透過您的圖書館登入
IP:18.225.57.49
  • 期刊

雲端開放資料分析運算平台之研究-以資訊安全紀錄檔分析為例

Cloud Computing Platform for Open Data Analysis

摘要


隨著電子商務蓬勃發展,近年來消費者的消費模式有著重大的改變,線上交易成為消費者重要的消費通路。因此電子商務網站以及企業也成為目標式攻擊(targeted attack)或是進階持續性滲透攻擊(Advanced Persistent Threat,簡稱APT)的目標之一。攻擊者針對特定目標使用先進且客製化攻擊技術,入侵目標網路與主機,並潛伏於企業中以竊取重要資訊。為了防禦攻擊,企業部署許多資訊安全設備,如防火牆、防毒軟體、入侵偵測系統等。由於目標式攻擊多半長時間潛伏於企業網路,因此偵測系統需要關聯大量且異質的資料。傳統偵測方式,已無法處理龐大且異質的資料,因此雲端運算成為入侵偵測與分析的重要平台之一。雲端運算平台的主要目的在於分散儲存與平行運算,提升運算效能。雲端運算系統之效能則取決(1)基礎建設的效能、(2)虛擬主機的規劃、以及(3)分析演算法的優劣。本研究以雲端主機規劃角度切入,探討如何虛擬主機與儲存空間之規畫對運算效能之影響。透過某企業之實際資料,評估本研究所提出之雲端運算平台效能。本研究採用支援向量機(support vector machine)對資料關聯性分析,找出可能的攻擊行為。本研究提供虛擬機器配置參數之建議,並建立一套偵測模型。透過本研究所提出的參數,企業可以根據本研究所提出之建議,以最經濟的方式建構雲端資訊安全分析平台。

並列摘要


The convenience of emerging electronic commerce and mobile commerce has changed the customer behaviors. Online purchase has played an important role on consumer shopping. In the meantime, high profit businesses have become primary targets for attackers, so called target attacks or advanced persistent threat (APT) attacks. Attackers apply high technology skills to attack high valued organizations, such as electronic commerce services, high tech companies, and governments. To protect the security of the premise, businesses have deployed various defense mechanisms, such as firewall, anti-virus software, spam filter, and intrusion detection system. To detect targeted attacks, the intrusion detection system requires to analyze and correlate a vast amount of log files in a long time span from various defense systems. The traditional computation model, a single powerful machine, was not capable of processing such big amount of data in a timely manner. Distributed cloud computing could improve the data processing performance. There are three aspects which influence the performance of cloud computing platform: (1) the infrastructure, (2) virtual machine planning, and (3) the data analysis model. By applying the real business data, this study proposed a cloud computing platform for analyzing security data. The study gives a list of recommendation on resource allocation of virtual machine and the minimum infrastructure specification for businesses which plan to apply for cloud platform in an economic way.

並列關鍵字

Big data cloud computing parallel computing

參考文獻


EMC Corporation (2011, June 28). EMC news: World's data more than doubling every Two Years-Driving big data opportunity, new IT roles. Retrieved December 1, 2016, from http://www.emc.com/about/news/press/2011/20110628-01.htm
Kambatla, K.,Kollias, G.,Kumar, V.,Grama, A.(2014).Trends in big data analytics.Journal of Parallel and Distributed Computing.74(7),2561-2573.
(Strauch, C., Sites, U. L. S., & Kriha, W. (2011). NoSQL Databases. Lecture Notes, Stuttgart Media University.).
He, P.,Zhu, J.,He, S.,Li, J.,Lyu, M. R.(2016).An evaluation study on log parsing and its use in log mining.Dependable Systems and Networks (DSN), 2016 46th Annual IEEE/IFIP International Conference.(Dependable Systems and Networks (DSN), 2016 46th Annual IEEE/IFIP International Conference).
White, T.(2012).Hadoop: The Definitive Guide.USA:O'Reilly Media, Inc..

延伸閱讀