98級-張宏昌-結合重覆捕取法及迴歸分析之惡意域名受害族群估計
[ 摘要 ]
惡意域名是目前網路世界所面臨的極大威脅,其技術可以讓攻擊者隱藏在一群代理伺服器(Agent)後面,這樣的隱匿方法可以讓攻擊者躲避偵測使資訊安全人員偵測失敗,Fast-Flux Service Network(FFSN)這項技術對犯罪份子經營的惡意網站可以受到保護,進而延長惡意網站的壽命。FFSN的危害日益嚴重,要估計FFSN-Agent規模也相當不容易,且Flux-Agent本身可能是Bot節點,對於FFSN的規模估計也可以知道其威脅程度。本研究的核心為規模估計動態惡意域名服務網路(Fast-Flux Service Network,FFSN)的族群規模大小,藉由重覆捕取法(Capture-Recapture Method,CRM)中的聯合超幾何最大似然估計法(Joint hypergeometric maximum likelihood estimator,JHE)來估計Flux-Agent的群體大小,以其JHE最小估計基數再加以線性迴歸預測分析,產生最小估計基數前之線性迴歸模型,形成兩階段預測分析,其結果發現比普查的方式可以更快速找出整個族群大小。
[ 英文摘要 ]
Fast-flux service networks (FFSNs) are currently the greatest threat encountered in the computer networking field. This technique hides attackers behind a network of proxy servers (agents), thereby avoiding detection by security personnel. FFSN benefits criminal parties because it protects their Web sites and extends Web site life span. FFSN is becoming more dangerous, and estimating the size of FFSN-agents is becoming increasingly difficult. Additionally, because flux-agents may represent bot nodes, we can estimate the scale of FFSNs to determine the extent of threats. This study primarily estimates the population size of FFSNs. The flux-agent population size was estimated using the joint hypergeometric maximum likelihood estimator (JHE) of capture-recapture methods (CRMs), and using the linear regression analysis to make a prediction of the initial data. The results showed that the JHE and CRM estimated the population size more rapidly compared to general survey approaches.
98級-莊竣程-偵測與分析Fast-Flux Service Network
98級-莊竣程-偵測與分析Fast-Flux Service Network
[ 摘要 ]
隨著網際網路的高度發展,網路安全已是我們所面臨最嚴重的問題之一。有一大群不法之徒運用著網際網路從事非法的活動,像是木馬、病毒散播、分散式阻斷服務攻擊、垃圾郵件與釣魚網站的威脅等,基於不法利益的考量,犯罪者對於他們的非法活動有高度的可用性需求,而為了混淆他們的詐欺活動,犯罪者們最近開始使用一種稱為Fast-Flux Service Networks的攻擊手法,FFSN是由一群被用來當作代理轉向服務的傀儡網路(botnet)所組成,同時利用這些受感染的傀儡主機來呈現犯罪者所架設的詐欺內容。
本研究實作建置一系統,針對Malware Domain List資料來源偵測FFSN惡意網域,探討當前網路犯罪中FFSN被犯罪者應用的實際情形、並分析被感染節點之分佈概況等。
[ 英文摘要 ]
As the highly development of Internet, one of the most serious threats we face is cyber-security. There are many groups of criminals using the Internet to engage in illegal activities like Trojan horse, viruses, DDoS attacks, spam emails and phishing. They motivated by illegal profit, have a high demand in availability of their illegal activities, and to confuse the location of their services. These criminals recently started to use a new technique called Fast-Flux Service Networks, composed of large groups of bots and acting as proxies to their scam contents.
In this thesis we implemented a system, detecting whether the data which are from Malware Domain List are belong to FFSN or not. Also, we investigate the utilization of FFSN by miscreants on the Internet, and analyzing the location details of the infected bots.
[ 摘要 ]
隨著網際網路的高度發展,網路安全已是我們所面臨最嚴重的問題之一。有一大群不法之徒運用著網際網路從事非法的活動,像是木馬、病毒散播、分散式阻斷服務攻擊、垃圾郵件與釣魚網站的威脅等,基於不法利益的考量,犯罪者對於他們的非法活動有高度的可用性需求,而為了混淆他們的詐欺活動,犯罪者們最近開始使用一種稱為Fast-Flux Service Networks的攻擊手法,FFSN是由一群被用來當作代理轉向服務的傀儡網路(botnet)所組成,同時利用這些受感染的傀儡主機來呈現犯罪者所架設的詐欺內容。
本研究實作建置一系統,針對Malware Domain List資料來源偵測FFSN惡意網域,探討當前網路犯罪中FFSN被犯罪者應用的實際情形、並分析被感染節點之分佈概況等。
[ 英文摘要 ]
As the highly development of Internet, one of the most serious threats we face is cyber-security. There are many groups of criminals using the Internet to engage in illegal activities like Trojan horse, viruses, DDoS attacks, spam emails and phishing. They motivated by illegal profit, have a high demand in availability of their illegal activities, and to confuse the location of their services. These criminals recently started to use a new technique called Fast-Flux Service Networks, composed of large groups of bots and acting as proxies to their scam contents.
In this thesis we implemented a system, detecting whether the data which are from Malware Domain List are belong to FFSN or not. Also, we investigate the utilization of FFSN by miscreants on the Internet, and analyzing the location details of the infected bots.
98級-廖紋淇-P2P Botnet之規模估計
98級-廖紋淇-P2P Botnet之規模估計
[ 摘要 ]
年來傀儡網路已成為網際網路安全的威脅,攻擊者能控制大量的電腦,以發動各種不同的攻擊,如DDoS攻擊、濫發垃圾郵件、竊取個資等。
Botnet的規模大小是評估其威脅的關鍵指標,愈大的Botnet其所帶來的威脅也愈大。
如何去估計Botnet的規模,也成為資安研究的一個重要議題。本研究提出一個利用P2P Botnet中,每個節點都會持有Botnet中部分成員的節點資訊之特性,以重複捕取法取樣估計的模式來估計P2P Botnet的規模。
[ 英文摘要 ]
In recent years, Botnets have become major security threats in Internet, since the attacker can control a large number of bots. Attackers primarily use them for DDoS attacks, e-mail spamming, or massive personal information theft.
The size of a Botnet is a key index to estimate the threat of a botnet. The larger size of a Botnet, the more devastating these attacks can be. To estimate the size of a botnet becomes an important issue in Internet security. In P2P Botnet, every bot peer holds information about some other bot peers. In this study, we utilize this characteristic and capture-recapture technique to estimate the size of a P2P botnet.
[ 摘要 ]
年來傀儡網路已成為網際網路安全的威脅,攻擊者能控制大量的電腦,以發動各種不同的攻擊,如DDoS攻擊、濫發垃圾郵件、竊取個資等。
Botnet的規模大小是評估其威脅的關鍵指標,愈大的Botnet其所帶來的威脅也愈大。
如何去估計Botnet的規模,也成為資安研究的一個重要議題。本研究提出一個利用P2P Botnet中,每個節點都會持有Botnet中部分成員的節點資訊之特性,以重複捕取法取樣估計的模式來估計P2P Botnet的規模。
[ 英文摘要 ]
In recent years, Botnets have become major security threats in Internet, since the attacker can control a large number of bots. Attackers primarily use them for DDoS attacks, e-mail spamming, or massive personal information theft.
The size of a Botnet is a key index to estimate the threat of a botnet. The larger size of a Botnet, the more devastating these attacks can be. To estimate the size of a botnet becomes an important issue in Internet security. In P2P Botnet, every bot peer holds information about some other bot peers. In this study, we utilize this characteristic and capture-recapture technique to estimate the size of a P2P botnet.
98級-郭權緯-建構P2P防火牆之HTTP-Botnet防禦機制
98級-郭權緯-建構P2P防火牆之HTTP-Botnet防禦機制
[ 摘要 ]
這幾年來, Botnet有增加的趨勢,如果沒有相對的解決辦法,未來必會有越來越嚴重的惡意攻擊情況發生。HTTP Botnet使用的是HTTP協定,利用一般HTTP 協定的80 port,達到隱藏的效果,可以順利通過防火牆跟IDS系統。
本研究採用重複標準差的方法偵測出HTTP Bot的連線,再使用JXTA P2P的網路分享偵測出結果,使用者利用名單過濾機制,進行封包的比對。
利用P2P交換資訊,已感染HTTP Bot的使用者,可以找出與HTTP Server與Bot的連線,而未感染的使用者,可以使用這些資訊,當作是比對的樣本,當有新的封包進來,可以判斷是否為惡意的連線,達到聯合防禦的目的。名單的過濾機制可以讓重複進到電腦的封包,只做第一次與黑名單的比對。使用P2P傳送,減少了建置成本,也讓整個網路變得更強韌。
[ 英文摘要 ]
The scale of Botnet is still increasing on the Internet in recently years. If there is no corresponding solution, there will be more serious and malicious attacks in the future. HTTP Botnet uses HTTP protocol. By using the general HTTP protocol and 80 port, the attacks not only can be hidden more easily, but go through the firewall and IDS systems without detected.
In this study, we use the Repeatability Standard Deviation method to detect the connection of Botnets within HTTP protocol. Furthermore, we use the JXTA P2P network to share the results we have detected, and users can compare the packets of traffic with lists of the filtering mechanism.
Using P2P technique to exchange the information we have detected, users who have been infected can find the connection of HTTP Botnet servers. And uninfected users can use this information as a comparison sample, when there are new packets. Users can use it for determining whether the connections are malicious or not, to achieve the purpose of co-defensive. Lists of filtering mechanism allow the duplicated packets entered in computers, compared only one time with the large number of blacklist. By using the P2P technique, we can not only decrease the cost of implementation, but also let the network more resilient.
[ 摘要 ]
這幾年來, Botnet有增加的趨勢,如果沒有相對的解決辦法,未來必會有越來越嚴重的惡意攻擊情況發生。HTTP Botnet使用的是HTTP協定,利用一般HTTP 協定的80 port,達到隱藏的效果,可以順利通過防火牆跟IDS系統。
本研究採用重複標準差的方法偵測出HTTP Bot的連線,再使用JXTA P2P的網路分享偵測出結果,使用者利用名單過濾機制,進行封包的比對。
利用P2P交換資訊,已感染HTTP Bot的使用者,可以找出與HTTP Server與Bot的連線,而未感染的使用者,可以使用這些資訊,當作是比對的樣本,當有新的封包進來,可以判斷是否為惡意的連線,達到聯合防禦的目的。名單的過濾機制可以讓重複進到電腦的封包,只做第一次與黑名單的比對。使用P2P傳送,減少了建置成本,也讓整個網路變得更強韌。
[ 英文摘要 ]
The scale of Botnet is still increasing on the Internet in recently years. If there is no corresponding solution, there will be more serious and malicious attacks in the future. HTTP Botnet uses HTTP protocol. By using the general HTTP protocol and 80 port, the attacks not only can be hidden more easily, but go through the firewall and IDS systems without detected.
In this study, we use the Repeatability Standard Deviation method to detect the connection of Botnets within HTTP protocol. Furthermore, we use the JXTA P2P network to share the results we have detected, and users can compare the packets of traffic with lists of the filtering mechanism.
Using P2P technique to exchange the information we have detected, users who have been infected can find the connection of HTTP Botnet servers. And uninfected users can use this information as a comparison sample, when there are new packets. Users can use it for determining whether the connections are malicious or not, to achieve the purpose of co-defensive. Lists of filtering mechanism allow the duplicated packets entered in computers, compared only one time with the large number of blacklist. By using the P2P technique, we can not only decrease the cost of implementation, but also let the network more resilient.
98級-許雅婷-以誘捕系統為基礎的惡意網頁偵測
98級-許雅婷-以誘捕系統為基礎的惡意網頁偵測
[ 摘要 ]
隨著資訊科技以及網際網路(Internet)的快速發展及普遍,已經改變了人們溝通模式,對網路的依賴程度升高,安全問題也隨之而來。近年來Web應用程式快速發展,應用的層面越來越廣,功能越來越複雜,人們對網頁應用程式的依賴度越來越高。一旦使用者的個人電腦抵抗力不佳時,如防護軟體辨識能力不足、或作業系統的安全漏洞未更新等,就可能受到感染。生活網路化的時代,任何人隨時都可能進入高風險的感染雷區,卻毫無警覺。近年來一種新型態的網路攻擊出現,當用戶端存取遠端惡意伺服器時,伺服器回應用戶端請求,同時有一部份的惡意攻擊程式也被傳送至用戶端,即啟動了強迫下載(Drive-by-download)的攻擊。如果成功,惡意伺服器將可以在用戶端執行任何程式。惡意網頁通常又會搭配混淆機制以逃避基於特徵比對(Signature-base)為基礎的偵測系統,網頁的混淆程度日漸複雜甚至延伸至多媒體檔案(JPG、Flash、PDF等),在這種情況下,若不是真正的瀏覽該網頁致使惡意程式引發某些特定行為,單只對網頁內容解析是非常難以判別出惡意行為的,加上網頁資料繁多,攻擊手法又一再翻新。本研究基於用戶端誘捕系統為研究基礎,提出能主動判別網頁是否屬於惡意的模型,提出一種檢測方法以提升判斷惡意網頁的準確性,並先以靜態內容分析加快分析速度,再搭配用戶端誘捕系統實際瀏覽網頁進行更為深層的探測讓使用者在瀏覽網頁時,能確保本身的安全。
[ 英文摘要 ]
With the information technology and the Internet the rapid development and widespread mode of communication has changed the people dependence on the Internet increased, security issues will follow. In recent years the rapid development of Web applications, the application level became more widely and the functions became more complex, people dependence on web applications is increasing. Once the user''s PC resistance is poor, such as the identification of a lack of protective software, or operating system vulnerabilities such as not updated, it may be infected by malicious code. In this networked age, each person may enter at any time minefields of high risk of infection, but no alert. In recent years a new kind of network attacks occur when a malicious client access to remote server, the server response to client requests, while a majority of malicious attacks has also sent to the client program, the Drive-by-download attacks. If infected, the malicious server to comment client that will be able to execute any program. Malicious Web page often confused with Signature-base mechanism to evade detection systems, increasingly complex web of confusion and even extended to the level of multimedia files (JPG, Flash, PDF, etc.).In this situation, if the website is really a result of certain malicious behavior caused, but only on the content analysis is very difficult to distinguish a malicious act. However, many Web data and methods of attack repeatedly renovated. This study is based on client honeypot system, this research can take the initiative to determine whether a malicious Web page model and a detection method to improve the malicious Web page to judge the accuracy and content analysis to speed up the first static analysis speed, and then with the client honeypot system actually visit the website for more in-depth probe allows users to browse the web, can ensure their own safety.
[ 摘要 ]
隨著資訊科技以及網際網路(Internet)的快速發展及普遍,已經改變了人們溝通模式,對網路的依賴程度升高,安全問題也隨之而來。近年來Web應用程式快速發展,應用的層面越來越廣,功能越來越複雜,人們對網頁應用程式的依賴度越來越高。一旦使用者的個人電腦抵抗力不佳時,如防護軟體辨識能力不足、或作業系統的安全漏洞未更新等,就可能受到感染。生活網路化的時代,任何人隨時都可能進入高風險的感染雷區,卻毫無警覺。近年來一種新型態的網路攻擊出現,當用戶端存取遠端惡意伺服器時,伺服器回應用戶端請求,同時有一部份的惡意攻擊程式也被傳送至用戶端,即啟動了強迫下載(Drive-by-download)的攻擊。如果成功,惡意伺服器將可以在用戶端執行任何程式。惡意網頁通常又會搭配混淆機制以逃避基於特徵比對(Signature-base)為基礎的偵測系統,網頁的混淆程度日漸複雜甚至延伸至多媒體檔案(JPG、Flash、PDF等),在這種情況下,若不是真正的瀏覽該網頁致使惡意程式引發某些特定行為,單只對網頁內容解析是非常難以判別出惡意行為的,加上網頁資料繁多,攻擊手法又一再翻新。本研究基於用戶端誘捕系統為研究基礎,提出能主動判別網頁是否屬於惡意的模型,提出一種檢測方法以提升判斷惡意網頁的準確性,並先以靜態內容分析加快分析速度,再搭配用戶端誘捕系統實際瀏覽網頁進行更為深層的探測讓使用者在瀏覽網頁時,能確保本身的安全。
[ 英文摘要 ]
With the information technology and the Internet the rapid development and widespread mode of communication has changed the people dependence on the Internet increased, security issues will follow. In recent years the rapid development of Web applications, the application level became more widely and the functions became more complex, people dependence on web applications is increasing. Once the user''s PC resistance is poor, such as the identification of a lack of protective software, or operating system vulnerabilities such as not updated, it may be infected by malicious code. In this networked age, each person may enter at any time minefields of high risk of infection, but no alert. In recent years a new kind of network attacks occur when a malicious client access to remote server, the server response to client requests, while a majority of malicious attacks has also sent to the client program, the Drive-by-download attacks. If infected, the malicious server to comment client that will be able to execute any program. Malicious Web page often confused with Signature-base mechanism to evade detection systems, increasingly complex web of confusion and even extended to the level of multimedia files (JPG, Flash, PDF, etc.).In this situation, if the website is really a result of certain malicious behavior caused, but only on the content analysis is very difficult to distinguish a malicious act. However, many Web data and methods of attack repeatedly renovated. This study is based on client honeypot system, this research can take the initiative to determine whether a malicious Web page model and a detection method to improve the malicious Web page to judge the accuracy and content analysis to speed up the first static analysis speed, and then with the client honeypot system actually visit the website for more in-depth probe allows users to browse the web, can ensure their own safety.
訂閱:
文章 (Atom)
RSS Feed
Twitter