Kusanthula kwakuyenda Wosanthula amatenga ntchito yayikulu yaluntha ndipo, pogwiritsa ntchito ma algorithms osiyanasiyana pamitsinje, amapeza mfundo zina. Mwachitsanzo, monga gawo la ntchito ya IT, wosanthula wotere amatha kuzindikira zovuta za netiweki kapena kusanthula kuchuluka kwa magalimoto pamsewu kuti muwonjezere kukhathamiritsa kwa netiweki. Ndipo pofuna chitetezo chazidziwitso, wosanthula wotere amatha kuzindikira kutayikira kwa data, kufalikira kwa code yoyipa kapena kuwukira kwa DoS.
Musaganize kuti zomangamanga zitatuzi ndizovuta kwambiri - zosankha zina zonse (kupatula, mwinamwake, machitidwe owunikira maukonde akugwira ntchito ndi SNMP ndi RMON) amagwiranso ntchito molingana ndi izo. Tili ndi jenereta ya data kuti tifufuze, zomwe zingakhale chipangizo cha intaneti kapena choyimira chokha. Tili ndi dongosolo lotolera ma alarm komanso dongosolo loyang'anira zowunikira zonse. Zigawo ziwiri zomaliza zimatha kuphatikizidwa mkati mwa node imodzi, koma mu maukonde ochulukirapo kapena ochepa nthawi zambiri zimafalikira pazida zosachepera ziwiri kuti zitsimikizire kudalirika komanso kudalirika.
Mosiyana ndi kusanthula kwa paketi, komwe kumachokera pakuphunzira mutu ndi thupi la paketi iliyonse ndi magawo omwe amakhala nawo, kusanthula kwamayendedwe kumadalira kusonkhanitsa metadata yokhudza kuchuluka kwa maukonde. Liti, mochuluka bwanji, kuchokera kuti ndi kuti, bwanji ... awa ndi mafunso omwe ayankhidwa ndi kusanthula kwa telemetry network pogwiritsa ntchito njira zosiyanasiyana zoyenda. Poyambirira, adagwiritsidwa ntchito kusanthula ziwerengero ndikupeza zovuta za IT pamaneti, koma, monga njira zowunikira zidapangidwa, zidakhala zotheka kuziyika pa telemetry yomweyo pazolinga zachitetezo. Ndikoyenera kudziwanso kuti kusanthula kwamayendedwe sikulowa m'malo kapena kulowetsa paketi. Iliyonse mwa njirazi ili ndi malo ake ogwiritsira ntchito. Koma m'nkhaniyi, ndikuwunika kwamayendedwe komwe kuli koyenera kuyang'anira zomangamanga zamkati. Muli ndi zida zapaintaneti (kaya zimagwira ntchito paradigm yofotokozedwa ndi pulogalamu kapena motsatira malamulo osasunthika) zomwe kuwukira sikungadutse. Imatha kudutsa sensa yapamwamba ya IDS, koma chipangizo cha netiweki chomwe chimathandizira protocol yothamanga sichingathe. Uwu ndiye ubwino wa njirayi.
Kumbali ina, ngati mukufuna umboni wazamalamulo kapena gulu lanu lofufuza zochitika, simungachite popanda paketi - telemetry network sikopera kwa magalimoto omwe angagwiritsidwe ntchito kusonkhanitsa umboni; ndizofunikira kuti zizindikire mwachangu komanso kupanga zisankho pankhani yachitetezo chazidziwitso. Kumbali ina, pogwiritsa ntchito kusanthula kwa telemetry, mukhoza "kulemba" osati magalimoto onse a pa intaneti (ngati pali chilichonse, Cisco imagwira ntchito ndi malo opangira deta :-), koma zomwe zimakhudzidwa ndi kuukira. Zida zowunikira ma telemetry pankhaniyi zithandizirana ndi njira zachikhalidwe zojambulira mapaketi bwino, ndikupereka malamulo oti agwire ndikusunga. Kupanda kutero, muyenera kukhala ndi malo osungiramo zinthu zambiri.
Tiyeni tiyerekeze maukonde akugwira ntchito pa liwiro la 250 Mbit / sec. Ngati mukufuna kusunga voliyumu yonseyi, ndiye kuti mudzafunika 31 MB yosungirako kwa sekondi imodzi ya magalimoto, 1,8 GB kwa mphindi imodzi, 108 GB kwa ola limodzi, ndi 2,6 TB kwa tsiku limodzi. Kuti musunge deta yatsiku ndi tsiku kuchokera pa netiweki yokhala ndi bandwidth ya 10 Gbit/s, mudzafunika 108 TB yosungirako. Koma owongolera ena amafunikira kusunga deta yachitetezo kwa zaka ... Kujambulitsa pakufunidwa, komwe kusanthula kwamayendedwe kumakuthandizani kuti mugwiritse ntchito, kumathandizira kuchepetsa zikhalidwe izi ndi malamulo akulu. Mwa njira, ngati tilankhula za chiΕ΅erengero cha kuchuluka kwa deta yojambulidwa ya telemetry ndi deta yonse, ndiye kuti pafupifupi 1 mpaka 500. Pazikhalidwe zomwezo zomwe zaperekedwa pamwambapa, kusunga zolemba zonse za tsiku ndi tsiku. idzakhala 5 ndi 216 GB, motsatana (mutha kuyijambulitsa pagalimoto yokhazikika).
Ngati pazida zowunikira deta yaiwisi yapaintaneti, njira yolumikizira ili pafupifupi yofanana kuchokera kwa ogulitsa kupita kwa ogulitsa, ndiye pankhani ya kusanthula koyenda zinthu ndizosiyana. Pali zosankha zingapo zama protocol otaya, kusiyana komwe muyenera kudziwa pankhani yachitetezo. Chodziwika kwambiri ndi Netflow protocol yopangidwa ndi Cisco. Pali mitundu ingapo ya protocol iyi, yosiyana ndi kuthekera kwawo komanso kuchuluka kwa zidziwitso zamagalimoto zojambulidwa. Mtundu wapano ndi wachisanu ndi chinayi (Netflow v9), pamaziko omwe muyezo wamakampani Netflow v10, womwe umadziwikanso kuti IPFIX, unapangidwa. Masiku ano, ogulitsa ma network ambiri amathandizira Netflow kapena IPFIX pazida zawo. Koma pali zosankha zina zosiyanasiyana zama protocol otaya - sFlow, jFlow, cFlow, rFlow, NetStream, ndi zina, zomwe sFlow ndi yotchuka kwambiri. Ndi mtundu uwu womwe nthawi zambiri umathandizidwa ndi opanga zoweta zapaintaneti chifukwa chosavuta kukhazikitsa. Kodi pali kusiyana kotani pakati pa Netflow, yomwe yakhala de facto standard, ndi sFlow? Ndikufuna kuwunikira zingapo zofunika. Choyamba, Netflow ili ndi magawo osinthika ogwiritsa ntchito mosiyana ndi minda yokhazikika mu sFlow. Ndipo kachiwiri, ndipo ichi ndi chinthu chofunika kwambiri kwa ife, sFlow amasonkhanitsa otchedwa sampuli telemetry; mosiyana ndi yosatsatiridwa ya Netflow ndi IPFIX. Kodi pali kusiyana kotani pakati pawo?
Tangoganizani kuti mwasankha kuwerenga bukuli "Security Operations Center: Kumanga, Kugwira Ntchito, ndi Kusamalira SOC yanuβ ya anzanga - Gary McIntyre, Joseph Munitz ndi Nadem Alfardan (mutha kutsitsa gawo la bukhuli pa ulalo). Muli ndi zinthu zitatu zomwe mungachite kuti mukwaniritse cholinga chanu - werengani buku lonse, fufuzani mozama, kuyima patsamba lililonse la 10 kapena 20, kapena yesani kupezanso mfundo zazikuluzikulu pabulogu kapena ntchito ngati SmartReading. Chifukwa chake, telemetry yosatsatiridwa ikuwerenga "tsamba" lililonse la traffic network, ndiko kuti, kusanthula metadata pa paketi iliyonse. Sampled telemetry ndiye kafukufuku wosankha wamagalimoto ndikuyembekeza kuti zitsanzo zomwe zasankhidwa zimakhala ndi zomwe mukufuna. Kutengera kuthamanga kwa tchanelo, sampuli za telemetry zimatumizidwa kuti zikawunikidwe pakiti iliyonse ya 64, 200, 500, 1000, 2000 kapena 10000.
Pankhani yowunikira chitetezo chazidziwitso, izi zikutanthauza kuti telemetry yotsatiridwa ndiyoyenera kuzindikira kuukira kwa DDoS, kusanthula, ndi kufalitsa ma code oyipa, koma ikhoza kuphonya ziwopsezo za ma atomiki kapena mapaketi angapo omwe sanaphatikizidwe mu zitsanzo zomwe zatumizidwa kuti ziwunikidwe. Telemetry yosasankhidwa ilibe zovuta zotere. Ndi izi, kuchuluka kwa ziwonetsero zomwe zapezeka ndizokulirapo. Nawu mndandanda wachidule wa zochitika zomwe zitha kuzindikirika pogwiritsa ntchito zida zowunikira ma network telemetry.
Zachidziwikire, ena otsegula Netflow analyzer sangakulole kuchita izi, chifukwa ntchito yake yayikulu ndikusonkhanitsa telemetry ndikusanthula koyambira pamalingaliro a IT. Kuti muzindikire ziwopsezo zachitetezo chazidziwitso kutengera kuyenderera, ndikofunikira kukonzekeretsa analyzer ndi mainjini osiyanasiyana ndi ma aligorivimu, omwe angazindikire zovuta za cybersecurity kutengera minda yanthawi zonse ya Netflow, kulemeretsa deta yokhazikika ndi data yakunja kuchokera kuzinthu zosiyanasiyana za Threat Intelligence, ndi zina zambiri.
Chifukwa chake, ngati muli ndi chisankho, sankhani Netflow kapena IPFIX. Koma ngakhale zida zanu zimagwira ntchito ndi sFlow, monga opanga zapakhomo, ndiye kuti ngakhale pakadali pano mutha kupindula nazo pachitetezo.
M'chilimwe cha 2019, ndidasanthula kuthekera komwe opanga ma hardware aku Russia ali nawo ndi onse, kuphatikiza NSG, Polygon ndi Craftway, adalengeza kuthandizira sFlow (osachepera Zelax, Natex, Eltex, QTech, Rusteleteh).
Funso lotsatira lomwe mungakumane nalo ndi komwe mungakhazikitse thandizo lakuyenda kwachitetezo? Ndipotu funsoli silinayankhidwe molondola. Zida zamakono nthawi zonse zimathandizira ma protocol oyenda. Chifukwa chake, ndingakonzenso funsoli mosiyana - ndi kuti komwe kuli kothandiza kwambiri kusonkhanitsa telemetry kuchokera pachiwonetsero chachitetezo? Yankho lidzakhala lodziwikiratu - pamlingo wofikira, pomwe mudzawona 100% ya magalimoto onse, pomwe mudzakhala ndi chidziwitso chambiri pa makamu (MAC, VLAN, ID ya mawonekedwe), pomwe mutha kuyang'anira kuchuluka kwa magalimoto a P2P pakati pa makamu, omwe ndizofunikira pakusanthula kuzindikira ndikugawa ma code oyipa. Pakatikati, mwina simungawone kuchuluka kwa magalimoto, koma pamlingo wozungulira, mudzawona gawo limodzi mwa magawo atatu a magalimoto anu onse pa intaneti. Koma ngati pazifukwa zina muli ndi zida zakunja pamaneti anu zomwe zimalola oukira "kulowa ndi kutuluka" osadumphadumpha, ndiye kuti kusanthula telemetry sikungakupatseni chilichonse. Chifukwa chake, kuti mupeze zambiri, tikulimbikitsidwa kuti muzitha kusonkhanitsa telemetry pamlingo wofikira. Panthawi imodzimodziyo, ndizofunika kudziwa kuti ngakhale tikukamba za virtualization kapena zitsulo, chithandizo chothamanga chimapezekanso nthawi zambiri mumasinthidwe amakono, omwe amakulolani kulamulira magalimoto kumeneko.
Koma popeza ndakweza mutuwo, ndiyenera kuyankha funsoli: bwanji ngati zida, zakuthupi kapena zenizeni, sizigwirizana ndi ma protocol otaya? Kapena kodi kuphatikizidwa kwake ndikoletsedwa (mwachitsanzo, m'magawo a mafakitale kuti atsimikizire kudalirika)? Kapena kuyatsa kumabweretsa kuchuluka kwa CPU (izi zimachitika pazida zakale)? Kuti athetse vutoli, pali masensa apadera apadera (mafunde othamanga), omwe ali ogawanitsa wamba omwe amadutsa magalimoto pawokha ndikuwulutsa munjira yopita ku gawo lotolera. Zowona, munkhaniyi timapeza zovuta zonse zomwe takambirana pamwambapa pokhudzana ndi zida zojambulira paketi. Ndiko kuti, muyenera kumvetsetsa osati ubwino wa teknoloji yosanthula otaya, komanso zofooka zake.
Mfundo ina yofunika kukumbukira polankhula za otaya kusanthula zida. Ngati mogwirizana ndi njira wamba zopangira zochitika zachitetezo timagwiritsa ntchito metric ya EPS (chochitika pamphindikati), ndiye kuti chizindikirochi sichigwira ntchito pakuwunika kwa telemetry; imasinthidwa ndi FPS (kuyenda pamphindikati). Monga momwe zilili ndi EPS, sizingawerengedwe pasadakhale, koma mukhoza kulingalira chiwerengero cha ulusi umene chipangizo china chimapanga malinga ndi ntchito yake. Mutha kupeza matebulo pa intaneti okhala ndi mitengo pafupifupi yamitundu yosiyanasiyana yamabizinesi ndi momwe zinthu ziliri, zomwe zingakuthandizeni kuyerekezera zilolezo zomwe mungafune pazida zowunikira komanso momwe angapangire? Chowonadi ndi chakuti sensa ya IDS imakhala yochepa ndi bandwidth inayake yomwe imatha "kukoka", ndipo oyendetsa othamanga ali ndi malire ake omwe ayenera kumveka. Choncho, m'magulu akuluakulu, omwe amagawidwa m'madera nthawi zambiri amakhala osonkhanitsa angapo. Pamene ndinalongosola momwe maukonde amayang'aniridwa mkati mwa Cisco, Ndapereka kale chiwerengero cha osonkhanitsa athu - alipo 21. Ndipo izi ndi za maukonde amwazikana m'makontinenti asanu ndi owerengera pafupifupi theka la milioni zipangizo zogwira ntchito).
Timagwiritsa ntchito yankho lathu ngati njira yowunikira Netflow Cisco Stealthwatch, yomwe imayang'ana kwambiri kuthetsa mavuto achitetezo. Ili ndi injini zambiri zomangidwira kuti zizindikire zochitika zosasangalatsa, zokayikitsa komanso zoyipa momveka bwino, zomwe zimalola kuti zizindikire zoopsa zosiyanasiyana - kuchokera ku cryptomining mpaka kutulutsa chidziwitso, kuyambira kufalikira kwa code yoyipa mpaka chinyengo. Monga ma analyzer ambiri oyenda, Stealthwatch imamangidwa molingana ndi dongosolo la magawo atatu (jenereta - osonkhanitsa - analyzer), koma imaphatikizidwa ndi zinthu zingapo zosangalatsa zomwe zili zofunika pazomwe zikukambidwa. Choyamba, imaphatikizana ndi mayankho ojambulira paketi (monga Cisco Security Packet Analyzer), kukulolani kuti mulembe magawo osankhidwa a netiweki kuti mufufuze mozama ndikusanthula. Kachiwiri, makamaka kukulitsa ntchito zachitetezo, tapanga pulogalamu yapadera ya nvzFlow, yomwe imakulolani "kufalitsa" ntchito zamapulogalamu pama node omaliza (maseva, malo ogwirira ntchito, ndi zina zambiri) mu telemetry ndikutumiza kwa wokhometsa kuti muwunikenso. Ngati mu mtundu wake woyambirira Stealthwatch imagwira ntchito ndi protocol iliyonse yotuluka (sFlow, rFlow, Netflow, IPFIX, cFlow, jFlow, NetStream) pamanetiweki, ndiye thandizo la nvzFlow limalola kulumikizana kwa data pamlingo wa node, potero. kukulitsa mphamvu ya dongosolo lonse ndikuwona kuukira kochulukirapo kuposa kusanthula koyenda kwa intaneti.
Zikuwonekeratu kuti polankhula za machitidwe owunikira a Netflow kuchokera pamalingaliro achitetezo, msika suli ndi yankho limodzi lochokera ku Cisco. Mutha kugwiritsa ntchito zonse zamalonda ndi zaulere kapena zogawana. Ndizodabwitsa kwambiri ngati nditchula mayankho a mpikisano monga zitsanzo pa Cisco blog, kotero ine ndinena mawu ochepa za momwe network telemetry ingasankhidwe pogwiritsa ntchito awiri otchuka, ofanana ndi mayina, komabe zida zosiyana - SiLK ndi ELK.
SiLK ndi zida (System for Internet-Level Knowledge) zowunikira magalimoto, opangidwa ndi American CERT/CC ndipo amathandizira, malinga ndi nkhani yamasiku ano, Netflow (5th ndi 9th, mitundu yotchuka kwambiri), IPFIX. ndi sFlow ndi kugwiritsa ntchito zofunikira zosiyanasiyana (rwfilter, rwcount, rwflowpack, etc.) kuti achite ntchito zosiyanasiyana pa telemetry network kuti azindikire zizindikiro za zochita zosaloleka mmenemo. Koma pali mfundo zingapo zofunika kuziganizira. SiLK ndi chida cholamula chomwe chimasanthula pa intaneti polemba malamulo ngati awa (kuzindikira mapaketi a ICMP akulu kuposa ma byte 200):
Kuyesa. Tsopano ikubwera nthawi yoti tiwone kulondola kwa malingaliro athu, omwe amatsimikiziridwa kapena kutsutsidwa pogwiritsa ntchito zida za SiLK kuyambira ndi 'rw', 'set', 'chikwama'.
Kusanthula deta yeniyeni. Mu ntchito ya mafakitale, SiLK imatithandiza kuzindikira chinachake ndipo wofufuza ayenera kuyankha mafunso akuti "Kodi tinapeza zomwe tinkayembekezera?", "Kodi izi zikugwirizana ndi malingaliro athu?", "Momwe mungachepetsere chiwerengero cha zolakwika?" kuti muwonjezere kuzindikirika? Β» ndi zina zotero.
Kupititsa patsogolo. Pamapeto pake, timakonza zomwe zidachitika kale - timapanga ma tempuleti, kukonza ndikuwongolera ma code, kukonzanso ndikumveketsa malingaliro, ndi zina zambiri.
Kuzungulira uku kudzagwiranso ntchito ku Cisco Stealthwatch, yomaliza yokhayo imapanga masitepe asanuwa mpaka pamlingo waukulu, kuchepetsa kuchuluka kwa zolakwika za akatswiri ndikuwonjezera luso la kuzindikira zochitika. Mwachitsanzo, mu SiLK mungathe kulemeretsa ziwerengero zapaintaneti ndi deta yakunja pa IPs yoyipa pogwiritsa ntchito malemba olembedwa pamanja, ndipo mu Cisco Stealthwatch ndi ntchito yomanga yomwe imasonyeza nthawi yomweyo alamu ngati magalimoto amtundu ali ndi machitidwe ndi ma adiresi a IP kuchokera pamndandanda wakuda.
Ngati mupita pamwamba pa piramidi "yolipidwa" pa pulogalamu yowunikira maulendo, ndiye kuti pambuyo pa SiLK yaulere padzakhala ELK ya shareware, yomwe ili ndi zigawo zitatu zofunika kwambiri - Elasticsearch (indexing, searching and data analysis), Logstash (kulowetsa / kutulutsa deta). ) ndi Kibana (kuona). Mosiyana ndi SiLK, komwe muyenera kulemba zonse nokha, ELK ili kale ndi malaibulale / ma module ambiri (ena amalipidwa, ena osatero) omwe amawunikira kusanthula kwa ma telemetry network. Mwachitsanzo, fyuluta ya GeoIP mu Logstash imakupatsani mwayi wogwirizanitsa ma adilesi a IP omwe amawunikidwa ndi malo omwe ali (Stealthwatch ili ndi izi).
ELK ilinso ndi gulu lalikulu lomwe likukwaniritsa zomwe zikusowa panjira yowunikirayi. Mwachitsanzo, kuti mugwire ntchito ndi Netflow, IPFIX ndi sFlow mutha kugwiritsa ntchito gawoli elastiflow, ngati simukukhutira ndi Logstash Netflow Module, yomwe imangothandiza Netflow.
Ngati mulibe chochita ndipo mukugwiritsa ntchito zida za netiweki zaku Russia, sankhani imodzi yomwe imathandizira ma protocol kapena ili ndi madoko a SPAN/RSPAN.
Ponena za nsonga yomaliza, ndikufuna ndipereke fanizo lomwe ndapereka kale. Mukuwona kuti ngati kale Cisco chidziwitso chachitetezo chachitetezo pafupifupi chimamanga dongosolo lake lowunikira zidziwitso pamaziko a njira zodziwikiratu ndi njira zosayina, tsopano amawerengera 20% yokha ya zochitika. 20% ina imagwera pamakina osanthula oyenda, omwe akuwonetsa kuti mayankho awa siwongopeka, koma chida chenicheni muzochita zachitetezo chazidziwitso zamakampani amakono. Kuphatikiza apo, muli ndi chinthu chofunikira kwambiri pakukhazikitsa kwawo - zomangamanga zama network, ndalama zomwe zitha kutetezedwa popereka ntchito zowunikira chitetezo pamaneti.
Ine makamaka sindinakhudze pa mutu wa kuyankha anomalies kapena ziwopsezo zodziwika mu maukonde umayenda, koma ine ndikuganiza kuti zaonekeratu kuti kuyang'anira sikuyenera kutha kokha ndi kuzindikira kuopseza. Iyenera kutsatiridwa ndi kuyankha ndipo makamaka mumayendedwe odzipangira okha. Koma uwu ndi mutu wa nkhani ina.