节点文献
使用蜜罐分析一种蠕虫病毒的运行机制
Analyses Running Mechanisms of A Worm Using Honeypot
【摘要】 本文使用VMWare以弱化系统方式在宿主机配置高交互的蜜罐系统。配置过程包括安装虚拟操作系统、系统补丁和杀毒程序、系统监视、数据包捕获软件等。利用该系统捕获了一种网络病毒,通过对捕获到的蠕虫病毒的攻击过程的记录和分析,了解了其特征和网络病毒运行机制,为进一步采取防范措施提供参考。
【Abstract】 Honeypot of high interactive weakened system is configured with VMWare on host.Configure progresses include installing of virtual OS,patches,antivirus program,system monitor program,recorders and packets capture program,etc.A kind of worm virus is captured with the honeypot system,by recording and analyzing the progresses of the worm virus captured,attack characters and mechanisms of the worm virus is discovered and known,which gives references for protection.
【基金】 国家科技型中小企业创新网络安全集成防御系统(03c26215100249)
- 【文献出处】 微计算机信息 ,Microcomputer Information , 编辑部邮箱 ,2008年03期
- 【分类号】TP309.5
- 【被引频次】3
- 【下载频次】150