跳到主要內容

臺灣博碩士論文加值系統

(216.73.216.141) 您好!臺灣時間:2026/08/24 11:37
字體大小: 字級放大   字級縮小   預設字形  
回查詢結果 :::

詳目顯示

: 
twitterline
研究生:郭政哲
研究生(外文):CHENG-CHE KUO
論文名稱:企業內部網路安全防護架構研究
論文名稱(外文):Research on Security Protection Architecture for Enterprise Intranet
指導教授:鄭進興鄭進興引用關係
指導教授(外文):JINN-SHING CHENG
口試委員:陳俊麟黃照貴鄭進興
口試委員(外文):CHIN-LING CHENECHO HUANGJINN-SHING CHENG
口試日期:2019-07-31
學位類別:碩士
校院名稱:國立高雄科技大學
系所名稱:資訊管理系
學門:電算機學門
學類:電算機一般學類
論文種類:學術論文
論文出版年:2019
畢業學年度:107
語文別:中文
論文頁數:61
中文關鍵詞:橫向擴散路由器新世代防火牆(NGFW)病毒過濾入侵防禦系統
外文關鍵詞:Horizontal diffusionRoutersNew generation firewall (NGFW)Virus filtering
DOI:Intrusion prevention systems
相關次數:
  • 被引用被引用:1
  • 點閱點閱:608
  • 評分評分:
  • 下載下載:132
  • 收藏至我的研究室書目清單書目收藏:0
隨著網際網路興起,有線網路與無線網路的訊號越來越綿密,政府與企業利用網路來支持服務的機會也越來越多,過往電腦病毒通過磁片、隨身碟來做單一設備傳播,演變至今則是透過網際網路與作業系統的漏洞來做攻擊,且多數的攻擊皆有橫向擴散的趨勢走向。以往政府與企業用戶的網路多以路由器來做第三層的溝通,並無病毒過濾,入侵防禦系統的功能,面對現行層出不窮且變化多端的資訊安全威脅,單靠單機安裝防毒軟體恐已無法抵禦。本論文針對內部網路第三層路由器的功能,由新世代防火牆(NGFW)來擔任,透過防火牆(NGFW)的應用程式管理功能,加強內部網路流量可視化,再搭配病毒過濾,入侵偵測系統功能使端點設備發生資訊安全威脅時,可以第一時把威脅限制在該設備上,而不發生橫向感染,為資訊管理者爭取更多的處理時間,進而達到預防、偵測、緩解。
With the rise of the Internet, the signals of wired and wireless networks are becoming more and more dense, and there are more and more opportunities for governments and enterprises to use the Internet to support services. In the past, computer viruses used a magnetic disk and a flash drive to make a single. The spread of equipment has evolved through attacks on the Internet and operating systems, and most attacks have a tendency to spread horizontally. In the past, the network of government and enterprise users mostly used routers to do the third layer of communication, there is no virus filtering, the function of the intrusion prevention system, facing the current endless and varied information security threats, and relying on the stand-alone installation of anti-virus software alone. Unable to resist. This paper is aimed at the function of the internal network third-layer router, which is operated by the new generation firewall (NGFW). Through the application management function of the firewall (NGFW), the internal network traffic is visualized, and then the virus filtering and intrusion detection system are matched. When the function causes the information security threat of the endpoint device, the threat can be firstly restricted to the device without horizontal infection, and the information manager can obtain more processing time to prevent, detect, and mitigate.
摘要 i
ABSTRACT ii
誌謝 iv
目錄 v
圖目錄 viii
表目錄 x
壹、 緒論 1
貳、 文獻探討 12
參、 系統規劃與設計 30
肆、 系統實作及成果展示 41
伍、 結論與未來研究方向 57
參考文獻 59





[01] World Economic Forum,2019。https://www.weforum.org/
[02] F. Cohen, ”Computer viruses, theory and experiments, ” Proc. 7th DOD/NBS Computer & Security Conf., pp. 22-35, 1987.
[03]http://www.research.ibm.com/antivirus/SciPapers/White/Problems/Problems.html
[04]圖1-1. DataFlow。https://zh.wikipedia.org/wiki/OSI%E6%A8%A1%E5%9E%8B
[05]圖1-2.OSI模型。https://community.fs.com/blog/tcpip-vs-osi-whats-the-difference-between-the-two-models.html
[06] World Economic Forum,2019,”The Global Risks Report 2019”,pp.5
http://www3.weforum.org/docs/WEF_Global_Risks_Report_2019.pdf
[07]次世代防火牆(NGFW)。https://www.ithome.com.tw/article/87912
[08]世界各國上網人口統計。https://zh.wikipedia.org/wiki/%E5%90%84%E5%9B%BD%E4%BA%92%E8%81%94%E7%BD%91%E4%BD%BF%E7%94%A8%E8%80%85%E6%95%B0%E7%9B%AE%E5%88%97%E8%A1%A8
[09]Frederick Cohen,Dwan,2000。https://www.researchgate.net/publication/222220088_The_Computer_Virus_-_From_There_to_Here_An_Historical_Perspective
[10]圖2-2、作業系統全球市佔率。https://zh.wikipedia.org/wiki/%E6%93%8D%E4%BD%9C%E7%B3%BB%E7%BB%9F%E4%BD%BF%E7%94%A8%E4%BB%BD%E9%A2%9D
[11] Cohen,1994,”A Short Course On Computer Viruses”http://all.net/books/virus/SCVirusBook.pdf
[12]陳大任、黃賢麟(譯)(2002)。D. Harley, R. Slade, & U. E. Gattiker著。病毒聖經。台北市:麥格羅希爾。
[13]蘇永護、包蒼龍,「以DNS 封包內涵為基礎之殭屍網路封包行為之偵測與阻擋」; 大同大學資訊工程研究所,碩士論文,July 2010.
[14]吳俊達,“進入Botnet 的世界”,RUN!PC 雜誌, June 2009.
[15]Moheeb Abu Rajab, Jay Zarfoss, Fabian Monrose and Andreas Terzis, ”A Multifaceted Approach to Understanding the Botnet Phenomenon,” In IMC’06, October 25–27, 2006.
[16]攻擊SYN Flood,https://zh.wikipedia.org/wiki/SYN_flood
[17]楊子翔,蔡錫鈞「Network DoS/DDoS攻擊及預防方法之研究」,TANET研討會,2000年.
[18]資策會整合技術實驗室ITL「ICMP DoS攻擊之原理與防禦方法」.
[19]安全通報TW-CA-2001-101,"Code Red Worm Exploiting Buffer Overflow In IIS Indexing Service DLL”台灣電腦網路危機處理暨協調中心,2001年7月26日,http://www.cert.org.tw/document/advisory/200107/TW-CA-2001-101.txt.
[20]李美雯,「一波未平一波又起-Nimda病毒」,台大資通安全服務小組
https://cert.ntu.edu.tw/document.html.
[21]李美雯,「紅色警戒(Code Red)事件分析」,台大資通安全服務小組
https://cert.ntu.edu.tw/document.html.
[22] Fortigate 60e,https://www.fortinet.com/tw/products/next-generation-firewall/entry-level.html
[23]Eicar,https://www.eicar.org/
[24]Eicar病毒下載,https://www.eicar.org/?page_id=3950
[25]Test Malware!,https://www.wicar.org/test-malware.html

QRCODE
 
 
 
 
 
                                                                                                                                                                                                                                                                                                                                                                                                               
第一頁 上一頁 下一頁 最後一頁 top