计算机工程与应用 ›› 2019, Vol. 55 ›› Issue (1): 109-114.DOI: 10.3778/j.issn.1002-8331.1709-0175

• 网络、通信与安全 • 上一篇    下一篇

一种基于拟态防御机制的SDN虚拟蜜网

廉  哲,殷肖川,席  茜,谭  韧   

  1. 空军工程大学 信息与导航学院,西安 710077
  • 出版日期:2019-01-01 发布日期:2019-01-07

SDN Virtual Honeynet Based on Mimic Defense Mechanism

LIAN Zhe, YIN Xiaochuan, XI Xi, TAN Ren   

  1. Information and Navigation College, Air Force Engineering University, Xi’an 710077, China
  • Online:2019-01-01 Published:2019-01-07

摘要: 针对传统蜜网部署不方便,流量控制困难,蜜网动态调整较复杂的缺陷,利用SDN技术灵活的控制机制与容器高速、轻量的技术特性,设计了具有动态可调整特性的SDN虚拟蜜网,结合拟态防御机制为SDN虚拟蜜网提供动态调整的依据,并通过博弈论验证了基于拟态防御机制的SDN虚拟蜜网的有效性。利用Containernet仿真实验平台搭建出SDN虚拟蜜网,并设计实现了基于拟态防御机制的动态跳变,通过实验验证了该蜜网的可行性。

关键词: 软件定义网路, 拟态防御, 容器技术, 虚拟蜜网, 动态跳变

Abstract: The traditional honeynet has many drawbacks such as inconvenient deployment, difficult flow control and complex dynamic adjustment. SDN technology has flexible controlling mechanism and container with high speed and lightweight. A SDN virtual honeynet is designed by using these advantages. It will provide dynamic adjustment basis to SDN virtual honeynet by using the mimic defense mechanism. The effectiveness of the SDN virtual honeynet is verified based on the game theory. At last, the SDN virtual honeynet is established using Containernet simulation platform, and the dynamic jumping change is designed and implemented based on mimic defense mechanism. The feasibility of the honeynet is verified through experiments.

Key words: software defined networking, mimic defense, container technology, virtual honeynet, dynamic jump