I-Network Packet Broker Identification Isekelwe ku-DPI - Ukuhlolwa Kwephakethe Okujulile

Ukuhlolwa Kwephakethe Okujulile (I-DPI)ubuchwepheshe obusetshenziswa ku-Network Packet Brokers (NPBs) ukuhlola nokuhlaziya okuqukethwe kwamaphakethe enethiwekhi ngezinga le-granular. Kubandakanya ukuhlola umthwalo okhokhelwayo, izihloko, nolunye ulwazi oluqondene nephrothokholi ngaphakathi kwamaphakethe ukuze uthole imininingwane enemininingwane ngethrafikhi yenethiwekhi.

I-DPI idlula ukuhlaziya okunhlokweni okulula futhi inikeza ukuqonda okujulile kwedatha egeleza kunethiwekhi. Ivumela ukuhlolwa okujulile kwezivumelwano zesendlalelo sohlelo lokusebenza, njenge-HTTP, FTP, SMTP, VoIP, noma amaphrothokholi okusakaza ividiyo. Ngokuhlola okuqukethwe kwangempela ngaphakathi kwamaphakethe, i-DPI ingathola futhi ihlonze izinhlelo zokusebenza ezithile, izivumelwano, noma amaphethini edatha athile.

Ngokungeziwe ekuhlaziyweni okulandelanayo kwamakheli omthombo, amakheli okuyiwa kuwo, izimbobo zomthombo, izimbobo zendawo okuyiwa kuzo, nezinhlobo zephrothokholi, i-DPI iphinda yengeze ukuhlaziywa kwesendlalelo sohlelo lokusebenza ukuhlonza izinhlelo zokusebenza ezihlukahlukene nokuqukethwe kwazo. Lapho iphakethe le-1P, i-TCP noma i-UDP igeleza ngohlelo lokuphathwa komkhawulokudonsa olusekelwe kubuchwepheshe be-DPI, uhlelo lufunda okuqukethwe kwephakethe le-1P ukuze luhlele kabusha ulwazi lwesendlalelo sohlelo lokusebenza kuphrothokholi ye-OSI Layer 7, ukuze lithole okuqukethwe lonke uhlelo lokufaka isicelo, bese ubumba ithrafikhi ngokwenqubomgomo yokuphatha echazwe uhlelo.

Isebenza kanjani i-DPI?

Ama-firewall avamile ngokuvamile angenawo amandla okucubungula ukuze enze ukuhlola kwesikhathi sangempela kumthamo omkhulu wethrafikhi. Njengoba ubuchwepheshe buthuthuka, i-DPI ingasetshenziswa ukwenza ukuhlola okuyinkimbinkimbi kakhulu ukuhlola izihloko nedatha. Ngokuvamile, izindonga zomlilo ezinamasistimu okuthola ukungena zivame ukusebenzisa i-DPI. Emhlabeni lapho ulwazi lwedijithali lubaluleke kakhulu, yonke imininingwane yedijithali ilethwa nge-inthanethi ngamaphakethe amancane. Lokhu kuhlanganisa i-imeyili, imilayezo ethunyelwe ngohlelo lokusebenza, amawebhusayithi avakashelwe, izingxoxo zevidiyo, nokuningi. Ngokungeziwe kudatha yangempela, lawa maphakethe ahlanganisa imethadatha ekhomba umthombo wethrafikhi, okuqukethwe, indawo, nolunye ulwazi olubalulekile. Ngobuchwepheshe bokuhlunga iphakethe, idatha ingaqashelwa ngokuqhubekayo futhi iphathwe ukuze kuqinisekiswe ukuthi idluliselwa endaweni efanele. Kodwa ukuze kuqinisekiswe ukuphepha kwenethiwekhi, ukuhlunga kwephakethe okungokwesiko akwanele. Ezinye zezindlela eziyinhloko zokuhlola iphakethe elijulile ekuphathweni kwenethiwekhi zibalwe ngezansi:

Imodi yokufanisa/Isiginesha

Iphakethe ngalinye lihlolelwa okufanayo ngokuqhathaniswa nesizindalwazi sokuhlaselwa kwenethiwekhi okwaziwayo ngohlelo lokuvikela olunamandla esistimu yokuthola ukungena (IDS). I-IDS isesha amaphethini akhethekile ayingozi futhi ikhubaza ithrafikhi lapho kutholwa amaphethini anonya. Ububi benqubomgomo yokufanisa isiginesha ukuthi isebenza kuphela kumasiginesha abuyekezwa njalo. Ngaphezu kwalokho, lobu buchwepheshe bungavikela kuphela ezinsongweni ezaziwayo noma ukuhlaselwa.

I-DPI

I-Protocol Exception

Njengoba indlela yokukhipha iphrothokholi ingavumeli nje yonke idatha engafani nesizindalwazi sesiginesha, indlela ehlukile yephrothokholi esetshenziswa i-firewall ye-IDS ayinawo amaphutha emvelo wendlela yokufanisa/yesiginesha. Kunalokho, yamukela inqubomgomo yokwenqaba ezenzakalelayo. Ngencazelo yephrothokholi, ama-firewall anquma ukuthi iyiphi ithrafikhi okufanele ivunyelwe futhi ivikele inethiwekhi ezinsongweni ezingaziwa.

Uhlelo Lokuvimbela Ukungena (IPS)

Izixazululo ze-IPS zingavimbela ukudluliswa kwamaphakethe ayingozi ngokusekelwe kokuqukethwe kwawo, ngaleyo ndlela kumise ukuhlasela okusolisayo ngesikhathi sangempela. Lokhu kusho ukuthi uma iphakethe limelela ubungozi bokuphepha obaziwayo, i-IPS izovimba ngokuqhubekayo ithrafikhi yenethiwekhi ngokusekelwe kusethi yemithetho echaziwe. Okunye okungalungile kwe-IPS isidingo sokuvuselela njalo isizindalwazi sokusongela nge-inthanethi ngemininingwane emayelana nezinsongo ezintsha, kanye nokuba nokwenzeka kwemibono engamanga. Kodwa le ngozi ingancishiswa ngokudala izinqubomgomo ezilondolozayo kanye nemingcele yangokwezifiso, ukusungula ukuziphatha okuyisisekelo okufanele kwezingxenye zenethiwekhi, nokuhlola ngezikhathi ezithile izexwayiso nemicimbi ebikiwe ukuze kuthuthukiswe ukugadwa nokuxwayisa.

1- I-DPI (I-Deep Packet Inspection) ku-Network Packet Broker

"Ukujula" kuyizinga kanye nesilinganiso esijwayelekile sokuhlaziya iphakethe, "ukuhlolwa kwephakethe okujwayelekile" kuphela ukuhlaziya okulandelayo kwesendlalelo sephakethe le-IP 4, okuhlanganisa ikheli lomthombo, ikheli lendawo, imbobo yomthombo, imbobo okuyiwa kuyo kanye nohlobo lwephrothokholi, kanye ne-DPI ngaphandle kokulandelana kwesigaba. ukuhlaziywa, kuphinde kwandise ukuhlaziywa kwesendlalelo sohlelo lokusebenza, ukuhlonza izinhlelo zokusebenza ezihlukahlukene nokuqukethwe, ukuze kubonakale imisebenzi eyinhloko:

1) Ukuhlaziywa kohlelo lokusebenza -- ukuhlaziya ukwakheka kwethrafikhi yenethiwekhi, ukuhlaziya ukusebenza, nokuhlaziywa kokugeleza

2) Ukuhlaziywa komsebenzisi -- ukuhlukaniswa kweqembu labasebenzisi, ukuhlaziya ukuziphatha, ukuhlaziya ukuphela, ukuhlaziya izitayela, njll.

3) I-Network Element Analysis -- ukuhlaziya okusekelwe kuzibaluli zesifunda (idolobha, isifunda, umgwaqo, njll.) kanye nesisekelo somthwalo wesiteshi

4) Ukulawulwa Kwethrafikhi -- Ukunciphisa isivinini se-P2P, isiqiniseko se-QoS, ukuqinisekiswa komkhawulokudonsa, ukulungiselelwa kwezinsiza zenethiwekhi, njll.

5) Isiqiniseko Sezokuphepha -- Ukuhlaselwa kwe-DDoS, isiphepho sokusakazwa kwedatha, ukuvimbela ukuhlaselwa kwegciwane okunonya, njll.

2- Ukuhlelwa Okujwayelekile Kwezinhlelo Zokusebenza Zenethiwekhi

Namuhla kunezicelo ezingenakubalwa ku-inthanethi, kodwa izinhlelo zokusebenza zewebhu ezijwayelekile zingaphela.

Ngokwazi kwami, inkampani ehamba phambili yokuqaphela uhlelo lokusebenza iHuawei, ethi ibona izinhlelo zokusebenza ezingu-4,000. Ukuhlaziywa kwephrothokholi kuyimojula eyisisekelo yezinkampani eziningi ze-firewall (i-Huawei, i-ZTE, njll.), futhi futhi kuyimojula ebaluleke kakhulu, esekela ukufezeka kwamanye amamojula asebenzayo, ukuhlonza isicelo esinembile, nokuthuthukisa kakhulu ukusebenza nokuthembeka kwemikhiqizo. Ekwenzeni imodeli yokuhlonza uhlelo olungayilungele ikhompuyutha ngokusekelwe ezicini zethrafikhi yenethiwekhi, njengoba ngenza manje, ukuhlonza iphrothokholi okunembile nokubanzi nakho kubaluleke kakhulu. Ngaphandle kwethrafikhi yenethiwekhi yezinhlelo zokusebenza ezijwayelekile ezivela kuthrafikhi yokuthekelisa yenkampani, ithrafikhi esele izolandisa ngengxenye encane, okungcono ukuhlaziya i-malware ne-alamu.

Ngokusekelwe kokuhlangenwe nakho kwami, izinhlelo zokusebenza ezisetshenziswa ngokuvamile ezikhona zihlukaniswa ngokwemisebenzi yazo:

I-PS: Ngokuqonda komuntu siqu ukuhlukaniswa kwesicelo, uneziphakamiso ezinhle wamukelekile ukushiya isiphakamiso somlayezo

1). I-imeyili

2). Ividiyo

3). Imidlalo

4). Ikilasi le-OA lehhovisi

5). Isibuyekezo sesoftware

6). Ezezimali (ibhange, i-Alipay)

7). Amasheya

8). Ukuxhumana Komphakathi (isoftware ye-IM)

9). Ukuphequlula iwebhu (cishe kuhlonzwe kangcono ngama-URL)

10). Landa amathuluzi (idiski lewebhu, ukulanda kwe-P2P, okuhlobene ne-BT)

20191210153150_32811

Bese, ukuthi i-DPI(Deep Packet Inspection) isebenza kanjani ku-NPB:

1). Ukuthwebula Kwephakethe: I-NPB ithwebula ithrafikhi yenethiwekhi kusuka emithonjeni ehlukahlukene, njengamaswishi, amarutha, noma ompompi. Ithola amaphakethe ageleza kunethiwekhi.

2). I-Packet Parsing: Amaphakethe athunjiwe acutshungulwa yi-NPB ukuze kukhishwe izendlalelo zephrothokholi ehlukahlukene kanye nedatha ehlobene. Le nqubo yokuhlaziya isiza ukukhomba izingxenye ezihlukene ezingaphakathi kwamaphakethe, njengezihloko ze-Ethernet, izihloko ze-IP, izihloko zesendlalelo sezokuthutha (isb., i-TCP noma i-UDP), kanye namaphrothokholi wesendlalelo sohlelo lokusebenza.

3). Ukuhlaziywa Kwenkokhelo: Nge-DPI, i-NPB idlulela ngalé kokuhlolwa kwesihloko futhi igxile ekulayisheni, okuhlanganisa nedatha yangempela engaphakathi kwamaphakethe. Ihlola okuqukethwe komthwalo okhokhelwayo ngokujulile, ngokunganaki isicelo noma iphrothokholi esetshenzisiwe, ukuze kukhishwe ulwazi olufanele.

4). Ukuhlonza Iphrothokholi: I-DPI yenza i-NPB ikwazi ukuhlonza izivumelwano ezithile nezinhlelo zokusebenza ezisetshenziswa ngaphakathi kwethrafikhi yenethiwekhi. Ingathola futhi ihlukanise izivumelwano ezifana ne-HTTP, FTP, SMTP, DNS, VoIP, noma amaphrothokholi okusakaza ividiyo.

5). Ukuhlolwa Kokuqukethwe: I-DPI ivumela i-NPB ukuthi ihlole okuqukethwe kwamaphakethe ukuze uthole amaphethini athile, amasiginesha, noma amagama angukhiye. Lokhu kuvumela ukutholwa kwezinsongo zenethiwekhi, ezifana nohlelo olungayilungele ikhompuyutha, amagciwane, imizamo yokungena, noma imisebenzi esolisayo. I-DPI ingaphinda isetshenziselwe ukuhlunga okuqukethwe, ukusebenzisa izinqubomgomo zenethiwekhi, noma ukuhlonza ukuphulwa kokuthobela idatha.

6). Ukukhishwa Kwemethadatha: Ngesikhathi se-DPI, i-NPB ikhipha imethadatha efanele emaphaketheni. Lokhu kungafaka ulwazi olufana namakheli e-IP omthombo nendawo okuyiwa kuyo, izinombolo zembobo, imininingwane yeseshini, idatha yokwenziwe, nanoma yiziphi ezinye izibaluli ezifanele.

7). Umzila Wethrafikhi noma Ukuhlunga: Ngokusekelwe ekuhlaziyweni kwe-DPI, i-NPB ingahambisa amaphakethe athile ezindaweni ezikhethiwe ukuze kuqhutshekwe nokucubungula, njengezinto zikagesi zokuphepha, amathuluzi okuqapha, noma izinkundla zezibalo. Ingase futhi isebenzise imithetho yokuhlunga ukuze ulahle noma uqondise kabusha amaphakethe ngokusekelwe kokuqukethwe okukhonjiwe noma amaphethini.

I-ML-NPB-5660 3d


Isikhathi sokuthumela: Jun-25-2023