Поддерживать
www.wikidata.ru-ru.nina.az
SCTP angl Stream Control Transmission Protocol protokol peredachi s upravleniem potokom protokol transportnogo urovnya v kompyuternyh setyah poyavivshijsya v 2000 godu v IETF RFC 4960 opisyvaet etot protokol a RFC 3286 soderzhit tehnicheskoe vstuplenie k nemu Kak i lyuboj drugoj protokol peredachi dannyh transportnogo urovnya SCTP rabotaet analogichno TCP ili UDP Buduchi bolee novym protokolom SCTP imeet neskolko novovvedenij takih kak mnogopotochnost zashita ot DDoS atak sinhronnoe soedinenie mezhdu dvumya hostami po dvum i bolee nezavisimym fizicheskim kanalam multi homing Bezopasnoe ustanovlenie soedineniyaSozdanie novogo podklyucheniya v protokolah TCP i SCTP proishodit pri pomoshi mehanizma podtverzhdeniya kvitirovaniya paketov V protokole TCP dannaya procedura poluchila nazvanie tryohetapnoe rukopozhatie three way handshake Klient posylaet paket SYN sokr Synchronize Server otvechaet paketom SYN ACK Synchronize Acknowledge Klient podtverzhdaet priyom paketa SYN ACK paketom ACK Na etom procedura ustanovleniya soedineniya zavershaetsya Protokol TCP imeet potencialnuyu uyazvimost obuslovlennuyu tem chto narushitel ustanavlivaya falshivye IP adresa otpravitelya mozhet poslat serveru mnozhestvo paketov SYN Pri poluchenii paketa SYN server vydelyaet chast svoih resursov dlya ustanovleniya novogo soedineniya Obrabotka mnozhestva paketov SYN rano ili pozdno zatrebuet vse resursy servera i sdelaet nevozmozhnoj obrabotku novyh zaprosov Takoj vid atak nazyvaetsya SYN flud SYN flood Protokol SCTP zashishyon ot podobnyh atak s pomoshyu mehanizma chetyryohetapnogo kvitirovaniya four way handshake i vvodom markera cookie Po protokolu SCTP klient nachinaet proceduru ustanovleniya soedineniya posylaya paket INIT V otvet server posylaet paket INIT ACK kotoryj soderzhit marker unikalnyj klyuch identificiruyushij novoe soedinenie Zatem klient otvechaet posylkoj paketa COOKIE ECHO v kotorom soderzhitsya marker poluchennyj ot servera Tolko posle etogo server vydelyaet svoi resursy novomu podklyucheniyu i podtverzhdaet eto otpravkoj klientu paketa COOKIE ACK Dlya resheniya problemy zaderzhki peresylki dannyh pri vypolnenii procedury chetyryohetapnogo kvitirovaniya v protokole SCTP dopuskaetsya vklyuchenie dannyh v pakety COOKIE ECHO i COOKIE ACK Poetapnoe zavershenie peredachi dannyhRassmotrim otlichiya mezhdu proceduroj zakrytiya soketov protokola SCTP i proceduroj chastichnogo zakrytiya half close protokola TCP V protokole TCP vozmozhna situaciya chastichnogo zakrytiya soedineniya kogda odin uzel zakonchil peredachu dannyh vypolniv posylku paketa FIN no prodolzhaet prinimat dannye po etomu soedineniyu Drugoj uzel mozhet prodolzhat peredavat dannye do teh por poka sam ne provedyot zakrytie soedineniya na svoej storone Sostoyanie chastichnogo zakrytiya ispolzuetsya prilozheniyami krajne redko poetomu razrabotchiki protokola SCTP poschitali nuzhnym zamenit ego posledovatelnostyu soobshenij dlya razryva sushestvuyushej associacii Kogda uzel zakryvaet svoj soket posylaet soobshenie SHUTDOWN oba korrespondenta dolzhny prekratit peredachu dannyh pri etom razreshaetsya lish obmen paketami podtverzhdayushimi priyom ranee otpravlennyh dannyh MnogopotochnostTCP upravlyaet posledovatelnostyu bajt dannye poslannye prilozheniem otpravitelem dolzhny postupat prilozheniyu poluchatelyu strogo v tom zhe poryadke v to vremya kak protokol IP sposoben pomenyat posledovatelnost paketov krome togo propavshie pakety posylayutsya povtorno i obychno pribyvayut k poluchatelyu s narusheniem posledovatelnosti dlya borby s etimi yavleniyami dannye nakaplivayutsya v bufere SCTP mozhet transportirovat dannye mezhdu dvumya tochkami uzlami odnovremenno po neskolkim potokam soobshenij V protivopolozhnost k TCP SCTP obrabatyvaet celye soobsheniya preserve message boundary a ne obychnye bajty informacii Etim SCTP pohozh na UDP Takim obrazom esli otpravitel otsylaet serveru soobshenie sostoyashee iz 100 bajt za pervyj shag a za nim eshyo 50 bajt to poluchatel za pervyj shag poluchit imenno pervye 100 bajt v pervom soobshenii a tolko zatem 50 bajt na vtoroj operacii chteniya iz soketa Termin mnogopotochnost angl multi streaming oboznachaet sposobnost SCTP parallelno peredavat po neskolkim nezavisimym potokam soobshenij Naprimer my peredayom neskolko fotografij cherez HTTP prilozhenie naprimer brauzer Mozhno ispolzovat dlya etogo svyazku iz neskolkih TCP soedinenij odnako takzhe dopustima SCTP associaciya angl SCTP association upravlyayushaya neskolkimi potokami soobshenij dlya etoj celi Potoki yavlyayutsya odnonapravlennymi to est peredayut informaciyu tolko v odnom napravlenii kartinka vyshe yavlyaetsya netochnoj TCP dostigaet pravilnogo poryadka bajt v potoke abstraktno naznachaya poryadkovyj nomer kazhdoj otoslannoj edinice a uporyadochivaya prinyatye bajty ispolzuya naznachennye poryadkovye nomera po mere ih pribyvaniya S drugoj storony SCTP prisvaivaet razlichnye poryadkovye nomera soobsheniyam posylaemym v konkretnom potoke Eto razreshaet nezavisimoe uporyadochivanie soobshenij po raznym potokam Tak ili inache mnogopotochnost yavlyaetsya opciej v SCTP V zavisimosti ot zhelanij polzovatelskogo prilozheniya soobsheniya mogut byt obrabotany ne v poryadke ih otpravleniya a v poryadke ih postupleniya DostoinstvaDostoinstva ispolzovaniya SCTP vklyuchayut v sebya Ispolzovanie mnozhestvennyh interfejsov angl Multihoming Dopustim u nas est dva hosta I hotya by odin iz nih imeet neskolko setevyh interfejsov i sootvetstvenno neskolko IP adresov V TCP ponyatie soedinenie oznachaet obmen dannymi mezhdu dvumya tochkami v to vremya kak v SCTP imeet mesto koncepciya associacii angl association oboznachayushaya vsyo proishodyashee mezhdu dvumya uzlami Mnogopotochnost Dannye prihodyat v tochku po nezavisimym potokam Eto pozvolyaet ustranit fenomen en Head of line blocking kotorym tak stradaet TCP Poisk puti s monitoringom Protokolom vybiraetsya pervichnyj marshrut peredachi dannyh a takzhe proizvoditsya proverka i monitoring svyaznosti puti Mehanizmy proverki podlinnosti Zashita adresata ot flood atak tehnologiya 4 way handshake i uvedomlenie o poteryannyh paketah i narushennyh cepochkah Uluchshennaya sistema kontrolya oshibok podhodyashaya dlya jumbo paketov v Ethernet Chast dostoinstv vytekaet iz togo fakta chto iznachalno razrabotchiki SCTP proektirovali protokol pod nuzhdy peredachi telefonii SS7 po protokolu IP NedostatkiBolshaya zanimaemaya polosa to est otnositelnyj obyom sluzhebnogo trafika bolshe chem pri ispolzovanii TCP UDP BezopasnostSCTP byl razrabotan s nekotorymi funkciyami pozvolyayushimi povysit bezopasnost takimi kak 4 kratnoe rukopozhatie po sravneniyu s tryohkratnym rukopozhatiem v TCP chtoby predotvratit SYN flood ataki i bolshih Cookie dlya proverki podlinnosti associacii Nadyozhnost byla odnim iz klyuchevyh aspektov razrabotki bezopasnosti protokola SCTP Multi homing pozvolyaet associacii ostavatsya otkrytoj dazhe esli nekotorye ispolzuemye marshruty i interfejsy stali nedostupny Eto imeet osoboe znachenie dlya SIGTRAN kotoryj ispolzuya SCTP peredayot soobsheniya i servisy protokolov OKS 7 poverh IP seti chto trebuet silnoj ustojchivosti vo vremya otklyuchenij linkov dlya podderzhaniya telekommunikacionnyh uslug dazhe pri seryoznyh anomaliyah v seti Shifrovanie ne yavlyaetsya chastyu originalnogo dizajna SCTP V nekotoryh sluchayah SCTP yavlyaetsya horoshim kandidatom dlya angl Prichinoj dlya etogo yavlyaetsya tot fakt chto nekotorye operacionnye sistemy rasprostranyayutsya s podderzhkoj protokola SCTP no vvidu ego slaboj izvestnosti po sravneniyu s TCP ili UDP administratory inogda zabyvayut nastroit v brandmauere obnaruzheniya vtorzhenij chto dayot vozmozhnosti dlya skanirovaniya trafika Sravnenie vozmozhnostej protokolov transportnogo urovnyaParametr UDP TCP SCTPUstanovka soedineniya Net Da DaNadyozhnaya peredacha Net Da DaSohranenie granic soobsheniya Da Net DaUporyadochennaya dostavka Net Da DaNeuporyadochennaya dostavka Da Net DaKontrolnye summy dannyh Da Da DaRazmer kontrolnoj summy bit 16 16 32MTU puti Net Da DaUpravlenie nakopleniem Net Da DaMnogopotochnost Net Net DaPodderzhka mnozhestvennyh interfejsov Net Net DaSvyazka potokov Net Da DaFormirovanie kadrov soobsheniyaPri formirovanii kadrov soobsheniya obespechivaetsya sohranenie granic soobsheniya v tom vide v kotorom ono peredayotsya soketu eto oznachaet chto esli klient posylaet serveru 100 bajt za kotorymi sleduyut 50 bajt to server vosprinimaet 100 bajt i 50 bajt za dve operacii chteniya Tochno tak zhe funkcioniruet protokol UDP eto yavlyaetsya osobennostyu protokolov orientirovannyh na rabotu s soobsheniyami V protivopolozhnost im protokol TCP obrabatyvaet nestrukturirovannyj potok bajt Esli ne ispolzovat proceduru formirovaniya kadrov soobsheniya to uzel seti mozhet poluchat dannye po razmeru bolshe ili menshe otpravlennyh Takoj rezhim funkcionirovaniya trebuet chtoby dlya protokolov orientirovannyh na rabotu s soobsheniyami i funkcioniruyushih poverh protokola TCP na prikladnom urovne byl predostavlen specialnyj bufer dannyh i vypolnyalas procedura formirovaniya kadrov soobshenij chto potencialno yavlyaetsya slozhnoj zadachej Protokol SCTP obespechivaet formirovanie kadrov pri peredache dannyh Kogda uzel vypolnyaet zapis v soket ego korrespondent s garantiej poluchaet blok dannyh togo zhe razmera Struktura paketaBity Bity 0 7 8 15 16 23 24 31 0 Port istochnika Port naznacheniya32 Teg proverki64 Kontrolnaya summa96 Tip 1 bloka Flagi 1 bloka Dlina 1 bloka128 Dannye 1 bloka Tip N bloka Flagi N bloka Dlina N bloka Dannye N bloka SCTP pakety imeyut bolee prostuyu strukturu chem pakety TCP Kazhdyj paket sostoit iz dvuh osnovnyh razdelov Obshij zagolovok kotoryj zanimaet pervye 12 bajt vydeleny sinim cvetom Bloki dannyh kotorye zanimayut ostavshuyusya chast paketa Pervyj blok otmechen zelyonym cvetom i poslednij iz blokov N N blok vydelen krasnym Kazhdyj blok imeet identifikator tipa zanimayushij odin bajt Takim obrazom vozmozhno opredelenie ne bolee 255 razlichnyh tipov blokov RFC 4960 opredelyaet spisok tipov blokov vsego na dannyj moment opredeleno 15 tipov Ostalnaya chast bloka sostoit iz polya dliny razmerom v 2 bajta maksimalnaya dlina kotoraya mozhet soderzhatsya v dannom pole ravna 65535 bajtam i sobstvenno dannyh Esli razmer bloka ne kraten 4 bajtam to on zapolnyaetsya nulyami do razmera kratnogo 4 bajtam Obrabotka oshibokPovtor peredachi Povtornaya peredacha blokov DATA mozhet byt obuslovlena a tajm autom opredelyaemym tajmerom povtora retransmission timer ili b polucheniem SACK pokazyvayushih chto blok DATA ne byl poluchen adresatom Dlya snizheniya veroyatnosti nasysheniya povtor peredachi blokov DATA ogranichivaetsya Znachenie tajm auta dlya povtora RTO ustanavlivaetsya na osnove ocenki vremeni krugovogo obhoda i umenshaetsya eksponencialno s rostom chastoty poteri soobshenij Dlya aktivnyh associacij s pochti postoyannym urovnem trafika DATA prichinoj povtora skorej vsego budut soobsheniya SACK a ne tajm aut Dlya snizheniya veroyatnosti nenuzhnyh povtorov ispolzuetsya pravilo 4 SACK v sootvetstvii s kotorym povtor peredachi proishodit tolko po chetvyortomu SACK ukazyvayushemu na propusk bloka dannyh Eto pozvolyaet predotvratit povtory peredachi vyzvannye narusheniem poryadka dostavki Sboj v puti Podderzhivaetsya schyotchik dlya chisla povtorov peredachi po konkretnomu adresu poluchatelya bez podtverzhdeniya uspeshnoj dostavki Kogda znachenie etogo schyotchika dostigaet zadannogo poroga konfiguracionnyj parametr adres obyavlyaetsya neaktivnym i protokol SCTP nachinaet ispolzovat drugoj adres dlya peredachi blokov DATA Krome togo po vsem neispolzuemym dopolnitelnym adresam periodicheski peredayutsya specialnye bloki Heartbeat i podderzhivaetsya schyotchik chisla blokov Heartbeat peredannyh bez vozvrata sootvetstvuyushego Heartbeat Ack Kogda znachenie schyotchika dostigaet zadannogo poroga parametr konfiguracii sootvetstvuyushij adres obyavlyaetsya neaktivnym Bloki Heartbeat peredayutsya po neaktivnym adresam do teh por poka ne budet polucheno soobshenie Ack govoryashee o vosstanovlenii aktivnosti adresa Chastota peredachi blokov Heartbeat opredelyaetsya znacheniem RTO i dopolnitelnoj zaderzhkoj kotoraya pozvolyaet peredavat bloki Heartbeat bez pomeh dlya polzovatelskogo trafika Otkaz v konechnoj tochke Dlya vseh adresov poluchatelya podderzhivaetsya obshij schyotchik chisla povtorov ili blokov Heartbeat peredachi dannyh udalyonnoj tochke bez polucheniya ot neyo sootvetstvuyushego podtverzhdeniya Ack Kogda znachenie schyotchika dostigaet zadannogo poroga parametr konfiguracii konechnaya tochka deklariruetsya kak nedostizhimaya i associaciya SCTP zakryvaetsya Prichiny poyavleniyaProtokol TCP predostavlyaet osnovnye sredstva dlya peredachi dannyh po seti Internet po nadyozhnomu puti Odnako TCP nakladyvaet nekotorye ogranicheniya na transport dannyh TCP predostavlyaet nadyozhnuyu peredachu dannyh v strogoj posledovatelnosti Tem ne menee odni prilozheniya trebuyut peredachu bez upravleniya i kontrolya posledovatelnosti a drugie budut vpolne udovletvoreny chastichnoj uporyadochennostyu dannyh Oba etih sluchaya stradayut iz za nenuzhnyh zaderzhek svyazannyh s vosstanovleniem i uporyadochivaniem narushennyh posledovatelnostej TCP Priroda TCP orientirovana na potok bajt chto vyzyvaet neudobstva Prilozheniya vynuzhdeny samostoyatelno dobavlyat sobstvennye markery v pakety chtoby rasparallelit peredachu sobstvennyh soobshenij a takzhe ispolzovat dopolnitelnye uhishreniya chtoby ubeditsya v tom chto celoe soobshenie bylo dostavleno za opredelyonnoe vremya Ogranichennye ramki vozmozhnostej TCP soketov eshyo bolee uslozhnyayut zadachu predostavleniya vozmozhnosti parallelnoj peredachi informacii k hostam po neskolkim kanalam svyazi sm multi homing vyshe TCP otnositelno uyazvim dlya atak klassa Otkaz v obsluzhivanii DoS takim kak SYN flood Vse eti ogranicheniya nanosyat usherb proizvoditelnosti raboty telefonnyh setej cherez IP Protokol byl razrabotan v ramkah raboty specialno sozdannoj gruppy SIGTRAN v sostave IETF dlya realizacii protokolov i adaptacij steka OKS 7 dlya primeneniya v IP setyah v svyazi s neobhodimostyu nadyozhnoj i bystroj dostavki dannyh Eto pryamo otrazheno v glave 1 1 Motivation Pobuzhdenie RFC 4960 Transport of PSTN signaling across the IP network is an application for which all of these limitations of TCP are relevant While this application directly motivated the development of SCTP other applications may find SCTP a good match to their requirements Peredacha signalizacii TfOP po IP seti eto primenenie dlya kotorogo vse ogranicheniya TCP imeyut neposredstvennoe otnoshenie Hotya eto napryamuyu motivirovalo razrabotku SCTP drugie prilozheniya mogut takzhe opredelit SCTP kak horosho sootvetstvuyushij ih trebovaniyam RFC 4960 Shema protokolov i adaptacij SIGTRAN Protokoly OKS 7 TCAP MTP3 MTP3 ISUP SCCP DSS1 TCAPSIGTRAN M3UA Kompyuternaya set SCTPIPRealizaciiSushestvuet referensnaya realizaciya pod FreeBSD Mac OS X Microsoft Windows i Linux Protokol SCTP realizovan v sleduyushih operacionnyh sistemah AIX Version 5 i novee BSD UNIX s vneshnim patchem ot angl Cisco IOS 12 i novee DragonFly BSD nachinaya s versii 1 4 podderzhka prekrashena v versii 4 2 FreeBSD nachinaya s versii 7 referensnaya realizaciya HP UX s versii 11i v2 i novee Linux versiya 2 4 i novee QNX Neutrino Realtime OS v versiyah s 6 3 0 po 6 3 2 no s 6 4 0 podderzhka prekrashena Sun Solaris 10 i novee VxWorks versii s 6 2 x po 6 4 x zatem s 6 7 i novee Realizaciya cherez storonnie drajvery Windows drajver SctpDrv yavlyaetsya portirovannym stekom SCTP iz BSD Mac OS X rasshirenie SCTP Network Kernel Extension Otdelnye polzovatelskie biblioteki Portable SCTP userland stack The SCTP libraryPortirovannaya versiya biblioteki pod Windows XP Java SE 7 Erlang OTP Prilozheniya SSH Secure Shell WebRTCPrimechaniyaTCP i UDP rabotayut stol razlichno chto provodit analogiyu k nim oboim nekorrektno Vsya analogiya v tom chto SCTP TCP i UDP otnosyatsya k odnomu i tomu zhe urovnyu steka TCP IP neopr www ietf org Data obrasheniya 16 oktyabrya 2018 Arhivirovano iz originala 29 oktyabrya 2018 goda Reference Implementation for SCTP RFC4960 neopr This is the reference implementation for SCTP It is portable and runs on FreeBSD MAC OS Windows and in User Space including linux Data obrasheniya 14 oktyabrya 2013 1 marta 2017 goda DragonFly Removes SCTP neopr Lists dragonflybsd org Data obrasheniya 28 aprelya 2016 7 avgusta 2017 goda About FreeBSD s Technological Advances neopr The FreeBSD Project 9 marta 2008 SCTP FreeBSD 7 0 is the reference implementation for the new IETF Stream Control Transmission Protocol SCTP protocol intended to support VoIP telecommunications and other applications with strong reliability and variable quality transmission through features such as multi path delivery fail over and multi streaming Data obrasheniya 13 sentyabrya 2008 5 avgusta 2011 goda Stream Control Transmission Protocol SCTP neopr Hewlett Packard Development Company Data obrasheniya 10 marta 2017 Arhivirovano iz originala 3 yanvarya 2013 goda TCP IP Networking neopr QNX Developer Support QNX Software Systems Data obrasheniya 13 sentyabrya 2008 23 oktyabrya 2008 goda What s New in this Reference neopr QNX Library Reference QNX Software Systems Data obrasheniya 18 dekabrya 2012 18 oktyabrya 2012 goda Solaris 10 Operating System Networking Extreme Network Performance neopr Sun Microsystems Data obrasheniya 13 sentyabrya 2008 20 aprelya 2009 goda neopr Data obrasheniya 4 fevralya 2011 Arhivirovano iz originala 8 yanvarya 2011 goda SCTP Network Kernel Extension for Mac OS X neopr Data obrasheniya 10 marta 2017 11 iyunya 2018 goda A portable SCTP userland stack neopr Data obrasheniya 10 marta 2017 20 dekabrya 2018 goda SCTP Download Page neopr 29 maya 2006 Data obrasheniya 4 fevralya 2011 22 aprelya 2019 goda Windows SCTP library installer neopr Data obrasheniya 4 fevralya 2011 11 sentyabrya 2016 goda Seggelmann R Tuxen M Rathgeb E P SSH over SCTP Optimizing a multi channel protocol by adapting it to SCTP angl Communication Systems Networks amp Digital Signal Processing CSNDSP 2012 8th International Symposium on journal 2012 18 July P 1 6 ISBN 978 1 4577 1473 3 doi 10 1109 CSNDSP 2012 6292659 SsylkiRFC 3286 http rfc2 ru 3286 rfc ot 24 sentyabrya 2010 na Wayback Machine perevod RFC 3286 na russkij yazyk http www sctp de ot 24 fevralya 2021 na Wayback Machine RFC 2960 Stream Control Transmission Protocol RFC 3257 Stream Control Transmission Protocol Applicability Statement RFC 3286 An Introduction to the Stream Control Transmission Protocol SCTP RFC 3309 Stream Control Transmission Protocol SCTP Checksum Change RFC 3436 Transport Layer Security over Stream Control Transmission Protocol RFC 3554 On the Use of Stream Control Transmission Protocol SCTP with IPsec RFC 3758 Stream Control Transmission Protocol SCTP Partial Reliability Extension RFC 3873 Stream Control Transmission Protocol SCTP Management Information Base MIB RFC 4460 Stream Control Transmission Protocol SCTP Specification Errata and Issues RFC 4820 Padding Chunk and Parameter for the Stream Control Transmission Protocol SCTP RFC 4895 Authenticated Chunks for the Stream Control Transmission Protocol SCTP RFC 4960 Stream Control Transmission Protocol RFC 5061 Stream Control Transmission Protocol SCTP Dynamic Address Reconfiguration RFC 5062 Security Attacks Found Against the Stream Control Transmission Protocol SCTP and Current Countermeasures, Википедия, чтение, книга, библиотека, поиск, нажмите, истории, книги, статьи, wikipedia, учить, информация, история, скачать, скачать бесплатно, mp3, видео, mp4, 3gp, jpg, jpeg, gif, png, картинка, музыка, песня, фильм, игра, игры, мобильный, телефон, Android, iOS, apple, мобильный телефон, Samsung, iphone, xiomi, xiaomi, redmi, honor, oppo, nokia, sonya, mi, ПК, web, Сеть, компьютер
Вершина