ืžืขืจื›ืช Arkime 3.1 ืœืื™ื ื“ืงืก ืชืขื‘ื•ืจืช ืจืฉืช ื–ืžื™ื ื”

ื”ื•ื›ื ื” ืžื”ื“ื•ืจื” ืฉืœ ื”ืžืขืจื›ืช ืœืœื›ื™ื“ื”, ืื—ืกื•ืŸ ื•ืื™ื ื“ืงืก ืฉืœ ื—ื‘ื™ืœื•ืช ืจืฉืช Arkime 3.1, ื”ืžืกืคืงืช ื›ืœื™ื ืœื”ืขืจื›ืช ื–ืจื™ืžื•ืช ืชื ื•ืขื” ื•ื™ื–ื•ืืœื™ืช ื•ื—ื™ืคื•ืฉ ืžื™ื“ืข ื”ืงืฉื•ืจ ืœืคืขื™ืœื•ืช ื”ืจืฉืช. ื”ืคืจื•ื™ืงื˜ ืคื•ืชื— ื‘ืžืงื•ืจ ืขืœ ื™ื“ื™ AOL ื‘ืžื˜ืจื” ืœื™ืฆื•ืจ ืชื—ืœื™ืฃ ืคืชื•ื— ื•ื ื™ืชืŸ ืœืคืจื™ืกื” ืขื‘ื•ืจ ืคืœื˜ืคื•ืจืžื•ืช ืขื™ื‘ื•ื“ ืžื ื•ืช ืžืกื—ืจื™ื•ืช ื‘ืจืฉืช, ื”ืžืกื•ื’ืœืช ืœื”ืชืื™ื ืœืขื™ื‘ื•ื“ ืชืขื‘ื•ืจื” ื‘ืžื”ื™ืจื•ื™ื•ืช ืฉืœ ืขืฉืจื•ืช ื’ื™ื’ื”-ื‘ื™ื˜ ืœืฉื ื™ื™ื”. ืงื•ื“ ืจื›ื™ื‘ ืœื›ื™ื“ืช ื”ืชืขื‘ื•ืจื” ื›ืชื•ื‘ ื‘-C, ื•ื”ืžืžืฉืง ืžื™ื•ืฉื ื‘-Node.js/JavaScript. ืงื•ื“ ื”ืžืงื•ืจ ืžื•ืคืฅ ืชื—ืช ืจื™ืฉื™ื•ืŸ Apache 2.0. ืชื•ืžืš ื‘ืขื‘ื•ื“ื” ืขืœ ืœื™ื ื•ืงืก ื•- FreeBSD. ื—ื‘ื™ืœื•ืช ืžื•ื›ื ื•ืช ืžื•ื›ื ื•ืช ืขื‘ื•ืจ Arch, CentOS ื•ืื•ื‘ื•ื ื˜ื•.

Arkime ื›ื•ืœืœ ื›ืœื™ื ืœืœื›ื™ื“ื” ื•ืื™ื ื“ืงืก ืฉืœ ืชืขื‘ื•ืจื” ื‘ืคื•ืจืžื˜ PCAP ืžืงื•ืจื™, ื•ื›ืŸ ืžืกืคืง ื›ืœื™ื ืœื’ื™ืฉื” ืžื”ื™ืจื” ืœื ืชื•ื ื™ื ืฉื ื•ืกืคื• ืœืื™ื ื“ืงืก. ื”ืฉื™ืžื•ืฉ ื‘ืคื•ืจืžื˜ PCAP ืžืคืฉื˜ ืžืื•ื“ ืืช ื”ืื™ื ื˜ื’ืจืฆื™ื” ืขื ืžื ืชื—ื™ ืชืขื‘ื•ืจื” ืงื™ื™ืžื™ื ื›ื’ื•ืŸ Wireshark. ื ืคื— ื”ื ืชื•ื ื™ื ื”ืžืื•ื—ืกื ื™ื ืžื•ื’ื‘ืœ ืจืง ืขืœ ื™ื“ื™ ื’ื•ื“ืœ ืžืขืจืš ื”ื“ื™ืกืงื™ื ื”ื–ืžื™ืŸ. ืžื˜ื-ื ืชื•ื ื™ื ืฉืœ ืคืขื™ืœื•ื™ื•ืช ื‘ืืชืจ ืžืชื•ื•ืกืคื™ื ืœืื™ื ื“ืงืก ื”ืžื‘ื•ืกืก ืขืœ ืžื ื•ืข Elasticsearch.

ืœื ื™ืชื•ื— ื”ืžื™ื“ืข ื”ืžืฆื˜ื‘ืจ ืžื•ืฆืข ืžืžืฉืง ืื™ื ื˜ืจื ื˜ ื”ืžืืคืฉืจ ืœื ื•ื•ื˜, ืœื—ืคืฉ ื•ืœื™ื™ืฆื ื“ื•ื’ืžืื•ืช. ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืžืกืคืง ืžืกืคืจ ืžืฆื‘ื™ ืฆืคื™ื™ื” - ืžืกื˜ื˜ื™ืกื˜ื™ืงื” ื›ืœืœื™ืช, ืžืคื•ืช ื—ื™ื‘ื•ืจ ื•ื’ืจืคื™ื ื•ื™ื–ื•ืืœื™ื™ื ืขื ื ืชื•ื ื™ื ืขืœ ืฉื™ื ื•ื™ื™ื ื‘ืคืขื™ืœื•ืช ื”ืจืฉืช ื•ืขื“ ืœื›ืœื™ื ืœืœื™ืžื•ื“ ืžืคื’ืฉื™ื ื‘ื•ื“ื“ื™ื, ื ื™ืชื•ื— ืคืขื™ืœื•ืช ื‘ื”ืงืฉืจ ืฉืœ ื”ืคืจื•ื˜ื•ืงื•ืœื™ื ื‘ืฉื™ืžื•ืฉ ื•ื ื™ืชื•ื— ื ืชื•ื ื™ื ืž-PCAP dumps. ืžืกื•ืคืง ื’ื API ื”ืžืืคืฉืจ ืœืฉืœื•ื— ื ืชื•ื ื™ื ืขืœ ืžื ื•ืช ืฉื ืœื›ื“ื• ื‘ืคื•ืจืžื˜ PCAP ื•ื”ืคืขืœื•ืช ืžืคื•ืจืงื•ืช ื‘ืคื•ืจืžื˜ JSON ืœื™ื™ืฉื•ืžื™ ืฆื“ ืฉืœื™ืฉื™.

ืžืขืจื›ืช Arkime 3.1 ืœืื™ื ื“ืงืก ืชืขื‘ื•ืจืช ืจืฉืช ื–ืžื™ื ื”

Arkime ืžื•ืจื›ื‘ ืžืฉืœื•ืฉื” ืžืจื›ื™ื‘ื™ื ื‘ืกื™ืกื™ื™ื:

  • ืžืขืจื›ืช ืœื›ื™ื“ืช ื”ืชืขื‘ื•ืจื” ื”ื™ื ืืคืœื™ืงืฆื™ื™ืช C ืžืจื•ื‘ื” ื”ืœื™ื›ื™ ืœื ื™ื˜ื•ืจ ืชืขื‘ื•ืจื”, ื›ืชื™ื‘ืช dump ื‘ืคื•ืจืžื˜ PCAP ืœื“ื™ืกืง, ื ื™ืชื•ื— ืžื ื•ืช ืฉื ืœื›ื“ื• ื•ืฉืœื™ื—ืช ืžื˜ื ื ืชื•ื ื™ื ืื•ื“ื•ืช ืžืคื’ืฉื™ื (SPI, Stateful packet inspection) ื•ืคืจื•ื˜ื•ืงื•ืœื™ื ืœืืฉื›ื•ืœ Elasticsearch. ืืคืฉืจ ืœืื—ืกืŸ ืงื‘ืฆื™ PCAP ื‘ืฆื•ืจื” ืžื•ืฆืคื ืช.
  • ืžืžืฉืง ืื™ื ื˜ืจื ื˜ ื”ืžื‘ื•ืกืก ืขืœ ืคืœื˜ืคื•ืจืžืช Node.js, ื”ืคื•ืขืœ ืขืœ ื›ืœ ืฉืจืช ืœื›ื™ื“ืช ืชืขื‘ื•ืจื” ื•ืžืขื‘ื“ ื‘ืงืฉื•ืช ื”ืงืฉื•ืจื•ืช ืœื’ื™ืฉื” ืœื ืชื•ื ื™ื ื‘ืื™ื ื“ืงืก ื•ื”ืขื‘ืจืช ืงื‘ืฆื™ PCAP ื“ืจืš ื”-API.
  • ืื—ืกื•ืŸ ืžื˜ื ื ืชื•ื ื™ื ืžื‘ื•ืกืก ืขืœ Elasticsearch.

ืžืขืจื›ืช Arkime 3.1 ืœืื™ื ื“ืงืก ืชืขื‘ื•ืจืช ืจืฉืช ื–ืžื™ื ื”

ื‘ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื”:

  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืคืจื•ื˜ื•ืงื•ืœื™ IETF QUIC, GENEVE, VXLAN-GPE.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืกื•ื’ Q-in-Q (Double VLAN), ื”ืžืืคืฉืจืช ืœื›ืœื•ืœ ืชื’ื™ VLAN ื‘ืชื’ื™ื•ืช ื‘ืจืžื” ืฉื ื™ื™ื” ื›ื“ื™ ืœื”ืจื—ื™ื‘ ืืช ืžืกืคืจ ื”-VLAN ืœ-16 ืžื™ืœื™ื•ืŸ.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืกื•ื’ ื”ืฉื“ื” "ืฆืฃ".
  • ืžื•ื“ื•ืœ ื”ื”ืงืœื˜ื” ื‘ืืžื–ื•ืŸ Elastic Compute Cloud ื”ื•ืžืจ ืœืฉื™ืžื•ืฉ ื‘ืคืจื•ื˜ื•ืงื•ืœ IMDSv2 (Instance Metadata Service).
  • ื”ืงื•ื“ ืฉื•ืคืฅ ืžื—ื“ืฉ ื›ื“ื™ ืœื”ื•ืกื™ืฃ ืžื ื”ืจื•ืช UDP.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ืขื‘ื•ืจ elasticsearchAPIKey ื•- elasticsearchBasicAuth.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”