NBADsensor°Ï°ìºô¸ô¤º MAC/IPºÞ²z»PARP«Â¯ÙÀË´ú¾¹

 

«¬¿ý¤U¸ü

 

 

NBAD sensor ¬°¤@¦h¥\¯à¾ã¦X«¬¤§ºô¸ô¸ê·½º[«Â¯ÙºÞ²z¤§¸Ñ¨M¤è®×²£«~¡A¥H±´°wªº¤è¦¡¾Ç²ß©Î±´´ú©ÎºÞ²z¤ººôVLAN¤º³¡¼s¼½²§±`ªº«Ê¥]¡A¥ç©Î¦P®É±´´ú©Î®i²{¤£¦PVLAN¤§¶¡ªºTCP/UDP/ICMPºô¸ô¬y¶q¸ê·½»P²§±`«Â¯Ùªº¨Ó·½¡F¥¦¤£¦P©ó¥«­±¤W¤@¯ë§G¸p©ó¹h¹D¤W¤§¦w¥þ²£«~, ¥i¼sªx±´´úºô¸ô¤º³¡¦U¨¤¸¨(VLAN)ªº²§±`ºô¸ô¦æ¬°¡A¥H´Á§Y¦­°»´ú©Îµo²{¨º¨Ç©|¥¼³Q±´´ú¥X¯S¼xªº¯f¬r©ÎÀb«È§ðÀ»¡CNBAD sensor ¬O¥iÀ³¥Î©ó¥ô¦óºô¸ôÀô¹Ò¤ä´©IEEE 802.1Q¤§«Ê¥]ÀË´ú¾¹(packet sensor)¡A¦¹³]³Æ¤£¶È¥i¥HÀË´ú°©·Fºô¸ô¤º¦U­ÓLayer 2¼hVLAN¤ººô¸ô¬O§_¦³²§±`ARP§ðÀ»¡A¨Ã¥iÀˬd¨Ï¥ÎªÌ¬O§_¦³¤£²Å¦X³W©w¤§ºô¸ô¦æ¬°¡C(µù:NBADmanager plus ¬°¤@¿W¥ß¦øªA¾¹¥i¤¤¥¡ºÞ²z¦h­ÓNBADsensor, ¥\¯à¥]¬A:¤¤¥¡ºÞ²zMAC/IP¸ê®Æ®w¦¬¶°¡B°»´ú»PºÞ²z¥\¯à¡AARP°»´ú¥\¯à - °»Å¥¡B«ÊÂê¡Bºô¸ô±±¨î¡C-½Ð°Ñ¦ÒNBADmanager¸ê°T)

NBADsensor ¡V¤º«ØASIC´¹¤ù§t¦³16Gbps«Ê¥]½Æ»s¡BÂà°e¡BÀ˰¼¡B¤À¬yªº¯à¤O, ¥H¤ä´©©Ò´£¨Ñ2ºØ¤A¤Óºô¸ôµwÅ餶­±³W®æ, ¥]¬A8­ÓCopper Gigabit¤A¤Óºô¸ô¤¶­±¤Î24­Ó100Mbps utp¤Î2­Ósfp/utp Gigabit Combo¤¶­±, ÂÇ¥H½u³tªº®Ä¯à°õ¦æºô¸ô¬y¶q«Ê¥]¾Ç²ß¤ÎÀË´úªº¥\¯à¡CNBADsensor¥D­n¥Øªº¡G

MAC/IP ¦s¨ú¦w¥þºÞ²z

l       MAC/IP ¦s¨ú¦w¥þºÞ²z -¦Û°Ê¾Ç²ß ¡VVLAN°Ïºô¤ºMAC¡BIP¤Î¨Ï¥ÎªÌ¹q¸£¦WºÙ¦¬¶°¡A¨ÑºÞ²zªÌ®e©ö§Ö³t«Ø¥ßºô¸ô¨Ï¥ÎªÌ¸ê®Æ®w¡C¨Ã¥i¦Û°Ê°»´úMAC/IP¦ì§}ªº·s¼W¡B²§°Ê¤Î½Ä¬ð¨Æ¥ó¥\¯à¡A¨Ã¥i±N¬ÛÃö¨t²Î°T®§Àx¦s©ó¸ê®Æ®wºÞ²z¨t²Î¡C

l       ¹ê¬I¸j©w ¡V MAC¡BIP¸j©wªººô¸ô¦s¨ú¦w¥þµ¦²¤¡A¥H¨¾¤î¨Ï¥ÎªÌ¨p¦Û«§ïIPµo¥Í¨Ï¥Î¦P¤@IPªº½Ä¬ð°ÝÃD¡CÁ×§K­Ó¤H¹q¸£»P­«­n³]³Æ¡B¦øªA¾¹¤§ºô¸ôIP¦ì§}½Ä¬ð¡A¥H«O»Ù­«­n³]³Æ©Î¦øªA¾¹¤§ªA°È¡C

l       ¸ê®ÆºÞ²z ¡V ¨t²Î¤ä´©³æµ§¸ê®ÆªººûÅ@¥~¨Ã´£¨Ñ¾ã­Ó¸ê®Æ®wªº¶×¤J¡B¶×¥X¡B²M°£ºÞ²z¡C¨t²Î¤]¤ä´©SNMP Private MIB´£¨ÑºôºÞ³nÅé©Î¨ä¥LÃþ¦üNBADmanagerºÞ²z³nÅ骺¦s¨ú¤¶­±¡C

DHCP  IP¦ì§}ºÞ²z

l       DHCP®e¿ùªA°È¾¹ ¡V¤º«ØDHCP¦øªA¾¹¥\¯à¡A´£¨Ñ±ÂÅv»P«D±ÂÅv¨âºØ«¬ºA¤§DHCPªA°È¡A¨Ã¤ä´©¨â¥x³]³Æ¤¬¬°³Æ´©¾÷¨î¤§¥\¯à¡C

l       MAC/IP¸j©w¬£°e ¡V DHCPªA°È¾¹°£¤ä´©¼Ð·ÇDHCP IP¯²¸îªA°È¡A¥i©w¸qIP Range for multi VLANs,¨Ã¬£µo¦¨¥\¤§¥~¡A¨Ã¥i¾ã¦X±ÂÅv¤§MAC/IP¸ê®Æ®w¡A´£¨ÑMAC/IP¸j©w¬£°e¥\¯à¡A¥H½T©w­n¨D¸ôªA°È¤§¸`ÂI¬°¦Xªk¤§¹q¸£³]³Æ«á¡A©l±o¥ÑDHCP¬£µo¯S©wªºIP¡C

l       ¬£µo°O¿ý»P¨Ò¥~ºÞ²z ¡V´£¨ÑDHCP¬£µo¾ú¥v°O¿ý¬d¸ß¤Î¶×¥X¥\¯à¡C¥»¨t²Î¥ç¥i¥ÑºÞ²zªÌ¦Û©wIP¬£µo¬Fµ¦¡A¥i°Ï¤À¬°©T©wIP¥Î¤á¤Î©Î¥Ñ¨t²Î¦Û¦æ¬£µoµ¥¡A¥i¨Ò¥~ºÞ²z³¡¥÷¤§¨p³]©T©wIP¨Ã¡C

l       ¥Î¤áºÝDHCPºÞ²z ¡V (1)¨p³]DHCPªA°È¾¹ªýÂ_ - LANÀô¹Ò¤º¨p¦Û¬[³]¤£¦XªkDHCP Server·|³QNBADsensorªý¹jµL®Ä (2)DHCP±j¨î - ¥i­­¨îºÝÂI¥u¯à¨Ï¥ÎDHCP¤è¦¡¨ú±oIP¡A¥ô¦ó¨p¦Û³]©wIP¦ì§}¤§²×ºÝ³]³ÆµL½×©Ò³]©wIP¦ì§}¬O§_¬°¦XªkIP¬Ò¸T¤î¨ä¨Ï¥Îºô¸ô ¡C

²§±`°»´úºÞ²z

l       IP Scan ±½´y°»´ú ¡V³]©wIP ScanªùÂe,¥i°»´ú¥Î¤á°õ¦æ IP scan®É,IP Scan­È¬O§_²Ö­p,¶W¹L®ÉÀ³¥i®Ú¾ÚLock Action¶i¦æ°Ê§@(Lock by MAC, send event log, send notify page)¡C

l       ARP²§±`°»´ú ¡V °»´ú¾¹´£¨Ñ°Ïºô¤ºARP´ÛÄF§ðÀ»°»´ú¥\¯à¥]¬A¡GARP ±½ºË°»´ú ¡V ¥i°»´úLAN¤º³¡ARP±½´y¦æ¬°¡CARP²§±`°»´ú - «h¬O°»´úLAN¤º³¡­þ¨Ç¥Î¤á°e¤@¨Ç¤£¦Xªk«Ê¥]¡CARP§ðÀ»°»´ú - ¥D­n¥Øªº¬O°»´ú¥X­þ¨Ç¥Î¤á¾D¨ü§ðÀ»¡C

l       DNS³¨³½´ÛÄF°»´ú ¡V¥i°»´ú¥Î¤áÂsÄý¾¹DNS¬O§_¾D¨ü§T«ù¦Ó¥i¯à³Q´Ó¤J¤ì°¨µ{¦¡¡C

l       ¼s¼½­·¼É°»´ú ¡V ¥i°»´ú°Ï°ì¤ººôVLAN¬O§_¦³¶W¹L²§±`¤§¼s¼½µo¥Í¡A¨Ã³qª¾ºÞ²zªÌ¡C

»·ºÝ¨¾½Ã End-point Defense - NBADsensor ¥i¥HÀË´úRogue MAC/IP address(«Dªk/¤J«I¦ì§}) ©Î³z¹LNBADanalyzer¤ÀªRWorm, DoS§ðÀ», ³o®É«áNBADsensor ¥i¥ß§Y°_°ÊºÝÂI¨¾½Ã(End-point defense)¥\¯à¼Ò²Õ¡A¨Ó§í¨îªý¤î³o¨Ç«Dªk¤J«I¡CºÝÂI¨¾½Ã(End-point defense) ¨Ã«D«ÊÂê¯S©wªº¥æ´«¾¹°ð¡A¦Ó¬Oª½±µ§í¨î¤J«IªÌ(«Dªk¨Ï¥Î)ªºPC©ÎNote Bookµ§°O¹q¸£ºô¸ôªº¨Ï¥Î¡A¦]¦¹§Y¨Ï¤J«IªÌ¨Ï¥Îªº¬ONote Book¹q¸£¨ã³Æ²¾°Êªº¯S©Ê¡A¤´µM°k¤£¹LEnd-point defenseªº«ÊÂê¡A¦Ó¥B¤]¤£»Ý§ïÅÜ¥ô¦óºô¸ô¬[ºc©Î§@½ÆÂøªº³]©w¡C