信息网络安全 ›› 2022, Vol. 22 ›› Issue (4): 40-48.doi: 10.3969/j.issn.1671-1122.2022.04.005

• 技术研究 • 上一篇    下一篇

一种基于动态Docker的SDN蜜网设计与实现

张伟1(), 徐智刚2, 陈云芳1, 黄海平1   

  1. 1.南京邮电大学计算机学院,南京 210023
    2.中通服咨询设计研究院有限公司,南京 210019
  • 收稿日期:2021-10-26 出版日期:2022-04-10 发布日期:2022-05-12
  • 通讯作者: 张伟 E-mail:zhangw@njupt.edu.cn
  • 作者简介:张伟(1973—),男,江苏,教授,博士,主要研究方向为网络信息安全、恶意代码分析、社会网络分析|徐智刚(1988—),男,江苏,硕士,主要研究方向为信息安全|陈云芳(1976—),男,江苏,副教授,博士,主要研究方向为社会计算、信息网络安全|黄海平(1981—),男,福建,教授,博士,主要研究方向为物联网技术、网络安全、数据隐私保护技术
  • 基金资助:
    国家自然科学基金(62072252);国家重点研发计划(2019YFB2101701)

Design and Implementation of a SDN Honeynet Based on Dynamic Docker

ZHANG Wei1(), XU Zhigang2, CHEN Yunfang1, HUANG Haiping1   

  1. 1. School of Computer Science, Nanjing University of Posts and Telecommunications, Nanjing 210023, China
    2. China Information Consulting & Designing Institute co., LTD, Nanjing 210019, China
  • Received:2021-10-26 Online:2022-04-10 Published:2022-05-12
  • Contact: ZHANG Wei E-mail:zhangw@njupt.edu.cn

摘要:

面对近年来越来越高级和组织化的黑客攻击,传统防护手段愈发力不从心。蜜网作为一种主动防御技术,在捕获和分析恶意行为方面发挥着不可替代的作用。现有蜜网技术无法实现细化粒度数据控制,蜜罐系统部署复杂,资源消耗大,文章结合Docker和SDN技术,设计并实现了一种基于动态Docker的SDN蜜网。在保证各蜜罐系统相互隔离的前提下,降低蜜网部署难度,减少资源消耗并实现资源的动态分配;同时使用SDN技术进行数据转发与控制解耦,有效实现数据流的灵活控制。

关键词: SDN蜜网, 主动防御, 动态Docker, 快速部署

Abstract:

In recent years, facing with more and more advanced and organized hacker attacks, the traditional means of protection are often inadequate. Honeynet is an active defense technology, which is playing an increasingly important role in capturing and analyzing malicious traffic and even unknown attack behavior. Aiming at the problem that the existing honeynet technology can not realize fine-grained data control and the deployment of honeypot system in honeynet is complex as well as the resource consumption is large, this paper designs and implements a SDN Honeynet by combining Docker with SDN technology. Under the premise of ensuring that the honeypot systems are isolated from each other, Docker technology simplifies and reduces the difficulty of Honeynet deployment, reduces resource consumption and realizes the dynamic allocation of resources. At the same time, SDN technology is used to decouple data forwarding and control, which effectively realizes flexible control of data flow. Experiment results showed that the proposed Honeynet architecture is of great value in large-scale rapid deployment scenarios with high degree of automation.

Key words: SDN honeynet, active defense, dynamic Docker, rapid deployment

中图分类号: