中大機構典藏-NCU Institutional Repository-提供博碩士論文、考古題、期刊論文、研究計畫等下載:Item 987654321/44777
English  |  正體中文  |  简体中文  |  Items with full text/Total items : 83776/83776 (100%)
Visitors : 59441917      Online Users : 1097
RC Version 7.0 © Powered By DSPACE, MIT. Enhanced by NTU Library IR team.
Scope Tips:
  • please add "double quotation mark" for query phrases to get precise results
  • please goto advance search for comprehansive author search
  • Adv. Search
    HomeLoginUploadHelpAboutAdminister Goto mobile version


    Please use this identifier to cite or link to this item: https://ir.lib.ncu.edu.tw/handle/987654321/44777


    Title: 使用Openflow 交換器偵測Botnet 受害者與通知機制;Botnet Victim Detection and Notification based on Openflow Switch
    Authors: 彭士家;Shi-Jia Peng
    Contributors: 資訊工程研究所
    Keywords: Openflow;封包轉向;NetFPGA;殭屍網路;Botnet;Openflow;redirect;NetFPGA
    Date: 2010-08-24
    Issue Date: 2010-12-09 13:55:00 (UTC+8)
    Publisher: 國立中央大學
    Abstract: 隨著網路不斷的發展,網路上的資料越來越重要,網路交易也越來越頻繁。 同時網路犯罪開始興起,而殭屍網路(botnet)就是其中一種。殭屍網路有攻擊 者隱密、且彈性大的特性,而且能夠一次對多台電腦進行控制。 本篇論文以IRC 協定的botnet 為研究對象,首先說明botnet 的運作機制, 和botnet 對於資安人員難以解決的問題。接著介紹由史丹佛大學開發的NetFPGA 網卡和openflow 計劃的特色及優點,並說明用linux gateway 來阻擋的效率問題。 本篇論文透過史丹佛大學設計的NetFPGA 和openflow 網路,設計了一套可以使 用openflow switch 來偵測已中毒的電腦。我們假設正常使用者皆會瀏覽網頁, 利用openflow switch 將中毒的電腦導向至一個警告頁面,告知使用者中毒資訊, 再透過網路的封鎖策略,讓使用者了解解決中毒情況的必要性和急迫性。Over the years, the network developed quickly and constantly. Because the rise of trade networks, data on the network become more and more important. Unfortunately, the rise of internet crime became a big problem at the same time such as Botnet. Botnet have hidden attackers, and the characteristics of high flexibility, but also an ability to control multiple computers. This paper describes the IRC-based botnet. First, we explain the botnet behavior and the hard to solve problems for security officer. Then we introduced the NetFPGA card developed by the Stanford University and explained the openflow project features and advantages. These devices are used as a linux gateway to be an efficient firewall. This paper use the NetFPGA card and openflow network project designed by Stanford University to detect bot in the botnet. Assume that normal users browser web everyday, we use openflow switch redirect the bot traffic to a particular page that show the warning information. Then through the network disconnected strategy, we try to let the user know the necessity and urgency.
    Appears in Collections:[Graduate Institute of Computer Science and Information Engineering] Electronic Thesis & Dissertation

    Files in This Item:

    File Description SizeFormat
    index.html0KbHTML796View/Open


    All items in NCUIR are protected by copyright, with all rights reserved.

    社群 sharing

    ::: Copyright National Central University. | 國立中央大學圖書館版權所有 | 收藏本站 | 設為首頁 | 最佳瀏覽畫面: 1024*768 | 建站日期:8-24-2009 :::
    DSpace Software Copyright © 2002-2004  MIT &  Hewlett-Packard  /   Enhanced by   NTU Library IR team Copyright ©   - 隱私權政策聲明