NBADanalyzer  °Ï°ìºô¸ô¶¡TCP/UDP¬y¶q»P²§±`¤ÀªR¦øªA¾¹

 

«¬¿ý¤U¸ü

 

NBADanalyzer - Real time monitor¥D­n¥Øªº¬OÅýºÞ²zªÌ¥i¥H¹ïºôµ¸ªºª¬ºA¥i¥H¤@¥Ø¤FµM¡A¥]¬A²Õ´ªí¤Wªº³]³Æ¥DÅé»P¤¶­±°ðªºª¬ºA(¨ã³ÆSNMP¯à¤OªÌ)¡BSNMP trap»Psyslog³Ì·sºôµ¸¤Wµo¥Í¨Æ¥óªº°O¿ý¡B²Õ´¤ººô¸ô¤WIP flowªº§Y®É¬y¶qÅã¥Ü¡BTCPÀ³¥ÎªA°È»PClient/Server¶¡®Ä¯à¡B·JÁ`«á¾ãÅéºôµ¸ªºTop-N IP¬y¶q¨Ï¥Î±Æ¦æªíµ¥µ¥¡C

²Õ´³]³Æ »PIP flow§Y®ÉºÊµø       

1         ³]³Æ²M³æ¡V²Õ´ªí, ³]³ÆIP, ¦WºÙ, ª¬ºA, Session #

2         ¨Æ¥ó°O¿ý¡V³Ì·sµo¥ÍªºSNMP trap & syslog event

3         §Y®Ésession¡Vºô¸ô³Ìªñ5¤ÀÄÁµo¥ÍªºIP flow ¼Æ.

4         ¾ú¥vnetflow¡V¦~/¤ë/¶g/¤é/®É¤wµo¹LIP flow °O¿ý¼Æ

Top-N IP¬y¶q§Y®É¤ÀªR ¡V NM-9100¥HSNMP·JÁ`²Õ´¤º©Ò¦³NBADswitch¤ºneflow log¡ANM-9200«h¦Ûµw½L¸ê®Æ®w¤º¨ú³Ìªñ5¤ÀÄÁnetflow/sflow°O¿ý¡AµM«á¦A¥[¥H±Æ§Ç²Ö­p¨Ã±Æ¦W¾ãÅéºôµ¸¤WIP¨Ï¥Î¶q±Æ¦W¡C

¹ï¬y¤ÀªR(to who) ¡V ºÞ²z­û¦Û±Æ¦æº]¤W¥i¿ï¾Ü¬YIPªº¹ï¬y¤ÀªR¡A¥HÁA¸Ñ¸ÓIP¹ï¥~ªº³q°Tªº¥æ¤e¤ÀªR¡C

¨ó©w¤ÀªR(do what) - ºÞ²z­û¦Û±Æ¦æº]¤W¥i¿ï¾Ü¬YIPªº¨ó©w¤ÀªR¡A¥HÁA¸Ñ¸ÓIP¹ï¥~ªº³q°T¨Ï¥ÎªºTCPªA°È¤ÀªR¡C

³]³Æ¤¶­±§Y®É¤ÀªR ¡V ºÞ²z­û¥i¥H¦Û³]³Æ²M³æ¤W¿ï¾ÜÅã¥Ü¬Y³]³Æªº¤¶­±ª¬ºA(¥]¬A¶Ç°e/±µ¨ü¡B¿ù»~¡B¼s¼½ªº¼Æ¾Ú¥]¼Æ¶q)¡B©ÎMRTG¬y¶qªí¡C

MRTG ¡V NM-9200¤w±NMRTG¬y¶qªí¾ã¦X¨ì¨t²Î¤W¡AºÞ²z­û¥i¥HÆ[¹î¬Y¤¶­±§Y®É©Îªø´Áªº¬y¶qÁͶաC

¨ó©w¤ÀªR/ICMP¤ÀªR

1         ²Õ´¹ï¥~ºô¨ó©w/ICMP¤ÀªR

2         ¥~ºô¹ï²Õ´¤º¨ó©w/ICMP¤ÀªR

3         ²Õ´¤ººô¶¡¨ó©w/ICMP¤ÀªR

4         ²Õ´¤º¬Yºô¬q(³æ¦ì)¨ó©w/ICMP¤ÀªR

5         ¥Øªº³q°T°ð數¤ÀªR(ICMP¥Øªº¥D¾÷數±Æ¦æ - ¤º¹ï¥~/¥~¹ï¤º/¤º¹ï¤º¡B¥H¨Ó·½¥D¾÷±Æ§Ç,¦Ó¥H¥Ø¼Ð­Ó¼Æ±Æ¦æ ¡B¨Ó·½¥D¾÷©¹¤U¥i¹ï¬y¤ÀªR©Î¨ó©w¤ÀªR

6         ²Õ´¨ó©w/ICMP歷¥v¤ÀªR - ¤º¹ï¥~/¥~¹ï¤º/¤º¹ï¤º¡B¶g/¤ë/¦~³ø¡B¥i¦A²Ó¤À¬Yºô¬q¨ó©w¤ÀªR, ¥B¥i©¹¤U     ¦A¹ï¬y¤ÀªR©Î¨ó©w¤ÀªR

²§±`¤ÀªR

*       µo¥Í²§±`®É¥i³z¹L¶l¥ó³qª¾ºÞ²zªÌ¡C

*       ¤ä´©CISCO L3 ¹h¹D¾¹¡C

*       ¤ä´©«ÊÂê±Æ°£¦W³æ¨Ã¥i®Ú¾Ú¤£¦Pºô¬q³]©w¨ä¬Û¹ïÀ³ªº«ÊÂê¹h¹D¾¹¡C

*       ³W«h¤ÀªR-¥i¨Ì¾Ú¨Ó·½¦ì§}¡B¨Ó·½°ð¡B¥Øªº¦ì¤¸§}¡B¥Øªº°ð¡B«Ê¥]¼Æ¡B¬y¶q¼Æµ¥±ø¥ó³]©w³W«h¡C

*       ´£¨Ñ°»´ú¤wª¾¯f¬r (Code-Red¡BNimda¡BW32.Sasser.Worm¡BW32.Blaster.Worm  DDos-DP445)µ¥²§±`ª¬ªp¡C

*       ¶W¬y¤ÀªR

*       ´£¨Ñ³]©w«ÊÂꫬºA¤Î²Î­p¬y¶q¶¡¹j®É¶¡¡C

*       ¥i¨Ì¾Úºô¸ô«¬ºA¡B¶Ç¿é«¬ºA¡B¶W¬yÁ{¬É­Èµ¥±ø¥ó³]©w¶W¬y³W«h¡C