標題: | 應用支持向量機偵測惡意網頁 Malicious Web Page Detection Using Support Vector Machine |
作者: | 柯昭生 Ke, Chao-Sheng 蔡文能 Tsai, Wen-Nung 資訊學院資訊學程 |
關鍵字: | 惡意網頁;機器學習;支持向量機;特徵拮取;malicious web page;machine learning;Support Vector Machine;feature extraction |
公開日期: | 2010 |
摘要: | 隨著網際網路的發展,同時也提供了攻擊者一個無遠弗屆的媒介以散佈這些惡意的程式或資訊,而目前最普遍的散佈管道即為“全球資訊網(WWW)服務”。使用者在瀏覽網站時,往往在尚未意識到的情況下即成為了惡意網頁的受害者,特別是這些惡意網頁非常擅於偽裝而隱藏於正常而無害的畫面之後,更讓使用者不易察覺。此外,惡意網頁快速變化的趨勢,也使得一般傳統以特徵比對方式的防護機制無法發揮作用。
在本研究裡,我應用了支持向量機,一個強而有力的機器學習技術,以偵測惡意網頁。在實驗裡,我從網址(URL) 與網頁內容拮取其特徵資訊做為支持向量機學習之用,並調整各個參數以得到最佳的偵測準確率。文中的實驗結果除了驗證此方法的有效性之外,同時也證明了此方法能抵抗惡意網頁快速變化所產生的影響。 The recent development of the Internet provides attackers with omnipresent media to spread malicious contents. The most prevailing channel is the World Wide Web (WWW) service. Innocent people's computers usually get infected when they browse a malicious web page, and such malicious pages are usually camouflaged with harmless materials on the screen, which makes users hard to beware of the danger. Furthermore, malicious web pages have a tendency to frequently change so that traditional signature matching might not be able to efficiently identify them. In my study, I leveraged Support Vector Machine (SVM), a powerful machine learning technique, to detect malicious web pages. I extracted features from both URLs and page contents and fine-tuned the parameters of SVM to yield the best performance. The experimental results demonstrate that my approach is effective and resistant to the effect of frequent change. |
URI: | http://140.113.39.130/cdrfb3/record/nctu/#GT079679512 http://hdl.handle.net/11536/44063 |
顯示於類別: | 畢業論文 |