摘要
针对现有蜜罐检测技术的特定性太强,通用性不足的缺点,通过研究分析不同蜜罐的工作原理,设计了一种基于资源争夺特征的蜜罐检测方法.它能够利用蜜罐之间普遍存在的资源争夺共性特征检测出各种不同的蜜罐系统,具有较好的通用性和准确性.通过设计并实施相应的实验方案,验证了这种方法的有效性.
With the extensive use of the new proactive technologies--honeypots, a growing number of organiza- tions and individuals begin to study the honeypot detection technology. The honeypot detection is important to find the weakness of the honeypot and improve the honeypot technology. In this paper, we firstly study the currently available honeypot detection technology, and find that they are lack of universality. Apart from that, we propose a honeypot de- tection method based on resource contention characteristics which can detect a variety of honeypots. In addition, we perform an experiment to verify its effectiveness. At last, we point out the shortcomings and put forward the impro- ving direction of this detection method.
出处
《武汉大学学报(理学版)》
CAS
CSCD
北大核心
2013年第3期272-276,共5页
Journal of Wuhan University:Natural Science Edition
基金
国家自然科学基金项目(60903196
61272451)
国家重大专项(2010ZX03006-001-01)
江西省教育厅科研课题(GJJ10661)
关键词
蜜罐检测
资源争夺
共性特征
主动防御
honeypot detection
resource contention
common characteristics
proactive defense