Generation los yog export ntawm ntws. Lub luag haujlwm no feem ntau yog muab rau lub router, hloov lossis lwm yam khoom siv network, uas, dhau los ntawm kev sib txuas hauv network los ntawm nws tus kheej, tso cai rau koj rho tawm cov ntsiab lus tseem ceeb ntawm nws, uas yog tom qab ntawd xa mus rau cov khoom sau. Piv txwv li, Cisco txhawb nqa Netflow raws tu qauv tsis tsuas yog ntawm routers thiab keyboards, suav nrog cov khoom siv hluav taws xob thiab kev lag luam, tab sis kuj tseem nyob ntawm wireless controllers, firewalls thiab txawm servers.
Collection flow. Xav txog tias lub network niaj hnub no feem ntau muaj ntau tshaj li ib qho khoom siv network, qhov teeb meem ntawm kev sib sau thiab kev sib koom ua ke tau tshwm sim, uas yog daws tau los ntawm kev siv lub npe hu ua collectors, uas ua cov txheej txheem tau txais thiab xa mus rau kev txheeb xyuas.
Flow tsom xam Tus kws tshuaj ntsuam xyuas siv lub luag haujlwm tseem ceeb ntawm kev txawj ntse thiab, siv ntau yam algorithms rau cov kwj deg, kos qee cov lus xaus. Piv txwv li, raws li ib feem ntawm IT muaj nuj nqi, xws li tus neeg soj ntsuam tuaj yeem txheeb xyuas cov kev tsis sib haum xeeb hauv lub network lossis txheeb xyuas cov tsheb thauj khoom profile rau kev txhim kho network ntxiv. Thiab rau cov ntaub ntawv kev ruaj ntseg, xws li ib tug analyzer tuaj yeem ntes cov ntaub ntawv xau, kev sib kis ntawm cov cai phem lossis DoS tawm tsam.
Tsis txhob xav tias qhov peb-tier architecture no nyuaj heev - tag nrho lwm yam kev xaiv (tshwj tsis yog, tej zaum, network saib xyuas kev ua haujlwm nrog SNMP thiab RMON) kuj ua haujlwm raws li nws. Peb muaj lub tshuab hluav taws xob cov ntaub ntawv rau kev tsom xam, uas tuaj yeem yog lub network ntaus ntawv lossis lub ntsuas hluav taws xob nyob ib leeg. Peb muaj lub tswb sau cov kab ke thiab kev tswj hwm kev tswj hwm rau tag nrho cov kev saib xyuas kev tsim kho. Ob lub ntsiab lus kawg tuaj yeem ua ke hauv ib qho ntawm ib qho, tab sis nyob rau hauv ntau dua lossis tsawg dua cov tes hauj lwm loj lawv feem ntau kis tau los ntawm tsawg kawg ob lub cuab yeej txhawm rau txhawm rau ua kom muaj peev xwm thiab kev ntseeg tau.
Tsis zoo li pob ntawv tsom xam, uas yog los ntawm kev kawm cov ntaub ntawv header thiab lub cev ntawm txhua pob ntawv thiab cov kev sib tham uas nws muaj, kev soj ntsuam ntws los ntawm kev sau cov metadata txog kev sib txuas hauv network. Thaum twg, ntau npaum li cas, los ntawm qhov twg thiab qhov twg, yuav ua li cas ... cov no yog cov lus nug teb los ntawm kev tsom xam ntawm network telemetry siv ntau yam kev cai ntws. Thaum xub thawj, lawv tau siv los txheeb xyuas cov txheeb cais thiab pom cov teeb meem IT hauv lub network, tab sis tom qab ntawd, raws li kev tshuaj ntsuam xyuas cov txheej txheem tsim, nws tau los siv rau tib lub telemetry rau kev ruaj ntseg. Nws yog ib qho tsim nyog yuav tsum tau rov qab hais dua tias kev soj ntsuam ntws tsis hloov lossis hloov pob ntawv ntes. Txhua txoj hauv kev no muaj nws qhov chaw ntawm kev thov. Tab sis nyob rau hauv cov ntsiab lus ntawm tsab xov xwm no, nws yog txaus tsom xam uas yog qhov zoo tshaj plaws haum rau kev soj ntsuam cov infrastructure. Koj muaj cov khoom siv hauv network (txawm lawv ua haujlwm hauv software-txhais lus piv txwv lossis raws li cov cai zoo li qub) uas qhov kev tawm tsam tsis tuaj yeem hla. Nws tuaj yeem hla lub IDS sensor classic, tab sis lub network ntaus ntawv uas txhawb nqa cov txheej txheem ntws tsis tuaj yeem. Qhov no yog qhov zoo ntawm txoj kev no.
Ntawm qhov tod tes, yog tias koj xav tau cov ntaub ntawv pov thawj rau tub ceev xwm lossis koj tus kheej pawg neeg tshawb xyuas qhov xwm txheej, koj tsis tuaj yeem ua yam tsis muaj pob ntawv ntes - network telemetry tsis yog daim ntawv luam ntawm cov tsheb uas tuaj yeem siv los sau cov pov thawj; nws yog qhov xav tau rau kev tshawb nrhiav sai thiab kev txiav txim siab hauv kev ruaj ntseg ntawm cov ntaub ntawv. Ntawm qhov tod tes, siv telemetry tsom xam, koj tuaj yeem "sau" tsis yog txhua qhov kev sib txuas hauv network (yog tias muaj dab tsi, Cisco cuam tshuam nrog cov chaw zov me nyuam :-), tab sis tsuas yog qhov uas koom nrog kev tawm tsam. Telemetry tsom xam cov cuab yeej nyob rau hauv no hais txog yuav ntxiv ib txwm packet capture mechanisms zoo, muab commands rau xaiv capture thiab cia. Txwv tsis pub, koj yuav tau muaj ib colossal cia infrastructure.
Cia peb xav txog lub network ua haujlwm ntawm qhov nrawm ntawm 250 Mbit / sec. Yog tias koj xav khaws tag nrho cov ntim no, ces koj yuav xav tau 31 MB ntawm kev cia rau ib thib ob ntawm kev sib kis, 1,8 GB rau ib feeb, 108 GB rau ib teev, thiab 2,6 TB rau ib hnub. Txhawm rau khaws cov ntaub ntawv txhua hnub los ntawm lub network nrog bandwidth ntawm 10 Gbit / s, koj yuav xav tau 108 TB ntawm kev cia. Tab sis qee qhov kev tswj hwm yuav tsum khaws cov ntaub ntawv kev ruaj ntseg rau xyoo ... Cov ntaub ntawv ntawm qhov xav tau, uas ntsuas ntws pab koj siv, pab txo cov nqi no los ntawm kev txiav txim siab ntau. Los ntawm txoj kev, yog tias peb tham txog qhov sib piv ntawm qhov ntim ntawm cov ntaub ntawv kaw lus network telemetry thiab ua tiav cov ntaub ntawv ntes, ces nws yog kwv yees li 1 mus rau 500. Rau tib qhov txiaj ntsig tau muab los saum toj no, khaws cov ntawv sau tag nrho ntawm txhua hnub kev khiav tsheb. yuav yog 5 thiab 216 GB, ntsig txog (koj tuaj yeem kaw nws ntawm lub flash drive li niaj zaus).
Yog hais tias rau cov cuab yeej rau kev soj ntsuam cov ntaub ntawv raw network, txoj kev ntawm kev ntes nws yuav luag zoo ib yam los ntawm tus neeg muag khoom mus rau tus neeg muag khoom, ces nyob rau hauv cov ntaub ntawv ntawm ntws tsom xam qhov teeb meem yog txawv. Muaj ntau ntau txoj kev xaiv rau kev khiav dej num, qhov sib txawv uas koj yuav tsum paub txog hauv cov ntsiab lus ntawm kev ruaj ntseg. Qhov nrov tshaj plaws yog Netflow raws tu qauv tsim los ntawm Cisco. Muaj ob peb lub versions ntawm no raws tu qauv, txawv nyob rau hauv lawv cov peev xwm thiab tus nqi ntawm cov ntaub ntawv tsheb thauj mus los. Cov qauv tam sim no yog cuaj (Netflow v9), raws li kev lag luam tus qauv Netflow v10, tseem hu ua IPFIX, tau tsim. Niaj hnub no, feem ntau cov neeg muag khoom network txhawb Netflow lossis IPFIX hauv lawv cov khoom siv. Tab sis muaj ntau yam kev xaiv rau kev khiav dej num - sFlow, jFlow, cFlow, rFlow, NetStream, thiab lwm yam, uas sFlow yog qhov nrov tshaj plaws. Nws yog hom no uas feem ntau tau txais kev txhawb nqa los ntawm domestic manufacturers ntawm cov khoom siv network vim nws yooj yim ntawm kev siv. Dab tsi yog qhov txawv ntawm Netflow, uas tau dhau los ua tus qauv de facto, thiab sFlow? Kuv yuav qhia ntau yam tseem ceeb. Ua ntej, Netflow muaj cov neeg siv-customizable teb as opposed to the fixed fields in sFlow. Thiab qhov thib ob, thiab qhov no yog qhov tseem ceeb tshaj plaws hauv peb cov ntaub ntawv, sFlow sau cov npe hu ua telemetry; nyob rau hauv sib piv rau unsampled ib tug rau Netflow thiab IPFIX. Qhov txawv ntawm lawv yog dab tsi?
Xav txog tias koj txiav txim siab nyeem phau ntawv "Chaw Ua Haujlwm Kev Ruaj Ntseg: Lub Tsev, Kev Ua Haujlwm, thiab Tswj koj SOCβ ntawm kuv cov npoj yaig - Gary McIntyre, Joseph Munitz thiab Nadem Alfardan (koj tuaj yeem rub tawm ib feem ntawm phau ntawv los ntawm qhov txuas). Koj muaj peb txoj kev xaiv kom ua tiav koj lub hom phiaj - nyeem tag nrho phau ntawv, hla dhau nws, nres ntawm txhua nplooj ntawv 10 lossis 20th, lossis sim nrhiav cov ntsiab lus tseem ceeb ntawm blog lossis kev pabcuam xws li SmartReading. Yog li, tsis siv neeg telemetry nyeem txhua "nplooj" ntawm kev sib txuas hauv network, uas yog, txheeb xyuas cov metadata rau txhua pob ntawv. Sampled telemetry yog qhov kev xaiv ntawm kev tsheb khiav hauv kev cia siab tias cov qauv xaiv yuav muaj qhov koj xav tau. Nyob ntawm cov channel ceev, cov qauv telemetry yuav raug xa mus rau kev tshuaj xyuas txhua txhua 64th, 200th, 500th, 1000th, 2000th lossis 10000th pob ntawv.
Thaum muab kev ua haujlwm ntau dua hauv kev sau thiab tshawb nrhiav hauv nws, ELK tam sim no tsis muaj cov khoom siv hauv kev txheeb xyuas kom pom qhov tsis txaus ntseeg thiab kev hem thawj hauv network telemetry. Ntawd yog, ua raws li lub neej voj voog uas tau piav qhia saum toj no, koj yuav tsum tau piav qhia txog kev ua txhaum cai ntawm tus kheej thiab tom qab ntawd siv nws hauv kev sib ntaus sib tua (tsis muaj cov qauv tsim muaj).
Muaj, tau kawg, muaj ntau yam kev txuas ntxiv rau ELK, uas twb muaj qee cov qauv rau kev kuaj xyuas qhov tsis sib xws hauv network telemetry, tab sis cov kev txuas ntxiv no raug nqi nyiaj thiab cov lus nug yog seb qhov kev ua si puas tsim nyog rau tswm ciab - sau tus qauv zoo sib xws ntawm koj tus kheej, yuav nws qhov kev siv. rau koj cov cuab yeej saib xyuas, lossis yuav npaj cov kev daws teeb meem ntawm Network Traffic Analysis class.
Feem ntau, kuv tsis xav kom nkag mus rau hauv kev sib cav hais tias nws yog qhov zoo dua los siv nyiaj thiab yuav qhov kev npaj ua tiav rau kev saib xyuas qhov tsis zoo thiab kev hem thawj hauv network telemetry (piv txwv li, Cisco Stealthwatch) lossis txheeb xyuas koj tus kheej thiab kho tib yam. SiLK, ELK lossis nfdump lossis OSU Flow Tools rau txhua qhov kev hem thawj tshiab (Kuv tab tom tham txog ob qhov kawg ntawm lawv hais zaum kawg)? Txhua tus xaiv rau lawv tus kheej thiab txhua tus muaj lawv tus kheej lub siab xav xaiv ib qho ntawm ob qho kev xaiv. Kuv tsuas yog xav qhia tias network telemetry yog ib qho cuab yeej tseem ceeb hauv kev ua kom muaj kev ruaj ntseg network ntawm koj cov kev tsim kho vaj tse sab hauv thiab koj yuav tsum tsis txhob tso tseg, yog li tsis txhob koom nrog cov npe ntawm cov tuam txhab uas nws lub npe tau hais hauv xov xwm nrog rau cov epithets " hacked", "tsis ua raws li cov ntaub ntawv kev ruaj ntseg", "tsis xav txog kev ruaj ntseg ntawm lawv cov ntaub ntawv thiab cov neeg siv khoom cov ntaub ntawv."
Txhawm rau kom ua tiav, Kuv xav sau cov lus qhia tseem ceeb uas koj yuav tsum ua raws thaum tsim cov ntaub ntawv kev ruaj ntseg saib xyuas koj qhov kev tsim kho hauv tsev:
Tsis txhob txwv koj tus kheej rau hauv ib puag ncig! Siv (thiab xaiv) network infrastructure tsis yog tsuas yog txav mus los ntawm point A mus rau point B, tab sis kuj los daws teeb meem cybersecurity.
PS. Yog tias nws yooj yim dua rau koj hnov ββββtxhua yam uas tau sau saum toj no, koj tuaj yeem saib qhov kev nthuav qhia ntev ib teev uas tsim lub hauv paus ntawm daim ntawv no.