A study of two intrusion detection methods-from email virus detection to web content self-integrity measurement
博士 === 國立中央大學 === 資訊管理研究所 === 94 === Security assurance is the basis for success on the Internet. Viruses and worms constitute a great threat. Many countermeasures have been applied to counteract these malicious threats. Signature-based detection method works well only for a known virus or worm. It...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2006
|
Online Access: | http://ndltd.ncl.edu.tw/handle/9t5stc |
id |
ndltd-TW-094NCU05396080 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-094NCU053960802018-05-17T04:28:46Z http://ndltd.ncl.edu.tw/handle/9t5stc A study of two intrusion detection methods-from email virus detection to web content self-integrity measurement 兩種入侵偵測方法之研究-從電子郵件病毒偵測到網頁完整性檢驗 Da-Wei Lin 林大為 博士 國立中央大學 資訊管理研究所 94 Security assurance is the basis for success on the Internet. Viruses and worms constitute a great threat. Many countermeasures have been applied to counteract these malicious threats. Signature-based detection method works well only for a known virus or worm. It is very difficult to defend against an unknown virus or worm. Anomaly detection has the potential to detect unknown attacks. In this thesis, we proposed an abnormal mail detection method based on user mailing behavior. In our observation, human communication would form many parties. This characteristic can help us to differentiate the mailing behavior from email viruses. The proposed method can help us to detect new unknown viruses at the beginning of virus outbreak. To model user behavior is not easy, however, since user behavior may change over time. In the second part of this thesis, we propose a web content protection method which has a very low error rate. It is based on the concept of “integrity”, that is, the information content can be represented by an integrity value. Integrity is a unique value for any given information content. From a distinct prospective, we measure the integrity of Web content, instead of detecting the intrusion directly. If the integrity is violated it means that content modification has occurred. There is no needed of signature updating which is necessary in signature-based detection system. Besides, the computation time is better than that of the traditional type of signature-based detection systems in the long run. In the future, we plan to construct an email system by combining the integrity concept into the email system design. Yi-Min Chen 陳奕明 2006 學位論文 ; thesis 88 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
博士 === 國立中央大學 === 資訊管理研究所 === 94 === Security assurance is the basis for success on the Internet. Viruses and worms constitute a great threat. Many countermeasures have been applied to counteract these malicious threats. Signature-based detection method works well only for a known virus or worm. It is very difficult to defend against an unknown virus or worm. Anomaly detection has the potential to detect unknown attacks. In this thesis, we proposed an abnormal mail detection method based on user mailing behavior. In our observation, human communication would form many parties. This characteristic can help us to differentiate the mailing behavior from email viruses. The proposed method can help us to detect new unknown viruses at the beginning of virus outbreak.
To model user behavior is not easy, however, since user behavior may change over time. In the second part of this thesis, we propose a web content protection method which has a very low error rate. It is based on the concept of “integrity”, that is, the information content can be represented by an integrity value. Integrity is a unique value for any given information content. From a distinct prospective, we measure the integrity of Web content, instead of detecting the intrusion directly. If the integrity is violated it means that content modification has occurred. There is no needed of signature updating which is necessary in signature-based detection system. Besides, the computation time is better than that of the traditional type of signature-based detection systems in the long run. In the future, we plan to construct an email system by combining the integrity concept into the email system design.
|
author2 |
Yi-Min Chen |
author_facet |
Yi-Min Chen Da-Wei Lin 林大為 |
author |
Da-Wei Lin 林大為 |
spellingShingle |
Da-Wei Lin 林大為 A study of two intrusion detection methods-from email virus detection to web content self-integrity measurement |
author_sort |
Da-Wei Lin |
title |
A study of two intrusion detection methods-from email virus detection to web content self-integrity measurement |
title_short |
A study of two intrusion detection methods-from email virus detection to web content self-integrity measurement |
title_full |
A study of two intrusion detection methods-from email virus detection to web content self-integrity measurement |
title_fullStr |
A study of two intrusion detection methods-from email virus detection to web content self-integrity measurement |
title_full_unstemmed |
A study of two intrusion detection methods-from email virus detection to web content self-integrity measurement |
title_sort |
study of two intrusion detection methods-from email virus detection to web content self-integrity measurement |
publishDate |
2006 |
url |
http://ndltd.ncl.edu.tw/handle/9t5stc |
work_keys_str_mv |
AT daweilin astudyoftwointrusiondetectionmethodsfromemailvirusdetectiontowebcontentselfintegritymeasurement AT líndàwèi astudyoftwointrusiondetectionmethodsfromemailvirusdetectiontowebcontentselfintegritymeasurement AT daweilin liǎngzhǒngrùqīnzhēncèfāngfǎzhīyánjiūcóngdiànziyóujiànbìngdúzhēncèdàowǎngyèwánzhěngxìngjiǎnyàn AT líndàwèi liǎngzhǒngrùqīnzhēncèfāngfǎzhīyánjiūcóngdiànziyóujiànbìngdúzhēncèdàowǎngyèwánzhěngxìngjiǎnyàn AT daweilin studyoftwointrusiondetectionmethodsfromemailvirusdetectiontowebcontentselfintegritymeasurement AT líndàwèi studyoftwointrusiondetectionmethodsfromemailvirusdetectiontowebcontentselfintegritymeasurement |
_version_ |
1718639909056544768 |