透過您的圖書館登入
IP:3.16.51.3
  • 學位論文

分散式網路事件分析紀錄系統之研製

The Design and Implementation of Distributed Network Event Analyzing and Recording System

指導教授 : 柯開維

摘要


本論文設計一套用於網際網路上的分散式網路事件分析紀錄系統,攔截網路封包、解析網路活動並讀取封包內容進行檔案還原紀錄。 此系統採分散式架構設計,由擷取紀錄子系統、資料庫子系統、分析子系統構成,透過網路連線合作達成明確的分工並可依通訊監察的需求組合出不同之監察網路,達成可彈性佈建的目標。 此外,為了滿足不同監聽環境的需求及未來可能新增之通訊協定,系統以模組化方式設計,並制定一標準化方式進行通訊協定之行為分析、擷取紀錄程式之撰寫及程式功能測試,達成系統在通訊協定上之高可擴充性及可維護性。 本論文亦實作此系統,以所設計之標準化方式分析並實作FTP、HTTP、SIP、H.323通訊協定分析紀錄及網路異常行為偵測功能,驗證此系統設計的可用性。並經由真實實驗室網路環境長時間監測及透過封包播放軟體大量產生網路事件進行測試,證明所實作之系統具有可長時間運作及應付瞬間大流量之穩定性。

關鍵字

網路監聽 分散式系統 FTP HTTP H.323 SIP ARP

並列摘要


This research was to design a distributed network event analyzing and recording system. It observed network activity by capturing and analyzing all packets flow on networks, and recorded data and reconstructed from the captured packets back to their original form as well. The distributed and modularized architecture were applied to the design. Three subsystems, Capture subsystem, Database subsystem and Analyzing subsystem, were cooperated through internet connection to reach a clear division of work loading and provide more flexibility on system provisioning. The design can also achieve high protocol extendibility, maintainability, and usability. By proposing a unified process, this work implemented protocol analysis and recording functions for FTP, HTTP, SIP and H.323 protocols, and suspected intrusion detection for ARP spoofing, SYN flood and PING attacks. The functionality and stability of the system have been verified through long term test in real laboratory network environment and pressure test by replay large amount of packets use packet generating software.

並列關鍵字

Internet interception Distributed system FTP HTTP H.323 SIP ARP

參考文獻


[9] 王謙志著,「以SIP Phone為基礎之跨平台側錄監聽與分析系統」,碩士論文,國立台北科技大學資訊工程系碩士班,台北,2010。
[10] International Telecommunication Union, "Packet-based Multimedia Communications Systems," Recommendation H.323, Telecommunication Standardization Sector of ITU, December 2009.
[11] 黃威穎著,「H.323網路電話音訊監控與錄製系統之研製」,碩士論文,國立台北科技大學資訊工程系碩士班,台北,2008。
[12] 蔡家瑞著,「客製化H.323協定之至慧型網路電話監控語錄音系統」,碩士論文,國立台北科技大學資訊工程系碩士班,台北,2009。
[14] International Telecommunication Union, "Control protocol for multimedia communication," Recommendation H.245, Telecommunication Standardization Sector of ITU, May 2011.

延伸閱讀