98級-張宏昌-結合重覆捕取法及迴歸分析之惡意域名受害族群估計
[ 摘要 ]
惡意域名是目前網路世界所面臨的極大威脅,其技術可以讓攻擊者隱藏在一群代理伺服器(Agent)後面,這樣的隱匿方法可以讓攻擊者躲避偵測使資訊安全人員偵測失敗,Fast-Flux Service Network(FFSN)這項技術對犯罪份子經營的惡意網站可以受到保護,進而延長惡意網站的壽命。FFSN的危害日益嚴重,要估計FFSN-Agent規模也相當不容易,且Flux-Agent本身可能是Bot節點,對於FFSN的規模估計也可以知道其威脅程度。本研究的核心為規模估計動態惡意域名服務網路(Fast-Flux Service Network,FFSN)的族群規模大小,藉由重覆捕取法(Capture-Recapture Method,CRM)中的聯合超幾何最大似然估計法(Joint hypergeometric maximum likelihood estimator,JHE)來估計Flux-Agent的群體大小,以其JHE最小估計基數再加以線性迴歸預測分析,產生最小估計基數前之線性迴歸模型,形成兩階段預測分析,其結果發現比普查的方式可以更快速找出整個族群大小。
[ 英文摘要 ]
Fast-flux service networks (FFSNs) are currently the greatest threat encountered in the computer networking field. This technique hides attackers behind a network of proxy servers (agents), thereby avoiding detection by security personnel. FFSN benefits criminal parties because it protects their Web sites and extends Web site life span. FFSN is becoming more dangerous, and estimating the size of FFSN-agents is becoming increasingly difficult. Additionally, because flux-agents may represent bot nodes, we can estimate the scale of FFSNs to determine the extent of threats. This study primarily estimates the population size of FFSNs. The flux-agent population size was estimated using the joint hypergeometric maximum likelihood estimator (JHE) of capture-recapture methods (CRMs), and using the linear regression analysis to make a prediction of the initial data. The results showed that the JHE and CRM estimated the population size more rapidly compared to general survey approaches.
100級-林玉燕-基於重複補取法之動態惡意域名服務網路規模估計
100級-林玉燕-基於重複補取法之動態惡意域名服務網路規模估計
[ 摘要 ]
本研究的核心為規模估計動態惡意域名服務網路(Fast-Flux Service Network)的族群規模大小,FFSN是目前網路世界所面臨的極大威脅,其技術可以讓攻擊者隱藏在一群代理伺服器(agent)後面,這樣的方式可以讓攻擊者來躲避偵測使資訊安全人員偵測失敗,FFSN這項技術對犯罪份子的好處是惡意網站可以受到保護,進而延長惡意網站的壽命。所以FFSN的危害日益嚴重,要規模估計FFSN-Agent也相當不容易,且Flux-Agent本身可能是Bot節點,估計FFSN的規模也可以知道其威脅程度。所以本研究藉由重複捕取法(Capture-Recapture Method,CRM)估計Flux-Agent的群體大小,其計算方式是透過Program NOREMARK 的Joint hypergeometric maximum likelihood estimator (JHE)估計族群量,實驗結果只需要前六天所Query的樣本數便可以估計出整個FFSN的族群大小,其實驗結果比普查的方式可以更快速找出整個族群大小。
[ 英文摘要 ]
The purpose of this study is to estimate the group size of Fast-Flux Service Network (FFSN.) FFSN is one of the enormous threats of internet. It can hide the attackers behind a group of agents and by this way the attackers can avoid being detected. The benefit of FFSN to attackers is the malicious websites can be protected and the survival time can be prolonged. The danger of FFSN is getting more serious and Flux-Agent could be a Bot note. To estimate the size of FFSN can find the danger degree but to estimate the size is not easy. Hence, this study uses Capture-Recapture Method (CRM) to estimate the group size of Flux-Agent. By computing the joint hypergeometric maximum likelihood estimator (JHE) of Program NOREMARK, the group size can be found. The experiment needs just the query samples among six days before and the group size of FFSN can be found. The experiment result can more quickly find the group size than census can.
[ 摘要 ]
本研究的核心為規模估計動態惡意域名服務網路(Fast-Flux Service Network)的族群規模大小,FFSN是目前網路世界所面臨的極大威脅,其技術可以讓攻擊者隱藏在一群代理伺服器(agent)後面,這樣的方式可以讓攻擊者來躲避偵測使資訊安全人員偵測失敗,FFSN這項技術對犯罪份子的好處是惡意網站可以受到保護,進而延長惡意網站的壽命。所以FFSN的危害日益嚴重,要規模估計FFSN-Agent也相當不容易,且Flux-Agent本身可能是Bot節點,估計FFSN的規模也可以知道其威脅程度。所以本研究藉由重複捕取法(Capture-Recapture Method,CRM)估計Flux-Agent的群體大小,其計算方式是透過Program NOREMARK 的Joint hypergeometric maximum likelihood estimator (JHE)估計族群量,實驗結果只需要前六天所Query的樣本數便可以估計出整個FFSN的族群大小,其實驗結果比普查的方式可以更快速找出整個族群大小。
[ 英文摘要 ]
The purpose of this study is to estimate the group size of Fast-Flux Service Network (FFSN.) FFSN is one of the enormous threats of internet. It can hide the attackers behind a group of agents and by this way the attackers can avoid being detected. The benefit of FFSN to attackers is the malicious websites can be protected and the survival time can be prolonged. The danger of FFSN is getting more serious and Flux-Agent could be a Bot note. To estimate the size of FFSN can find the danger degree but to estimate the size is not easy. Hence, this study uses Capture-Recapture Method (CRM) to estimate the group size of Flux-Agent. By computing the joint hypergeometric maximum likelihood estimator (JHE) of Program NOREMARK, the group size can be found. The experiment needs just the query samples among six days before and the group size of FFSN can be found. The experiment result can more quickly find the group size than census can.
100級-蔡佩旻-自動化部署與運用虛擬化蜜網系統
100級-蔡佩旻-自動化部署與運用虛擬化蜜網系統
[ 摘要 ]
由於網際網路的普及化越來越高,以及社群網站的盛行,已讓網際網路安全成為一大重要課題。尤其在學術網路的使用上,對於網路與電腦的管理都採取較寬鬆的方式處理,使的學術網路成為大部分犯罪者攻擊的目標。當犯罪者成功入侵電腦之後往往使用諸多的惡意軟體工具來從事許多的非法活動,像是木馬、垃圾郵件、分散式阻斷服務攻擊、釣魚網站與病毒散播等威脅。Honeynet屬於一種dummy的網路架構,藉著所提供諸多網路服務來吸引犯罪者入侵,並可部署在許多的區域當作一種防禦策略。
本研究利用honeynet的特性,提供使用者可以快速的偵測與確認malicious source,但由於honeynety在部署與實作上本身就存在諸多的困難度,所以本研究提出一個新的自動化系統,讓管理者可以藉此將系統快速的部署在學術網路上加以運用。
[ 英文摘要 ]
Because the popularization of the Internet is increasingly high, and the prevalence of social networking , which have allowed Internet security has become an important issue. Campus Network has become the target of attacks by the majority of offenders, to adopt a more lenient approach to the management of network and computer. After the successful invasion of the computer, the offender spreads a lot of malicious software tools to engage in illegal activities, such as Trojans, spam, distributed denial of service attacks, phishing sites, and other threats. The Honeynet belong to a dummy network infrastructure, to attract a lot of network services through the provision of the criminal invasion and can be deployed in many areas as a defense strategy。
In this thesis we can quickly detect and confirm the malicious source through characteristic of honeypot. Users would be a lot difficulty to deploy and implement the honeynet. In this thesis we present the new automatic system that allows managers to rapid deployment of the virtual honeynet system in the Campus Network.
[ 摘要 ]
由於網際網路的普及化越來越高,以及社群網站的盛行,已讓網際網路安全成為一大重要課題。尤其在學術網路的使用上,對於網路與電腦的管理都採取較寬鬆的方式處理,使的學術網路成為大部分犯罪者攻擊的目標。當犯罪者成功入侵電腦之後往往使用諸多的惡意軟體工具來從事許多的非法活動,像是木馬、垃圾郵件、分散式阻斷服務攻擊、釣魚網站與病毒散播等威脅。Honeynet屬於一種dummy的網路架構,藉著所提供諸多網路服務來吸引犯罪者入侵,並可部署在許多的區域當作一種防禦策略。
本研究利用honeynet的特性,提供使用者可以快速的偵測與確認malicious source,但由於honeynety在部署與實作上本身就存在諸多的困難度,所以本研究提出一個新的自動化系統,讓管理者可以藉此將系統快速的部署在學術網路上加以運用。
[ 英文摘要 ]
Because the popularization of the Internet is increasingly high, and the prevalence of social networking , which have allowed Internet security has become an important issue. Campus Network has become the target of attacks by the majority of offenders, to adopt a more lenient approach to the management of network and computer. After the successful invasion of the computer, the offender spreads a lot of malicious software tools to engage in illegal activities, such as Trojans, spam, distributed denial of service attacks, phishing sites, and other threats. The Honeynet belong to a dummy network infrastructure, to attract a lot of network services through the provision of the criminal invasion and can be deployed in many areas as a defense strategy。
In this thesis we can quickly detect and confirm the malicious source through characteristic of honeypot. Users would be a lot difficulty to deploy and implement the honeynet. In this thesis we present the new automatic system that allows managers to rapid deployment of the virtual honeynet system in the Campus Network.
100級-黃宗恩-以網域名稱服務之郵件交換紀錄為基礎偵測動態惡意域名服務網路
100級-黃宗恩-以網域名稱服務之郵件交換紀錄為基礎偵測動態惡意域名服務網路
[ 摘要 ]
近年來隨著科技與網際網路的進步,人們的日常生活及商業活動變得越來越依賴網路,因此使許多駭客開始藉由種種不當的入侵與攻擊手法企圖謀取龐大的非法利益;例如「動態惡意域名服務網路(Fast-Flux Service Networks)」便是一項近年來廣被許多駭客使用的新興的攻擊方式,此入侵手法藉由導入DNS之輪替式網域名稱服務(Round Robin DNS, RR-DNS) 技術,透過不斷變換其所對應到的實體機器之網域,來保護具備惡意用途的內容網站,其中被對應的實體機器常為受害的電腦主機,導致此攻擊所造成之危害日益漸增。因此,本研究利用FFSN特徵偵測技術搭配其既有之特徵值為偵測基準來實作一偵測系統,並針對ATLAS及ALEXA所獲取之資料進行測試,以利後續驗證本研究所建置之偵測系統之偵測率及正確率,並分析特徵搭配後的偵測效益,進而從中挑選出最佳方案作為日後之偵測基準。
[ 英文摘要 ]
During recent decades, the explosive development of the Internet brings a remarkable advance in information exchange. Hence, people’s daily life and commercial activities rely on the Internet much tremendously. More and more hackers try to gain enormous illegal profits by such illegitimate invasion and attack approaches. For instance, Fast-Flux Service Networks is one of emerging attack technologies, which is used to invade the system through combining the RR-DNS technology (Round Robin DNS) of DNS. Fast-Flux can protect malicious websites by keeping changing the IP address of the Mothership. In most cases, naïve users’ computers are usually the attack targets so the damage is getting worse with each passing day. Therefore, this study uses FFSN characterization and original features as detection patterns to construct a detection system. The data from ATLAS and ALEXA are tested to evaluate the detection rate and accuracy of the proposed system. Finally, through the analysis of the detection effectiveness after features mapping, the best solution can be found as the future detection pattern.
[ 摘要 ]
近年來隨著科技與網際網路的進步,人們的日常生活及商業活動變得越來越依賴網路,因此使許多駭客開始藉由種種不當的入侵與攻擊手法企圖謀取龐大的非法利益;例如「動態惡意域名服務網路(Fast-Flux Service Networks)」便是一項近年來廣被許多駭客使用的新興的攻擊方式,此入侵手法藉由導入DNS之輪替式網域名稱服務(Round Robin DNS, RR-DNS) 技術,透過不斷變換其所對應到的實體機器之網域,來保護具備惡意用途的內容網站,其中被對應的實體機器常為受害的電腦主機,導致此攻擊所造成之危害日益漸增。因此,本研究利用FFSN特徵偵測技術搭配其既有之特徵值為偵測基準來實作一偵測系統,並針對ATLAS及ALEXA所獲取之資料進行測試,以利後續驗證本研究所建置之偵測系統之偵測率及正確率,並分析特徵搭配後的偵測效益,進而從中挑選出最佳方案作為日後之偵測基準。
[ 英文摘要 ]
During recent decades, the explosive development of the Internet brings a remarkable advance in information exchange. Hence, people’s daily life and commercial activities rely on the Internet much tremendously. More and more hackers try to gain enormous illegal profits by such illegitimate invasion and attack approaches. For instance, Fast-Flux Service Networks is one of emerging attack technologies, which is used to invade the system through combining the RR-DNS technology (Round Robin DNS) of DNS. Fast-Flux can protect malicious websites by keeping changing the IP address of the Mothership. In most cases, naïve users’ computers are usually the attack targets so the damage is getting worse with each passing day. Therefore, this study uses FFSN characterization and original features as detection patterns to construct a detection system. The data from ATLAS and ALEXA are tested to evaluate the detection rate and accuracy of the proposed system. Finally, through the analysis of the detection effectiveness after features mapping, the best solution can be found as the future detection pattern.
100級-林添財-社交網站惡意程式分析:以Koobface為例
100級-林添財-社交網站惡意程式分析:以Koobface為例
[ 摘要 ]
社交網路服務(Social Networking Service,SNS)目前成已為網路上最受歡迎的活動,舉凡聊天、寄信、影音、分享檔案等,讓相同興趣的人建立線上的社群,透過網際網路提供使用者各種聯繫與交流的功能來鞏固的彼此的關係。隨著社交網路服務被廣泛的使用,駭客利用惡意連結、社交工程、網路釣魚等攻擊的方式,使社交網路成為散佈惡意程式的跳板工具。
本研究以社交網站中的惡意程式koobface為主題,討論其散佈、感染的方式、對外網路的行為,研究結果最終證實都具有惡意的性質,探究其原因駭客就是利用社交網路中對人的信任或是好奇的心理,藉由這樣的誘因、手段,以達到預先想要的目的。
[ 英文摘要 ]
Social networking service (Social Networking Service, SNS), as currently the most popular activities on the network covered the chat, e-mail, video, file sharing, etc., so that the same people interested in the establishment of online community through the Internet provide users with a variety of contacts and exchanges to consolidate the mutual relationship. The malicious link with the social networking service is widely used, hackers, social engineering, phishing and other mode of attack, so that the social network to become a springboard for spreading malware tools.
In this study, the malware koobface social networking sites as the theme, to discuss its spread infection, the behavior of the external network, the results eventually confirmed to have a malicious nature, explore the reason hackers use social networks in the human the trust or the curious psychology, by this incentive, means, in order to achieve the desired purpose in advance.
[ 摘要 ]
社交網路服務(Social Networking Service,SNS)目前成已為網路上最受歡迎的活動,舉凡聊天、寄信、影音、分享檔案等,讓相同興趣的人建立線上的社群,透過網際網路提供使用者各種聯繫與交流的功能來鞏固的彼此的關係。隨著社交網路服務被廣泛的使用,駭客利用惡意連結、社交工程、網路釣魚等攻擊的方式,使社交網路成為散佈惡意程式的跳板工具。
本研究以社交網站中的惡意程式koobface為主題,討論其散佈、感染的方式、對外網路的行為,研究結果最終證實都具有惡意的性質,探究其原因駭客就是利用社交網路中對人的信任或是好奇的心理,藉由這樣的誘因、手段,以達到預先想要的目的。
[ 英文摘要 ]
Social networking service (Social Networking Service, SNS), as currently the most popular activities on the network covered the chat, e-mail, video, file sharing, etc., so that the same people interested in the establishment of online community through the Internet provide users with a variety of contacts and exchanges to consolidate the mutual relationship. The malicious link with the social networking service is widely used, hackers, social engineering, phishing and other mode of attack, so that the social network to become a springboard for spreading malware tools.
In this study, the malware koobface social networking sites as the theme, to discuss its spread infection, the behavior of the external network, the results eventually confirmed to have a malicious nature, explore the reason hackers use social networks in the human the trust or the curious psychology, by this incentive, means, in order to achieve the desired purpose in advance.
100級-吳沅錄-以連接埠掃描為基礎偵測動態惡意域名服務網路
100級-吳沅錄-以連接埠掃描為基礎偵測動態惡意域名服務網路
[ 摘要 ]
動態惡意域名服務網路Fast-Flux Service Networks (FFSN)源自於一種稱為輪替式網域名稱服務Round-Robin DNS (RR-DNS)的技術。它是一種透過將DNS記錄快速更換,使得網域名稱能夠被快速對應到數個不同的主機,以達到負載平衡的機制。Fast-Flux與RR-DNS相似,然而不同的是,Fast-Flux是將網域名稱快速對應到數個來自殭屍網路(Botnet)的受害電腦設備,並以保護惡意內容網站,如釣魚網站、惡意程式下載站及垃圾郵件內容網站為目的,使惡意攻擊時效得以延長。過去的研究著重於多次對特定網域進行DNS查詢,並找出多次查詢之間的相異之處,然而這樣的作法容易受到網路環境影響,且偵測時間較長。本研究透過掃描網域內的每個主機,並計算各個主機間的連接埠重複程度,藉此來判斷此網域為重複程度低的FFSN惡意網域或重複度高的正常網域,此外,本研究還搭配了過去研究所發現的另一項Fast-Flux之特徵,DNS query time之標準差,並以標準差高於門檻值者判定為FFSN惡意網域,而低於門檻值者則判定為正常網域,以此二特徵搭配作為Fast-Flux之偵測特徵,並得出相當高的精確率。本研究也針對了此二特徵進行偵測速度分析,並得出了使用連接埠重複程度作為FFSN之偵測特徵,不同於過去研究所發現到的特徵必須利用多次查詢,並在每一次查詢之中皆需等候TTL時間經過才能進行下一步驟的特點,它在平均約47秒內便可得出偵測結果,比過去偵測時間動輒約數百秒還快上許多,且在降低偵測時間的同時,亦能維持一定的精確率。
[ 英文摘要 ]
Fast-Flux Service Networks (FFSN) derives from Round-Robin DNS. RR-DNS is a method of choosing a resource for a task from a list of available resources, usually for the purposes of load balancing. FFSN is similar to RR-DNS, but there have some differentials that the list of available resources is come from the victim hosts, and those victim hosts are used to protect phishing sites, malicious sites and spam server by hackers. In the past, the research usually focused on “To DNS query a specific domain, and finding the difference between each results of DNS query”, the result of detection will easily be influenced by the network environment, and the time of detection may be increased. In this thesis, we use the nmap to scan host’s port in specific domain, to calculate the discrepancy between each hosts, and to determine the FFSN domain (high differentiate) and the benign domain (low differentiate), in addition, we use another FFSN feature “The standard deviation of DNS query time”, if the standard deviation are higher than threshold, then it is a FFSN domain, if it not, it is a benign domain. We combine this two FFSN feature, and then we get a high accuracy. We also analyze this two FFSN feature about their detection speed, we find that the feature “differentiate of each host’s port” is not the same with the past’s research, it do not need to wait for TTL time, it’s average of complete the detection is about 47 seconds, and the past’s research is more than 100 seconds. “Differentiate of each host’s port” is not only decreasing the time of detection, but also keep the accuracy higher.
[ 摘要 ]
動態惡意域名服務網路Fast-Flux Service Networks (FFSN)源自於一種稱為輪替式網域名稱服務Round-Robin DNS (RR-DNS)的技術。它是一種透過將DNS記錄快速更換,使得網域名稱能夠被快速對應到數個不同的主機,以達到負載平衡的機制。Fast-Flux與RR-DNS相似,然而不同的是,Fast-Flux是將網域名稱快速對應到數個來自殭屍網路(Botnet)的受害電腦設備,並以保護惡意內容網站,如釣魚網站、惡意程式下載站及垃圾郵件內容網站為目的,使惡意攻擊時效得以延長。過去的研究著重於多次對特定網域進行DNS查詢,並找出多次查詢之間的相異之處,然而這樣的作法容易受到網路環境影響,且偵測時間較長。本研究透過掃描網域內的每個主機,並計算各個主機間的連接埠重複程度,藉此來判斷此網域為重複程度低的FFSN惡意網域或重複度高的正常網域,此外,本研究還搭配了過去研究所發現的另一項Fast-Flux之特徵,DNS query time之標準差,並以標準差高於門檻值者判定為FFSN惡意網域,而低於門檻值者則判定為正常網域,以此二特徵搭配作為Fast-Flux之偵測特徵,並得出相當高的精確率。本研究也針對了此二特徵進行偵測速度分析,並得出了使用連接埠重複程度作為FFSN之偵測特徵,不同於過去研究所發現到的特徵必須利用多次查詢,並在每一次查詢之中皆需等候TTL時間經過才能進行下一步驟的特點,它在平均約47秒內便可得出偵測結果,比過去偵測時間動輒約數百秒還快上許多,且在降低偵測時間的同時,亦能維持一定的精確率。
[ 英文摘要 ]
Fast-Flux Service Networks (FFSN) derives from Round-Robin DNS. RR-DNS is a method of choosing a resource for a task from a list of available resources, usually for the purposes of load balancing. FFSN is similar to RR-DNS, but there have some differentials that the list of available resources is come from the victim hosts, and those victim hosts are used to protect phishing sites, malicious sites and spam server by hackers. In the past, the research usually focused on “To DNS query a specific domain, and finding the difference between each results of DNS query”, the result of detection will easily be influenced by the network environment, and the time of detection may be increased. In this thesis, we use the nmap to scan host’s port in specific domain, to calculate the discrepancy between each hosts, and to determine the FFSN domain (high differentiate) and the benign domain (low differentiate), in addition, we use another FFSN feature “The standard deviation of DNS query time”, if the standard deviation are higher than threshold, then it is a FFSN domain, if it not, it is a benign domain. We combine this two FFSN feature, and then we get a high accuracy. We also analyze this two FFSN feature about their detection speed, we find that the feature “differentiate of each host’s port” is not the same with the past’s research, it do not need to wait for TTL time, it’s average of complete the detection is about 47 seconds, and the past’s research is more than 100 seconds. “Differentiate of each host’s port” is not only decreasing the time of detection, but also keep the accuracy higher.
99級-楊昆鑫-以DNS Query Time 為基礎偵測Fast-Flux Service Networks(FFSN)
99級-楊昆鑫-以DNS Query Time 為基礎偵測Fast-Flux Service Networks(FFSN)
[ 摘要 ]
隨著網際網路被運用在商業的頻率越來越高,網路攻擊所造成的利益損害已經逐漸擴大。駭客運用著網際網路從事非法的活動,像是木馬、病毒散播、分散式阻斷服務攻擊、垃圾郵件與釣魚網站的威脅等,為了獲取龐大的利益,犯罪者對於非法活動的需求日漸成長,而為了讓這些詐欺行為具有高度的隱蔽性,犯罪者開始使用一種稱為Fast-Flux Service Networks的攻擊手法,FFSN是由一群被用來當作代理轉向服務的傀儡網路(botnet)所組成,利用這些受感染的傀儡主機便可以將使用者重新導向至犯罪者所架設的惡意內容。
本研究實作建置一系統,以本研究所探討之偵測特徵搭配既有特徵為偵測基準,針對Malware Domain List及ATLAS資料來源偵測FFSN惡意網域,探討當前網路犯罪中FFSN被犯罪者應用的實際情形、並分析偵測效益並挑選出最佳方案作為日後之偵測基準。
[ 英文摘要 ]
With the Internet being used more frequently in the business, network attack have caused damage to the interests gradually expanded. Hackers use the Internet for illegal activities, such as Trojan, viruses, DDoS attacks, spam and phishing, etc. In order to obtain huge benefits, the offender’s demand for illegal activities growth, and to make such fraud a high degree of concealment, the offender began to use the attack tactics called Fast-Flux Service Network (FFSN). FFSN is composed by who is used by a group of agents to service as a proxy of the botnet. Use these infected host can redirect the user to the malicious content that offender set.
In this thesis we implemented a system, we use the detection feature discuss in this thesis and the features that is already discussed in other study to detect whether the data which are from Malware Domain List and ATLAS are belong to FFSN or not. Also, we investigate the utilization of FFSN by miscreants on the Internet, and analyze the detection performance and select the best case as the baseline of detection in the future.
[ 摘要 ]
隨著網際網路被運用在商業的頻率越來越高,網路攻擊所造成的利益損害已經逐漸擴大。駭客運用著網際網路從事非法的活動,像是木馬、病毒散播、分散式阻斷服務攻擊、垃圾郵件與釣魚網站的威脅等,為了獲取龐大的利益,犯罪者對於非法活動的需求日漸成長,而為了讓這些詐欺行為具有高度的隱蔽性,犯罪者開始使用一種稱為Fast-Flux Service Networks的攻擊手法,FFSN是由一群被用來當作代理轉向服務的傀儡網路(botnet)所組成,利用這些受感染的傀儡主機便可以將使用者重新導向至犯罪者所架設的惡意內容。
本研究實作建置一系統,以本研究所探討之偵測特徵搭配既有特徵為偵測基準,針對Malware Domain List及ATLAS資料來源偵測FFSN惡意網域,探討當前網路犯罪中FFSN被犯罪者應用的實際情形、並分析偵測效益並挑選出最佳方案作為日後之偵測基準。
[ 英文摘要 ]
With the Internet being used more frequently in the business, network attack have caused damage to the interests gradually expanded. Hackers use the Internet for illegal activities, such as Trojan, viruses, DDoS attacks, spam and phishing, etc. In order to obtain huge benefits, the offender’s demand for illegal activities growth, and to make such fraud a high degree of concealment, the offender began to use the attack tactics called Fast-Flux Service Network (FFSN). FFSN is composed by who is used by a group of agents to service as a proxy of the botnet. Use these infected host can redirect the user to the malicious content that offender set.
In this thesis we implemented a system, we use the detection feature discuss in this thesis and the features that is already discussed in other study to detect whether the data which are from Malware Domain List and ATLAS are belong to FFSN or not. Also, we investigate the utilization of FFSN by miscreants on the Internet, and analyze the detection performance and select the best case as the baseline of detection in the future.
99級-林庭弘-以逆向工程偵測惡意代碼行為
99級-林庭弘-以逆向工程偵測惡意代碼行為
[ 摘要 ]
過去幾年來惡意程式的數量和破壞能力已成倍數成長,惡意程式開始使用代碼混淆技術、加密和加殼技術來躲避防毒軟體的特徵碼偵測。目前很多惡意作者都是使用加殼技術加密惡意程式,以躲避防毒軟體的檢測,所以惡意程式加殼已成為現今防毒公司最具挑戰性的問題。
如何去偵測惡意加殼程式,本研究提出使用Entropy和其他的輔助特徵來檢測加殼程式,並使用靜態特徵與動態特徵來偵測惡意加殼程式。實驗結果,本研究能即時偵測出代碼混淆技術、加殼和加殼技術,並能有效區分善意加殼程式和惡意加殼程式的差別。
[ 英文摘要 ]
In the past few years, the amount of the malicious program and the capability of destruction have become more and more. Malicious programs and their writers are also staring to use the packed technology of encryption and code obfuscation to avoid the detection from anti-virus software. Therefore, the packed technology has become a challenging problem to the anti-virus company.
How to detect the malicious packed program is also the important issue of researches of the information security. This study uses the encryption and the other assistant feature to help the detection to malicious packed program. Furthermore, there has use the combination of the static and dynamic feature to detect the malicious packed program. The result of this study shows that the packed technology of encryption and code obfuscation could be detected more efficiency and the different between the friendly packed program and the malicious packed program can also be identified more operative.
[ 摘要 ]
過去幾年來惡意程式的數量和破壞能力已成倍數成長,惡意程式開始使用代碼混淆技術、加密和加殼技術來躲避防毒軟體的特徵碼偵測。目前很多惡意作者都是使用加殼技術加密惡意程式,以躲避防毒軟體的檢測,所以惡意程式加殼已成為現今防毒公司最具挑戰性的問題。
如何去偵測惡意加殼程式,本研究提出使用Entropy和其他的輔助特徵來檢測加殼程式,並使用靜態特徵與動態特徵來偵測惡意加殼程式。實驗結果,本研究能即時偵測出代碼混淆技術、加殼和加殼技術,並能有效區分善意加殼程式和惡意加殼程式的差別。
[ 英文摘要 ]
In the past few years, the amount of the malicious program and the capability of destruction have become more and more. Malicious programs and their writers are also staring to use the packed technology of encryption and code obfuscation to avoid the detection from anti-virus software. Therefore, the packed technology has become a challenging problem to the anti-virus company.
How to detect the malicious packed program is also the important issue of researches of the information security. This study uses the encryption and the other assistant feature to help the detection to malicious packed program. Furthermore, there has use the combination of the static and dynamic feature to detect the malicious packed program. The result of this study shows that the packed technology of encryption and code obfuscation could be detected more efficiency and the different between the friendly packed program and the malicious packed program can also be identified more operative.
98級-莊竣程-偵測與分析Fast-Flux Service Network
98級-莊竣程-偵測與分析Fast-Flux Service Network
[ 摘要 ]
隨著網際網路的高度發展,網路安全已是我們所面臨最嚴重的問題之一。有一大群不法之徒運用著網際網路從事非法的活動,像是木馬、病毒散播、分散式阻斷服務攻擊、垃圾郵件與釣魚網站的威脅等,基於不法利益的考量,犯罪者對於他們的非法活動有高度的可用性需求,而為了混淆他們的詐欺活動,犯罪者們最近開始使用一種稱為Fast-Flux Service Networks的攻擊手法,FFSN是由一群被用來當作代理轉向服務的傀儡網路(botnet)所組成,同時利用這些受感染的傀儡主機來呈現犯罪者所架設的詐欺內容。
本研究實作建置一系統,針對Malware Domain List資料來源偵測FFSN惡意網域,探討當前網路犯罪中FFSN被犯罪者應用的實際情形、並分析被感染節點之分佈概況等。
[ 英文摘要 ]
As the highly development of Internet, one of the most serious threats we face is cyber-security. There are many groups of criminals using the Internet to engage in illegal activities like Trojan horse, viruses, DDoS attacks, spam emails and phishing. They motivated by illegal profit, have a high demand in availability of their illegal activities, and to confuse the location of their services. These criminals recently started to use a new technique called Fast-Flux Service Networks, composed of large groups of bots and acting as proxies to their scam contents.
In this thesis we implemented a system, detecting whether the data which are from Malware Domain List are belong to FFSN or not. Also, we investigate the utilization of FFSN by miscreants on the Internet, and analyzing the location details of the infected bots.
[ 摘要 ]
隨著網際網路的高度發展,網路安全已是我們所面臨最嚴重的問題之一。有一大群不法之徒運用著網際網路從事非法的活動,像是木馬、病毒散播、分散式阻斷服務攻擊、垃圾郵件與釣魚網站的威脅等,基於不法利益的考量,犯罪者對於他們的非法活動有高度的可用性需求,而為了混淆他們的詐欺活動,犯罪者們最近開始使用一種稱為Fast-Flux Service Networks的攻擊手法,FFSN是由一群被用來當作代理轉向服務的傀儡網路(botnet)所組成,同時利用這些受感染的傀儡主機來呈現犯罪者所架設的詐欺內容。
本研究實作建置一系統,針對Malware Domain List資料來源偵測FFSN惡意網域,探討當前網路犯罪中FFSN被犯罪者應用的實際情形、並分析被感染節點之分佈概況等。
[ 英文摘要 ]
As the highly development of Internet, one of the most serious threats we face is cyber-security. There are many groups of criminals using the Internet to engage in illegal activities like Trojan horse, viruses, DDoS attacks, spam emails and phishing. They motivated by illegal profit, have a high demand in availability of their illegal activities, and to confuse the location of their services. These criminals recently started to use a new technique called Fast-Flux Service Networks, composed of large groups of bots and acting as proxies to their scam contents.
In this thesis we implemented a system, detecting whether the data which are from Malware Domain List are belong to FFSN or not. Also, we investigate the utilization of FFSN by miscreants on the Internet, and analyzing the location details of the infected bots.
98級-廖紋淇-P2P Botnet之規模估計
98級-廖紋淇-P2P Botnet之規模估計
[ 摘要 ]
年來傀儡網路已成為網際網路安全的威脅,攻擊者能控制大量的電腦,以發動各種不同的攻擊,如DDoS攻擊、濫發垃圾郵件、竊取個資等。
Botnet的規模大小是評估其威脅的關鍵指標,愈大的Botnet其所帶來的威脅也愈大。
如何去估計Botnet的規模,也成為資安研究的一個重要議題。本研究提出一個利用P2P Botnet中,每個節點都會持有Botnet中部分成員的節點資訊之特性,以重複捕取法取樣估計的模式來估計P2P Botnet的規模。
[ 英文摘要 ]
In recent years, Botnets have become major security threats in Internet, since the attacker can control a large number of bots. Attackers primarily use them for DDoS attacks, e-mail spamming, or massive personal information theft.
The size of a Botnet is a key index to estimate the threat of a botnet. The larger size of a Botnet, the more devastating these attacks can be. To estimate the size of a botnet becomes an important issue in Internet security. In P2P Botnet, every bot peer holds information about some other bot peers. In this study, we utilize this characteristic and capture-recapture technique to estimate the size of a P2P botnet.
[ 摘要 ]
年來傀儡網路已成為網際網路安全的威脅,攻擊者能控制大量的電腦,以發動各種不同的攻擊,如DDoS攻擊、濫發垃圾郵件、竊取個資等。
Botnet的規模大小是評估其威脅的關鍵指標,愈大的Botnet其所帶來的威脅也愈大。
如何去估計Botnet的規模,也成為資安研究的一個重要議題。本研究提出一個利用P2P Botnet中,每個節點都會持有Botnet中部分成員的節點資訊之特性,以重複捕取法取樣估計的模式來估計P2P Botnet的規模。
[ 英文摘要 ]
In recent years, Botnets have become major security threats in Internet, since the attacker can control a large number of bots. Attackers primarily use them for DDoS attacks, e-mail spamming, or massive personal information theft.
The size of a Botnet is a key index to estimate the threat of a botnet. The larger size of a Botnet, the more devastating these attacks can be. To estimate the size of a botnet becomes an important issue in Internet security. In P2P Botnet, every bot peer holds information about some other bot peers. In this study, we utilize this characteristic and capture-recapture technique to estimate the size of a P2P botnet.
98級-郭權緯-建構P2P防火牆之HTTP-Botnet防禦機制
98級-郭權緯-建構P2P防火牆之HTTP-Botnet防禦機制
[ 摘要 ]
這幾年來, Botnet有增加的趨勢,如果沒有相對的解決辦法,未來必會有越來越嚴重的惡意攻擊情況發生。HTTP Botnet使用的是HTTP協定,利用一般HTTP 協定的80 port,達到隱藏的效果,可以順利通過防火牆跟IDS系統。
本研究採用重複標準差的方法偵測出HTTP Bot的連線,再使用JXTA P2P的網路分享偵測出結果,使用者利用名單過濾機制,進行封包的比對。
利用P2P交換資訊,已感染HTTP Bot的使用者,可以找出與HTTP Server與Bot的連線,而未感染的使用者,可以使用這些資訊,當作是比對的樣本,當有新的封包進來,可以判斷是否為惡意的連線,達到聯合防禦的目的。名單的過濾機制可以讓重複進到電腦的封包,只做第一次與黑名單的比對。使用P2P傳送,減少了建置成本,也讓整個網路變得更強韌。
[ 英文摘要 ]
The scale of Botnet is still increasing on the Internet in recently years. If there is no corresponding solution, there will be more serious and malicious attacks in the future. HTTP Botnet uses HTTP protocol. By using the general HTTP protocol and 80 port, the attacks not only can be hidden more easily, but go through the firewall and IDS systems without detected.
In this study, we use the Repeatability Standard Deviation method to detect the connection of Botnets within HTTP protocol. Furthermore, we use the JXTA P2P network to share the results we have detected, and users can compare the packets of traffic with lists of the filtering mechanism.
Using P2P technique to exchange the information we have detected, users who have been infected can find the connection of HTTP Botnet servers. And uninfected users can use this information as a comparison sample, when there are new packets. Users can use it for determining whether the connections are malicious or not, to achieve the purpose of co-defensive. Lists of filtering mechanism allow the duplicated packets entered in computers, compared only one time with the large number of blacklist. By using the P2P technique, we can not only decrease the cost of implementation, but also let the network more resilient.
[ 摘要 ]
這幾年來, Botnet有增加的趨勢,如果沒有相對的解決辦法,未來必會有越來越嚴重的惡意攻擊情況發生。HTTP Botnet使用的是HTTP協定,利用一般HTTP 協定的80 port,達到隱藏的效果,可以順利通過防火牆跟IDS系統。
本研究採用重複標準差的方法偵測出HTTP Bot的連線,再使用JXTA P2P的網路分享偵測出結果,使用者利用名單過濾機制,進行封包的比對。
利用P2P交換資訊,已感染HTTP Bot的使用者,可以找出與HTTP Server與Bot的連線,而未感染的使用者,可以使用這些資訊,當作是比對的樣本,當有新的封包進來,可以判斷是否為惡意的連線,達到聯合防禦的目的。名單的過濾機制可以讓重複進到電腦的封包,只做第一次與黑名單的比對。使用P2P傳送,減少了建置成本,也讓整個網路變得更強韌。
[ 英文摘要 ]
The scale of Botnet is still increasing on the Internet in recently years. If there is no corresponding solution, there will be more serious and malicious attacks in the future. HTTP Botnet uses HTTP protocol. By using the general HTTP protocol and 80 port, the attacks not only can be hidden more easily, but go through the firewall and IDS systems without detected.
In this study, we use the Repeatability Standard Deviation method to detect the connection of Botnets within HTTP protocol. Furthermore, we use the JXTA P2P network to share the results we have detected, and users can compare the packets of traffic with lists of the filtering mechanism.
Using P2P technique to exchange the information we have detected, users who have been infected can find the connection of HTTP Botnet servers. And uninfected users can use this information as a comparison sample, when there are new packets. Users can use it for determining whether the connections are malicious or not, to achieve the purpose of co-defensive. Lists of filtering mechanism allow the duplicated packets entered in computers, compared only one time with the large number of blacklist. By using the P2P technique, we can not only decrease the cost of implementation, but also let the network more resilient.
98級-許雅婷-以誘捕系統為基礎的惡意網頁偵測
98級-許雅婷-以誘捕系統為基礎的惡意網頁偵測
[ 摘要 ]
隨著資訊科技以及網際網路(Internet)的快速發展及普遍,已經改變了人們溝通模式,對網路的依賴程度升高,安全問題也隨之而來。近年來Web應用程式快速發展,應用的層面越來越廣,功能越來越複雜,人們對網頁應用程式的依賴度越來越高。一旦使用者的個人電腦抵抗力不佳時,如防護軟體辨識能力不足、或作業系統的安全漏洞未更新等,就可能受到感染。生活網路化的時代,任何人隨時都可能進入高風險的感染雷區,卻毫無警覺。近年來一種新型態的網路攻擊出現,當用戶端存取遠端惡意伺服器時,伺服器回應用戶端請求,同時有一部份的惡意攻擊程式也被傳送至用戶端,即啟動了強迫下載(Drive-by-download)的攻擊。如果成功,惡意伺服器將可以在用戶端執行任何程式。惡意網頁通常又會搭配混淆機制以逃避基於特徵比對(Signature-base)為基礎的偵測系統,網頁的混淆程度日漸複雜甚至延伸至多媒體檔案(JPG、Flash、PDF等),在這種情況下,若不是真正的瀏覽該網頁致使惡意程式引發某些特定行為,單只對網頁內容解析是非常難以判別出惡意行為的,加上網頁資料繁多,攻擊手法又一再翻新。本研究基於用戶端誘捕系統為研究基礎,提出能主動判別網頁是否屬於惡意的模型,提出一種檢測方法以提升判斷惡意網頁的準確性,並先以靜態內容分析加快分析速度,再搭配用戶端誘捕系統實際瀏覽網頁進行更為深層的探測讓使用者在瀏覽網頁時,能確保本身的安全。
[ 英文摘要 ]
With the information technology and the Internet the rapid development and widespread mode of communication has changed the people dependence on the Internet increased, security issues will follow. In recent years the rapid development of Web applications, the application level became more widely and the functions became more complex, people dependence on web applications is increasing. Once the user''s PC resistance is poor, such as the identification of a lack of protective software, or operating system vulnerabilities such as not updated, it may be infected by malicious code. In this networked age, each person may enter at any time minefields of high risk of infection, but no alert. In recent years a new kind of network attacks occur when a malicious client access to remote server, the server response to client requests, while a majority of malicious attacks has also sent to the client program, the Drive-by-download attacks. If infected, the malicious server to comment client that will be able to execute any program. Malicious Web page often confused with Signature-base mechanism to evade detection systems, increasingly complex web of confusion and even extended to the level of multimedia files (JPG, Flash, PDF, etc.).In this situation, if the website is really a result of certain malicious behavior caused, but only on the content analysis is very difficult to distinguish a malicious act. However, many Web data and methods of attack repeatedly renovated. This study is based on client honeypot system, this research can take the initiative to determine whether a malicious Web page model and a detection method to improve the malicious Web page to judge the accuracy and content analysis to speed up the first static analysis speed, and then with the client honeypot system actually visit the website for more in-depth probe allows users to browse the web, can ensure their own safety.
[ 摘要 ]
隨著資訊科技以及網際網路(Internet)的快速發展及普遍,已經改變了人們溝通模式,對網路的依賴程度升高,安全問題也隨之而來。近年來Web應用程式快速發展,應用的層面越來越廣,功能越來越複雜,人們對網頁應用程式的依賴度越來越高。一旦使用者的個人電腦抵抗力不佳時,如防護軟體辨識能力不足、或作業系統的安全漏洞未更新等,就可能受到感染。生活網路化的時代,任何人隨時都可能進入高風險的感染雷區,卻毫無警覺。近年來一種新型態的網路攻擊出現,當用戶端存取遠端惡意伺服器時,伺服器回應用戶端請求,同時有一部份的惡意攻擊程式也被傳送至用戶端,即啟動了強迫下載(Drive-by-download)的攻擊。如果成功,惡意伺服器將可以在用戶端執行任何程式。惡意網頁通常又會搭配混淆機制以逃避基於特徵比對(Signature-base)為基礎的偵測系統,網頁的混淆程度日漸複雜甚至延伸至多媒體檔案(JPG、Flash、PDF等),在這種情況下,若不是真正的瀏覽該網頁致使惡意程式引發某些特定行為,單只對網頁內容解析是非常難以判別出惡意行為的,加上網頁資料繁多,攻擊手法又一再翻新。本研究基於用戶端誘捕系統為研究基礎,提出能主動判別網頁是否屬於惡意的模型,提出一種檢測方法以提升判斷惡意網頁的準確性,並先以靜態內容分析加快分析速度,再搭配用戶端誘捕系統實際瀏覽網頁進行更為深層的探測讓使用者在瀏覽網頁時,能確保本身的安全。
[ 英文摘要 ]
With the information technology and the Internet the rapid development and widespread mode of communication has changed the people dependence on the Internet increased, security issues will follow. In recent years the rapid development of Web applications, the application level became more widely and the functions became more complex, people dependence on web applications is increasing. Once the user''s PC resistance is poor, such as the identification of a lack of protective software, or operating system vulnerabilities such as not updated, it may be infected by malicious code. In this networked age, each person may enter at any time minefields of high risk of infection, but no alert. In recent years a new kind of network attacks occur when a malicious client access to remote server, the server response to client requests, while a majority of malicious attacks has also sent to the client program, the Drive-by-download attacks. If infected, the malicious server to comment client that will be able to execute any program. Malicious Web page often confused with Signature-base mechanism to evade detection systems, increasingly complex web of confusion and even extended to the level of multimedia files (JPG, Flash, PDF, etc.).In this situation, if the website is really a result of certain malicious behavior caused, but only on the content analysis is very difficult to distinguish a malicious act. However, many Web data and methods of attack repeatedly renovated. This study is based on client honeypot system, this research can take the initiative to determine whether a malicious Web page model and a detection method to improve the malicious Web page to judge the accuracy and content analysis to speed up the first static analysis speed, and then with the client honeypot system actually visit the website for more in-depth probe allows users to browse the web, can ensure their own safety.
97級-陳曉琪-改良分散式DRM機制控管P2P即時串流服務
97級-陳曉琪-改良分散式DRM機制控管P2P即時串流服務
[ 摘要 ]
P2P 傳輸技術目前相當熱門,因為它能同時讓兩個使用者直接分享彼此的檔案,而不用透過第三方(伺服器);對使用者而言,意謂可以透過網際網路直接由檔案擁有者手中得到最新的資訊,而不用再等待數位內容上傳至伺服器;對網路提供者而言,則意謂不用再浪費多餘的時間成本管理或操作伺服器。除此之外,還有許多因素加速P2P 網路之實用性,這些因素包括可用的頻寬上升、運算能力提高、儲存容量加大及網路資訊激增等。但是,P2P 傳輸技術同時也是惡名昭彰的非法活動溫床,它使得盜版和非法使用變得容易,因此許多使用者利用它來從事違反著作權法的資料交換。
為解決P2P 傳輸架構帶給大眾的不好印象,導入適合P2P 網路之數位權利管理機制(Digital Rights Management, DRM)是可行的,本研究於現有P2P 即時串流傳輸架構上,改良分散式DRM 機制,並導入新型金鑰管理系統。即時串流傳輸架構具有即載即看即丟的特性,能預防數位內容被重複利用,對於本研究所改良之DRM機制具有加強效果;而導入新型金鑰管理系統,使得DRM 機制運作時,惟有使用者缺乏合法解密金鑰時,才會出現警告,其餘時候使用者並不會感受到DRM 機制之控管,因此能提升使用者對於DRM 機制的接受度。
[ 英文摘要 ]
P2P transmission technology is very popular at present, because it can allow two users to share files directly rather than through a third party. For the users, means users can receive the latest information from the owners, and don''t have to wait for digital content uploaded to the server. For the providers, means providers don''t have to waste the extra time and cost to manage the servers. In addition, a lot of factors accelerate the practicability of P2P network, include the increased availability of bandwidth, computing capacity raise, storage capacity expansion and network information is increased. However, P2P transmission technology is also a notorious breeding ground for illegal activities, it makes piracy and illegal use easier, and many users use it in violation of copyright law to engage in the exchange of information.
In order to solve the bad impression of the P2P transmission structure, implement Digital Rights Management (DRM) for P2P network is feasible. This study improved distributed DRM architecture, and implement the novel key management scheme, in the existing P2P live streaming. Live streaming have the characteristic that is downloaded immediately, watched immediately and deleted immediately, to prevent digital content to be reused. Implement the novel key management scheme, makes a warning only when the user there is no decryption key, and the rest of the time, users will not feel the DRM mechanisms of control, so users can upgrade the mechanism for the acceptance.
[ 摘要 ]
P2P 傳輸技術目前相當熱門,因為它能同時讓兩個使用者直接分享彼此的檔案,而不用透過第三方(伺服器);對使用者而言,意謂可以透過網際網路直接由檔案擁有者手中得到最新的資訊,而不用再等待數位內容上傳至伺服器;對網路提供者而言,則意謂不用再浪費多餘的時間成本管理或操作伺服器。除此之外,還有許多因素加速P2P 網路之實用性,這些因素包括可用的頻寬上升、運算能力提高、儲存容量加大及網路資訊激增等。但是,P2P 傳輸技術同時也是惡名昭彰的非法活動溫床,它使得盜版和非法使用變得容易,因此許多使用者利用它來從事違反著作權法的資料交換。
為解決P2P 傳輸架構帶給大眾的不好印象,導入適合P2P 網路之數位權利管理機制(Digital Rights Management, DRM)是可行的,本研究於現有P2P 即時串流傳輸架構上,改良分散式DRM 機制,並導入新型金鑰管理系統。即時串流傳輸架構具有即載即看即丟的特性,能預防數位內容被重複利用,對於本研究所改良之DRM機制具有加強效果;而導入新型金鑰管理系統,使得DRM 機制運作時,惟有使用者缺乏合法解密金鑰時,才會出現警告,其餘時候使用者並不會感受到DRM 機制之控管,因此能提升使用者對於DRM 機制的接受度。
[ 英文摘要 ]
P2P transmission technology is very popular at present, because it can allow two users to share files directly rather than through a third party. For the users, means users can receive the latest information from the owners, and don''t have to wait for digital content uploaded to the server. For the providers, means providers don''t have to waste the extra time and cost to manage the servers. In addition, a lot of factors accelerate the practicability of P2P network, include the increased availability of bandwidth, computing capacity raise, storage capacity expansion and network information is increased. However, P2P transmission technology is also a notorious breeding ground for illegal activities, it makes piracy and illegal use easier, and many users use it in violation of copyright law to engage in the exchange of information.
In order to solve the bad impression of the P2P transmission structure, implement Digital Rights Management (DRM) for P2P network is feasible. This study improved distributed DRM architecture, and implement the novel key management scheme, in the existing P2P live streaming. Live streaming have the characteristic that is downloaded immediately, watched immediately and deleted immediately, to prevent digital content to be reused. Implement the novel key management scheme, makes a warning only when the user there is no decryption key, and the rest of the time, users will not feel the DRM mechanisms of control, so users can upgrade the mechanism for the acceptance.
97級-游婷敬-基於動態群播金鑰管理系統之改良研究
97級-游婷敬-基於動態群播金鑰管理系統之改良研究
[ 摘要 ]
隨著市場的需求,群播通訊技術的應用,如視訊會議和隨選視訊(Video On Demand, VOD)等,而不同的群播通訊技術,有著不同的運作方式,因此群播金鑰管理系統會隨著不同的環境而改變其需求條件。在前人的動態群播金鑰管理系統,主要針對動態的環境下,當成員加入或離開時,管理者能夠有效率的更新金鑰,並且不影響其他成員金鑰,而管理者更新金鑰的計算量為O(1),但管理者在群播訊息時,卻因中國餘數定理(Chinese Remainder Theorem, CRT) 的群播技術,影響了重新發佈群播訊息時的計算量,並且造成相當大的負擔量。因此本研究將針對金鑰群播訊息重新傳送效率問題的不足,利用不同的群播技術或降低其金鑰的長度來改良,不但使動態群播管理系統保有原先管理者在成員更動時金鑰更新的優點,並降低重新計算其群播訊息時的計算負擔。
[ 英文摘要 ]
With the market demand, the applications of multicast communication technologies such as video conferencing and on-demand video (Video On Demand, VOD), etc. Different multicast communication technologies, there are different mode of operation, so multicast key management system as different environmental conditions and their needs change. In the previous dynamic multicast key management systems, they are mainly for dynamic environment. When members join or leave, managers can efficiently update the key and does not affect the key of the other members, and the calculation that key managers update keys is O (1). But in multicasting message, the multicast technology of the Chinese remainder theorem(CRT) impacts the computation loading of the re-calculate multicast message, Therefore the research will be to improve the lack of transmission efficiency of the multicast message, using of different multicast technology or reduce the length of its keys to improve not only the dynamic multicast management system managers to maintain the original members when the key changes update the advantages and reduce re-calculate the multicast message at the time of the computational loading.
[ 摘要 ]
隨著市場的需求,群播通訊技術的應用,如視訊會議和隨選視訊(Video On Demand, VOD)等,而不同的群播通訊技術,有著不同的運作方式,因此群播金鑰管理系統會隨著不同的環境而改變其需求條件。在前人的動態群播金鑰管理系統,主要針對動態的環境下,當成員加入或離開時,管理者能夠有效率的更新金鑰,並且不影響其他成員金鑰,而管理者更新金鑰的計算量為O(1),但管理者在群播訊息時,卻因中國餘數定理(Chinese Remainder Theorem, CRT) 的群播技術,影響了重新發佈群播訊息時的計算量,並且造成相當大的負擔量。因此本研究將針對金鑰群播訊息重新傳送效率問題的不足,利用不同的群播技術或降低其金鑰的長度來改良,不但使動態群播管理系統保有原先管理者在成員更動時金鑰更新的優點,並降低重新計算其群播訊息時的計算負擔。
[ 英文摘要 ]
With the market demand, the applications of multicast communication technologies such as video conferencing and on-demand video (Video On Demand, VOD), etc. Different multicast communication technologies, there are different mode of operation, so multicast key management system as different environmental conditions and their needs change. In the previous dynamic multicast key management systems, they are mainly for dynamic environment. When members join or leave, managers can efficiently update the key and does not affect the key of the other members, and the calculation that key managers update keys is O (1). But in multicasting message, the multicast technology of the Chinese remainder theorem(CRT) impacts the computation loading of the re-calculate multicast message, Therefore the research will be to improve the lack of transmission efficiency of the multicast message, using of different multicast technology or reduce the length of its keys to improve not only the dynamic multicast management system managers to maintain the original members when the key changes update the advantages and reduce re-calculate the multicast message at the time of the computational loading.
97級-沈俊宏-基於P2P網路架構下之即時通訊系統離線檔案傳輸機制
97級-沈俊宏-基於P2P網路架構下之即時通訊系統離線檔案傳輸機制
[ 摘要 ]
隨著Internet的發展,人與人之間溝通連繫的管道已從舊有的書信、電話…等,慢慢的轉移到網際網路的世界,而最常被使用的通訊軟體為E-mail、即時通訊軟體…等。這些技術主要以Client-Server架構為主,換言之當Server故障或損壞時,就會造成通訊的中斷或是無法使用,因此利用P2P架構來取代Client-Server架構的情況也愈來愈普遍。但在檔案傳輸方面,即時通訊系統還是只能在傳送端與接收端同時為上線狀態來進行檔案傳輸的動作,在有任一方面離線的情況還是需要依靠Server進行檔案暫存的動作,如此一來導入P2P架構並未完全減輕Server的負擔。本研究中,將P2P即時通訊系統導入檔案傳輸的動作,利用所有Peers的資源分享概念,讓檔案傳輸的動作不限定在傳送端與接收端同時在線的情況下才得以進行。本系統利用JXTA進行開發的動作,在即時通訊系統的檔案傳輸架構上導入P2P機制,利用所有的Peers進行檔案片段暫存與備份的動作,以確保檔案傳輸成功率。
[ 英文摘要 ]
With the development of Internet, communication between people from the pipeline linking the old correspondence, phone ... and so on, slowly shift to the Internet world, and the most commonly used communications software for E - mail, instant messaging software ... and so on. These techniques mainly based Client-Server architecture, in other words when the Server failure or damage, will result in the interruption of communication or unable to used, so the use of P2P architecture to replace the Client-Server architecture is also becoming increasingly common. However, file transfer, the instant messaging system or client can only send and receive on-line client for file transfer status to the action, in the case of any aspect of off-line or need to rely on temporary files Server moves This P2P framework Import Server does not fully alleviate the burden. This study, instant messaging P2P file transfer system into action, using all the Peers of the concept of resource sharing, file transfer so that the action is not limited to sending and receiving end at the same time online client circumstances to proceed. The system uses JXTA development action, in the instant messaging system, file transfer P2P mechanisms into the structure, use of all segments of the Peers to temporary and backup files of the action, to ensure that the success rate of file transfer.
[ 摘要 ]
隨著Internet的發展,人與人之間溝通連繫的管道已從舊有的書信、電話…等,慢慢的轉移到網際網路的世界,而最常被使用的通訊軟體為E-mail、即時通訊軟體…等。這些技術主要以Client-Server架構為主,換言之當Server故障或損壞時,就會造成通訊的中斷或是無法使用,因此利用P2P架構來取代Client-Server架構的情況也愈來愈普遍。但在檔案傳輸方面,即時通訊系統還是只能在傳送端與接收端同時為上線狀態來進行檔案傳輸的動作,在有任一方面離線的情況還是需要依靠Server進行檔案暫存的動作,如此一來導入P2P架構並未完全減輕Server的負擔。本研究中,將P2P即時通訊系統導入檔案傳輸的動作,利用所有Peers的資源分享概念,讓檔案傳輸的動作不限定在傳送端與接收端同時在線的情況下才得以進行。本系統利用JXTA進行開發的動作,在即時通訊系統的檔案傳輸架構上導入P2P機制,利用所有的Peers進行檔案片段暫存與備份的動作,以確保檔案傳輸成功率。
[ 英文摘要 ]
With the development of Internet, communication between people from the pipeline linking the old correspondence, phone ... and so on, slowly shift to the Internet world, and the most commonly used communications software for E - mail, instant messaging software ... and so on. These techniques mainly based Client-Server architecture, in other words when the Server failure or damage, will result in the interruption of communication or unable to used, so the use of P2P architecture to replace the Client-Server architecture is also becoming increasingly common. However, file transfer, the instant messaging system or client can only send and receive on-line client for file transfer status to the action, in the case of any aspect of off-line or need to rely on temporary files Server moves This P2P framework Import Server does not fully alleviate the burden. This study, instant messaging P2P file transfer system into action, using all the Peers of the concept of resource sharing, file transfer so that the action is not limited to sending and receiving end at the same time online client circumstances to proceed. The system uses JXTA development action, in the instant messaging system, file transfer P2P mechanisms into the structure, use of all segments of the Peers to temporary and backup files of the action, to ensure that the success rate of file transfer.
97級-蘇文輝-基於新的金鑰管理建構P2P Botnet
97級-蘇文輝-基於新的金鑰管理建構P2P Botnet
[ 摘要 ]
近年來網路惡意攻擊駭客已經逐漸發展成組織化,形成一股趨利主義的勢力。發送大量垃圾信件、利用阻斷服務攻擊(denial-of-service, DoS)來勒索和點擊詐欺(click fraud)等等相關新聞事件都是未來趨勢的警告訊息。傀儡網路(Botnet)在這些惡意攻擊中,是份量極為重大的角色之一,許多攻擊者都利用傀儡網路來發動這些惡意攻擊以賺取利益。
目前以傀儡網路為主的攻擊變的流行和危險,因此有許多研究會致力於如何偵測、監控和防禦傀儡網路(Botnet)。目前大部分的研究是致力於C&C Botnet的研究,是最早出現、研究的傀儡網路,以Internet Relay Chat(IRC) 網路即時聊天系統為主的傀儡網路,而引導這些研究的成果來應付目前我們面對的威脅是必要的。然而還有許多更進階的傀儡網路會被攻擊者發展出來,我們必需提前去設法瞭解才能知己知彼,例如P2P傀儡網路相較於IRC傀儡網路,因為不存在集中的控制點,因此在對P2P傀儡網路的反制會更困難,因此要防禦要先瞭解攻擊,所以我們想要設法先了解,否則,我們未來在下一代的惡意攻擊仍處於被動的情況。
除了P2P惡意程式的惡意攻擊,也有學者提出以P2P良性Botnet來對抗惡意Botnet的分散式阻斷服務攻擊(Distributed Denial of Service,DDoS),因此良性Botnet的發展也是抵制目前網路上龐大的惡意程式攻擊的方法之一,因此我們導入的新型金鑰管理在P2P Botnet在良性Botnet的領域上是否有幫助,在未來也值得探討。
[ 英文摘要 ]
In the recently many years, Internet malware attack have become better organized and more profitable. Email spam, extortion by denial-of-attack, and click fraud represent something of this emerging trend. “Botnet” is the main cause of these problems, many attackers use it to do these malware attacks.
Because botnet-based attacks become popular and dangerous, security researchers have studied how to detect, monitor and defend against them. Most of the present research has focused on the C&C Botnets that have first occurred in the past, especially the Internet Relay Chat (IRC) based Botnet. It’s necessary to conduct such research so as to deal with the threat we are facing today. However, it’s important to research on the advanced Botnet that be designed by the attacker in the near future – P2P Botnet for example. Otherwise, we will remain susceptible to the future internet malware attacks.
In addition to the malicious attacks of the P2P malware, some academics have suggested to P2P friendly Botnet against distributed denial of service attacks (Distributed Denial of Service, DDoS) of the malicious Botnet. Therefore the development of friendly Botnet is one of the ways to resist the current network of malicious programs attack. We import a new key management in the field of benign Botnet to research into whether it is worth exploring in the future.
[ 摘要 ]
近年來網路惡意攻擊駭客已經逐漸發展成組織化,形成一股趨利主義的勢力。發送大量垃圾信件、利用阻斷服務攻擊(denial-of-service, DoS)來勒索和點擊詐欺(click fraud)等等相關新聞事件都是未來趨勢的警告訊息。傀儡網路(Botnet)在這些惡意攻擊中,是份量極為重大的角色之一,許多攻擊者都利用傀儡網路來發動這些惡意攻擊以賺取利益。
目前以傀儡網路為主的攻擊變的流行和危險,因此有許多研究會致力於如何偵測、監控和防禦傀儡網路(Botnet)。目前大部分的研究是致力於C&C Botnet的研究,是最早出現、研究的傀儡網路,以Internet Relay Chat(IRC) 網路即時聊天系統為主的傀儡網路,而引導這些研究的成果來應付目前我們面對的威脅是必要的。然而還有許多更進階的傀儡網路會被攻擊者發展出來,我們必需提前去設法瞭解才能知己知彼,例如P2P傀儡網路相較於IRC傀儡網路,因為不存在集中的控制點,因此在對P2P傀儡網路的反制會更困難,因此要防禦要先瞭解攻擊,所以我們想要設法先了解,否則,我們未來在下一代的惡意攻擊仍處於被動的情況。
除了P2P惡意程式的惡意攻擊,也有學者提出以P2P良性Botnet來對抗惡意Botnet的分散式阻斷服務攻擊(Distributed Denial of Service,DDoS),因此良性Botnet的發展也是抵制目前網路上龐大的惡意程式攻擊的方法之一,因此我們導入的新型金鑰管理在P2P Botnet在良性Botnet的領域上是否有幫助,在未來也值得探討。
[ 英文摘要 ]
In the recently many years, Internet malware attack have become better organized and more profitable. Email spam, extortion by denial-of-attack, and click fraud represent something of this emerging trend. “Botnet” is the main cause of these problems, many attackers use it to do these malware attacks.
Because botnet-based attacks become popular and dangerous, security researchers have studied how to detect, monitor and defend against them. Most of the present research has focused on the C&C Botnets that have first occurred in the past, especially the Internet Relay Chat (IRC) based Botnet. It’s necessary to conduct such research so as to deal with the threat we are facing today. However, it’s important to research on the advanced Botnet that be designed by the attacker in the near future – P2P Botnet for example. Otherwise, we will remain susceptible to the future internet malware attacks.
In addition to the malicious attacks of the P2P malware, some academics have suggested to P2P friendly Botnet against distributed denial of service attacks (Distributed Denial of Service, DDoS) of the malicious Botnet. Therefore the development of friendly Botnet is one of the ways to resist the current network of malicious programs attack. We import a new key management in the field of benign Botnet to research into whether it is worth exploring in the future.
獲獎資訊
|
2013年4月率領學生參加首屆海峽兩岸(福州)大學生創業創新大賽,在768個參賽團隊中脫穎而出,進入前100強。獲邀參加第十五屆海峽兩岸經貿交易會的現場展示及媒合。(http://gwy.fuzhou.gov.cn/cyds/tzgg/201304/t20130419_671819.htm)
|
|
2013年2月輔導畢業生參加教育部主辦的101年度「大專畢業生創業服務計畫」創業競賽獲獎,獲得總共25萬元的補助金,(名稱:樂活資訊服務公司)。
(http://ustart.moe.edu.tw/NewShow.aspx?CDE=CGE20090514154544048&NEWCDE=NEW20130218142520IT5&TYP=NEW20090508190226FME)
|
|
2012年11月率領學生參加經濟部主辦的「2012第17屆全國大專校院資訊應用服務創新競賽」,獲得產學合作組佳作,(名稱:路跑競賽報名、收費、晶片計時及終點攝影系統)。(http://csim.tca.org.tw/award.aspx)
|
|
2012年7月輔導畢業生參加教育部主辦的U-Start創業服務計畫競賽,通過審核,獲得總共50萬元的開辦費補助費,(名稱:樂活資訊服務公司)。(http://ustart.moe.edu.tw/NewShow.aspx?CDE=CGE20090514154544048&NEWCDE=NEW20120730121327BEF&TYP=NEW20090508190226FME)
|
|
2012年5月率領學生參加教育部主辦的「2012全國技專校院學生實務專題製作競賽」,獲得商業群的第三名銅牌獎(題目:My Musician讀譜器)。(http:// iacc.kuas.edu.tw/)
|
|
2011年12月率領學生參加行政院國家資通安全會報技術服務中心主辦的「100年度全國大專校院資安技能金盾獎」競賽,通過初賽,進入決賽。(http://security.cisanet.org.tw/)
|
|
2011年11月率領學生參加IEEE的「第一屆國際機器人競賽競速自走車組The First
International Conference on Robot, Vision and Signal Processing (RVSP-2011)」獲得一個銀牌、三個佳作(http://bit.kuas.edu.tw/~rvsp11/)
|
|
2011年11月率領學生參加「2011全國機器人程式設計競賽」,獲得兩個佳作。(http://legoway.dlit.edu.tw/front/bin/home.phtml)
|
|
2011年10月率領學生參加經濟部主辦的「樂活百年搶鮮大賽(系統整合實作類)」獲得優秀獎(題目:My Musician)。(http://www.lohas100.org.tw/lohas100/index.jsp)
|
|
2011年6月率領學生參加中華電信主辦的「2011電信創新應用大賽(行動應用校園組遊戲類)」進入複賽。(題目:My
Musician)。(http://telsoft.hinet.net/winner_a01.php)
|
|
2010年率領學生參加經濟部工業局主辦的「99年智慧型機器人產品創意競賽」,榮獲『產業應用組』第一名(題目:自動化腳踏車出租管理系統),獎金15萬元。(http://ira.ee.ntu.edu.tw/pmc99/)
|
|
2009年率領學生參加資管學會主辦的「2009第14屆大專校院資訊服務創新競賽」,榮獲AP5資訊應用組第二名(題目:電子智慧索引節目表系統),獎金五千元。(http://csim.tca.org.tw/award.aspx)
|
|
2009年率領學生參加行政院國家資通安全會報技術服務中心主辦的「98年度第四屆全國大專校院資安技能金盾獎」競賽,通過初賽,進入決賽。
|
|
2008年12月率領學生參加經濟部工業局與資訊管理學會主辦的2008(第十三屆)全國大專院校資訊服務創新競賽,榮獲PKI應用組第一名(題目:以DRM為基礎之Eyes
TV),獎金五萬元。(http://csim.tca.org.tw/award.aspx)
|
|
2008年9月率領學生參加宏碁基金會主辦的第三屆龍騰微笑競賽,進入最後12強的決賽,榮獲入圍獎。(題目:EnjoyTV)
|
|
2007年,率領專題學生參加教育部主辦的2007第三屆全國技專校院軟體創思競賽,以變態藍箭毒蛙的P2P-VOD作品,榮獲入圍獎、獎金二萬元。
|
|
2007年,率領專題學生參加教育部主辦的2007全國技專校院學生實務專題製作競賽暨成果展,以「網路語音廣告之防堵」,榮獲入圍獎。
|
|
2007年,榮獲教育部96年度大專校院辦理志工服務/服務學習績優教師獎
(http://ecare.moe.gov.tw) |
|
2006年,指導大學部學生(蔡嘉原等,隊名:想電我請排隊)製作「SPIT制裁秘書」專題,參與教育部指導的「第二屆全國技專校院軟體創思競賽」,獲得佳作(http://140.124.181.36/csidc2006/round.htm)
,獲獎金五萬元。
|
|
2004年初,指導大學部學生(劉士豪等)製作XBRL相關的實務專題,參與美國舉辦的XBRL國際學術競賽(2003-2004 XBRL International
Academic Competition)獲得冠軍(http://bryant2.bryant.edu/~xbrl/2004.htm)
,並獲邀前往領獎。
|
|
|
|
2003年11月指導研究生黃耀慶、林佳輝參加NICI IPv6 推動工作小組研究發展分組於國立東華大學舉辦的「IPv6創意企劃競賽」,作品名稱:「利用Mobile IPv6及SIP建置未來行動通訊新世界」,榮獲佳作
|
|
|
|
2002年11月4~6日帶領學生參加教育部「91年度校園軟體創作競賽」電腦系統組(國立中山大學承辦),作品名稱:「以衛星定位即時傳訊為基礎的計程車與乘客媒合系統」,榮獲佳作獎。
|
|
|
|
|
|
2001年帶領學生參加資訊管理學會主辦的「第五屆全國大專院校資訊管理專題成果競賽」電子商務組,榮獲第一名。
|
|
2001年7月起擔任資策會「新資訊家電系統發展計畫」顧問。
|
|
2001年帶領學生參加資策會主辦的「第一屆手持式IA產品應用程式開發暨應用創意大賽」,榮獲「IA創意提案組優勝獎」。
|
|
2001年帶領學生參加資策會主辦的「第一屆手持式IA產品應用程式開發暨應用創意大賽」,榮獲「企業創新獎」。
|
|
參與教育部87年度暑期大專教師至企業單位研究訪問,擔任榮剛重工公司的「Factor應用程式修改與研發」計畫主持人。
|
|
參與教育部86年度暑期大專教師至企業單位研究訪問,擔任東雲公司的「企業網路之規劃與建置」計畫主持人。
|
指導老師
本實驗室指導教授: 古東明 副教授
奧克拉荷馬州立大學 資訊科學 博士
專長
- 資訊安全
- 資料壓縮
- 資料結溝與演算法
- 資料庫
奧克拉荷馬州立大學 資訊科學 博士
專長
(A)期刊論文
1.
Tung-Ming
Koo, Hung-Chang Chang, “Combining the Capture-Recapture Method and Simple
Linear Regression Analysis of the Malicious Domains Estimation”, Applied
Mathematics & Information Sciences (AMIS), Vol. 7, No. 2L , pp. 425-433, June 2013 (SCI-E)
2.
古東明、張宏昌,”惡意域名受害族群估計-使用聯合超幾何最大似然估計法”,Journal of e-Business(電子商務學報),Accepted, June
2013, (TSSCI)
3.
Tung-Ming
Koo, Hung-Chang Chang, Wen-Chi Liao, "Estimating the Size of P2P
Botnets", IJACT, Vol. 4, No. 12, pp. 386 ~ 395, July 15, 2012 (EI)
4.
Tung-Ming
Koo, Hung-Chang Chang, Chun-Cheng Chuang, Detecting and Analyzing Fast-Flux
Service Networks, AISS, Vol. 4, No. 10, pp. 183 ~ 190, June 2012 (EI)
5.
Tung-Ming
Koo, Hung-Chang Chang, Wun-Huei Su, Building a P2P Botnet Based on a New Key
Management Scheme, Advances in Information Sciences and Service Sciences, Vol. 4, No. 5,
pp. 199 ~ 207, March 2012 (EI)
6.
Tung-Ming
Koo, Hung-Chang Chang, Ting-Ching Yu, A Refined Research on Dynamic Multicast Management
Scheme, International Journal of Digital Content Technology and its
Applications, Vol. 6, No. 7,
pp. 41 ~ 49, April 2012 (EI)
7.
Tung-Ming Koo,
Zuo-Ren Liou, Chih-Chang Shen, Ting-Chin Yu, SIP phone vulnerability exam
system based on Attack Tree , Journal of Internet Technology, Vol. 9, No. 5, December,
2008 (EI, SCI-E)
8.
Tung-Ming
Koo, Shih-Ying Huang, Chih-Chang Shen, Xiao-Qi Chen, A SPIT Prevention System
by Black/White List for P2P SIP, Journal of Beijing Jiaotong University, Vol.
32, No. 5, pp.1-7, Oct. 2008. (EI)
9.
Chih-Chang
Shen, Tung-Ming Koo, Bo-Lin Kuo, Design and Practice of the Interworking System
of the Heterogeneous-VoIP, WSEAS TRANSACTIONS on BUSINESS and ECONOMICS, Issue
12, Volume 4, December 2007. (EI)
10.
Tung-Ming
Koo, Chih-Chang Shen, I-Long Lin,Ching-Huang Lin, Real-Time Remote Log
Collect-Monitoring Mechanism for Cyber Forensics, WSEAS Transactions On
Information Science & Applications, Vol. 4, Issue 6, pp.1219-1224, June 2007.
(EI)
11.
沈志昌、古東明、楊禎葆、鄭進興,”主動式DNS網域安全設定檢測機制”,Journal of Internet Technology,Volume
6,No.2,2005年。(NSC 93-2218-E-224-013)。(EI)
12.
洪健斌、古東明,”四元樹資料結構在影像壓縮編碼技術上之應用”,技術學刊,17:3, 497-505頁,2002年9月。(NSC
90-2213-E-224-010)
(B)研討會論文
1.
古東明、林庭弘,以逆向工程偵測惡意代碼行為,CISC2012第二十二屆資訊安全會議,2012/05/30 -31,中興大學。
2.
古東明、楊昆鑫,以DNS Query Time為基礎偵測Fast-Flux
Service Networks,2011全國計算機會議,嘉義大學,2011/12/2 -3
3.
Tung-Ming
Koo, Tien-Teng Shih, Implement authentication and non-repudiation on RTP
protocol for VoIP, The Tenth International Conference on Information and
Management Sciences, China, 2011/8/6 -11
4.
Tung-Ming Koo,
Hung-Chang Chang, Quan-Wei Guo, Construction P2P firewall HTTP-Botnet defense
mechanism, 2011 IEEE International Conference on Computer Science and
Automation Engineering, (CSAE 2011), Shanghai, China, CSAE 2011, v 1, p 33-39, 2011/6/10 -12,
(EI)
5.
沈志昌、古東明、鄭琮憲、徐俊傑,以語音資訊隱藏方法建構ECDH安全語音通訊,第十六屆資訊管理暨實務研討會,2010/12/11 ,雲林科技大學。
6.
古東明、許雅婷,以誘捕系統為基礎的惡意網頁偵測,第二十屆資訊安全會議,2010/05/27 -28,交通大學。
7.
Tung-Ming
Koo, Ching-Hsing Lin, VoIP Interception in P2P SIP environment, The 2nd
International Conference on Computer and Automation Engineering, Singapore, 2010/02/26 -28,
(EI)
8.
古東明、陳曉琪,改良分散式DRM機制控管P2P即時串流服務,全國計算機會議(NCS) ,2009/11/27 -28,台北大學。
9.
古東明、邱心伶,以ZRTP實作具有End-to-End安全特性的網路電話,第十九屆資訊安全會議,2009/06。
10. 古東明、陳曉琪,導入改良式DRM機制控管P2P即時串流服務,第十九屆資訊安全會議,2009/06。
11. 古東明、沈志昌、游婷敬,基於無縫式換手機制實現點對點加密之安全通道,2008健康與管理學術研討會,2008/12/20 ,元培科技大學。
12. 古東明、沈俊宏、曾若慈、林敬憲,以P2P架構為基礎之個人化網路電視,2008民生電子研討會(WCE
2008),2008/12/05 ,景文科技大學電資學院。
13. 古東明、曾若慈,具DRM功能的P2P個人網路電視平台服務:一種帶動產業經濟的新模式,2008年服務創新與應用研討會,2008/11/7 ,國立台北科技大學。
14. 古東明、劉作仁、沈志昌、游婷敬,基於SIP協定實現以攻擊樹為基礎之VoIP弱點檢測機制,2008海峽兩岸信息科學與信息技術學術交流會議,pp.32-43,2008/10/16 ~18,北京交通大學。
15. 古東明、黃世穎、沈志昌、陳曉琪,基於P2P
SIP環境下之網路語音廣告防堵系統,2008海峽兩岸信息科學與信息技術學術交流會議pp.20-31,2008/10/16 ~18,北京交通大學。
16. 古東明、劉作仁、沈志昌,基於SIP協定實現網路電話系統安全性檢測機制,第18屆資訊安全會議,2008/5/29 ~30,國立東華大學。
17. 古東明、林慶興,基於P2P
SIP環境下之網路語音監聽機制,第十九屆國際資訊管理學術研討會,2008/5/16 ~17,國立暨南國際大學。
18. Tung-Ming Koo, Chih-Chang Shen, Shih
Yuan, Huey-Yeh Lin, A Study for the VOD System Based on the P2P Technique, 4th
International Conference IT & Application(ICITA2007), China, Harbin
2007.01(EI). (NSC 95-2219-E-224-001 )
19. Tung-Ming Koo, Chih-Chang Shen, Hong-Jie
Chen, Real-Time Remote Log Collect-Monitoring System with Characteristic of
Cyber Forensics, 4th International Conference IT &
Application(ICITA2007),China Harbin 2007.01(EI). (NSC 94-2218-E-224-007 )
20. 古東明、郭伯琳、沈志昌、黃世穎,異質網路電話互通系統之設計與實作, 第十二屆資訊管理暨實務研討會,2006年12月9日 ,虎尾科技大學。
21. 古東明、蔡嘉原、林皇伸、魏見安、陳曉蘭、陳麗紋,網路語音之垃圾廣告防堵機制探討—採用兩階段黑白名單,2006年「網際空間:資安、犯罪與法律社會」學術研究暨實務研討會,台灣師範大學。2006年11月20日,pp.71-79。(NSC 95-2815-C-224-018-E )
22. 古東明、陳弘傑、沈志昌,具電腦鑑識特性之即時遠端log蒐集監測機制,TANET2006台灣網際網路研討會,花蓮教育大學。2006年11月。(NSC 94-2218-E-224-007)
23. 古東明、原仕、沈志昌,基於P2P技術之VOD系統研究,TANET2006台灣網際網路研討會,花蓮教育大學。2006年11月。
24. 古東明、蔡嘉原、林皇伸、魏見安、陳曉蘭、陳麗紋,網路語音廣告之防堵-實作於SIP協定,TANET2006台灣網際網路研討會,花蓮教育大學。2006年11月。(NSC
95-2815-C-224 -018 -E )
25. 古東明、郭建麟,“以BT和數位版權管理為基礎之隨選視訊系統”,2006年,ICIM2006 第十七屆國際資訊管理學術研討會,義守大學,2006年5月。
26. 古東明、沈志昌、林敬皇、林宜隆,“基於電腦鑑識下之即時遠端log監測蒐集機制”,2005年「網際空間:資安、犯罪與法律社會」學術研究暨實務研討會,2005/12/23 ,台北。(NSC
94-2218-E-224-007)
27. 古東明、 沈志昌、林佳輝,“開放原始碼下主動式DNS安全檢測系統開發”,2005開放原始碼技術與應用研討會”,2005/11/9 -12,台北。(NSC 93-2218-E-224-013)
28. Tung-Ming Koo ,Chia-Hui Lin ,Chih-Chang Shen, “A Study on Interception of SIP based
VoIP/IM of ENUM Framework on Secured Monitoring Environment”, 2005
International Forensic Science Symposium, 2005/11/7 -9,
Taipei
29. 林慧葉、古東明,“網路財務資訊公開揭露系統之雛形:以具安全性的XBRL為基礎”,2005管理與技術國際學術研討會,雲林科技大學,2005年9月5日 。(NSC
93-2416-H-150-002)
30. 林慧葉、黃素慧、古東明,”從顧客滿意度與財務績效分析企業資源規劃效益”,第一屆創新與管理研討會,實踐大學,2004年12月17日 。
31. 古東明、林佳輝、沈志昌,”基於SIP-ENUM基礎通訊架構之VoIP監聽系統”,Cyber2004「網際空間:資安、犯罪與法律社會」學術研究暨實務研討會,淡江大學,2004年11月26日 ,pp.155-161。
32. 沈志昌、古東明、楊禎葆、鄭進興,”主動式DNS網域安全設定檢測機制”,TANET2004台灣網際網路研討會,台東大學,2004年10月27-29日,pp.1215-1220。(NSC
93-2218-E-224-013)
33. 古東明、邱議賢、沈志昌,”應用雜湊函數與Session分析之數位蒐證機制研究”,Cyber2003 「網際空間:科技、犯罪與法律社會」學術研究暨實務研討會,台灣師範大學,2003年12月19日 ,pp.481-489。(NSC
93-2219-E-006-003)
34. 潘志勝、古東明、卓忠志,”位置導向之室內服務探索系統”, 中華民國九十二年全國計算機會議,逢甲大學,2003年12月18-19日。(NSC 92-2213-E-224-025)
35. 鄭進興、沈志昌、古東明、陳嘉玫,”DNS網域安全稽核防護系統之建置”,TANET2003台灣網際網路研討會,政治大學,2003年10月29-31日,pp.675-680。(NSC 93-2218-E-224-013)
36. 梁文俊、古東明,”以MPEG-4多媒體為基礎的互動式教材之雛形設計”,TANET2003台灣網際網路研討會,政治大學,2003年10月29-31日。
37. 潘志勝、古東明,”整合服務探索與室內定位技術”,二○○三數位生活與網際網路科技研討會,成功大學,2003年9月18-19日。(NSC 92-2213-E-224-025)
38. Lijian Sun,
Steven Lei, Yitung Chen, Hsuan-Tsung Hsieh, 古東明, “Data
Management System Design and Development for Las Vegas Valley, Nevada”, 第十四屆國際資訊管理學術研討會,國立中正大學,2003年7月12日 。
39. 古東明等,”以衛星定位即時傳訊為基礎的計程車與乘客媒合系統”,2002 教育部區域產學合作成果展示暨發表會,教育部區域產學合作中心- -國立雲林科技大學,2002年12月17日 。
40. 古東明、潘志勝,”以Wireless LAN為基礎之區域定位系統”,2002主動式網路研討會,元智大學資訊學院,2002年9月10日。(NSC 92-2213-E-224-025)
41. 古東明、洪健斌,”植基於四元樹之數位浮水印技術之研究”,第一屆數位典藏技術研討會,中央研究院資訊科學研究所,2002年7月25-26日。(NSC 90-2213-E-224-010)
42. 古東明、張克弘、許錫賓、闕甫伋,”以即時傳訊為基礎的重建訊息系統研究”,二OO二數位生活與網際網路科技研討會,成功大學,2002年6月28日 。
43. 古東明、莊俊輝、王台中,”行動嵌入式軟體元件以個人行動資訊系統為例”,二OO二數位生活與網際網路科技研討會,成功大學,2002年6月28日 。
44. 古東明、洪健斌、陳淳齡,”以布林代數為基礎的數位影像資料隱藏方法”,第十三屆國際資訊管理學術研討會論文,2002年。(NSC
90-2213-E-224-010)
45. 古東明、洪健斌、陳淳齡,”以位元平面與區塊分類編碼法為基礎的數位影像資料隱藏方法”,第十三屆國際資訊管理學術研討會論文,2002年。(NSC 90-2213-E-224-010)
46. 洪健斌、古東生、古東明,”布林代數在數位影像資料隱藏技術上之應用”,第三屆管理學域學術研討會論文集,p201~207,2002年。(NSC 90-2213-E-224-010)
47. 古東明、洪健斌、陳淳齡,”線性四元樹壓縮編碼法在數位影像資料隱藏技術上之應用”,第三屆電子化企業經營管理理論暨實務研討會論文,2002年。(NSC 90-2213-E-224-010)
48. Tung-Ming Koo, Dong-Sheng Koo, J. P.
Chandler, “Higher Order BFT with Cross
Terms for Fractal Image Compression”, ISCA 14th International Conference
on Computer Applications in Industry and Engineering (CAINE-2001), November
27-29, 2001, Las Vegas, Nevada, USA. (NSC 90-2213-E-224-021)
49. 古東明,洪健斌,陳淳齡,”四元樹資料結構在影像資料隱藏技術上之應用”,第七屆資訊管理研究暨實務研討會,2001年12月。(NSC 90-2213-E-224-010)
50. 古東明,洪健斌,莊俊輝,陳淳齡,”以四元樹為架構的數位影像智慧財產權之保護技術”,台灣區網際網路研討會(TANET2001),2001年10月。(NSC 90-2213-E-224-010)
51. 古東明,莊俊輝,洪健斌,”以行動式代理人輔助之網路教學系統”,2001年資訊管理學術暨實務研討會,2001年6月,頁85-90。
52. 古東明、莊俊輝,”以行動式代理人之軟體開發方式”,第一屆離島資訊技術與應用研討會,2001年6月,頁264-274。
53. 古東明、張克弘、鄭昌杰,”以資訊家電與即時傳訊系統建構家庭自動化”,第十二屆全國自動化科技研討會,2001年5月。
54. 洪健斌、古東明,”以四元樹為基礎的資料影藏方法”,第十一屆全國資訊安全會議論文集,2001年5月,頁91-97。(NSC 90-2213-E-224-010)
55. 古東明、林慧葉、楊麗秋,"基礎資訊教育之問題與研究",第十五屆全國技術及職業教育研討會,2000年4月,頁61-66。
56. 古東明、古東生、林慧葉,"用於網際網路傅真的拋棄式安全傳真郵票",第十屆國際資訊管理學術研討會,1999年6月,頁160-164。
57. 古東明、林慧葉、蘇靜芳,"人事薪資系統的再生工程",第二屆商業現代化研討會,1999年5月,頁121-128。
58. 林慧葉、古東明、黃智琨、蘇靜芳,"電子簽章法之憑證中心管理問題探討",第二屆商業現代化研討會,1999年5月,頁117-120。
59. 林慧葉、古東明、杜昭誼,"食品業中盤商的管理資訊系統",第二屆商業現代化研討會,1999年5月,頁339-342。
60. 林慧葉、古東明,"程式設計課程的成績預測",第十四屆全國技術及職業教育研討會,1999年5月,頁307-310。
61. 黃智琨、古東明、林慧葉,"電子簽章法之憑證中心管理問題",第九屆全國資訊安全會議,1999年5月,頁179-183。
62. 古東明,林慧葉,"一種基於座標軸投影的空間物件動態索引",第十三屆全國技術及職業教育研討會,1998年5月,頁95-101。
63. 古東明,楊宗澧,"虛擬實境在潛艦操控訓練上的應用",第五屆三軍官校基礎學術研討會,1998年5月,頁1.16-1~1.16-4。
64. 林慧葉,古東明,"預測程式設計課程的學習成效",第五屆三軍官校基礎學術研討會,1998年5月,頁1.15-1~1.15-4。
65. 吳曉君,古東明,“五專資訊管理科程式設計相關課程設計”,第八屆國際資訊管理學術研討會論文集,1997年3月,頁614-619。
66. 古東明,曾生元,“以中心化法改良Fractal影像壓縮技術”,第十二屆全國技術及職業教育研討會論文集, 1997年5月,頁135-140
67. Tung-Ming Koo, H. Lu, “A Method of Dictionary Compression for
Spelling Checkers”, Proceedings of Data Compression Conference,
1993
68. Tung-Ming Koo, “Acquisition of Syntactic Properties of
English Unknown Words from a Corpus”, ROCLING III
(R.O.C. Computational Linguistics Conference III) 1990.
(C)專書及專書論文
1.
資訊生活電腦教材,雲林科技大學,ISBN986-00-4335-3,2006年
2.
自由軟體OpenOFFICE,碁峰出版社,2005 年 01 月
3.
C & C++程式設計,東橋資訊,2002年6月
4.
“Improved
Fractal Image Compression: Centered BFT with Quadtrees”, Ph.D. Dissertation, Oklahoma State
University, U. S. A., 1995.
(D)專利
類別
|
專利名稱
|
國別
|
專利號碼
|
發明人
|
專利權人
|
專利期間
|
發明專利
|
具數位權利管理之點對點傳輸方法
|
中華民國
|
377827
|
古東明、陳曉琪
|
國立雲林科技大學
|
|
發明專利
|
動態群播金鑰之產生暨群播資訊加密與傳送方法及其應用
|
中華民國
|
374648
|
古東明、游婷敬
|
國立雲林科技大學
|
|
發明專利
|
適用於多媒體播放之點對點檔案片段傳輸選擇方法
|
中華民國
|
申請案號:096115512
|
古東明
|
國立雲林科技大學
|
(審核中)
|
發明專利
|
點對點多媒體隨選服務傳輸之方法
|
中華民國
|
申請案號:096115511
|
古東明
|
國立雲林科技大學
|
(審核中)
|
發明專利
|
全球資訊網環境下之公文編輯系統資訊轉換及查詢方法
|
中華民國
|
申請案號:94108809
|
古東明、惠龍、何芳玲、楊士毅
|
國立雲林科技大學
|
(審核中)
|
發明專利
|
提高中文辨識率之錯字更正法
|
中華民國
|
187192
|
古東明、黎偉權
|
財團法人工業技術研究院
|
1992/7
至
1997/7
|
發明專利
|
A Compressed Dictionary For Chinese Word
|
日本
|
3127969
|
古東明
|
財團法人工業技術研究院
|
1991/12至2000/11
|
發明專利
|
一種壓縮詞典記憶系統
|
中華民國
|
179750
|
古東明
|
財團法人工業技術研究院
|
1992/3
至
1997/3
|
訂閱:
文章 (Atom)
RSS Feed
Twitter