博碩士論文 974203034 完整後設資料紀錄

DC 欄位 語言
DC.contributor資訊管理學系zh_TW
DC.creator陳玉佩zh_TW
DC.creatorYu-Pei Chenen_US
dc.date.accessioned2010-7-21T07:39:07Z
dc.date.available2010-7-21T07:39:07Z
dc.date.issued2010
dc.identifier.urihttp://ir.lib.ncu.edu.tw:88/thesis/view_etd.asp?URN=974203034
dc.contributor.department資訊管理學系zh_TW
DC.description國立中央大學zh_TW
DC.descriptionNational Central Universityen_US
dc.description.abstract企業組織以異質資安設備架構出大範圍網路聯合防禦網,藉由區域聯合防禦方式,能提供聯合防禦網中的成員獲取充足威脅預警資訊。將公司內部產生的資安警訊送給資訊安全營運管理中心(Security Operation Center,以下簡稱SOC)處理,但警訊難免會暗藏一些公司內部網路資訊及敏感隱私內容,使得企業組織不願意和外界分享內部資安設備所偵測的警訊,為了避免被惡意者取得企業組織機密資訊,造成商譽或資產損害。然而每家企業的資安政策不同,所要求的隱私保護程度也不同,依據分享者不同的隱私保護需求前提下,如何提供一個可隨企業資訊安全政策不同而具彈性調整的警訊分享機制,更能兼顧警訊隱私保護與警訊關聯分析之間取得平衡,成為一個很重要的安全議題。 針對此議題,本論文探討對資安警訊封包標頭做模糊化隱私保護處理,進而評估警訊封包經處理後影響因素,包括警訊封包IP位址模糊化轉換區間大小與警訊關聯性,警訊封包隱私保護與原始警訊封包資訊的資訊含量(entropy)變化關係,以及警訊封包模糊化後的警訊關聯能力。本論文透過將原始警訊封包的IP位址資訊模糊化來計算警訊封包經隱私保護後的資訊含量,再由SOC警訊關聯分析。本論文提供以量化指標讓企業依據資訊安全政策可彈性調整其警訊內容隱私防護程度,藉以達到隱私保護與警訊關聯正確性之間的最佳平衡。 zh_TW
dc.description.abstractCompanies and Organizations usually structure the large-scale joint defense network by information security devices. Through joint regional defense, the network can provide members sufficient threat warning information. In companies, the information security alerts are sent to Security Operation Center (SOC), but there are some internal network information and sensitive privacy content in the alerts. Taking the alerts into consideration, companies and Organizations would not prefer to share the warning of internal information security. Therefore, they can avoid malicious person to obtain confidential information of organization or result in damage to goodwill or assets. However, not only information security policy but also requested level of privacy protection is different from each company. In addition to protect the information privacy, we also want to provide companies a sharing mechanism which is changeable to information security policy. A balance in the trade between privacy protection and warning association analysis becomes a significant issue people concern. For this issue, this thesis discusses processing of fuzzy information privacy protection on the packet header and the factors of assessing the alert packets. The factors include the fuzzy conversion region of IP address, warning Relevance, information content changes between privacy protection of warning packet and original warning packet information (entropy), and the capability of warning packet after fuzzy. In this thesis, there are two steps in the purposed method. First, calculate the information of warning packet. Use IP address of the original warning packet and get the information after fuzzy to calculate. Second, analyze correlation of SOC. Also, we provide the quantitative standard for companies to change the level of privacy protection. Finally, it will achieve optimal condition between privacy protection and accuracy of warning relevance. en_US
DC.subject資訊安全政策zh_TW
DC.subject資訊含量zh_TW
DC.subject資訊安全營運管理中心zh_TW
DC.subject隱私保護zh_TW
DC.subject警訊關聯zh_TW
DC.subjectalert correlationen_US
DC.subjectentropyen_US
DC.subjectprivacy preservingen_US
DC.subjectsecurity policyen_US
DC.subjectsecurity operations centeren_US
DC.title可調適符合資安隱私政策之大範圍網路警訊分享機制zh_TW
dc.language.isozh-TWzh-TW
DC.titleAdjust Able for Privacy of Information Security Policies Consistent with a Wide Range of Network Alert Sharing Mechanismen_US
DC.type博碩士論文zh_TW
DC.typethesisen_US
DC.publisherNational Central Universityen_US

若有論文相關問題,請聯絡國立中央大學圖書館推廣服務組 TEL:(03)422-7151轉57407,或E-mail聯絡  - 隱私權政策聲明