研究生(外文):Fan Yi Ming
論文名稱(外文):A Study on Anomaly Detection Mechanisms in Linux Environments
指導教授(外文):Tsaur Woei Jiunn
外文關鍵詞:Fuzzy c-meansAnomaly detectionIntrusion detectionLinux
近年來,由於網際網路發展成熟,網路技術也不斷地推陳出新,造成網路犯罪的行為及入侵手法也一直不斷地翻新。電腦病毒或者駭客透過網際網路的延伸與蔓延,可攻擊全世界的各個電腦系統,所造成的潛在危害不僅難以估計,亦暴露出資訊系統本身存在的安全問題。異常行為偵測法(anomaly detection)是基於正常行為為基礎,首先必須建立正常行為的規範,而異常行為的決定是由該行為是否背離正常行為來判斷。其次,透過分析使用者過去使用習慣與即時發生的事件,以辨識出異常的行為。而用傳統的群集(clustering)方式來做異常行為與正常行為之比對,經常會造成誤判(false alarm)。因此,本論文基於模糊理論中較快速的群集演算法(multistage random sampling fuzzy c-means;mrFCM)來解決異常行為偵測的問題,以達到增加正確率與減少誤判的機率。此外,我們亦有開發成實際的系統,經由真實的記錄檔執行後,結果顯示出本論文所提出的方法確實能達到預期的成效。
Recently, since the growing development of Internet technology, the approaches of network crime have been keeping changing. Computer virus and hackers can attack the computer systems all over the world through Internet to destroy and intrude their computer resource. Therefore, we must do our best to develop intrusion detection mechanisms to prevent such situations. An anomaly detection mechanism must establish work profile based on normal behaviors, and the decision of anomaly is judged from the difference between normal and abnormal behaviors. Conventional clustering methods for anomaly detection often cause the situation of false alarm. Thus, in this thesis we will detect the anomaly accurately using the faster multistage random sampling fuzzy c-means (mrFCM) so that the possibility of false alarm can be reduced greatly. Besides, we also develop a program system, and test it by employing a real log file. The results derived from the program system validate the feasibility of our proposed algorithm.
第一章 緒論…………………………………………1
1.1 研究背景與動機 ……………………………… 1
1.2 研究目的……………………………………… 3
1.3 論文架構……………………………………… 4
第二章 文獻探討………………………………… 6
2.1 入侵手法簡介………………………………… 6
2.2 Linux的安全問題…………………………… 13
2.3 異常偵測………………………………………18
2.4 群集的技術……………………………………22
第三章 Linux作業系統下異常偵測………………30
3.1 研究架構………………………………………30
3.2 研究模型………………………………………32
3.3 研究方法………………………………………34
第四章 系統分析與實作………………………… 43
4.1 網頁記錄檔分析………………………………43
4.2 資料轉換………………………………………44
4.3 開發工具與環境………………………………46
4.4 系統實作………………………………………46
4.5 分析資料………………………………………52
第五章 結論與建議……………………………… 54
