摘要
面对网络上复杂而多变的黑客攻击,提出利用虚拟蜜罐技术主动吸引黑客的攻击,来监视和跟踪入侵者的行为并进行记录,进而研究入侵者所使用的攻击工具、攻击策略和方法。笔者论述了虚拟蜜罐技术的基本概念,通过3方面的应用实例,较为系统地研究了虚拟蜜罐技术在网络安全中的应用,证明虚拟蜜罐技术可以有效收集攻击信息,保护实际工作网络,并讨论了虚拟蜜罐的优点和风险。
Aiming at various complex and flexible Hacker' network attacks, an effective method is presented, in which the Virtual Honey-pot Technology is used to actively attract attacks, monitor and track attackers, and record the relevant actions so that the attacking tools and tactics used by the intruders can be analyzed and studied. Firstly, the basic definition of Virtual Honey-pot Technology is introduced. Then, the applications of Virtual Honey-pot Technology to network security are systematically studied with three aspects of applied instances, which proves that the Virtual Honey-pot Technology can effectively gather information about attacks and protect the real network. Finally, the advantages and the risks of Virtual Honey -pot Technology are discussed.
出处
《中国安全科学学报》
CAS
CSCD
2008年第12期106-111,共6页
China Safety Science Journal
基金
哈尔滨市科技创新人才研究专项资金资助(2008RFQXG066)
关键词
网络安全
虚拟蜜罐
入侵检测
蠕虫病毒
虚拟网络
network security
virtual honey-pot
detection of intrusion
worm virus
virtual network