ãããžã§ã¯ã
ãããžã§ã¯ã
OpenDPI ãšã®éãã¯ãè¿œå ãããã³ã«ã®ãµããŒããWindows ãã©ãããã©ãŒã ãžã®ç§»æ€ãããã©ãŒãã³ã¹ã®æé©åããªã¢ã«ã¿ã€ã ãã©ãã£ãã¯ç£èŠã¢ããªã±ãŒã·ã§ã³ã§ã®äœ¿çšãžã®é©å¿ (ãšã³ãžã³ã®é床ãäœäžãããããã€ãã®ç¹å®ã®æ©èœã¯åé€ãããŸãã) ã«ãªããŸãã
Linux ã«ãŒãã« ã¢ãžã¥ãŒã«ã®åœ¢åŒã§ã®ã¢ã»ã³ããªæ©èœãšããµããããã³ã«ã®å®çŸ©ã®ãµããŒãã
åèš 238 ã®ãããã³ã«ããã³ã¢ããªã±ãŒã·ã§ã³å®çŸ©ããµããŒããããŠããŸãã
OpenVPNãTorãQUICãSOCKSãBitTorrentãããã³ IPsec ãã Telegramã
ViberãWhatsAppãPostgreSQLãããã³ GMailãOffice365 ãžã®é話
Googleããã¥ã¡ã³ããšYouTubeã ãµãŒããŒããã³ã¯ã©ã€ã¢ã³ãã® SSL 蚌ææžãã³ãŒãããããæå·å蚌ææžã䜿çšããŠãããã³ã« (Citrix Online ã Apple iCloud ãªã©) ã決å®ã§ããŸãã nDPIreader ãŠãŒãã£ãªãã£ã¯ãpcap ãã³ãã®å
容ããããã¯ãŒã¯ ã€ã³ã¿ãŒãã§ã€ã¹ãä»ããçŸåšã®ãã©ãã£ãã¯ãåæããããã«æäŸãããŠããŸãã
$ ./nDPIreader -i eth0 -s 20 -f "ãã¹ã 192.168.1.10"
æ€åºããããããã³ã«:
DNS ãã±ãã: 57 ãã€ã: 7904 ãããŒ: 28
SSL_No_Cert ãã±ãã: 483 ãã€ã: 229203 ãããŒ: 6
FaceBook ãã±ãã: 136 ãã€ã: 74702 ãããŒ: 4
DropBox ãã±ãã: 9 ãã€ã: 668 ãããŒ: 3
Skype ãã±ãã: 5 ãã€ã: 339 ãããŒ: 3
Google ãã±ãã: 1700 ãã€ã: 619135 ãããŒ: 34
æ°ãããªãªãŒã¹ã§ã¯:
- ãããã³ã«æ å ±ã¯ãå®å šãªã¡ã¿ããŒã¿ã®åä¿¡ãåŸ ããã«ïŒå¯Ÿå¿ãããããã¯ãŒã¯ ãã±ãããåä¿¡ãããªãããã«ç¹å®ã®ãã£ãŒã«ãããŸã 解æãããŠããªãå Žåã§ãïŒãæ€åºåŸããã«è¡šç€ºãããããã«ãªããŸãããããã¯ãå³æã«å¿çããå¿ èŠããããã©ãã£ã㯠ã¢ãã©ã€ã¶ãŒã«ãšã£ãŠéèŠã§ããç¹å®ã®çš®é¡ã®ãã©ãã£ãã¯ã«é©çšãããŸãã å®å šãªãããã³ã«åæãå¿ èŠãªã¢ããªã±ãŒã·ã§ã³ã®å Žåããã¹ãŠã®ãããã³ã« ã¡ã¿ããŒã¿ã確å®ã«å®çŸ©ãããããã« ndpi_extra_dissection_possible() API ãæäŸãããŸãã
- 蚌ææžã®æ£ç¢ºæ§ãšèšŒææžã® SHA-1 ããã·ã¥ã«é¢ããæ å ±ãæœåºãããTLS ã®ãã詳现ãªåæãå®è£ ããŸããã
- CSV 圢åŒã§ãšã¯ã¹ããŒãããããã®ã-Cããã©ã°ã nDPIreader ã¢ããªã±ãŒã·ã§ã³ã«è¿œå ãããŸãããããã«ãããè¿œå ã® ntop ããŒã«ãããã䜿çšããŠãšã¯ã¹ããŒããå¯èœã«ãªããŸãã
å®æœãã ããªãè€éãªçµ±èšãµã³ãã«ã ããšãã°ãNetFlix ã§æ ç»ãæãé·ãèŠèŽãããŠãŒã¶ãŒã® IP ãç¹å®ããã«ã¯ã次ã®ããã«ããŸãã$ ndpiReader -i netflix.pcap -C /tmp/netflix.csv
$ q -H -d ',' "src_ip,SUM(src2dst_bytes+dst2src_bytes) ã /tmp/netflix.csv ããéžæããŸããããã§ãndpi_proto 㯠'%NetFlix%' ã®ããã« src_ip ã§ã°ã«ãŒãåãããŠããŸã"192.168.1.7,6151821
- ã§ææ¡ãããŠãããµããŒããè¿œå ããŸãã
ã·ã¹ã³ãžã§ã€ æ©åš ãã±ãã ãµã€ãºãšéä¿¡æé/é 延åæã䜿çšããŠãæå·åããããã©ãã£ãã¯ã«é ãããæªæã®ããã¢ã¯ãã£ããã£ãç¹å®ããŸãã ndpiReader ã§ã¯ããã®ã¡ãœããã¯ã-Jããªãã·ã§ã³ã§ã¢ã¯ãã£ãåãããŸãã - ã«ããŽãªããšã®ãããã³ã«ã®åé¡ãæäŸãããŸãã
- ããšãã°ãDoS æ»æäžã®ãããã³ã«ã®äœ¿çšãæ€åºããããã«ããããã³ã«ã®äœ¿çšã«ãããç°åžžãæ€åºããããã® IAT (å°çéé) ã®èšç®ã®ãµããŒããè¿œå ãããŸããã
- ãšã³ããããŒãå¹³åãæšæºåå·®ãåæ£ãªã©ã®èšç®ãããã¡ããªã¯ã¹ã«åºã¥ãããŒã¿åææ©èœãè¿œå ãããŸããã
- Python èšèªã®ãã€ã³ãã£ã³ã°ã®åæããŒãžã§ã³ãææ¡ãããŠããŸãã
- ããŒã¿æŒæŽ©ãæ€åºããããã«ããã©ãã£ãã¯å
ã®èªã¿åãå¯èœãªè¡ãæ€åºããã¢ãŒããè¿œå ããŸããã ã§
ndpiReader ã¢ãŒãã¯ãã-eããªãã·ã§ã³ã§æå¹ã«ãªããŸãã - TLS ã¯ã©ã€ã¢ã³ãèå¥æ¹æ³ã®ãµããŒããè¿œå ããŸãã
JA3 ããã«ãããæ¥ç¶ããŽã·ãšãŒã·ã§ã³ã®æ©èœãšæå®ããããã©ã¡ãŒã¿ãŒã«åºã¥ããŠãæ¥ç¶ã®ç¢ºç«ã«ã©ã®ãœãããŠã§ã¢ã䜿çšããããã決å®ã§ããŸã (ããšãã°ãTor ããã®ä»ã®äžè¬çãªã¢ããªã±ãŒã·ã§ã³ã®äœ¿çšã決å®ã§ããŸã)ã - SSHå®è£
èå¥æ¹æ³ã®ãµããŒããè¿œå ããŸãã(
ããã·ãŒ ) ãš DHCPã - ããŒã¿ãã·ãªã¢ã«åããã³éã·ãªã¢ã«åããé¢æ°ãè¿œå ããŸããã
Type-Length-Value (TLV) ããã³ JSON 圢åŒã - ãããã³ã«ãšãµãŒãã¹ã®ãµããŒããè¿œå ããŸãã: DTLS (TLS over UDP)ã
Huluã
TikTok/Musical.lyã
Whatsappãããªã
DNSoverHTTPSã
ããŒã¿ã»ãŒããŒã
ã©ã€ã³ã
Google Duoããã³ã°ã¢ãŠãã
ã¯ã€ã€ãŒã¬ãŒãVPNã
IMOã
ãºãŒã .us. - TLSãSIPãSTUN åæã®ãµããŒãã®åäž
Viberã
WhatsAppã
ã¢ããŸã³ãããªã
ã¹ããããã£ããã
FTPã
QUIC
OpenVPN UDPã
Facebook ã¡ãã»ã³ãžã£ãŒãšãã³ã°ã¢ãŠãã
åºæïŒ ãªãŒãã³ããã.ru