检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
机构地区:[1]解放军理工大学指挥自动化学院,江苏南京210007
出 处:《计算机工程与设计》2009年第12期2878-2881,共4页Computer Engineering and Design
摘 要:针对当前基于暗网的蠕虫监控技术存在诸如诱捕能力低、资源耗费大等问题,研究了当前的蜜罐、暗网监测技术,提出了一种蠕虫诱捕方案。在主动响应蠕虫的扫描探测之后,利用在可动态切换IP的高交互蜜罐部署有漏洞的网络服务正确响应蠕虫攻击的特点,完成与攻击者的深入交互。不采用传统的模拟网络服务漏洞的方法,减轻了研究网络服务漏洞的攻击原理的负担。实验结果表明,设计的原型系统原理可行,在蠕虫早期预警方面发挥作用。To solve some problems such as low worm trap capacity and big resource-consuming, the current honeypot and darknet monitoring technology is studied, and a new active worm trapping solution is proposed. With the help of dynamic honeypot IP and the capability of network service vulnerability which can respond to the worms attack rightly, it responds to the scan and completes the high interaction with the worms. Instead of traditional simulating the behavior of network service vulnerability, the burden of studying the principle of vulnerability is much less. The experimental results show that the principle is feasible and this prototype system can play a role in the predicting worms.
分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.188