Skip navigation

DSpace JSPUI

DSpace preserves and enables easy and open access to all types of digital content including text, images, moving images, mpegs and data sets

Learn More
DSpace logo
English
中文
  • Browse
    • Communities
      & Collections
    • Publication Year
    • Author
    • Title
    • Subject
    • Advisor
  • Search TDR
  • Rights Q&A
    • My Page
    • Receive email
      updates
    • Edit Profile
  1. NTU Theses and Dissertations Repository
  2. 電機資訊學院
  3. 電機工程學系
Please use this identifier to cite or link to this item: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/37883
Title: 提高系統安全性與服務可用性之機制與實作
Mechanisms and Implementations for Enhancing System Security and Service Availability
Authors: Ming-Wei Wu
吳明蔚
Advisor: 郭斯彥(Sy-Yen Kuo)
Keyword: 間諜軟體,垃圾郵件,P2P網路,安全性,可用性,
Spyware,Spam,P2P,Security,Availability,
Publication Year : 2008
Degree: 博士
Abstract: 隨著越來越多使用者與終端設備透過網際網路來存取伺服器所提供的服務,仍有諸多的重要議題迫切地需要檢討與提出解決方案。這些問題包括1)間諜軟體入侵所帶來的安全顧慮,2)同儕式(P2P)通訊環境的連線問題,以及3)郵件伺服器的可靠度議題。
本論文提出一系列的機制與實作來解決這些問題。首先,我們提出具狀態的威脅感知移除系統(STARS),此系統能動態地監控系統行為,並確保已移除的惡意程式無法自行修復(自癒)。再者透過觀察間諜軟體的惡意行為所建構而成的隱藏馬可夫模型(HMM),可用來表示資安狀態的轉移機率,並可作為評估惡意軟體入侵可能性之依據。接著,為解決同儕式通訊環境下諸多終端使用者係使用私有IP位址而影響通訊雙方的連線能見度,我們提出具延展性的埠號轉換,其時間與空間複雜度極低,卻可大幅地增強傳統網路位址轉換器(NAT)的連線能力與延展性,諸多優點包括1)降低P2P穿透的競爭情況,2)系統的可用埠號透過多工可超過65,535理論值,以及3)允許單一埠號同時提供更多的應用服務。最末,大量的垃圾郵件湧入郵件轉送代理人(MTA)造成類似阻斷服務的攻擊,不僅降低伺服器的可靠度,亦為收件人帶來諸多困擾。由於沒有單一解決方案可以有效地阻絕垃圾郵件,我們提出可抵禦垃圾郵件之代理人(SRMA),其結合多種垃圾郵件識別機制,能有效地降低甚至消彌現有的垃圾郵件氾濫之困境。
Nowadays, numerous clients are connected to Internet to access the applications offered by the servers, and has encountered various problems that significantly affect their user experiences. These problems are typically 1) the security concerns for spyware infection, 2) the connectivity issues in Peer-to-Peer (P2P) communications, and 3) the dependability of mail servers as well as the productivity of mail recipients.
This thesis aims to propose a suite of mechanisms that offer better security to client system and improved availability to Internet servers. First, a Stateful Threat-Aware Removal System (STARS) is proposed and implemented that at run time monitors critical system behaviors, and ensures that removed spyware does not recover after deletion (so called self-healing). Second, a Hidden Markov Model (HMM) is trained based on visible observations of spyware behaviors. The constructed HMM represents the likelihood of transitions between security states and indicates the risk level of spyware invasion. Third, in order to resolve the visibility problem between peers that used private IPv4 addresses, a scalable port forwarding (SPF) design is proposed and implemented, which introduces negligible time and space complexity. SPF enables a legacy Network Address Translation (NAT) device to significantly improve its connectivity and scalability by 1) lessening the race condition of P2P traversals, 2) multiplexing the port numbers to exceed theoretical upper bound 65,535 and 3) allowing more servers to bind to a specific port. Lastly, bulk volume of spam mails delivering to mail transfer agents (MTA), which is similar to the effect of denial of services (DoS) attacks, dramatically reduces the dependability and efficiency of networking systems. While there is no silver bullet to deter spammers and eliminate spam mails, a spam-resistible mail agent (SRMA) that employed a multi-faceted approach to have most advantages and the least disadvantages of existing anti-spam solutions.
URI: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/37883
Fulltext Rights: 有償授權
Appears in Collections:電機工程學系

Files in This Item:
File SizeFormat 
ntu-97-1.pdf
  Restricted Access
927.76 kBAdobe PDF
Show full item record


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

社群連結
聯絡資訊
10617臺北市大安區羅斯福路四段1號
No.1 Sec.4, Roosevelt Rd., Taipei, Taiwan, R.O.C. 106
Tel: (02)33662353
Email: ntuetds@ntu.edu.tw
意見箱
相關連結
館藏目錄
國內圖書館整合查詢 MetaCat
臺大學術典藏 NTU Scholars
臺大圖書館數位典藏館
本站聲明
© NTU Library All Rights Reserved