|
With the rapid development of Internet, and now we work other aspects of life are inseparable from the support of the network. Internet a lot of popularity, network security has become a hot issue in the community, because the network failures, security information leaks and other issues of national security, economic development, social stability and so has a great impact. Common network threats are: the destruction or loss of resources, information leakage, service interruptions and even system crash. In order to deal with the network in the face of various threats and attacks, people use a variety of security technologies to protect their networks, are: authentication, encryption, firewall, intrusion detection, access control, the trusted services, backup recovery. The intrusion detection technology is a key technology in network protection, intrusion detection systems (IntrusionDetectionSystem, IDS) information security has become a very important part of the system, but the traditional IDS is used mainly passive defense technology, for the moment due to changes in the network invasive means seemed more difficult. How to make the IDS defense system consists of static to dynamic, from passive defense to active detection, this paper proposes the use of virtual honeypot technology to assist IDS, which can detect network traffic to reduce the load of IDS, as well as generate IDS new features rules to improve network security defense system performance and detection efficiency. Main innovation is to ensure overall system performance under the premise of using virtual honeypots IDS rules generation features a timely manner, which is a key issue related strategies, in addition to this intrusion deception detection system can be monitored in real-time network status on the page, which greatly facilitates the user. Main work topics: Understanding intrusion detection systems, Honeypot (honeypots) the history and current status, and then through open source software Snort and Honeyd, in-depth analysis of intrusion detection technology and virtual honeypot technologies and use them to design a joint initiative invasion deception detection system. Mainly using virtual honeypot Honeyd plug Honeycomb Snort intrusion detection system for the automatic generation of attack signatures, thereby reducing the risk of intrusion detection systems omissions, improve overall system performance. Finally, specific experiments, to build the Snort Intrusion Deception Honeyd based detection systems, and the experimental data and the results were analyzed, a better understanding of the principles of which verify the correctness of the view.
|