Boitsebiso ba Kopo ea Packet Broker e Thehiloe ho DPI - Tlhahlobo e tebileng ea Pakete

Tekolo ea Pakete e Tebileng (DPI)ke theknoloji e sebelisoang ho Network Packet Brokers (NPBs) ho hlahloba le ho hlahloba likahare tsa lipakete tsa marang-rang ka tekanyo ea granular. E kenyelletsa ho hlahloba moputso, lihlooho, le lintlha tse ling tse khethehileng tsa protocol ka har'a lipakete ho fumana lintlha tse qaqileng mabapi le sephethephethe sa marang-rang.

DPI e fetela ka nģ'ane ho tlhahlobo e bonolo ea lihlooho 'me e fana ka kutloisiso e tebileng ea data e phallang ka marang-rang. E lumella tlhahlobo e tebileng ea liprothokholo tsa lera la kopo, joalo ka HTTP, FTP, SMTP, VoIP, kapa liprothokholo tsa ho phallela video. Ka ho hlahloba litaba tsa 'nete ka har'a lipakete, DPI e khona ho bona le ho tseba lits'ebetso tse ikhethileng, liprothokholo, kapa esita le mekhoa e itseng ea data.

Ntle le tlhahlobo ea maemo a holimo ea liaterese tsa mohloli, liaterese tsa moo ho eang teng, likou tsa mehloli, likou tsa libaka, le mefuta ea protocol, DPI e boetse e eketsa tlhahlobo ea lera la kopo ho tseba lits'ebetso tse fapaneng le litaba tsa tsona. Ha pakete ea 1P, TCP kapa UDP e phalla ka har'a tsamaiso ea bandwidth e thehiloeng ho thekenoloji ea DPI, tsamaiso e bala litaba tsa mojaro oa pakete ea 1P ho hlophisa bocha boitsebiso ba lera la kopo ho protocol ea OSI Layer 7, e le ho fumana litaba tsa lenaneo lohle la kopo, ebe o bōpa sephethephethe ho ea ka leano la tsamaiso le hlalositsoeng ke tsamaiso.

DPI e sebetsa joang?

Li-firewall tsa setso hangata ha li na matla a ho sebetsa ho etsa licheke tsa nako ea nnete ho bongata bo boholo ba sephethephethe. Ha theknoloji e ntse e tsoela pele, DPI e ka sebelisoa ho etsa licheke tse rarahaneng ho lekola lihlooho le data. Ka tloaelo, li-firewall tse nang le lisebelisoa tsa ho lemoha ho kenella hangata li sebelisa DPI. Lefatšeng leo tlhahisoleseling ea dijithale e leng Paramount, karolo e 'ngoe le e 'ngoe ea tlhaiso-leseling ea dijithale e romelloa inthaneteng ka lipakete tse nyane. Sena se kenyelletsa lengolo-tsoibila, melaetsa e rometsoeng ka sesebelisoa, liwebsaete tse etetsoeng, lipuisano tsa video, le tse ling. Ho phaella ho data ea sebele, lipakete tsena li kenyelletsa metadata e khethollang mohloli oa sephethephethe, litaba, sebaka seo u eang ho sona le lintlha tse ling tsa bohlokoa. Ka theknoloji ea ho sefa lipakete, data e ka lula e beiloe leihlo le ho laoloa ho netefatsa hore e fetisetsoa sebakeng se nepahetseng. Empa ho netefatsa ts'ireletso ea marang-rang, ho sefa lipakete tsa setso ho hole haholo. E meng ea mekhoa ea mantlha ea tlhahlobo e tebileng ea lipakete taolong ea marang-rang e thathamisitsoe ka tlase:

Matching Mode/Tshaeno

Pakete e 'ngoe le e' ngoe e hlahlojoa bakeng sa papali khahlanong le database ea litlhaselo tsa marang-rang tse tsejoang ke firewall e nang le bokhoni ba ho lemoha intrusion system (IDS). IDS e batla mekhoa e tsebahalang e kotsi 'me e tima sephethephethe ha mekhoa e kotsi e fumanoa. Bobebe ba leano la ho tsamaellana le mesaeno ke hore e sebetsa feela ho mesaeno e nchafatsoang khafetsa. Ho phaella moo, theknoloji ena e ka itšireletsa feela khahlanong le litšokelo kapa litlhaselo tse tsejoang.

DPI

Mokhelo oa Protocol

Kaha mokhoa oa mokhelo oa protocol ha o lumelle feela data eohle e sa lumellaneng le polokelo ea motekeno, mokhoa oa mokhelo oa protocol o sebelisoang ke firewall ea IDS ha o na liphoso tsa tlhaho tsa mokhoa oa ho nyallana oa mohlala. Ho e-na le hoo, e amohela leano la kamehla la ho hana. Ka tlhaloso ea protocol, li-firewall li etsa qeto ea hore na ke sephethephethe sefe se lokelang ho lumelloa le ho sireletsa marang-rang ho tsoa lits'oso tse sa tsejoeng.

Sistimi ea Thibelo ea ho Thibela (IPS)

Litharollo tsa IPS li ka thibela phetiso ea lipakete tse kotsi tse ipapisitseng le litaba tsa tsona, ka hona li emisa litlhaselo tse belaelloang ka nako ea nnete. Sena se bolela hore haeba pakete e emela kotsi e tsebahalang ea ts'ireletso, IPS e tla thibela sephethephethe sa marang-rang ho latela melao e hlalositsoeng. Phoso e 'ngoe ea IPS ke tlhokahalo ea ho nchafatsa sebaka sa polokelo ea litšokelo tsa marang-rang khafetsa ka lintlha tse mabapi le litšokelo tse ncha, le monyetla oa ho fana ka maikutlo a fosahetseng. Empa kotsi ena e ka fokotsoa ka ho theha maano a boits'oaro le mekhoa e tloaelehileng, ho theha boitšoaro bo nepahetseng bakeng sa likarolo tsa marang-rang, le ho lekola litemoso le liketsahalo tse tlalehiloeng nako le nako ho ntlafatsa tlhokomelo le tlhokomeliso.

1- The DPI (Deep Packet Inspection) ho Network Packet Broker

"Botebo" ke boemo le papiso e tloaelehileng ea pakete, "tlhahlobo e tloaelehileng ea pakete" feela tlhahlobo e latelang ea IP packet 4 layer, ho kenyeletsoa aterese ea mohloli, aterese ea moo u eang teng, boema-kepe ba mohloli, boema-kepe le mofuta oa protocol, le DPI ntle le maemo a phahameng. tlhahlobo, hape e ekelitse tlhahlobo ea lera la kopo, ho tseba lits'ebetso le litaba tse fapaneng, ho hlokomela mesebetsi ea mantlha:

1) Tlhahlobo ea Kopo - tlhahlobo ea sebopeho sa sephethephethe sa marang-rang, tlhahlobo ea ts'ebetso, le tlhahlobo ea phallo

2) Tlhahlobo ea mosebelisi - karohano ea sehlopha sa basebelisi, tlhahlobo ea boitšoaro, tlhahlobo ea terminal, tlhahlobo ea mekhoa, jj.

3) Network Element Analysis -- tlhahlobo e ipapisitseng le litšoaneleho tsa libaka (toropo, setereke, seterata, joalo-joalo) le boima ba liteishene.

4) Taolo ea Sephethephethe - Phokotso ea lebelo la P2P, netefatso ea QoS, netefatso ea bandwidth, ts'ebeliso ea lisebelisoa tsa marang-rang, jj.

5) Tiisetso ea Ts'ireletso - Litlhaselo tsa DDoS, sefefo sa phatlalatso ea data, thibelo ea litlhaselo tse mpe tsa vaerase, jj.

2- Kakaretso ea Kakaretso ea Likopo tsa Marang-rang

Kajeno ho na le lits'ebetso tse ngata marang-rang, empa lits'ebetso tse tloaelehileng tsa webo li ka phetheha.

Ho ea kamoo ke tsebang, k'hamphani e tsebahalang ka ho fetesisa ea lisebelisoa ke Huawei, e ipolelang hore e hlokomela lits'ebetso tse 4,000. Tlhahlobo ea protocol ke mojule oa motheo oa lik'hamphani tse ngata tsa firewall (Huawei, ZTE, joalo-joalo), hape ke mojule oa bohlokoa haholo, o tšehetsang ho phethahala ha li-module tse ling tse sebetsang, ho tsebahatsa kopo e nepahetseng, le ho ntlafatsa haholo ts'ebetso le ho tšepahala ha lihlahisoa. Ha ke etsa mohlala oa boitsebiso ba malware ho latela litšobotsi tsa sephethephethe sa marang-rang, joalo ka ha ke ntse ke etsa hona joale, boitsebiso bo nepahetseng le bo pharaletseng ba protocol le bona bo bohlokoa haholo. Ntle le sephethephethe sa marang-rang sa likopo tse tloaelehileng ho tsoa ho sephethephethe sa kantle ho naha sa k'hamphani, sephethephethe se setseng se tla ikarabella bakeng sa karolo e nyane, e leng molemo bakeng sa tlhahlobo ea malware le alamo.

Ho ipapisitsoe le boiphihlelo ba ka, lits'ebetso tse sebelisoang hangata li arotsoe ho latela mesebetsi ea tsona:

PS: Ho ea ka kutloisiso ea botho ea sehlopha sa kopo, o na le litlhahiso tse ntle tse amohelehang ho tlohela tlhahiso ea molaetsa

1). E-mail

2). Video

3). Lipapali

4). Sehlopha sa Ofisi ea OA

5). Ntlafatso ea software

6). Tsa lichelete (banka, Alipay)

7). Li-stock

8). Puisano ea Sechaba (IM)

9). Ho bala marang-rang (mohlomong ho tsebisitsoe hamolemo ka li-URL)

10). Lisebelisoa tsa ho khoasolla (web disk, download P2P, BT e amanang)

20191210153150_32811

Joale, na DPI(Deep Packet Inspection) e sebetsa joang ho NPB:

1). Pakete Capture: NPB e hapa sephethephethe sa marang-rang ho tsoa mehloling e fapaneng, joalo ka li-switches, li-routers kapa lipompo. E amohela lipakete tse phallang ka marang-rang.

2). Packet Parsing: Lipakete tse hapuoeng li aroloa ke NPB ho ntša likarolo tse fapaneng tsa protocol le data e amanang le eona. Ts'ebetso ena ea ho arola e thusa ho tseba likarolo tse fapaneng ka har'a lipakete, joalo ka lihlooho tsa Ethernet, lihlooho tsa IP, lihlooho tsa lera la lipalangoang (mohlala, TCP kapa UDP), le liprothokholo tsa layer layer.

3). Tlhahlobo ea Lekhetho: Ka DPI, NPB e fetela ka nģ'ane ho tlhahlobo ea hlooho 'me e tsepamisitse maikutlo holim'a moputso, ho kenyelletsa le data ea sebele ka har'a lipakete. E hlahloba litaba tsa mojaro oa moputso ka botebo, ho sa natsoe kopo kapa protocol e sebelisitsoeng, ho ntša tlhahisoleseling e nepahetseng.

4). Boitsebiso ba Protocol: DPI e nolofalletsa NPB ho tseba mekhoa e itseng le mekhoa e sebelisoang ka har'a sephethephethe sa marang-rang. E khona ho bona le ho hlophisa liprothokholo tse kang HTTP, FTP, SMTP, DNS, VoIP, kapa liprothokholo tsa ho hasanya video.

5). Tlhahlobo ea Likahare: DPI e lumella NPB ho hlahloba likahare tsa lipakete bakeng sa mekhoa e itseng, li-signature kapa mantsoe a bohlokoa. Sena se nolofalletsa ho lemoha litšokelo tsa marang-rang, joalo ka malware, livaerase, liteko tsa ho kenella, kapa mesebetsi e belaetsang. DPI e ka boela ea sebelisoa bakeng sa ho sefa litaba, ho tiisa melaoana ea marang-rang, kapa ho tsebahatsa tlolo ea molao ea data.

6). Tlhahiso ea Metadata: Nakong ea DPI, NPB e ntša metadata e nepahetseng ho tsoa lipaketeng. Sena se ka kenyelletsa lintlha tse kang liaterese tsa IP tsa mohloli le moo u eang teng, linomoro tsa boema-kepe, lintlha tsa seshene, data ea transaction, kapa litšobotsi life kapa life tse amehang.

7). Tsela ea Sephethephethe kapa Ho Filtering: Ho ipapisitsoe le tlhahlobo ea DPI, NPB e ka tsamaisa lipakete tse ikhethileng ho ea libakeng tse khethiloeng bakeng sa ts'ebetso e tsoelang pele, joalo ka lisebelisoa tsa ts'ireletso, lisebelisoa tsa ho beha leihlo, kapa sethala sa analytics. E ka boela ea sebelisa melao ea ho sefa ho lahla kapa ho tsamaisa lipakete hape ho latela litaba tse khethiloeng kapa lipaterone.

ML-NPB-5660 3d


Nako ea poso: Jun-25-2023