On Payload Transformation Mechanism with Privacy-Preserving and Packet Analysis Capability

碩士 === 國立中央大學 === 資訊管理研究所 === 97 === The emergence of the internet has provided convenient way to exchange information, but many cybercrime incidents and network attacks has been discovered. In order to prevent from numerous and complicated network attacks, defending against a large scale attacks be...

Full description

Bibliographic Details
Main Authors: Chun-Hao Tzeng, 曾俊豪
Other Authors: Yi-Ming Chen
Format: Others
Language:zh-TW
Published: 2009
Online Access:http://ndltd.ncl.edu.tw/handle/45672868412702865578
id ndltd-TW-097NCU05396085
record_format oai_dc
spelling ndltd-TW-097NCU053960852015-11-16T16:08:55Z http://ndltd.ncl.edu.tw/handle/45672868412702865578 On Payload Transformation Mechanism with Privacy-Preserving and Packet Analysis Capability 具隱私防護與分析能力之網路封包酬載轉換機制研究 Chun-Hao Tzeng 曾俊豪 碩士 國立中央大學 資訊管理研究所 97 The emergence of the internet has provided convenient way to exchange information, but many cybercrime incidents and network attacks has been discovered. In order to prevent from numerous and complicated network attacks, defending against a large scale attacks become more popular. In this architecture, individual organizations from anywhere would collect alerts or packets to share with SOC. However, packet payload has a lot of privacy information about corporations, we need to protect payload content. Anagram enables privacy-preserving payload sharing by using Bloom Filters. Generated payload signature still keep malicious signature, researcher can find anomalous payload, but Anagram has a poor detection rate when it detects short malicious signature and adjusting threshold is very difficult. We propose a payload transformative method: Group-Difference payload transformation. It would calculate groups and differences of payload character to encode the payload. Produced code is irreversible, attackers cannot get the original payload content. Produced code still keep signature of original payload, researcher can find malicious payload from produced code. Finally, we propose a privacy-preserving indicator to evaluate Group-Distance payload transformation, user can understand whether encode parameters are optimization or not. Yi-Ming Chen 陳奕明 2009 學位論文 ; thesis 59 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 國立中央大學 === 資訊管理研究所 === 97 === The emergence of the internet has provided convenient way to exchange information, but many cybercrime incidents and network attacks has been discovered. In order to prevent from numerous and complicated network attacks, defending against a large scale attacks become more popular. In this architecture, individual organizations from anywhere would collect alerts or packets to share with SOC. However, packet payload has a lot of privacy information about corporations, we need to protect payload content. Anagram enables privacy-preserving payload sharing by using Bloom Filters. Generated payload signature still keep malicious signature, researcher can find anomalous payload, but Anagram has a poor detection rate when it detects short malicious signature and adjusting threshold is very difficult. We propose a payload transformative method: Group-Difference payload transformation. It would calculate groups and differences of payload character to encode the payload. Produced code is irreversible, attackers cannot get the original payload content. Produced code still keep signature of original payload, researcher can find malicious payload from produced code. Finally, we propose a privacy-preserving indicator to evaluate Group-Distance payload transformation, user can understand whether encode parameters are optimization or not.
author2 Yi-Ming Chen
author_facet Yi-Ming Chen
Chun-Hao Tzeng
曾俊豪
author Chun-Hao Tzeng
曾俊豪
spellingShingle Chun-Hao Tzeng
曾俊豪
On Payload Transformation Mechanism with Privacy-Preserving and Packet Analysis Capability
author_sort Chun-Hao Tzeng
title On Payload Transformation Mechanism with Privacy-Preserving and Packet Analysis Capability
title_short On Payload Transformation Mechanism with Privacy-Preserving and Packet Analysis Capability
title_full On Payload Transformation Mechanism with Privacy-Preserving and Packet Analysis Capability
title_fullStr On Payload Transformation Mechanism with Privacy-Preserving and Packet Analysis Capability
title_full_unstemmed On Payload Transformation Mechanism with Privacy-Preserving and Packet Analysis Capability
title_sort on payload transformation mechanism with privacy-preserving and packet analysis capability
publishDate 2009
url http://ndltd.ncl.edu.tw/handle/45672868412702865578
work_keys_str_mv AT chunhaotzeng onpayloadtransformationmechanismwithprivacypreservingandpacketanalysiscapability
AT céngjùnháo onpayloadtransformationmechanismwithprivacypreservingandpacketanalysiscapability
AT chunhaotzeng jùyǐnsīfánghùyǔfēnxīnénglìzhīwǎnglùfēngbāochóuzàizhuǎnhuànjīzhìyánjiū
AT céngjùnháo jùyǐnsīfánghùyǔfēnxīnénglìzhīwǎnglùfēngbāochóuzàizhuǎnhuànjīzhìyánjiū
_version_ 1718130381722484736