首页> 外文期刊>Computing and informatics >Securing Distributed Computer Systems Using an Advanced Sophisticated Hybrid Honeypot Technology
【24h】

Securing Distributed Computer Systems Using an Advanced Sophisticated Hybrid Honeypot Technology

机译:使用先进的复杂混合蜜罐技术保护分布式计算机系统

获取原文
           

摘要

Computer system security is the fastest developing segment in information technology. The conventional approach to system security is mostly aimed at protecting the system, while current trends are focusing on more aggressive forms of protection against potential attackers and intruders. One of the forms of protection is also the application of advanced technology based on the principle of baits - honeypots. Honeypots are specialized devices aimed at slowing down or diverting the attention of attackers from the critical system resources to allow future examination of the methods and tools used by the attackers. Currently, most honeypots are being configured and managed statically. This paper deals with the design of a sophisticated hybrid honeypot and its properties having in mind enhancing computer system security. The architecture of a sophisticated hybrid honeypot is represented by a single device capable of adapting to a constantly changing environment by using active and passive scanning techniques, which mitigate the disadvantages of low-interaction and high-interaction honeypots. The low-interaction honeypot serves as a proxy for multiple IP addresses and filters out traffic beyond concern, while the high-interaction honeypot provides an optimum level of interaction. The proposed architecture employing the prototype of a hybrid honeypot featuring autonomous operation should represent a security mechanism minimizing the disadvantages of intrusion detection systems and can be used as a solution to increase the security of a distributed computer system rapidly, both autonomously and in real-time.
机译:计算机系统安全是信息技术中发展最快的部分。传统的系统安全方法主要是为了保护系统,而当前的趋势则集中在针对潜在攻击者和入侵者的更具攻击性的保护形式上。保护的一种形式也是基于诱饵原理的先进技术的应用-蜜罐。蜜罐是专用设备,旨在减慢攻击者的注意力或使其从关键系统资源中转移开来,以便将来检查攻击者使用的方法和工具。当前,大多数蜜罐都是静态配置和管理的。本文着眼于增强计算机系统安全性的复杂混合蜜罐的设计及其特性。复杂的混合蜜罐的体系结构以单个设备为代表,该设备可以通过使用主动和被动扫描技术来适应不断变化的环境,从而减轻了低交互性和高交互性蜜罐的缺点。低交互性蜜罐可以充当多个IP地址的代理,并过滤掉不必要的流量,而高交互性蜜罐则可以提供最佳交互级别。提出的采用具有自主运行功能的混合蜜罐原型的体系结构应代表一种安全机制,可最大程度地减少入侵检测系统的弊端,并且可以用作解决方案,以快速,自主和实时地提高分布式计算机系统的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号