节点文献
基于欺骗的网络主动防御技术研究
A Study on the Network Active Defense Technology Based on Deception
【摘要】 针对网络对抗和计算机网络安全防护的现实需求,提出了一种在分布式欺骗空间中实施多重欺骗的网络主动防御技术,通过仿真常用的网络服务程序以及伪造安全漏洞来诱骗入侵者,利用内核级操作控制、文件系统镜像和信息欺骗,构建基于Windows和Linux平台的欺骗性操作环境,实现了对网络入侵全过程的欺骗、监视与控制。该技术突破了普通蜜罐技术单一欺骗层次的局限性,使得欺骗性、交互性和安全性同时得到明显提高。
【Abstract】 A network active defense technology based on multi-layers deception in the distributed deception space is proposed to meet the needs of network countermeasure and network security.This technology simulates usual network service programs and forges vulnerabilities to lure the intruder.With operation control at kernel level,file system mirror and information deception,it creates the deceiving operating environment on the platform of Windows and Linux.Thus the process of intrusion is fully deceived,monitored and controlled.This technology breaks the limitation of a single layer deception used by other general honeypots,and obviously promotes the level of deception,interaction and ensures security.
【Key words】 network deception; active defense; honeypot; network service simulation; operation control;
- 【文献出处】 国防科技大学学报 ,Journal of National University of Defense Technology , 编辑部邮箱 ,2008年03期
- 【分类号】TP393.08
- 【被引频次】29
- 【下载频次】353