A study of two intrusion detection methods-from email virus detection to web content self-integrity measurement

博士 === 國立中央大學 === 資訊管理研究所 === 94 === Security assurance is the basis for success on the Internet. Viruses and worms constitute a great threat. Many countermeasures have been applied to counteract these malicious threats. Signature-based detection method works well only for a known virus or worm. It...

Full description

Bibliographic Details
Main Authors: Da-Wei Lin, 林大為
Other Authors: Yi-Min Chen
Format: Others
Language:zh-TW
Published: 2006
Online Access:http://ndltd.ncl.edu.tw/handle/9t5stc
id ndltd-TW-094NCU05396080
record_format oai_dc
spelling ndltd-TW-094NCU053960802018-05-17T04:28:46Z http://ndltd.ncl.edu.tw/handle/9t5stc A study of two intrusion detection methods-from email virus detection to web content self-integrity measurement 兩種入侵偵測方法之研究-從電子郵件病毒偵測到網頁完整性檢驗 Da-Wei Lin 林大為 博士 國立中央大學 資訊管理研究所 94 Security assurance is the basis for success on the Internet. Viruses and worms constitute a great threat. Many countermeasures have been applied to counteract these malicious threats. Signature-based detection method works well only for a known virus or worm. It is very difficult to defend against an unknown virus or worm. Anomaly detection has the potential to detect unknown attacks. In this thesis, we proposed an abnormal mail detection method based on user mailing behavior. In our observation, human communication would form many parties. This characteristic can help us to differentiate the mailing behavior from email viruses. The proposed method can help us to detect new unknown viruses at the beginning of virus outbreak. To model user behavior is not easy, however, since user behavior may change over time. In the second part of this thesis, we propose a web content protection method which has a very low error rate. It is based on the concept of “integrity”, that is, the information content can be represented by an integrity value. Integrity is a unique value for any given information content. From a distinct prospective, we measure the integrity of Web content, instead of detecting the intrusion directly. If the integrity is violated it means that content modification has occurred. There is no needed of signature updating which is necessary in signature-based detection system. Besides, the computation time is better than that of the traditional type of signature-based detection systems in the long run. In the future, we plan to construct an email system by combining the integrity concept into the email system design. Yi-Min Chen 陳奕明 2006 學位論文 ; thesis 88 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 博士 === 國立中央大學 === 資訊管理研究所 === 94 === Security assurance is the basis for success on the Internet. Viruses and worms constitute a great threat. Many countermeasures have been applied to counteract these malicious threats. Signature-based detection method works well only for a known virus or worm. It is very difficult to defend against an unknown virus or worm. Anomaly detection has the potential to detect unknown attacks. In this thesis, we proposed an abnormal mail detection method based on user mailing behavior. In our observation, human communication would form many parties. This characteristic can help us to differentiate the mailing behavior from email viruses. The proposed method can help us to detect new unknown viruses at the beginning of virus outbreak. To model user behavior is not easy, however, since user behavior may change over time. In the second part of this thesis, we propose a web content protection method which has a very low error rate. It is based on the concept of “integrity”, that is, the information content can be represented by an integrity value. Integrity is a unique value for any given information content. From a distinct prospective, we measure the integrity of Web content, instead of detecting the intrusion directly. If the integrity is violated it means that content modification has occurred. There is no needed of signature updating which is necessary in signature-based detection system. Besides, the computation time is better than that of the traditional type of signature-based detection systems in the long run. In the future, we plan to construct an email system by combining the integrity concept into the email system design.
author2 Yi-Min Chen
author_facet Yi-Min Chen
Da-Wei Lin
林大為
author Da-Wei Lin
林大為
spellingShingle Da-Wei Lin
林大為
A study of two intrusion detection methods-from email virus detection to web content self-integrity measurement
author_sort Da-Wei Lin
title A study of two intrusion detection methods-from email virus detection to web content self-integrity measurement
title_short A study of two intrusion detection methods-from email virus detection to web content self-integrity measurement
title_full A study of two intrusion detection methods-from email virus detection to web content self-integrity measurement
title_fullStr A study of two intrusion detection methods-from email virus detection to web content self-integrity measurement
title_full_unstemmed A study of two intrusion detection methods-from email virus detection to web content self-integrity measurement
title_sort study of two intrusion detection methods-from email virus detection to web content self-integrity measurement
publishDate 2006
url http://ndltd.ncl.edu.tw/handle/9t5stc
work_keys_str_mv AT daweilin astudyoftwointrusiondetectionmethodsfromemailvirusdetectiontowebcontentselfintegritymeasurement
AT líndàwèi astudyoftwointrusiondetectionmethodsfromemailvirusdetectiontowebcontentselfintegritymeasurement
AT daweilin liǎngzhǒngrùqīnzhēncèfāngfǎzhīyánjiūcóngdiànziyóujiànbìngdúzhēncèdàowǎngyèwánzhěngxìngjiǎnyàn
AT líndàwèi liǎngzhǒngrùqīnzhēncèfāngfǎzhīyánjiūcóngdiànziyóujiànbìngdúzhēncèdàowǎngyèwánzhěngxìngjiǎnyàn
AT daweilin studyoftwointrusiondetectionmethodsfromemailvirusdetectiontowebcontentselfintegritymeasurement
AT líndàwèi studyoftwointrusiondetectionmethodsfromemailvirusdetectiontowebcontentselfintegritymeasurement
_version_ 1718639909056544768