A Dynamic Honeypot Design for Intrusion Detection

A Dynamic Honeypot Design for Intrusion Detection
复制标题

DOI:
10.1109/perser.2004.1356776
复制
发表时间:
2004
期刊:
The IEEE/ACS International Conference on Pervasive Services
影响因子:
--
通讯作者:
I. Kuwatly;M. Sraj;Z. Al Masri;H. Artail
I. Kuwatly;M. Sraj;Z. Al Masri;H. Artail
中科院分区:
其他
文献类型:
--
作者:
I. Kuwatly;M. Sraj;Z. Al Masri;H. Artail

文献摘要

被引文献

相似文献

蜜罐技术是入侵检测领域的一项现代技术,它与普通的入侵防御系统不同,它倾向于为攻击者提供成功攻击所需的所有必要资源。蜜罐提供了一个研究入侵者(黑帽社区)使用的方法和工具的平台,从而从未经授权使用其资源中获取其价值。本文讨论了动态蜜罐的设计,动态蜜罐是一种能够适应动态和不断变化的网络环境的自主蜜罐。动态蜜罐方法集成了被动或主动探测和虚拟蜜罐。这种方法解决了部署和配置虚拟蜜罐的挑战。
A modern technology in the area of intrusion detection is honeypot technology that unlike common IDSs tends to provide the attacker with all the necessary resources needed for a successful attack. Honeypots provide a platform for studying the methods and tools used by the intruders (blackhat community), thus deriving their value from the unauthorized use of their resources. This paper discusses the design of a dynamic honeypot, which is an autonomous honeypot capable of adapting in a dynamic and constantly changing network environment. The dynamic honeypot approach integrates passive or active probing and virtual honeypots. This approach addresses the challenge of deploying and configuring virtual honeypots.