姓名 曾宇澤(Yu-Tse Tseng)  查詢紙本館藏   畢業系所 資訊工程學系在職專班
(A Solution for Detecting and Defending ARP Spoofing on Virtual Machines)
摘要(中) 為了更有效利用中央處理器的效能,虛擬化也越來越被廣泛使用且非常容易建構,一台實體主機上同時執行多個虛擬作業體統是常見的情況,多台虛擬主機組成的虛擬網路,資料連接層的攻擊也跟著出現在這些虛擬網路上,例如網路位址解析欺騙、媒體存取控制位址替換攻擊等。由於虛擬主機有可預先包裝的特性,有很多已經包裝好特定服務的虛擬主機,方便使用者透過網路下載直接佈屬,如包裝 Apache 伺服器的虛擬主機,使用者下載佈屬後就立即使用,因為使用者無法掌握這些虛擬主機實際包裝的服務,使得虛擬主機不能被性任,我們想在Linux KVM 開源虛擬機器平台上實做,驗證一套不需複雜設定的資料連接層防護偵測系統是否可行,並以網路位址解析欺騙的偵測防護作為首要實做項目。
摘要(英) In order to make more effective use of CPU performance, virtualization has also become more and more widely used and very easy to build, it is a common situation to perform multiple virtual machines simultaneously on a physical host, virtual network composed of multiple virtual machines comes also, Layer 2 attacks also appeared on these virtual networks, for example ARP spoofing, MAC spoofing attacks. Because the virtual machine has packing features, lot of packed virtual machines can be downloaded at INTERNET, user can directly provision those packed virtual machines to physical host, we can′t ensued these is no any malicious software packed in the virtual machine, therefore the virtual machine download from INTERNET is un-trustable, above reasons made us want to implement a system in Linux KVM, verify the feasibility of a Layer 2 protection detection system that does not require complex settings, and take the detection and protection of ARP spoofing as the first practical item.
關鍵字(中) ★ 虛擬機器
★ 位址解析協定
★ 位址解析協定欺騙
關鍵字(英) ★ KVM
★ VM
★ ARP Spoofing
★ libvirt
論文目次 摘要 i
Abstract ii
目錄 iii
圖目錄 v
表目錄 vi
一、緒論 1
1-1 研究背景 1
1-2 研究動機 1
二、背景介紹 3
2-1 背景知識 3
2-1-1 ARP 3
2-1-2 ARP Spoofing 6
2-1-3 QEMU 8
2-1-4 KVM 9
2-1-5 libvirt 10
2-2 相關研究 11
2-2-1 S-ARP 11
2-2-2 靜態ARP記錄 11
2-2-3 Layer-2交換器 12
三、系統設計 13
3-1 VMADS架構 15
3-1-1 VMs Info Table 15
3-1-2 Main Process (Main_P) 15
3-1-3 VM Event Process (VM_EVENT_P) 16
3-1-4 Package Monitor Process (PKG_MONITOR_P) 16
3-2 運作流程 17
四、實驗 18
4-1 實際運作 18
4-1-1 實驗環境 18
4-1-2 執行畫面 18
4-2 吞吐量測試 20
4-2-1 測試工具與參數 20
4-2-2 測試結果 20
4-3 基準測試 22
4-3-1 測試工具與參數 22
4-3-2 測試結果 22
五、結論與未來方向 23
參考文獻 24
指導教授 許富皓(Fu-Hau Hsu) 審核日期 2020-6-12
