論文名稱:建構物聯網連線偵測機制以防禦 以欺騙為基礎之中間人攻擊
論文名稱(外文):Building an IoT connection detection mechanism to defend fraud-based man-in-the-middle attacks
指導教授(外文):HUNG, WEI-HSI
外文關鍵詞:Internet of ThingsMan-in-the-middle attacksDesign scienceCrisis life cycleExpert interview
In the environment of the booming Internet of Things, there will be more and more cyber attacks through the Internet of Things or directly attacking the Internet of Things. Man-in- the-middle attacks and similar attacks are also expected to grow in mobile devices or applications. The man-in-the-middle attack is mainly that the third party acts as a middleman hiding in the middle of the exchange of messages to steal information transmitted between the victims or the devices. Although it is an ancient method, the man-in-the-middle attack still exists and even is evolving. Therefore, the prevention of man-in-the-middle attacks is very important, especially under the environment of Internet of Things.
This study adopts a design science research method to develop a protection framework for preventing man-in-the-middle attacks in the Internet of Things scenario. This framework uses the literature of crisis life cycles and man-in-the-middle attacks as the prototype of the architecture, and then analyzes the literature of man-in-the-middle attack prevention and related news cases. Finally, interviews and evaluations from five experts in order to achieve refinement to improve the architecture were carried out based on how the framework can be used to help companies to choose the appropriate protection recommendations according to the extent of their attack Their suggestions become the recommendations of the protection structure to prevent man-in-the-middle attacks.
The results show that the man-in-the-middle attack not only causes the loss or forgery of information, but also has a negative impact on the trust of the enterprise. It is also found that the reason for the successful attack of the man-in-the-middle is mostly due to the weak security concept of the organization personnel, especially the data of the border network and system alternation, or the equipment is neglected to manage. So, the professional technology and the management of the organization personnel and equipment are required to prevent the crisis caused by the man-in-the-middle attack. Therefore, the prevention structure defines the situation in which the man-in-the-middle attacks occur at various stages in the crisis life cycle. The appropriate prevention methods include, such as confirming the correctness of the transmission channel during the prodromal stage, communicating with the user during the chronic stage, and revisiting past improvements during the resolution stage
第一章、緒論 ............................................................................................................... 1
1.1 研究背景 .......................................................................................................................... 1 1.2 研究動機 .......................................................................................................................... 3 1.3 研究目的 .......................................................................................................................... 6
第二章、文獻探討........................................................................................................ 7
2.1 物聯網與資訊安全介紹 ................................................................................................... 7 2.1.1 物聯網架構 ..................................................................................................................... 7 2.1.2 資訊安全 ....................................................................................................................... 10 2.1.3 網路或計算機攻擊分類 .............................................................................................. 11 2.1.4 物聯網的資訊安全 ...................................................................................................... 12 2.2 中間人攻擊介紹............................................................................................................. 13 2.2.1 分散式阻斷服務攻擊(Distributed denial of service attack,DDoS) ...................... 14 2.1.2Karma 攻擊 ................................................................................................................... 15 2.2.3 隱身中間人攻擊(Stealth Man-in-The-Middle,SMiTM) ......................................... 16 2.2.4 高級隱身中間人攻擊(Advanced Stealth Man-in-The-Middle,ASMiTM) ................ 17 2.2.5 ARP 緩存中毒(ARP cache poisoning) ......................................................................... 18 2.3 緩存中毒(ARP cache poisoning)相關研究 .................................................................... 20
3.1 設計科學 ........................................................................................................................ 24 3.2 研究架構 ........................................................................................................................ 26 3.3 研究流程細節與步驟 ..................................................................................................... 26
第四章、研究結果與討論 ...........................................................................................28
4.1 危機生命週期 ................................................................................................................ 28 4.2 文獻收集.......................................................................................................................30
4.3 新聞報導 ........................................................................................................................ 33
4.4 專家訪談.......................................................................................................................38
4.4.1 專家訪談 ....................................................................................................................... 38 4.4.2 MITM 防護架構 V3................................................................................................... 39 4.4.3 MITM 防護架構 V4................................................................................................... 41 4.4.4 MITM 防護架構 V5 ..................................................................................................... 43 4.4.5 MITM 防護架構 V6 ..................................................................................................... 45
4.4.6 MITM 防護架構 V7 ..................................................................................................... 46 4.4.7 MITM 防護架構統整 ................................................................................................... 48
第五章、結論與未來方向 ...........................................................................................50
5.1 結論..............................................................................................................................50
5.2 研究貢獻.......................................................................................................................52
5.3 研究限制.......................................................................................................................52
附錄A-北市單一陳請系統資安問題新聞摘錄 ............................................................61


