English  |  正體中文  |  简体中文  |  全文筆數/總筆數 : 81570/81570 (100%)
造訪人次 : 47015601      線上人數 : 177
RC Version 7.0 © Powered By DSPACE, MIT. Enhanced by NTU Library IR team.
搜尋範圍 查詢小技巧:
  • 您可在西文檢索詞彙前後加上"雙引號",以獲取較精準的檢索結果
  • 若欲以作者姓名搜尋,建議至進階搜尋限定作者欄位,可獲得較完整資料
  • 進階搜尋


    請使用永久網址來引用或連結此文件: http://ir.lib.ncu.edu.tw/handle/987654321/88313


    題名: USBIPS: A Framework for Protecting A Host against Malicious Behaviors behind USB Peripherals
    作者: 王駿逸;Wang, Chun-Yi
    貢獻者: 資訊工程學系
    關鍵詞: USB peripheral;HID (Human Interface Device);protocol masquerading;USB firewall;EDR (Endpoint Detection and Response);USB peripheral;HID (Human Interface Device);protocol masquerading;USB firewall;EDR (Endpoint Detection and Response)
    日期: 2022-01-26
    上傳時間: 2022-07-13 22:46:17 (UTC+8)
    出版者: 國立中央大學
    摘要: 近年來,以USB為媒介的攻擊手法變得越來越複雜。從社交工程到信號注入,現代的攻擊手法涵蓋了廣泛的攻擊面向。為了應對這些挑戰,資安社群已採用了越來越多技術深入卻範圍零散的防禦措施。無論基於USB的攻擊採用何種面向的手法,許多個人和企業所關注的最重要風險是服務中斷和資料外洩。電腦的作業系統負責管理USB周邊設備,然而透過USB周邊設備的惡意攻擊可以導致服務中斷或從作業系統內竊取資料,例如BadUSB這類型的攻擊。儘管有相關研究提出使用USB防火牆的概念,例如USBFILTER和USBGuard等方法,來防禦USB周邊設備的惡意行為,但它們仍無法有效地阻止現實世界中的入侵。

    本論文的重點是在電腦作業系統內建構一個稱為USBIPS的安全架構,以防禦惡意的USB周邊設備,其中包括三項主要研究,目的是為了探索惡意行為的本質,並對於以USB為媒介的入侵手法建立持續性的防護。首先,我們提出一種基於行為的偵測機制,置重點於偵測以USB為媒介或與USB結合運用的攻擊行為。 其次,我們提出了一種基於白名單的USB存取控制方法的創新思維。最後,我們開發並實現了一套端點偵測與回應(EDR)系統,並構建了第一個以USB入侵防護為主的通用安全架構。 藉由集中式的威脅分析架構,此系統可以進行持續性的防護,並能偵測未知的惡意行為。透過解決關鍵的安全與效能挑戰,本論文中的這些研究成果,不僅使現今常用的作業系統足以抵禦來自不受信任的USB周邊設備攻擊,也為後續的研究工作開創了一條寬敞大道。;USB-based attacks have increased in complexity in recent years. Modern attacks now incorporate a wide range of attack vectors, from social engineering to signal injection. To address these challenges, the security community has responded with a growing set of fragmented defenses. No matter what vector a USB-based attack operated, the most important risks that most people and enterprises care about are service crashes and data loss. The host operating system is responsible for managing USB peripherals; however, malicious ones can crash a service or steal data from the OS, such as BadUSB attacks. Although some methods work as a USB firewall, such as USBFILTER and USBGuard were proposed to defend against malicious USB peripherals, they still cannot stop the intrusions in the real world.

    The focus of this dissertation is on building a security framework called USBIPS within operating systems to defend against malicious USB peripherals, which includes three major efforts to explore the nature of malicious behaviors and to build persistent protection from USB-based intrusions. We first present a behavior-based detection mechanism focusing on the attacks combined with USB peripherals. We then introduce a novel idea of a whitelisting-based method for USB access control. We finally develop an Endpoint Detection and Response (EDR) system to build the first generic security framework for USB-based intrusion protection. Withing the centralized threat analysis framework, the protection works persistently and could have the capability to detect unknown malicious behaviors. By addressing key security and performance challenges, these works pave the way for hardening modern operating systems against attacks from untrusted USB peripherals.
    顯示於類別:[資訊工程研究所] 博碩士論文

    文件中的檔案:

    檔案 描述 大小格式瀏覽次數
    index.html0KbHTML121檢視/開啟


    在NCUIR中所有的資料項目都受到原著作權保護.

    社群 sharing

    ::: Copyright National Central University. | 國立中央大學圖書館版權所有 | 收藏本站 | 設為首頁 | 最佳瀏覽畫面: 1024*768 | 建站日期:8-24-2009 :::
    DSpace Software Copyright © 2002-2004  MIT &  Hewlett-Packard  /   Enhanced by   NTU Library IR team Copyright ©   - 隱私權政策聲明