Kuburitswa kwenDPI 4.8 yakadzika packet yekuongorora system

Iyo ntop purojekiti, iyo inovandudza maturusi ekutora uye kuongorora traffic, yakaburitsa kuburitswa kwenDPI 4.8 yakadzika packet yekuongorora toolkit, inoenderera mberi nekuvandudzwa kweraibhurari yeOpenDPI. Iyo nDPI purojekiti yakavambwa mushure mekuyedza kusabudirira kusundira shanduko kune OpenDPI repository, iyo yakasara isina kuchengetedzwa. Iyo nDPI kodhi yakanyorwa muC uye ine rezinesi pasi pe LGPLv3.

Iyo sisitimu inobvumidza iwe kuti uone iyo application-level maprotocol anoshandiswa mutraffic, uchiongorora mamiriro etiweki chiitiko pasina kusungirirwa kune network ports (inogona kuona zvinonyatsozivikanwa maprotocol ayo vanobata vanogamuchira kubatana pane asiri-standard network ports, semuenzaniso, kana http isina kutumirwa kubva pachiteshi 80, kana, ukuwo, apo iyo Vari kuedza kuvhara mamwe mabasa etiweki se http nekuimhanyisa pachiteshi 80).

Misiyano kubva kuOpenDPI inosanganisira tsigiro yemamwe maprotocol, kuendesa kuWindows platform, performance optimization, gadziriso yekushandiswa mune chaiyo-nguva yekutarisa traffic traffic application (mamwe maficha akadzikisa injini akabviswa), kugona kuvaka nenzira ye Linux kernel module, uye rutsigiro rwekutsanangura subprotocols.

Inotsigira kuwonekwa kwemhando makumi mashanu nenhatu dzekutyisidzira kwenetiweki (njodzi yekuyerera) uye anopfuura mazana matatu nemakumi mashanu mapuroteni uye maapplication (kubva OpenVPN, Tor, QUIC, SOCKS, BitTorrent uye IPsec kuenda kuTeregiramu, Viber, WhatsApp, PostgreSQL uye kufona kuGmail, Hofisi 53, Google Docs. uye YouTube). Kune sevha uye mutengi SSL chitupa decoder iyo inokutendera iwe kuti uone iyo protocol (semuenzaniso, Citrix Online uye Apple iCloud) uchishandisa encryption chitupa. Iyo nDPIreader utility inopihwa kuti iongorore zviri mukati pcap dumps kana yazvino traffic kuburikidza netiweki interface.

Mukuburitswa kutsva:

  • Kushandiswa kwendangariro kwakaderedzwa nemirairo yehukuru, nekuda kwekugadzirisazve kwekuita kwezvinyorwa.
  • IPv6 rutsigiro rwakawedzerwa.
  • Yakawedzera mitsva yeprotocol identifiers ine chekuita nevakuru zvemukati, kushambadzira, webhu analytics uye yekutevera.
  • Yakawedzera rutsigiro rweprotocol nemasevhisi:
    • HAProxy
    • Apache Thrift
    • RMCP (Remote Management Control Protocol)
    • SLP (Sevhisi Nzvimbo Protocol)
    • Bitcoin
    • HTTP/2 pasina encryption
    • SRTP (Chengetedza Chaiyo-Nguva Yekufambisa)
    • BACnet
    • OICQ (mutumwa wechiChinese)
  • Yakawedzerwa tsananguro yeOperaVPN uye ProtonVPN. Yakavandudzwa Wireguard yekuona.
  • Yakatemerwa heuristics yekuona yakazara encrypted traffic inoyerera.
  • Yakawedzerwa tsananguro yeYandex uye VK masevhisi.
  • Yakawedzera kutariswa kweFacebook reels uye nyaya.
  • Yakawedzerwa tsananguro yeRoblox yemitambo papuratifomu, NVIDIA GeForceNow gore sevhisi, Epic Mitambo mitambo, uye mutambo "Heroes of the Storm".
  • Kuvandudzwa kwekuona kwetraffic kubva pakutsvaga bots.
  • Kuvandudzwa kwekupatsanurwa uye kuzivikanwa kweprotocol nemasevhisi:
    • gnutella
    • H323
    • HTTP
    • Tandara
    • MS Mapoka
    • Alibaba
    • MGCP
    • chiutsi
    • MySQL
    • Zabbix
  • Huwandu hwekutyisidzira kwenetiweki uye matambudziko ane chekuita nenjodzi yekukanganisika (njodzi yekuyerera) yakawedzerwa. Yakawedzerwa rutsigiro rwemhando itsva dzekutyisidzira: NDPI_MALWARE_HOST_CONTACTED uye NDPI_TLS_ALPN_SNI_MISMATCH.
  • Fuzzing kuyedzwa kwakarongeka kuona matambudziko ekuvimbika.
  • Matambudziko nekuvaka paFreeBSD akagadziriswa.

Source: opennet.ru

Voeg