摘要
Internet大面积遭受蠕虫攻击的事件时有发生,针对这种问题,引入Honeypot技术,结合入侵检测系统(IDS)、数据挖掘提出了一种解决办法:将Honeypot置于DMZ中,利用其欺骗地址空间技术覆盖服务器中没有用到的IP地址,捕获蠕虫;IDS监控流入网络的数据包,对入侵作出反映;系统日志异地保存。该系统能有效抵御目前已经出现的蠕虫攻击,同时对新出现的目前未知的蠕虫攻击也有很好的防御效果。
Recentely, more and more worm attacks happen on Internet. According to this situation, honey-pot technology with IDS and data mining is used to resolve the problem; Honeypot is put in DMZ. The address and space spoofing technology is utilized to cover the unused IP address and space. Then the worms are captured. IDS monitors the data pachet that flows into the internet, and then reacts to the attacks. The system log keeps it in other places. This new approach could defend present known worm attacks effectively, and have effect on some future unknown work attacks.
出处
《西南科技大学学报》
CAS
2005年第2期10-12,22,共4页
Journal of Southwest University of Science and Technology
关键词
密罐
数据挖掘
入侵检测
蠕虫病毒
Honeypot
data mining
intrusion detecion
worm virus