研究生(外文):Chih-Shiung Huang
論文名稱(外文):The Study of the Integration of Agent-based Intrusion Detection System and Deception System
指導教授(外文):Chih-Hung Wang, Ph. D.
外文關鍵詞:Agent-based Intrusion Dectection SystemDeception SystemNetwork Security
現今的網路入侵行為已漸趨複雜與多變,單一的防衛設備如防火牆已不足以保護網路的安全。近年來提出的入侵偵測系統 (Intrusion Detection System; IDS),主要能夠發現可疑的攻擊,並對系統管理者發出警告,因此對於網路提供了更堅實的保護。然而,系統管理者卻常因為IDS 的高誤報率而十分困擾。經常許多正常的連線卻被警告為攻擊事件。而許多潛在未知的攻擊行為卻無法被IDS 偵測出來。因此,我們提出一個整合代理人入侵偵測系統(Agent-based Intrusion Detection System)與陷阱誘捕系統(Deception System)的安全防禦機制,解決傳統IDS長期以來存在的問題。

Currently, the intrusion behavior in the network has become more and more complicated and diverse. The conventional network defense which uses a single device, such as firewall, is not enough to safeguard the network against the various threats. Intrusion detection system proposed recently can help the administrator to detect the suspicious behaviors and alarms, so that the network communication can be protected more robustly. However, the system administrator is usually in trouble over the false alarms of IDS. Many valid connections are regarded as attack events, while many potential unknown-attacks cannot be detected by IDS. For this reason, we propose a better solution which integrates agent-based intrusion detection system and deception system to overcome the critical problems of the traditional IDS.
Since the intruders can perform a variety of attacks in different network sections, the integration of IDS and deception system will help us make a full-scale analysis. In our way, we analyze the raw data of the attack features in Honeyd are analyzed. The analyzing results will be transmitted to AIDS such that AIDS can use them to adjust threshold values and discover the potential attacks in advance. We also provide a nice solution to enhance the detection performance and security in the network by adopting multilevel checking systems.

