Skip navigation

DSpace JSPUI

DSpace preserves and enables easy and open access to all types of digital content including text, images, moving images, mpegs and data sets

Learn More
DSpace logo
English
中文
  • Browse
    • Communities
      & Collections
    • Publication Year
    • Author
    • Title
    • Subject
    • Advisor
  • Search TDR
  • Rights Q&A
    • My Page
    • Receive email
      updates
    • Edit Profile
  1. NTU Theses and Dissertations Repository
  2. 電機資訊學院
  3. 電機工程學系
Please use this identifier to cite or link to this item: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/6938
Title: 在網路偵測上可變步伐的樣式比對
Variable-Stride Pattern Matching for Network Intrusion Detection
Authors: Kuang-Min Hsu
徐光民
Advisor: 雷欽隆(Chin-Laung Lei)
Keyword: 樣式比對,正規表式法,自動機,入侵偵測,多步伐,
pattern matching,regular expression,automata,intrusion detection,multi-stride,
Publication Year : 2012
Degree: 碩士
Abstract: 樣式比對是研究如何從文章中找出特定樣式的字串。在網路中,電腦之間的溝通可以視為雙方互相傳遞一些字串,所以樣式比對便可以用來偵測網路之間的溝通內容,而其中一種應用便是網路入侵偵測和預防。網路入侵偵測和預防是試著找出由外面網路進來的惡意封包,為了找到這些封包定義了一些關於惡意封包的規則,在偵測封包時會將這些規則轉為自動狀態機,而自動狀態機的效能通常決定了整個系統的效能。
可變步伐是一個基於Winnowing演算法的方法,這個方法被應用在字串辨識上能在保持和多步伐策略一樣的偵測速度下使用較少的記憶體。使用可變步伐策略下的自動狀態機每一次狀態轉換時都會一次處理不定數量的符號,而不是只有一個符號,如此減少了狀態轉換的次數而增加偵測速度,然而這個方法只被使用在字串辨識,這片論文擴展可變步伐的策略到樣式比對,同時保持其原來的優點。
Pattern matching is a research topic that focuses on how to efficiently find strings of expected form in some text. In the network, the communication between the computers can be view as sending string to each other, so the knowledge of pattern matching is used to detect the content of communication in network. The network instruction detection and prevention, one of application used pattern matching in the network, is try to find the malicious data from the incoming data stream which come from outside network. To find malicious data, the rules that present how malicious data look like are converted into automata. The performance of the automata always determines the performance of detecting system.
Variable-stride is base on Winnowing algorithm, and this scheme has more memory efficiency than multi-stride method when it has the same throughput improvement. Every transition in the automata applied variable stride may deal with a variable number of symbols, and reduce number of state transition when detecting, so make detecting process faster. However, this scheme is only applied in string matching. Thus this dissertation extends variable-stride to NFA, and keeps its advantage at the same time.
URI: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/6938
Fulltext Rights: 同意授權(全球公開)
Appears in Collections:電機工程學系

Files in This Item:
File SizeFormat 
ntu-101-1.pdf462.71 kBAdobe PDFView/Open
Show full item record


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

社群連結
聯絡資訊
10617臺北市大安區羅斯福路四段1號
No.1 Sec.4, Roosevelt Rd., Taipei, Taiwan, R.O.C. 106
Tel: (02)33662353
Email: ntuetds@ntu.edu.tw
意見箱
相關連結
館藏目錄
國內圖書館整合查詢 MetaCat
臺大學術典藏 NTU Scholars
臺大圖書館數位典藏館
本站聲明
© NTU Library All Rights Reserved