摘要
网络攻击手段的多样性和攻击行为的动态性,给网络安全防御带来了困难。在基于免疫危险理论的入侵检测系统基础上,结合蜜罐技术和重定向机制,提出一个蜜罐和免疫入侵检测系统联动模型。介绍该模型的功能模块构成,分析检测器和危险信号相关机制。与其他模型相比,该模型具有主动性、动态性和低漏报率等优点。
The multiplicity of the network attack method and the dynamic of the network aggressive behavior bring difficulties to network security defense.Presents a linkage model of honeypot and immune intrusion detection system based on immune danger theory intrusion detection system, combining the redirection mechanism and honeypot technology.Introduces the function modules in details and analyses some mechanisms related to the detector and the danger signal.Comparing with other intrusion detection system,this module has many advantages,such as initiative,dynamic,lower false positive rate and so on.
出处
《现代计算机》
2011年第4期77-80,共4页
Modern Computer
基金
内蒙古高等院校重点项目(No.NJ10162)
内蒙古自然科学基金资助项目(No.2010BS0904)
关键词
蜜罐
免疫危险理论
入侵检测系统
联动
Honeypot
Immune Danger Theory
Intrusion Detection System
Linkage