A Distributed Denial-of-Service Resistant Intrusion Detection Scheme Using Mobile Agents
碩士 === 大葉大學 === 資訊管理學系碩士班 === 91 === Today, computer networks become increasingly, and the attacks have grown in complexity and automation. Successful distributed denial of service attacks can put e-commerce-based organizations out of business. As the capabilities of IDSs advance, attackers may atte...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2003
|
Online Access: | http://ndltd.ncl.edu.tw/handle/59450525833634111613 |
id |
ndltd-TW-091DYU00396027 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-091DYU003960272015-10-13T17:01:16Z http://ndltd.ncl.edu.tw/handle/59450525833634111613 A Distributed Denial-of-Service Resistant Intrusion Detection Scheme Using Mobile Agents 運用行動代理人抵抗分散式阻絕服務之入侵偵測機制 Cheng-Kuang Wu 吳正光 碩士 大葉大學 資訊管理學系碩士班 91 Today, computer networks become increasingly, and the attacks have grown in complexity and automation. Successful distributed denial of service attacks can put e-commerce-based organizations out of business. As the capabilities of IDSs advance, attackers may attempt to penetrate more valuable targets before disabling organizations’ IDSs. Thus, the preventive defense has been merged to improve the performance of intrusion detection systems (IDSs). In this thesis, we investigate effective methods for detecting and responding to DDoS attacks. We find that the existing hierarchical IDS architectures are prone to have single points of failure that are easily discovered by an attacker. To solve the problem of finding attackers and improving IDS’s weakness, we present an integrated scheme that is resistant to distributed denial of service attacks. First, we propose a cooperative intrusion detection System (CIDS) that consists of packet filtering, traceback of DDoS attack and network monitoring schemes. Second, CIDS can frustrate attackers by mobile agents’ fault-tolerant ability, and backup hosts that it intruded. Finally, we present formal proofs using the logical reasoning to validated our attack-resistant model. We also analyze the computational complexity of the proposed algorithm, and further implement the mobile agent based program. The results derived in the thesis consolidate the feasibility of our proposed schemes. 曹偉駿 2003 學位論文 ; thesis 0 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 大葉大學 === 資訊管理學系碩士班 === 91 === Today, computer networks become increasingly, and the attacks have grown in complexity and automation. Successful distributed denial of service attacks can put e-commerce-based organizations out of business. As the capabilities of IDSs advance, attackers may attempt to penetrate more valuable targets before disabling organizations’ IDSs. Thus, the preventive defense has been merged to improve the performance of intrusion detection systems (IDSs).
In this thesis, we investigate effective methods for detecting and responding to DDoS attacks. We find that the existing hierarchical IDS architectures are prone to have single points of failure that are easily discovered by an attacker. To solve the problem of finding attackers and improving IDS’s weakness, we present an integrated scheme that is resistant to distributed denial of service attacks. First, we propose a cooperative intrusion detection System (CIDS) that consists of packet filtering, traceback of DDoS attack and network monitoring schemes. Second, CIDS can frustrate attackers by mobile agents’ fault-tolerant ability, and backup hosts that it intruded. Finally, we present formal proofs using the logical reasoning to validated our attack-resistant model. We also analyze the computational complexity of the proposed algorithm, and further implement the mobile agent based program. The results derived in the thesis consolidate the feasibility of our proposed schemes.
|
author2 |
曹偉駿 |
author_facet |
曹偉駿 Cheng-Kuang Wu 吳正光 |
author |
Cheng-Kuang Wu 吳正光 |
spellingShingle |
Cheng-Kuang Wu 吳正光 A Distributed Denial-of-Service Resistant Intrusion Detection Scheme Using Mobile Agents |
author_sort |
Cheng-Kuang Wu |
title |
A Distributed Denial-of-Service Resistant Intrusion Detection Scheme Using Mobile Agents |
title_short |
A Distributed Denial-of-Service Resistant Intrusion Detection Scheme Using Mobile Agents |
title_full |
A Distributed Denial-of-Service Resistant Intrusion Detection Scheme Using Mobile Agents |
title_fullStr |
A Distributed Denial-of-Service Resistant Intrusion Detection Scheme Using Mobile Agents |
title_full_unstemmed |
A Distributed Denial-of-Service Resistant Intrusion Detection Scheme Using Mobile Agents |
title_sort |
distributed denial-of-service resistant intrusion detection scheme using mobile agents |
publishDate |
2003 |
url |
http://ndltd.ncl.edu.tw/handle/59450525833634111613 |
work_keys_str_mv |
AT chengkuangwu adistributeddenialofserviceresistantintrusiondetectionschemeusingmobileagents AT wúzhèngguāng adistributeddenialofserviceresistantintrusiondetectionschemeusingmobileagents AT chengkuangwu yùnyòngxíngdòngdàilǐréndǐkàngfēnsànshìzǔjuéfúwùzhīrùqīnzhēncèjīzhì AT wúzhèngguāng yùnyòngxíngdòngdàilǐréndǐkàngfēnsànshìzǔjuéfúwùzhīrùqīnzhēncèjīzhì AT chengkuangwu distributeddenialofserviceresistantintrusiondetectionschemeusingmobileagents AT wúzhèngguāng distributeddenialofserviceresistantintrusiondetectionschemeusingmobileagents |
_version_ |
1717777776926261248 |