૬ޓ௨৴ʹணͨ͠҉߸Խ
P2P
τϥώοΫͷหผख๏
ླক࢙
†Ѩ෦༸ৎ
††Ԭ෦ਖ਼
†††കଜګ࢘
† P2P ϑΝΠϧڞ༗ΞϓϦέʔγϣϯʹΑΔใ࿙Ӯஶ࡞ݖ৵ɼҰ෦ͷϔϏʔϢʔβʹΑΔτϥ ώοΫ༗େ͖ͳͱͳ͍ͬͯΔɽ͜ͷͨΊɼ௨৴τϥώοΫ͔Β P2P ͷ௨৴Λหผ͢Δ͜ͱ Ͱ্هͷΛࢭ͢Δ͜ͱ͕ٻΊΒΕ͍ͯΔɽ͜ΕΛ͏͚༷ͯʑͳหผख๏͕ఏҊ͞Ε͍ͯΔ͕ɼ ैདྷͷหผख๏Ͱ௨৴͕҉߸Խ͞Εͨ߹ʹ P2P τϥώοΫΛหผ͢Δ͜ͱ͕ࠔͰ͋Δͱ͍ͬ ͕ͨੜ͡Δɽͦ͜ͰຊߘͰ P2P τϥοΫͷ૬ޓଓੑʹண͠ɼ҉߸Խ͞Εͨ௨৴Ͱ P2P τϥώοΫΛหผͰ͖Δख๏ΛఏҊ͢Δɽ·ͨɼఏҊख๏ʹରͯ͠҉߸Խ͞Εͨ P2P τϥώοΫΛ ༻͍ͯධՁΛߦ͏ɽ͞ΒʹɼPlanetlab Λ༻͍ͯҬωοτϫʔΫͰͷଌఆΛߦ͍ɼఏҊख๏ͷద༻ ൣғΛ໌Β͔ʹ͢ΔɽAn analytical method for the pure P2P traffic
that focus attention on a bidirectional
connection for encrypted connection
Masashi Suzuki,
†Hirotake Abe,
††Masayuki Okabe
†††and Kyoji Umemura
†Today, There are problems such as the information leak and the copyright infringement by the peer-to-peer file-sharing application, and the traffic occupation by some heavy users. For these reasons, P2P communication discrimination becomes necessary to suppress the above problems. As a result, various discrimination techniques have been proposed. However, if the communication is encrypted, it is usually difficult to distinguish P2P traffic from ordinal traffic by the existing discrimination technique. In this paper, we propose a technique to detect P2P traffic in encrypted communications, focusing on the inter-connecting behaving of P2P traffic. We have evaluated using the proposed methodology for an encrypted P2P traffic. In addition, by measurement in the wide-area networks using planetlab, we have discussed the limitation of the proposed methodology.
1. ͡ Ί ʹ
1.1 എ ܠ ۙɼWinnyͳͲͷP2PϑΝΠϧڞ༗ΞϓϦέʔ γϣϯͰใྲྀग़ஶ࡞ݖ৵ͳͲͷ͕ൃੜ͠ ͍ͯΔɽ·ͨɼ͜ͷ΄͔ͷͱͯ͠P2PϑΝΠϧ ڞ༗ΞϓϦέʔγϣϯʹΑͬͯಈըԻָͳͲڊେͳ αΠζͷϑΝΠϧަ͕ߦΘΕΔͨΊɼωοτϫʔΫ τϥώοΫ͕େ෯ʹ૿େ͓ͯ͠ΓɼΠϯϑϥͷଟେ † ๛ڮٕज़ՊֶେֶใֶܥInformation and Computer Science, Toyohashi Univer-sity of Technology
†† େࡕେֶαΠόʔϝσΟΞηϯλʔ
Cybermedia Center, Osaka University
††† ๛ڮٕज़ՊֶେֶใϝσΟΞج൫ηϯλʔ
Information and Media Center, Toyohashi University of Technolog ͳෛ୲ͱͳ͍ͬͯΔ5)ɽ͜ͷͨΊɼP2PϑΝΠϧڞ༗ ΞϓϦέʔγϣϯͷτϥώοΫΛಛఆ͠ɼ্هͷ Λࢭ͢Δ͜ͱ͕ظ͞Ε͍ͯΔɽ ɹ͜ΕΛ͏͚ͯP2PϑΝΠϧڞ༗ΞϓϦέʔγϣϯΛ ಛఆ͢ΔͨΊʹ͍͔ͭ͘ͷݚڀ͕ͳ͞Ε͍ͯΔɽྫ͑ ύέοτͷϖΠϩʔυΛղੳ͢Δ͜ͱʹΑͬͯP2P ϑΝΠϧڞ༗ΞϓϦέʔγϣϯΛಛఆ͢ΔOne Point Wall3)͕͋Δɽ͜ΕϖΠϩʔυ෦ʹؚ·ΕΔP2P ϑΝΠϧڞ༗ΞϓϦέʔγϣϯಛ༗ͷϏοτύλʔϯ Λݕग़͢Δํ๏Ͱ͋Δɽ͜ͷ΄͔ʹτϥϯεϙʔ τͷϔομใ͔ΒಘΒΕΔใΛར༻ͯ͠ɼP2P ϑΝΠϧڞ༗ΞϓϦέʔγϣϯͷτϥώοΫύλʔϯ Λหผ͢Δํ๏͋Δ4)ɽ͔͠͠ɼ͜ΕΒͷղੳख๏ ͰτϥϯεϙʔτͰͷ҉߸Խ͕ࢪ͞Εͯ͠·ͬͨ ߹ɼղੳ͢ΔͨΊͷใ͕ಡΈऔΕͳ͘ͳͬͯ͠· ͏ɽͦͷͨΊɼ্هͰڍ͛ͨหผख๏Ͱ҉߸Խ௨৴
ͱ͍͏݅ԼͰP2PτϥώοΫΛਖ਼͘͠หผ͢Δ ͜ͱ͕Ͱ͖ͳ͍ͱ͍ͬͨՄೳੑੜ͡Δɽ 1.2 ຊݚڀͷత લઅͰड़ͨΑ͏ʹطଘͷղੳख๏Ͱ҉߸Խ͞Ε ͨ௨৴͔ΒP2PτϥώοΫΛหผ͢Δ͜ͱ͕͍͠ ͜ͱ͕Θ͔Δɽͦ͜ͰɼզʑP2PϑΝΠϧڞ༗Ξϓ Ϧέʔγϣϯͷํ௨৴ʹணͯ͠P2PτϥώοΫ ղੳΛߦ͏ɽ͜ͷख๏௨৴͕҉߸Խ͞Ε͍ͯͳ͍ ݅Ͱͷղੳख๏2)͕ఏҊ͞Ε͍ͯΔɽຊߘͰ͜ͷख ๏Λ֦ு͠ɼτϥϯεϙʔτͰͷ҉߸Խ͕ࢪ͞Εͨ ݅ԼͰP2PτϥώοΫΛหผͰ͖Δख๏ΛఏҊ ͢Δɽͳ͓ɼ͜ͷख๏1)Λͱʹ͓ͯ͠Γɼ࣮σʔ λͷଌఆΛͱʹվྑͨ͠ͷͰ͋Δɽ 1.3 ຊߘͷߏ ຊߘશ5ষͰߏ͞ΕΔɽ ɹୈ1ষͰɼຊݚڀͷഎܠͱతʹ͍ͭͯड़ͨɽ ɹୈ2ষͰɼຊݚڀͷϕʔεͱͳΔP2Pτϥώο Ϋหผख๏ͱɼຊݚڀͰఏҊ͢ΔP2PτϥώοΫห ผख๏ʹ͍ͭͯड़Δɽ ɹୈ3ষͰɼ҉߸ԽΛࢪͨ͠௨৴ʹରͯ͠ຊݚڀͷ ख๏Λ༻͍ͨ߹ʹݒ೦͞ΕΔʹ͍ͭͯड़Δɽ ͦͯ͠ɼ͜ΕΒͷʹର͢ΔղܾࡦΛࣔ͢ɽ ɹୈ4ষͰɼ༷ʑͳτϥώοΫʹରͯ͠ຊݚڀͷख ๏Λద༻ͨ݁͠ՌΛࣔ͢ɽ͜ΕʹΑΓɼຊݚڀͷख๏ ͕༗ޮͰ͋Δ͔Ͳ͏͔Λݕ౼͢Δɽ ɹୈ5ষͰɼຊݚڀͷ݁Λड़Δɽ
2. ํ௨৴ʹணͨ͠ P2P τϥώοΫห
ผख๏
2.1 ϕʔεݚڀʹ͍ͭͯ ௨ৗͷαʔόͱΫϥΠΞϯτؒͷ௨৴ͰɼΫϥΠ Ξϯτଆ͔Βαʔόଆ௨৴࿏ͷཱ֬Λߦ͏ɽ͜ͷΑ ͏ͳ௨৴ϞσϧΫϥΠΞϯταʔόϞσϧͱݺΕ Δɽ͔͠͠ɼҰ෦ͷϐϡΞP2Pͷ௨৴ͰΫϥΠΞϯ τಉ࢜Ͱํʹ௨৴࿏Λཱ֬͢Δඞཁ͕͋ΔͨΊɼ ֤ϊʔυؒͰ͖ͷҟͳΔೋຊͷ௨৴࿏͕ଘࡏ͢Δ͜ ͱʹͳΔɽ·ͨP2P௨৴Ͱ֤ϊʔυ͕ࣗ༝ʹࢀՃɼ Ͱ͖ΔͨΊɼසൟʹϊʔυؒͰ௨৴࿏Λཱ֬͢Δ ඞཁ͕͋Δɽ͜ͷΑ͏ͳ௨৴ϞσϧϐϡΞP2PϞ σϧͱݺΕΔɽ͜ͷΑ͏ʹසൟʹํʹ௨৴࿏Λ ཱ֬͢ΔΑ͏ͳ௨৴αʔόͱΫϥΠΞϯτʹΑΔ௨ ৴ͰଘࡏͤͣɼϐϡΞP2PͰͷ௨৴Ҏ֎ʹ͋· Γଘࡏ͠ͳ͍ɽͦ͜Ͱ͜ͷํ௨৴ʹண͢Δ͜ͱ ͰɼΫϥΠΞϯταʔόϞσϧͱϐϡΞP2PϞσϧ Λ۠ผͯ͠P2PτϥώοΫͷหผΛߦ͏ɽ ͔͠͠ɼ ͜ͷϕʔεݚڀͰTCPͷϔομใΛ༻͍ͯ௨৴ ࿏ͷཱ֬Λผ͍ͯ͠ΔͨΊɼ௨৴͕҉߸Խ͞Εͯ͠ ·ͬͨ߹ʹP2PτϥώοΫΛหผ͢Δ͜ͱ͕Ͱ ͖ͳ͍ͱ͍͏͕͋Δɽ 2.2 ҉߸Խ௨৴͓͚ΔP2PτϥώοΫหผͷఏ Ҋख๏ ௨৴࿏ͷཱ֬Λߦ͏ͨΊʹωΰγΤʔγϣϯΛߦ͏ɽ ͜ͷωΰγΤʔγϣϯͷखॱεϦʔΣΠϋϯυγΣ ΠΫͱݺΕΔɽεϦʔΣΠϋϯυγΣΠΫσʔ λ௨৴ʹઌཱͬͯSYNύέοτɼSYN/ACKύέο τɼACKύέοτͷॱʹ3ճͷ௨৴Λߦ͏ɽ͜ΕΒ ͷύέοτͷૹड৴ޙʹ௨৴࿏ཱ͕֬͞ΕΔɽ ɹ ϕ ʔ ε ݚ ڀ ͷ ख ๏ Ͱ ͜ ͷ SYN ύ έοτ SYN/ACKύέοτΛTCPͷϔομใΛݟΔ͜ ͱͰ֬ೝ͍ͯͨ͠ɽ͔͠͠ɼ҉߸Խ͞Εͨ௨৴Ͱ TCPͷϔομใ͕Θ͔Βͳ͍ͨΊɼ ϕʔεݚڀͷ Α͏ʹSYNύέοτSYN/ACKύέοτΛ֬ೝ ͢Δ͜ͱͰ͖ͳ͍ɽͦ͜ͰຊߘͰɼࣄલʹௐࠪ͠ ͨSYNύέοτͱSYN/ACKύέοτͷִ࣌ؒؒ Ћͱɼ૬ޓʹεϦʔΣΠϋϯυγΣΠΫ͕ߦΘΕΔ ִ࣌ؒؒЌɼͦΕͱSYNύέοτͱSYN/ACKύ έοτͷύέοτΛͱʹP2PτϥώοΫΛหผ ͢Δɽ͜ΕΒͷִ࣌ؒؒΛਤ1ʹࣔ͢ɽ ɹҎ্ͷಛྔΛ༻͍ͯP2PτϥώοΫΛหผ͢Δɽ ·ͣεϦʔΣΠϋϯυγΣΠΫͷఆ݅SYN ύέοτͱSYN/ACKύέοτͷύέοτ͕ڞʹ 62byteͰ͋Δ͜ͱ͔Βɼ62byteͷύέοτ͕ૹ৴͞ Ε͔ͯΒִ࣌ؒؒЋͷؒʹ62byteͷύέοτ͕ฦ৴ ͞Εͨ߹ʹεϦʔΣΠϋϯυγΣΠΫͰ͋Δͱ ఆ͢Δɽͦͷޙɼִ࣌ؒؒЌҎʹରଆͷϗετ͔ Β࠶্هͷఆํ๏ͰεϦʔΣΠϋϯυγΣΠΫ Λߦ͍ͬͯΔ͜ͱ͕ఆ͞ΕΕɼP2P௨৴Ͱ͋Δͱ ఆ͢Δɽ ɹ͜ΕʹΑΓɼͨͱ͑҉߸ԽʹΑͬͯTCPͷϔομ ใΛಡΈऔΔ͜ͱ͕Ͱ͖ͳ͘ͱɼύέοτͱ࣌ ִؒؒЋɼЌΛ༻͍Δ͜ͱͰεϦʔΣΠϋϯυγΣ ΠΫΛผͰ͖ΔͨΊɼP2PτϥώοΫΛหผ͢Δ ͜ͱ͕Ͱ͖Δͱߟ͑ΒΕΔɽ·ͨɼִ࣌ؒؒЋɼЌ P2PΞϓϦέʔγϣϯͷ௨৴ΛΩϟϓνϟͨ͠τϥ ώοΫΛͱʹܾͯ͠ΊΔ(۩ମతʹޙड़͢Δ)3. ҉߸Խ௨৴ʹ͍ͭͯ
3.1 ҉߸Խʹ͍ͭͯ ຊߘͰ௨৴ͷ҉߸Խʹ༻͢Δ҉߸Խϓϩτίϧ ͱͯ͠IPsec6)Λఆ͢ΔɽIPsecෳͷ҉߸Խํ ࣜΛ࠾༻͢Δ͜ͱ͕Ͱ͖ΔͷͰɼ௨৴૬खͱͷؒͰ௨ਤ 1 P2P τϥώοΫͷಛྔ ৴ͷઃఆΛ߹ΘͤΔͨΊʹύϥϝʔλΛڞ༗͢Δඞ ཁ͕͋Δɽ͜ͷͱ͖௨৴૬खͱڞ༗͢ΔύϥϝʔλΛ SAͱݺͿɽSAʹ༷ʑͳύϥϝʔλ͕͋Δ͕ɼॏ ཁͳύϥϝʔλͱͳΔͷ͕ηΩϡϦςΟϓϩτίϧͱ ϞʔυͰ͋ΔɽηΩϡϦςΟϓϩτίϧʹESPͱ AH͕͋Δ7)ɽESPύέοτͷ҉߸ԽػೳΛఏڙ͠ɼ AHൃ৴ݩͷೝূɼશੑೝূΛఏڙ͢ΔɽϞʔυ ʹτϥϯεϙʔτϞʔυͱτϯωϧϞʔυͷ2͕ͭ ͋ΔɽτϥϯεϙʔτϞʔυϖΠϩʔυ͚ͩΛɼτ ϯωϧϞʔυIPύέοτશମΛΧϓηϧԽ͢Δɽ ɹຊߘͰηΩϡϦςΟϓϩτίϧʹESPɼϞʔυʹ τϥϯεϙʔτϞʔυΛબͯٞ͠ΛਐΊΔɽηΩϡ ϦςΟϓϩτίϧΛESPͱͨ͠ཧ༝ͱͯ͠ɼAHͰ ௨৴ͷ҉߸Խ͕Ͱ͖ͣೝূ͔͠ఏڙ͞Ε͍ͯͳ͍ͨ ΊͰ͋Δɽ·ͨɼτϥϯεϙʔτϞʔυΛબͨ͠ཧ ༝ɼࠓճIPϔομ·Ͱ҉߸Խ͢ΔΘ͚Ͱͳ͘ɼ TCPϔομ·Ͱ҉߸Խ͢Δ͜ͱΛఆ͍ͯ͠ΔͨΊ Ͱ͋Δɽͳ͓ɼτϥϯεϙʔτϞʔυΛબ͔ͨ͠Β ͱ͍ͬͯɼύέοτ͕͍ύέοτ͘ɼ͍ύ έοτ͍͜ͱʹมΘΓͳ͍ɽ͞ΒʹIPϔομ ͕҉߸Խ͞Εͨ߹ͰɼPoint-to-PointͰP2PϑΝ Πϧڞ༗ΞϓϦέʔγϣϯ͕௨৴Λߦ͍ͬͯΔ͜ͱ ผͰ͖Δɽ͜ͷͨΊɼτϥϯεϙʔτϞʔυΛબ ͔ͨ͠Βͱ͍ͬͯɼҰൠੑ͕ࣦΘΕΔ͜ͱͳ͍ɽ 3.2 ௨৴ͷ҉߸ԽʹΑΔͱରࡦ 3.2.1 ύέοτͷมߋʹΑΔӨڹ IPsecʹΑͬͯ҉߸ԽΛߦ͏߹ɼύέοτʹର͠ ͯ҉߸ԽͷͨΊͷσʔλ͕Ճ͞ΕΔɽͦͷͨΊɼτ ϥώοΫหผͰඞཁͳಛྔͰ͋Δύέοτ͕มԽ ͯ͠͠·͏ͱ͍͕ͬͨ͋Δɽ ɹͦ͜ͰɼWindows XPͰར༻Ͱ͖ΔIPsecʹΑͬ ͯ҉߸Խ͞Εͨ௨৴ΛΩϟϓνϟͯ͠ɼ҉߸Խ͞Εͯ ͍ͳ͍௨৴ͱ҉߸Խ͞Εͨ௨৴Λൺֱͯ͠ύέοτ ਤ 2 3 ΣΠϋϯυγΣΠΫͷִ࣌ؒؒͷൺֱ ͷ૿ՃΛௐͨɽ݁Ռͱͯ͠ɼͯ͢ͷύέοτ͕ 32byteͣͭ૿Ճ͍ͯ͠Δ͜ͱ͕Θ͔ͬͨɽ͜Ε͕ଞ ͷڥͰ͋ͬͨͱͯ͠ɼύέοτͷ૿Ճϓϩτ ίϧʹґଘ͢ΔͨΊʹͦΕ΄ͲมԽͳ͍ɽ͜ΕʹΑ Γɼ҉߸Խ͞Εͨ௨৴ʹରͯ͠ຊߘͷख๏Λ༻͍Δʹ ɼಛྔͱͯ͠༻͍ΔύέοτΛ32byte૿Ճ͞ ͤΕ͍͍͜ͱ͕Θ͔ͬͨɽ 3.2.2 ҉߸ԽॲཧʹΑΔԆͷӨڹ ҉߸Խ௨৴Λߦ͏ࡍʹ҉߸Խ෮߸Խॲཧ͕ඞ ཁͱͳΔɽ͜ͷॲཧʹΑͬͯϥϯυτϦοϓλΠ ϜʢRTTʣ͕૿Ճ͢Δ͜ͱ͕ఆ͞ΕΔɽRTT ͕ ૿Ճͯ͠͠·ͬͨ߹ɼSYNύέοτΛૹ͔ͬͯΒ SYN/ACKύέοτ͕ฦͬͯ͘Δִ͕࣌ؒؒ͘ͳ ΓɼτϥώοΫͷหผʹରͯ͠Өڹ͕ͰΔՄೳੑ͕͋ Δɽ ɹલઅͱಉ༷ʹWindows XPΛར༻ͨ͠IPsecʹΑͬ ͯ҉߸Խ͞ΕͨτϥώοΫͱ҉߸Խ͞Ε͍ͯͳ͍τϥ ώοΫ͔ΒͦΕͧΕ1000݅ͷεϦʔΣΠϋϯυγΣ ΠΫΛநग़͠ɼͦΕͧΕͷִ࣌ؒؒͱൺֱͨ͠ɽ݁Ռ Λਤ2ʹࣔ͢ɽਤ2͔Β҉߸ॲཧʹΑΔฏۉͷԆ࣌ ؒ0.001ඵͰ͋Δ͜ͱ͕Θ͔ͬͨ
4. ධ Ձ ࣮ ݧ
4.1 ҉߸Խ௨৴ʹର͢Δหผख๏ͷධՁ࣮ݧ ຊઅͰɼΑ͘ΒΕͨϐϡΞP2PϑΝΠϧڞ༗Ξ ϓϦέʔγϣϯͰ͋ΔWinny8)Λ༻͍࣮ͯݧΛߦ͏ɽ ࣮ݧͰIPsecʹΑͬͯ҉߸Խ͞Εͨ௨৴Λ༻͍ͯຊ ߘͷหผख๏͕҉߸Խ௨৴ʹରͯ͠༗ޮੑ͕͋Δ͔Ͳ ͏͔ݕ౼͢Δɽ·ͨɼ҉߸ԽϓϩτίϧʹWindows XPͰར༻͢Δ͜ͱ͕Ͱ͖ΔIPsecΛ༻͍Δɽɹ࣮ݧʹɼWinnyʹΑΔ௨৴ͷΈΛΩϟϓνϟͨ͠ ̎छྨͷτϥώοΫͱɼWinnyʹΑΔ௨৴ύέοτΛ ؚ·ͳ͍̍छྨͷτϥώοΫΛ༻͍ΔɽWinnyͷΈ ͷ௨৴ΛΩϟϓνϟͨ͠τϥώοΫɼ ௨৴͕҉߸Խ ͞ΕͨτϥώοΫʢIPsecτϥώοΫʣͱɼ௨৴͕҉ ߸Խ͞Ε͍ͯͳ͍τϥώοΫʢnonIPsecτϥώοΫʣ ͕͋Δɽ·ͨɼWinnyʹΑΔ௨৴ύέοτΛؚ·ͳ ͍௨৴τϥώοΫʢnonP2PτϥώοΫʣɼ҉߸Խ ͞Ε͍ͯͳ͍௨৴ΛΩϟϓνϟͨ͠ͷͰ͋Δɽ͜Ε ΒͷτϥώοΫͷҰཡΛද1ʹࣔ͢ɽ ɹલड़ͷ֤τϥώοΫʹରͯ͠หผख๏Λద༻͢Δ͜ ͱͰɼหผख๏ͷ༗ޮੑΛݕ౼͢Δɽ࣮ݧͷྲྀΕΛҎ Լʹࣔ͢ɽ ( 1 ) WinnyͷΈͷ௨৴τϥώοΫΛޙड़͢Δ࣮ݧ ڥ͔Βऔಘ͢ΔɽWinnyύέοτΛؚ·ͳ͍τϥώο ΫݚڀࣨͷτϥώοΫ͔Βऔಘ͢Δɽ֤τϥώοΫ ͷଌఆ࣌ؒͦΕͧΕ3࣌ؒͱͨ͠ ( 2 ) P2PτϥώοΫ͔ΒಛྔЋɼЌΛܾఆͨ͠ɽ ۩ମతͳ༰ޙड़͢Δ ( 3 ) ಛྔЋɼЌΛ༻͍ͯτϥώοΫͷఆ݅Λ ઃఆͨ͠ɽ͜ͷ݅ʹैͬͯͦΕͧΕͷτϥώοΫʹ ରͯ͠หผख๏Λ༻͍ͨ݁Ռ͔Βหผख๏ΛධՁ͢Δ 4.1.1 P2PτϥώοΫऩूͷͨΊͷ࣮ݧڥ ࣮ݧڥʹϗετOSͱͯ͠Linux(Ubuntu9.04) ΛΠϯετʔϧͨ͠5ͷϚγϯΛ༻ҙͨ͠ɽ͜ͷ͏ ͪ4ͷϗετϚγϯʹԾڥͱͯ͠VMware ServerΛಋೖ͠ɼΓҰΛύέοτΩϟϓνϟͷͨ ΊͷϚγϯͱͨ͠ɽVMware ServerΛಋೖͨ͠4 ͷϗετϚγϯ্ͰɼͦΕͧΕ2ͣͭͷԾϚγϯ Λಈ࡞ͤ͞ɼ͜ͷԾϚγϯ্ͰWinnyΛಈ࡞ͤ͞ Δ͜ͱʹΑͬͯWinnyʹΑΔ௨৴ͷΈΛΩϟϓνϟ ͨ͠τϥώοΫΛऔಘͨ͠ɽ্هͷߏΛਤ3ʹࣔ͢ɽ 4.1.2 ಛྔͰ͋Δִ࣌ؒؒЋͷܾఆ ࣮ݧڥ͔Βऔಘͨ͠P2PτϥώοΫ͔Β150݅ ͷεϦʔΣΠϋϯυγΣΠΫΛநग़ͯ͠ɼSYNύ έοτͱSYN/ACKύέοτͷ௨৴ִؒΛܭଌͨ͠ɽ ܭଌ݁ՌΛਤ4ʹࣔ͢ɽਤ4͔ΒSYNύέοτͱ SYN/ACKύέοτͷִ࣌ؒؒ࠷Ͱ0.0418ඵͰ ͋ͬͨɽ͜Ε͔Βִ࣌ؒؒЋΛЋ=0.042ͱͨ͠ɽ͜ ͷΑ͏ʹઃఆͨ͠ཧ༝ɼεϦʔΣΠϋϯυγΣΠ ΫΛݟಀ͞ͳ͍Α͏ʹ͢ΔͨΊͰ͋Δɽ·ͨЋΛ͘ ઃఆͨ͠ͱִͯ࣌ؒؒ͠ЌʹΑͬͯP2Pτϥώο ද 1 τϥώοΫҰཡ ਤ 3 ࣮ݧڥͷߏ ਤ 4 ִ࣌ؒؒЋͷଌఆ Ϋࣗମͷޡݕग़͙͜ͱ͕Ͱ͖Δ 4.1.3 ಛྔͰ͋Δִ࣌ؒؒЌͷܾఆ ૬ޓʹεϦʔΣΠϋϯυγΣΠΫΛߦ͏ִ࣌ؒؒ ЌΛܭଌ͢Δɽ࣮ݧڥͰಘͨP2PτϥώοΫ͔Β ૬ޓʹεϦʔΣΠϋϯυγΣΠΫΛߦ͏ࡍͷ࣌ؒؒ ִΛ320݅؍ଌͨ͠ɽ؍ଌ݁Ռ͕ਤ5Ͱ͋Δɽਤ5͔ Β૬ޓʹεϦʔΣΠϋϯυγΣΠΫΛߦ͏ִ࣌ؒؒ ࠷Ͱ0.307ඵͰ͋ͬͨɽЋͰ࠷ΑΓ͍࣌ؒ ͱ͕ͨ͠ɼЌ͜ͷΑ͏ʹ͢Δ͜ͱదͰͳ͍ɽ ִ࣌ؒؒЌΛେ͖ͳʹઃఆ͢Δ߹ɼޡݕग़͕େ͖ ͘ͳΔՄೳੑ͕͋ΔɽͦͷͨΊɼROCΧʔϒΛ࡞ ͢Δ͜ͱͰ࠷దͳಛྔЌΛಛఆͨ͠ɽύέοτΛ 62byteɼಛྔЋΛ0.042ͱ͠ɼಛྔЌΛ0.01ؒ ִͰ0ඵ͔Β0.25ඵมԽͤͨ͞ͱ͖ͷnonIPsecτ ϥώοΫͷݕग़Λy࣠ɼnonP2PτϥώοΫͷݕग़ Λx࣠ͱͯ͠ϓϩοτͨ͠ਤΛਤ6ʹࣔ͢ɽਤ6͔
ਤ 5 ִ࣌ؒؒЌͷଌఆ ਤ 6 ִ࣌ؒؒЌͷ ROC Χʔϒ Βݕग़ͷߴ͘ɼޡݕग़ͷগͳ͍ͱ͖ͷЌͷύϥϝʔ λ0.048Ͱ͋ͬͨ 4.1.4 ҉߸Խ͞Εͨ௨৴ʹର͢Δหผ݁Ռ औ ಘ ͠ ͨ τ ϥ ώοΫ ͔ Β ห ผ ख ๏ Λ ධ Ձ ͢ Δ ɽ nonP2PτϥώοΫͱnonIPsecτϥώοΫʹରͯ͠ ͷಛྔΛЋ=0.042ɼЌ=0.048ɼύέοτ=62ͱ ͨ͠ɽ·ͨɼIPsecτϥώοΫʹରͯ͠ͷಛྔЋɼЌ 3ɽ2ষͷ͔݁ΒԆ࣌ؒΛߟྀͯ͠ЋΛ0.001ඵ ૿Ճͤ͞ɼЌΛ0.003ඵ૿Ճͤͨ͞ɽЌΛ0.003ඵ૿Ճ ͤͨ͞ཧ༝ͱͯ͠1ճͷεϦʔΣΠϋϯυγΣΠ Ϋ͔Β2ճͷεϦʔΣΠϋϯυγΣΠΫ͕ߦΘΕ Δ·ͰʹACKύέοτɼSYNύέοτɼSYN/ACK
ύέοτ͕ૹ৴͞ΕΔͨΊͰ͋Δɽ͜ͷͨΊIPsecτ ϥώοΫʹରͯ͠ͷಛྔЋ=0.043ɼЌ=0.051ɼύ έοτ=94ͱͨ͠ɽ֤τϥώοΫͷหผ݁ՌΛද2 ʹࣔ͢ɽ ɹIPsecτϥώοΫ௨৴͕҉߸Խ͞Εͯ͠·͍ͬͯ ΔͨΊɼεϦʔΣΠϋϯυγΣΠΫ͕ߦΘΕͨճ Λਖ਼֬ʹѲ͢Δ͜ͱ͕Ͱ͖ͳ͍͕ɼҎԼͷΑ͏ʹ ߟ͑ͯॲཧͨ͠ɽIPsecτϥώοΫͱnonIPsecτϥ ώοΫಉ༷ͷڥͰಉ༷ͷ͚࣌ؒͩΩϟϓνϟͨ͠ τϥώοΫͰ͋ΔͨΊɼWinny͕௨৴Λߦͬͨճ ಉఔʹͳΔͱߟ͑ͨɽ͜ΕΛ౿·͑ͯIPsecτ ϥώοΫͱnonIPsecτϥώοΫͷ݁ՌΛൺֱ͢Δͱɼ nonIPsecτϥώοΫͷݕग़ʹൺͯIPsecτϥώο Ϋͷݕग़1/4·ͰԼ͕ͬͯ͠·͍ͬͯΔɽͨͩɼ nonP2PτϥώοΫͷ݁Ռ͔ΒΘ͔ΔΑ͏ʹϑΥʔϧ εϙδςΟϒϨʔτʢFPRʣ0.5064%ͱ͍ͷͰɼ IPsecτϥώοΫͷݕग़͕গͳ͘ͳͬͨͱͯ͠ɼ Winny௨৴Λߦ͍ͬͯΔτϥώοΫΛൃݟ͢Δ͜ͱ ͕Ͱ͖Δͱߟ͑ΒΕΔɽ ද 2 ֤τϥώοΫͷหผख๏ͷద༻ 4.2 Ԇ࣌ؒΛߟྀͨ͠หผख๏ͷධՁ ্هͷ࣮ݧͰϩʔΧϧڥʹ͓͚ΔఏҊख๏ͷධ ՁΛߦͬͨɽϧʔςΟϯά͕҆ఆ͍ͯ͠ΔڥͰຊํ ࣜ༗ޮͱߟ͑ΒΕΔ͕ɼϧʔςΟϯά͕ෳࡶͳΠϯ λʔωοτͳͲͷڥͰɼϩʔΧϧڥͷΑ͏ʹ҆ ఆͰ͍Ԇ࣌ؒͱͳΒͳ͍͜ͱ͕༧͞ΕΔɽͦ ͷͨΊɼΠϯλʔωοτͷςετϕουͰ͋Δ Plan-etlabΛར༻ͯ͠Πϯλʔωοτʹ͍ۙڥͰͷωο τϫʔΫԆΛௐΔ͜ͱͰຊߘͷఏҊ͢Δํ๏ͷద ༻ͷݶքΛݕ౼͢Δɽ 4.3 Planetlab্ͰͷωοτϫʔΫԆͷӨڹ ࣮ݧڥͱPlanetlab্ͰͦΕͧΕ100݅ͷεϦʔ ΣΠϋϯυγΣΠΫͷԆ࣌ؒΛ؍ଌͨ͠ɽ Plan-etlabͰ༻ͨ͠ϊʔυpl2ɽPlanetlab.ics.tut.ac.jp (133.15.59.2)ͱɼplanetlab-02.naist.jp (163.221.11.72) Ͱ͋ΔɽͦΕͧΕͷڥͰ؍ଌͨ͠Ԇ࣌ؒͷฏۉͱ ࢄΛද3ʹࣔ͢ɽද3͔Β࣮ݧڥͱPlanetlab ͷԆ࣌ؒͷฏۉΛൺֱ͢Δͱɼ࣮ݧڥʹൺͯɼ PlanetlabͷԆ࣌ؒͷฏۉ͕େมେ͖͍͜ͱ͕Θ͔ Δɽ·ͨࢄʹ࣮ؔͯ͠ݧڥ͕҆ఆ͍ͯ͠Δ͜ͱ ʹൺͯɼPlanetlabͷ؍ଌσʔλʹΒ͖͕ͭ͋ Δ͜ͱ͕Θ͔Δɽ͜͜ͰɼͦΕͧΕͷ؍ଌ݁ՌΛϓϩο τͨ͠ͷΛਤ7ʹࣔ͢ɽ͜ͷσʔλ͔ΒΘ͔ΔΑ͏ ʹɼฏۉ͔Βʶ0.02ͷൣғͰ࣮ݧڥ90%ͷ
ਤ 7 Planetlab ͱ࣮ݧڥ্ͰͷωοτϫʔΫԆͷ؍ଌ݁Ռ ؍ଌσʔλ͕ू·͍ͬͯΔ͜ͱʹର͠ɼPlanetlabͰ 30%΄Ͳͷ؍ଌσʔλ͔͠ͳ͍͜ͱ͕Θ͔Δɽ͞Β ʹɼ߹ʹΑͬͯେ͖ͳԆ͕ൃੜ͢ΔɽͦͷͨΊ ҬωοτϫʔΫʹରִ͚ͯ࣌ؒؒͩ͠Ͱใ͕ෆ ͍ͯ͠Δ͜ͱ͕Θ͔ͬͨ
5. ݁
ຊߘͰ௨৴͕҉߸Խ͞ΕͨP2PτϥώοΫΛห ผ͢Δख๏Λઆ໌͠ɼͦͷख๏ͷ༗ޮੑΛௐࠪͨ͠ɽ IPsecʹΑͬͯ҉߸Խ͞Εͨ௨৴τϥώοΫʹରͯ͠ 2.2ষͰड़ͨหผख๏Λద༻ͨ͠ɽP2PʹΑΔ௨৴ Λؚ·ͳ͍τϥώοΫʹΑͬͯޡݕग़Λௐͨ݁Ռɼ ϑΥʔϧεϙδςΟϒϨʔτ͕0.5064%ͱେม͔ͬ ͨɽ௨৴͕҉߸Խ͞Εͨ߹Ͱɼ௨৴͕҉߸Խ͞Ε ͍ͯͳ͍߹ʹൺͯP2PΞϓϦέʔγϣϯʹΑͬͯ ཱ֬͞ΕͨίωΫγϣϯͷݕग़͕1/4·ͰԼ͕ͬ ͕ͨɼ௨৴͕҉߸Խ͞Εͨঢ়ଶͰɼϩʔΧϧωοτ ͷڥͳΒຊख๏P2PτϥώοΫΛݕग़͢Δख ๏ͱͯ͠ଥͰ͋ΔͱΘ͔ͬͨɽ ɹ͞ΒʹɼPlanetlabΛ༻͍ͯΠϯλʔωοτʹ͍ۙ ڥͰͷԆ࣌ؒΛௐΔ͜ͱͰɼఏҊख๏͕ద༻Ͱ ͖ΔൣғΛௐࠪͨ͠ɽ݁Ռͱ࣮ͯ͠ݧڥͰͷԆ࣌ ؒͷฏۉʹൺͯPlanetlab্ͰͷԆ࣌ؒͷฏۉ ͕େ͖͍͜ͱ͕Θ͔ͬͨɽ͞ΒʹɼPlanetlabͰ ࣮ݧڥʹൺͯ؍ଌσʔλʹΒ͖ͭ͋Δ͜ͱ͕ ද 3 Ԇ࣌ؒͷฏۉͱࢄ Θ͔ͬͨɽҎ্ͷ݁Ռ͔Βɼฏۉ͔ΒͣΕͨσʔ λ͕ଟ͘ͳΔҬωοτϫʔΫʹ͓͍ͯɼຊߘͷఏ Ҋख๏Λͦͷ··༻͢Δ͜ͱʹ͕͋Δ͜ͱ͕ ໌ͨ͠ɽࢀ
ߟ
จ
ݙ
1) ࡾӜ໌߳ɼകଜګ࢘ɼѨ෦༸ৎɼԬ෦ਖ਼: SYN ύέοτͷݺԠʹணͨ͠P2PτϥώοΫͷදࣔɼ ใॲཧֶձશࠃେձߨԋจूɼpp.239-240 (2009) 2) দాᜁɼ தଜจོɼ एݪګɼ ాதྑ໌:૬ޓ ଓʹ͓͚ΔॱٯଓִؒΛར༻ͨ͠P2Pτϥ ώοΫผख๏ɼ ৴ֶٕใɼNo.NS2006-237ɼ pp.415-420 (2007)3) ”One Point Wall” http://www.onepointwall.jp/ 4) দాᜁɼ தଜจོɼ एݪګɼ ాதྑ໌ɼ େ ࡚३ɼ ઍాߒҰɼ Ճ౻ܓɼ ൧௩ਖ਼: PureP2P ϑΝΠϧڞ༗τϥώοΫͷಛੑղੳɼ ৴ֶٕใɼ No.NS2005-2ɼpp.5-8 (2005) 5) ُҪ૱: P2Pٕज़͕ωοτϫʔΫΠϯϑϥʹٴ ΅͢Өڹͱ՝ɼ ίϯϐϡʔλιϑτΣΞɼ Vol.22ɼNo.3ɼpp.8-18ɼ ຊιϑτΣΞՊ ֶձ, (2005)
6) ”Security Architecture for the Internet Proto-col”, RFC 4301, IETF
7) ”Cryptographic Algorithm Implementation Requirements for Encapsulating Security Pay-load (ESP) and Authentication Header (AH)”, RFC 4305, IETF