Font Size: a A A

Research And Implementation Of Honeypot Based On Redirection Mechanism

Posted on:2009-03-10Degree:MasterType:Thesis
Country:ChinaCandidate:X X PanFull Text:PDF
GTID:2178330332988692Subject:Computer application technology
Abstract/Summary:
As assault being more and more, especially new security holes and their attacks constantly issued, network security receives the serious threat. Traditional security practice such as firewall, intrusion detection system can't well prevent network system from new security holes and attacks, so the problem of detecting them has already become the difficult point. The technology of honeypot has offered the foundation for capturing and analyzing in depth intrusion behavior in the face of the serious security threat day by day. Honeypot was used to resolve the problem of detecting unknown attacks. But it will bring maximum hidden peril of the security if we improper dispose honeypot system.So, combines the work reality of network security, the paper studies "Intrusion Deception System". in this paper, elaborates on the technique theory of Intrusion Detection System(IDS) and the traditional honeypot technique for realizing the system, analyses the technique and tactics realized based on redirection; proposes an active redirection-based prevention model of Intrusion Deception System which combines intrusion detection and honeypot technology; analyses the architecture of Intrusion Deception system and the theory, finished the system design; and put emphasis on the implementation procedure of IDS module, honeypot system module, redirection module and data trapping module, and also gave some demonstrations of segment interface. At last, testing design and testing report are proposed.Through the experiment and practical effect use of, this system may increase the capacity of detecting unknown attacks, reduce false positives and negatives for the information; wide vision and raise using efficiency of honeypot; prolong the period of the attackers are held up in honeypot therefore may protect the computer; analyzing intrusion data will offered the foundation for safe tactics; reduce the possibility that honeypot system become the access board to attack third party.Next, we will add the interaction between honeypot system and other security products. This model will join various security techniques; give a safe and practical active defense system model.
Keywords/Search Tags:Network security, Honeypot, IDS, Redirection
Related items