The Design and Implementation of Distributed Network Event Analyzing and Recording System

碩士 === 國立臺北科技大學 === 資訊工程系研究所 === 101 === This research was to design a distributed network event analyzing and recording system. It observed network activity by capturing and analyzing all packets flow on networks, and recorded data and reconstructed from the captured packets back to their original...

Full description

Bibliographic Details
Main Authors: Yi-Lei Chang, 張以磊
Other Authors: 柯開維
Format: Others
Language:zh-TW
Published: 2013
Online Access:http://ndltd.ncl.edu.tw/handle/28s82r
Description
Summary:碩士 === 國立臺北科技大學 === 資訊工程系研究所 === 101 === This research was to design a distributed network event analyzing and recording system. It observed network activity by capturing and analyzing all packets flow on networks, and recorded data and reconstructed from the captured packets back to their original form as well. The distributed and modularized architecture were applied to the design. Three subsystems, Capture subsystem, Database subsystem and Analyzing subsystem, were cooperated through internet connection to reach a clear division of work loading and provide more flexibility on system provisioning. The design can also achieve high protocol extendibility, maintainability, and usability. By proposing a unified process, this work implemented protocol analysis and recording functions for FTP, HTTP, SIP and H.323 protocols, and suspected intrusion detection for ARP spoofing, SYN flood and PING attacks. The functionality and stability of the system have been verified through long term test in real laboratory network environment and pressure test by replay large amount of packets use packet generating software.