摘要
本文根据NIDS存在的问题和蜜罐系统的优势,设计了一个将NIDS与蜜罐系统相结合的模型。由蜜罐吸引攻击者,NIDS将可疑数据包重定向至蜜罐系统中。蜜罐记录下攻击者的行为,进行远程备份,并通过恢复模块保证整个系统处于安全状态。
According to the defects of NIDS and the advantages of honeypot ,a model of cooperation system of honeypot and NIDS is introduced in this paper. Honeypots attract the attackers,then NIDS redirect the suspicious packets to honeypot system .Honeypots record the action of attackers to the Remote Log Server, and remain safe state by the recovery module.
出处
《电脑知识与技术》
2006年第8期58-58,94,共2页
Computer Knowledge and Technology