WO2020162181A1 - 試験装置 - Google Patents
試験装置 Download PDFInfo
- Publication number
- WO2020162181A1 WO2020162181A1 PCT/JP2020/002141 JP2020002141W WO2020162181A1 WO 2020162181 A1 WO2020162181 A1 WO 2020162181A1 JP 2020002141 W JP2020002141 W JP 2020002141W WO 2020162181 A1 WO2020162181 A1 WO 2020162181A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- test
- packet
- response
- unit
- authentication
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1433—Vulnerability analysis
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/44—Program or device authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/66—Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0884—Network architectures or network communication protocols for network security for authentication of entities by delegation of authentication, e.g. a proxy authenticates an entity to be authenticated on behalf of this entity vis-à-vis an authentication entity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0227—Filtering policies
- H04L63/0236—Filtering by address, protocol, port number or service, e.g. IP-address or URL
Definitions
- the present invention relates to a test device.
- Non-Patent Document 1 a method of transmitting a packet for applying a load to a device and performing a packet load test has been proposed (for example, see Non-Patent Document 1). Further, a method has been proposed in which a packet load test is performed on a target device protected by a security system (for example, refer to Patent Document 1).
- the source IP address that establishes a session such as HTTP is limited, so security devices such as WAF (Web Application Firewall) are used.
- WAF Web Application Firewall
- the packet load test cannot be performed because the packet is discarded by the unit time packet number filter for each source IP address.
- a plurality of test devices are required in order to not correspond to the unit time packet number filter of the source IP address unit, resulting in cost increase.
- the test scenario is limited to authentication response and simple transmission such as HTTP GET Flood, there is a problem that the test items for the device under test are limited even if the security system can be broken.
- the test apparatus of the present invention is an apparatus protected by a security system that authenticates packets transmitted to the apparatus to be protected and restricts packets for each source IP address.
- a transmission unit that transmits a test packet that increases the processing load a test scenario unit that generates a test session based on a scenario when transmitting the test packet, and the test packet include a plurality of source IP addresses.
- the test packet is a valid one by the security system in response to a response request up to a predetermined stage of authentication among a plurality of stages of authentication performed by the address distributing unit that constructs a packet to be used and the security system.
- a monitoring unit for monitoring the packet filter status and the processing load of the security system to which the test packet is transmitted at the predetermined stage.
- a packet load test such as login or search can be performed on a device protected by a security system that authenticates packets transmitted to a device to be protected and restricts packets for each source IP address. it can.
- FIG. 1 is a diagram illustrating an example of a configuration of a network including a test device according to the first embodiment.
- FIG. 2 is a diagram illustrating an example of the configuration of the test apparatus according to the first embodiment.
- FIG. 3 is a diagram for explaining the multi-step defense function.
- FIG. 4 is a sequence diagram for explaining a packet load test performed by the test apparatus according to the first embodiment.
- FIG. 5 is a diagram illustrating a computer that executes a program.
- test apparatus An embodiment of the test apparatus according to the present application will be described in detail below with reference to the drawings.
- the present invention is not limited to this embodiment.
- FIG. 1 is a diagram illustrating an example of a configuration of a network including a test device according to the first embodiment.
- the network 1 has a test apparatus 10 and a test target system 20.
- the test target system 20 also includes a network device 21, a security device 22, and a server 23.
- Each system and each device of the network 1 are connected by an arbitrary type of communication network such as a wired or wireless LAN (Local Area Network) or VPN (Virtual Private Network).
- LAN Local Area Network
- VPN Virtual Private Network
- the test apparatus 10 has a test packet transmission/reception unit 121, a monitoring unit 122, a management unit 123, and a storage unit 13.
- the test packet transmitting/receiving unit 121 transmits a test packet for the security tolerance test to each device included in the test target system 20, and receives a packet transmitted from the test target system 20 for the test packet.
- the monitoring unit 122 monitors the load status of each device of the test target system 20.
- the management unit 123 performs settings regarding the test packet transmission/reception unit 121 and the monitoring unit 122, and obtains and analyzes information.
- the test apparatus 10 causes the test packet transmitting/receiving unit 121 and the monitoring unit 122 to be executed by the setting of the management unit 123.
- the test apparatus 10 may be distributed and the test packet transmitting/receiving unit 121, the monitoring unit 122, and the management unit 123 may be distributed and executed by a plurality of test apparatuses.
- FIG. 2 is a diagram illustrating an example of the configuration of the test apparatus according to the first embodiment.
- the test apparatus 10 has an interface unit 11, a control unit 12, and a storage unit 13.
- the interface unit 11 is an interface that controls communication with other devices. For example, the interface unit 11 transmits/receives a packet to/from another device via the network.
- the interface unit 11 is a network interface card such as a LAN card.
- the interface unit 11 has a test packet interface 111, a monitoring interface 112, and a management interface 113.
- the test packet interface 111 transmits/receives a packet accompanying the execution of the test packet transmitting/receiving function.
- the monitoring interface 112 transmits/receives packets associated with the execution of the monitoring unit 122 of the test apparatus 10.
- the management interface 113 transmits/receives packets accompanying the execution of the management unit 123 of the test apparatus 10.
- the control unit 12 controls the entire test apparatus 10.
- the control unit 12 integrates electronic circuits such as CPU (Central Processing Unit), MPU (Micro Processing Unit), and GPU (Graphical Processing Unit), and ASIC (Application Specific Integrated Circuit) and FPGA (Field Programmable Gate Array). Circuit.
- the control unit 12 includes a test packet transmission/reception unit 121, a monitoring unit 122, and a management unit 123.
- the monitoring unit 122 is an example of a monitoring unit.
- the test scenario unit 124 constructs an HTTP and HTTPS session with the test target system 20 such as a Web server based on a scenario described using a script or the like, and then a test packet to the test target system 20. Is generated and a test packet that maintains session information such as login information is transmitted, a test packet based on the Cookie received from the server 23 is generated.
- the test scenario unit 124 not only carries out attack tests of multiple account creation/deletion to/from the server 23, frequent login/logout from multiple accounts, and frequent search execution, in addition to GET and POST Flood. , Perform an attack test to change the TCP header such as SlowREAD on the maintained session.
- the response unit 125 receives a response request corresponding to TCP authentication, HTTP authentication and challenge response confirmation performed by the security device 22, identifies the received response request, and a response that matches the identified response request, that is, an attack packet The security device 22 responds so that it is authenticated.
- the address distribution unit 126 distributes the source IP address of the test packet to be transmitted, based on the list of preset IP addresses. As an example, the address distribution unit 126 assigns different source IP addresses to the TCP SYN packet transmitted as the test packet based on the IP address list, and uses the same source IP address in the same TCP connection thereafter. Thus, communication is performed with different source IP addresses for a plurality of TCP connections. In addition, when the packet filter threshold of the test target system is notified from the monitoring unit 122, the address distribution unit 126 controls the number of source IP addresses so that the source IP address does not correspond to the packet filter threshold of the test target system. Adjust the test packet transmission of.
- the transmitting unit 127 transmits a test packet for increasing the processing load to the server 23 protected by the security device 22 that authenticates the packet transmitted to the device to be protected.
- the security device 22 has a packet discard function based on a packet signature when transmitting the test packet
- the transmitting unit 127 determines that the packet is not a general browser based on the packet information of the user agent or the like and prevents the packet from being discarded. Therefore, the packet information such as the user agent is set to be the same as that of a general browser.
- the packet transmission function of a general browser may be used.
- the monitoring unit 122 monitors the packet filter status and the processing load status of the security device 22 or the server 23 to which the attack packet authenticated by the security device 22 is transmitted.
- the monitoring unit 122 monitors the number of test packets per unit time of the source IP address, the amount of bytes, the number of sessions, and the response packet from the test target system to monitor the packet filter status, and monitors other source IP address test packets. Although the response packet has arrived, the transmission source IP address for which the response packet has stopped coming although the test packet is transmitted is grasped.
- the number of test packets, the amount of bytes, the number of sessions, and the time stamp transmitted at the time immediately before the response packet did not arrive for the source IP address are recorded as the packet filter threshold of the system under test, and are recorded in the control unit 12. Notify against
- the storage unit 13 stores various information used in the execution of the control unit.
- the storage unit 13 is a semiconductor memory device such as a RAM (Random Access Memory) or a flash memory (Flash Memory), or a storage device such as a hard disk or an optical disk.
- the packet load test of each device included in the test target system 20 can be performed.
- the packet load test by the test apparatus 10 will be described by taking the case where the packet load test of the security device 22 and the server 23 is performed as an example.
- the security device 22 when transmitting a packet to the server 23, the security device 22 allows normal browser communication to pass and blocks attack packets from bots and attack tools. For example, when the security device 22 detects the transmission of a packet to the server 23, the security device 22 makes an authentication request for the packet. For example, TCP authentication, HTTP authentication, and challenge response authentication are performed. Further, the number of packets per unit time of the source IP address, the amount of bytes, the number of sessions, etc. are monitored, and when a predetermined threshold is exceeded, the source IP address is registered in the blacklist.
- the source of the packet is a general browser operated by a person
- a response matching the response request is made by the operated person
- the number of unit time packets transmitted by the general browser operated by a person It is based on the fact that the amount of bytes does not correspond to a predetermined threshold.
- FIG. 3 is a diagram for explaining the multi-step defense function.
- the security device 22 when transmitting a packet to the server 23, it is necessary for the security device 22 to limit the number of transmission source packets and perform authentication in multiple stages.
- the security device 22 performs, for example, TCP authentication, HTTP authentication, challenge response authentication, unit time source packet number limit, unit time source byte number limit, and unit time session number limit.
- the security device 22 when the security device 22 detects transmission of a packet to the server 23, the security device 22 monitors the number of packets, the number of sessions, etc. for each source IP address of the packet, and the source of the packet is generally operated by a person. If the threshold value based on the number of packets transmitted by the browser or the number of sessions is cleared, the source packet number limiting function is passed. For example, when the threshold value to be passed is set to 6 packets/second or less and the session number is 6 sessions or less, the security device 22 determines that the source IP address satisfying the passing threshold value is a communication from a general browser. Let it pass.
- the security device 22 discards the packet at the TCP authentication stage. Therefore, even when the packet is transmitted by the attack tool for the packet load test of the server 23, the security device 22 detects that the transmission of the packet is an attack at a predetermined stage, and Discard. Furthermore, even if there is an attack tool that can respond to TCP authentication, HTTP authentication, and challenge/response, it can be judged as an attack by the packet number limit per unit time by the source packet limit, the byte number limit, and the session number limit. Then, the source IP address is blacklisted and the packet is discarded. As a result, it is difficult for the attack tool for the conventional packet load test to perform the packet load test of the server 23 and the security device 22.
- test device of the first embodiment it is possible to perform a packet load test on the server 23 and the security device 22.
- the operation when the test apparatus 10 performs the packet load test of the server 23 or the security apparatus 22 will be described with reference to FIG.
- FIG. 4 is a sequence diagram for explaining a packet load test performed by the test device according to the first embodiment.
- the test apparatus 10 sets an attack packet and monitoring (step S101).
- the test apparatus 10 performs setting so as to transmit, as a test packet, a test packet for logging in a large number of servers after HTTP connection and performing a large number of searches.
- the test apparatus 10 performs settings such as confirmation of response to ping or traceback of the server 23 or confirmation of HTTP response as monitoring.
- the packet filter status the number of test packets per unit time of the source IP address, the amount of bytes, the number of sessions, and the response packet from the system under test are monitored, and the response packet is sent to other source IP address test packets.
- the source IP address where the response packet has stopped coming though the packet has arrived but the test packet has been sent is grasped.
- the source IP address, the number of test packets, the number of bytes, the number of sessions, and the time stamp, which were transmitted at the time immediately before the response packet did not arrive for the source IP address The packet filter threshold value of 1 is recorded and is notified to the control unit 12.
- the transmission unit 127 of the test apparatus 10 transmits the test packet from the test packet interface 111.
- the transmission unit 127 transmits a TCP SYN packet to 10.0.0.1, which is the IP address of the server 23, in order to establish a TCP connection with the server 23 (step S102).
- the security device 22 makes a TCP authentication response request to determine whether the SYN packet sent to the server 23 is an attack packet (step S103).
- the SYN/ACK packet is transmitted to the sender of the SYN packet.
- the security device 22 uses, for example, a SYN/ACK packet containing a Cookie, a SYN/ACK packet containing an invalid ACK Sequence number, an ACK packet, and an RST packet as a test device. Send to 10. Then, the security device 22 allows TCP authentication to pass when a response matching the transmitted illegal packet is returned.
- the response unit 125 of the test apparatus 10 makes a response to the security apparatus 22 in conformity with the TCP authentication response request (step S104). For example, when the SYN/ACK packet including the Cookie is transmitted to the SYN packet, the response unit 125 identifies that the packet is the SYN/ACK packet including the Cookie. Then, the response unit 125 transmits the ACK packet in which the Sequence number based on the content of the Cookie is set to the security device 22. An attack tool for SYN Flood attack may not respond even if the security device 22 sends a SYN/ACK packet containing a cookie.
- the test apparatus 10 can establish a TCP connection with the server 23 and prevent the test packet transmitted by the transmission unit 127 from being discarded at the TCP authentication stage. Then, the test apparatus 10 can perform a packet load test on the security device 22 and the server 23 when performing the authentication at a stage prior to the TCP authentication.
- the transmission unit 127 transmits an HTTP request packet to the server 23 (step S105).
- the security device 22 makes an HTTP authentication response request to determine whether or not the HTTP request packet transmitted to the server 23 is a test packet (step S106).
- the response unit 125 makes a response conforming to HTTPS authentication to the security device 22 (step S107). For example, the response unit 125 identifies that the response from the security device 22 is a redirect response. Then, the response unit 125 transmits the HTTP request packet to the redirect destination designated by the value such as URI (Uniform Resource Identifier) indicated by the Location header of the redirect response. Note that it is conceivable that an attack tool that does not respond to the redirect response does not refer to the Location header and does not send the HTTP request packet to the redirect destination.
- URI Uniform Resource Identifier
- the security device 22 makes an HTTP authentication response request by HTTP Cookie or JavaScript (registered trademark) to determine whether the HTTP request request packet sent to the server 23 is an attack packet (step S108). ..
- the security device 22 When performing HTTP authentication by HTTP Cookie or JavaScript, the security device 22 requests the test device 10 to execute the process of reading the description content of Cookie by the program described in Javascript and returning the read result, for example. To do. Then, when the execution result of the program is returned within the predetermined time, the security device 22 allows the HTTP authentication to pass.
- the response unit 125 makes a response to the security device 22 in conformity with HTTP authentication using HTTP Cookie or Java Script (step S109). For example, the response unit 125 identifies that the data transmitted from the security device 22 is a Javascript execution instruction. Then, the response unit 125 notifies the security device 22 of the description content of the Cookie obtained as a result of executing the program described in JavaScript. Note that an attack tool that does not respond to HTTP authentication by Java Script and Cookie may not respond to HTTP authentication by HTTP Cookie or Java Script.
- the test apparatus 10 can pass the HTTP authentication and can prevent the attack packet transmitted by the transmission unit 127 from being discarded at the HTTP authentication stage. Then, the test apparatus 10 can perform a packet load test on the security device 22 and the server 23 when performing the authentication at a stage prior to the HTTP authentication.
- the transmission unit 127 transmits an HTTP request packet to the server 23 (step S110).
- the security device 22 makes a challenge response authentication response request to determine whether the HTTP request packet sent to the server 23 is an attack packet (step S111).
- the security device 22 When performing challenge response authentication, for example, the security device 22 requests the test device 10b to move the mouse on a predetermined route or CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart). Then, when a response matching the mouse movement or CAPTCHA is returned, the security device 22 passes the authentication by the challenge response authentication.
- CAPTCHA Completely Automated Public Turing test to tell Computers and Humans Apart
- the response unit 125 responds to the security device 22 in response to challenge response authentication (step S112). For example, the response unit 125 identifies that the security device 22 indicates a mouse movement path. Then, the response unit 125 reads the route indicated as the mouse movement route, and transmits the same signal as the signal generated when the mouse is moved along the read route to the security device 22.
- the response unit 125 also identifies that CAPTCHA is indicated by the security device 22. Then, the response unit 125 transmits the data in which CAPTCHA is converted into text using the image text conversion service or OCR to the security device 22. An attack tool that does not respond to challenge response authentication may not respond to mouse response or challenge response authentication by CAPTCHA.
- the test apparatus 10 can pass the challenge response authentication, and can prevent the test packet transmitted by the transmission unit 127 from being discarded in the challenge response authentication stage.
- the test apparatus 10 transmits a test packet to the server 23 of the test target system 20 (step S113) and receives a response packet from the test target system 20 (step S114), thereby performing a packet load test on the server 23. be able to.
- the test packet can be transmitted from, and the test resource can be reduced.
- the address distribution unit 126 sequentially allocates a source IP address different from the previous TCP SYN packet based on the IP address list set by the management unit 123, and By assigning the same source IP address to the connection, the test packet can be transmitted by a plurality of source IP addresses while maintaining the IP address consistency of the TCP connection.
- the monitoring unit 122 monitors and analyzes the packet filter status of the test target system 20 for the test packet.
- the number of test packets per unit time of the source IP address, the number of bytes, the number of sessions, and the response packet from the system under test are monitored, and response packets are sent to other source IP address test packets.
- the source IP address for which the response packet has stopped coming is grasped.
- the source IP address, the number of test packets, the number of bytes, the number of sessions, and the time stamp, which were transmitted at the time immediately before the response packet did not arrive for the source IP address The packet filter threshold value of 20 is recorded and set to notify the control unit 12.
- the address distribution unit 126 of the control unit 12 controls the number of source IP addresses so that the source address may not fall under the packet filter threshold value of the test target system. Coordinate test packet transmission per IP address. For example, the transmission from the source IP address, which is determined to be packet filtered because the response packet does not come, is stopped for a certain period of time, and a test packet is transmitted from a new source IP address that has not been packet filtered yet. Limit the unit packet transmission to the range that does not correspond to the packet filter.
- the test apparatus 10 can pass the transmission source packet restriction shown in FIG. 3 and prevent the test packet transmitted by the transmission unit 127 from being discarded at the transmission source packet restriction step. Then, the test apparatus 10 can perform a packet load test on the server 23.
- the processing load can be measured only for a part of the server processing against a denial of service attack by simply transmitting a packet such as SYN Flood or GET Flood. Therefore, the test scenario unit 124 constructs an HTTP and HTTPS session with the test target system 20 such as a Web server based on a scenario described using a script or the like, and then logs in the server 23 with login information. In order to transmit the test packet maintaining the session information such as, the test packet based on the Cookie received from the server 23 is generated.
- GET and POST Flood multiple account creation/deletion to/from server 23, frequent login/logout from multiple accounts, frequent search execution attack tests are performed, and on the maintained session. Perform an attack test that changes TCP headers such as Slow READ.
- This not only measures simple server processing load such as HTTP GET packet processing load or HTTP POST packet processing load on the server 23, but also login information encryption and decryption processing load and search processing load of the server 23. , And a load test such as database processing load can be performed.
- the monitoring unit 122 makes a monitoring response request to the server 23.
- the monitoring unit 122 confirms the response to the ping or traceback of the server 23 or the HTTP response according to the setting made by the test apparatus 10.
- the server 23 responds to the monitoring response request while processing the attack packet. Then, the monitoring unit 122 outputs the monitoring result from the monitoring interface 112.
- the test apparatus 10 analyzes the monitoring result and instructs the test apparatus 10 to change the scenario if necessary. Specifically, the test apparatus 10 analyzes the response time and response content of the server 23 while correlating the received monitoring result with the test traffic that is the type and amount of attack packet.
- the response time change of the server 23, the response message, the test traffic content when the response is lost, the test traffic content when the response is restored, and the like are recorded and analyzed in time series, and the function having a high processing load is grasped.
- the management unit 123 changes the amount of test packets transmitted by the transmission unit 127 according to the processing load status of the security device 22 or the server 23. Specifically, the management unit 123 increases the amount of test packets transmitted to the security device 22 or the server 23 by the transmission unit 127 when the processing load of the security device 22 or the server 23 is greater than or equal to a predetermined value.
- the scenario of the test traffic is changed, the response time change of the server 23 at that time, the response message, the test traffic content when the response is lost, and the test when the response is restored. From the traffic content, extract the test traffic condition that maximizes the load of the function with high processing load.
- the test apparatus 10 may test and analyze a plurality of test target devices including devices other than the server 23, and may recognize a device having a high processing load from the test target devices.
- test device 10 increases the login attack packet amount, the processing load on the server 23 increases and the HTTP response time increases. Then, the test apparatus 10 sends the HTTP 404 error response in which the server 23 can connect to the server but cannot display the web page, and the attack packet amount at the time when the server 23 cannot respond. Record the amount of attack packets. As a result, it is possible to know the resistance of the server 23 to the login attack.
- the security device 22 may detect an attack, discard the attack packet, and the processing load on the server 23 may stop increasing. At this time, the test apparatus 10 recognizes from the monitoring result that the processing load on the server 23 does not increase even if the attack packets to the server 23 are increased. In this case, by the processing of the address distribution unit 126, it is possible to test whether the processing load increases by transmitting test packets from different source IP addresses in a range that does not correspond to the packet filter threshold.
- test devices 10 may send a denial-of-service attack packet or the like to the server 23 according to a scenario.
- the effectiveness of countermeasures against a large number of source IP addresses such as attacks and cache are investigated, and further monitoring is performed to understand the limit of service denial, bottlenecks, and test traffic patterns at that time. can do.
- the reason why the responses of the server 23 due to the monitoring from the plurality of test devices are different is that the network device 21, the security device 22, or the server 23 itself sets the filter to the test device 10, or the server 23 Determine if it is due to load.
- the test apparatus 10 may stop the authentication halfway and perform a load test for the processing of the security apparatus 22 at an arbitrary authentication stage. For example, the test apparatus 10 may make a conforming response to the TCP authentication response request made by the security apparatus 22, and thereafter may make no conforming response to the HTTP authentication response request made by the security apparatus 22. As a result, the test apparatus 10 can perform a load test for the processing of the security apparatus 22 in the HTTP authentication stage. Similarly, the test apparatus 10 can identify the authentication stage that becomes a bottleneck by performing a load test on each authentication stage of the security device 22.
- the test scenario unit 124 of the test apparatus 10 constructs an HTTP and HTTPS session with a test target device such as a Web server, and then executes a test such as login or search for the test target device based on the scenario. Generate a packet.
- the address distribution unit 126 distributes the source IP address of the test packet to be transmitted based on the list of preset IP addresses, but sets the same source IP address in the same connection, and the packet filter of the security device 22 and the server 23. The amount of packets per source IP address is changed so as to avoid the packet filter depending on the situation.
- the transmission unit 127 transmits a test packet that increases the processing load based on the packet generated by the test scenario unit 124 and the transmission source IP address setting of the address distribution unit 126.
- the response unit 125 receives a response request corresponding to the authentication performed by the security device 22, identifies the received response request, and a response that matches the identified response request, that is, an attack packet is legitimate by the security device 22. It responds so that it can be authenticated.
- the monitoring unit 122 monitors the status of the authentication function having a high processing load on the security device 22 or the processing load on the server to which the attack packet authenticated by the security device 22 is transmitted.
- the authentication is passed by making a response suitable for the response request corresponding to the authentication, and the packet filter for each source IP address is avoided.
- a security tolerance test by applying a load to a plurality of places such as a decryption process of a device to be tested and a database.
- it is possible to identify the bottleneck by performing authentication at multiple stages and testing multiple devices.
- the response unit 125 identifies the received response request every time it receives a response request corresponding to the authentication up to an arbitrary step of the authentication performed stepwise by the security device 22, and conforms to the identified response request.
- Response that is, the test packet is authenticated as valid by the security system. This allows the security device 22 to be tested at any stage.
- the transmitting unit 127 transmits a packet generated by the operation of the Web browser together with the test packet to the server 23 that is the Web server. This makes it possible to perform a test in a situation close to that when an attack is actually performed.
- the management unit 123 changes the amount of attack packets transmitted by the transmission unit 127 according to the processing load situation of the security device 22 or the server 23. It is possible to understand the operation according to the processing load of the device under test.
- the management unit 123 changes the content of the test packet transmitted by the transmission unit 127 to the security device 22 or the server 23 when the processing load of the security device 22 or the server 23 is equal to or more than a predetermined value. This makes it possible to grasp the limit of the processing load of the device under test.
- the test apparatus 10 When the server 23 is a server other than a Web server such as a DNS server, or when investigating the network device 21 or the security device 22, the test apparatus 10 provides a service according to a protocol and an application serviced by the device under test. Send impossible attack packet and normal packet.
- the security device 22 may send a request for DNS authentication such as a TCP resend request, but the test device 10a sends a packet according to the request. As a result, even if additional authentication is performed, it is possible to proceed with the security tolerance investigation and bottleneck investigation of the device under test.
- each component of each device shown in the drawings is functionally conceptual and does not necessarily have to be physically configured as shown. That is, the specific form of distribution/integration of each device is not limited to that shown in the figure, and all or part of the device may be functionally or physically distributed/arranged in arbitrary units according to various loads and usage conditions. It can be integrated and configured. Further, each processing function performed by each device may be implemented entirely or in part by a CPU and a program that is analyzed and executed by the CPU, or may be implemented as hardware by a wired logic.
- program Further, it is also possible to create a program described in a computer-executable language for the processing executed by the test apparatus described in the above embodiment.
- a program described in a computer-executable language can be created for the process executed by the test apparatus according to the embodiment.
- the computer executes the program to obtain the same effect as that of the above embodiment.
- an example of a computer that executes a program will be described.
- FIG. 5 is a diagram showing a computer that executes a program.
- the computer 1000 has, for example, a memory 1010 and a CPU 1020.
- the computer 1000 also has a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These units are connected by a bus 1080.
- the memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM 1012.
- the ROM 1011 stores, for example, a boot program such as BIOS (Basic Input Output System).
- BIOS Basic Input Output System
- the hard disk drive interface 1030 is connected to the hard disk drive 1090.
- the disk drive interface 1040 is connected to the disk drive 1100.
- a removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1100.
- the serial port interface 1050 is connected to, for example, the mouse 1051 and the keyboard 1052.
- the video adapter 1060 is connected to the display 1061, for example.
- the hard disk drive 1090 stores, for example, an OS 1091, an application program 1092, a program module 1093, and program data 1094. That is, the program defining each process of each device is implemented as a program module 1093 in which a code executable by a computer is described.
- the program module 1093 is stored in the hard disk drive 1090, for example.
- a program module 1093 for executing the same processing as the functional configuration of the device is stored in the hard disk drive 1090.
- the hard disk drive 1090 may be replaced with an SSD (Solid State Drive).
- the data used in the processing of the above-described embodiment is stored as program data 1094 in, for example, the memory 1010 or the hard disk drive 1090. Then, the CPU 1020 reads the program module 1093 and the program data 1094 stored in the memory 1010 or the hard disk drive 1090 into the RAM 1012 as necessary and executes them.
- the program module 1093 and the program data 1094 are not limited to being stored in the hard disk drive 1090, but may be stored in, for example, a removable storage medium and read by the CPU 1020 via the disk drive 1100 or the like. Alternatively, the program module 1093 and the program data 1094 may be stored in another computer connected via a network or WAN. Then, the program module 1093 and the program data 1094 may be read by the CPU 1020 from another computer via the network interface 1070.
- test apparatus 11 interface section 12 control section 13 storage section 20 test target system 21 network apparatus 22 security apparatus 23 server 111 test packet interface 112 monitoring interface 113 management interface 121 test packet transmission/reception section 122 monitoring section 123 management section 124 Test scenario section 125 Response section 126 Address distribution section 127 Transmission section
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computing Systems (AREA)
- Theoretical Computer Science (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Abstract
試験装置(10)は、防御対象の装置宛てに送信されたパケットの認証及び送信元IPアドレス毎パケット制限を行うセキュリティシステムによって防御された装置に対し、処理負荷を増加させる試験パケットを送信する。また、試験装置(10)は、試験パケットを送信する際、シナリオに基づいて試験セッションを生成し、試験パケットが複数の送信元IPアドレスを用いるようにパケットを構築する。また、試験装置(10)は、セキュリティシステムによって行われる複数の段階の認証のうち、所定の段階の認証までの応答要求に対し、試験パケットがセキュリティシステムによって正当なものであると認証されるように応答を行う。また、試験装置(10)は、所定の段階における、試験パケットが送信されたセキュリティシステムのパケットフィルタ状況及び処理負荷を監視する。
Description
本発明は、試験装置に関する。
従来、機器に対し負荷を印加するためのパケットを送信し、パケット負荷試験を実施する方式が提案されている(例えば、非特許文献1参照)。また、セキュリティシステムによって防御された対象装置に対してパケット負荷試験を実施する方式が提案されている(例えば、特許文献1参照)。
IXIA, "Denial of Service (DOS) Testing"
しかしながら、従来の方式には、認証のための応答要求を行う機器を突破できても、HTTP等のセッションを張る送信元IPアドレスが限定されるため、WAF(Web Application Firewall)などのセキュリティ機器による送信元IPアドレス単位の単位時間パケット数フィルタにより廃棄され、パケット負荷試験が行えないという問題があった。また、送信元IPアドレス単位の単位時間パケット数フィルタに該当しないためには複数の試験装置が必要であり、コストがかかるという問題があった。さらに、試験シナリオが認証応答とHTTP GET Flood等の単純送信に限られるため、セキュリティシステムを突破できても、試験対象装置への試験項目が限定されるという問題があった。
上述した課題を解決し、目的を達成するために、本発明の試験装置は、防御対象の装置宛てに送信されたパケットの認証及び送信元IPアドレス毎パケット制限を行うセキュリティシステムによって防御された装置に対し、処理負荷を増加させる試験パケットを送信する送信部と、前記試験パケットを送信する際、シナリオに基づいて試験セッションを生成する試験シナリオ部と、前記試験パケットが複数の送信元IPアドレスを用いるようにパケットを構築するアドレス分散部と、前記セキュリティシステムによって行われる複数の段階の認証のうち、所定の段階の認証までの応答要求に対し、前記試験パケットが前記セキュリティシステムによって正当なものであると認証されるように応答を行う応答部と、前記所定の段階における、前記試験パケットが送信された前記セキュリティシステムのパケットフィルタ状況及び処理負荷を監視する監視部と、を有することを特徴とする。
本発明によれば、防御対象の装置宛てに送信されたパケットの認証及び送信元IPアドレス毎パケット制限を行うセキュリティシステムによって防御された装置に対し、ログインや検索等のパケット負荷試験を行うことができる。
以下に、本願に係る試験装置の実施形態を図面に基づいて詳細に説明する。なお、この実施形態により本発明が限定されるものではない。
[第1の実施形態の構成]
まず、図1を用いて、第1の実施形態に係る試験装置を有するネットワークの構成について説明する。図1は、第1の実施形態に係る試験装置を有するネットワークの構成の一例を示す図である。
まず、図1を用いて、第1の実施形態に係る試験装置を有するネットワークの構成について説明する。図1は、第1の実施形態に係る試験装置を有するネットワークの構成の一例を示す図である。
図1に示すように、ネットワーク1は、試験装置10、および試験対象システム20を有する。また、試験対象システム20は、ネットワーク装置21、セキュリティ装置22、サーバ23を有する。ネットワーク1の各システム、および各装置は、例えば、有線または無線のLAN(Local Area Network)やVPN(Virtual Private Network)等の任意の種類の通信網によって接続されている。
試験装置10は、試験パケット送受信部121、モニタリング部122、管理部123および記憶部13を有する。試験パケット送受信部121は、セキュリティ耐性試験のための試験パケットを試験対象システム20に含まれる各装置に対し送信し、試験パケットに対して試験対象システム20から送信されるパケットを受信する。モニタリング部122は、試験対象システム20の各装置の負荷の状況を監視する。また、管理部123は、試験パケット送受信部121およびモニタリング部122に関する設定や、情報の取得および分析を行う。
例えば、図1の例では、試験装置10によって管理部123の設定により試験パケット送受信部121及びモニタリング部122が実行される。なお、例えば、試験装置10を分散させ、試験パケット送受信部121、モニタリング部122および管理部123を複数の試験装置で分散して実行されるようにしてもよい。
ここで、図2を用いて、試験装置10について説明する。図2は、第1の実施形態に係る試験装置の構成の一例を示す図である。図2に示すように、試験装置10は、インタフェース部11、制御部12および記憶部13を有する。
インタフェース部11は、他の装置との間で通信制御を行うインタフェースである。例えば、インタフェース部11は、ネットワークを介して他の装置との間でパケットの送受信を行う。また、インタフェース部11は、例えばLANカード等のネットワークインタフェースカードである。
インタフェース部11は、試験パケット用インタフェース111、モニタリング用インタフェース112および管理用インタフェース113を有する。試験パケット用インタフェース111は、試験パケット送受信機能の実行にともなうパケットの送受信を行う。また、モニタリング用インタフェース112は、試験装置10のモニタリング部122の実行にともなうパケットの送受信を行う。また、管理用インタフェース113は、試験装置10の管理部123の実行にともなうパケットの送受信を行う。
制御部12は、試験装置10全体を制御する。例えば、制御部12は、CPU(Central Processing Unit)やMPU(Micro Processing Unit)、GPU(Graphical Processing Unit)などの電子回路やASIC(Application Specific Integrated Circuit)やFPGA(Field Programmable Gate Array)などの集積回路である。制御部12は、試験パケット送受信部121、モニタリング部122および管理部123を有する。なお、モニタリング部122は、監視部の一例である。
試験シナリオ部124は、スクリプト等を用いて記述されたシナリオに基づき、Webサーバ等の試験対象システム20との間でHTTP及びHTTPSのセッションを構築した上で、試験対象システム20に対して試験パケットを生成するとともに、ログイン情報などのセッション情報を維持した試験パケットを送信するため、サーバ23から受信したCookieに基づいた試験パケットを生成する。試験シナリオ部124は、試験パケットとして、GET及びPOST Flood以外に、サーバ23への複数アカウント作成・削除、複数アカウントからの頻繁なログイン・ログアウト、頻繁な検索実行の攻撃試験を実施するだけでなく、維持したセッション上でSlow READ等のTCPヘッダを変更する攻撃試験を実施する。
応答部125は、セキュリティ装置22によって行われるTCP認証、HTTP認証及びチャレンジレスポンス認に対応した応答要求を受信し、受信した応答要求を識別し、識別した応答要求に適合する応答、すなわち攻撃パケットがセキュリティ装置22によって正当なものであると認証されるような応答を行う。
アドレス分散部126は、あらかじめ設定されたIPアドレスのリストに基づいて、送信する試験パケットの送信元IPアドレスを分散させる。一例として、アドレス分散部126は、試験パケットとして送信されるTCP SYNパケットに対して、IPアドレスリストに基づいて異なる送信元IPアドレスを割り当て、その後の同一TCPコネクションでは同一送信元IPアドレスを用いる事で、複数のTCPコネクションに対して異なる送信元IPアドレスで通信する。また、アドレス分散部126は、モニタリング部122から試験対象システムのパケットフィルタ閾値が通知された場合、送信元IPアドレス数を制御して試験対象システムのパケットフィルタ閾値に該当しないよう送信元IPアドレスあたりの試験パケット送信を調整する。
送信部127は、防御対象の装置宛てに送信されたパケットの認証を行うセキュリティ装置22によって防御されたサーバ23に対し、処理負荷を増加させる試験パケットを送信する。送信部127は、試験パケットを送信するにあたり、セキュリティ装置22がパケットシグネチャによるパケット廃棄機能を有している場合、ユーザエージェント等のパケット情報により一般ブラウザではないと判別して廃棄されるのを防ぐため、ユーザエージェント等パケット情報が一般ブラウザと同じになるよう設定する。一例として、一般ブラウザのパケット送信機能を利用してもよい。
モニタリング部122は、セキュリティ装置22によって正当なものであると認証された攻撃パケットが送信されたセキュリティ装置22またはサーバ23のパケットフィルタ状況及び処理負荷の状況を監視する。モニタリング部122は、パケットフィルタ状況の監視として、送信元IPアドレス単位の単位時間あたり試験パケット数、バイト量、セッション数及び試験対象システムからの応答パケットを監視し、他の送信元IPアドレス試験パケットには応答パケットが来ているものの、試験パケットを送信しているのに応答パケットが来なくなった送信元IPアドレスを把握する。当該送信元IPアドレスに対して応答パケットが来なくなった直前の時刻に送信していた試験パケット数、バイト量、セッション数、タイムスタンプを試験対象システムのパケットフィルタ閾値として記録し、制御部12に対して通知する。
記憶部13は、制御部の実行で用いられる各種情報を記憶する。例えば、記憶部13は、RAM(Random Access Memory)、フラッシュメモリ(Flash Memory)等の半導体メモリ素子、又は、ハードディスク、光ディスク等の記憶装置などである。
試験装置10によれば、試験対象システム20に含まれる各装置のパケット負荷試験を行うことができる。ここで、セキュリティ装置22およびサーバ23のパケット負荷試験を行う場合を例に挙げて、試験装置10によるパケット負荷試験について説明する。
試験対象システム20では、サーバ23にパケットを送信する際、セキュリティ装置22により正常なブラウザ通信は通過させてボットや攻撃ツールによる攻撃パケットを遮断する。例えば、セキュリティ装置22は、サーバ23に対するパケットの送信を検知した場合、当該パケットに対し認証要求を行う。例えばTCP認証、HTTP認証、およびチャレンジレスポンス認証を行う。さらに、送信元IPアドレス単位の単位時間パケット数、バイト量、セッション数などを監視し、所定の閾値を超過した場合に当該送信元IPアドレスをブラックリストに登録する。これは、パケットの送信元が人によって操作される一般ブラウザであって、操作した人によって応答要求に適合した応答が行われる事、及び人によって操作される一般ブラウザが送信する単位時間パケット数やバイト量であれば所定の閾値に該当しない事に基づく。
また、サーバ23に対する処理負荷を試験するために、SYN FloodやGET Floodなど単純にパケットを送信するだけでは、サービス不能攻撃に対するサーバ処理の一部しか処理負荷を計測できない。
これにより、従来のパケット負荷試験を目的とした攻撃ツールでは、サーバ23やセキュリティ装置22の各段階の処理負荷を測るパケット負荷試験を行うことが難しかった。
まず、図3を用いて多段階防御機能について説明する。図3は、多段階防御機能について説明するための図である。図3に示すように、サーバ23にパケットを送信する場合、セキュリティ装置22による送信元パケット数制限や複数の段階の認証が行われる必要がある。セキュリティ装置22は、例えば、TCP認証、HTTP認証、チャレンジレスポンス認証、単位時間送信元パケット数制限、単位時間送信元バイト数制限、単位時間セッション数制限を行う。
例えば、セキュリティ装置22は、サーバ23に対するパケットの送信を検知した場合、当該パケットに対し、送信元IPアドレス毎にパケット数やセッション数等を監視し、パケットの送信元が人によって操作される一般ブラウザが送信するパケット数やセッション数等に基づいた閾値をクリアすれば、送信元パケット数制限機能を通過させる。例えば、セキュリティ装置22は、通過させる閾値をパケット数6個/秒以下、セッション数6セッション以下のように設定した場合、通過させる閾値を満たす送信元IPアドレスを一般ブラウザからの通信と判断して通過させる。
一方、送信されたパケットが、詐称した送信元によるSYN Flood攻撃を目的としたものである場合、セキュリティ装置22は、TCP認証の段階で当該パケットを廃棄する。このため、サーバ23のパケット負荷試験を目的とした攻撃ツールによってパケットが送信された場合であっても、セキュリティ装置22は所定の段階で当該パケットの送信が攻撃であることを検知し、当該パケットを廃棄する。さらに、TCP認証、HTTP認証、チャレンジ/レスポンスに応答可能な攻撃ツールが存在した場合でも、送信元パケット制限による単位時間あたりのパケット数制限、バイト数制限、セッション数制限により攻撃として判定される事で、当該送信元IPアドレスがブラックリスト登録されてパケット廃棄される。これらにより、従来のパケット負荷試験を目的とした攻撃ツールでは、サーバ23やセキュリティ装置22のパケット負荷試験を行うことが難しかった。
これに対し、第1の実施形態に係る試験装置によれば、サーバ23やセキュリティ装置22のパケット負荷試験を行うことが可能である。ここで、図4を用いて、試験装置10がサーバ23またはセキュリティ装置22のパケット負荷試験を行う場合の動作について説明する。
図4は、第1の実施形態に係る試験装置によるパケット負荷試験について説明するためのシーケンス図である。まず、試験装置10は、攻撃パケットおよびモニタリングの設定を行う(ステップS101)。このとき、試験装置10は、試験パケットとして、例えばHTTP接続後にサーバに大量にログインし、大量に検索を行う試験パケットを送信するように設定を行う。また、試験装置10は、モニタリングとして、例えばサーバ23のpingやtracebackへの応答確認、またはHTTP応答確認を行うような設定を行う。また、パケットフィルタ状況の監視として、送信元IPアドレス単位の単位時間あたり試験パケット数、バイト量、セッション数及び試験対象システムからの応答パケットを監視し、他の送信元IPアドレス試験パケットには応答パケットが来ているものの、試験パケットを送信しているのに応答パケットが来なくなった送信元IPアドレスを把握する。当該送信元IPアドレスに対して応答パケットが来なくなった直前の時刻に送信していた、応答パケットが来なくなった送信元IPアドレス、試験パケット数、バイト量、セッション数、タイムスタンプを試験対象システムのパケットフィルタ閾値として記録して制御部12に対して通知するような設定を行う。
そして、試験装置10の送信部127は、試験パケット用インタフェース111から試験パケットを送信する。このとき、まず、送信部127は、サーバ23との間にTCPコネクションを確立するために、サーバ23のIPアドレスである10.0.0.1にTCP SYNパケットを送信する(ステップS102)。
これに対し、セキュリティ装置22は、サーバ23宛てに送信されたSYNパケットが攻撃パケットであるか否かを判定するため、TCP認証応答要求を行う(ステップS103)。なお、TCPコネクションが確立される場合、SYNパケットの送信元に対してはSYN/ACKパケットが送信される。
ここで、例えば、攻撃ツールは、SYNパケットに対して不当なパケットが送信されてきた場合であっても、不当なパケットに適合した応答を行わず、再びSYNパケットを送信するといった行動を取ることが知られている。そこで、TCP認証を行う場合、セキュリティ装置22は、例えば、Cookieを入れたSYN/ACKパケット、不当なACK Sequenceナンバーを入れたSYN/ACKパケット、ACKパケット、RSTパケット等の不当なパケットを試験装置10に送信する。そして、セキュリティ装置22は、送信した不当なパケットに適合した応答が返ってきた場合、TCP認証を通過させる。
ここで、試験装置10の応答部125は、セキュリティ装置22に対し、TCP認証応答要求に適合した応答を行う(ステップS104)。例えば、応答部125は、SYNパケットに対しCookieを入れたSYN/ACKパケットが送信されてきた場合、当該パケットがCookieを入れたSYN/ACKパケットであることを識別する。そして、応答部125は、当該Cookieの内容に基づいたSequenceナンバーを設定したACKパケットをセキュリティ装置22に送信する。なお、SYN Flood攻撃を目的とした攻撃ツールは、セキュリティ装置22からCookieを入れたSYN/ACKパケットが送信されてきた場合であっても、何も応答しないことが考えられる。
これにより、試験装置10は、サーバ23との間でTCPコネクションを確立させることができ、送信部127によって送信された試験パケットがTCP認証段階で廃棄されることを防止することができる。そして、試験装置10は、TCP認証より先の段階の認証を行う際のセキュリティ装置22や、サーバ23を対象にパケット負荷試験を行うことができる。
TCPコネクションが確立されると、送信部127は、サーバ23宛てにHTTPリクエストパケットを送信する(ステップS105)。セキュリティ装置22は、サーバ23宛てに送信されたHTTPリクエストパケットが試験パケットであるか否かを判定するため、HTTP認証応答要求を行う(ステップS106)。
ここで、応答部125は、セキュリティ装置22に対し、HTTPS認証に適合した応答を行う(ステップS107)。例えば、応答部125は、セキュリティ装置22からの応答がリダイレクト応答であることを識別する。そして、応答部125は、リダイレクト応答のLocationヘッダで示されるURI(Uniform Resource Identifier)等の値に指定されたリダイレクト先にHTTPリクエストパケットを送信する。なお、リダイレクト応答に適合した応答を行わない攻撃ツールは、Locationヘッダを参照せず、リダイレクト先にHTTPリクエストパケットを送信しないことが考えられる。
さらに、セキュリティ装置22は、サーバ23宛てに送信されたHTTPリクエストリクエストパケットが攻撃パケットであるか否かを判定するため、HTTP CookieやJavaScript(登録商標)によるHTTP認証応答要求を行う(ステップS108)。
HTTP CookieやJavaScriptによるHTTP認証を行う場合、セキュリティ装置22は、例えば、試験装置10に対し、JavaScriptで記述したプログラムによって、Cookieの記載内容を読み取り、読み取った結果を返す処理を実行することを要求する。そして、セキュリティ装置22は、所定時間内に当該プログラムの実行結果が返ってきた場合、HTTP認証を通過させる。
ここで、応答部125は、セキュリティ装置22に対し、HTTP CookieやJavaScriptによるHTTP認証に適合した応答を行う(ステップS109)。例えば、応答部125は、セキュリティ装置22から送信されたデータが、JavaScriptの実行命令であることを識別する。そして、応答部125は、JavaScriptで記述されたプログラムを実行した結果得られるCookieの記載内容をセキュリティ装置22に通知する。なお、JavaScriptおよびCookieによるHTTP認証に適合した応答を行わない攻撃ツールは、HTTP CookieやJavaScriptによるHTTP認証に対し何も応答しないことが考えられる。
これにより、試験装置10は、HTTP認証を通過することができ、送信部127によって送信された攻撃パケットがHTTP認証段階で廃棄されることを防止することができる。そして、試験装置10は、HTTP認証より先の段階の認証を行う際のセキュリティ装置22や、サーバ23を対象にパケット負荷試験を行うことができる。
さらに、HTTP認証がされた場合、送信部127は、サーバ23宛てにHTTPリクエストパケットを送信する(ステップS110)。セキュリティ装置22は、サーバ23宛てに送信されたHTTPリクエストパケットが攻撃パケットであるか否かを判定するため、チャレンジレスポンス認証応答要求を行う(ステップS111)。
チャレンジレスポンス認証を行う場合、セキュリティ装置22は、例えば、試験装置10bに対し、所定経路上におけるマウス移動やCAPTCHA(Completely Automated Public Turing test to tell Computers and Humans Apart)を要求する。そして、セキュリティ装置22は、マウス移動やCAPTCHAに適合した応答が返ってきた場合、チャレンジレスポンス認証による認証を通過させる。
ここで、応答部125は、セキュリティ装置22に対し、チャレンジレスポンス認証に適合した応答を行う(ステップS112)。例えば、応答部125は、セキュリティ装置22によってマウス移動経路が示されていることを識別する。そして、応答部125は、マウス移動経路として示された経路を読み取り、読み取った経路に沿ってマウスを移動させた際に発生する信号と同じ信号をセキュリティ装置22に送信する。
また、応答部125は、セキュリティ装置22によってCAPTCHAが示されていることを識別する。そして、応答部125は、画像テキスト化サービスやOCR等を用いてCAPTCHAをテキスト化したデータをセキュリティ装置22に送信する。なお、チャレンジレスポンス認証に適合した応答を行わない攻撃ツールは、マウス移動やCAPTCHAによるチャレンジレスポンス認証に対し何も応答しないことが考えられる。
これにより、試験装置10は、チャレンジレスポンス認証を通過することができ、送信部127によって送信された試験パケットがチャレンジレスポンス認証段階で廃棄されることを防止することができる。試験装置10は、試験パケットを試験対象システム20のサーバ23に送信し(ステップS113)、試験対象システム20から応答パケットを受信する(ステップS114)ことで、サーバ23を対象にパケット負荷試験を行うことができる。
単体の試験装置10から送信可能な試験パケットの送信元IPアドレスを増やすことにより、複数攻撃元からのサービス不能攻撃を模擬可能になるとともに、試験装置の制御部を複数用意せずに複数IPアドレスからの試験パケット送信が可能になり、試験リソースを削減できる。アドレス分散部126は、例えば、送信する試験パケットがTCP SYNパケットの時、管理部123から設定されたIPアドレスリストに基づいて前回のTCP SYNパケットとは異なる送信元IPアドレスを順次割り当て、当該TCPコネクションに対して同一送信元IPアドレスを割り当てることで、TCPコネクションのIPアドレス整合性を保ちながら複数の送信元IPアドレスにより試験パケットの送信が可能になる。
そして、試験装置10から送信された試験パケット及び試験パケットへの試験対象システム20からの応答パケットに対して、モニタリング部122は、試験パケットに対する試験対象システム20のパケットフィルタ状況のモニタリングおよび分析を行う(ステップS115)。パケットフィルタ状況の監視として、送信元IPアドレス単位の単位時間あたり試験パケット数、バイト量、セッション数及び試験対象システムからの応答パケットを監視し、他の送信元IPアドレス試験パケットには応答パケットが来ているものの、試験パケットを送信しているのに応答パケットが来なくなった送信元IPアドレスを把握する。当該送信元IPアドレスに対して応答パケットが来なくなった直前の時刻に送信していた、応答パケットが来なくなった送信元IPアドレス、試験パケット数、バイト量、セッション数、タイムスタンプを試験対象システム20のパケットフィルタ閾値として記録して制御部12に対して通知するような設定を行う。
制御部12のアドレス分散部126は、モニタリング部122から試験対象システム20のパケットフィルタ閾値が通知された場合、送信元IPアドレス数を制御して試験対象システムのパケットフィルタ閾値に該当しないよう送信元IPアドレスあたりの試験パケット送信を調整する。例えば、応答パケットが来なくなりパケットフィルタされたと判断した送信元IPアドレスからの送信を一定時間停止し、まだパケットフィルタされていない新たな送信元IPアドレスから試験パケットを送信するとともに、送信元IPアドレス単位のパケット送信をパケットフィルタに該当しない範囲に絞って実施する。
これにより、試験装置10は、図3で示す送信元パケット制限を通過することができ、送信部127によって送信された試験パケットが送信元パケット制限段階で廃棄されることを防止することができる。そして、試験装置10は、サーバ23を対象にパケット負荷試験を行うことができる。
サーバ23を対象としたパケット負荷試験として、SYN FloodやGET Floodなど単純にパケットを送信するだけでは、サービス不能攻撃に対するサーバ処理の一部しか処理負荷を計測できない。そこで、試験シナリオ部124は、スクリプト等を用いて記述されたシナリオに基づき、Webサーバ等の試験対象システム20との間でHTTP及びHTTPSのセッションを構築した上で、サーバ23に対してログイン情報などのセッション情報を維持した試験パケットを送信するため、サーバ23から受信したCookieに基づいた試験パケットを生成する。試験パケットとして、GET及びPOST Flood以外に、サーバ23への複数アカウント作成・削除、複数アカウントからの頻繁なログイン・ログアウト、頻繁な検索実行の攻撃試験を実施するだけでなく、維持したセッション上でSlow READ等のTCPヘッダを変更する攻撃試験を実施する。
これにより、サーバ23に対して、HTTP GETパケット処理負荷やHTTP POSTパケット処理負荷などの単純なサーバ処理負荷を計測するだけでなく、サーバ23のログイン情報暗号化および復号化処理負荷、検索処理負荷、およびデータベース処理負荷などの負荷試験を行うことができる。
一方で、モニタリング部122は、サーバ23にモニタリング応答要求を行う。例えば、モニタリング部122は、試験装置10による設定に従い、サーバ23のpingやtracebackへの応答確認、またはHTTP応答確認を行う。
そして、サーバ23は、攻撃パケットを処理しつつ、モニタリング応答要求に対して応答する。そして、モニタリング部122は、モニタリング用インタフェース112からモニタリング結果を出力する。
さらに、試験装置10は、モニタリング結果を分析し、必要に応じて試験装置10にシナリオ変更を指示する。具体的には、試験装置10は、受信したモニタリング結果と、攻撃パケットの種類や量である試験トラフィックとの相関を取りながらサーバ23の応答時間や応答内容を分析する。サーバ23の応答時間変化や応答メッセージ、応答がなくなったときの試験トラフィック内容、応答が復活したときの試験トラフィック内容等を時系列で記録・分析し、処理負荷が高い機能を把握する。
シナリオ変更として、例えば、管理部123は、セキュリティ装置22またはサーバ23の処理負荷の状況に応じて、送信部127によって送信される試験パケットの量を変化させる。具体的には、管理部123は、セキュリティ装置22またはサーバ23の処理負荷が所定以上である場合、セキュリティ装置22またはサーバ23に送信部127によって送信される試験パケットの量を増加させる。
そして、処理負荷が高い機能を把握するとともに、試験トラフィックのシナリオを変化させ、そのときのサーバ23の応答時間変化や応答メッセージ、応答がなくなったときの試験トラフィック内容、応答が復活したときの試験トラフィック内容から処理負荷が高い機能の負荷が最大になる試験トラフィック条件を抽出する。
なお、試験装置10は、サーバ23以外の機器を含めた複数の試験対象機器について試験および分析を行い、試験対象機器の中から処理負荷が高い機器を把握するようにしてもよい。
例えば、試験装置10がログイン攻撃パケット量を増加させていくと、サーバ23の処理負荷が増加するとともにHTTP応答時間が増加していく。そして、試験装置10は、サーバ23がサーバに接続できたもののウェブページを表示できないHTTP 404エラー応答を行うようになった時点の攻撃パケット量、およびサーバ23が応答することができなくなった時点の攻撃パケット量を記録する。これにより、サーバ23のログイン攻撃への耐性を把握することができる。
また、試験パケットの量が増加すると、セキュリティ装置22が攻撃を検出して、当該攻撃パケットを廃棄し、サーバ23の処理負荷の増加が止まることがある。このとき、試験装置10は、モニタリング結果から、サーバ23への攻撃パケットを増加させても、サーバ23の処理負荷が増加しないことを把握する。この場合、アドレス分散部126の処理により異なる送信元IPアドレスからパケットフィルタ閾値に該当しない範囲で試験パケットを送信して、処理負荷が増加するか試験することができる。
さらに、単体の試験装置10だけでなく、複数の試験装置から、サーバ23に対し、サービス不能攻撃パケット等をシナリオに沿って送信するようにしてもよい。これにより、大量の送信元IPアドレス単位の攻撃対策やキャッシュ等の対策有効度を調査し、さらにモニタリングを行うことで、サービス不能になる限界、ボトルネック、およびそのときの試験トラフィックパターン等を把握することができる。
これにより、複数の試験装置からのモニタリングによるサーバ23の応答が異なる原因が、ネットワーク装置21、セキュリティ装置22、もしくはサーバ23自身による試験装置10へのフィルタ設定によるものであるのか、またはサーバ23の負荷によるものであるのかを判定する。
なお、試験装置10は、認証を途中で中止し、セキュリティ装置22の任意の認証段階の処理に対する負荷試験を行うようにしてもよい。例えば、試験装置10は、セキュリティ装置22によるTCP認証応答要求に対して適合する応答を行い、その後、セキュリティ装置22によるHTTP認証応答要求に対して適合する応答を行わないようにしてもよい。これにより、試験装置10は、セキュリティ装置22のHTTP認証段階の処理に対する負荷試験を行うことができる。同様に、試験装置10は、セキュリティ装置22の各認証段階について負荷試験を行うことで、ボトルネックとなる認証段階を特定することができる。
[第1の実施形態の効果]
試験装置10の試験シナリオ部124は、Webサーバ等の試験対象装置との間でHTTP及びHTTPSのセッションを構築した上で、試験対象装置に対してシナリオに基づいてログインや検索等を実行する試験パケットを生成する。アドレス分散部126は、あらかじめ設定されたIPアドレスのリストに基づいて送信する試験パケットの送信元IPアドレスを分散させるが、同一コネクションでは同一送信元IPアドレスにし、セキュリティ装置22及びサーバ23のパケットフィルタ状況に応じてパケットフィルタを回避するよう送信元IPアドレス単位のパケット量を変化させる。送信部127は、試験シナリオ部124が生成したパケットとアドレス分散部126の送信元IPアドレス設定に基づいて処理負荷を増加させる試験パケットを送信する。また、応答部125は、セキュリティ装置22によって行われる認証に対応した応答要求を受信し、受信した応答要求を識別し、識別した応答要求に適合する応答、すなわち攻撃パケットがセキュリティ装置22によって正当なものであると認証されるような応答を行う。また、モニタリング部122は、セキュリティ装置22によって正当なものであると認証された攻撃パケットが送信されたセキュリティ装置22の処理負荷の高い認証機能またはサーバの処理負荷の状況を監視する。
試験装置10の試験シナリオ部124は、Webサーバ等の試験対象装置との間でHTTP及びHTTPSのセッションを構築した上で、試験対象装置に対してシナリオに基づいてログインや検索等を実行する試験パケットを生成する。アドレス分散部126は、あらかじめ設定されたIPアドレスのリストに基づいて送信する試験パケットの送信元IPアドレスを分散させるが、同一コネクションでは同一送信元IPアドレスにし、セキュリティ装置22及びサーバ23のパケットフィルタ状況に応じてパケットフィルタを回避するよう送信元IPアドレス単位のパケット量を変化させる。送信部127は、試験シナリオ部124が生成したパケットとアドレス分散部126の送信元IPアドレス設定に基づいて処理負荷を増加させる試験パケットを送信する。また、応答部125は、セキュリティ装置22によって行われる認証に対応した応答要求を受信し、受信した応答要求を識別し、識別した応答要求に適合する応答、すなわち攻撃パケットがセキュリティ装置22によって正当なものであると認証されるような応答を行う。また、モニタリング部122は、セキュリティ装置22によって正当なものであると認証された攻撃パケットが送信されたセキュリティ装置22の処理負荷の高い認証機能またはサーバの処理負荷の状況を監視する。
このように、第1の実施形態に係る試験装置10によれば、認証に対応した応答要求に適した応答を行うことで認証を通過したうえで、送信元IPアドレス単位のパケットフィルタを回避したうえ、試験対象の機器の復号化処理やデータベース等複数個所に負荷を印加し、セキュリティ耐性の試験を行うことが可能となる。また、複数の段階の認証や複数の機器を試験対象とすることで、ボトルネックを特定することが可能となる。
また、応答部125は、セキュリティ装置22によって段階的に行われる認証のうち任意の段階までの認証に対応した応答要求を受信するたびに、受信した応答要求を識別し、識別した応答要求に適合する応答、すなわち試験パケットがセキュリティシステムによって正当なものであると認証されるような応答を行う。これにより、セキュリティ装置22の任意の段階の試験を行うことが可能となる。
送信部127は、Webサーバであるサーバ23に、試験パケットとともに、Webブラウザの操作により発生するパケットを送信する。これにより、実際に攻撃が行われる場合に近い状況での試験を行うことが可能となる。
管理部123は、セキュリティ装置22またはサーバ23の処理負荷の状況に応じて、送信部127によって送信される攻撃パケットの量を変化させる。試験対象機器の処理負荷に応じた動作を把握することが可能となる。
管理部123は、セキュリティ装置22またはサーバ23の処理負荷が所定以上である場合、セキュリティ装置22またはサーバ23に送信部127によって送信される試験パケットの内容を変化させる。これにより、試験対象機器の処理負荷の限界を把握することが可能となる。
[その他の実施形態]
サーバ23がDNSサーバ等のWebサーバ以外のサーバである場合や、ネットワーク装置21やセキュリティ装置22に対する調査を行う場合、試験装置10は、試験対象機器がサービスしているプロトコル、アプリケーションに従ったサービス不能攻撃パケットと正常パケットを送信する。このとき、セキュリティ装置22がTCP再送要求等のDNS認証等の要求を送信する場合があるが、試験装置10aは、要求に従ったパケットを送信する。これにより、追加の認証が行われる場合であっても、試験対象機器のセキュリティ耐性調査やボトルネック調査を進めることができる。
サーバ23がDNSサーバ等のWebサーバ以外のサーバである場合や、ネットワーク装置21やセキュリティ装置22に対する調査を行う場合、試験装置10は、試験対象機器がサービスしているプロトコル、アプリケーションに従ったサービス不能攻撃パケットと正常パケットを送信する。このとき、セキュリティ装置22がTCP再送要求等のDNS認証等の要求を送信する場合があるが、試験装置10aは、要求に従ったパケットを送信する。これにより、追加の認証が行われる場合であっても、試験対象機器のセキュリティ耐性調査やボトルネック調査を進めることができる。
[システム構成等]
また、図示した各装置の各構成要素は機能概念的なものであり、必ずしも物理的に図示の如く構成されていることを要しない。すなわち、各装置の分散・統合の具体的形態は図示のものに限られず、その全部または一部を、各種の負荷や使用状況などに応じて、任意の単位で機能的または物理的に分散・統合して構成することができる。さらに、各装置にて行われる各処理機能は、その全部または任意の一部が、CPUおよび当該CPUにて解析実行されるプログラムにて実現され、あるいは、ワイヤードロジックによるハードウェアとして実現され得る。
また、図示した各装置の各構成要素は機能概念的なものであり、必ずしも物理的に図示の如く構成されていることを要しない。すなわち、各装置の分散・統合の具体的形態は図示のものに限られず、その全部または一部を、各種の負荷や使用状況などに応じて、任意の単位で機能的または物理的に分散・統合して構成することができる。さらに、各装置にて行われる各処理機能は、その全部または任意の一部が、CPUおよび当該CPUにて解析実行されるプログラムにて実現され、あるいは、ワイヤードロジックによるハードウェアとして実現され得る。
また、本実施の形態において説明した各処理のうち、自動的に行われるものとして説明した処理の全部または一部を手動的に行うこともでき、あるいは、手動的におこなわれるものとして説明した処理の全部または一部を公知の方法で自動的に行うこともできる。この他、上記文書中や図面中で示した処理手順、制御手順、具体的名称、各種のデータやパラメータを含む情報については、特記する場合を除いて任意に変更することができる。
[プログラム]
また、上記実施形態において説明した試験装置が実行する処理について、コンピュータが実行可能な言語で記述したプログラムを作成することもできる。例えば、実施形態に係る試験装置が実行する処理について、コンピュータが実行可能な言語で記述したプログラムを作成することもできる。この場合、コンピュータがプログラムを実行することにより、上記実施形態と同様の効果を得ることができる。以下に、プログラムを実行するコンピュータの一例を説明する。
また、上記実施形態において説明した試験装置が実行する処理について、コンピュータが実行可能な言語で記述したプログラムを作成することもできる。例えば、実施形態に係る試験装置が実行する処理について、コンピュータが実行可能な言語で記述したプログラムを作成することもできる。この場合、コンピュータがプログラムを実行することにより、上記実施形態と同様の効果を得ることができる。以下に、プログラムを実行するコンピュータの一例を説明する。
図5は、プログラムを実行するコンピュータを示す図である。コンピュータ1000は、例えば、メモリ1010、CPU1020を有する。また、コンピュータ1000は、ハードディスクドライブインタフェース1030、ディスクドライブインタフェース1040、シリアルポートインタフェース1050、ビデオアダプタ1060、ネットワークインタフェース1070を有する。これらの各部は、バス1080によって接続される。
メモリ1010は、ROM(Read Only Memory)1011及びRAM1012を含む。ROM1011は、例えば、BIOS(Basic Input Output System)等のブートプログラムを記憶する。ハードディスクドライブインタフェース1030は、ハードディスクドライブ1090に接続される。ディスクドライブインタフェース1040は、ディスクドライブ1100に接続される。例えば磁気ディスクや光ディスク等の着脱可能な記憶媒体が、ディスクドライブ1100に挿入される。シリアルポートインタフェース1050は、例えばマウス1051、キーボード1052に接続される。ビデオアダプタ1060は、例えばディスプレイ1061に接続される。
ハードディスクドライブ1090は、例えば、OS1091、アプリケーションプログラム1092、プログラムモジュール1093、プログラムデータ1094を記憶する。すなわち各装置の各処理を規定するプログラムは、コンピュータにより実行可能なコードが記述されたプログラムモジュール1093として実装される。プログラムモジュール1093は、例えばハードディスクドライブ1090に記憶される。例えば、装置における機能構成と同様の処理を実行するためのプログラムモジュール1093が、ハードディスクドライブ1090に記憶される。なお、ハードディスクドライブ1090は、SSD(Solid State Drive)により代替されてもよい。
また、上述した実施の形態の処理で用いられるデータは、プログラムデータ1094として、例えばメモリ1010やハードディスクドライブ1090に記憶される。そして、CPU1020が、メモリ1010やハードディスクドライブ1090に記憶されたプログラムモジュール1093やプログラムデータ1094を必要に応じてRAM1012に読み出して実行する。
なお、プログラムモジュール1093やプログラムデータ1094は、ハードディスクドライブ1090に記憶される場合に限らず、例えば着脱可能な記憶媒体に記憶され、ディスクドライブ1100等を介してCPU1020によって読み出されてもよい。あるいは、プログラムモジュール1093及びプログラムデータ1094は、ネットワーク、WANを介して接続された他のコンピュータに記憶されてもよい。そして、プログラムモジュール1093及びプログラムデータ1094は、他のコンピュータから、ネットワークインタフェース1070を介してCPU1020によって読み出されてもよい。
1 ネットワーク
10 試験装置
11 インタフェース部
12 制御部
13 記憶部
20 試験対象システム
21 ネットワーク装置
22 セキュリティ装置
23 サーバ
111 試験パケット用インタフェース
112 モニタリング用インタフェース
113 管理用インタフェース
121 試験パケット送受信部
122 モニタリング部
123 管理部
124 試験シナリオ部
125 応答部
126 アドレス分散部
127 送信部
10 試験装置
11 インタフェース部
12 制御部
13 記憶部
20 試験対象システム
21 ネットワーク装置
22 セキュリティ装置
23 サーバ
111 試験パケット用インタフェース
112 モニタリング用インタフェース
113 管理用インタフェース
121 試験パケット送受信部
122 モニタリング部
123 管理部
124 試験シナリオ部
125 応答部
126 アドレス分散部
127 送信部
Claims (8)
- 防御対象の装置宛てに送信されたパケットの認証及び送信元IPアドレス毎パケット制限を行うセキュリティシステムによって防御された装置に対し、処理負荷を増加させる試験パケットを送信する送信部と、
前記試験パケットを送信する際、シナリオに基づいて試験セッションを生成する試験シナリオ部と、
前記試験パケットが複数の送信元IPアドレスを用いるようにパケットを構築するアドレス分散部と、
前記セキュリティシステムによって行われる複数の段階の認証のうち、所定の段階の認証までの応答要求に対し、前記試験パケットが前記セキュリティシステムによって正当なものであると認証されるように応答を行う応答部と、
前記所定の段階における、前記試験パケットが送信された前記セキュリティシステムのパケットフィルタ状況及び処理負荷を監視する監視部と、
を有することを特徴とする試験装置。 - 前記試験シナリオ部は、Webサーバ等の試験対象装置との間でHTTP及びHTTPSのセッションを構築した上で、試験対象装置に対してシナリオに基づいてログインや検索等を実行する試験パケットを生成するとともに、ログイン情報などのセッション情報を維持した試験パケットを送信するために試験対象装置から受信したCookieに基づいた試験パケットを生成することを特徴とする請求項1に記載の試験装置。
- 前記応答部は、前記所定の段階までの認証に対応した応答要求を受信するたびに、受信した応答要求を識別し、識別した応答要求に対し、前記試験パケットが前記セキュリティシステムによって正当なものであると認証されるように応答を行うことを特徴とする請求項1に記載の試験装置。
- 前記アドレス分散部は、あらかじめ設定されたIPアドレスのリストに基づいて、送信する試験パケットの送信元IPアドレスを分散させるが、同一コネクションでは同一送信元IPアドレスを用いることを特徴とする請求項1に記載の試験装置。
- 前記応答部は、TCP認証、HTTP認証およびチャレンジレスポンス認証のいずれかに対応した応答要求を受信した場合、受信した応答要求の種別として、TCP認証、HTTP認証およびチャレンジレスポンス認証のいずれに対応した応答要求であるかを識別し、識別した種別の認証において正当なものであると認証されるように応答を行うことを特徴とする請求項4に記載の試験装置。
- 前記送信部は、Webサーバである前記装置に、前記試験パケットとともに、Webブラウザの操作により発生するパケットを送信することを特徴とする請求項1に記載の試験装置。
- 前記セキュリティシステム及び防御対象装置のパケットフィルタ状況及び処理負荷の状況に応じて、前記送信部によって送信される前記試験パケットの量を変化させる管理部をさらに有することを特徴とする請求項1に記載の試験装置。
- 前記管理部は、前記セキュリティシステムの処理負荷が所定以上である場合、前記セキュリティシステムに前記送信部によって送信される前記試験パケットの量を増加させることを特徴とする請求項7に記載の試験装置。
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US17/428,618 US11943250B2 (en) | 2019-02-07 | 2020-01-22 | Test device |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2019-021081 | 2019-02-07 | ||
| JP2019021081A JP7222260B2 (ja) | 2019-02-07 | 2019-02-07 | 試験装置 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020162181A1 true WO2020162181A1 (ja) | 2020-08-13 |
Family
ID=71947870
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2020/002141 Ceased WO2020162181A1 (ja) | 2019-02-07 | 2020-01-22 | 試験装置 |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US11943250B2 (ja) |
| JP (1) | JP7222260B2 (ja) |
| WO (1) | WO2020162181A1 (ja) |
Families Citing this family (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP7222260B2 (ja) * | 2019-02-07 | 2023-02-15 | 日本電信電話株式会社 | 試験装置 |
| WO2022070425A1 (ja) * | 2020-10-02 | 2022-04-07 | 日本電信電話株式会社 | 試験装置、試験方法および試験プログラム |
| JP7608380B2 (ja) * | 2022-01-21 | 2025-01-06 | 株式会社東芝 | 情報処理装置及びプログラム |
| CN115866109B (zh) * | 2022-11-30 | 2025-09-26 | 长城信息股份有限公司 | 一种远程设备原生驱动控制方法及装置 |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2014041463A (ja) * | 2012-08-22 | 2014-03-06 | Mitsubishi Electric Corp | テスト装置及びテスト方法及びプログラム |
| JP2017195432A (ja) * | 2016-04-18 | 2017-10-26 | 日本電信電話株式会社 | 試験装置、試験方法および試験プログラム |
Family Cites Families (15)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP1802059A2 (en) * | 2004-10-12 | 2007-06-27 | Nippon Telegraph and Telephone Corporation | Repeater, repeating method, repeating program, and network attack defending system |
| US8149730B1 (en) * | 2009-05-12 | 2012-04-03 | Juniper Networks, Inc. | Methods and apparatus related to packet generation and analysis |
| SG11201400524QA (en) * | 2011-10-13 | 2014-04-28 | Ericsson Telefon Ab L M | Detection of load balancing across network paths in a communication network |
| US9001687B2 (en) * | 2013-04-05 | 2015-04-07 | Telefonaktiebolaget L M Ericsson (Publ) | Packet interception and timestamping for error estimation in active measurement protocols |
| US9413783B1 (en) * | 2014-06-02 | 2016-08-09 | Amazon Technologies, Inc. | Network interface with on-board packet processing |
| WO2016080446A1 (ja) * | 2014-11-19 | 2016-05-26 | 日本電信電話株式会社 | 制御装置、境界ルータ、制御方法、および、制御プログラム |
| US10728281B2 (en) * | 2015-04-28 | 2020-07-28 | Nippon Telegraph And Telephone Corporation | Connection control apparatus, connection control method, and connection control program |
| US10212195B2 (en) * | 2015-08-29 | 2019-02-19 | Vmware, Inc. | Multi-spoke connectivity of private data centers to the cloud |
| WO2017166047A1 (zh) * | 2016-03-29 | 2017-10-05 | 华为技术有限公司 | 网络攻击防御策略发送、网络攻击防御的方法和装置 |
| JP6740264B2 (ja) * | 2018-02-13 | 2020-08-12 | 日本電信電話株式会社 | 監視システム、監視方法及び監視プログラム |
| JP6778229B2 (ja) * | 2018-03-05 | 2020-10-28 | 日本電信電話株式会社 | ネットワークサービス選択装置及びネットワークサービス選択方法 |
| US10944770B2 (en) * | 2018-10-25 | 2021-03-09 | EMC IP Holding Company LLC | Protecting against and learning attack vectors on web artifacts |
| JP7222260B2 (ja) * | 2019-02-07 | 2023-02-15 | 日本電信電話株式会社 | 試験装置 |
| US11233883B2 (en) * | 2020-03-11 | 2022-01-25 | Verizon Patent And Licensing Inc. | Systems and methods for acquiring an internet protocol network address of a user equipment in networks |
| JP7521496B2 (ja) * | 2021-06-29 | 2024-07-24 | 株式会社デンソー | 帯域推定装置、方法、及びプログラム |
-
2019
- 2019-02-07 JP JP2019021081A patent/JP7222260B2/ja active Active
-
2020
- 2020-01-22 WO PCT/JP2020/002141 patent/WO2020162181A1/ja not_active Ceased
- 2020-01-22 US US17/428,618 patent/US11943250B2/en active Active
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2014041463A (ja) * | 2012-08-22 | 2014-03-06 | Mitsubishi Electric Corp | テスト装置及びテスト方法及びプログラム |
| JP2017195432A (ja) * | 2016-04-18 | 2017-10-26 | 日本電信電話株式会社 | 試験装置、試験方法および試験プログラム |
Also Published As
| Publication number | Publication date |
|---|---|
| JP7222260B2 (ja) | 2023-02-15 |
| JP2020129736A (ja) | 2020-08-27 |
| US11943250B2 (en) | 2024-03-26 |
| US20220116413A1 (en) | 2022-04-14 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11075885B2 (en) | Methods and systems for API deception environment and API traffic control and security | |
| Izhikevich et al. | {LZR}: Identifying unexpected internet services | |
| JP7388613B2 (ja) | パケット処理方法及び装置、デバイス、並びに、コンピュータ可読ストレージ媒体 | |
| JP7472997B2 (ja) | 試験装置、試験方法および試験プログラム | |
| US10257213B2 (en) | Extraction criterion determination method, communication monitoring system, extraction criterion determination apparatus and extraction criterion determination program | |
| Alzahrani et al. | Generation of DDoS attack dataset for effective IDS development and evaluation | |
| US10693908B2 (en) | Apparatus and method for detecting distributed reflection denial of service attack | |
| WO2020162181A1 (ja) | 試験装置 | |
| Vanitha et al. | Distributed denial of service: Attack techniques and mitigation | |
| EP2887602A1 (en) | Session level mitigation of service disrupting attacks | |
| Muraleedharan et al. | Behaviour analysis of HTTP based slow denial of service attack | |
| Luckie et al. | Resilience of deployed TCP to blind attacks | |
| JP2018026747A (ja) | 攻撃検知装置、攻撃検知システムおよび攻撃検知方法 | |
| Mohammad et al. | DDoS attack mitigation using entropy in SDN-IoT environment | |
| Vizváry et al. | Flow-based detection of RDP brute-force attacks | |
| Aborujilah et al. | Detecting TCP SYN based flooding attacks by analyzing CPU and network resources performance | |
| JP7318730B2 (ja) | 試験装置、試験方法および試験プログラム | |
| Suethanuwong | An Effective Prevention Approach Against ARP Cache Poisoning Attacks in MikroTik-based Networks | |
| JP6497782B2 (ja) | 試験装置、試験方法および試験プログラム | |
| KR20130009130A (ko) | 좀비 피씨 및 디도스 대응 장치 및 방법 | |
| CN116319028A (zh) | 一种反弹shell攻击拦截方法和装置 | |
| Sidabutar et al. | Comparative Study of Open-source Firewall | |
| Hyppönen | Securing a linux server against cyber attacks | |
| Sachidananda et al. | Spill the Beans: Extrospection of Internet of Things by Exploiting Denial of Service. | |
| John et al. | Impact of AAB-DDoS Attacks in a Real-Time Cloud Environment and the Mitigation Strategies |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 20752686 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 20752686 Country of ref document: EP Kind code of ref document: A1 |