节点文献
基于蜜罐的网络动态取证系统研究
Research on a Honeypot Based Network Dynamic Forensics System
【摘要】 针对计算机静态取证技术和常用的动态取证技术中存在的问题,提出了基于虚拟蜜罐的网络动态取证系统模型。该模型将在被保护子网上对流经的网络数据进行实时监控,编写程序对检测到的入侵进行报警,并通过修改iptables的nat表,利用重定向技术将检测到的入侵数据导入到蜜罐中进行记录,实现了入侵检测技术、蜜罐技术与防火墙技术的联动,达到实时动态取证的目的。实验结果表明,该系统不仅可以保护网络和主机不受攻击,还可以长时间的获取证据,并使得证据不受污染,达到了预期效果。
【Abstract】 This paper presents a honeypot based network dynamic forensics system in view of the negatives of computer static forensics and conventional dynamic forensics.This system can monitor the network data flow in a protected subnet,send an alarm when a an intrusion is detected,and input the intrusion data into a honeypot and record them with redirection technology.The system can help us dynamically acquire the intrusion evidences by the linkage of intrusion detection,firewall and honeypot.Experiments show that the system can not only avoid servers and networks from attacking but also persistently prevent intrusion evidence from being polluted,so we obtain the expected results.
【Key words】 dynamic forensics; intrusion detection; redirection technology; honeypot;
- 【文献出处】 山东科学 ,Shandong Science , 编辑部邮箱 ,2010年05期
- 【分类号】TP393.08
- 【被引频次】5
- 【下载频次】115