首页> 外文期刊>Virus Bulletin >EVOLUTION FROM A HONEYPOT TO A DISTRIBUTED HONEY NET
【24h】

EVOLUTION FROM A HONEYPOT TO A DISTRIBUTED HONEY NET

机译:从蜜罐到分布式蜜网的演变

获取原文
获取原文并翻译 | 示例
       

摘要

Over the last few years worms and bots in particular have become a penetrating widespread threat. Anti-virus companies have developed better and better heuristic detection against these pests, but some are still slipping through. Therefore, the old method of adding signatures as soon as a new variant shows up remains very important. At a time when more than 40 new bot variants are appearing each day, it is extremely important to have a binary sample of each for analysis in house. A traditional honeypot that captures the latest variants is quite an efficient technique. However, a slight disadvantage of the technique is that most of the attacks will be from the same subnet and after a while you will be aware of all the bots around the honeypot, and fewer new variants will be discovered.
机译:在过去的几年中,蠕虫和僵尸程序已成为一种广泛渗透的威胁。反病毒公司已经开发出了越来越好的针对这些害虫的启发式检测方法,但其中一些仍在漏查。因此,一旦出现新的变体,添加签名的旧方法仍然非常重要。在每天出现40多种新的bot变体的时候,拥有每个样本的二进制样本以供内部分析是非常重要的。捕获最新变种的传统蜜罐是一种非常有效的技术。但是,该技术的一个小缺点是,大多数攻击将来自同一子网,过一会儿您将意识到蜜罐周围的所有僵尸程序,并且发现的新变种更少。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号