摘要
通过诱骗容忍入侵者的破坏行为,蜜罐可以深入了解入侵工具和入侵目的等入侵行为信息,解决传统网络安全技术对未知入侵攻击无能为力的难题,直接或间接地提高系统网络安全性能。深入研究了蜜罐技术的高级实现形式蜜网系统,对比了业务型和研究型两种蜜网系统,并通过有限自动机形式化模拟了业务蜜网系统,描述了其状态转换过程,为业务蜜网系统的行为描述和结构设计提供了理论依据和论证。
By trapping and tolerating attack actions in the given system, honeypot can learn attack tools,attack motivations and much other intrusion information. It can also solve the dilemmas that the traditional network security technologies could not deal with unknown attack actions so that the performance of the network security is improved directly or indirectly. As the advanced realization form of honeypot technology, the honeynet system is researched into mainly, and the contrast of production honeynet and research honeynet are also made.A Turing machine is presented to simulate the common production honeynet system and describe the state transition of the common production honeynet system and a theory for designing architecture of production honeynet system and its reasoning is supplied.
出处
《重庆邮电学院学报(自然科学版)》
2004年第3期87-90,共4页
Journal of Chongqing University of Posts and Telecommunications(Natural Sciences Edition)
基金
国家信息关防与网络安全保障发展计划项目(2002-研1-B-007)
国家"863"项目资助(2002AA001042)
关键词
蜜罐
业务蜜网
入侵
诱骗
网络安全
honeypot
production honeynet
intrusion
trap
network security