为有效防范蠕虫传播所带来的日益严峻的安全威胁,主动防护技术一分布式蜜网被应用到网络中以保障网络安全。分布式蜜网下的蜜罐对蠕虫表现出强诱骗性和“宽进严出”的数据控制策略等特性,影响到蠕虫的传播及控制。基于双因子模型,考虑到分布式蜜网下的蜜罐特性和Internet的无标度网络特性,提出基于分布式蜜网的蠕虫传播模型,并进行了分析;通过模拟实验对模型进行验证,以探讨部署分布式蜜网下的蠕虫传播规律。实验结果表明,部署分布式蜜网不但能第一时间捕获蠕虫样本,而且能减少网络中感染蠕虫主机总数、具备感染能力的最大主机数等、缓蠕虫感染速度等,对于加强蠕虫预警、遏制蠕虫大范围传播等具有重要作用。
In order to prevent serious threat posted by worm rapid propagation, used active security technology-distributed ho- neynet in ensuring the safety of network. The honeypot host under distributed honeynet performed high inveiglement to worms and possesses "come in easily, out strictly" data control policy, this influenced worm propagation and control. Considering the scale-free characters in topology structure and the characters of honeypot host, this paper presented a worm propagation model in the network which distributed honeynet have been deployed based on two-factor model, and gave a analysis to it. At last, validated the correctness of model over simulation experiment, and discussed worm propagation trend in the network that distributed honeynet had been deployed. Experiment result indicates that distributed honeynet not only can capture worm sample in time, but also can reduce the total number of infected hosts and the number of largest infectious hosts, slow down the speed of worm infection, it is of great significance in strengthen worm warning and prevent worm from spreading in large-scale networks.