Intrusion Detection Using Honeypots

Intrusion Detection Using Honeypots
复制标题

使用蜜罐进行入侵检测

DOI:
--
复制
发表时间:
2018
期刊:
2018 Fifth International Conference on Parallel, Distributed and Grid Computing (PDGC)
影响因子:
--
通讯作者:
B. Arora
B. Arora
中科院分区:
--
文献类型:
--
作者:
Neeraj Bhagat;B. Arora

文献摘要

被引文献

相似文献

网络安全成为每个组织的首要任务,以保护其免受任何类型的网络攻击。为此,在网络中旅行的流量分析是一项势在必行的任务。通过安装各种网络入侵检测(NID)设备,对网络进行流量分析。蜜罐是检测网络入侵的一种非常重要的设备。蜜罐与攻击者交互并收集数据,这些数据可以被分析以检索关于网络中的攻击和攻击者的信息。蜜罐是攻击者的目标,并生成攻击的数据日志的安全资源。蜜罐提供少量的相关数据,使安全研究人员能够容易地理解和分析数据变得可行。本文模拟蜜罐与攻击者进行交互,并使用各种工具分析蜜罐收集的数据。
Security of network becomes primary importance of every organization to protect it from any kind of cyber attack. For this, the analysis of traffic that travels in the network is an imperative task. Traffic analysis on network is done by installing various network intrusion detection (NID) devices. One of a very vital device for detecting network intrusions is a Honeypot. Honeypots interact with the attacker and collect the data which can be analyzed to retrieve information regarding the attacks and attacker in the network. Honeypots are security resources that are targeted by the attacker and generate data logs of the attacks. Honeypots provide relevant data in a small quantity so that security researchers could easily understand and the analysis of the data becomes feasible. In this paper honeypot is simulated to interact with attackers and the data collected by using honeypot is analyzed using various tools.