基于伪装网络服务监测跟踪攻击行为及过程,可以有效研究发现未知攻击方式及其特征。为使伪装网络服务能够自动响应不确定的攻击探测行为,引入了网络服务伪装自动响应模型。该模型对网络会话进行自学习生成状态机,利用经过特征提取的状态机进行模式匹配,进而构造网络会话响应内容。同时利用基于有色事件驱动状态变迁的思想对响应过程进行控制。实验结果验证了该模型的有效性。
Monitoring and tracking attacks and its processes based on network service camouflaging can find out unknown attack and its characters.In order to response uncertain attacks automatically, automatic response model of network service camouflaging is introduced.This model builds state machine through self-learning from network services.Then it uses the ex- tracted state machine to do the pattern matching and then constructs the content of the response.At the same time,the idea of CEST(Colored Event-driven State Transition) is introduced to control the response process.The experimental results verify the validity of this model.