首页> 外文会议>Saudi Computer Society National Computer Conference >Hybrid System Between Anomaly Based Detection System and Honeypot to Detect Zero Day Attack
【24h】

Hybrid System Between Anomaly Based Detection System and Honeypot to Detect Zero Day Attack

机译:基于异常的检测系统和蜜罐之间的混合系统以检测零日攻击

获取原文

摘要

Honeypots are systems designed to lure the potential attacker to a real system by make him busy with emulated system. Its primary objective is gathering information about the attacker as possible to avoid any future similar attacks. Another method for protecting the systems against attacks is anomaly based detection system, where its main goal is to monitor the traffic to detect any known worm behavior based on the previous knowledge of the environment. In this paper, we will mention some techniques to avoid Zero day attacks. Then we will analyze the strengths and weakness of both approaches that are honeypot and anomaly based detection. As a result, to integrate both approaches in one hybrid model as enhanced solution of detecting the Zero day attack that may occur in the system.
机译:蜜罐是一种旨在通过使潜在的攻击者忙于仿真系统来吸引潜在攻击者的系统。其主要目标是尽可能收集有关攻击者的信息,以避免将来发生任何类似的攻击。保护系统免受攻击的另一种方法是基于异常的检测系统,其主要目标是基于对环境的先前了解,监视流量以检测任何已知的蠕虫行为。在本文中,我们将提到一些避免零日攻击的技术。然后,我们将分析两种基于蜜罐和基于异常的检测方法的优缺点。结果,将这两种方法都集成在一个混合模型中,作为检测系统中可能发生的零日攻击的增强解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号