透過您的圖書館登入
IP:18.224.44.108
  • 會議論文
  • OpenAccess

軟體定義網路基於網路功能虛擬化之通訊監察系統

摘要


本研究在軟體定義網路架構下,設計一套網際網路事件分析紀錄系統,此系統由擷取紀錄子系統、資料庫子系統以及分析子系統所構成,可以攔截網路封包、解析網路活動並讀取封包內容進行資料及檔案還原、紀錄與檢索。本系統實作上採用SDN Ryu 控制器以及支持OpenFlow 標準的Open vSwitch(OVS)交換器,分別針對一個交換器與多個交換器的拓樸環境, 讓其可分類出FTP、HTTP、SMTP、POP3和IMAP4這五種不同應用協定的資料流(flow),並且讓相同通訊協定之流量透過映射(mirror)的方法將封包轉送到欲監察的擷取紀錄子系統中,同時也提供藉由開啟或關閉映射的功能,設定欲監察的通訊協定類型,在控制器上達到類似網路功能虛擬化之操作模式。

並列摘要


This research designed and implemented internet lawful interception, recording and analyzing system operated in a SDN network. This system was composed of Interception and Recording, Database, and Analyzing subsystems. In the realization, the SDN Ryu controller and Open vSwitch(OVS) that supports OpenFlow standard were adopted to emulated real SDN switches. Two different SDN architectures, single-switch and multi-switches topologies, were applied and implemented on both Mininet thru emulation and real devices. They can classify application flows of file transfer, web, and email services (i.e., corresponding to FTP, HTTP, SMTP, POP3 and IMAP4 protocols, respectively) and mirror each specific flow to the appropriate Interception and Recording Subsystem for analyzing and recording. Also, the implementation utilized the idea of network function virtualization so that the interception capability was designed to be able to arbitrarily enable or disable by activating on deactivating the mirroring function for the specific protocol in SDN switches.

延伸閱讀