Abstract:
An apparatus and method for processing packets are disclosed. The apparatus for processing packets includes a session processing unit, a parallel processing unit, and a storage unit. The session processing unit divides a packet group, including a plurality of HTTP packets, into a plurality of session files, and then distributes the session files. The parallel processing unit generates metadata and extracts content from each of the distributed session files based on the plurality of session files. The storage unit stores the metadata generated by the parallel processing unit and the content extracted by the parallel processing unit.
Abstract:
A packet analysis apparatus and method and a VPN server, which secure evidence against a situation in which a hacker disguises a packet as a normal packet so as to make an attack using a VPN server as a router. The packet analysis apparatus includes a packet classification unit for classifying packets provided and collected from a host into encrypted VPN packets and plaintext packets. A first comparative analysis unit compares contents of an encapsulated IP datagram of each encrypted VPN packet, obtained by decrypting the encrypted VPN packet, with contents of a plaintext IP datagram that is included in each plaintext packet and that is present for a target to which the host desires to transfer the encrypted VPN packet. A second comparative analysis unit compares lengths of the encapsulated IP datagram and the plaintext IP datagram with each other.