Next-Generation Honeynet Technology with Real-Time Forensics for U.S. Defense

Next-Generation Honeynet Technology with Real-Time Forensics for U.S. Defense
复制标题

DOI:
10.1109/milcom.2007.4455171
复制
发表时间:
2007-10
期刊:
MILCOM 2007 - IEEE Military Communications Conference
影响因子:
--
通讯作者:
Alen Capalik
Alen Capalik
中科院分区:
其他
文献类型:
--
作者:
Alen Capalik

文献摘要

被引文献

相似文献

高交互蜜网是一种非凡的入侵情报工具。不幸的是,他们的力量付出了巨大的代价。取证分析可能是繁琐的,劳动密集型的,管理负担通常是繁重的,并且被破坏的蜜网存在被用来进行进一步攻击的风险。简而言之,这些高度互动的智能工具缺乏操作灵活性。我们提出了一种新的方法蜜罐体系结构,结合虚拟化,低层次的内省,签名生成和取证分析的进步,构建一个实时的,高交互的入侵智能和预防工具。
High-interaction honeynets are extraordinary intrusion intelligence tools. Unfortunately, their power has come at a significant cost. Forensic analysis can be cumbersome and labor intensive, management burdens are often onerous, and compromised honeynets present a risk of being used to stage further attacks. In short, these high-interaction intelligence tools have lacked operational agility. We present a novel approach to honeypot architecture that combines advances in virtualization, low-level introspection, signature generation, and forensic analysis to construct a real-time, high-interaction intrusion intelligence and prevention tool.