• umutwe_banner_03
  • umutwe_umutware_02

Kurungika no kugenzura sisitemu

Uburyo Sbc ikora muri sisitemu yo kohereza IP hamwe na sisitemu yo kugenzura

• Incamake

Hamwe niterambere ryihuse rya IP nikoranabuhanga ryamakuru, kurwanya inkongi zumuriro na sisitemu yo gutabara byihutirwa bigenda bitera imbere no kuzamura. Sisitemu yo kohereza IP ihujwe nijwi, amashusho namakuru byahindutse igice cyingirakamaro muri sisitemu yihutirwa, gutegeka no kohereza, kugirango hamenyekane itegeko rihuriweho hamwe nubufatanye hagati yimbuga n’amashami atandukanye, no kugera ku gihe gikwiye, igisubizo cyihuse kandi cyiza ku mutekano ibyabaye.

Ariko, kohereza sisitemu yo kohereza IP nayo ihura nibibazo bishya.

Nigute ushobora kurinda umutekano wa sisitemu yibanze no gukumira ibitero byurusobe mugihe seriveri yubucuruzi na seriveri yamakuru ivugana nibikoresho byo hanze binyuze kuri interineti?

Nigute ushobora kwemeza imikoranire isanzwe yamakuru yubucuruzi atambukiranya imiyoboro ya NAT mugihe seriveri yoherejwe inyuma ya firewall?

Gukurikirana amashusho, kugarura amashusho nibindi bikorwa mubisanzwe birimo imitwe yihariye ya SIP hamwe nuburyo bwihariye bwo gutangaza. Nigute ushobora kwemeza itumanaho rihamye ryibimenyetso nibitangazamakuru hagati yimpande zombi?

Nigute ushobora gutanga itumanaho rihamye kandi ryizewe, kwemeza QoS yerekana amajwi n'amashusho, kugenzura ibimenyetso n'umutekano?

Kohereza Cashly Isomo ryumupaka kumugenzuzi wo kohereza hamwe nibitangazamakuru bya seriveri birashobora gukemura neza ibibazo byavuzwe haruguru.

Topologiya ya Scenario

sbc1

Ibiranga & Inyungu

DOS / DDoS kwirwanaho, kurinda IP, kurinda SIP hamwe nizindi politiki zumutekano zo kurinda sisitemu.

Inzira nyabagendwa kugirango itumanaho ryorohewe.

Serivisi za QoS, kugenzura ubuziranenge / gutanga raporo kugirango tunoze amajwi na videwo.

Itangazamakuru rya RTMP, ikarita yerekana ikarita hamwe na porokisi ya HTTP.

Shyigikira mubiganiro no hanze-y'ibiganiro SIP MESSAGE uburyo, byoroshye kwiyandikisha amashusho.

SIP Umutwe na numero manipulation kugirango yuzuze ibisabwa bitandukanye mubihe bitandukanye.

Kuboneka Byinshi: 1 + 1 ibyuma birenze urugero kugirango ibikorwa bikomeze.

Urubanza 1: Sbc muri sisitemu yo kugenzura amashusho

Sitasiyo ishinzwe kuzimya amashyamba, ishinzwe inkongi z’umuriro n’izindi nkeragutabara z’ibiza, irashaka kubaka IP yohereza itumanaho rya IP, rikoresha cyane cyane ibinyabiziga bitagira abapilote (UAV) kugira ngo bikurikirane hirya no hino kandi biterefona, kandi bitange videwo nyayo binyuze mu muyoboro umuyoboro kuri data center. Sisitemu igamije kugabanya cyane igihe cyo gusubiza no koroshya kohereza no kohereza byihuse. Muri iyi sisitemu, Cashly Sbc yoherejwe mukigo cyamakuru nkirembo ryumupaka wa media stream seriveri hamwe na sisitemu yohereza ibintu, itanga ibimenyetso byerekana firewall, NAT traversal na serivise yo kwiyandikisha kuri sisitemu.

Urusobe Topologiya

sbc2

Ibintu by'ingenzi

Ubuyobozi: imicungire y abakozi, imiyoborere yitsinda, gukurikirana ibidukikije nubufatanye hagati yamakipe nishami

Gukurikirana amashusho: gukina amashusho nyayo, gufata amashusho no kubika nibindi.

Kohereza amajwi ya IP: guhamagarwa umwe, itsinda rya paji nibindi

Itumanaho ryihutirwa: kumenyesha, amabwiriza, itumanaho ryanditse nibindi

Inyungu

Sbc ikora nka porokisi ya SIP isohoka. Kohereza porogaramu hamwe na porogaramu zigendanwa zishobora kwiyandikisha hamwe na seriveri y'itumanaho ihuriweho binyuze muri Sbc.

RTMP itanga amakuru yibitangazamakuru, Sbc yohereza amashusho ya UAV kuri seriveri.

Ikarita yerekana ikarita ya ICE hamwe na porokisi ya HTTP.

Menya abakiriya serivisi ya FEC ya videwo yoherejwe na Sbc umutwe wa passthrough.

Itumanaho ryijwi, SIP intercom hagati yo kohereza konsole na porogaramu igendanwa.

Kumenyesha SMS, Sbc ishyigikira kumenyesha SMS hakoreshejwe uburyo bwa SIP MESSAGE.

Ibimenyetso byose nibitangazamakuru bigomba koherezwa muri data center na Sbc, ishobora gukemura ibibazo byo guhuza protocole, inzira ya NAT n'umutekano.

Ikiburanwa cya 2: Sbc ifasha inganda zikora peteroli gukoresha neza sisitemu yo kugenzura amashusho

Ibidukikije byinganda zikora imiti mubusanzwe biri munsi yubushyuhe bwinshi, umuvuduko mwinshi, umuvuduko mwinshi, nibindi bihe bikabije. Ibikoresho birimo birimo gutwikwa, guturika, uburozi bukabije, kandi byangirika. Kubwibyo, umutekano mubikorwa niwo shingiro ryimikorere isanzwe yinganda zikora imiti. Hamwe niterambere ryubumenyi nikoranabuhanga, sisitemu yo kugenzura amashusho yabaye igice cyingirakamaro mu musaruro w’umutekano w’inganda zikora imiti. Igenzura rya videwo ryashyizwe mu turere tw’akaga, kandi ikigo cya kure kirashobora gukurikirana uko ibintu bimeze kure kandi mu gihe gikwiye, kugira ngo hamenyekane ingaruka zishobora guterwa n’impanuka aho zikora kandi zivurwe neza.

Topologiya

sbc3

Ibintu by'ingenzi

Kamera zashyizwe kuri buri ngingo yingenzi muri parike ya peteroli, kandi urubuga rwo kurebera kure rushobora kureba amashusho uko bishakiye.

Seriveri ya videwo ivugana na SIP seriveri binyuze muri protokole ya SIP kandi ishyiraho imiyoboro ihuza kamera na monitor yikigo.

Ihuriro ryo gukurikirana rikurura amashusho ya buri kamera binyuze muburyo bwa SIP MESSAGE.

Gukurikirana igihe nyacyo kuri centre ya kure.

Amashusho yafashwe abikwa hagati kugirango yizere ko kohereza no gutegeka byanditswe neza.

Inyungu

Gukemura ikibazo cya NAT unyuze kandi urebe neza itumanaho ryiza hagati ya kamera nikigo cya kure.

Reba amashusho ya kamera na SIP MESSAGE abiyandikishije.

Igenzura inguni ya kamera mugihe nyacyo ukoresheje SIP yerekana inzira.

Umutwe wa SDP passthrough na manipulation kugirango uhuze ibyifuzo bitandukanye byubucuruzi.

Gukemura ibibazo bihujwe na sbc SIP umutwe wumutwe ukoresheje ubutumwa bwa SIP bwoherejwe na seriveri.

Kohereza serivise nziza ya videwo ukoresheje ubutumwa bwa SIP (ubutumwa bwa SDP urungano rurimo amashusho gusa, nta majwi).

Hitamo amashusho yigihe-ya kamera ya kamera ijyanye na sbc nimero ya manipulation.