增强的Zeek网络流量采集与监控分析系统设计OACSTPCD
Design of an Enhanced Zeek Network Traffic Collection and Monitoring Analysis System
随着计算机技术和网络攻击手段的不断发展,网络监控需求不断强烈.针对企事业单位网络监控效果与实际需求不匹配、缺少可复用的流量采集与监控分析一体化系统的现状,该文设计了增强的Zeek的网络流量采集与监控分析系统,用于企事业单位的流量管理.系统利用Zeek的可扩展性,设计了多端口识别与自定义采集时间间隔的功能,实现了对网络汇聚流量的更精准和灵活的采集.接着,将采集数据的本地存储与持久化存储相结合,在Web端提供对网络安全数据的全面分析.系统实现了流量数据的定制化采集、持久化存储与Web交互展示和控制功能,在保证现有应用系统平稳运行的前提下,降低了信息时延,满足了真实大规模网络环境流量数据的个性化采集和实时监测与溯源分析需求,同时为进一步扩展为其他应用模式提供了可用的架构基础.
With the development of computer technology and network attack methods,the need for network monitoring continues to be strong.We present a network traffic collection,monitoring and analysis system based on enhanced Zeek.The system is designed to address the discrepancy between enterprises and institutions'current network monitoring capabilities and their actual needs.It also aims to provide a reusable,integrated system for traffic management.The system utilizes Zeek's scalability and incorporates multi-port identi-fication and customized collection intervals to achieve a more accurate and flexible collection of network aggregated traffic.It then combines locally stored collected data with persistent storage to comprehensively analyze network security data on the web.The system enables personalized collection,real-time monitoring,and traceability analysis of traffic data in large-scale network environments and reduces information latency while ensuring the smooth operation of existing application systems.It provides a foundation for further expansion into other application modes.
沈萍;陈俊丽;张汉举
上海大学 通信与信息工程学院,上海 200444上海博弋信息科技有限公司,上海 200030
计算机与自动化
网络流量Zeek个性化采集端口识别流量监控分析Web
network trafficZeekpersonalized collectionport identificationtraffic monitoring analysisWeb
《计算机技术与发展》 2024 (010)
77-83 / 7
国家自然科学基金(12174245)
评论