On Payload Transformation Mechanism with Privacy-Preserving and Packet Analysis Capability
碩士 === 國立中央大學 === 資訊管理研究所 === 97 === The emergence of the internet has provided convenient way to exchange information, but many cybercrime incidents and network attacks has been discovered. In order to prevent from numerous and complicated network attacks, defending against a large scale attacks be...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2009
|
Online Access: | http://ndltd.ncl.edu.tw/handle/45672868412702865578 |
id |
ndltd-TW-097NCU05396085 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-097NCU053960852015-11-16T16:08:55Z http://ndltd.ncl.edu.tw/handle/45672868412702865578 On Payload Transformation Mechanism with Privacy-Preserving and Packet Analysis Capability 具隱私防護與分析能力之網路封包酬載轉換機制研究 Chun-Hao Tzeng 曾俊豪 碩士 國立中央大學 資訊管理研究所 97 The emergence of the internet has provided convenient way to exchange information, but many cybercrime incidents and network attacks has been discovered. In order to prevent from numerous and complicated network attacks, defending against a large scale attacks become more popular. In this architecture, individual organizations from anywhere would collect alerts or packets to share with SOC. However, packet payload has a lot of privacy information about corporations, we need to protect payload content. Anagram enables privacy-preserving payload sharing by using Bloom Filters. Generated payload signature still keep malicious signature, researcher can find anomalous payload, but Anagram has a poor detection rate when it detects short malicious signature and adjusting threshold is very difficult. We propose a payload transformative method: Group-Difference payload transformation. It would calculate groups and differences of payload character to encode the payload. Produced code is irreversible, attackers cannot get the original payload content. Produced code still keep signature of original payload, researcher can find malicious payload from produced code. Finally, we propose a privacy-preserving indicator to evaluate Group-Distance payload transformation, user can understand whether encode parameters are optimization or not. Yi-Ming Chen 陳奕明 2009 學位論文 ; thesis 59 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 國立中央大學 === 資訊管理研究所 === 97 === The emergence of the internet has provided convenient way to exchange information, but many cybercrime incidents and network attacks has been discovered. In order to prevent from numerous and complicated network attacks, defending against a large scale attacks become more popular. In this architecture, individual organizations from anywhere would collect alerts or packets to share with SOC.
However, packet payload has a lot of privacy information about corporations, we need to protect payload content. Anagram enables privacy-preserving payload sharing by using Bloom Filters. Generated payload signature still keep malicious signature, researcher can find anomalous payload, but Anagram has a poor detection rate when it detects short malicious signature and adjusting threshold is very difficult.
We propose a payload transformative method: Group-Difference payload transformation. It would calculate groups and differences of payload character to encode the payload. Produced code is irreversible, attackers cannot get the original payload content. Produced code still keep signature of original payload, researcher can find malicious payload from produced code. Finally, we propose a privacy-preserving indicator to evaluate Group-Distance payload transformation, user can understand whether encode parameters are optimization or not.
|
author2 |
Yi-Ming Chen |
author_facet |
Yi-Ming Chen Chun-Hao Tzeng 曾俊豪 |
author |
Chun-Hao Tzeng 曾俊豪 |
spellingShingle |
Chun-Hao Tzeng 曾俊豪 On Payload Transformation Mechanism with Privacy-Preserving and Packet Analysis Capability |
author_sort |
Chun-Hao Tzeng |
title |
On Payload Transformation Mechanism with Privacy-Preserving and Packet Analysis Capability |
title_short |
On Payload Transformation Mechanism with Privacy-Preserving and Packet Analysis Capability |
title_full |
On Payload Transformation Mechanism with Privacy-Preserving and Packet Analysis Capability |
title_fullStr |
On Payload Transformation Mechanism with Privacy-Preserving and Packet Analysis Capability |
title_full_unstemmed |
On Payload Transformation Mechanism with Privacy-Preserving and Packet Analysis Capability |
title_sort |
on payload transformation mechanism with privacy-preserving and packet analysis capability |
publishDate |
2009 |
url |
http://ndltd.ncl.edu.tw/handle/45672868412702865578 |
work_keys_str_mv |
AT chunhaotzeng onpayloadtransformationmechanismwithprivacypreservingandpacketanalysiscapability AT céngjùnháo onpayloadtransformationmechanismwithprivacypreservingandpacketanalysiscapability AT chunhaotzeng jùyǐnsīfánghùyǔfēnxīnénglìzhīwǎnglùfēngbāochóuzàizhuǎnhuànjīzhìyánjiū AT céngjùnháo jùyǐnsīfánghùyǔfēnxīnénglìzhīwǎnglùfēngbāochóuzàizhuǎnhuànjīzhìyánjiū |
_version_ |
1718130381722484736 |