节点文献

使用蜜罐分析一种蠕虫病毒的运行机制

Analyses Running Mechanisms of A Worm Using Honeypot

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 孙海峰宋丽丽

【Author】 (College of Computer Science,Southwest University of Science & Technology,Mianyang 621010,China)Sun HaiFeng Song LiLi

【机构】 西南科技大学计算机科学与技术学院西南科技大学计算机科学与技术学院 621010绵阳621010绵阳

【摘要】 本文使用VMWare以弱化系统方式在宿主机配置高交互的蜜罐系统。配置过程包括安装虚拟操作系统、系统补丁和杀毒程序、系统监视、数据包捕获软件等。利用该系统捕获了一种网络病毒,通过对捕获到的蠕虫病毒的攻击过程的记录和分析,了解了其特征和网络病毒运行机制,为进一步采取防范措施提供参考。

【Abstract】 Honeypot of high interactive weakened system is configured with VMWare on host.Configure progresses include installing of virtual OS,patches,antivirus program,system monitor program,recorders and packets capture program,etc.A kind of worm virus is captured with the honeypot system,by recording and analyzing the progresses of the worm virus captured,attack characters and mechanisms of the worm virus is discovered and known,which gives references for protection.

【关键词】 虚拟机弱化系统蜜罐蠕虫病毒
【Key words】 VMWareWeakened SystemHoneypotWorm Virus
【基金】 国家科技型中小企业创新网络安全集成防御系统(03c26215100249)
  • 【文献出处】 微计算机信息 ,Microcomputer Information , 编辑部邮箱 ,2008年03期
  • 【分类号】TP309.5
  • 【被引频次】3
  • 【下载频次】150
节点文献中: 

本文链接的文献网络图示:

本文的引文网络