A Study of Alert-Based Collaborative Defense
碩士 === 國立交通大學 === 電機資訊學院碩士在職專班 === 93 === This thesis proposes a lightweight alert-based collaborative defense solution. We notice that malicious attack is difficult to prevent in the enterprise interior. Because it is hard to analyze a large number of logs and alerts, the administrator can not cont...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | en_US |
Published: |
2005
|
Online Access: | http://ndltd.ncl.edu.tw/handle/47592549324960755416 |
id |
ndltd-TW-093NCTU5446005 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-093NCTU54460052016-06-06T04:11:37Z http://ndltd.ncl.edu.tw/handle/47592549324960755416 A Study of Alert-Based Collaborative Defense 一個以警報為基礎的聯合防禦系統 Hsin Wen-Yi 辛文義 碩士 國立交通大學 電機資訊學院碩士在職專班 93 This thesis proposes a lightweight alert-based collaborative defense solution. We notice that malicious attack is difficult to prevent in the enterprise interior. Because it is hard to analyze a large number of logs and alerts, the administrator can not control the situation and make decision immediately. The Worms, Virus and Trojan spread rapidly, the scale of the problem is large and growing rapidly. Modern Security Systems have many predicaments. We had discussed the intrusion detection, distributed intrusion system, collaborative defense system, security information sharing mechanism and alert analysis in this thesis. We propose a framework for collaborative defense by extending the original distributed intrusion detection model. It contains alert’s collector, extractor, analyzer, report’s generator, alert warehouse and alert’s analysis. Besides, we develop a hybrid approach to share security information like raising the wolf smoke to warn partners. By the security information sharing, the members of CSIRT can obtain the solutions of defense, such as blacklists, detection rules, and security knowledge about alerts. The framework provides a solution to build effective cooperative security teams for academia and industry. We evaluate the feasibility of our framework and track the spreading behaviors of the SQL Slammer Worm. As a result, we can deploy security system more widely and detect the aggressor's behavior more accurately. The alert-based collaborative defense mechanism can help members to evaluate the impact of the threats and take proper actions to mitigate the risk. Shian-Shyong Tseng 曾憲雄 2005 學位論文 ; thesis 66 en_US |
collection |
NDLTD |
language |
en_US |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 國立交通大學 === 電機資訊學院碩士在職專班 === 93 === This thesis proposes a lightweight alert-based collaborative defense solution.
We notice that malicious attack is difficult to prevent in the enterprise interior. Because it is hard to analyze a large number of logs and alerts, the administrator can not control the situation and make decision immediately. The Worms, Virus and Trojan spread rapidly, the scale of the problem is large and growing rapidly. Modern Security Systems have many predicaments. We had discussed the intrusion detection, distributed intrusion system, collaborative defense system, security information sharing mechanism and alert analysis in this thesis.
We propose a framework for collaborative defense by extending the original distributed intrusion detection model. It contains alert’s collector, extractor, analyzer, report’s generator, alert warehouse and alert’s analysis. Besides, we develop a hybrid approach to share security information like raising the wolf smoke to warn partners. By the security information sharing, the members of CSIRT can obtain the solutions of defense, such as blacklists, detection rules, and security knowledge about alerts. The framework provides a solution to build effective cooperative security teams for academia and industry.
We evaluate the feasibility of our framework and track the spreading behaviors of the SQL Slammer Worm. As a result, we can deploy security system more widely and detect the aggressor's behavior more accurately. The alert-based collaborative defense mechanism can help members to evaluate the impact of the threats and take proper actions to mitigate the risk.
|
author2 |
Shian-Shyong Tseng |
author_facet |
Shian-Shyong Tseng Hsin Wen-Yi 辛文義 |
author |
Hsin Wen-Yi 辛文義 |
spellingShingle |
Hsin Wen-Yi 辛文義 A Study of Alert-Based Collaborative Defense |
author_sort |
Hsin Wen-Yi |
title |
A Study of Alert-Based Collaborative Defense |
title_short |
A Study of Alert-Based Collaborative Defense |
title_full |
A Study of Alert-Based Collaborative Defense |
title_fullStr |
A Study of Alert-Based Collaborative Defense |
title_full_unstemmed |
A Study of Alert-Based Collaborative Defense |
title_sort |
study of alert-based collaborative defense |
publishDate |
2005 |
url |
http://ndltd.ncl.edu.tw/handle/47592549324960755416 |
work_keys_str_mv |
AT hsinwenyi astudyofalertbasedcollaborativedefense AT xīnwényì astudyofalertbasedcollaborativedefense AT hsinwenyi yīgèyǐjǐngbàowèijīchǔdeliánhéfángyùxìtǒng AT xīnwényì yīgèyǐjǐngbàowèijīchǔdeliánhéfángyùxìtǒng AT hsinwenyi studyofalertbasedcollaborativedefense AT xīnwényì studyofalertbasedcollaborativedefense |
_version_ |
1718295809877868544 |