摘要
在分析国内外研究现状的基础上,针对目前蜜罐技术应用中存在的问题,提出了一种基于蜜罐的分布式容侵防御模型,并在模型中设计权限状态监控和基于匹配度的检测算法。测试实验证明,该模型能够弥补当前蜜罐技术应用的不足,辅助IDS提高威胁检测的准确度,有效地增强网络的容侵能力和生存能力。
On the basis of domestic and overseas research,the article puts forward a distributed intrusion tolerance resisting model based on honey pot according to problems existing in the current application of honey pot technology,and designs authority status monitoring and detection algorithm based on matching in the model.Test experiment proves that the model can make up the deficiency in the application of honey pot technology,enhance the accuracy of threat detection of IDS,and effectively lift the intrusion tolerance capacity and existence capacity of network effectively.
基金
陕西省自然科学基金项目(07JK339)
关键词
蜜罐
分布式
容侵防御
匹配度
honey pot
distribution
intrusion tolerance resisting
matching