Inkampani ye-AOL
Le projekthi yenziwe ngo-2012 ngenjongo yokudala ukutshintshwa okuvulekileyo kweplatifomu yokuthengisa ipakethe yenethiwekhi enokuthi ifikelele kwi-AOL traffic volumes. Ukuphunyezwa kwenkqubo entsha kwi-AOL kwenza kube lula ukuphumeza ulawulo olupheleleyo kwiziseko ezingundoqo ngenxa yokuthunyelwa kwiiseva zayo kunye nokunciphisa kakhulu iindleko - usebenzisa i-Moloch ukubamba ngokupheleleyo i-traffic kuzo zonke iinethiwekhi ze-AOL zibiza imali efanayo xa usebenzisa.
Imetadata yeseshoni ifakwe kwi-indexed cluster esekelwe kwi-injini
I-Moloch iquka izixhobo zokubamba kunye ne-indexing traffic kwifomathi ye-PCAP yendabuko, kunye nokufikelela ngokukhawuleza kwidatha enesalathisi. Ukuhlalutya ulwazi oluqokelelweyo, i-interface yewebhu inikezelwa evumela ukuba uhambe, ukhangele kwaye ukhuphe iisampuli. Kubonelelwe kwakhona
IMoloch inamacandelo amathathu asisiseko:
- Inkqubo yokubamba i-traffic system yi-multi-threaded C yesicelo sokubeka iliso kwi-traffic, ukubhala ukulahla kwifomathi ye-PCAP kwi-disk, ukucazulula iipakethi ezifakiwe kunye nokuthumela i-metadata malunga neeseshoni (SPI, ukuhlolwa kwepakethi ye-Stateful) kunye neeprotocol kwi-cluster ye-Elasticsearch. Kuyenzeka ukugcina iifayile zePCAP kwifom efihliweyo.
- Ujongano lwewebhu olusekwe kwiqonga leNode.js, elisebenza kwiseva yokubanjwa kwetrafikhi nganye kunye neenkqubo zezicelo ezinxulumene nokufikelela kwidatha enesalathisi kunye nokudlulisa iifayile zePCAP nge.
API . - Ugcino lwemetadata olusekwe kwi-Elasticsearch.
Ujongano lwewebhu lubonelela ngeendlela ezininzi zokujonga - ukusuka kwiinkcukacha-manani ngokubanzi, iimephu zoqhagamshelo kunye neegrafu ezibonakalayo ezinedatha malunga notshintsho kumsebenzi womnatha ukuya kwizixhobo zokufunda iiseshoni zomntu ngamnye, ukuhlalutya umsebenzi kumxholo wemigaqo esetyenziswayo kunye nokwahlulahlula idatha kwi-PCAP yokulahla.
Π
- Utshintsho lwenziwe ekusebenziseni ifomati engachwetheziyo ukulungiselela isalathiso kwi-Elasticsearch.
- Imizekelo eyongeziweyo yezihluzi zokubanjwa kwetrafikhi eLua.
- Inkxaso ye-46-draft version ye-QUIC protocol iphunyeziwe.
- Ikhowudi yokwahlulahlula iiprothokholi iye yaphinda yasetyenziswa, nto leyo eyenza kube lula ukubhala abahlalutyi be-Ethernet kunye neeprothokholi zenqanaba le-IP.
- Abahlalutyi abatsha baye bandululwa kwiiprothokholi ze-arp, i-bgp, igmp, isis, lldp, ospf kunye ne-pim, kunye noluhlu lweeprotocol ezingaziwayo ze-unkEthernet kunye ne-unkIpProtocol.
- Kongezwe ukhetho lokuvala ngokukhethiweyo abahluli (disableParsers).
- Ukukwazi ukubonisa nayiphi na indawo edibeneyo kwiitshathi, ezibekwe kwiphepha lezicwangciso, zongezwe kujongano lwewebhu.
- Iigrafu kunye nezihloko ngoku zinokumiswa kwaye zingashukumi xa kuskrolwa iphepha.
- Uninzi lweebar zokukhangela zifihliwe okanye zidilike ngokungagqibekanga.
umthombo: opennet.ru