I-Project Salmon: ungamelana kanjani ngempumelelo nokuhlolwa kwe-inthanethi usebenzisa ama-proxi anamazinga okuthenjwa komsebenzisi

I-Project Salmon: ungamelana kanjani ngempumelelo nokuhlolwa kwe-inthanethi usebenzisa ama-proxi anamazinga okuthenjwa komsebenzisi

Ohulumeni bamazwe amaningi, ngandlela thize, banciphisa ukufinyelela kwezakhamuzi ukwaziswa nezinkonzo kuyi-Internet. Ukulwa nokuhlolwa okunjalo kuwumsebenzi obalulekile futhi onzima. Ngokuvamile, izixazululo ezilula azikwazi ukuziqhayisa ngokwethembeka okuphezulu noma ukusebenza kahle kwesikhathi eside. Izindlela eziyinkimbinkimbi kakhulu zokunqoba ukuvinjelwa zinezinkinga mayelana nokusebenziseka, ukusebenza okuphansi, noma ukungavumeli ukugcinwa kwekhwalithi yokusetshenziswa kwe-inthanethi ezingeni elifanele.

Iqembu lososayensi baseMelika abavela eNyuvesi yase-Illinois ithuthukile indlela entsha yokunqoba ukuvinjwa, esekelwe ekusetshenzisweni kobuchwepheshe be-proxy, kanye nokuhlukanisa abasebenzisi ngezinga lokuthembela ukuze babone ngempumelelo ama-agent asebenzela ama-censors. Sethula ekunakeni kwakho izihloko eziyinhloko zalo msebenzi.

Incazelo yendlela yokwenza

Ososayensi benze ithuluzi elibizwa ngokuthi i-Salmon, uhlelo lwamaseva elibamba oluqhutshwa amavolontiya avela emazweni ngaphandle kwemingcele ekusetshenzisweni kwe-inthanethi. Ukuze kuvikelwe lawa maseva ukuthi angavinjwa ama-censor, isistimu isebenzisa i-algorithm ekhethekile yokunikeza ileveli yokwethembeka kubasebenzisi.

Indlela ibandakanya ukudalula ama-ejenti okucwaninga anamandla azenza abasebenzisi abajwayelekile ukuze bathole ikheli lasesizindeni se-inthanethi leseva elibamba futhi bavinjwe. Ngaphezu kwalokho, ukuphikiswa Ukuhlasela kukaSibyl kwenziwa ngezidingo zokuhlinzeka, lapho kubhaliswa ohlelweni, isixhumanisi se-akhawunti evumelekile yokuxhumana nomphakathi noma ukuthola izincomo kumsebenzisi onokwethenjwa okuphezulu.

Kanjani lo msebenzi

I-censor kufanele ibe yinhlangano elawulwa uhulumeni enekhono lokulawula noma iyiphi i-router ngaphakathi kwezwe. Kuphinde kucatshangwe ukuthi umsebenzi we-censor ukuvimba ukufinyelela ezinsizeni ezithile, hhayi ukukhomba abasebenzisi ukuze baboshwe. Uhlelo alukwazi ukuvimbela ukuthuthukiswa kwezenzakalo nganoma iyiphi indlela - umbuso unamathuba amaningi okuthola ukuthi yiziphi izinsizakalo ezisetshenziswa izakhamuzi. Enye yazo ukusetshenziswa kwamaseva e-honeypot ukuvimbela ukuxhumana.

Kuphinde kucatshangelwe ukuthi umbuso unezinsiza ezibalulekile, okuhlanganisa nezabasebenzi. I-censor ingaxazulula izinkinga ezidinga amakhulu noma izinkulungwane zezisebenzi zesikhathi esigcwele.

Amanye amaphuzu ayisisekelo ambalwa:

  • Inhloso yesistimu ukuhlinzeka ngekhono lokudlula ukuvinjwa (okungukuthi, ukunikeza ikheli le-IP leseva elibamba) kubo bonke abasebenzisi abahlala ezifundeni ezinokuhlolwa okuku-inthanethi.
  • Ama-ejenti/abasebenzi beziphathimandla zokuhlolwa kwe-inthanethi neminyango bangase bazame ukuxhuma ohlelweni ngokucasha abasebenzisi abajwayelekile.
  • I-censor ingavimba noma iyiphi iseva elibamba ikheli layo elaziwa nguye.
  • Kulokhu, abahleli bohlelo lwe-Salmon bayaqonda ukuthi isithwebuli sifunde ikheli leseva ngandlela thile.

Konke lokhu kusiletha encazelweni yezingxenye ezintathu ezibalulekile zohlelo lokunqoba ukuvinjwa.

  1. Isistimu ibala amathuba okuthi umsebenzisi umenzeli wezinhlangano ezihlola. Abasebenzisi okutholakala ukuthi banamathuba amaningi okuba ngabenzeli abanjalo bayavinjelwa.
  2. Wonke umsebenzisi unezinga lokwethenjwa okufanele alizuzwe. Ama-proxi asebenza ngokushesha anikezelwe kubasebenzisi abanamazinga aphezulu okuthembana. Ngaphezu kwalokho, lokhu kukuvumela ukuthi uhlukanise abasebenzisi abanokwethenjelwa, abahlolwe isikhathi kwabasanda kufika, ngoba phakathi kwabo kungenzeka ukuthi babe ngama-censor agents.
  3. Abasebenzisi abaneleveli ephezulu yokuthembeka bangamema abasebenzisi abasha ohlelweni. Umphumela uyigrafu yomphakathi yabasebenzisi abathembekile.

Konke kunengqondo: i-censor ngokuvamile idinga ukuvimba iseva elibamba lapha futhi manje; ngeke alinde isikhathi eside ukuze azame "ukumpompa" ama-akhawunti ama-ejenti akhe ohlelweni. Ngaphezu kwalokho, kuyacaca futhi ukuthi abasebenzisi abasha bangase baqale bathole amazinga ahlukene okuthenjwa - isibonelo, abangani nezihlobo zabadali bephrojekthi mancane amathuba okuba babambisane nezifunda zokucwaninga.

Amazinga Okwethenjwa: Imininingwane Yokusetshenziswa

Kukhona izinga lokuthembana hhayi phakathi kwabasebenzisi kuphela, kodwa naphakathi kwamaseva wommeleli. Uhlelo lunikeza umsebenzisi ileveli ethile iseva eneleveli yokwethenjwa efanayo. Ngesikhathi esifanayo, izinga lokuthembela komsebenzisi lingakhula noma linciphise, futhi esimweni samaseva likhula kuphela.

Ngaso sonke isikhathi lapho ama-censor avimba iseva eyayisetshenziswa umsebenzisi othile, izinga labo lokuthemba liyehla. Ukwethenjwa kuyanda uma iseva ingavinjwanga isikhathi eside - kuleveli entsha ngayinye isikhathi esidingekayo siyaphindwa kabili: ukuze usuke kuleveli n uye ku-n+1, ​​udinga izinsuku ezingu-2n+1 zokusebenza okungaphazanyiswa kweseva elibamba. Indlela eya ezingeni eliphezulu, lesithupha, lokuthembela kuthatha ngaphezu kwezinyanga ezimbili.

I-Project Salmon: ungamelana kanjani ngempumelelo nokuhlolwa kwe-inthanethi usebenzisa ama-proxi anamazinga okuthenjwa komsebenzisi

Ukulinda isikhathi eside kangako ukuze uthole amakheli eziphakeli ezingcono kakhulu zommeleli kuyisinyathelo esisebenza kahle kakhulu sokumelana nama-censors.

Izinga lokwethenjwa leseva liyizinga eliphansi lokuthenjwa elinikezwe abasebenzisi. Isibonelo, uma iseva entsha ohlelweni yabelwe abasebenzisi, phakathi kwabo isilinganiso esincane esingu-2, khona-ke ummeleli uzophinde athole okufanayo. Uma-ke umuntu onesilinganiso esingu-3 eqala ukusebenzisa iseva, kodwa abasebenzisi abavela ezingeni lesibili nabo basala, khona-ke isilinganiso seseva sizoba ngu-2. Uma bonke abasebenzisi beseva bekhuphule izinga, khona-ke liyakhuphuka kummeleli. Ngesikhathi esifanayo, iseva ayikwazi ukulahlekelwa izinga layo lokwethenjwa, ngokuphambene nalokho, uma ivinjiwe, abasebenzisi bazohlawuliswa.

Abasebenzisi abanezinga eliphezulu lokwethembeka bathola izinhlobo ezimbili zemiklomelo. Okokuqala, amaseva awafani. Kunezidingo ezincane zomkhawulokudonsa (100 Kbps), kodwa umnikazi weseva yevolontiya anganikeza okwengeziwe - awukho umkhawulo ophezulu. Uhlelo lwe-Salmon lukhetha amaseva akhiqiza kakhulu kubasebenzisi abanezilinganiso eziphezulu kakhulu.

Ngaphezu kwalokho, abasebenzisi abanezinga eliphezulu lokwethenjwa bavikelekile kangcono ekuhlaselweni ngabahloli, njengoba i-censor kufanele ilinde izinyanga ukuze ithole ikheli lommeleli. Ngenxa yalokho, amathuba okuthi amaseva avinjwe kubantu abasengozini enkulu aphansi ngokuphindaphindiwe kunalawo anokuthenjwa okuphansi.

Ukuze kuxhunywe abasebenzisi abaningi abafanelekayo ngangokunokwenzeka kuma-proxies angcono kakhulu, abadali be-Salmon benze uhlelo lokuncoma. Abasebenzisi abanesilinganiso esiphezulu (L) bangamema abangani babo ukuthi bajoyine inkundla. Abantu abamenyiwe balinganiselwa ku-L-1.

Isistimu yokuncoma isebenza ngamagagasi. Igagasi lokuqala labasebenzisi abamenyiwe lithola kuphela ithuba lokumema abangani babo ngemva kwezinyanga ezine. Abasebenzisi abavela kumagagasi esibili nalandelayo kufanele balinde izinyanga ezi-2.

Amamojula wesistimu

Uhlelo luqukethe izingxenye ezintathu:

  • Iklayenti leSalmon leWindows;
  • uhlelo lwe-daemon yeseva olufakwe amavolontiya (izinguqulo ze-Windows ne-Linux);
  • Isiphakeli sohla lwemibhalo esimaphakathi esigcina isizindalwazi sawo wonke amaseva elibamba futhi sisabalalisa amakheli e-IP phakathi kwabasebenzisi.

I-Project Salmon: ungamelana kanjani ngempumelelo nokuhlolwa kwe-inthanethi usebenzisa ama-proxi anamazinga okuthenjwa komsebenzisi

Uhlelo lokusebenza lweklayenti lesistimu

Ukuze usebenzise uhlelo, umuntu kufanele enze i-akhawunti esebenzisa i-akhawunti ye-Facebook.

isiphetho

Okwamanje, indlela ye-Salmon ayisetshenziswa kakhulu, ngamaphrojekthi amancane okuhlola aziwa ngabasebenzisi base-Iran nase-China. Naphezu kweqiniso lokuthi lena iphrojekthi ethakazelisayo, ayinikezi ngokugcwele ukungaziwa noma ukuvikelwa kwamavolontiya, futhi abadali ngokwabo bayavuma ukuthi kusengozini yokuhlaselwa kusetshenziswa izinsizakalo ze-honeypot. Noma kunjalo, ukuqaliswa kwesistimu enamazinga okuthembana kubukeka njengokuhlola okuthakazelisayo okungaqhutshekwa.

Yilokho kuphela okwanamuhla, ngiyabonga ngokunaka kwakho!

Izixhumanisi eziwusizo nezinto zokwakha ezivela I-Infatica:

Source: www.habr.com

Engeza amazwana