首页> 外文学位 >Mitigating rapidly propagating worm threats in emergent networks .
【24h】

Mitigating rapidly propagating worm threats in emergent networks .

机译:缓解紧急网络中迅速传播的蠕虫威胁。

获取原文
获取原文并翻译 | 示例

摘要

This dissertation presents a series of techniques that help both client devices and network elements defend against a wide variety of worm attacks. These techniques can be deployed to secure emergent networks including peer-to-peer (P2P) file-sharing systems and wireless communication systems.;In recent years, worms have emerged as one of the most disastrous security threats to various information systems and network infrastructures. Although Internet worms have been extensively studied, worm issues in such emergent networks as peer-to-peer (P2P) systems and cellular networks have yet received due attention. This dissertation aims at designing automated, realtime, and systematic countermeasures, which leverage the existing internal communication mechanisms and network infrastructure to contain worm propagation. The proposed defenses consist of security solutions for both client and system software.;For P2P networks, this dissertation first proposes a partition-based scheme and a CDS-based scheme to contain ultra-fast topological worm spreads. These schemes leverage the underlying P2P overlay for distributing automated security patches to vulnerable machines. They are unique in adopting graph-theory techniques for containing fast spreading worms. This dissertation then proposes a P2P-tailored solution to combat file-sharing worms in P2P environments. Our solution consists of a download-based scheme and a search-based scheme. Both schemes utilize the existing file-sharing mechanisms to internally disseminate security patches to participating peers in a timely and distributed fashion.;For cell-phone networks, this dissertation proposes two device-level defenses for securing smartphone software, namely an access-control--based scheme and a GTT-based scheme. These schemes are unique in that they either enforce security policies in phone devices to identify and block worm attacks or leverage artificial intelligence (AI) methods to differentiate human or worm initiators of the phone applications. This dissertation also proposes a systematic countermeasure consisting of both terminal-level and network-level defenses for combating cell-phone worms. Unlike the existing solutions that split the collaboration between the terminal device and the network to throttle system-wide worm spreads, the proposed solution adopts an identity-based signature scheme at both the sender and the receiver side, and a detection-based automated patching scheme at the network side. Combining terminal-level and network-level defenses effectively speeds up the process of worm detection and victim disinfection.;This dissertation also provides solid mathematical analyses, extensive simulations and experiments to evaluate the effectiveness and show the applicability of the proposed defenses. In addition, it discusses some open issues related to the proposed solutions and suggests some interesting directions in combating the worm threats as the emergent networks evolve.
机译:本文提出了一系列技术,可以帮助客户端设备和网络元素抵御各种蠕虫攻击。可以将这些技术部署到安全的新兴网络中,包括对等(P2P)文件共享系统和无线通信系统。近年来,蠕虫已成为对各种信息系统和网络基础结构造成的最灾难性的安全威胁之一。 。尽管已经对Internet蠕虫进行了广泛的研究,但是诸如P2P(P2P)系统和蜂窝网络之类的新兴网络中的蠕虫问题尚未受到应有的关注。本文旨在设计一种自动化,实时,系统的对策,利用现有的内部通信机制和网络基础设施来遏制蠕虫的传播。所提出的防御措施包括针对客户端和系统软件的安全解决方案。对于P2P网络,本文首先提出了一种基于分区的方案和一种基于CDS的方案,以包含超快速拓扑蠕虫传播。这些方案利用基础的P2P覆盖将自动安全补丁分发给易受攻击的计算机。它们在采用图论技术来遏制快速传播的蠕虫方面是独一无二的。然后,本文提出了一种针对P2P的解决方案,以对抗P2P环境中的文件共享蠕虫。我们的解决方案包括基于下载的方案和基于搜索的方案。两种方案都利用现有的文件共享机制,以及时,分布式的方式在内部向参与的对等方分发安全补丁。对于手机网络,本文提出了两种用于保护智能手机软件的设备级防御,即访问控制基于方案和基于GTT的方案。这些方案的独特之处在于,它们要么在电话设备中实施安全策略以识别和阻止蠕虫攻击,要么利用人工智能(AI)方法来区分电话应用程序的人类或蠕虫发起者。本文还提出了一种针对终端蠕虫的系统对策,包括终端级和网络级防御。与将终端设备和网络之间的协作拆分以限制整个系统的蠕虫传播的现有解决方案不同,所提出的解决方案在发送方和接收方均采用基于身份的签名方案,并采用基于检测的自动修补方案。在网络端。结合终端级和网络级防御有效地加快了蠕虫检测和受害者消毒的过程。本文还提供了可靠的数学分析,广泛的仿真和实验,以评估有效性,并证明了所提出的防御的适用性。此外,它讨论了与所提出的解决方案相关的一些未解决的问题,并提出了在新兴网络演进过程中应对蠕虫威胁的一些有趣方向。

著录项

  • 作者

    Xie, Liang.;

  • 作者单位

    The Pennsylvania State University.;

  • 授予单位 The Pennsylvania State University.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2008
  • 页码 143 p.
  • 总页数 143
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号