标题: 一个在云端环境上的二阶段入侵侦测合作机制
A Two-phase Collaborative Intrusion Detection Mechanism for Cloud Computing
作者: 陈光禹
罗济群
Lo, Chi-Chun
资讯管理研究所
关键字: 入侵侦测;信誉管理;云端安全;intrusion detection;trust management;cloud security
公开日期: 2010
摘要: 随着云端环境运算的进步,有许多相关的议题被热烈讨论,资讯安全是其中一项重要课题。本论文将专注于入侵攻击的防范,并探讨如何运用已建构在云端中多个入侵侦测系统,使它们彼此合作成为一个可行方案。一个两阶段的合作机制被提出来加强云端安全。第一阶段是建构信誉管理模型,此模型被设计用来建立入侵侦测系统之间的信赖关系。它是由三个步骤的方法所构成,分别是传送验证讯息,鼓励回应以及考虑信誉的递移性。第二阶段是协同合作,是利用系统之间彼此的信赖关系,来加强合作的品质;而这些信赖关系是在第一阶段中被建立完成。第二阶段有两种协同合作方法,分别是警报关联整合与攻击征状的分享。入侵侦测系统能够藉由系统间分享彼此的资讯,显着的提升侦测的效能。最后,透过模拟结果分析,本机制在侦测系统对攻击最敏感的情况下,平均侦测准确度98%,明显高于不合作的情况(88%)或是其他学者提出的合作机制(90%)。
With the advent of cloud computing, a number of issues are discussed and among them, security is an important one. This thesis concentrates on intrusion detection. It studies how to apply the intrusion detection systems (IDS) in cloud and makes them cooperate with each other to provide a more secure solution. A two-phase collaborative mechanism is proposed to enhance the security in cloud. The first phase is constructing the trust management model. Such model is designed to establish the trustworthiness relationships between each IDS. It is contributed by three steps, sending test messages, encouraging replying, and considering the transitivity of trust. The second phase is collaborating. The trustworthiness between each system, derived at first phase, is used to strengthen the quality of collaboration. There are two ways to collaborate, alert correlation and symptoms sharing. An IDS can increase the performance obviously by sharing the information with each other. Eventually, with analyzing the simulation results, the average detection accuracy of IDSs in the proposed mechanism is 98% when the IDSs are sensitive to attacks. It is higher than the non-cooperation (88%) and the other proposal (90%).
URI: http://140.113.39.130/cdrfb3/record/nctu/#GT079834530
http://hdl.handle.net/11536/47938
显示于类别:Thesis


文件中的档案:

  1. 453001.pdf

If it is a zip file, please download the file and unzip it, then open index.html in a browser to view the full text content.