nDPI 4.0 ์‹ฌ์ธต ํŒจํ‚ท ๊ฒ€์‚ฌ ์‹œ์Šคํ…œ ์ถœ์‹œ

ํŠธ๋ž˜ํ”ฝ ์บก์ฒ˜ ๋ฐ ๋ถ„์„ ๋„๊ตฌ๋ฅผ ๊ฐœ๋ฐœํ•˜๋Š” ntop ํ”„๋กœ์ ํŠธ๋Š” OpenDPI ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ๊ฐœ๋ฐœ์„ ๊ณ„์†ํ•˜๋Š” nDPI 4.0 ์‹ฌ์ธต ํŒจํ‚ท ๊ฒ€์‚ฌ ๋„๊ตฌ ํ‚คํŠธ๋ฅผ ์ถœ์‹œํ–ˆ์Šต๋‹ˆ๋‹ค. nDPI ํ”„๋กœ์ ํŠธ๋Š” ์œ ์ง€ ๊ด€๋ฆฌ๋˜์ง€ ์•Š์€ ์ƒํƒœ๋กœ ๋‚จ์•„ ์žˆ๋Š” OpenDPI ์ €์žฅ์†Œ์— ๋ณ€๊ฒฝ ์‚ฌํ•ญ์„ ํ‘ธ์‹œํ•˜๋ ค๋Š” ์‹œ๋„๊ฐ€ ์‹คํŒจํ•œ ํ›„์— ์„ค๋ฆฝ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. nDPI ์ฝ”๋“œ๋Š” C๋กœ ์ž‘์„ฑ๋˜์—ˆ์œผ๋ฉฐ LGPLv3์— ๋”ฐ๋ผ ๋ผ์ด์„ผ์Šค๊ฐ€ ๋ถ€์—ฌ๋ฉ๋‹ˆ๋‹ค.

์ด ํ”„๋กœ์ ํŠธ๋ฅผ ํ†ตํ•ด ํŠธ๋ž˜ํ”ฝ์— ์‚ฌ์šฉ๋˜๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ˆ˜์ค€ ํ”„๋กœํ† ์ฝœ์„ ๊ฒฐ์ •ํ•˜๊ณ  ๋„คํŠธ์›Œํฌ ํฌํŠธ์— ๋ฌถ์ด์ง€ ์•Š๊ณ  ๋„คํŠธ์›Œํฌ ํ™œ๋™์˜ ํŠน์„ฑ์„ ๋ถ„์„ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด http๊ฐ€ 80์ด ์•„๋‹Œ ํฌํŠธ์—์„œ ์ „์†ก๋˜๊ฑฐ๋‚˜ ๋ฐ˜๋Œ€๋กœ ๋‹ค๋ฅธ ๋„คํŠธ์›Œํฌ ํ™œ๋™์„ ํฌํŠธ 80์—์„œ ์‹คํ–‰ํ•˜์—ฌ http๋กœ ์œ„์žฅํ•˜๋ ค๊ณ  ํ•  ๋•Œ).

OpenDPI์™€์˜ ์ฐจ์ด์ ์—๋Š” ์ถ”๊ฐ€ ํ”„๋กœํ† ์ฝœ ์ง€์›, Windows ํ”Œ๋žซํผ์œผ๋กœ ํฌํŒ…, ์„ฑ๋Šฅ ์ตœ์ ํ™”, ์‹ค์‹œ๊ฐ„ ํŠธ๋ž˜ํ”ฝ ๋ชจ๋‹ˆํ„ฐ๋ง ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ์‚ฌ์šฉํ•˜๊ธฐ ์œ„ํ•œ ์ ์‘(์—”์ง„ ์†๋„๋ฅผ ๋Šฆ์ถ”๋Š” ์ผ๋ถ€ ํŠน์ • ๊ธฐ๋Šฅ์ด ์ œ๊ฑฐ๋จ), Linux ์ปค๋„ ๋ชจ๋“ˆ ๋ฐ ํ•˜์œ„ ํ”„๋กœํ† ์ฝœ ์ •์˜ ์ง€์›.

OpenVPN, Tor, QUIC, SOCKS, BitTorrent ๋ฐ IPsec๋ถ€ํ„ฐ Telegram, Viber, WhatsApp, PostgreSQL ๋ฐ GMail, Office247 GoogleDocs ๋ฐ YouTube ํ˜ธ์ถœ์— ์ด๋ฅด๊ธฐ๊นŒ์ง€ ์ด 365๊ฐœ์˜ ํ”„๋กœํ† ์ฝœ ๋ฐ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ •์˜๊ฐ€ ์ง€์›๋ฉ๋‹ˆ๋‹ค. ์•”ํ˜ธํ™” ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ”„๋กœํ† ์ฝœ(์˜ˆ: Citrix Online ๋ฐ Apple iCloud)์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋Š” ์„œ๋ฒ„ ๋ฐ ํด๋ผ์ด์–ธํŠธ SSL ์ธ์ฆ์„œ ๋””์ฝ”๋”๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. nDPIreader ์œ ํ‹ธ๋ฆฌํ‹ฐ๋Š” ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ํ†ตํ•ด pcap ๋คํ”„ ๋‚ด์šฉ์ด๋‚˜ ํ˜„์žฌ ํŠธ๋ž˜ํ”ฝ์„ ๋ถ„์„ํ•˜๊ธฐ ์œ„ํ•ด ์ œ๊ณต๋ฉ๋‹ˆ๋‹ค.

$ ./nDPIreader -i eth0 -s 20 -f "host 192.168.1.10" ๊ฐ์ง€๋œ ํ”„๋กœํ† ์ฝœ: DNS ํŒจํ‚ท: 57๋ฐ”์ดํŠธ: 7904 ํ๋ฆ„: 28 SSL_No_Cert ํŒจํ‚ท: 483๋ฐ”์ดํŠธ: 229203 ํ๋ฆ„: 6 FaceBook ํŒจํ‚ท: 136๋ฐ”์ดํŠธ: 74702 ํ๋ฆ„: DropBox ํŒจํ‚ท 4๊ฐœ: 9๋ฐ”์ดํŠธ: 668 ํ๋ฆ„: 3 Skype ํŒจํ‚ท: 5๋ฐ”์ดํŠธ: 339 ํ๋ฆ„: 3 Google ํŒจํ‚ท: 1700๋ฐ”์ดํŠธ: 619135 ํ๋ฆ„: 34

์ƒˆ ๋ฆด๋ฆฌ์Šค์—์„œ:

  • ์•”ํ˜ธํ™”๋œ ํŠธ๋ž˜ํ”ฝ ๋ถ„์„ ๋ฐฉ๋ฒ•(ETA - ์•”ํ˜ธํ™”๋œ ํŠธ๋ž˜ํ”ฝ ๋ถ„์„)์— ๋Œ€ํ•œ ์ง€์›์ด ํ–ฅ์ƒ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • ํ–ฅ์ƒ๋œ JA3+ TLS ํด๋ผ์ด์–ธํŠธ ์‹๋ณ„ ๋ฐฉ๋ฒ•์— ๋Œ€ํ•œ ์ง€์›์ด ๊ตฌํ˜„๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฅผ ํ†ตํ•ด ์—ฐ๊ฒฐ ํ˜‘์ƒ ๊ธฐ๋Šฅ ๋ฐ ์ง€์ •๋œ ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ์—ฐ๊ฒฐ์„ ์„ค์ •ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋˜๋Š” ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ๊ฒฐ์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค(์˜ˆ: Tor ๋ฐ ๋‹ค๋ฅธ ์ผ๋ฐ˜์ ์ธ ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ). ์ด์ „์— ์ง€์›๋œ JA3 ๋ฐฉ๋ฒ•๊ณผ ๋‹ฌ๋ฆฌ JA3+๋Š” ๊ฑฐ์ง“ ๊ธ์ •์ด ๋” ์ ์Šต๋‹ˆ๋‹ค.
  • ์‹๋ณ„๋œ ๋„คํŠธ์›Œํฌ ์œ„ํ˜‘ ๋ฐ ์†์ƒ ์œ„ํ—˜(ํ๋ฆ„ ์œ„ํ—˜)๊ณผ ๊ด€๋ จ๋œ ๋ฌธ์ œ์˜ ์ˆ˜๊ฐ€ 33๊ฐœ๋กœ ํ™•์žฅ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๋ฐ์Šคํฌํ†ฑ ๋ฐ ํŒŒ์ผ ๊ณต์œ , ์˜์‹ฌ์Šค๋Ÿฌ์šด HTTP ํŠธ๋ž˜ํ”ฝ, ์•…์„ฑ JA3 ๋ฐ SHA1, ๋ฌธ์ œ๊ฐ€ ์žˆ๋Š” ์•ก์„ธ์Šค์— ๊ด€๋ จ๋œ ์ƒˆ๋กœ์šด ์œ„ํ˜‘ ํƒ์ง€๊ธฐ๊ฐ€ ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๋„๋ฉ”์ธ ๋ฐ ์ž์œจ ์‹œ์Šคํ…œ, ์˜์‹ฌ์Šค๋Ÿฌ์šด ํ™•์žฅ ๊ธฐ๋Šฅ์ด ์žˆ๊ฑฐ๋‚˜ ์œ ํšจ ๊ธฐ๊ฐ„์ด ๋„ˆ๋ฌด ๊ธด TLS ์ธ์ฆ์„œ ์‚ฌ์šฉ.
  • ๋Œ€ํญ์ ์ธ ์„ฑ๋Šฅ ์ตœ์ ํ™”๊ฐ€ ์ด๋ฃจ์–ด์กŒ์œผ๋ฉฐ, ๋ธŒ๋žœ์น˜ 3.0์— ๋น„ํ•ด ํŠธ๋ž˜ํ”ฝ ์ฒ˜๋ฆฌ ์†๋„๊ฐ€ 2.5๋ฐฐ ํ–ฅ์ƒ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • IP ์ฃผ์†Œ๋กœ ์œ„์น˜๋ฅผ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•œ GeoIP ์ง€์›์ด ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • RSI(์ƒ๋Œ€ ๊ฐ•๋„ ์ง€์ˆ˜) ๊ณ„์‚ฐ์„ ์œ„ํ•œ API๊ฐ€ ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • ์กฐ๊ฐํ™” ์ œ์–ด๊ฐ€ ๊ตฌํ˜„๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • ํ๋ฆ„ ๊ท ์ผ์„ฑ(์ง€ํ„ฐ) ๊ณ„์‚ฐ์„ ์œ„ํ•œ API๊ฐ€ ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • ํ”„๋กœํ† ์ฝœ ๋ฐ ์„œ๋น„์Šค์— ๋Œ€ํ•œ ์ง€์› ์ถ”๊ฐ€: BetweenUs, AVAST SecureDNS, CPHA(CheckPoint High Availability Protocol), DisneyPlus, DTLS, Genshin Impact, HP Virtual Machine Group Management(hpvirtgrp), Mongodb, Pinterest, Reddit, Snapchat VoIP, Tumblr, Virtual Assitant( ์•Œ๋ ‰์‚ฌ, ์‹œ๋ฆฌ), Z39.50.
  • AnyDesk, DNS, Hulu, DCE/RPC, dnscrypt, Facebook, Fortigate, FTP Control, HTTP, IEC104, IEC60870, IRC, Netbios, Netflix, Ookla speedtest, openspeedtest.com, Outlook/MicrosoftMail, QUIC, RTSP์˜ ๊ตฌ๋ฌธ ๋ถ„์„ ๋ฐ ๊ฐ์ง€ ๊ฐœ์„  ํ”„๋กœํ† ์ฝœ, HTTP๋ฅผ ํ†ตํ•œ RTSP, SNMP, Skype, SSH, Steam, STUN, TeamViewer, TOR, TLS, UPnP, wireguard.

์ถœ์ฒ˜ : opennet.ru

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€