A Study of Alert-Based Collaborative Defense

碩士 === 國立交通大學 === 電機資訊學院碩士在職專班 === 93 === This thesis proposes a lightweight alert-based collaborative defense solution. We notice that malicious attack is difficult to prevent in the enterprise interior. Because it is hard to analyze a large number of logs and alerts, the administrator can not cont...

Full description

Bibliographic Details
Main Authors: Hsin Wen-Yi, 辛文義
Other Authors: Shian-Shyong Tseng
Format: Others
Language:en_US
Published: 2005
Online Access:http://ndltd.ncl.edu.tw/handle/47592549324960755416
id ndltd-TW-093NCTU5446005
record_format oai_dc
spelling ndltd-TW-093NCTU54460052016-06-06T04:11:37Z http://ndltd.ncl.edu.tw/handle/47592549324960755416 A Study of Alert-Based Collaborative Defense 一個以警報為基礎的聯合防禦系統 Hsin Wen-Yi 辛文義 碩士 國立交通大學 電機資訊學院碩士在職專班 93 This thesis proposes a lightweight alert-based collaborative defense solution. We notice that malicious attack is difficult to prevent in the enterprise interior. Because it is hard to analyze a large number of logs and alerts, the administrator can not control the situation and make decision immediately. The Worms, Virus and Trojan spread rapidly, the scale of the problem is large and growing rapidly. Modern Security Systems have many predicaments. We had discussed the intrusion detection, distributed intrusion system, collaborative defense system, security information sharing mechanism and alert analysis in this thesis. We propose a framework for collaborative defense by extending the original distributed intrusion detection model. It contains alert’s collector, extractor, analyzer, report’s generator, alert warehouse and alert’s analysis. Besides, we develop a hybrid approach to share security information like raising the wolf smoke to warn partners. By the security information sharing, the members of CSIRT can obtain the solutions of defense, such as blacklists, detection rules, and security knowledge about alerts. The framework provides a solution to build effective cooperative security teams for academia and industry. We evaluate the feasibility of our framework and track the spreading behaviors of the SQL Slammer Worm. As a result, we can deploy security system more widely and detect the aggressor's behavior more accurately. The alert-based collaborative defense mechanism can help members to evaluate the impact of the threats and take proper actions to mitigate the risk. Shian-Shyong Tseng 曾憲雄 2005 學位論文 ; thesis 66 en_US
collection NDLTD
language en_US
format Others
sources NDLTD
description 碩士 === 國立交通大學 === 電機資訊學院碩士在職專班 === 93 === This thesis proposes a lightweight alert-based collaborative defense solution. We notice that malicious attack is difficult to prevent in the enterprise interior. Because it is hard to analyze a large number of logs and alerts, the administrator can not control the situation and make decision immediately. The Worms, Virus and Trojan spread rapidly, the scale of the problem is large and growing rapidly. Modern Security Systems have many predicaments. We had discussed the intrusion detection, distributed intrusion system, collaborative defense system, security information sharing mechanism and alert analysis in this thesis. We propose a framework for collaborative defense by extending the original distributed intrusion detection model. It contains alert’s collector, extractor, analyzer, report’s generator, alert warehouse and alert’s analysis. Besides, we develop a hybrid approach to share security information like raising the wolf smoke to warn partners. By the security information sharing, the members of CSIRT can obtain the solutions of defense, such as blacklists, detection rules, and security knowledge about alerts. The framework provides a solution to build effective cooperative security teams for academia and industry. We evaluate the feasibility of our framework and track the spreading behaviors of the SQL Slammer Worm. As a result, we can deploy security system more widely and detect the aggressor's behavior more accurately. The alert-based collaborative defense mechanism can help members to evaluate the impact of the threats and take proper actions to mitigate the risk.
author2 Shian-Shyong Tseng
author_facet Shian-Shyong Tseng
Hsin Wen-Yi
辛文義
author Hsin Wen-Yi
辛文義
spellingShingle Hsin Wen-Yi
辛文義
A Study of Alert-Based Collaborative Defense
author_sort Hsin Wen-Yi
title A Study of Alert-Based Collaborative Defense
title_short A Study of Alert-Based Collaborative Defense
title_full A Study of Alert-Based Collaborative Defense
title_fullStr A Study of Alert-Based Collaborative Defense
title_full_unstemmed A Study of Alert-Based Collaborative Defense
title_sort study of alert-based collaborative defense
publishDate 2005
url http://ndltd.ncl.edu.tw/handle/47592549324960755416
work_keys_str_mv AT hsinwenyi astudyofalertbasedcollaborativedefense
AT xīnwényì astudyofalertbasedcollaborativedefense
AT hsinwenyi yīgèyǐjǐngbàowèijīchǔdeliánhéfángyùxìtǒng
AT xīnwényì yīgèyǐjǐngbàowèijīchǔdeliánhéfángyùxìtǒng
AT hsinwenyi studyofalertbasedcollaborativedefense
AT xīnwényì studyofalertbasedcollaborativedefense
_version_ 1718295809877868544