Skip navigation

DSpace JSPUI

DSpace preserves and enables easy and open access to all types of digital content including text, images, moving images, mpegs and data sets

Learn More
DSpace logo
English
中文
  • Browse
    • Communities
      & Collections
    • Publication Year
    • Author
    • Title
    • Subject
  • Search TDR
  • Rights Q&A
    • My Page
    • Receive email
      updates
    • Edit Profile
  1. NTU Theses and Dissertations Repository
  2. 電機資訊學院
  3. 電信工程學研究所
Please use this identifier to cite or link to this item: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/21455
Title: 利用封包表頭識別來自於大型網站伺服器的封包流
Identifying Traffic of Large Scale Web Server Using Packet
Header Information
Authors: Ju-Hsuan Hsieh
謝儒萱
Advisor: 鍾嘉德(Char-Dir Chung)
Co-Advisor: 林風(Phone Lin)
Keyword: 機器學習,封包表頭資訊,網路流量辨識,台大網路校園流量,
machine learning,packet header information,internet traffic identification,NTU campus traffic,
Publication Year : 2019
Degree: 碩士
Abstract: 網路流量的識別對於網路安全以及管理非常重要。這個技術可以幫助網路管理者找出網路中的異常。許多大型網站已經成為網路攻擊的目標,而當他們遭受到攻擊時,對外流出的流量行為可能會產生異常。在先前的文獻當中,網路流量識別使用到載荷檢查(payload inspection)以及基於同一條流量的特徵(flow-based features)辨識。然而,當封包是加密的時候,載荷檢查無法發揮它的作用,並且檢查載荷時會有隱私問題。再者,在訂定這些檢查規則時造成的負擔很重,也需要定期的更新。再基於同一條流量的特徵辨識時,需要蒐集多個封包來計算統計特徵,運算複雜度相當大,而且耗時。因此,我們提出一個只使用封包表頭來辨認封包是否正常的機制。由於只需要一個封包的表頭資訊來做辨認,不僅降低計算特徵時的負擔,也可降低封包辨認所需要的時間。
Network traffic identification technique plays an important role in modern network security and management architectures. It can help the network manager to find out the anomalies in the network. Some large scale servers have become the targets of security attacks, and the behaviors of the servers may become abnormal. In previous works, network identification requires payload inspection and flow-based features collecting. Payload inspection cannot function when the payload is encrypted and may incur the privacy issue because the content should be scanned. Furthermore, it usually imposes heavy overhead to construct the rules. In the flow-based feature identification technique, the computation overhead to collect multiple packets and calculate the statistic features is very high and time-consuming. Therefore, we proposed a mechanism to determine whether the Internet traffics from large scale servers are normal or not by using the packet header information. Furthermore, because it only requires the information of one packet for detection, the detection time and the computation overhead can be reduced.
URI: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/21455
DOI: 10.6342/NTU201901028
Fulltext Rights: 未授權
Appears in Collections:電信工程學研究所

Files in This Item:
File SizeFormat 
ntu-108-1.pdf
  Restricted Access
2.76 MBAdobe PDF
Show full item record


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

社群連結
聯絡資訊
10617臺北市大安區羅斯福路四段1號
No.1 Sec.4, Roosevelt Rd., Taipei, Taiwan, R.O.C. 106
Tel: (02)33662353
Email: ntuetds@ntu.edu.tw
意見箱
相關連結
館藏目錄
國內圖書館整合查詢 MetaCat
臺大學術典藏 NTU Scholars
臺大圖書館數位典藏館
本站聲明
© NTU Library All Rights Reserved