摘要
NIDS在检测网络入侵行为时面临的难题是错报、漏报和数据整合,Honeypot很好地解决了这几个问题,是NIDS的有益补充。论文分析探讨了基于Honeypot的网络入侵行为检测、捕获、预警的相关技术,在此基础上给出一个基于Honeypot的网络入侵行为捕获模型。实验证明了这个模型在捕获网络入侵行为过程中的有效性和适用性。
The difficulty of detecting the intrusion with NIDS lies as error-warning, miss-warning and integrity of data. The Honeypot is a good method on this problem. The paper discusses the technique of detecting, capturing and warning the network intrusion, given the model of capturing intrusion base on it. The experimentation proved it worked.
出处
《信息安全与通信保密》
2006年第11期132-134,共3页
Information Security and Communications Privacy