Next-Generation Honeynet Technology with Real-Time Forensics for U.S. Defense
Next-Generation Honeynet Technology with Real-Time Forensics for U.S. Defense
复制标题
DOI:
10.1109/milcom.2007.4455171
复制
发表时间:
2007-10
期刊:
影响因子:
--
通讯作者:
Alen Capalik
中科院分区:
文献类型:
--
作者:
Alen Capalik
High-interaction honeynets are extraordinary intrusion intelligence tools. Unfortunately, their power has come at a significant cost. Forensic analysis can be cumbersome and labor intensive, management burdens are often onerous, and compromised honeynets present a risk of being used to stage further attacks. In short, these high-interaction intelligence tools have lacked operational agility. We present a novel approach to honeypot architecture that combines advances in virtualization, low-level introspection, signature generation, and forensic analysis to construct a real-time, high-interaction intrusion intelligence and prevention tool.