摘要
网络攻击流重定向是蜜场中的关键技术之一。文中对其机制进行了研究,提出了基于网络环境信息自动感知技术与入侵检测技术相结合的网络攻击检测机制,以及基于OpenVPN与策略路由的透明网络流重定向机制,并实现了一个基于上述机制的网络攻击流重定向系统,最后通过实验验证了系统的有效性。
Network attack flow redirection is a key technology in honeyfarm, this paper focuses on the research of its mechanism. We propose a mechanism to detect network attack, based on the combination of the network environment information auto-apperceiving technology and the intrusion detection technology, and present annother mechanism of network flow transparent redirection based on OpenVPN and strategy routing. Moreover, a network attack flow redirection system based on the proposed mechanism is accom-plished. Finally, some experiments are performed and the results verify the effectiveness of the system.
出处
《南京邮电大学学报(自然科学版)》
2009年第3期14-20,共7页
Journal of Nanjing University of Posts and Telecommunications:Natural Science Edition
基金
国家高技术研究发展计划(863计划)(2006AA01Z445)
高等学校博士学科点专项科研基金(200800011019)资助项目
关键词
网络流重定向
非业务访问
网络环境信息自动感知
蜜场
蜜罐
network flow redirection
non-service visit
network environment information auto-apperceiring
honeyfarm
honeypot