面向欺骗防御的蜜网技术研究

DECEPTION DEFENSE ORIENTED HONEYNET TECHNIQUES

  • 摘要: 蜜网通过构建诱捕环境并伪装成真实的业务网络来欺骗攻击者,吸引攻击者攻击,监控攻击者的行为并分析其特征,已经成为网络欺骗防御的核心手段。介绍蜜网的定义、分类与功能,在此基础上结合蜜网的攻击防护流程,按照欺骗场景生成部署、攻击诱捕、攻击行为分析、安全性增强等四种蜜网关键技术对现有研究成果进行分析归纳,详细讨论上述关键技术的作用及其研究进展,总结分析现有蜜网研究存在的问题与不足,展望未来的发展趋势和面临的挑战。

     

    Abstract: Honeynet deceives the attackers by constructing a trapping environment and masquerading as a real business network. Attracting attackers, monitoring attackers' behavior and analyzing their characteristics have become the trump card of network deception defense. The definition, classification and functions of honeynets were introduced. On this basis, combining the attack protection process of honeynets, the existing research results were analyzed and concluded according to the key technologies of honeynets, such as generation and deployment of deception scenarios, attack trapping, attack behavior analysis, and security enhancement. In addition, the effect and research progress of the above-mentioned key technologies were discussed in detail and the existing problems and shortcomings in the existing honeynet research were summarized. The development trend and challenge in the future were prospected.

     

/

返回文章
返回