透過您的圖書館登入
IP:3.15.229.113
  • 學位論文

環境相依之入侵偵測系統測試平台

Environment Dependent Testing Platform for Intrusion Detection System

指導教授 : 田筱榮 黃世昆
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


入侵偵測系統(Intrusion Detection System, IDS)是電腦安全防禦一個重要的機制,藉著入侵偵測系統的協助,我們可以察覺網路環境中的異常行為,並採取相對應的處理機制。然而入侵偵測系統種類繁多,其功能各有所長,IDS使用者希望在採購時知道哪一個是最合適的系統。在使用時知道所用的IDS提供的效能如何,因此我們需要一個考量系統與環境特性的評估架構。 本篇論文中提出一個入侵偵測系統的測試平台。希望藉由此測試平台,有效地比較在每一個特定環境當中,各種入侵偵測系統的效能。讓使用者可以依據此測試結果,選擇適合自己的入侵偵測系統來防衛自己的網域。 我們的測試平台考慮了入侵偵測系統跟環境的相依性,因為一個入侵偵測系統在不同的環境中會有不同的偵測效能與結果。測試平台包含三個子系統:環境分析、測試規劃與IDS稽核檔的分析。環境分析子系統檢視使用者環境的特徵及缺失。測試規劃子系統經由使用者介面提供工具箱協助使用者根據其環境特性建置特定的測試內容。最後的IDS稽核檔分析則是將實驗後的結果繪製成受端運作特性圖(Receiver Operating Characteristic, ROC)圖形,表現出一個入侵偵測系統的偵測率 (detection rate) 與誤報率 (false alarm rate) 的關係,其曲線亦可當作我們判斷入侵偵測系統效能的基準。 我們以研究室當作測試環境,進行一系列的掃瞄、檢視及實際的測試,並對結果進行探討與分析。

並列摘要


Intrusion detection system (IDS) is an important mechanism in protecting computer system security. With assistance of IDS, we can discover abnormal behavior in the network environment and, in response to that, take corresponding actions to deal with it. Many intrusion detection systems and their merits are different. Users want to know which candidate IDS among the availables will fit their needs best before making a procurement decision, or, if an Intrusion detection system is adapted already, how well it performs. It calls for an evaluation framework that takes the characteristic pertaining individual system and network environment into concern. In this thesis, an Intrusion Detection System testing platform was proposed. With this platform, the performance of various kind of IDSs can be evaluated in the contests of specific network environments. And users can select a proper IDS to protect their network environment according to the testing result. The proposed platform considers the dependence relation between IDS performance and the application environment, since the same IDS may have different detection performance in distinct environments. It consists of three subsystems: Environment Analysis, Test Planning and Log Analysis. The Environment Analysis subsystem examines the characteristic and critical flaws of the application environment. The Test Planning subsystem provides toolkit through an User Interface which allows users to construct specific test profile to their environment. According to the test result, Log Analysis Subsystem produces Receiver Operating Characteristic (ROC) curves of individual IDS. With ROC curves, the relation of detection rate and false alarm rate of an intrusion detection system can be comprehended easily. The proposed platform has been done a series of scanning, auditing and testing against the environment in our laboratory. The result was examined and analyzed.

參考文獻


[1] P. Innella, O. McMillan, “An Introduction to Intrusion Detection Systems”, http://online.securityfocus.com/infocus/1520
[4] 趙育釧, “考量環境因素下入侵偵測系統效能評估基準之建立”, 中原大學資訊工程研究所碩士論文, 2001.
[5] MedCalc, Receiver Operating Characteristic curves (ROC curves), http://www.medcalc.be/index.html, 2002.
[6] MIT Lincoln Laboratory – DARPA Intrusion Detection Evaluation, http://www.ll.mit.edu/IST/ideval/index.html, 2002.
[7] R. Lippmann, D. Fried, I. Graf, J. Haines, K. Kendall, D. McClung, D. Weber, S. Webster, D. Wyschogrod, R. Cunningham, M. Zissman, “Evaluating intrusion detection systems: the 1998 DARPA off-line intrusion detection evaluation”, Proceedings of the 2000 DARPA Information Survivability Conference and Exposition, 2000, volume: 2, pages: 12 –26, 2000.

被引用紀錄


簡嘉煌(2003)。以成本效益模型評估入侵偵測系統〔碩士論文,中原大學〕。華藝線上圖書館。https://doi.org/10.6840/cycu200300492
曾俊溶(2010)。汽車駕駛疲勞偵測系統研發〔碩士論文,國立臺灣大學〕。華藝線上圖書館。https://doi.org/10.6342/NTU.2010.00658

延伸閱讀