論文名稱 資安協作自動化應變(SOAR)對於企業資安防護之研究-以P公司為例
(Study on the Impact of Security Orchestration, Automation, and Re-sponse (SOAR) on Enterprise Cybersecurity Protection - A Case Study of Company P)
摘要(中) 隨著網際網路的快速發展,勒索軟體攻擊愈發頻繁,這些攻擊往往難以完全阻止。然而企業不僅面臨著日益複雜的資安管理挑戰,同時也遭遇了專業人才的短缺。資安協作自動化應變(SOAR)技術解決方案號稱為能夠改善這些問題,但從企業角度來看,實際驗證SOAR在企業環境中資安防護效益的案例仍然不足,無法讓決策者了解其實際導入效益及評估其導入應用流程。
摘要(英) With the rapid development of the Internet, ransomware attacks have become increas-ingly frequent and are often difficult to completely prevent. Companies are not only facing increasingly complex cybersecurity management challenges but also encountering a short-age of professional talent. Security Orchestration, Automation, and Response (SOAR) tech-nology solutions are claimed to address these issues. However, from a corporate perspective, there are still insufficient cases verifying the security benefits of SOAR in enterprise envi-ronments, leaving decision-makers unable to understand its actual implementation benefits and evaluate its application processes.
Therefore, this study adopts a case study approach, analyzing three specific cybersecu-rity incident response scenarios: the TW-ISAC intelligence application process, the abnor-mal group policy setting monitoring application process, and the decoy file alteration detec-tion process, to practically verify the differences and benefits after implementing SOAR. The results of the study show that after applying the SOAR system, the processing time for these scenarios was significantly reduced, thereby demonstrating the great potential of SOAR technology in integrating security tools and achieving process automation. Through these case analyses, this study not only confirms the value of the SOAR system in enhancing enterprise cybersecurity protection and improving the efficiency of handling security inci-dents but also provides important references for the automation transformation of corporate cybersecurity management.
關鍵字(中) ★ 企業資安
★ 網路安全
★ 資安協作自動化應變
★ 安全事件檢測與回應
★ 自動化流程
關鍵字(英) ★ enterprise cybersecurity
★ cybersecurity
★ security orchestration automated response
★ incident detection and response
★ process automation
論文目次 摘要 i
致謝 iii
目錄 iv
表目錄 vii
圖目錄 viii
第一章 緒論 1
1.1 研究背景 1
1.2 研究動機 2
1.3 研究目的 3
1.4 論文架構 5
第二章 文獻探討 6
2.1 勒索病毒 (Ransomware) 6
2.1.1 病毒發展背景 6
2.1.2 勒索病毒加密標的 10
2.1.3 勒索病毒偵測機制 10
2.2 資安威脅情資(Threat Intelligence) 11
2.2.1 威脅情資定義及類別 11
2.2.2 資訊分享與分析中心(Information Sharing and Analysis Center, ISAC) 12
2.3 資安協作自動化應變SOAR(Security Orchestration, Automation and Response) 13
2.3.1 SOAR背景及定義 13
2.3.2 SOAR應用與探討 15
2.3.3 SOAR與其他資安工具比較 16
2.4 資安防護框架及安全指標 18
2.4.1 安全防護框架 18
2.4.2 安全關鍵指標MTTD/ MTTR 19
2.5章節小節 20
第三章 研究設計 22
3.1 研究方法 22
3.2 研究對象及架構 22
3.2.1 資訊安全應用架構框架 23
3.3 實驗環境 25
3.3.1 SOAR實驗環境配置 25
3.3.2 SOAR環境建置 28
3.4 實驗流程設計 29
3.4.1 設計情境一:TW-ISAC情資應用流程 29
3.4.2 設計情境二:GPO(Group Policy Object)異常監控應用流程 35
3.4.3 設計情境三:誘餌檔案異動偵測流程 41
第四章 實驗結果 46
4.1 實驗情境一:TW-ISAC情資應用流程 46
4.1.1偵測及擷取情資通報 46
4.1.2資料檢驗及分類應用流程 49
4.1.3自動阻擋及通報實施流程 50
4.1.4情境一實驗結果 54
4.2 實驗情境二:GPO異常監控應用流程 62
4.2.1 偵測及擷取警報郵件內容 62
4.2.2 資料檢驗及分類應用流程 64
4.2.3 自動阻擋及通報實施流程 68
4.2.4 情境二實驗結果 70
4.3 實驗情境三:誘餌檔案異動偵測流程 76
4.3.1 偵測及擷取警報郵件內容 76
4.3.2 資料檢驗及分類應用流程 78
4.3.3 自動阻擋、查詢及通報實施流程 80
4.3.4 情境三實驗結果 84
4.4 個案情境驗證結果 90
4.5 研究限制 92
第五章 結論與未來研究 94
5.1 結論與貢獻 94
5.2 未來研究 95
參考文獻 96
指導教授 陳奕明(Yi-Ming Chen) 審核日期 2024-7-23
