论文部分内容阅读
传统取证技术大多为事后取证、静态取证,这种取证方式存在效率低、有效性差、数据保留不完整等问题。与攻击者在技术层面比较,取证工作处于信息获取不对称的位置,采用蜜罐及蜜罐网技术在一定程度上可以弥补数字取证上的不足。本文就网络主动防御性取证技术进行了研究,从目前取证技术存在的不足出发,逐步引出一个相对较完善的蜜罐及蜜罐网架构解决方案。
Most of the traditional forensics technology is evidence-based and static forensics. This method of forensics has the problems of low efficiency, poor validity and incomplete data retention. Compared with the attackers in the technical level, the forensics work is in an asymmetric position for information acquisition. Using honeypot and honeypot technology can make up for the deficiency of digital forensics to a certain extent. In this paper, the network active defensive forensics technology was studied, starting from the current lack of evidence-based technology, and gradually lead to a relatively complete honeypot and honeypot network architecture solutions.