研究生(外文):Wen-Yang Luo
論文名稱(外文):A Lightweight System of Detecting DoS/Probe Attacks Based on Packet Header
指導教授(外文):Shi-Jinn Horng
外文關鍵詞:Denial of Service (DoS)Packet HeaderEntropyDARPA dataset
A denial-of-service (DoS) attack is a serious threat to the Internet security nowadays. According to a 2006 CSI/FBI Computer Crime and Security Survey, 25 percent of respondents whose computer detected DoS attacks in the last 12 months. Moreover, the Symantec Internet Security Threat Report showed that an average of 6,110 DoS attacks occurred per day in the first half year of 2006. In the early days, many DoS attacks spoofed source addresses in the attack packets. Now they can use a number of zombies simultaneously to send tremendous packets to a victim and this makes it more difficult to trace the attackers.
In this research, we applied an entropy-based method to analyze the characteristic of network traffic and revealed that it is helpful to detect great scale of DoS/Probe attacks by observing the variation of the entropy of each header field. To accomplish this idea in real-time network, we had to simplify the process and turn it into three detection approaches: Distributed Addresses Detection Approach, S/R Ratio Detection Approach and TCP Connection Detection Approach. Based on the result of DARPA 98 testing dataset, we proved that our proposed lightweight system could detect DoS/probe attacks efficiently in an actual network and keep a low false positive rate.
摘  要 I
目錄 VI
圖目錄 VIII
表目錄 X
第一章 緒論 1
 第一節 研究背景 1
 第二節 研究動機 5
第二章 阻斷服務攻擊與網路探測 6
 第一節 (分散式)阻斷服務攻擊 6
 第二節 (分散式)阻斷服務攻擊分類 9
 第三節 典型阻斷服務攻擊介紹 13
 第四節 網路探測 16
 第五節 常見網路探測攻擊介紹 18
 第六節 相關研究 20
第三章 網路流量分析 22
 第一節 網路封包格式 22
 第二節 網路流量資料集 26
 第三節 網路流量分析 31
第四章 系統實作 41
 第一節 系統概述 41
 第二節 取樣封包數 43
 第三節 位址分散偵測機制 45
 第四節 傳接比值偵測機制 47
 第五節 TCP連線偵測機制 53
 第六節 系統流程設計 55
第五章 實驗結果 58
 第一節 DARPA測試集實驗 58
 第二節 即時模擬實驗 63
第六章 結論 69
參考文獻 71
