鏈€寮虹嫍澶磋蒋浠跺畨瑁呴厤缃缁嗘暀绋嬩粠鍏ラ棬鍒扮簿閫氬叏娴佺▼瑙f瀽鎸囧崡

棰戦亾锛�娓告垙璧勮 鏃ユ湡锛� 娴忚锛�8

杞欢瀹氫綅涓庡熀纭€璁ょ煡

鏈€寮虹嫍澶磋蒋浠跺畨瑁呴厤缃缁嗘暀绋嬩粠鍏ラ棬鍒扮簿閫氬叏娴佺▼瑙f瀽鎸囧崡

鐙楀ご杞欢浣滀负涓€娆句笓娉ㄤ簬缃戠粶鏁版嵁鍖呭垎鏋愬強瀹夊叏瀹¤鐨勫紑婧愬伐鍏凤紝鍏舵牳蹇冧环鍊煎湪浜庢彁渚涗紒涓氱骇娴侀噺鐩戞帶涓庡▉鑳佹娴嬭兘鍔涖€傛湰杞欢鍩轰簬Linux鍐呮牳寮€鍙戯紝鏀寔璺ㄥ钩鍙伴儴缃诧紝鍏峰娣卞害鍗忚瑙f瀽銆佸疄鏃舵祦閲忓彲瑙嗗寲銆佸叆渚垫娴嬬郴缁燂紙IDS锛夐泦鎴愪笁澶ф牳蹇冨姛鑳芥ā鍧椼€傜敤鎴烽渶鏄庣‘鍏跺吀鍨嬪簲鐢ㄥ満鏅寘鎷細缃戠粶瀹夊叏闃插尽浣撶郴鏋勫缓銆佸簲鐢ㄥ眰鍗忚璋冭瘯銆佺綉缁滄€ц兘鐡堕瀹氫綅绛変笓涓氶鍩熴€�

鐜鍑嗗涓庡墠缃潯浠�

1. 纭欢瑕佹眰

鎺ㄨ崘閰嶇疆Intel i5浠ヤ笂澶勭悊鍣紙鏀寔AVX鎸囦护闆嗭級锛�16GB鍐呭瓨璧锋锛孲SD瀛樺偍绌洪棿涓嶄綆浜�100GB銆傚浜庡崈鍏嗙綉缁滅幆澧冪洃鎺э紝闇€閰嶅涓撶敤缃戝崱鏀寔娣锋潅妯″紡銆�

2. 绯荤粺渚濊禆

  • Ubuntu 20.04 LTS/22.04 LTS锛堟帹鑽愶級
  • CentOS 7.9+锛堥渶EPEL浠撳簱鏀寔锛�
  • 纭繚宸插畨瑁卨ibpcap 1.10+銆丱penSSL 1.1.1+寮€鍙戝簱
  • Python 3.8+鐜鍙妏ip鍖呯鐞嗗櫒
  • 3. **鏉冮檺閰嶇疆

    鎵ц`sudo sysctl -w net.core.rmem_max=16777216`璋冩暣鍐呮牳缃戠粶缂撳啿鍖猴紝閬垮厤鏁版嵁鍖呬涪澶便€傛案涔呯敓鏁堥渶鍦╜/etc/sysctl.conf`娣诲姞`net.core.rmem_max=16777216`閰嶇疆椤广€�

    瀹夎閮ㄧ讲鍏ㄦ祦绋�

    1. 婧愮爜缂栬瘧瀹夎锛堢敓浜х幆澧冩帹鑽愶級

    ```bash

    git clone

    cd doghead-core

    mkdir build && cd build

    cmake -DCMAKE_BUILD_TYPE=Release -DENABLE_IPSEC_DECODE=ON ..

    make -j$(nproc)

    sudo make install

    ```

    鍏抽敭缂栬瘧鍙傛暟璇存槑锛�

  • `-DENABLE_IPSEC_DECODE` 鍚敤IPSec鍗忚瑙e瘑
  • `-DWITH_DPDK=ON` 闆嗘垚DPDK鍔犻€熸鏋�
  • `-DUSE_GPU_ACCEL=ON` 鍚敤GPU鍔犻€燂紙闇€NVIDIA CUDA鐜锛�
  • 2. 浜岃繘鍒跺寘蹇€熼儴缃�

    ```bash

    wget

    sudo apt install ./doghead-linux-amd64-3.2.1.deb

    sudo systemctl enable dogheadd

    ```

    鏍稿績閰嶇疆璇﹁В

    1. 涓婚厤缃枃浠惰В鏋�

    缂栬緫`/etc/doghead/doghead.yaml`锛�

    ```yaml

    capture:

    interface: eth0

    buffer_size: 256MB

    filter: "not port 22" # 鎺掗櫎SSH娴侀噺

    analysis:

    threat_detection:

    enabled: true

    ruleset: /etc/doghead/rules/emerging-threats.rules

    logging:

    level: info

    rotation: 500MB

    ```

    2. 瑙勫垯搴撶鐞�

    浠庡畼鏂瑰▉鑳佹儏鎶ユ簮鍚屾瑙勫垯锛�

    ```bash

    doghead-ctl update-rules --feed et_pro --feed alienvault

    ```

    鑷畾涔夎鍒欑ず渚嬶紙淇濆瓨涓篳custom.rules`锛夛細

    ```

    alert tcp any any -> 192.168.1.0/24 80 \\

    (msg:"SQLi Detection"; content:"select%20"; nocase; threshold:3/60s;)

    ```

    楂樼骇鍔熻兘瀹炵幇

    1. 鍒嗗竷寮忛儴缃叉灦鏋�

    鏋勫缓涓夎妭鐐归泦缇わ細

    ```bash

    # 鎺у埗鑺傜偣

    doghead-ctl cluster init --control-node 192.168.1.10

    # 鏁版嵁鑺傜偣

    doghead-node --join 192.168.1.10 --role capture --tags "dc=shanghai

    # 鍒嗘瀽鑺傜偣

    doghead-node --join 192.168.1.10 --role analysis --gpu-enabled

    ```

    2. 鎬ц兘璋冧紭绛栫暐

  • 缃戝崱浼樺寲锛氬惎鐢≧SS澶氶槦鍒�
  • `ethtool -L eth0 combined 8`

  • 鍐呭瓨绠$悊锛氶厤缃瓾ugePages
  • `echo 1024 > /sys/kernel/mm/hugepages/hugepages-2048kB/nr_hugepages`

  • CPU缁戝畾锛氭寚瀹氬鐞嗘牳蹇�
  • `taskset -c 2-6 doghead-node --role capture`

    杩愮淮鐩戞帶浣撶郴

    1. Prometheus鎸囨爣閲囬泦

    鏆撮湶鐩戞帶绔偣锛�

    ```yaml

    monitoring:

    prometheus:

    enable: true

    port: 9091

    metrics: [packets, drops, alerts]

    ```

    Grafana浠〃鐩樺鍏ュ畼鏂规ā鏉縛doghead-15932`锛屽疄鏃剁洃鎺т互涓嬪叧閿寚鏍囷細

  • 鏁版嵁鍖呭鐞嗛€熺巼锛坧ps锛�
  • 瑙勫垯鍖归厤鍛戒腑鐜�
  • 鍐呭瓨椤典氦鎹㈤鐜�
  • 2. 鏃ュ織鑱氬悎鍒嗘瀽

    閰嶇疆Logstash绠¢亾锛�

    ```ruby

    input {

    syslog { port => 514 }

    filter {

    grok { match => { "message" => "%{DOGHEAD_LOG}" } }

    output {

    elasticsearch { hosts => ["es01:9200"] }

    ```

    鏁呴殰鎺掓煡鎵嬪唽

    1. 甯歌闂璇婃柇

  • 涓㈠寘闂锛�
  • `doghead-stat --live --show-drop-causes` 鏌ョ湅鍏蜂綋涓㈠寘鍘熷洜

  • 鎬ц兘鐡堕锛�
  • 浣跨敤`perf record -g -p `鐢熸垚鐏劙鍥惧畾浣嶇儹鐐瑰嚱鏁�

  • 瑙勫垯澶辨晥锛�
  • 鎵ц`doghead-ctl test-rule custom.rules`楠岃瘉璇硶鏈夋晥鎬�

    2. 搴旀€ユ仮澶嶆祦绋�

    1. 鎵ц`doghead-ctl emergency-stop`绔嬪嵆鍋滄鏁版嵁鎹曡幏

    2. 妫€鏌/var/log/doghead/crash.log`鑾峰彇鍫嗘爤璺熻釜

    3. 鍥炴粴閰嶇疆锛歚doghead-ctl config rollback v1.2`

    4. 鎻愪氦閿欒鎶ュ憡锛歚doghead-bugreport --include-core`

    瀹夊叏鍔犲浐鏂规

    1. 閫氫俊鍔犲瘑锛氬惎鐢═LS 1.3

    鐢熸垚璇佷功锛歚openssl req -x509 -newkey rsa:4096 -nodes -out doghead.pem -keyout doghead.key -days 365`

    2. 鏉冮檺闅旂锛�

    鍒涘缓涓撶敤鐢ㄦ埛锛歚useradd -r -s /bin/false doghead`

    3. 婕忔礊闃叉姢锛�

    閰嶇疆SELinux绛栫暐锛�

    `setsebool -P doghead_can_network 1`

    鎸佺画闆嗘垚瀹炶返

    閫氳繃Ansible瀹炵幇鑷姩鍖栭儴缃诧細

    ```yaml

  • name: Deploy Doghead Cluster
  • hosts: doghead_nodes

    roles:

  • role: install_dependencies
  • role: deploy_doghead
  • vars:

    node_role: "{{ capture_node | default('analysis') }}

    ```

    鎶€鏈紨杩涙柟鍚�

    1. 鏈哄櫒瀛︿範闆嗘垚锛氶儴缃睺ensorFlow妯″瀷瀹炵幇寮傚父娴侀噺璇嗗埆

    2. eBPF鎶€鏈瀺鍚堬細浣跨敤XDP妗嗘灦瀹炵幇鍐呮牳灞傚寘澶勭悊

    3. 浜戝師鐢熸敮鎸侊細寮€鍙慘ubernetes Operator瀹炵幇寮规€ф墿缂╁

    閫氳繃鏈寚鍗楃殑绯荤粺瀛︿範锛岀敤鎴峰彲瀹屾垚浠庡熀纭€閮ㄧ讲鍒扮敓浜х骇杩愮淮鐨勫叏鐢熷懡鍛ㄦ湡绠$悊銆傚缓璁畾鏈熷叧娉ㄥ畼鏂瑰畨鍏ㄥ叕鍛婅幏鍙栨渶鏂版洿鏂帮紝鍚屾椂鍙備笌绀惧尯璁哄潧鐨勬妧鏈璁轰互鎺屾彙鍓嶆部鍔ㄦ€併€�

    鍐呭鐏垫劅鏉ヨ嚜锛堟渶寮烘敾鐣ュ惂锛�

    Baidu
    map