摘要
本文分析了蜜罐Honeyd的软件架构和扩展Honeyd的原理,提出了将蜜罐与入侵检测系统、防火墙联动起来协同工作的框架。该联动框架可以有效地为IDS添加未知攻击的新规则,并能有效阻断这些新型攻击,提高了管理效率。
This paper analyses the software configuration of Honeyd, and gives the principle about how to extend Honeyd, presents a framework to make honeypot IDS and firewall interact to work together. This framework is able to add new rules for unbeknown attack of IDS, it's also effective to hold back the new attack and improves the manage efficiency.
出处
《北京电子科技学院学报》
2006年第4期83-85,90,共4页
Journal of Beijing Electronic Science And Technology Institute
关键词
蜜罐
入侵检测
扩展:联动
Honeypot
Instruct Detection
Extension
Interaction