:::

詳目顯示

回上一頁
題名:結合入侵偵測和蜜罐之分散式預警系統的設計與實現
書刊名:資訊、科技與社會學報
作者:黃培生楊中皇
出版日期:2009
卷期:16
頁次:頁83-97
主題關鍵詞:防火牆入侵偵測系統蜜罐惡意程式FirewallIntrusion detection systemHoneypotMalware
原始連結:連回原系統網址new window
相關次數:
  • 被引用次數被引用次數:期刊(1) 博士論文(0) 專書(0) 專書論文(0)
  • 排除自我引用排除自我引用:1
  • 共同引用共同引用:0
  • 點閱點閱:30
網路世界的攻防是永無止境的戰爭。伴隨著網際網路的快速發展,網路攻擊也隨之增加且多樣化,面對不斷變種的惡意程式和推陳出新的攻擊手法,僅使用傳統防火牆和入侵偵測技術的系統已無法對應此一快速變化。為因應此一趨勢,可藉蜜罐吸引惡意攻擊,並將攻擊過程記錄下來,藉蜜罐收集的資訊 (如:攻擊類型、惡意程式檔案、執行的程序和指令等),分析惡意攻擊所使用的方法、工具及動機,以作為預測或防治攻擊的參考資料。 本研究結合開放原始碼軟體建立一套分散式預警系統,收集大範圍的網路攻擊趨勢 (包含惡意程式活動和駭客攻擊行為) 及警示訊息通知,藉由彙整過的資訊,讓資訊安全人員提前收到警訊通知,並瞭解目前網路攻擊的行為與意圖,以擬定應變措施、確保網路安全。本系統結合 Snort、Nepenthes、Sebek 等入侵偵測及蜜罐工具,增加不同攻擊面向的記錄、分析能力。若發生攻擊行為,管理者可收到正在進行的攻擊警告,並使用統計攻擊資訊,來瞭解攻擊行為特性、推論發動攻擊的工具與方式。建置完成的分散式預警系統可安裝於 Live USB,藉由 Live USB 的高可攜性與隨插即用的特色,降低分散式預警系統部署的負擔。
Network attack and defense is a never-ending war. Along with the rapid development of the Internet, network attacks have increased and diversified. Use of traditional firewall and intrusion detection technologies cannot match to this rapid change. In response to this trend, we designed and implemented a distributed early warning system where several clients collected a wide range of network attack activities, such as malicious codes, sent attack activities back to a central server, and provided warning messages to the network administrator. The proposed system consists of Snort intrusion detection system with Nepenthes/Sebek honeypot software. This combination comes with client and server architecture so that various aspects of attack-oriented records with analytical capabilities are provided. Network administrators will receive warning notices when the entire network under monitoring was attacking. To reduce the burden on the deployment of distributed early warning system, we also implemented the system on the live USB and our system can be easily installed with high portability and plug-and-play features.
期刊論文
1.李駿偉、田筱榮、黃世昆(20020300)。入侵偵測分析方法評估與比較。資訊安全通訊,8(2),21-37。  延伸查詢new window
2.張思源(1998)。揭開防火牆的神祕面紗。網路通訊雜誌,75,107-109。  延伸查詢new window
3.Artail, H.、Safa, H.、Sraj, M.、Kuwatly, I.、Al-Masri, Z.(2006)。A Hybrid Honeypot Framework for Improving Intrusion Detection Systems in Protecting Organizational Networks。Computers & Security,25(4),274-288。  new window
4.Bellovin, S. M.、Cheswick, W. R.(1994)。Network Firewalls。IEEE Communications Magazine,32(9),50-57。  new window
5.Chuvakin, A.(2003)。Honeynets: High Value Security Data: Analysis of Real Attacks Launched at a Honeypot。Network Security,2003(8),11-15。  new window
6.Levine, J. G.、Grizzard, J. B.、Owen, H. L.(2004)。Using Honeynets to Protect Large Enterprise Networks。IEEE Security & Privacy,2(6),56-58。  new window
7.McGraw, G.、Morrisett, G.(2000)。Attacking Malicious Code: a Report to the Infosec Research Council。IEEE Software,17(5),33-41。  new window
8.McHugh, J.、Christie, A.、Allen, J.(2000)。Defending Yourself: The Role of Intrusion Detection Systems。IEEE Software,17(5),42-51。  new window
會議論文
1.黃家楷、邱國政、黃盈源、馮立琪(2003)。一個可動態調控的元件化網路式入侵偵測系統。第十三屆全國資訊安全會議,333-340。  延伸查詢new window
2.Cuppens, F.、Miège, A.(2002)。Alert Correlation in a Cooperative Intrusion Detection Framework202-215。  new window
3.Singh, S.、Kaur, G.(2007)。Unsupervised Anomaly Detection In Network Intrusion Detection Using Clusters107-110。  new window
4.Zhang, F.、Zhou, S.、Qin, Z.、Liu, J.(2003)。Honeypot: a Supplemented Active Defense System for Network Security231-235。  new window
圖書
1.楊中皇(2008)。網路安全:理論與實務。台北。  延伸查詢new window
其他
1.賴明豐(2007)。蜜罐技術的分析與應用。  延伸查詢new window
2.賽門鐵克公司。入侵偵測系統:誘捕式網路防禦技術的演進。  延伸查詢new window
3.賽門鐵克公司。第十三期網路安全威脅研究報告。  延伸查詢new window
4.Computer Security Institute。CSI computer crime and security survey。  new window
5.Nepenthes,http://nepenthes.mwcollect.org/。  new window
6.Pillay, H.。The Magic of Live CDs。  new window
7.Prelude,http://www.prelude-ids.com/。  new window
8.Sebek,http://www.honeynet.org/tools/sebek/。  new window
9.Snort,http://www.snort.org/。  new window
10.Spitzner, L.(2003)。Honeypots: Simple, Cost-Effective Detection。  new window
11.Spitzner, Lance(2003)。Honeytokens: The Other Honeypot,http://www.securityfocus.com/infocus/1713。  new window
12.VirusTotal,http://www.virustotal.com/zh-tw/。  new window
 
 
 
 
第一頁 上一頁 下一頁 最後一頁 top
QR Code
QRCODE