Skip navigation

DSpace JSPUI

DSpace preserves and enables easy and open access to all types of digital content including text, images, moving images, mpegs and data sets

Learn More
DSpace logo
English
中文
  • Browse
    • Communities
      & Collections
    • Publication Year
    • Author
    • Title
    • Subject
    • Advisor
  • Search TDR
  • Rights Q&A
    • My Page
    • Receive email
      updates
    • Edit Profile
  1. NTU Theses and Dissertations Repository
  2. 管理學院
  3. 資訊管理學系
Please use this identifier to cite or link to this item: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/29326
Title: 達成網路存活性最大化之近似最佳化網路防禦資源配置策略
Near Optimal Network Defense Resource Allocation Policies for Maximization of Network Survivability
Authors: Ya-Fang Wen
溫 雅 芳
Advisor: 林永松
Co-Advisor: 顏宏旭
Keyword: 網路分隔度,拉格蘭日鬆弛法,網路存活性,最佳化,資源配置,無尺度網路,
Degree of Separation,Lagrangean Relaxation,Network Survivability,Optimization,Resource Allocation,Scale-free Network,
Publication Year : 2007
Degree: 碩士
Abstract: 由於電腦硬體成本逐漸下降、軟體性能逐漸上昇,大部份的關鍵性網路都已電腦化控制。這些與日常生活息息相關的網路系統,一旦其毀損,除了對我們的生活造成極大的不方便,更是在生命與財產方面,引起不小的損失。所以,有效地評估與衡量關鍵性網路系統的存活性,是現今資訊安全領域中亟需重視的議題。
有鑑於此,我們提出一個全新且簡單的網路存活性指標—網路分隔度(Degree Of Separation, DOS)。這是一種網路傷害指標,用來衡量網路遭受毀損的平均程度。DOS值愈大,代表其網路毀損愈嚴重,即表示必須付出更大的代價去修復整個網路。倘若其損害程度大於某一門檻值,則我們宣稱該網路已全然毀損。
因此,我們模擬一個網路攻防情境以建立一個最佳化資源配置目標之數學線性規劃模型,並加入DOS指標的概念來評估其存活性。在求解的過程之中,利用“拉格蘭日鬆弛法”與“梯度法”來幫助我們逐漸找到最佳解。
最後,經由實驗證明,不僅我們所提出的三階段選擇 (3-Stage Selection, 3SS) 攻擊演算法能夠有效評估攻擊成本,而且針對不同的網路拓樸所提出的網路資源配置策略效果顯著。
Due to the decreasing cost of computer hardware and the increasing capacity of computer software, most critical networks are being progressively computerized. If one of these systems were to fail, it would not only cause extreme inconvenience in our daily lives, but could even have catastrophic or fatal consequences. Thus, how to assess and evaluate the survivability of a system effectively is a crucial issue in the field of information security.
In this thesis, we propose a simple and novel metric of network survivability, called Degree of Separation (DOS). DOS is a survivability metric used to measure the average damage level of a system; naturally, the larger the DOS value, the more serious the network damage will be. If the DOS value is larger than a pre-established threshold, we say that the network has been compromised.
We express the scenario of network attack-defense as a mathematical linear programming model to near-optimize the resource allocation policies. In the process of problem solving, we adopt the concept of DOS to assess the network survivability and use the Lagrangean Relaxation method and the subgradient method to approach the optimal solution.
Finally, based on the experiment results, not only can the 3-stage selection (3SS) attack algorithm we proposed evaluate the attack cost effectively, but are the results of different defense budget allocation policies to different network topologies quite significant.
URI: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/29326
Fulltext Rights: 有償授權
Appears in Collections:資訊管理學系

Files in This Item:
File SizeFormat 
ntu-96-1.pdf
  Restricted Access
1.16 MBAdobe PDF
Show full item record


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

社群連結
聯絡資訊
10617臺北市大安區羅斯福路四段1號
No.1 Sec.4, Roosevelt Rd., Taipei, Taiwan, R.O.C. 106
Tel: (02)33662353
Email: ntuetds@ntu.edu.tw
意見箱
相關連結
館藏目錄
國內圖書館整合查詢 MetaCat
臺大學術典藏 NTU Scholars
臺大圖書館數位典藏館
本站聲明
© NTU Library All Rights Reserved