摘要
目前许多入侵检测系统基于被动防御,需要及时更新入侵检测规则库,否则将对最新的攻击产生漏报现象。而虚拟蜜罐系统基于主动防御,利用虚拟蜜罐软件Honeyd的插件Honeycomb可以为入侵检测系统自动生成攻击特征码,从而降低入侵检测系统的漏报几率。
Many instrusion detection system (IDS) are based on the passive defense currently, thus needs to renew the instrusion detection signatures in time.Otherwise, it will fail to report the latest attack. Virtual Honeypots are based on the active defense, which requires such Honeyd plug-in software named Honeycomb to create aggressive condition code for the IDS, dropping the rate of failing report.
作者
唐新玉
陈浩
TANG Xin-yu,CHEN hao (School of Computer and Communication,Hunan University,Changsha 410082,China)
出处
《电脑知识与技术》
2008年第8期716-717,共2页
Computer Knowledge and Technology