摘要
针对入侵检测系统自身的被动性和蜜罐的陷阱机制,从IP地址欺骗、数据捕捉、端口重定向和操作系统及其服务模拟等角度设计蜜罐,为提前发现新的入侵检测规则提供有效信息,改善入侵检测技术被动性的不足。
According to the passivity of IDS and deception of honeypot, through IP deception, data capture, port redirection, operation system and service simulation, etc, to design honeypot, provides infomation about hostile visitor, improves IDS' flaw of passivity.
出处
《现代计算机》
2008年第3期40-42,共3页
Modern Computer