ืฉื—ืจื•ืจ ืžืขืจื›ืช ื‘ื“ื™ืงืช ืžื ื•ืช ืขืžื•ืงื” nDPI 4.8

ืคืจื•ื™ืงื˜ ntop, ื”ืžืคืชื— ื›ืœื™ื ืœืœื›ื™ื“ืช ื•ื ื™ืชื•ื— ืชืขื‘ื•ืจื”, ืคืจืกื ืืช ืฉื—ืจื•ืจื• ืฉืœ ืขืจื›ืช ื”ื›ืœื™ื ืœื‘ื“ื™ืงืช ืžื ื•ืช ืขืžื•ืงื” nDPI 4.8, ืืฉืจ ืžืžืฉื™ื›ื” ื‘ืคื™ืชื•ื— ืกืคืจื™ื™ืช OpenDPI. ืคืจื•ื™ืงื˜ nDPI ื”ื•ืงื ืœืื—ืจ ื ื™ืกื™ื•ืŸ ืœื ืžื•ืฆืœื— ืœื“ื—ื•ืฃ ืฉื™ื ื•ื™ื™ื ื‘ืžืื’ืจ OpenDPI, ืฉื ื•ืชืจ ืœืœื ืชื—ื–ื•ืงื”. ืงื•ื“ nDPI ื›ืชื•ื‘ ื‘-C ื•ื”ื•ื ืžื•ืจืฉื” ืชื—ืช LGPLv3.

ื”ืžืขืจื›ืช ืžืืคืฉืจืช ืœืš ืœืงื‘ื•ืข ืืช ื”ืคืจื•ื˜ื•ืงื•ืœื™ื ื‘ืจืžืช ื”ื™ื™ืฉื•ื ื”ืžืฉืžืฉื™ื ื‘ืชืขื‘ื•ืจื”, ืœื ืชื— ืืช ืื•ืคื™ ืคืขื™ืœื•ืช ื”ืจืฉืช ืžื‘ืœื™ ืœื”ื™ื•ืช ืงืฉื•ืจื” ืœื™ืฆื™ืื•ืช ืจืฉืช (ื”ื™ื ื™ื›ื•ืœื” ืœืงื‘ื•ืข ืคืจื•ื˜ื•ืงื•ืœื™ื ื™ื“ื•ืขื™ื ืฉื”ืžื˜ืคืœื™ื ืฉืœื”ื ืžืงื‘ืœื™ื ื—ื™ื‘ื•ืจื™ื ื‘ื™ืฆื™ืื•ืช ืจืฉืช ืœื ืกื˜ื ื“ืจื˜ื™ื•ืช, ืœืžืฉืœ, ืื http ืœื ื ืฉืœื— ืžื™ืฆื™ืื” 80, ืื• ืœื”ื™ืคืš, ื›ืืฉืจ ื”ื ืžื ืกื™ื ืœื”ืกื•ื•ืช ืคืขื™ืœื•ืช ืจืฉืช ืื—ืจืช ื›-http ืขืœ ื™ื“ื™ ื”ืคืขืœืชื” ืขืœ ื™ืฆื™ืื” 80).

ื”ื”ื‘ื“ืœื™ื ืž-OpenDPI ื›ื•ืœืœื™ื ืชืžื™ื›ื” ื‘ืคืจื•ื˜ื•ืงื•ืœื™ื ื ื•ืกืคื™ื, ื”ืขื‘ืจื” ืœืคืœื˜ืคื•ืจืžืช Windows, ืื•ืคื˜ื™ืžื™ื–ืฆื™ื” ืฉืœ ื‘ื™ืฆื•ืขื™ื, ื”ืชืืžื” ืœืฉื™ืžื•ืฉ ื‘ื™ื™ืฉื•ืžื™ ื ื™ื˜ื•ืจ ืชืขื‘ื•ืจื” ื‘ื–ืžืŸ ืืžืช (ื”ื•ืกืจื• ื›ืžื” ืชื›ื•ื ื•ืช ืกืคืฆื™ืคื™ื•ืช ืฉื”ืื˜ื• ืืช ื”ืžื ื•ืข), ื™ื›ื•ืœืช ืœื‘ื ื•ืช ื‘ืฆื•ืจื” ืฉืœ ืžื•ื“ื•ืœ ืœื™ื‘ืช ืœื™ื ื•ืงืก, ื•ืชืžื™ื›ื” ื‘ื”ื’ื“ืจืช ืชืช-ืคืจื•ื˜ื•ืงื•ืœื™ื.

ืชื•ืžืš ื‘ื–ื™ื”ื•ื™ ืฉืœ 53 ืกื•ื’ื™ื ืฉืœ ืื™ื•ืžื™ ืจืฉืช (ืกื™ื›ื•ืŸ ื–ืจื™ืžื”) ื•ื™ื•ืชืจ ืž-350 ืคืจื•ื˜ื•ืงื•ืœื™ื ื•ื™ื™ืฉื•ืžื™ื (ืž-OpenVPN, Tor, QUIC, SOCKS, BitTorrent ื•-IPsec ื•ืขื“ ืœื˜ืœื’ืจื, Viber, WhatsApp, PostgreSQL ื•ืฉื™ื—ื•ืช ืœ-Gmail, Office 365, Google Docs ื•ื™ื•ื˜ื™ื•ื‘). ืงื™ื™ื ืžืคืขื ื— ืื™ืฉื•ืจ SSL ืฉืœ ืฉืจืช ื•ืœืงื•ื— ื”ืžืืคืฉืจ ืœืงื‘ื•ืข ืืช ื”ืคืจื•ื˜ื•ืงื•ืœ (ืœื“ื•ื’ืžื”, Citrix Online ื•- Apple iCloud) ื‘ืืžืฆืขื•ืช ืชืขื•ื“ืช ื”ื”ืฆืคื ื”. ืชื•ื›ื ื™ืช ื”ืฉื™ืจื•ืช nDPIreader ืžืกื•ืคืงืช ื›ื“ื™ ืœื ืชื— ืืช ืชื•ื›ืŸ ื”-pcap dumps ืื• ืชืขื‘ื•ืจื” ื ื•ื›ื—ื™ืช ื“ืจืš ืžืžืฉืง ื”ืจืฉืช.

ื‘ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื”:

  • ืฆืจื™ื›ืช ื”ื–ื™ื›ืจื•ืŸ ืฆื•ืžืฆืžื” ื‘ืกื“ืจื™ ื’ื•ื“ืœ, ื”ื•ื“ื•ืช ืœืขื™ื‘ื•ื“ ืžื—ื“ืฉ ืฉืœ ื™ื™ืฉื•ื ื”ืจืฉื™ืžื•ืช.
  • ื”ืชืžื™ื›ื” ื‘-IPv6 ื”ื•ืจื—ื‘ื”.
  • ื ื•ืกืคื• ืžื–ื”ื™ ืคืจื•ื˜ื•ืงื•ืœ ื—ื“ืฉื™ื ื”ืงืฉื•ืจื™ื ืœืชื•ื›ืŸ ืœืžื‘ื•ื’ืจื™ื, ืคืจืกื•ื, ื ื™ืชื•ื— ืื™ื ื˜ืจื ื˜ ื•ืžืขืงื‘.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ืœืคืจื•ื˜ื•ืงื•ืœื™ื ื•ืฉื™ืจื•ืชื™ื:
    • HAProxy
    • ื—ืกื›ื•ืŸ ืฉืœ ืืคืืฆ'ื™
    • RMCP (ืคืจื•ื˜ื•ืงื•ืœ ื‘ืงืจืช ื ื™ื”ื•ืœ ืžืจื—ื•ืง)
    • SLP (Protocol Service Location)
    • ื‘ื™ื˜ืงื•ื™ืŸ
    • HTTP/2 ืœืœื ื”ืฆืคื ื”
    • SRTP (ืชื—ื‘ื•ืจื” ืžืื•ื‘ื˜ื—ืช ื‘ื–ืžืŸ ืืžืช)
    • BACnet
    • OICQ (ืฉืœื™ื— ืกื™ื ื™)
  • ื ื•ืกืคื” ื”ื’ื“ืจื” ืฉืœ OperaVPN ื•- ProtonVPN. ื–ื™ื”ื•ื™ Wireguard ืžืฉื•ืคืจ.
  • ื”ื˜ืžืขื” ื”ื™ื•ืจื™ืกื˜ื™ื•ืช ืœื–ื™ื”ื•ื™ ื–ืจื™ืžื•ืช ืชืขื‘ื•ืจื” ืžื•ืฆืคื ื•ืช ื‘ืžืœื•ืืŸ.
  • ื ื•ืกืคื” ื”ื’ื“ืจื” ืฉืœ ืฉื™ืจื•ืชื™ Yandex ื•-VK.
  • ื ื•ืกืฃ ื–ื™ื”ื•ื™ ืฉืœ ืกืœื™ืœื™ื ื•ืกื™ืคื•ืจื™ื ืฉืœ ืคื™ื™ืกื‘ื•ืง.
  • ื ื•ืกืคื” ื”ื’ื“ืจื” ืฉืœ ืคืœื˜ืคื•ืจืžืช ื”ืžืฉื—ืงื™ื Roblox, ืฉื™ืจื•ืช ื”ืขื ืŸ NVIDIA GeForceNow, ืžืฉื—ืงื™ Epic Games ื•ื”ืžืฉื—ืง "Heroes of the Storm".
  • ื–ื™ื”ื•ื™ ืžืฉื•ืคืจ ืฉืœ ืชื ื•ืขื” ืžื‘ื•ื˜ื™ ื—ื™ืคื•ืฉ.
  • ื ื™ืชื•ื— ื•ื–ื™ื”ื•ื™ ืžืฉื•ืคืจื™ื ืฉืœ ืคืจื•ื˜ื•ืงื•ืœื™ื ื•ืฉื™ืจื•ืชื™ื:
    • Gnutella
    • H323
    • HTTP
    • Hangout
    • ืฆื•ื•ืชื™ MS
    • Alibaba
    • MGCP
    • ืงึดื™ื˜ื•ึนืจ
    • MySQL
    • ื–ืื‘ื™ืงืก
  • ืžื’ื•ื•ืŸ ื”ืื™ื•ืžื™ื ื•ื”ื‘ืขื™ื•ืช ื‘ืจืฉืช ืฉื–ื•ื”ื• ื”ืงืฉื•ืจื™ื ืœืกื™ื›ื•ืŸ ืฉืœ ืคืฉืจื” (ืกื™ื›ื•ืŸ ื–ืจื™ืžื”) ื”ื•ืจื—ื‘. ื ื•ืกืคื” ืชืžื™ื›ื” ืขื‘ื•ืจ ืกื•ื’ื™ ืื™ื•ืžื™ื ื—ื“ืฉื™ื: NDPI_MALWARE_HOST_CONTACTED ื•-NDPI_TLS_ALPN_SNI_MISMATCH.
  • ื‘ื“ื™ืงื•ืช ืžื˜ื•ืฉื˜ืฉื•ืช ืื•ืจื’ื ื• ื›ื“ื™ ืœื–ื”ื•ืช ื‘ืขื™ื•ืช ืžื”ื™ืžื ื•ืช.
  • ื‘ืขื™ื•ืช ื‘ื‘ื ื™ื™ื” ืขืœ FreeBSD ื ืคืชืจื•.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”