Lock in $30 Savings on PRO—Offer Ends Soon! ⏳
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
インターネットの片隅で〜mirai亜種のスキャン活動を可視化して流行を知る〜
Search
nhnmomonga
February 24, 2018
Programming
1
560
インターネットの片隅で〜mirai亜種のスキャン活動を可視化して流行を知る〜
第三回ハニーポッター技術者交流会
nhnmomonga
February 24, 2018
Tweet
Share
More Decks by nhnmomonga
See All by nhnmomonga
ハニーポット同人誌の反響と収支
nhnmomonga
0
770
Other Decks in Programming
See All in Programming
tparseでgo testの出力を見やすくする
utgwkk
2
240
実は歴史的なアップデートだと思う AWS Interconnect - multicloud
maroon1st
0
210
新卒エンジニアのプルリクエスト with AI駆動
fukunaga2025
0
230
これならできる!個人開発のすゝめ
tinykitten
PRO
0
110
Full-Cycle Reactivity in Angular: SignalStore mit Signal Forms und Resources
manfredsteyer
PRO
0
150
從冷知識到漏洞,你不懂的 Web,駭客懂 - Huli @ WebConf Taiwan 2025
aszx87410
2
2.7k
JETLS.jl ─ A New Language Server for Julia
abap34
1
420
안드로이드 9년차 개발자, 프론트엔드 주니어로 커리어 리셋하기
maryang
1
120
WebRTC、 綺麗に見るか滑らかに見るか
sublimer
1
190
AtCoder Conference 2025「LLM時代のAHC」
imjk
2
520
LLM Çağında Backend Olmak: 10 Milyon Prompt'u Milisaniyede Sorgulamak
selcukusta
0
120
大規模Cloud Native環境におけるFalcoの運用
owlinux1000
0
130
Featured
See All Featured
Practical Orchestrator
shlominoach
190
11k
Leading Effective Engineering Teams in the AI Era
addyosmani
9
1.3k
Building an army of robots
kneath
306
46k
Balancing Empowerment & Direction
lara
5
800
Building a Modern Day E-commerce SEO Strategy
aleyda
45
8.3k
Sharpening the Axe: The Primacy of Toolmaking
bcantrill
46
2.6k
How GitHub (no longer) Works
holman
316
140k
Designing Experiences People Love
moore
143
24k
For a Future-Friendly Web
brad_frost
180
10k
Code Reviewing Like a Champion
maltzj
527
40k
Art, The Web, and Tiny UX
lynnandtonic
304
21k
Product Roadmaps are Hard
iamctodd
PRO
55
12k
Transcript
Πϯλʔωοτͷ ย۱Ͱ @nhnmomonga ʙmiraiѥछͷεΩϟϯ׆ಈΛՄࢹԽͯ͠ྲྀߦΛΔʙ
ࣗݾհ • @nhnmomongaʢʹ΄ΜΜΜ͕ʣ • ୈ̎ճͰൃදͰ͖ͣࢿྉ্͚ͩ͛ͯΒͬͨਓͰ͢ • ʮϋχʔϙοτಉਓࢽͷڹͱऩࢧʯͬͯࢿྉ • ීஈίϯϐϡʔλʔϑΥϨϯδοΫΛͬͯ·͢ •
࣌ʑޡղ͞Ε·͕͢͜ΕΒࣄͰΓಘͨใͰ͋Γ·ͤΜʢػ ඍใͰͳ͍ʣ
ຊ • ͱ͋ΔIIJ͞Μͷϒϩάهࣄ[1]ΛಡΜͰ͍ͨ • miraiѥछʹײછ͍ͯ͠Δຊࠃͷϗετ͕૿͑ͯΔ • ʢࣗͷཧ͍ͯ͠ΔʣϋχʔϙοτͰಉ͡Α͏ͳ͕ग़Δʁ • Θ͟Θ͟ૂΘΕΔΑ͏ͳ͜ͱ͍ͯ͠ͳ͍ •
͍ΘΠϯλʔωοτͷย۱ʹ͋Δ • SHDOANʹਖ਼֬ʹัଊ͞ΕͨΓ͞Εͳ͔ͬͨΓ… • ϩάΠϯͯ͠ͳ͍͔Β͓ۚΛ͏ͱͲ͏ͳΔ͔Θ͔Βͳ͍ [1]ຊࠃʹ͓͚Δ Mirai ѥछͷײછঢ়گ (201712݄) | https://sect.iij.ad.jp/d/2018/01/091843.html
ݕূ • ಉϒϩάʹΑΔͱɺʮmiraiѥछͷεΩϟϯ׆ಈʹεΩϟϯͷύέο τͷॳظγʔέϯεφϯόʔ͕ѼઌIPͱಉ͡ʯͱͯ͠؍ଌ • ಉ͜͡ͱΛϋχʔϙοτͰͯ͠ൺֱ͢Δ • ͲΕ͚ͩʢmiraiѥछʹײછ͍ͯ͠Δͱࢥ͖͠ʣࠃͷϗετ͔Β εΩϟϯΛड͚͍ͯΔ͔ݟͯΈ͍ͨ •
ϋχʔϙοτΛҰ͔͠ӡ༻͍ͯ͠ͳͯ͘ɺʢͪΌΜͱʣྲྀߦ ʹࠨӈ͞ΕΔͷ͔ʁ
ݕূํ๏ • tsharkͰύέοτΩϟϓνϟΛͱΔ • ʢ͓ۚͳ͍ͷͰʣखݩʹpcapϑΝΠϧΛμϯϩʔυ • pcapϑΝΠϧΛtsharkΛͬͯcsvϑΝΠϧ͢Δ • LogstashͰElasticsearchʹͿͪࠐΉ •
KibanaͰDashboard࡞Δ • ํ๏ͷৄࡉϒϩάʹͯ • http://onthesoup.hatenablog.com/entry/2018/02/11/061500
DEMO
݁Ռ • ͜͜·ͰͬͯɺΑ͘ߟ͑ͨΒ͕ಉ͔͡·ͰIIJ͞Μ͕2݄ͷ ੳ݁ՌΛग़ͯ͘͠Εͳ͍ͱΘ͔Βͳ͍͜ͱ͕Θ͔ͬͨʢসʣ • Ͳͷ͘Β͍ࠃϗετ͔ΒεΩϟϯ͕͋Δ͔Θ͔͚ͬͨͲ • ϓϥεʹߟ͑Δͱࠓͷঢ়گ͕Θ͔ͬͨʢͱ͍͏͜ͱʹ͍ͯͩ͘͠͞ʣ • ॳతͷୡདྷ݄IIJ͞Μ͕2݄ͷϒϩάΛॻ͍ͯ͘ΕΔ͔Ͳ
͏͔ʹ͔͔͍ͬͯΔ…ʂ • ͜͠ͷʹؔऀ͍Βͬ͠ΌͬͨΒͳΜͱ͔͓ئ͍͠·͢
͓Ͷ͕͍ • DemoΛݟͯͩ͘͞ΔͱΘ͔ͬͨͱࢥ͍·͕͢ɺࠃϗετ͔Βͷε Ωϟϯ݁ߏଘࡏ͍ͯ͠·͢ • ࣮ࣗ͝ՈʹؼͬͨΒҰϧʔλʔIPΧϝϥΛݕ͍ͯͩ͘͠͞ • ઃஔͨ͠Β୯ҐͰͦͷ··ͬͯී௨ͷ͝ՈఉͳΒΑ͋͘Δͣ • ڈ͔Βࠓʹ͔͚ͯࠃͰྲྀߦ֦ͨ͠ࢄ׆ಈʹར༻͞Ε͍ͯΔͱ
ݴΘΕ͍ͯΔ੬ऑੑ2014ʹެ։͞Εͨ੬ऑੑʢCVE-2014-8361ʣ • ࣮͝ՈʹؼΔػձͬͯҰͰԿճ͋Γ·͔͢ʁ • Miraiѥछ͚ͩ͡Όͳ͘CoinMinerྲྀߦ͍ͬͯ·͢ ͓͠·͍