当前网络安全形势日益严峻,传统的安全技术如防火墙、入侵检测技术存在着对未知入侵模式的攻击不能有效识别等诸多缺陷,Honeypot技术作为一种网络主动防御的安全技术,也具有一定的局限性。针对以上单一技术在网络安全防御上的缺陷,从主动防御的角度,基于网络主动防御安全模型构建了入侵诱骗系统的体系结构,并且设计了Honeypot与防火墙、IDS的联动系统,既克服了防火墙不能提供实时检测的缺陷,又降低了IDS的漏报率和误报率,弥补了各自的不足,充分发挥了优势,从而提高了网络系统的主动防御能力。同时,给出了有限自动机模型,模拟了入侵诱骗系统的基本功能,为系统的行为描述和结构设计提供了理论依据和论证。
The situation of present network security is becoming rigorous day by day,the traditional security technologies such as firewall,intrusion detective system have some kinds of defects,that is,they cannot identify the unknown intrusion pattern effectively,the honeypot technology as a proactive defense method also has its own limitations.As to the defaults of the above every single technology and from the angle of active defense,the paper builds up an Intrusion deception architecture based on network active defensive security model,and simultaneously designs an interface system among the honeypot,firewall and the IDS to overcome the default that the firewall can not perform unreal time detection.This can decrease the false alarm and leaking alarm of IDS,make up the deficiency and unleash the superior of each method,thus,the proactive defense capacity of the network systems is enhanced.The paper also gives out a finite state auto-machine model,simulates the basic functions of the intrusion deception system,which provide a theory and reasoning supplement for the system's action description and architecture design.