顯示具有 碩士論文 標籤的文章。 顯示所有文章
顯示具有 碩士論文 標籤的文章。 顯示所有文章

100級-林玉燕-基於重複補取法之動態惡意域名服務網路規模估計

100級-林玉燕-基於重複補取法之動態惡意域名服務網路規模估計

[ 摘要 ]
本研究的核心為規模估計動態惡意域名服務網路(Fast-Flux Service Network)的族群規模大小,FFSN是目前網路世界所面臨的極大威脅,其技術可以讓攻擊者隱藏在一群代理伺服器(agent)後面,這樣的方式可以讓攻擊者來躲避偵測使資訊安全人員偵測失敗,FFSN這項技術對犯罪份子的好處是惡意網站可以受到保護,進而延長惡意網站的壽命。所以FFSN的危害日益嚴重,要規模估計FFSN-Agent也相當不容易,且Flux-Agent本身可能是Bot節點,估計FFSN的規模也可以知道其威脅程度。所以本研究藉由重複捕取法(Capture-Recapture Method,CRM)估計Flux-Agent的群體大小,其計算方式是透過Program NOREMARK 的Joint hypergeometric maximum likelihood estimator (JHE)估計族群量,實驗結果只需要前六天所Query的樣本數便可以估計出整個FFSN的族群大小,其實驗結果比普查的方式可以更快速找出整個族群大小。

[ 英文摘要 ]
The purpose of this study is to estimate the group size of Fast-Flux Service Network (FFSN.) FFSN is one of the enormous threats of internet. It can hide the attackers behind a group of agents and by this way the attackers can avoid being detected. The benefit of FFSN to attackers is the malicious websites can be protected and the survival time can be prolonged. The danger of FFSN is getting more serious and Flux-Agent could be a Bot note. To estimate the size of FFSN can find the danger degree but to estimate the size is not easy. Hence, this study uses Capture-Recapture Method (CRM) to estimate the group size of Flux-Agent. By computing the joint hypergeometric maximum likelihood estimator (JHE) of Program NOREMARK, the group size can be found. The experiment needs just the query samples among six days before and the group size of FFSN can be found. The experiment result can more quickly find the group size than census can.

100級-蔡佩旻-自動化部署與運用虛擬化蜜網系統

100級-蔡佩旻-自動化部署與運用虛擬化蜜網系統

[ 摘要 ]
由於網際網路的普及化越來越高,以及社群網站的盛行,已讓網際網路安全成為一大重要課題。尤其在學術網路的使用上,對於網路與電腦的管理都採取較寬鬆的方式處理,使的學術網路成為大部分犯罪者攻擊的目標。當犯罪者成功入侵電腦之後往往使用諸多的惡意軟體工具來從事許多的非法活動,像是木馬、垃圾郵件、分散式阻斷服務攻擊、釣魚網站與病毒散播等威脅。Honeynet屬於一種dummy的網路架構,藉著所提供諸多網路服務來吸引犯罪者入侵,並可部署在許多的區域當作一種防禦策略。

本研究利用honeynet的特性,提供使用者可以快速的偵測與確認malicious source,但由於honeynety在部署與實作上本身就存在諸多的困難度,所以本研究提出一個新的自動化系統,讓管理者可以藉此將系統快速的部署在學術網路上加以運用。

[ 英文摘要 ]
Because the popularization of the Internet is increasingly high, and the prevalence of social networking , which have allowed Internet security has become an important issue. Campus Network has become the target of attacks by the majority of offenders, to adopt a more lenient approach to the management of network and computer. After the successful invasion of the computer, the offender spreads a lot of malicious software tools to engage in illegal activities, such as Trojans, spam, distributed denial of service attacks, phishing sites, and other threats. The Honeynet belong to a dummy network infrastructure, to attract a lot of network services through the provision of the criminal invasion and can be deployed in many areas as a defense strategy。

In this thesis we can quickly detect and confirm the malicious source through characteristic of honeypot. Users would be a lot difficulty to deploy and implement the honeynet. In this thesis we present the new automatic system that allows managers to rapid deployment of the virtual honeynet system in the Campus Network.

100級-黃宗恩-以網域名稱服務之郵件交換紀錄為基礎偵測動態惡意域名服務網路

100級-黃宗恩-以網域名稱服務之郵件交換紀錄為基礎偵測動態惡意域名服務網路

[ 摘要 ]
近年來隨著科技與網際網路的進步,人們的日常生活及商業活動變得越來越依賴網路,因此使許多駭客開始藉由種種不當的入侵與攻擊手法企圖謀取龐大的非法利益;例如「動態惡意域名服務網路(Fast-Flux Service Networks)」便是一項近年來廣被許多駭客使用的新興的攻擊方式,此入侵手法藉由導入DNS之輪替式網域名稱服務(Round Robin DNS, RR-DNS) 技術,透過不斷變換其所對應到的實體機器之網域,來保護具備惡意用途的內容網站,其中被對應的實體機器常為受害的電腦主機,導致此攻擊所造成之危害日益漸增。因此,本研究利用FFSN特徵偵測技術搭配其既有之特徵值為偵測基準來實作一偵測系統,並針對ATLAS及ALEXA所獲取之資料進行測試,以利後續驗證本研究所建置之偵測系統之偵測率及正確率,並分析特徵搭配後的偵測效益,進而從中挑選出最佳方案作為日後之偵測基準。

[ 英文摘要 ]
During recent decades, the explosive development of the Internet brings a remarkable advance in information exchange. Hence, people’s daily life and commercial activities rely on the Internet much tremendously. More and more hackers try to gain enormous illegal profits by such illegitimate invasion and attack approaches. For instance, Fast-Flux Service Networks is one of emerging attack technologies, which is used to invade the system through combining the RR-DNS technology (Round Robin DNS) of DNS. Fast-Flux can protect malicious websites by keeping changing the IP address of the Mothership. In most cases, naïve users’ computers are usually the attack targets so the damage is getting worse with each passing day. Therefore, this study uses FFSN characterization and original features as detection patterns to construct a detection system. The data from ATLAS and ALEXA are tested to evaluate the detection rate and accuracy of the proposed system. Finally, through the analysis of the detection effectiveness after features mapping, the best solution can be found as the future detection pattern.

100級-林添財-社交網站惡意程式分析:以Koobface為例

100級-林添財-社交網站惡意程式分析:以Koobface為例

[ 摘要 ]
社交網路服務(Social Networking Service,SNS)目前成已為網路上最受歡迎的活動,舉凡聊天、寄信、影音、分享檔案等,讓相同興趣的人建立線上的社群,透過網際網路提供使用者各種聯繫與交流的功能來鞏固的彼此的關係。隨著社交網路服務被廣泛的使用,駭客利用惡意連結、社交工程、網路釣魚等攻擊的方式,使社交網路成為散佈惡意程式的跳板工具。
本研究以社交網站中的惡意程式koobface為主題,討論其散佈、感染的方式、對外網路的行為,研究結果最終證實都具有惡意的性質,探究其原因駭客就是利用社交網路中對人的信任或是好奇的心理,藉由這樣的誘因、手段,以達到預先想要的目的。

[ 英文摘要 ]
Social networking service (Social Networking Service, SNS), as currently the most popular activities on the network covered the chat, e-mail, video, file sharing, etc., so that the same people interested in the establishment of online community through the Internet provide users with a variety of contacts and exchanges to consolidate the mutual relationship. The malicious link with the social networking service is widely used, hackers, social engineering, phishing and other mode of attack, so that the social network to become a springboard for spreading malware tools.
In this study, the malware koobface social networking sites as the theme, to discuss its spread infection, the behavior of the external network, the results eventually confirmed to have a malicious nature, explore the reason hackers use social networks in the human the trust or the curious psychology, by this incentive, means, in order to achieve the desired purpose in advance.

100級-吳沅錄-以連接埠掃描為基礎偵測動態惡意域名服務網路

100級-吳沅錄-以連接埠掃描為基礎偵測動態惡意域名服務網路

[ 摘要 ]
動態惡意域名服務網路Fast-Flux Service Networks (FFSN)源自於一種稱為輪替式網域名稱服務Round-Robin DNS (RR-DNS)的技術。它是一種透過將DNS記錄快速更換,使得網域名稱能夠被快速對應到數個不同的主機,以達到負載平衡的機制。Fast-Flux與RR-DNS相似,然而不同的是,Fast-Flux是將網域名稱快速對應到數個來自殭屍網路(Botnet)的受害電腦設備,並以保護惡意內容網站,如釣魚網站、惡意程式下載站及垃圾郵件內容網站為目的,使惡意攻擊時效得以延長。過去的研究著重於多次對特定網域進行DNS查詢,並找出多次查詢之間的相異之處,然而這樣的作法容易受到網路環境影響,且偵測時間較長。本研究透過掃描網域內的每個主機,並計算各個主機間的連接埠重複程度,藉此來判斷此網域為重複程度低的FFSN惡意網域或重複度高的正常網域,此外,本研究還搭配了過去研究所發現的另一項Fast-Flux之特徵,DNS query time之標準差,並以標準差高於門檻值者判定為FFSN惡意網域,而低於門檻值者則判定為正常網域,以此二特徵搭配作為Fast-Flux之偵測特徵,並得出相當高的精確率。本研究也針對了此二特徵進行偵測速度分析,並得出了使用連接埠重複程度作為FFSN之偵測特徵,不同於過去研究所發現到的特徵必須利用多次查詢,並在每一次查詢之中皆需等候TTL時間經過才能進行下一步驟的特點,它在平均約47秒內便可得出偵測結果,比過去偵測時間動輒約數百秒還快上許多,且在降低偵測時間的同時,亦能維持一定的精確率。

[ 英文摘要 ]
Fast-Flux Service Networks (FFSN) derives from Round-Robin DNS. RR-DNS is a method of choosing a resource for a task from a list of available resources, usually for the purposes of load balancing. FFSN is similar to RR-DNS, but there have some differentials that the list of available resources is come from the victim hosts, and those victim hosts are used to protect phishing sites, malicious sites and spam server by hackers. In the past, the research usually focused on “To DNS query a specific domain, and finding the difference between each results of DNS query”, the result of detection will easily be influenced by the network environment, and the time of detection may be increased. In this thesis, we use the nmap to scan host’s port in specific domain, to calculate the discrepancy between each hosts, and to determine the FFSN domain (high differentiate) and the benign domain (low differentiate), in addition, we use another FFSN feature “The standard deviation of DNS query time”, if the standard deviation are higher than threshold, then it is a FFSN domain, if it not, it is a benign domain. We combine this two FFSN feature, and then we get a high accuracy. We also analyze this two FFSN feature about their detection speed, we find that the feature “differentiate of each host’s port” is not the same with the past’s research, it do not need to wait for TTL time, it’s average of complete the detection is about 47 seconds, and the past’s research is more than 100 seconds. “Differentiate of each host’s port” is not only decreasing the time of detection, but also keep the accuracy higher.

99級-楊昆鑫-以DNS Query Time 為基礎偵測Fast-Flux Service Networks(FFSN)

99級-楊昆鑫-以DNS Query Time 為基礎偵測Fast-Flux Service Networks(FFSN)

[ 摘要 ]
隨著網際網路被運用在商業的頻率越來越高,網路攻擊所造成的利益損害已經逐漸擴大。駭客運用著網際網路從事非法的活動,像是木馬、病毒散播、分散式阻斷服務攻擊、垃圾郵件與釣魚網站的威脅等,為了獲取龐大的利益,犯罪者對於非法活動的需求日漸成長,而為了讓這些詐欺行為具有高度的隱蔽性,犯罪者開始使用一種稱為Fast-Flux Service Networks的攻擊手法,FFSN是由一群被用來當作代理轉向服務的傀儡網路(botnet)所組成,利用這些受感染的傀儡主機便可以將使用者重新導向至犯罪者所架設的惡意內容。
本研究實作建置一系統,以本研究所探討之偵測特徵搭配既有特徵為偵測基準,針對Malware Domain List及ATLAS資料來源偵測FFSN惡意網域,探討當前網路犯罪中FFSN被犯罪者應用的實際情形、並分析偵測效益並挑選出最佳方案作為日後之偵測基準。

[ 英文摘要 ]
With the Internet being used more frequently in the business, network attack have caused damage to the interests gradually expanded. Hackers use the Internet for illegal activities, such as Trojan, viruses, DDoS attacks, spam and phishing, etc. In order to obtain huge benefits, the offender’s demand for illegal activities growth, and to make such fraud a high degree of concealment, the offender began to use the attack tactics called Fast-Flux Service Network (FFSN). FFSN is composed by who is used by a group of agents to service as a proxy of the botnet. Use these infected host can redirect the user to the malicious content that offender set.
In this thesis we implemented a system, we use the detection feature discuss in this thesis and the features that is already discussed in other study to detect whether the data which are from Malware Domain List and ATLAS are belong to FFSN or not. Also, we investigate the utilization of FFSN by miscreants on the Internet, and analyze the detection performance and select the best case as the baseline of detection in the future.

99級-林庭弘-以逆向工程偵測惡意代碼行為

99級-林庭弘-以逆向工程偵測惡意代碼行為

[ 摘要 ]
過去幾年來惡意程式的數量和破壞能力已成倍數成長,惡意程式開始使用代碼混淆技術、加密和加殼技術來躲避防毒軟體的特徵碼偵測。目前很多惡意作者都是使用加殼技術加密惡意程式,以躲避防毒軟體的檢測,所以惡意程式加殼已成為現今防毒公司最具挑戰性的問題。
如何去偵測惡意加殼程式,本研究提出使用Entropy和其他的輔助特徵來檢測加殼程式,並使用靜態特徵與動態特徵來偵測惡意加殼程式。實驗結果,本研究能即時偵測出代碼混淆技術、加殼和加殼技術,並能有效區分善意加殼程式和惡意加殼程式的差別。

[ 英文摘要 ]
In the past few years, the amount of the malicious program and the capability of destruction have become more and more. Malicious programs and their writers are also staring to use the packed technology of encryption and code obfuscation to avoid the detection from anti-virus software. Therefore, the packed technology has become a challenging problem to the anti-virus company.
How to detect the malicious packed program is also the important issue of researches of the information security. This study uses the encryption and the other assistant feature to help the detection to malicious packed program. Furthermore, there has use the combination of the static and dynamic feature to detect the malicious packed program. The result of this study shows that the packed technology of encryption and code obfuscation could be detected more efficiency and the different between the friendly packed program and the malicious packed program can also be identified more operative.

98級-莊竣程-偵測與分析Fast-Flux Service Network

98級-莊竣程-偵測與分析Fast-Flux Service Network

[ 摘要 ]
隨著網際網路的高度發展,網路安全已是我們所面臨最嚴重的問題之一。有一大群不法之徒運用著網際網路從事非法的活動,像是木馬、病毒散播、分散式阻斷服務攻擊、垃圾郵件與釣魚網站的威脅等,基於不法利益的考量,犯罪者對於他們的非法活動有高度的可用性需求,而為了混淆他們的詐欺活動,犯罪者們最近開始使用一種稱為Fast-Flux Service Networks的攻擊手法,FFSN是由一群被用來當作代理轉向服務的傀儡網路(botnet)所組成,同時利用這些受感染的傀儡主機來呈現犯罪者所架設的詐欺內容。
本研究實作建置一系統,針對Malware Domain List資料來源偵測FFSN惡意網域,探討當前網路犯罪中FFSN被犯罪者應用的實際情形、並分析被感染節點之分佈概況等。

[ 英文摘要 ]
As the highly development of Internet, one of the most serious threats we face is cyber-security. There are many groups of criminals using the Internet to engage in illegal activities like Trojan horse, viruses, DDoS attacks, spam emails and phishing. They motivated by illegal profit, have a high demand in availability of their illegal activities, and to confuse the location of their services. These criminals recently started to use a new technique called Fast-Flux Service Networks, composed of large groups of bots and acting as proxies to their scam contents.
In this thesis we implemented a system, detecting whether the data which are from Malware Domain List are belong to FFSN or not. Also, we investigate the utilization of FFSN by miscreants on the Internet, and analyzing the location details of the infected bots.

98級-廖紋淇-P2P Botnet之規模估計

98級-廖紋淇-P2P Botnet之規模估計

[ 摘要 ]
年來傀儡網路已成為網際網路安全的威脅,攻擊者能控制大量的電腦,以發動各種不同的攻擊,如DDoS攻擊、濫發垃圾郵件、竊取個資等。
Botnet的規模大小是評估其威脅的關鍵指標,愈大的Botnet其所帶來的威脅也愈大。
如何去估計Botnet的規模,也成為資安研究的一個重要議題。本研究提出一個利用P2P Botnet中,每個節點都會持有Botnet中部分成員的節點資訊之特性,以重複捕取法取樣估計的模式來估計P2P Botnet的規模。

[ 英文摘要 ]
In recent years, Botnets have become major security threats in Internet, since the attacker can control a large number of bots. Attackers primarily use them for DDoS attacks, e-mail spamming, or massive personal information theft.

The size of a Botnet is a key index to estimate the threat of a botnet. The larger size of a Botnet, the more devastating these attacks can be. To estimate the size of a botnet becomes an important issue in Internet security. In P2P Botnet, every bot peer holds information about some other bot peers. In this study, we utilize this characteristic and capture-recapture technique to estimate the size of a P2P botnet.

98級-郭權緯-建構P2P防火牆之HTTP-Botnet防禦機制

98級-郭權緯-建構P2P防火牆之HTTP-Botnet防禦機制

[ 摘要 ]
這幾年來, Botnet有增加的趨勢,如果沒有相對的解決辦法,未來必會有越來越嚴重的惡意攻擊情況發生。HTTP Botnet使用的是HTTP協定,利用一般HTTP 協定的80 port,達到隱藏的效果,可以順利通過防火牆跟IDS系統。
本研究採用重複標準差的方法偵測出HTTP Bot的連線,再使用JXTA P2P的網路分享偵測出結果,使用者利用名單過濾機制,進行封包的比對。
利用P2P交換資訊,已感染HTTP Bot的使用者,可以找出與HTTP Server與Bot的連線,而未感染的使用者,可以使用這些資訊,當作是比對的樣本,當有新的封包進來,可以判斷是否為惡意的連線,達到聯合防禦的目的。名單的過濾機制可以讓重複進到電腦的封包,只做第一次與黑名單的比對。使用P2P傳送,減少了建置成本,也讓整個網路變得更強韌。

[ 英文摘要 ]
The scale of Botnet is still increasing on the Internet in recently years. If there is no corresponding solution, there will be more serious and malicious attacks in the future. HTTP Botnet uses HTTP protocol. By using the general HTTP protocol and 80 port, the attacks not only can be hidden more easily, but go through the firewall and IDS systems without detected.
In this study, we use the Repeatability Standard Deviation method to detect the connection of Botnets within HTTP protocol. Furthermore, we use the JXTA P2P network to share the results we have detected, and users can compare the packets of traffic with lists of the filtering mechanism.
Using P2P technique to exchange the information we have detected, users who have been infected can find the connection of HTTP Botnet servers. And uninfected users can use this information as a comparison sample, when there are new packets. Users can use it for determining whether the connections are malicious or not, to achieve the purpose of co-defensive. Lists of filtering mechanism allow the duplicated packets entered in computers, compared only one time with the large number of blacklist. By using the P2P technique, we can not only decrease the cost of implementation, but also let the network more resilient.

98級-許雅婷-以誘捕系統為基礎的惡意網頁偵測

98級-許雅婷-以誘捕系統為基礎的惡意網頁偵測

[ 摘要 ]
隨著資訊科技以及網際網路(Internet)的快速發展及普遍,已經改變了人們溝通模式,對網路的依賴程度升高,安全問題也隨之而來。近年來Web應用程式快速發展,應用的層面越來越廣,功能越來越複雜,人們對網頁應用程式的依賴度越來越高。一旦使用者的個人電腦抵抗力不佳時,如防護軟體辨識能力不足、或作業系統的安全漏洞未更新等,就可能受到感染。生活網路化的時代,任何人隨時都可能進入高風險的感染雷區,卻毫無警覺。近年來一種新型態的網路攻擊出現,當用戶端存取遠端惡意伺服器時,伺服器回應用戶端請求,同時有一部份的惡意攻擊程式也被傳送至用戶端,即啟動了強迫下載(Drive-by-download)的攻擊。如果成功,惡意伺服器將可以在用戶端執行任何程式。惡意網頁通常又會搭配混淆機制以逃避基於特徵比對(Signature-base)為基礎的偵測系統,網頁的混淆程度日漸複雜甚至延伸至多媒體檔案(JPG、Flash、PDF等),在這種情況下,若不是真正的瀏覽該網頁致使惡意程式引發某些特定行為,單只對網頁內容解析是非常難以判別出惡意行為的,加上網頁資料繁多,攻擊手法又一再翻新。本研究基於用戶端誘捕系統為研究基礎,提出能主動判別網頁是否屬於惡意的模型,提出一種檢測方法以提升判斷惡意網頁的準確性,並先以靜態內容分析加快分析速度,再搭配用戶端誘捕系統實際瀏覽網頁進行更為深層的探測讓使用者在瀏覽網頁時,能確保本身的安全。

[ 英文摘要 ]
With the information technology and the Internet the rapid development and widespread mode of communication has changed the people dependence on the Internet increased, security issues will follow. In recent years the rapid development of Web applications, the application level became more widely and the functions became more complex, people dependence on web applications is increasing. Once the user''s PC resistance is poor, such as the identification of a lack of protective software, or operating system vulnerabilities such as not updated, it may be infected by malicious code. In this networked age, each person may enter at any time minefields of high risk of infection, but no alert. In recent years a new kind of network attacks occur when a malicious client access to remote server, the server response to client requests, while a majority of malicious attacks has also sent to the client program, the Drive-by-download attacks. If infected, the malicious server to comment client that will be able to execute any program. Malicious Web page often confused with Signature-base mechanism to evade detection systems, increasingly complex web of confusion and even extended to the level of multimedia files (JPG, Flash, PDF, etc.).In this situation, if the website is really a result of certain malicious behavior caused, but only on the content analysis is very difficult to distinguish a malicious act. However, many Web data and methods of attack repeatedly renovated. This study is based on client honeypot system, this research can take the initiative to determine whether a malicious Web page model and a detection method to improve the malicious Web page to judge the accuracy and content analysis to speed up the first static analysis speed, and then with the client honeypot system actually visit the website for more in-depth probe allows users to browse the web, can ensure their own safety.

97級-陳曉琪-改良分散式DRM機制控管P2P即時串流服務

97級-陳曉琪-改良分散式DRM機制控管P2P即時串流服務

[ 摘要 ]
P2P 傳輸技術目前相當熱門,因為它能同時讓兩個使用者直接分享彼此的檔案,而不用透過第三方(伺服器);對使用者而言,意謂可以透過網際網路直接由檔案擁有者手中得到最新的資訊,而不用再等待數位內容上傳至伺服器;對網路提供者而言,則意謂不用再浪費多餘的時間成本管理或操作伺服器。除此之外,還有許多因素加速P2P 網路之實用性,這些因素包括可用的頻寬上升、運算能力提高、儲存容量加大及網路資訊激增等。但是,P2P 傳輸技術同時也是惡名昭彰的非法活動溫床,它使得盜版和非法使用變得容易,因此許多使用者利用它來從事違反著作權法的資料交換。
為解決P2P 傳輸架構帶給大眾的不好印象,導入適合P2P 網路之數位權利管理機制(Digital Rights Management, DRM)是可行的,本研究於現有P2P 即時串流傳輸架構上,改良分散式DRM 機制,並導入新型金鑰管理系統。即時串流傳輸架構具有即載即看即丟的特性,能預防數位內容被重複利用,對於本研究所改良之DRM機制具有加強效果;而導入新型金鑰管理系統,使得DRM 機制運作時,惟有使用者缺乏合法解密金鑰時,才會出現警告,其餘時候使用者並不會感受到DRM 機制之控管,因此能提升使用者對於DRM 機制的接受度。

[ 英文摘要 ]
P2P transmission technology is very popular at present, because it can allow two users to share files directly rather than through a third party. For the users, means users can receive the latest information from the owners, and don''t have to wait for digital content uploaded to the server. For the providers, means providers don''t have to waste the extra time and cost to manage the servers. In addition, a lot of factors accelerate the practicability of P2P network, include the increased availability of bandwidth, computing capacity raise, storage capacity expansion and network information is increased. However, P2P transmission technology is also a notorious breeding ground for illegal activities, it makes piracy and illegal use easier, and many users use it in violation of copyright law to engage in the exchange of information.
In order to solve the bad impression of the P2P transmission structure, implement Digital Rights Management (DRM) for P2P network is feasible. This study improved distributed DRM architecture, and implement the novel key management scheme, in the existing P2P live streaming. Live streaming have the characteristic that is downloaded immediately, watched immediately and deleted immediately, to prevent digital content to be reused. Implement the novel key management scheme, makes a warning only when the user there is no decryption key, and the rest of the time, users will not feel the DRM mechanisms of control, so users can upgrade the mechanism for the acceptance.

97級-游婷敬-基於動態群播金鑰管理系統之改良研究

97級-游婷敬-基於動態群播金鑰管理系統之改良研究

[ 摘要 ]
隨著市場的需求,群播通訊技術的應用,如視訊會議和隨選視訊(Video On Demand, VOD)等,而不同的群播通訊技術,有著不同的運作方式,因此群播金鑰管理系統會隨著不同的環境而改變其需求條件。在前人的動態群播金鑰管理系統,主要針對動態的環境下,當成員加入或離開時,管理者能夠有效率的更新金鑰,並且不影響其他成員金鑰,而管理者更新金鑰的計算量為O(1),但管理者在群播訊息時,卻因中國餘數定理(Chinese Remainder Theorem, CRT) 的群播技術,影響了重新發佈群播訊息時的計算量,並且造成相當大的負擔量。因此本研究將針對金鑰群播訊息重新傳送效率問題的不足,利用不同的群播技術或降低其金鑰的長度來改良,不但使動態群播管理系統保有原先管理者在成員更動時金鑰更新的優點,並降低重新計算其群播訊息時的計算負擔。

[ 英文摘要 ]
With the market demand, the applications of multicast communication technologies such as video conferencing and on-demand video (Video On Demand, VOD), etc. Different multicast communication technologies, there are different mode of operation, so multicast key management system as different environmental conditions and their needs change. In the previous dynamic multicast key management systems, they are mainly for dynamic environment. When members join or leave, managers can efficiently update the key and does not affect the key of the other members, and the calculation that key managers update keys is O (1). But in multicasting message, the multicast technology of the Chinese remainder theorem(CRT) impacts the computation loading of the re-calculate multicast message, Therefore the research will be to improve the lack of transmission efficiency of the multicast message, using of different multicast technology or reduce the length of its keys to improve not only the dynamic multicast management system managers to maintain the original members when the key changes update the advantages and reduce re-calculate the multicast message at the time of the computational loading.

97級-沈俊宏-基於P2P網路架構下之即時通訊系統離線檔案傳輸機制

97級-沈俊宏-基於P2P網路架構下之即時通訊系統離線檔案傳輸機制

[ 摘要 ]
隨著Internet的發展,人與人之間溝通連繫的管道已從舊有的書信、電話…等,慢慢的轉移到網際網路的世界,而最常被使用的通訊軟體為E-mail、即時通訊軟體…等。這些技術主要以Client-Server架構為主,換言之當Server故障或損壞時,就會造成通訊的中斷或是無法使用,因此利用P2P架構來取代Client-Server架構的情況也愈來愈普遍。但在檔案傳輸方面,即時通訊系統還是只能在傳送端與接收端同時為上線狀態來進行檔案傳輸的動作,在有任一方面離線的情況還是需要依靠Server進行檔案暫存的動作,如此一來導入P2P架構並未完全減輕Server的負擔。本研究中,將P2P即時通訊系統導入檔案傳輸的動作,利用所有Peers的資源分享概念,讓檔案傳輸的動作不限定在傳送端與接收端同時在線的情況下才得以進行。本系統利用JXTA進行開發的動作,在即時通訊系統的檔案傳輸架構上導入P2P機制,利用所有的Peers進行檔案片段暫存與備份的動作,以確保檔案傳輸成功率。

[ 英文摘要 ]
With the development of Internet, communication between people from the pipeline linking the old correspondence, phone ... and so on, slowly shift to the Internet world, and the most commonly used communications software for E - mail, instant messaging software ... and so on. These techniques mainly based Client-Server architecture, in other words when the Server failure or damage, will result in the interruption of communication or unable to used, so the use of P2P architecture to replace the Client-Server architecture is also becoming increasingly common. However, file transfer, the instant messaging system or client can only send and receive on-line client for file transfer status to the action, in the case of any aspect of off-line or need to rely on temporary files Server moves This P2P framework Import Server does not fully alleviate the burden. This study, instant messaging P2P file transfer system into action, using all the Peers of the concept of resource sharing, file transfer so that the action is not limited to sending and receiving end at the same time online client circumstances to proceed. The system uses JXTA development action, in the instant messaging system, file transfer P2P mechanisms into the structure, use of all segments of the Peers to temporary and backup files of the action, to ensure that the success rate of file transfer.

97級-蘇文輝-基於新的金鑰管理建構P2P Botnet

97級-蘇文輝-基於新的金鑰管理建構P2P Botnet

[ 摘要 ]
近年來網路惡意攻擊駭客已經逐漸發展成組織化,形成一股趨利主義的勢力。發送大量垃圾信件、利用阻斷服務攻擊(denial-of-service, DoS)來勒索和點擊詐欺(click fraud)等等相關新聞事件都是未來趨勢的警告訊息。傀儡網路(Botnet)在這些惡意攻擊中,是份量極為重大的角色之一,許多攻擊者都利用傀儡網路來發動這些惡意攻擊以賺取利益。
目前以傀儡網路為主的攻擊變的流行和危險,因此有許多研究會致力於如何偵測、監控和防禦傀儡網路(Botnet)。目前大部分的研究是致力於C&C Botnet的研究,是最早出現、研究的傀儡網路,以Internet Relay Chat(IRC) 網路即時聊天系統為主的傀儡網路,而引導這些研究的成果來應付目前我們面對的威脅是必要的。然而還有許多更進階的傀儡網路會被攻擊者發展出來,我們必需提前去設法瞭解才能知己知彼,例如P2P傀儡網路相較於IRC傀儡網路,因為不存在集中的控制點,因此在對P2P傀儡網路的反制會更困難,因此要防禦要先瞭解攻擊,所以我們想要設法先了解,否則,我們未來在下一代的惡意攻擊仍處於被動的情況。
除了P2P惡意程式的惡意攻擊,也有學者提出以P2P良性Botnet來對抗惡意Botnet的分散式阻斷服務攻擊(Distributed Denial of Service,DDoS),因此良性Botnet的發展也是抵制目前網路上龐大的惡意程式攻擊的方法之一,因此我們導入的新型金鑰管理在P2P Botnet在良性Botnet的領域上是否有幫助,在未來也值得探討。

[ 英文摘要 ]
In the recently many years, Internet malware attack have become better organized and more profitable. Email spam, extortion by denial-of-attack, and click fraud represent something of this emerging trend. “Botnet” is the main cause of these problems, many attackers use it to do these malware attacks.
Because botnet-based attacks become popular and dangerous, security researchers have studied how to detect, monitor and defend against them. Most of the present research has focused on the C&C Botnets that have first occurred in the past, especially the Internet Relay Chat (IRC) based Botnet. It’s necessary to conduct such research so as to deal with the threat we are facing today. However, it’s important to research on the advanced Botnet that be designed by the attacker in the near future – P2P Botnet for example. Otherwise, we will remain susceptible to the future internet malware attacks.
In addition to the malicious attacks of the P2P malware, some academics have suggested to P2P friendly Botnet against distributed denial of service attacks (Distributed Denial of Service, DDoS) of the malicious Botnet. Therefore the development of friendly Botnet is one of the ways to resist the current network of malicious programs attack. We import a new key management in the field of benign Botnet to research into whether it is worth exploring in the future.

91級-位置導向之室內服務探索系統

潘志勝-位置導向之室內服務探索系統

[ 摘要 ]
網路環境越來越複雜且龐大的,在這樣的背景下,我們應該思考如何結合適當的資訊科技來開發新的資訊應用,學術研究與業界報告提出了許多新觀念、架構、甚至是實作,其中運用位置資訊來開發資訊應用系統最引人注目,本研究整合位置服務、行動定位技術、服務探索技術這三種技術,來達到繫結真實世界與網路虛擬世界、位置導向的網路服務、適用於室內環境三個目的,我們設計與實作一系統平台,並建立一情境模擬來測試系統,我們期望本系統成為開發室內位置導向相關服務的基礎平台。
[ 英文摘要 ]
The network environment is becoming more and more complicated. Based on this circumstance, we need to find out how to combine appropriate information technologies to develop new information applications. The academic research and business report has been proposed many new ideas, frameworks, more over in actual works, especially in applying location information to develop information application system has grab most attention. This research integrate location service with mobile positioning technology and service discovery technology to achieve the connection of real world and virtual network, location-oriented network services, and the suitable for indoor environment. In the research, we design and develop a system framework, and build up situation simulation to test the system. We expected this system can become the foundation framework of indoor location-oriented service system.

92級碩士論文- 符合SCORM機制的教材元件之實作研究

梁文俊- 符合SCORM機制的教材元件之實作研究

[ 摘要 ]
隨著科技進步,人們的知識的需求正快速成長及多變,教學也跟隨著產生變化,而E-Learning能突破時間和地點教學的特性,是E-Learning逐漸普及的主因。然而在各個組織、學校實施E-Learning之後,卻發現由於不同的單位,所使用的資訊教學平台和編製的教材格式不盡相同,造成教材與教學系統不盡相容,教材資源無法共享,因此SCORM規範便因應產生,希望透過SCORM規範讓E-Learning的學習資源,能再使用(reusable)、可共享(sharable)且可跨平台相互溝通使用(interoperable)。
本研究參照SCORM規範,實作一SCORM教材元件的編寫工具,並探討在網站上搜尋SCORM元件,希望透過研究,可以提供使用者較簡單製作SCORM教材的方法。
[ 英文摘要 ]
With the dramatic advance of technology, the human’s require for knowledge has been constantly growing and varying; consequently, the way of disseminating knowledge has also changed. At the very revolution time, E-Learning conquers the limits of time and location in traditional teaching, which mainly accounts for its increasing popularity. However, in popularizing E-Learning in any given organizations or schools, it is often found that, due to the differences of formats of teaching materials and of the employed information teaching platform, the teaching materials can not be fully compatible with the teaching platforms and, as a result, the teaching resources can not be shared widely. Under such circumstance, the formulation of SCORM is expected to solve this problem. It is hoped that through the formulation of SCORM, the learning resources in E-Learning can be reusable, sharable, and interoperable in different teaching platforms.
The research, under the basis of the formulation of SCORM, is aimed to work out a practical compiling tools of the SCORM elements and to discuss how to find out such SCORM elements on any given Websites. Hopefully, the research can offer the users simpler methods to make the teaching materials of SCORM.

92級碩士論文- 以GSM為基礎之室外自動定位之研究

卓忠志-以GSM為基礎之室外自動定位之研究

[ 摘要 ]
近年來由於行動通訊的快速成長,各種與行動通訊有關的應用不斷增加,尤其是定位的服務。這種定位技術多是透過基地台與後端的網路設備傳送位置資訊,再以各種定位法來定出使用者端的正確位置。這類技術的缺點在於定位的資料流佔用了有限的頻寬,使原本頻寬就不足的網路更加吃緊,換句話說,設備正常服務與定位服務彼此間造成排擠,定位服務的普及與利用率便大打折扣,由此看來,一個定位技術應該是獨立運作於使用者端,定位資訊不必藉由網路傳輸,如此才不會佔用原本正常服務的頻寬,也不必更動原有系統架構。
本篇論文實作一種架構在使用者端的自我定位系統,以GSM提供的TA(time advance)值來達成定位的需求。完全不需依賴第三者(系統服務業者)的以GSM為基礎的室外定位系統,不須更改GSM 系統的整體架構、不需向系統服務業者繳交費用,又可以達到定位要求。
[ 英文摘要 ]
Due to the availability of the cellular phone, the use of Mobil Communication Services has quickly grown beyond what anyone had imagined,especially on location services. Our main proposal in this paper is implement a wireless position location through a single cellular phone. This system has the following two features: First, it does not require any modification to the current GSM (Global System for Mobile Communication) architecture, that is, it does not increase network traffic. Second, the location identifications is performed on the mobile end, which does not increase computation load of the network system.
The intention of this paper is to introduce innovation uses single cellular phone to implement ALI (Automatic Location Identification) system. The whole issue determining the TA (Timing Advance) between the MS (Mobile Station) and the BTS (Base Transference Station) as well as coupling the calculated distance with the determined direction of the BTS signal so as to calculate the location of the MS.

92級碩士論文- 網路犯罪蒐證工具研究與設計

王一帆-網路犯罪蒐證工具研究與設計

[ 摘要 ]
近年來電腦網路的普及使得生活更加的便利,但同時也引發不少問題。使用網路造成他人或組織名譽財產上的損失已成為社會的棘手問題。檢調人員或是企業資訊系統管理者,需要一套有系統的方法來檢查及取得這些裝置或設備內儲存的資訊,用來提供偵查的資訊以幫助司法機關的調查,作為法庭上呈堂、判決與起訴參考依據之數位證據。本研究參考國內外文獻與軟體工具,建立了一個網路電腦入侵蒐證軟體以供警務機關辦案時之輔助,期能對企業的系統管理者以及檢調人員在進行電腦蒐證時能有所參考與助益。
[ 英文摘要 ]
In recent years, internet has available to all, but it brings many problems. Information system administrator, policeman and court prosecutor all need some systematized method to investigate or retrieve the information that used to support investigator, and these evidences would be accepted on court. This research constructs a computer intrusion investigation system, to hope to assist the information system administrator, policeman or court prosecutor in forensics.

92級碩士論文- 行動裝置上即時影像傳輸系統

郭楷彬- 行動裝置上即時影像傳輸系統

[ 摘要 ]
無線網路和有線網路存在著許多不同的差異性,其中 (1) 較小的頻寬 (2)不穩定的傳輸媒介 (3) 硬體設備的限制,使得無線網路上的即時多媒體影音傳輸並不是那麼容易實現。目前行動通訊網路的發展,無線網路的頻寬已經足夠讓多媒體資料在上傳輸了,如 802.11b 提供了11Mbps 的傳輸速率,以直接序列展頻(DSSS)技術,操作在2.4GHz頻帶上。而在手持或行動設備,如Pocket PC、PDA、Notebook等等,搭配了無線通訊模組後,也可以透過網際網路讓訊息流通,因此傳輸的資料型態已經不在只侷限於文字,各種的多媒體數據資料亦可進行傳輸,因此本研究利用了這樣的特性來開發行動裝置上的即時影像傳輸服務,希望藉由即時傳輸的特性,來解決更多我們在使用行動裝置上的瓶頸。
[ 英文摘要 ]
There are a lot of different differences between wireless network and wired network, among them (1)Smaller wide (2 ) unstable transmission media frequently (3)The restriction of the hardware equipment, it is not so easy to realize to transmit that the instant multimedia that makes on the wireless network is audio-visual. It is neither at present for action development, communication of network nor the getting wide and getting more enough to let by multimedia materials more already frequently in network not wireless in on transmit, if 802.11b offers the transfer rate of 11Mbps, the technology with the direct array exhibition frequently (DSSS ), operates and takes frequently in 2.4GHz. And is holding action equipment, for instance Pocket PC , PDA , Notebook ,etc., after matching. the wireless communication mould group, can let information flow by network through internet too, so materials type that transmit attitude confine characters to only already, various kinds of multimedia data materials can also be transmitted , so this researh has made use of such a characteristic to develop the instant image on the action device to transmit and serve, hope to solve more our bottlenecks in using the action device with the characteristic transmitted immediately