节点文献
高交互蜜罐主机的识别技术研究
Detecting High-Level Interactive Honeypots
【作者】 梁知音; 司端峰; 李成; 毛剑; 陈昱; 诸葛建伟;
【Author】 Liang Zhiyin~1 Si Duanfeng~2 Li Cheng~1 Mao Jian~1 Chen Yu~1 Zhuge Jianwei~1 (1 Institute of Computer Science & Technology of Peking University,Beijing,100871;2 Institute of Software,Chinese Academy of Sciences,Beijing, 100080)
【机构】 北京大学计算机科学技术研究所; 中国科学院软件研究所;
【摘要】 高交互蜜罐是信息安全研究人员用于收集网络攻击信息的重要工具,但攻击者也常常会利用蜜罐主机自身的特点探测其存在进而绕开陷阱,严重降低蜜罐主机的有效性。本文根据高交互蜜罐主机的特点,分析总结出攻击者常用的蜜罐识别技术原理,并给予具体攻击行为刻画与实例分析。高交互蜜罐主机识别技术的原理与实例分析将为安全人员进行蜜罐高效部署与维护提供决策依据;攻击者恶意行为模式的刻画也可为蜜罐主机识别规避与反探测等主动安全防御方式提供强有力的理论与技术支持。
【Abstract】 High-level interactive honeypots are important tools used by information security researchers to collect network attack information.However, attackers are often so sophisticated to escape from those honeypots by detecting their characteristics, which severely lessen the effectiveness of honeypots.In this paper, we analyzed methodologies used in detecting High-level interactive honeypots and demonstrated how they work.The technology of high level interactive honeypot identification and its case studies will help to improve the effectiveness of deployment and maintenance of honeypots, and the analysis of these malicious detections patterns will support to find countermeasure to avoid the detection to honeypots.
【Key words】 Honeypot; Detecting Honeypot; Anti-honeypot; Virtual Machine Detection;
- 【会议录名称】 全国网络与信息安全技术研讨会论文集(上册)
- 【会议名称】全国网络与信息安全技术研讨会
- 【会议时间】2007-07
- 【会议地点】中国山东青岛
- 【分类号】TP393.08
- 【主办单位】信息产业部互联网应急处理协调办公室