首页> 外文OA文献 >Design and Implementation of a Low-Cost Low Interaction IDS/IPS System Using Virtual Honeypot Approach
【2h】

Design and Implementation of a Low-Cost Low Interaction IDS/IPS System Using Virtual Honeypot Approach

机译:使用虚拟蜜罐方法的低成本低交互性IDS / IPS系统的设计与实现

摘要

Network attacks have become prominent in the modern-day web activities and the black hat community have also gain more sophistication with the tools used to penetrate poorly guarded or unguarded networks. Network security administrators have also moved swiftly to counter the threats posed by the attacker with different network intrusion detection and monitoring tools. Low interaction honeypots were developed to entice hackers without causing any serious downtime to the production network, so that their activities and the way they access the network can be studied with a minimal setup cost. In this work, a low interaction virtual honeypot using the Honeyd daemon to lure attackers to the network and alert the attacker's activities in the network using the Snort IDS. The data captured is analysed based on the protocol and port used. It is then validated by analysing the attacker's activities once it is logged and accessed through Wireshark protocol analyser.
机译:在当今的网络活动中,网络攻击已变得十分重要,并且黑帽社区还利用用于渗透防护不完善或不受防护的网络的工具而变得更加成熟。网络安全管理员也已迅速采取行动,以使用不同的网络入侵检测和监视工具来应对攻击者所构成的威胁。低交互性蜜罐的开发是为了诱使黑客而又不会导致生产网络严重停机,因此可以以最小的设置成本研究其活动和访问网络的方式。在这项工作中,使用Honeyd守护程序的低交互性虚拟蜜罐通过Snort IDS诱使攻击者进入网络并警告网络中的攻击者活动。根据所使用的协议和端口来分析捕获的数据。一旦通过Wireshark协议分析器记录和访问攻击者的活动,就可以通过分析攻击者的活动来对其进行验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号