Iyo kambani AOL
Iyo purojekiti yakagadzirwa muna 2012 nechinangwa chekugadzira yakavhurika kutsiva yekutengeserana network packet processing platform inogona kukwira kusvika kuAOL traffic volumes. Kuitwa kwehurongwa hutsva muAOL kwakaita kuti zvikwanise kuwana kutonga kwakazara pamusoro pezvivakwa nekuda kwekuiswa pamasevha ayo uye kuderedza zvakanyanya mutengo - kushandisa Moloch kutora zvachose traffic mune ese maAOL network inodhura yakaenzana kana uchishandisa.
Session metadata inonongedzwa muinjini-yakavakirwa cluster
Moloch inosanganisira maturusi ekutora uye indexing traffic mune yekuzvarwa PCAP fomati, pamwe nekukurumidza kuwana kune indexed data. Kuti uongorore ruzivo rwakaunganidzirwa, webhu interface inopihwa iyo inobvumidza iwe kufamba, kutsvaga uye kutumira masampula. Zvakare zvakapihwa
Moloch ine zvikamu zvitatu zvakakosha:
- Iyo traffic yekutora system ndeye yakawanda-yakarukwa C application yekutarisa traffic, kunyora marasi muPCAP fomati kune diski, kufambisa mapaketi akabatwa uye kutumira metadata nezve masesheni (SPI, Stateful packet inspection) uye mapuroteni kuElasticsearch cluster. Zvinogoneka kuchengeta mafaira ePCAP mune encrypted fomu.
- Iyo yewebhu interface yakavakirwa paNode.js papuratifomu, iyo inomhanya pane yega yega traffic traffic server uye inogadzirisa zvikumbiro zvine chekuita nekuwana indexed data uye kuendesa PCAP mafaera kuburikidza.
API . - Metadata chengetedzo yakavakirwa paElasticsearch.
Iyo yewebhu interface inopa akati wandei ekuona modhi - kubva kune akajairwa manhamba, mamepu ekubatanidza uye anoona magirafu ane data pamusoro pekuchinja kwetiweki chiitiko kune zvishandiso zvekudzidza zvidzidzo zvega, kuongorora chiitiko mumamiriro ezvibvumirano zvakashandiswa uye kupatsanura data kubva kuPCAP dumps.
- Shanduko yaitwa pakushandisa fomati isina kutaipa yekuisa indexing muElasticsearch.
- Yakawedzerwa mienzaniso yemafirita ekutora traffic muLua.
- Tsigiro ye46-draft vhezheni yeQUIC protocol yaitwa.
- Iyo kodhi yekuparura maprotocol yakagadziridzwa, zvichiita kuti zvikwanise kunyora parsers yeEthernet uye IP level protocol.
- New parsers yakakurudzirwa kune arp, bgp, igmp, isis, lldp, ospf uye pim protocol, pamwe nemaparser easingazivikanwe unkEthernet uye unkIpProtocol protocol.
- Yakawedzera sarudzo yekudzima zvakasarudzika (disableParsers).
- Iko kugona kuratidza chero nzvimbo yakazara pamachati, yakaiswa pane peji rezvirongwa, yakawedzerwa kune yewebhu interface.
- Magirafu nemazita zvino anogona kuomeswa nechando uye kusafamba kana uchikwenya peji.
- Mabhawa mazhinji ekufambisa akavanzwa kana kupunzika nekusarudzika.
Source: opennet.ru