SQL Injection 攻擊偵測:使用資訊安全日誌管理系統平台的實踐方法

dc.contributor黃文吉zh_TW
dc.contributorHwang, Wen-Jyien_US
dc.contributor.author許智翔zh_TW
dc.contributor.authorHsu, Chin-Hsiangen_US
dc.date.accessioned2023-12-08T08:02:52Z
dc.date.available9999-12-31
dc.date.available2023-12-08T08:02:52Z
dc.date.issued2023
dc.description.abstract本論文旨在探討如何利用Wazuh安全監控平台和有限狀態機方法來檢測和預防SQL注入攻擊。首先,我們介紹了SQL注入攻擊的威脅性和常見形式,並分析了目前現有方法在應對這一問題上的局限性。接著,我們詳細介紹了Wazuh平台和有限狀態機方法的原理和應用。通過結合日誌檔的收集和分析,我們提出了一套基於規則的檢測和預警機制,以提前發現和處理SQL注入攻擊。在實驗中,我們利用不同類型的SQL注入攻擊案例來驗證我們的方法的有效性。zh_TW
dc.description.abstractThis thesis aims to explore how to detect and prevent SQL injection attacks using the Wazuh security monitoring platform and Finite State Machine (FSM) method. Firstly, we introduce the threats and common forms of SQL injection attacks, and analyze the limitations of existing methods in addressing this issue. Next, we provide a detailed overview of the principles and application of the Wazuh platform and the Finite State Machine method. By combining log collection and analysis, we propose a rule-based detection and alerting mechanism to proactively detect and handle SQL injection attacks. In our experiments, we validate the effectiveness of our approach using various types of SQL injection attack scenarios.en_US
dc.description.sponsorship資訊工程學系zh_TW
dc.identifier61047097S-44169
dc.identifier.urihttps://etds.lib.ntnu.edu.tw/thesis/detail/7401e60fa0aef25cd32c73724eb83981/
dc.identifier.urihttp://rportal.lib.ntnu.edu.tw/handle/20.500.12235/121643
dc.language中文
dc.subjectSQL注入攻擊zh_TW
dc.subjectWazuh安全監控平台zh_TW
dc.subject有限狀態機zh_TW
dc.subject日誌檔分析zh_TW
dc.subject攻擊檢測zh_TW
dc.subject預警機制zh_TW
dc.subjectSQL injection attacksen_US
dc.subjectWazuh security monitoring platformen_US
dc.subjectFinite State Machineen_US
dc.subjectLog analysisen_US
dc.subjectAttack detectionen_US
dc.subjectAlerting mechanismen_US
dc.titleSQL Injection 攻擊偵測:使用資訊安全日誌管理系統平台的實踐方法zh_TW
dc.titleDetection of SQL Injection Attacks by Security Information and Event Management System Platformen_US
dc.typeetd

Files

Collections