透過您的圖書館登入
IP:52.14.240.178
  • 學位論文

入侵偵測系統快速原型架構

A Fast Prototyping Framework for Intrusion Detection

指導教授 : 田筱榮
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


入侵偵測系統在於安全防護架構上可說是不可缺少的一環, 因此我們對於入侵偵測系統的改善做更進一步的研究。 綜觀目前的研究,我們發現在眾多不同的入侵偵測系統裡 雖然都可達到入侵偵測的功能,但卻無法讓管理者能夠相當 容易的去組成一個適合其所需的入侵偵測系統,換言之便是 目前的入侵偵測系統沒有提供快速原型的方式。快速原型架構 在入侵偵測上的應用可以讓管理者進一步接觸不同特性的入侵偵測系統。 在本論文中,試著在不同的入侵偵測系統內找尋相同的組成元素, 其原因是為了要讓快速原型入侵偵測系統更容易實作出來。 有了入侵偵測系統相同的組成元素之後,我們發現每種不同的元素 可採用層次的方式來表達,於是便提出多層次入侵偵測系統。 多層次入侵偵測系統與一般常見整合型的入侵偵測系統的看法不同, 所以在本文中將會提出為何以及如何使用多層次入侵偵測系統。 藉由軟體形式的分析多層次入侵偵測系統能夠更具體展現,而軟體形式 包含了架構形式分析與設計形式分析。架構形式分析整體性質而 設計分析則再更深入研究軟體結構。除此之外我們還說明這個系統 可以應用上的範例,以及討論這個系統的執行效率、擴增能力、與 偵測效能等等。

並列摘要


Intrusion detection system is an essential portion of the whole security framework; thus we pay much attention on the IDSs refinement issue. From other IDS researches, we realize that general IDSs have ability to detect intrusion, but hardly having the capability to let system administrator easily modeling an new IDSs according to their architecture. Hence, we propose fast prototyping framework for intrusion detection. In this thesis, we investigate into different IDSs and try to find the same elements of them, and this helps to pay true the fast prototyping framework. After IDS main elements are observed, we found that IDS essential elements can be interpreted as software layers. Hence, a multi-layer IDS is proposed to accomplish the goal of fast prototyping for intrusion detection. However, the multi-layer IDS design concept is far away from all-in-one IDS in the past, so we will describe why and how to use multiple layers while modeling an IDS with MLIDS. And through software pattern analysis MLIDS framework then becomes more concrete and real. Besides the implementation, we show how to add components into layers in MLIDS framework, and also demonstrate some applications. To justify the fitness of variety environment, we discuss efficiency, capacity, and performance of it.

參考文獻


[3] A. K. Gosh, J. Wanken, F. Charron, "Detecting Anomalous and Unknown Intrusions Against Programs", 14th Annual Computer Security Applications Conference, 7-11 December, 1998
[7] Millers Liang, An Adaptive Feature Selection Method for Intrusion Detection System, June 2000
[8] Common Intrusion Detection Framework, http://www.gidos.org/
[9] Common Intrusion Specification Language, http://www.gidos.org/drafts/language.txt
[10] Internet Engineering Task Force, http://www.ietf.org

被引用紀錄


吳志聰(2003)。以特徵探勘提升入侵偵測系統效率〔碩士論文,中原大學〕。華藝線上圖書館。https://doi.org/10.6840/cycu200300136
李駿偉(2002)。入侵偵測系統分析方法效能之定量評估〔碩士論文,中原大學〕。華藝線上圖書館。https://doi.org/10.6840/cycu200200377

延伸閱讀