|
NBADanalyzer
°Ï°ìºô¸ô¶¡TCP/UDP¬y¶q»P²§±`¤ÀªR¦øªA¾¹
NBADanalyzer - Real time monitor¥Dn¥Øªº¬OÅýºÞ²zªÌ¥i¥H¹ïºôµ¸ªºª¬ºA¥i¥H¤@¥Ø¤FµM¡A¥]¬A²Õ´ªí¤Wªº³]³Æ¥DÅé»P¤¶±°ðªºª¬ºA(¨ã³ÆSNMP¯à¤OªÌ)¡BSNMP trap»Psyslog³Ì·sºôµ¸¤Wµo¥Í¨Æ¥óªº°O¿ý¡B²Õ´¤ººô¸ô¤WIP flowªº§Y®É¬y¶qÅã¥Ü¡BTCPÀ³¥ÎªA°È»PClient/Server¶¡®Ä¯à¡B·JÁ`«á¾ãÅéºôµ¸ªºTop-N IP¬y¶q¨Ï¥Î±Æ¦æªíµ¥µ¥¡C
²Õ´³]³Æ »PIP flow§Y®ÉºÊµø
1
³]³Æ²M³æ¡V²Õ´ªí, ³]³ÆIP, ¦WºÙ, ª¬ºA, Session #
2
¨Æ¥ó°O¿ý¡V³Ì·sµo¥ÍªºSNMP trap & syslog event
3
§Y®Ésession¡Vºô¸ô³Ìªñ5¤ÀÄÁµo¥ÍªºIP flow ¼Æ.
4
¾ú¥vnetflow¡V¦~/¤ë/¶g/¤é/®É¤wµo¹LIP flow °O¿ý¼Æ
Top-N IP¬y¶q§Y®É¤ÀªR ¡V NM-9100¥HSNMP·JÁ`²Õ´¤º©Ò¦³NBADswitch¤ºneflow log¡ANM-9200«h¦Ûµw½L¸ê®Æ®w¤º¨ú³Ìªñ5¤ÀÄÁnetflow/sflow°O¿ý¡AµM«á¦A¥[¥H±Æ§Ç²Öp¨Ã±Æ¦W¾ãÅéºôµ¸¤WIP¨Ï¥Î¶q±Æ¦W¡C
¹ï¬y¤ÀªR(to who) ¡V ºÞ²zû¦Û±Æ¦æº]¤W¥i¿ï¾Ü¬YIPªº¹ï¬y¤ÀªR¡A¥HÁA¸Ñ¸ÓIP¹ï¥~ªº³q°Tªº¥æ¤e¤ÀªR¡C
¨ó©w¤ÀªR(do what) - ºÞ²zû¦Û±Æ¦æº]¤W¥i¿ï¾Ü¬YIPªº¨ó©w¤ÀªR¡A¥HÁA¸Ñ¸ÓIP¹ï¥~ªº³q°T¨Ï¥ÎªºTCPªA°È¤ÀªR¡C
³]³Æ¤¶±§Y®É¤ÀªR ¡V ºÞ²zû¥i¥H¦Û³]³Æ²M³æ¤W¿ï¾ÜÅã¥Ü¬Y³]³Æªº¤¶±ª¬ºA(¥]¬A¶Ç°e/±µ¨ü¡B¿ù»~¡B¼s¼½ªº¼Æ¾Ú¥]¼Æ¶q)¡B©ÎMRTG¬y¶qªí¡C
MRTG
¡V NM-9200¤w±NMRTG¬y¶qªí¾ã¦X¨ì¨t²Î¤W¡AºÞ²zû¥i¥HÆ[¹î¬Y¤¶±§Y®É©Îªø´Áªº¬y¶qÁͶաC
¨ó©w¤ÀªR/ICMP¤ÀªR
1
²Õ´¹ï¥~ºô¨ó©w/ICMP¤ÀªR
2
¥~ºô¹ï²Õ´¤º¨ó©w/ICMP¤ÀªR
3
²Õ´¤ººô¶¡¨ó©w/ICMP¤ÀªR
4
²Õ´¤º¬Yºô¬q(³æ¦ì)¨ó©w/ICMP¤ÀªR
5
¥Øªº³q°T°ð數¤ÀªR(ICMP¥Øªº¥D¾÷數±Æ¦æ - ¤º¹ï¥~/¥~¹ï¤º/¤º¹ï¤º¡B¥H¨Ó·½¥D¾÷±Æ§Ç,¦Ó¥H¥Ø¼ÐÓ¼Æ±Æ¦æ ¡B¨Ó·½¥D¾÷©¹¤U¥i¹ï¬y¤ÀªR©Î¨ó©w¤ÀªR
6
²Õ´¨ó©w/ICMP歷¥v¤ÀªR - ¤º¹ï¥~/¥~¹ï¤º/¤º¹ï¤º¡B¶g/¤ë/¦~³ø¡B¥i¦A²Ó¤À¬Yºô¬q¨ó©w¤ÀªR, ¥B¥i©¹¤U ¦A¹ï¬y¤ÀªR©Î¨ó©w¤ÀªR
²§±`¤ÀªR
µo¥Í²§±`®É¥i³z¹L¶l¥ó³qª¾ºÞ²zªÌ¡C
¤ä´©CISCO L3 ¹h¹D¾¹¡C
¤ä´©«ÊÂê±Æ°£¦W³æ¨Ã¥i®Ú¾Ú¤£¦Pºô¬q³]©w¨ä¬Û¹ïÀ³ªº«ÊÂê¹h¹D¾¹¡C
³W«h¤ÀªR-¥i¨Ì¾Ú¨Ó·½¦ì§}¡B¨Ó·½°ð¡B¥Øªº¦ì¤¸§}¡B¥Øªº°ð¡B«Ê¥]¼Æ¡B¬y¶q¼Æµ¥±ø¥ó³]©w³W«h¡C
´£¨Ñ°»´ú¤wª¾¯f¬r (Code-Red¡BNimda¡BW32.Sasser.Worm¡BW32.Blaster.Worm DDos-DP445)µ¥²§±`ª¬ªp¡C
¶W¬y¤ÀªR
´£¨Ñ³]©w«ÊÂꫬºA¤Î²Îp¬y¶q¶¡¹j®É¶¡¡C
¥i¨Ì¾Úºô¸ô«¬ºA¡B¶Ç¿é«¬ºA¡B¶W¬yÁ{¬Éȵ¥±ø¥ó³]©w¶W¬y³W«h¡C
|