跳到主要內容

臺灣博碩士論文加值系統

(216.73.217.167) 您好!臺灣時間:2026/08/13 14:32
字體大小: 字級放大   字級縮小   預設字形  
回查詢結果 :::

詳目顯示

: 
twitterline
研究生:張昌鈐
研究生(外文):CHANG ,CHANG-CHIEN
論文名稱:網路行為與資訊安全之統計分析
論文名稱(外文):Statistical analysis Analysis on Network behavior Behavior and Data Security
指導教授:吳建文
指導教授(外文):WU, CHIEIN-WEN
口試委員:李炯三翁頌舜
口試委員(外文):LEE, CHIUNG-SANWENG, SUNG-SHUN
口試日期:2019-05-14
學位類別:碩士
校院名稱:國立臺北科技大學
系所名稱:管理學院資訊與財金管理EMBA專班
學門:商業及管理學門
學類:財務金融學類
論文種類:學術論文
論文出版年:2019
畢業學年度:107
語文別:中文
論文頁數:37
中文關鍵詞:資訊安全管理制度網路行為資訊安全分散式阻斷服務攻擊網頁過濾器
外文關鍵詞:Information Security Management SystemNetwork BehaviorInformation Securitydistributed denial-of-service attackURL Filter
相關次數:
  • 被引用被引用:1
  • 點閱點閱:508
  • 評分評分:
  • 下載下載:14
  • 收藏至我的研究室書目清單書目收藏:1
網路已成為現代人必備,無論是工作、學習、食衣住行、娛樂皆離不開網路,但是網路處處充滿風險,病毒、入侵、攻擊事件等資訊安全事件災害頻傳,個人受災,輕者資料遭破壞、作業系統受損,重者帳號密碼失竊造成財物損失,企業受災除有形財物上損失外,如果影響交易或資料遭竊取或損壞,所損失的商譽及客戶的信賴度,是無法估計的。近年來企業開始意識到資訊安全的重要,不斷的從作業面-委託外部顧問公司制定資訊安全管理制度(ISMS)並通過以ISO27001的國際資訊安全標準的認證、或從實體的防護面-購買資安設備做防禦,投資大量的成本,防止資安事件的發生,但事與願違的 資安事件仍不斷的發生,造成企業的重大損失。
隨著電子交易的盛行,各項網路金融開始熱絡,網路的含金量變高,也讓駭客們虎視眈眈的覬覦,用各種的方式竊取資訊(如銀行帳戶資料、信用卡資料等),獲取實質的金錢利益,首當其衝含金量最高的金融機構成為駭客之最愛,故其資訊安全的維護的難度也相對更高,綜觀近年金融業發生的重大資安事件如:證券商集體遭DDoS攻擊(分散式阻斷服務攻擊)事件及國際匯款系統SWIFT遭盜轉事件,前者可藉由ISP清洗及內部加購DDoS防禦設備防範,而後者以病毒的方式感染企業內部電腦,傳染至目標電腦後進行破壞,達成其盜轉帳的目的,然分析病毒來源大部分為連接外部網頁感染,如可減少上網中毒的機會,必能有效降低資安事件。本研究以台灣某金融機構之網路行為的紀錄(網頁過濾器)與中電腦病毒紀錄(防毒軟體)做數據分析,解析病毒與上網次數、網頁類別、網頁及各種病毒與網頁類別之關聯性,提供相關數據,提供更完整的上網政策的建議(有效的禁止問題網站),以數據分析強化現有資訊安全機制,減少資安事件的發生。
研究結果顯示,使用者上網的次數與中毒的次數應成正比或資訊人員應該是最懂資訊安全的,統計數值中也透露真正的答案,相關後續研究,更多其他的資安設備紀錄加入,進行更全面及不同設備為主的多面向分析,獲得更精確的數據,提供政策面及管理面相關建議,全方位的提升資訊安全。

The INTERNET, nowadays, has become a must-have part for modern community. No matter whether we are on working, studying, entertainment activities or basic lifestyles such as food and clothing, it is inseparable obviously. However, the INTERNET is still full of risks. Information security incidents such like viruses, intrusions, and attacks are frequently reported. If the data or operating system is damaged or the account password is lost, our property will face lost surely. It is impossible to estimate once the enterprise suffers from the loss of tangible property, or the transaction or data is stolen or damaged. If events above occurred, it will lead to huge loss of goodwill and customers trust. In recent years, companies have begun to realize the importance of information security and mainly take the following two ways. The first is on working surface - appointing an external consultant company to develop an Information Security Management System (ISMS) to pass and acquire the ISO27001 international information security standard certification. The other is on physical protection surface - Investing a large amount of cost to purchase security equipment to prevent the occurrence of security incidents. However, the Information security incident still continues and causes significant losses to the company in the world.
With the prevalence of electronic transactions and the take-off of various online-financing, making the hackers to look at the privacy and steal information (such as bank account information, credit card information, … etc.) by various ways to obtain substantial monetary benefits. The financial institutions are the favorite of hackers, so the maintenance of information security is relatively more difficult. We can review the major financial incidents in recent years, such as securities dealers attacked by DDoS (Distributed Damage of the Service) and the international remittance system SWIFT were stolen. The former can be protected by cleaning model of ISP and additional purchasing of DDoS defense equipment. But the latter is difficult. Once internal computer infected, it will lead to chain-infected efficient and collapse the target computer then hacker can achieve the piracy purpose. While analyzing the source of the virus, we find that most of the infections were connected to external web pages. If we can reduce the chance of online-poisoning, it will effectively reduce the security incident. This study uses a record of online behaviors from a financial institution in Taiwan (web filter) and a computer virus record (antivirus software) to analyze the relationship between virus and Internet access, webpage categories, web pages, and various virus and webpage categories. Hereunder we provide relevant data and more complete online policy advice (effective banned website) to strengthen existing information security mechanisms with data analysis and to reduce the occurrence of security incidents.
The results of the study show that the number of users surfing the Internet should be proportional to the number of poisonings. Information officer should be the most knowledgeable about this, and the real answer is also revealed in the statistics. With the relevant follow-up research, more equipment records added and more comprehensive as well as different equipment-based and multi-oriented analysis are carried out, we can obtain more accurate data to provide relevant recommendations about policy and management then to improve information security.

中文摘要 i
英文摘要 ii
誌謝 iii
目錄 iv
表目錄 v
圖目錄 vi
第一章 緒論 1
1.1 研究背景 1
1.2 研究動機 2
1.3 現行方式的問題 3
1.4 研究的目地 4
第二章 文獻探討 5
2.1 資訊安全 5
2.1.1 資訊安全管理制度建立 5
2.1.2 資訊安全管理制度的實施範圍 6
2.1.3 管理制度的運作架構 6
2.2 網路行為的分析 7
2.3 電腦病毒的演進與威脅 13
2.4 數據分析的方法 15
2.4.1 數據資料類型 15
2.4.2 資料分析演算法 16
第三章 研究方法與設計 17
3.1 研究架構 17
3.2 研究資料描述 18
3.3 研究範圍說明 19
3.4 研究資料分析方法 19
3.4.1 次數統計 20
3.4.2 最大中毒數網址類別分析 21
3.4.3 最大中毒數網址分析 21
3.4.4 不同病毒與網址類別關聯分析 23
第四章 研究分析結果與處置 24
4.1 研究分析說明 24
4.1-1外部風險 24
4.1-2內部風險 24
4.1-3風險防範措施 25
4.2 分析資料說明 25
4.3 分析結果與處置 26
4.3-1次數統計分析結果 27
4.3-2最大中毒數網址類別分析結果 28
4.3-3最大中毒數網址分析結果 29
4.3-4不同病毒與網址類別關聯分析結果 30
第五章 研究結論與建議 32
5.1 研究結論 32
5.2 研究限制 33
5.3 後續研究建議 33
參考文獻 35

1.媒體調查機構We Are Social與Hootsuite「2018年全球數位報告」. (2018年2月1日). 擷取自 https://newtalk.tw/ me.com.tw/article/122191
2.國立政治大學統計系. (2017年2月). 2017 年台灣寬頻網路使用調查報告. 擷取自 https://www.twnic.net.tw/doc/twrp/20170721e.pdf
3.芬-安全與全球網路聯盟合作 提供惡意網站黑名單加強打擊惡意網址. (2017年12月25日). 擷取自 https://www.fservice.com.tw/芬-安全與全球網路聯盟合作-提供惡意網站黑名單加.html
4.風暴再起!資安攻擊造成台灣損失GDP總值5%. (2017年6月11日). 擷取自 https://newtalk.tw/news/view/2018-06-11/127487
5.【iThome 2018企業資安大調查:資安事件衝擊篇】員工資安意識不足的威脅,比駭客更大. (無日期). 擷取自 https://www.ithome.com.tw/article/122191
6.無檔案病毒攻擊: 新數位貨幣採礦病毒,亞太區為重度感染區,台灣排名第三. (無日期). 擷取自 https://blog.trendmicro.com.tw/?p=51904
7.【iThome 2018企業資安大調查:資安人力編制篇】6成IT部門兼管資安,金融業編制最大. (無日期). 擷取自 https://www.ithome.com.tw/article/122187
8.曹昱仁. (2017). 探討醫療院所導入資訊安全管理系統對資訊安全成熟度. 國立中山大學資訊管理學系碩士論文.
9.經濟部標準檢驗局. (無日期). ISO 27001驗證說明會標準檢驗局之驗證程序介紹報告.
10.陳國增. (無日期). 資訊安全簡介與資訊安全政策. 工業技術研究院資訊技術服務中心.
11.孫郁興. (2006年12月). 電腦病毒科技發展史之研究. 中華科技史學會會刊第十期, 頁 29-36. doi:10.7094/BAFHS.200612.0029
12.維基百科 (編者). (2017). 知名病毒及蠕蟲的歷史年表. 2019年2月1日 擷取自 https://zh.wikipedia.org/wiki/知名病毒及蠕蟲的歷史年表
13. 陳建煒. (2016). 大數據之醫療運用-大數據研究之機會與限制. 台灣醫學台灣醫學2016 20卷6期. doi:10.6320/FJM.2006.20(6).5
14. 結構化資料是什麼? 數據分析前,重新認識你的資料. (2018年4月30日). (Power BI 數據工坊) 擷取自 https://daxpowerbi.com/結構化資料
15. 工作筆記 結構、半結構、非結構式資料是啥意思. (無日期). 擷取自 Kevin 的 MongoDB: https://kevinwang.gitbooks.io/bigdata/content/general/structured-data.html
16. 蘇凱平. (2016). 再訪法實證研究概念與價值:以簡單量化方法研究我國減刑政策為例. 臺大法學論叢NTU Law Journal第45 卷第3期. doi:10.6199/NTULJ.2016.45.03.04
17. 資料分析 Machine Learning(3). (2017年7月4日). (Blog, Leo Yehs) 擷取自 https://leoyeh.me/2017/07/04/資料分析-Machine-Learning-3
18. 資料探勘演算法 - 分群法. (2016年12月25日). 擷取自 https://ithelp.ithome.com.tw/articles/10187496
19. 黃彥棻. (2017年10月13日). 【遠銀遭駭追追追】更多入侵細節大公開!18億元遠銀遭駭盜轉事件追追追. 擷取自 https://www.ithome.com.tw/news/117397
20. 水坑攻擊. (2017年12月2日). (維基百科) doi:https://zh.wikipedia.org/wiki/水坑攻击
21. 金融機構辦理電腦系統資訊安全評估辦法. (2014年7月10日). (中華民國銀行商業同業公會全國聯合會) 擷取自 https://law.fsc.gov.tw/law/LawContent.aspx?id=GL001625

QRCODE
 
 
 
 
 
                                                                                                                                                                                                                                                                                                                                                                                                               
第一頁 上一頁 下一頁 最後一頁 top
無相關期刊