蜜罐技术是信息安全保障的研究热点与核心技术。对近年来蜜罐技术的研究进展进行了综述评论。剖析了蜜罐和蜜网的定义,根据系统功能、系统交互活动级别、服务实现方式、服务提供方式对蜜罐进行分类和比较,根据服务提供方式对蜜网进行了分类和比较,分析了各类系统的优缺点。指出了现阶段该技术存在的主要问题,并讨论了这些问题可能采取的方法。系统动态自适应、分布式蜜罐体系结构、多源信息融合、攻击特征自动提取及计算机取证等是蜜罐技术重要的发展方向。
Honeypot technique is one of the hotspots and key techniques in information assurance. After analyzing the recent researches in the domain of honeypot technology, the definition and categories of honeypot are expatiated. Based on varied features honeypot, honeynet are classified and analyzed. A review on current key techniques in honeypot together with their advantages and disadvantages is provided. At last, the challenges ofhoneypot are outlined and the main prospects ofhoneypot technique for future improvement are system auto-adaptation, distributed architecture, multi-resource information fusion, automatic extraction of attack signature and computer forensics.