计算机应用与软件2024,Vol.41Issue(10) :362-371.DOI:10.3969/j.issn.1000-386x.2024.10.053

面向欺骗防御的蜜网技术研究

DECEPTION DEFENSE ORIENTED HONEYNET TECHNIQUES

刘亚群 高雅卓 邢长友 张国敏
计算机应用与软件2024,Vol.41Issue(10) :362-371.DOI:10.3969/j.issn.1000-386x.2024.10.053

面向欺骗防御的蜜网技术研究

DECEPTION DEFENSE ORIENTED HONEYNET TECHNIQUES

刘亚群 1高雅卓 1邢长友 1张国敏1
扫码查看

作者信息

  • 1. 中国人民解放军陆军工程大学 江苏南京 210007
  • 折叠

摘要

蜜网通过构建诱捕环境并伪装成真实的业务网络来欺骗攻击者,吸引攻击者攻击,监控攻击者的行为并分析其特征,已经成为网络欺骗防御的核心手段.介绍蜜网的定义、分类与功能,在此基础上结合蜜网的攻击防护流程,按照欺骗场景生成部署、攻击诱捕、攻击行为分析、安全性增强等四种蜜网关键技术对现有研究成果进行分析归纳,详细讨论上述关键技术的作用及其研究进展,总结分析现有蜜网研究存在的问题与不足,展望未来的发展趋势和面临的挑战.

Abstract

Honeynet deceives the attackers by constructing a trapping environment and masquerading as a real business network.Attracting attackers,monitoring attackers'behavior and analyzing their characteristics have become the trump card of network deception defense.The definition,classification and functions of honeynets were introduced.On this basis,combining the attack protection process of honeynets,the existing research results were analyzed and concluded according to the key technologies of honeynets,such as generation and deployment of deception scenarios,attack trapping,attack behavior analysis,and security enhancement.In addition,the effect and research progress of the above-mentioned key technologies were discussed in detail and the existing problems and shortcomings in the existing honeynet research were summarized.The development trend and challenge in the future were prospected.

关键词

蜜网/欺骗防御/网络攻击/蜜罐

Key words

Honeynet/Deception defense/Cyber attack/Honeypot

引用本文复制引用

基金项目

国家自然科学基金项目(61379149)

国家博士后科学基金项目(2017M610296)

出版年

2024
计算机应用与软件
上海市计算技术研究所 上海计算机软件技术开发中心

计算机应用与软件

CSTPCD北大核心
影响因子:0.615
ISSN:1000-386X
段落导航相关论文