English  |  正體中文  |  简体中文  |  全文筆數/總筆數 : 78818/78818 (100%)
造訪人次 : 34789356      線上人數 : 1201
RC Version 7.0 © Powered By DSPACE, MIT. Enhanced by NTU Library IR team.
搜尋範圍 查詢小技巧:
  • 您可在西文檢索詞彙前後加上"雙引號",以獲取較精準的檢索結果
  • 若欲以作者姓名搜尋,建議至進階搜尋限定作者欄位,可獲得較完整資料
  • 進階搜尋


    請使用永久網址來引用或連結此文件: http://ir.lib.ncu.edu.tw/handle/987654321/13418


    題名: 基於D-S證據理論之階層式網路安全情境察覺系統;Hierarchical Network Security Situation Awareness System Based on D-S Evidence Theory
    作者: 陳婉宜;Wan-yi Chen
    貢獻者: 資訊管理研究所
    關鍵詞: D-S證據理論;情境察覺;網路安全;階層式風險評估;Network Security;Hierarchical Risk Assessment;Situation Awareness;D-S Evidence Theory
    日期: 2008-07-08
    上傳時間: 2009-09-22 15:31:22 (UTC+8)
    出版者: 國立中央大學圖書館
    摘要: 情境察覺(Situation Awareness, SA)簡單來說就是知道現在發生什麼事並能知道如何回應,其由最初之飛航安全領域被引申用於其他動態、複雜且需要人力介入之領域中,如資訊安全領域,所以近年來網路安全情境察覺(Network Security Situation Awareness)之研究議題也逐漸受到重視。然而目前提出的網路安全情境察覺模型,仍無法提供足夠量化的安全情境或風險評估數據來幫助管理者依據當下網路狀態即時做出對的決策。因此在本論文中我們提出了階層式網路安全情境察覺系統(HNSSAS),目的則是為了協助網管人員迅速找出網路中最弱環節,並給予合適的對策。我們首先使用D-S證據理論(D-S Evidence Theory)融合各異質網路感應器所回報警訊(Alert)之信賴值(Belief),接著結合服務(Service)、主機(Host)本身的重要性參數,以及網路拓樸(Network Topology),由下而上、先局部後整體去評估每個階層的安全情境。本論文最後以模擬案例的方式進行系統推演,實驗結果除了提供宏觀的系統安全情況,還提供了三種不同層次直觀的安全情境評估數值,有助於管理者適切地調整系統安全策略,而提高網路整體安全性能。 Situation Awareness is simply “knowing what is going on so you can figure out what to do”. The term was first used by U.S. Air Force (USAF) fighter aircrew and was considered to be essential for those who are responsible for being in control of complex, dynamic systems and high-risk situations. In recent years, Network Security Situation Awareness is a hot research in the domain of information security. However, present-day cyberspace situation awareness model is unable to provide useful security situation or risk estimation for administrators, or to help administrators to make right and timely decisions based on current state of the network security. A Hierarchical Network Security Situation Awareness System in this paper helps administrator to find out the Achilles' heel fast and deal with by suitable way. First using D-S Evidence Theory to fuse alert believes from multi-sensors. According to the network topology and the importance of services and hosts. The evaluation policy from bottom to top and from local to global is adopted in this model. The simulation results show that this model can provide the intuitive security threat status in three hierarchies, so that system administrators are freed from tedious analysis tasks to have overall security status of the entire system. It is possible for them to find the security behaviors of the system, to adjust the security strategies and to enhance the performance on system security.
    顯示於類別:[資訊管理研究所] 博碩士論文

    文件中的檔案:

    檔案 大小格式瀏覽次數


    在NCUIR中所有的資料項目都受到原著作權保護.

    社群 sharing

    ::: Copyright National Central University. | 國立中央大學圖書館版權所有 | 收藏本站 | 設為首頁 | 最佳瀏覽畫面: 1024*768 | 建站日期:8-24-2009 :::
    DSpace Software Copyright © 2002-2004  MIT &  Hewlett-Packard  /   Enhanced by   NTU Library IR team Copyright ©   - 隱私權政策聲明