完整後設資料紀錄
DC 欄位語言
dc.contributor.author鄭又瑞en_US
dc.contributor.authorCheng, Yu-Juien_US
dc.contributor.author吳育松en_US
dc.contributor.authorWu, Yu-Sungen_US
dc.date.accessioned2014-12-12T02:44:09Z-
dc.date.available2014-12-12T02:44:09Z-
dc.date.issued2014en_US
dc.identifier.urihttp://140.113.39.130/cdrfb3/record/nctu/#GT070156031en_US
dc.identifier.urihttp://hdl.handle.net/11536/75789-
dc.description.abstract利用行為比對偵測惡意程式有很高的偵測率。然而觀測行為時,惡意程式仍持續對系統造成傷害,因此在判定惡意程式後,對其造成的傷害進行估測,可以協助管理者修復造成的系統傷害。 在半虛擬化的環境下,我們設計一套傷害範圍估測機制,藉由記錄在虛擬機中程式寫入的檔案路徑以及磁區位置,估測惡意程式造成的傷害範圍。我們修改xen-blkback攔截磁碟寫入的磁區位置,修改Xen hypervisor攔截系統呼叫,將兩者的I/O資訊合併進行傷害範圍估測。zh_TW
dc.description.abstractBehavior matching is a malware detection method with high detection rate. However, during the time matching behaviors, the malware is continually making damage. Thus, estimating the damaged area the detected malware made can help administrator relieve the damage. In paravirtualized environment, we design a storage-layer damage estimation mechanism. We estimate the damage that a malware made by using the disk I/O information from guest VM. We modify xen-blkback to intercept raw disk I/O information, and Xen hypervisor to intercept system calls. We combine raw disk information and system call information to estimate damaged area.en_US
dc.language.isoen_USen_US
dc.subject磁碟zh_TW
dc.subject傷害zh_TW
dc.subject估測zh_TW
dc.subjectstorageen_US
dc.subjectdisken_US
dc.subjectdamageen_US
dc.subjectestimateen_US
dc.title磁碟傷害範圍估測機制zh_TW
dc.titleA Storage-Layer Security Attack Damage Estimation Mechanismen_US
dc.typeThesisen_US
dc.contributor.department資訊科學與工程研究所zh_TW
顯示於類別:畢業論文


文件中的檔案:

  1. 603101.pdf

若為 zip 檔案,請下載檔案解壓縮後,用瀏覽器開啟資料夾中的 index.html 瀏覽全文。