在區域網路中部署的專用感測器節點「RoamSwitch Sensor」
RoamSwitch Sensor 是部署於區域網路內的專用節點,從外部稽核同一區域網路上的 RoamSwitch 終端(Mac / Linux Client / Server Edition)。會確認「從同一區域網路的其他裝置看過來是什麼樣子」(開放連接埠、無需驗證即可存取的服務、橫向移動的立足點),這是主機自我診斷在原理上無法看見的。同時也提供區域網路裝置台帳與 ARP 欺騙偵測。
🛡️ 主動漏洞稽核(僅針對已配對端點)
由全連接埠掃描 → 已知特徵偵測(Redis/dockerd/Memcached/MongoDB/Elasticsearch/CouchDB/Jenkins/VNC 未授權暴露、SMBv1 與未強制 SMB 簽章、RDP 未強制 NLA、SMTP 開放中繼等)→ 通用 Banner 取得 → nmap NSE 補充掃描共 4 個階段構成,全程不含任何破壞性操作。
📋 掌握網路組成(主動 ARP 掃描)
透過 ARP 掃描找出區域網路內的裝置。將 IP、MAC、主機名稱、廠商、線上狀態、首次/最近偵測時間與 IP 歷程整理成裝置清單,並可為每台裝置自由填寫名稱、用途等備註。沒有備註的裝置會標示為「需確認」,可用於與資產清單核對。未安裝 nmap 時,會退回到只顯示 Sensor 自己通訊過之裝置的被動模式。
👁️ ARP 事件與「下一步操作」
新裝置出現,以及已知 IP 對應的 MAC 變化(ARP 詐騙的跡象),會連同發生時間、嚴重程度(嚴重~資訊)、判斷依據、相關裝置的身分與具體的查證步驟一併提供。閘道器 IP 的 MAC 變化視為「嚴重」。啟用選用的被動擷取後,也能偵測單一裝置對大量 IP 發送 ARP 請求(內網偵察)。
🔎 掌握區域網路內其他裝置與可疑行為(僅偵測)
以參考資訊的形式提供:MAC 廠商與裝置類別、依 mDNS/SSDP/DHCP 自我通告的型號辨識、連線至已知惡意 IP 或管理連接埠、殭屍網路/DDoS 參與跡象(連線至大量目的地)、DNS 通道/C2 跡象。多數功能需啟用選用的被動擷取設定(例如鏡像連接埠),且 Sensor 不會封鎖任何流量。
🔑 配對碼方式(Ed25519・固定 IP)
初始狀態下不信任任何裝置。在端點端輸入 Sensor 操作者發放的、10 分鐘內有效的一次性配對碼,並搭配 Sensor 的固定 IP 位址,即可在一次操作中同時建立雙向信任。公鑰會自動交換,無需事先得知。無需雲端註冊或建立帳號。
📅 定期稽核與差異比對(可選擇啟用)
依排程自動稽核所有已配對的端點,並顯示與上一次稽核相比的變化——新增發現、已解決項目和新開放的連接埠。若先前開放的連接埠全部看不到了,會視為「疑似無法連線」,而不是「已解決」。即使無人值守,Sensor 也會在每次稽核前後確認端點仍是其認證時的 MAC 位址;若該 IP 已屬於其他裝置,則不進行稽核。預設關閉,可設定執行間隔與允許執行的時間帶。
📣 通知與稽核證據(可選擇啟用)
可將迴歸、新裝置、ARP 欺騙等通知到 Webhook(Slack、Discord、Teams 等)與 syslog(RFC 5424)。配對、解除配對、稽核與設定變更會連同執行者記錄到具備防竄改能力的操作紀錄(雜湊鏈)中,稽核結果、裝置清單與操作紀錄可匯出為 CSV、JSON 或 HTML 報告(可在瀏覽器中另存為 PDF)。所有通知目的地均由維運人員自行設定,預設不傳送任何內容。
🗂️ 彙總多個 Sensor(中央收集器,可選擇啟用)
面向在多個據點部署 Sensor 的組織,隨附一個收集帶簽章摘要的中央收集器(預設不啟用)。提供依據點檢視狀態的儀表板與 CSV 匯出,並能偵測 Sensor 端稽核紀錄被截斷或倒轉。僅接受已登錄 Sensor 所傳送的帶簽章請求,未啟用 TLS 時不允許對區域網路之外開放。
如需對 Sensor 本身進行攻擊防護,建議在同一台機器上另行安裝 RoamSwitch for Linux 的 Server Edition,兩者可作為完全獨立的行程共存。
稽核報告輸出範例
這是透過 roamswitch-sensor export all --format html(TUI 中為 e 鍵)匯出的報告範例。它是單一 HTML 檔案,以瀏覽器開啟後選擇「另存為 PDF」即可得到可提交給稽核人員的 PDF。
RoamSwitch Sensor 稽核報告
| 建立時間 (UTC) | 2026-09-20T02:30:12.508136294+00:00 |
|---|---|
| 據點 | 總部 3 樓伺服器機房 |
| Sensor 公開金鑰 | +kbYCoN5jJSykTAr8zDv/VCs2SdBcrwYbkCrzCRgsLM= |
| 稽核日誌 | 完整性驗證:正常(未遭竄改),18 筆,head #18 771a265c58fa2f0a8990bc6be79ff5259d96a76a0a3fea472f308df02eaa087f |
各裝置最新稽核結果
| 裝置 | 位址 | 執行時間 | 偵測 | 開放連接埠 |
|---|---|---|---|---|
| web-prod-01 | 192.168.20.21 | 2026-09-20T02:00:43.318204577+00:00 | 1 項 | 2 |
| db-prod-01 | 192.168.20.22 | 2026-09-20T02:01:14.774390215+00:00 | 2 項 | 3 |
| dev-laptop-07 | 192.168.20.35 | 2026-09-20T02:02:07.120765432+00:00 | 無問題 | 1 |
偵測事項
| 時間 | 裝置 | 連接埠 | 描述 | 建議處置 |
|---|---|---|---|---|
| 2026-09-20T02:01:14.774390215+00:00 | db-prod-01 | 22 | SSH 版本橫幅公開 此 SSH 伺服器在連線時會公開版本橫幅。橫幅本身屬正常行為,但會成為攻擊者縮小已知弱點範圍的線索。 | 請將 SSH 更新至最新版本,並視需要精簡橫幅內容。 |
| 2026-09-20T02:01:14.774390215+00:00 | db-prod-01 | 6379 | 已知弱點:CVE-2021-32626 (Redis) NVD 說明(英文原文):Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be overflowed, due to incomplete checks for this condition. This can result with heap corruption and potentially remote code execution. This problem exists in all versions of Redis with Lua scripting support, starting from 2.6. The problem is fixed in versions 6.2.6, 6.0.16 and 5.0.14. | 請盡快將 Redis 升級至不受 CVE-2021-32626 影響的版本,在此之前請限制未經驗證的網路存取。 |
| 2026-09-20T02:00:43.318204577+00:00 | web-prod-01 | 22 | SSH 版本橫幅公開 此 SSH 伺服器在連線時會公開版本橫幅。橫幅本身屬正常行為,但會成為攻擊者縮小已知弱點範圍的線索。 | 請將 SSH 更新至最新版本,並視需要精簡橫幅內容。 |
| 2026-09-19T08:33:18.402118906+00:00 | db-prod-01 | 22 | SSH 版本橫幅公開 此 SSH 伺服器在連線時會公開版本橫幅。橫幅本身屬正常行為,但會成為攻擊者縮小已知弱點範圍的線索。 | 請將 SSH 更新至最新版本,並視需要精簡橫幅內容。 |
裝置清冊(在區域網路中觀測到的所有裝置)
| MAC | IP | 主機名稱 | 廠商 | RoamSwitch 管理 | 備註 |
|---|---|---|---|---|---|
| 00:1b:8b:3c:9a:07 | 192.168.20.1 | _gateway | NEC Platforms | 未管理 | 總部閘道路由器 |
| 7c:8b:ca:61:d2:4e | 192.168.20.2 | TP-Link Technologies | 未管理 | 3 樓 Wi-Fi 存取點 | |
| e4:e7:49:2b:70:c1 | 192.168.20.3 | Hewlett Packard | 未管理 | 2 樓多功能事務機 | |
| 90:61:ae:17:4d:e2 | 192.168.20.21 | Intel Corporate | 已管理 | 正式環境 Web 伺服器 | |
| 90:61:ae:17:4d:f9 | 192.168.20.22 | Intel Corporate | 已管理 | 正式環境資料庫伺服器 | |
| 04:20:9a:cc:31:8f | 192.168.20.31 | sensor-hq-01 | Panasonic AVC Networks Company | 未管理 | RoamSwitch-Sensor |
| a0:c9:a0:5e:83:2b | 192.168.20.35 | Murata Manufacturing | 已管理 | 開發用筆記型電腦 | |
| 8e:0f:95:a2:64:5d | 192.168.20.44 | 未管理 | |||
| 5e:e2:59:1d:c8:03 | 192.168.20.45 | 未管理 | |||
| a8:3b:76:9c:20:e4 | 192.168.20.52 | Cloud Network Technology Singapore PTE. | 未管理 |
操作與核准日誌
| # | 時間 | 執行者 | 操作 | 適用對象 | 詳細資料 |
|---|---|---|---|---|---|
| 18 | 2026-09-20T02:02:07.120765432+00:00 | scheduler | audit_completed | dev-laptop-07 (Q9mW3sLp0xVc) | trigger=scheduled host=192.168.20.35 findings=0 open_ports=1 new_findings=0 resolved_findings=0 |
| 17 | 2026-09-20T02:02:05.402816653+00:00 | scheduler | audit_started | dev-laptop-07 (Q9mW3sLp0xVc) | host=192.168.20.35 |
| 16 | 2026-09-20T02:01:14.774390215+00:00 | scheduler | audit_completed | db-prod-01 (Zt4Kb8NwY1eR) | trigger=scheduled host=192.168.20.22 findings=2 open_ports=3 new_findings=1 resolved_findings=0 |
| 15 | 2026-09-20T02:01:12.117409552+00:00 | scheduler | audit_started | db-prod-01 (Zt4Kb8NwY1eR) | host=192.168.20.22 |
| 14 | 2026-09-20T02:00:43.318204577+00:00 | scheduler | audit_completed | web-prod-01 (Xk3F9aLm2QzB) | trigger=scheduled host=192.168.20.21 findings=1 open_ports=2 new_findings=1 resolved_findings=0 |
| 13 | 2026-09-20T02:00:41.029385714+00:00 | scheduler | audit_started | web-prod-01 (Xk3F9aLm2QzB) | host=192.168.20.21 |
| 12 | 2026-09-19T09:11:40.318842077+00:00 | cli:uid=1000 | config_changed | schedule.window_end_hour | value=5 |
| 11 | 2026-09-19T09:11:32.640571920+00:00 | cli:uid=1000 | config_changed | schedule.window_start_hour | value=1 |
| 10 | 2026-09-19T09:10:02.205197346+00:00 | cli:uid=1000 | config_changed | schedule.enabled | value=true |
| 9 | 2026-09-19T08:47:19.771263084+00:00 | control_api: | pair | dev-laptop-07 (Q9mW3sLp0xVc) | endpoint redeemed an operator-issued pairing code and was added to the audit scope |
| 8 | 2026-09-19T08:46:52.093718455+00:00 | cli:uid=1000 | pairing_code_issued | single-use, valid 10 minutes | |
| 7 | 2026-09-19T08:33:18.402118906+00:00 | cli:uid=1000 | audit_completed | db-prod-01 (Zt4Kb8NwY1eR) | trigger=manual host=192.168.20.22 findings=1 open_ports=2 new_findings=1 resolved_findings=0 |
| 6 | 2026-09-19T08:33:15.588240391+00:00 | cli:uid=1000 | audit_started | db-prod-01 (Zt4Kb8NwY1eR) | manual audit; host=192.168.20.22 |
| 5 | 2026-09-19T08:31:07.336914608+00:00 | control_api: | pair | db-prod-01 (Zt4Kb8NwY1eR) | endpoint redeemed an operator-issued pairing code and was added to the audit scope |
| 4 | 2026-09-19T08:30:41.874526103+00:00 | cli:uid=1000 | pairing_code_issued | single-use, valid 10 minutes | |
| 3 | 2026-09-19T08:12:26.152083967+00:00 | control_api: | pair | web-prod-01 (Xk3F9aLm2QzB) | endpoint redeemed an operator-issued pairing code and was added to the audit scope |
| 2 | 2026-09-19T08:11:58.960417225+00:00 | cli:uid=1000 | pairing_code_issued | single-use, valid 10 minutes | |
| 1 | 2026-09-19T08:00:03.415602838+00:00 | daemon | daemon_started | version 0.3.4 |
RoamSwitch Sensor Audit Report
| Generated (UTC) | 2026-09-20T02:30:12.508136294+00:00 |
|---|---|
| Site | HQ – 3F server room |
| Sensor public key | +kbYCoN5jJSykTAr8zDv/VCs2SdBcrwYbkCrzCRgsLM= |
| Audit log | Integrity check: OK (no tampering detected) — 18 entries, head #18 771a265c58fa2f0a8990bc6be79ff5259d96a76a0a3fea472f308df02eaa087f |
Latest audit per endpoint
| Endpoint | Address | Timestamp | Findings | Open ports |
|---|---|---|---|---|
| web-prod-01 | 192.168.20.21 | 2026-09-20T02:00:43.318204577+00:00 | 1 finding(s) | 2 |
| db-prod-01 | 192.168.20.22 | 2026-09-20T02:01:14.774390215+00:00 | 2 finding(s) | 3 |
| dev-laptop-07 | 192.168.20.35 | 2026-09-20T02:02:07.120765432+00:00 | clean | 1 |
Findings
| When | Endpoint | Port | Finding | Recommendation |
|---|---|---|---|---|
| 2026-09-20T02:01:14.774390215+00:00 | db-prod-01 | 22 | SSH Version Banner Disclosed This SSH server discloses its version banner on connect. This is normal SSH behavior, but the banner gives an attacker a starting point to look up known vulnerabilities for that version. | Keep SSH updated to the latest version, and minimize the banner's detail if your SSH implementation allows it. |
| 2026-09-20T02:01:14.774390215+00:00 | db-prod-01 | 6379 | Known Vulnerability: CVE-2021-32626 (Redis) Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be overflowed, due to incomplete checks for this condition. This can result with heap corruption and potentially remote code execution. This problem exists in all versions of Redis with Lua scripting support, starting from 2.6. The problem is fixed in versions 6.2.6, 6.0.16 and 5.0.14. | Upgrade Redis to a version not affected by CVE-2021-32626 as soon as possible, and restrict unauthenticated network access to it in the meantime. |
| 2026-09-20T02:00:43.318204577+00:00 | web-prod-01 | 22 | SSH Version Banner Disclosed This SSH server discloses its version banner on connect. This is normal SSH behavior, but the banner gives an attacker a starting point to look up known vulnerabilities for that version. | Keep SSH updated to the latest version, and minimize the banner's detail if your SSH implementation allows it. |
| 2026-09-19T08:33:18.402118906+00:00 | db-prod-01 | 22 | SSH Version Banner Disclosed This SSH server discloses its version banner on connect. This is normal SSH behavior, but the banner gives an attacker a starting point to look up known vulnerabilities for that version. | Keep SSH updated to the latest version, and minimize the banner's detail if your SSH implementation allows it. |
Device inventory (every device observed on the LAN)
| MAC | IP | Hostname | Vendor | Managed | Note |
|---|---|---|---|---|---|
| 00:1b:8b:3c:9a:07 | 192.168.20.1 | _gateway | NEC Platforms | no | HQ gateway router |
| 7c:8b:ca:61:d2:4e | 192.168.20.2 | TP-Link Technologies | no | 3F Wi-Fi access point | |
| e4:e7:49:2b:70:c1 | 192.168.20.3 | Hewlett Packard | no | 2F multifunction printer | |
| 90:61:ae:17:4d:e2 | 192.168.20.21 | Intel Corporate | yes | Production web server | |
| 90:61:ae:17:4d:f9 | 192.168.20.22 | Intel Corporate | yes | Production database server | |
| 04:20:9a:cc:31:8f | 192.168.20.31 | sensor-hq-01 | Panasonic AVC Networks Company | no | RoamSwitch-Sensor |
| a0:c9:a0:5e:83:2b | 192.168.20.35 | Murata Manufacturing | yes | Development laptop | |
| 8e:0f:95:a2:64:5d | 192.168.20.44 | no | |||
| 5e:e2:59:1d:c8:03 | 192.168.20.45 | no | |||
| a8:3b:76:9c:20:e4 | 192.168.20.52 | Cloud Network Technology Singapore PTE. | no |
Operation & approval log
| # | When | Actor | Action | Target | Detail |
|---|---|---|---|---|---|
| 18 | 2026-09-20T02:02:07.120765432+00:00 | scheduler | audit_completed | dev-laptop-07 (Q9mW3sLp0xVc) | trigger=scheduled host=192.168.20.35 findings=0 open_ports=1 new_findings=0 resolved_findings=0 |
| 17 | 2026-09-20T02:02:05.402816653+00:00 | scheduler | audit_started | dev-laptop-07 (Q9mW3sLp0xVc) | host=192.168.20.35 |
| 16 | 2026-09-20T02:01:14.774390215+00:00 | scheduler | audit_completed | db-prod-01 (Zt4Kb8NwY1eR) | trigger=scheduled host=192.168.20.22 findings=2 open_ports=3 new_findings=1 resolved_findings=0 |
| 15 | 2026-09-20T02:01:12.117409552+00:00 | scheduler | audit_started | db-prod-01 (Zt4Kb8NwY1eR) | host=192.168.20.22 |
| 14 | 2026-09-20T02:00:43.318204577+00:00 | scheduler | audit_completed | web-prod-01 (Xk3F9aLm2QzB) | trigger=scheduled host=192.168.20.21 findings=1 open_ports=2 new_findings=1 resolved_findings=0 |
| 13 | 2026-09-20T02:00:41.029385714+00:00 | scheduler | audit_started | web-prod-01 (Xk3F9aLm2QzB) | host=192.168.20.21 |
| 12 | 2026-09-19T09:11:40.318842077+00:00 | cli:uid=1000 | config_changed | schedule.window_end_hour | value=5 |
| 11 | 2026-09-19T09:11:32.640571920+00:00 | cli:uid=1000 | config_changed | schedule.window_start_hour | value=1 |
| 10 | 2026-09-19T09:10:02.205197346+00:00 | cli:uid=1000 | config_changed | schedule.enabled | value=true |
| 9 | 2026-09-19T08:47:19.771263084+00:00 | control_api: | pair | dev-laptop-07 (Q9mW3sLp0xVc) | endpoint redeemed an operator-issued pairing code and was added to the audit scope |
| 8 | 2026-09-19T08:46:52.093718455+00:00 | cli:uid=1000 | pairing_code_issued | single-use, valid 10 minutes | |
| 7 | 2026-09-19T08:33:18.402118906+00:00 | cli:uid=1000 | audit_completed | db-prod-01 (Zt4Kb8NwY1eR) | trigger=manual host=192.168.20.22 findings=1 open_ports=2 new_findings=1 resolved_findings=0 |
| 6 | 2026-09-19T08:33:15.588240391+00:00 | cli:uid=1000 | audit_started | db-prod-01 (Zt4Kb8NwY1eR) | manual audit; host=192.168.20.22 |
| 5 | 2026-09-19T08:31:07.336914608+00:00 | control_api: | pair | db-prod-01 (Zt4Kb8NwY1eR) | endpoint redeemed an operator-issued pairing code and was added to the audit scope |
| 4 | 2026-09-19T08:30:41.874526103+00:00 | cli:uid=1000 | pairing_code_issued | single-use, valid 10 minutes | |
| 3 | 2026-09-19T08:12:26.152083967+00:00 | control_api: | pair | web-prod-01 (Xk3F9aLm2QzB) | endpoint redeemed an operator-issued pairing code and was added to the audit scope |
| 2 | 2026-09-19T08:11:58.960417225+00:00 | cli:uid=1000 | pairing_code_issued | single-use, valid 10 minutes | |
| 1 | 2026-09-19T08:00:03.415602838+00:00 | daemon | daemon_started | version 0.3.4 |
所示的機器名稱、MAC 位址、IP 位址與金鑰均為虛構。報告本文以日文或英文輸出(日文以外的介面顯示英文版)。