òÊ᪤·´Ñ¬¤Ç¤­¤ë¡£¤½¤³¤Çbot¤äbotnet¤ÎµóÆ°¤Î²òÀϤä¼ÂºÝ¤ÎspamÁ÷¿®¤ËÂФ·¤Æ¤µ¤Þ¤¶¤Þ¤Êºö¤ò»Ü¤·¤Æ¤ß¤Æ¤½¤ÎµóÆ°¤ÎÊѲ½¤ò¸«¤ë¤³¤È¤¬¤Ç¤­¤ë¤Î¤À¤¬¡¢¤½¤Î·ë²Ì¤Ï°Ê²¼¤Î¤è¤¦¤Ê¤â¤Î¤Ç¤¢¤Ã¤¿¡£

  • °ìÅÙ¶¯À©ÀÚÃǤµ¤ì¤ì¤ÐSMTP¥ì¥Ù¥ë¤Ç¤ÎºÆÁ÷¤Ï¹Ô¤ï¤Ê¤¤
  • SMTP¥ì¥Ù¥ë¤Ç¤Î¶¯À©ÀÚÃǤËÈ¿±þ¤·¤Ê¤¤¤â¤Î¤¬¤¢¤ë
  • timeout»þ´Ö¤Ï°Õ³°¤ÈÉáÄÌ¡©

1.°ìÅÙ¶¯À©ÀÚÃǤµ¤ì¤ì¤ÐSMTP¥ì¥Ù¥ë¤Ç¤ÎºÆÁ÷¤Ï¹Ô¤ï¤Ê¤¤

¡¡bot·Ðͳ¤ÇÁ÷¿®¤µ¤ì¤ëspam¤ÎÂçȾ¤Ïbot¤òProxy¥µ¡¼¥Ð¡¼¤È¤·¤ÆÍøÍѤ·¤Æ¤¤¤ë¤À¤±¤Ç¡¢¼ÂºÝ¤Î¥á¡¼¥ëÁ÷¿®¤Ïspammer¤¬»ÈÍѤ¹¤ëspamÁ÷¿®¥Ä¡¼¥ë¡Êmass¥á¡¼¥é¡¼¡Ë¤Ç¹Ô¤Ã¤Æ¤¤¤ë¤À¤±¤Î¤â¤Î¡£bot¤ÏMTA¤Ç¤Ï¤Ê¤¯MUA¡£MTA´Ö¤ÎºÆÁ÷¤Î¥ë¡¼¥ë¤Ë½¾¤¦¤ï¤±¤Ç¤Ï¤Ê¤¤¡£¼ÂºÝ¤ÎÁ÷¿®¤Ï¤Ò¤È¤Ä¤ÎÁ÷¿®Àè¥ê¥¹¥È¤òÍѤ¤¤Æ1¡Á3¼þÄøÅÙÁ÷¿®¤ò¹Ô¤¦¤Î¤Ç¡¢°ìÅÙÁ÷¿®¤Ë¼ºÇÔ¤·¤¿¤é¡¢¡ÖÀßÄê¤Ë¤è¤Ã¤Æ¤Ï¡×¼¡¤Î¥ë¡¼¥Æ¥£¥ó¤Ç¤â¤¦°ìÅÙÁ÷¿®¤ò»î¤ß¤ë¤³¤È¤Ë¤Ê¤ë¡£ºÆÁ÷¤È¤Ï´Ø·¸¤Ê¤¯¼ºÇÔ¤·¤¿MTA¤ä¼ºÇÔ¤·¤¿Á÷¿®Àè¾ðÊó¤ò¥ê¥¹¥È²½¤·¤Æ¡Ö»È¤¨¤Ê¤¤MTA¡×¡Ö¤Ä¤«¤¨¤Ê¤¤Á÷¿®Àè¡×¤È¤·¤ÆspamÁ÷¿®¤Î¤¿¤á¤Î¥ê¥¹¥È¤Î¥¯¥ê¡¼¥Ë¥ó¥°¤ËÍѤ¤¤é¤ì¤¿¤ê¤â¤¹¤ë¡£¤Þ¤¿bot¤Ë¼«Î©Åª¤Ë¥á¡¼¥ëÁ÷¿®¤¹¤ëµ¡Ç½¤¬Æ³Æþ¤µ¤ì¤Æ¤¤¤ë¾ì¹ç¤Ç¤âMUA¤Ç¤¢¤êÁ°½Ò¤ÈƱÍͤεóÆ°¤ò¼¨¤¹¡£¤·¤¿¤¬¤Ã¤Æ°ìÅÙ¤­¤ê¤ÎÁ÷¿®¹Ô°Ù¤ò·«¤êÊÖ¤·¤Æ¼Â¹Ô¤·¤Æ¤¤¤ë¤À¤±¤Ç¤¢¤ê¡¢Á÷¿®list¤ÎŤµ¡¢ÀßÄê¤Ë¤è¤êºÆÁ÷¤¬¤¢¤Ã¤¿¤ê¡¢¤Ê¤«¤Ã¤¿¤ê¡¢10ʬ¸å¤À¤Ã¤¿¤ê¡¢¤¤¤í¤¤¤í¤Ê¸«¤¨Êý¤ò¤¹¤ë¡£¤Ä¤Þ¤ê¡ÖSMTPŪ¤ÊºÆÁ÷¡×¤Ï¤Ê¤¤¤È¤¤¤Ã¤Æ¤¤¤¤¤È»×¤¦¡£


2.SMTP¥ì¥Ù¥ë¤Ç¤Î¶¯À©ÀÚÃǤËÈ¿±þ¤·¤Ê¤¤¤â¤Î¤¬¤¢¤ë

¡¡MTA¤«¤é500ÈÖÂæ¤ä400ÈÖÂæ¤Ç±þÅú¤·¤Æ¤â̵»ë¡£MTA¦¤ÇSMTP¥ì¥Ù¥ë¤ÇÀÚÃǤµ¤ì¤Æ¤âTCP connection¤Ï°Ý»ý¤µ¤ì¤¿¤Þ¤Þ¤È¤¤¤¦¥á¡¼¥ë¥µ¡¼¥Ð¡¼Åª¤Ë¤ÏÈó¾ï¤Ë¤ä¤Ã¤«¤¤¤Ê¾õ¶·¤Ë¤Ê¤ë¤â¤Î¤¬¤¢¤ë¡£spam¤ò»ß¤á¤¿¤é¡¢¤¤¤ï¤æ¤ëDDoS¡¢¤¤¤ï¤æ¤ëconnection flood¤ò¿©¤é¤¦¾õ¶·¤Ë¤Ê¤ê¡¢¥µ¡¼¥Ð¡¼¥ê¥½¡¼¥¹¤¬¸Ï³é¤·¤Æ¥á¡¼¥ëÁ÷¿®ÉÔǽ¤Ë¤Ê¤Ã¤Æ¤·¤Þ¤¦¡£¤³¤Î¤è¤¦¤ÊÌäÂê¤Ï2006ǯÅö½é¤«¤éISP³Æ¼Ò¤òǺ¤Þ¤»¤Æ¤¤¤¿¤ê¤¹¤ë¡£¤³¤ì¤Ï¤µ¤¹¤¬¤Ë°Õ¿ÞŪ¤Ç¤Ï¤Ê¤¯¡¢°ìÉôÁ÷¿®¥Ä¡¼¥ë¤ÎÉÔÈ÷¤Ë¤è¤ë¤â¤Î¤À¤È»×¤¦¤¬¡¢¤É¤ó¤Ê¤â¤Î¤Ç¤âºî¤Ã¤¿Â¦¤Î°Õ¿Þ¤Ë¤è¤é¤ºÊ̤θú²Ì¤òÀ¸¤ß½Ð¤·¤Æ¤·¤Þ¤¦Î㤬¿ô¿¤¯¤¢¤ë¤¬¡¢¤³¤ì¤â¤½¤Î¤Ò¤È¤Ä¤À¤í¤¦¡£¤³¤ì¤ËÂбþ¤¹¤ë¤¿¤á¤Ë¤ÏMTA¦¤ÇSMTP¥ì¥Ù¥ë¤ÎÀÚÃǤÈƱ»þ¤ËTCP¥³¥Í¥¯¥·¥ç¥ó¤â¶¯À©ÀÚÃǤ¹¤ë»ÅÁȤߤ¬É¬Íפˤʤ롣


3.timeout¤Ï°Õ³°¤ÈÉáÄÌ¡©

¡¡bot¤«¤é¤ÎsmtpÄÌ¿®¤Îtimeout¤¬Ã»¤¤¤È¤è¤¯¤¤¤ï¤ì¤Æ¤¤¤ë¤â¤Î¤Ç¤¢¤ë¡£¤³¤ì¤òÍøÍѤ·¤¿spamÂкö¤È¤·¤ÆÃΤé¤ì¤Æ¤¤¤ë¤Î¤¬¡Ötarpit¡×¤È¸Æ¤Ð¤ì¤ë¼êË¡¤Ç¤¢¤ë¡£¤³¤Î¼êË¡¤ÎÍøÍÑÎã¤Ï¿¿ô¤¢¤ê¡¢¸ú²Ì¤òµó¤²¤Æ¤¤¤ë¤è¤¦¤Ç¤¢¤ë¡£É®¼Ô¤â2005ǯ¤´¤íWeb¥µ¡¼¥Ð¡¼¤Ø¤ÎDDoS¡ÊRequest flood¡Ë¤Ø¤ÎÂй³ºö¤È¤·¤ÆÍøÍѤ·¤¿¤³¤È¤¬¤¢¤êÂ礭¤Ê¸ú²Ì¤òµó¤²¤¿¤³¤È¤¬¤¢¤ë¡£

¤³¤ì¤âƱÍͤˡÖHoneyPot+²¾ÁÛMTA¡×¥·¥¹¥Æ¥à¤Ë¤ª¤±¤ë½ã¿è¤Ë100%bot¤Ë¤è¤ëSMTPÄÌ¿®¤ËÂФ·¤Æ¤¤¤í¤¤¤í¼Â¸³¤·¤Æ¤ß¤¿¡£

¤³¤³¤Ç¤Ï´Ê°×¤Ëpostfix¤Îµ¡Ç½¤ò»È¤Ã¤Æ¤ß¤¿¡£/etc/postfix/main.cf¤Ë°Ê²¼¤Î¤è¤¦¤ÊÀßÄê¤ò¤¤¤ì¤ë¤À¤±¡£

 ­¡smtpd_helo_restrictions = sleep 60
 ­¢smtpd_client_restrictions = sleep 60
 ­£smtpd_recipient_restrictions = sleep 60
 ­¤smtpd_data_restrictions = sleep 60

¤¤¤í¤¤¤í¤Ê¾ì½ê¤Çsleep¤ò»î¤·¤¿¤«¤Ã¤¿¤¬­¡¡Á­£¤¤¤Å¤ì¤â¡ÖRCPT TO¡×¤Î¸å¤Ë»ØÄꤷ¤¿Éÿô¤À¤±sleep¤¬Æþ¤ê¡¢­¤¤Î¾ì¹ç¤Î¤ß¡ÖDATA¡×¤Î¸å¤Ësleep¤¬Æþ¤ë¡£

¡ÖRCPT TO¡×¤Ësleep¤¬¸ú¤¤¤Æ¤·¤Þ¤¦¤È¡¢Ê£¿ô¤Î°¸À褬»ØÄꤵ¤ì¤Æ¤¤¤ë¾ì¹ç¤Ë¤¹¤Ù¤Æ¤Î¡ÖRCPT TO¡×¥³¥Þ¥ó¥É¤Ësleep¤¬¸ú¤¤¤Æ¤·¤Þ¤¦¡£¤³¤ÎÎã¤Ç¤Ï°¸Àè¤ò10¸Ä»ØÄꤷ¤Æ¤¤¤ë¤È¥á¡¼¥ë1ÄÌÁ÷¿®¤¹¤ë¤Î¤Ë60x10=600É䫤«¤Ã¤Æ¤·¤Þ¤¤¼ÂÍѾåÌäÂ꤬µ¯¤³¤ë¤«¤â¤·¤ì¤Ê¤¤¡£¤½¤ì¤Ê¤é¼ÂÍÑŪ¤Ë¤Ï¡ÖDATA¡×¥³¥Þ¥ó¥É¸å¤Ë¸ú¤¤¤Æ¤â¤é¤Ã¤¿¤Û¤¦¤¬Îɤ¤¤Î¤Ç¤³¤³¤Ç¤Ï¡ÖDATA¡×¥³¥Þ¥ó¥É¤ËÂФ·¤Æ¡Ösleep 180¡×¤òÆþ¤ì¤¿Îã¤ò¤¢¤²¤ë¡£

90ÉðÊÆâ¤Ëtimeout¤·¤¿¤â¤Î¤¬Á´ÂΤÎ93%ÄøÅÙ¤·¤á¡¢112ÉÃÄøÅ٤ǤۤÜ99%¤È¤Ê¤ë¡£ºÇŤÏ162Éá£

RFC2821Ū¤Ë¤Ï°Ê²¼¤Î¤è¤¦¤Ë¤Ê¤Ã¤Æ¤¤¤ë¤Î¤Ç¤Û¤ÜRFC¤É¤ª¤ê¤È¤¤¤¦¤³¤È¤Ë¤Ê¤ë¡£

 RCPT Command: 5 minutes 
 A longer timeout is required if processing of mailing lists and aliases is   
 not deferred until after the message was accepted. 
 
 DATA Initiation: 2 minutes
 This is while awaiting the "354 Start Input" reply to a DATA command. 

(¢¨¼ÂºÝ¤Î¤È¤³¤í¡ÖRCPT TO¡×¤Î¸å¤Ësleep¤òÆþ¤ì¤¿¾ì¹ç¤Ç¤â¤³¤Î·ë²Ì¤ÏƱ¤¸¤Ç¤¢¤ë¡£¤½¤Î¸«Êý¤ò¤¹¤ì¤Ðtimeout¤Ïû¤á¤Èª¤¨¤ë¤³¤È¤â¤Ç¤­¤ë¡£¤³¤³¤Ç³Îǧ¤Ç¤­¤Æ¤¤¤ëspamÁ÷¿®¤Ïsleep°ÌÃ֤˴ط¸¤Ê¤¯°ìΧ¤ÎtimeoutÃͤÇÆ°ºî¤·¤Æ¤¤¤ë¤Î¤À¤í¤¦¡£¡Ë

¤·¤¿¤¬¤Ã¤ÆMTA¤Ë¤Æ91ÉÃÄøÅ٤ޤǡ¢¶ËÏÀ¤Ç¤Ï121ÉäޤÇsleep¤òÆþ¤ì¤Æ¤ä¤ì¤Ð¡¢¤³¤³¤Ç´Ñ¬¤µ¤ì¤Æ¤¤¤ëspam¤ÎÁ÷¿®¤ÏÍ޻ߤ¹¤ë¤³¤È¤¬¤Ç¤­¤ë¤³¤È¤Ë¤Ê¤ë¡£¤¿¤À¼ÂºÝ¤Ë¤ÏÀµ¾ï¤ÊMTA¤äMUA¤«¤é¤ÎÁ÷¿®¤Ø¤Î±Æ¶Á¤Ï¤¢¤ë¤ï¤±¤Ç¤¢¤ê¡¢¤Þ¤¿¥»¥Ã¥·¥ç¥óÊÝ»ý»þ´Ö¤¬Ä¹¤¯¤Ê¤ëʬsmtpd¤Îµ¯Æ°¿ô¤ä¡¢TCP¥³¥Í¥¯¥·¥ç¥ó¿ô¤Ë¤â±Æ¶Á¤òÍ¿¤¨¤ë¤Î¤Ç¡¢¤³¤ì¤ò°Â°×¤Ë¤½¤Î¤Þ¤ÞŬÍѤ¹¤ë¤³¤È¤Ï¤¹¤¹¤á¤Ê¤¤¡£

¤¿¤À¸ú²Ì¤¬¤¢¤ë¤³¤È¤Ïµ¿¤¤¤è¤¦¤Î¤Ê¤¤¤â¤Î¤Ê¤Î¤Ç¡¢°Ê²¼¤ÎÃí°ÕÅÀ¤ò²¡¤µ¤¨¤¿¾å¤Ç¤ÎŬÍѤθ¡Æ¤¤¬É¬Íס£

  • ¥Û¥ï¥¤¥È¥ê¥¹¥È¤ÎÀ°È÷¡¢update¤Î·Ñ³
  • ¾¤Î¼êË¡¡Êgreylisting¤Ê¤É¡Ë¤ÈÊ»ÍѤ¹¤ë¤³¤È¤Ë¤è¤ê¡¢tarpit¤ò¸ú¤«¤»¤ëÂоݤò¹Ê¤ë
  • smtpd¤Îµ¯Æ°¿ôÅù¼«Ê¬¤Î±¿ÍѤ¹¤ë´Ä¶­¤òÇÄ°®¤·¥Á¥å¡¼¥Ë¥ó¥°¤¬¤Ç¤­¤ë¤³¤È

¤Ê¤É¡£

spamÂкö¡á½ª¤ï¤ê¤Ê¤­¥Û¥ï¥¤¥È¥ê¥¹¥ÈºîÀ®¤ÎÅØÎÏ

¤Ç¤¢¤ë¤³¤È¤ò˺¤ì¤Æ¤Ï¤¤¤±¤Ê¤¤¡£¡£¡£

[¥«¥Æ¥´¥ê:spam´Ñ»¡Æüµ­][¥«¥Æ¥´¥ê:botnet´Ñ»¡Æüµ­]

by jyake