Skip navigation

DSpace JSPUI

DSpace preserves and enables easy and open access to all types of digital content including text, images, moving images, mpegs and data sets

Learn More
DSpace logo
English
中文
  • Browse
    • Communities
      & Collections
    • Publication Year
    • Author
    • Title
    • Subject
  • Search TDR
  • Rights Q&A
    • My Page
    • Receive email
      updates
    • Edit Profile
  1. NTU Theses and Dissertations Repository
  2. 管理學院
  3. 資訊管理學系
Please use this identifier to cite or link to this item: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/89984
Title: 利用惡意攻擊樣板比對評量資安威脅情資報告品質
Measuring the Quality of Cyber Threat Intelligence Documents through Malware Attack Pattern Matching
Authors: 呂晟維
Cheng-Wei Lu
Advisor: 孫雅麗
Yea-Li Sun
Keyword: 惡意程式動態分析,威脅情資報評量,報告解析,Syscall Synonym Base,
Dynamically Analysis,Malware CTI Document Quality Evaluation,Report Extraction,Syscall Synonym Base,
Publication Year : 2023
Degree: 碩士
Abstract: 惡意程式的資安威脅情報(CTI)記錄入侵指標(IoCs)和惡意活動,對於偵測和應對網路威脅的環節扮演了至關重要的角色。然而,目前現有研究很少涉及文本報告的評估,我們需要解決評估層面、自動化和基本事實等方面的議題。在這篇論文中,我們引入了基於系統物件和行為層次的 CTI 文件質量評估概念,並使用評估指標和視覺的攻擊圖譜來進行評估。我們的評估系統是客觀、自動化和有效率的,並通過案例研究來展示其流程、功能和效能。此外,我們還提供了一個嶄新的、整理有序的資安威脅情報文件數據集,以及一個 Syscall SynonymBase,用於彌合 Linux 系統呼叫和自然語言之間的語意隔閡。
Malware Cyber Threat Intelligence (CTI) reports – which record the Indicators of Compromise (IoCs) and malicious activities – playing a crucial role in detecting and responding to cyber threats. Text report evaluation is an area that is not often covered by existing research and we need to overcome evaluation aspect issue, automation issue and ground truth issue. In this paper, we introduce concepts of measuring the quality of individual CTI document based on system object and behavior levels with quality metrics and visual representations. Our evaluation system is objective, automated, and distinguished, and we demonstrate its pipeline, functionality, and effectiveness through case studies. We also contribute a new, well-sorted malware CTI documents dataset and a Syscall SynonymBase that bridge the semantic gap between Linux system call and natural language.
URI: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/89984
DOI: 10.6342/NTU202302378
Fulltext Rights: 同意授權(全球公開)
Appears in Collections:資訊管理學系

Files in This Item:
File SizeFormat 
ntu-111-2.pdf4.43 MBAdobe PDFView/Open
Show full item record


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

社群連結
聯絡資訊
10617臺北市大安區羅斯福路四段1號
No.1 Sec.4, Roosevelt Rd., Taipei, Taiwan, R.O.C. 106
Tel: (02)33662353
Email: ntuetds@ntu.edu.tw
意見箱
相關連結
館藏目錄
國內圖書館整合查詢 MetaCat
臺大學術典藏 NTU Scholars
臺大圖書館數位典藏館
本站聲明
© NTU Library All Rights Reserved