首页    期刊浏览 2024年11月28日 星期四
登录注册

文章基本信息

  • 标题:NCAP—協調的なネットワーク解析のための分散キャプチャ
  • 本地全文:下载
  • 作者:Paul VIXIE ; 村井 純
  • 期刊名称:コンピュータ ソフトウェア
  • 印刷版ISSN:0289-6540
  • 出版年度:2010
  • 卷号:27
  • 期号:4
  • 页码:4_133-4_143
  • DOI:10.11309/jssst.27.4_133
  • 出版社:Japan Society for Software Science and Technology
  • 摘要:

    We describe NCAP, a new network capturing tool for distributed sensor systems. NCAP operates on messages rather than on packets, and so performs full IP reassembly at the point of measurement. The resulting data can either be managed as files or be transmitted as encapsulated UDP datagrams either unicast or multicast. The NCAP library is highly portable with C and Python interfaces, and has a plug-in mechanism whereby analysis logic can be written discretely and without regard to the handling of encapsulated datagrams or files. The primary application of NCAP is the Security Information Exchange, where cooperating distributed sensor operators now submit captured DNS traffic to a centralized location for subsequent long-running analysis. Examples of value added reprocessing and rebroadcast will be shown, as well as samples of captured traffic and of possible security problems illuminated by our analysis. These results will show that NCAP makes it possible to capture, share, and analyze live network data on a larger scale than has ever been done.

国家哲学社会科学文献中心版权所有