博碩士論文 104522093 完整後設資料紀錄

DC 欄位 語言
DC.contributor資訊工程學系zh_TW
DC.creator黃柏勝zh_TW
DC.creatorBo-Sheng Huangen_US
dc.date.accessioned2017-8-22T07:39:07Z
dc.date.available2017-8-22T07:39:07Z
dc.date.issued2017
dc.identifier.urihttp://ir.lib.ncu.edu.tw:88/thesis/view_etd.asp?URN=104522093
dc.contributor.department資訊工程學系zh_TW
DC.description國立中央大學zh_TW
DC.descriptionNational Central Universityen_US
dc.description.abstract隨著科技的進步與連網裝置的普及,網路安全防護面臨嚴峻的挑戰。網路技術的快速發展也讓駭客的攻擊方式更加成熟且多樣化。如木馬病毒的散播、阻斷服務攻擊(Denial of Service, DoS)以及分散式阻斷服務攻擊(Distributed Denial of Service, DDoS)。其中最嚴重的資安問題之一便是分散式阻斷服務攻擊。網路技術的進步讓駭客的攻擊手法更加多元化,能夠透過切換不同的DDoS攻擊型態(SYN flooding、UDP flooding、ICMP flooding等)進行攻擊。若攻擊者發現攻擊方法無法達到預期目標時,也有可能轉換成其他的攻擊手法。如何有效偵測分散式阻斷服務攻擊並抵檔為重要的研究議題。 為了應付資訊安全易攻難守的問題,新型的防禦思維:移動目標防禦(Moving Target Defense, MTD)被提出,目的在於透過不斷地變動系統的資訊來拖延攻擊者探測的時程與攻擊成功的副作用。新型網路架構:軟體定義網路(Software Defined Network, SDN)與網路功能虛擬化(Network Function Virtualization, NFV)的出現也改變了未來網路安全防護的模式,未來網路安全架構的設計將朝可程式化與虛擬化的方向演進。本論文提出基於SDN、NFV與移動目標防禦之分散式阻斷服務攻擊防禦機制。利用多重模糊系統進行DDoS的偵測,並利用移動目標防禦進行DDoS的減緩與防禦。在DDoS攻擊發生時,透過多重模糊系統偵測並阻擋重點攻擊流量;若有可疑之DDoS流量,則利用SDN與移動目標防禦的概念重新導向流量,使用者能不受攻擊影響,正常獲取服務。zh_TW
dc.description.abstract With the advancement of technology and popularity of networking devices, network security is facing severe challenges. The rapid development of Internet technology also makes the hacker′s attack more mature and diversified. Such as Trojan virus, Denial of Service (DoS) and Distributed Denial of Service (DDoS). One of the most serious security problems is DDoS attack.The Development of Internet technology have made hacker′s attack more diversified and can be switched to different DDoS attacks (UDP flooding, ICMP flooding, etc.). If the attacker found that the attack method can not achieve the desired goal, it may be converted into other attacks. How to effectively detect DDoS attacks and mitigate it is an important research topics. In order to cope with information security issues, the new defensive thinking: Moving Target Defense (MTD) was proposed, the purpose of MTD is to constantly change the system information to delay the attacker detect and probe scheduling. The emergence of the new network architecture: Software Defined Network (SDN) and Network Function Virtualization (NFV) has also changed the future of network security scheme. The future design of the network security architecture will towards the programmable network and virtualized. This paper proposes a Distributed Denial of Service attack defense mechanism based on SDN, NFV and Moving Target Defense.Explicit multiple fuzzy systems to achieve DDoS detection and using Proxy VNF based Moving Target Defense mechanism to achieve DDoS mitigation. Using SDN to control and redirect packets flexibly. If there is suspicious traffic, the proposed approach can redirect suspicious traffic and quarantine, therefore shift the attack surface.en_US
DC.subject軟體定義網路zh_TW
DC.subject網路功能虛擬化zh_TW
DC.subject分散式阻斷服務攻擊zh_TW
DC.subject移動目標防禦zh_TW
DC.subject模糊理論zh_TW
DC.subjectSDNen_US
DC.subjectNFVen_US
DC.subjectMoving Target Defenseen_US
DC.subjectDDoSen_US
DC.subjectFuzzy Theoryen_US
DC.title基於SDN、NFV與移動目標防禦之分散式阻斷服務攻擊防禦機制zh_TW
dc.language.isozh-TWzh-TW
DC.titleSDN/NFV Based Moving Target DDoS Defense Mechanismen_US
DC.type博碩士論文zh_TW
DC.typethesisen_US
DC.publisherNational Central Universityen_US

若有論文相關問題,請聯絡國立中央大學圖書館推廣服務組 TEL:(03)422-7151轉57407,或E-mail聯絡  - 隱私權政策聲明