Netinfo Security ›› 2022, Vol. 22 ›› Issue (4): 40-48.doi: 10.3969/j.issn.1671-1122.2022.04.005

Previous Articles     Next Articles

Design and Implementation of a SDN Honeynet Based on Dynamic Docker

ZHANG Wei1(), XU Zhigang2, CHEN Yunfang1, HUANG Haiping1   

  1. 1. School of Computer Science, Nanjing University of Posts and Telecommunications, Nanjing 210023, China
    2. China Information Consulting & Designing Institute co., LTD, Nanjing 210019, China
  • Received:2021-10-26 Online:2022-04-10 Published:2022-05-12
  • Contact: ZHANG Wei E-mail:zhangw@njupt.edu.cn

Abstract:

In recent years, facing with more and more advanced and organized hacker attacks, the traditional means of protection are often inadequate. Honeynet is an active defense technology, which is playing an increasingly important role in capturing and analyzing malicious traffic and even unknown attack behavior. Aiming at the problem that the existing honeynet technology can not realize fine-grained data control and the deployment of honeypot system in honeynet is complex as well as the resource consumption is large, this paper designs and implements a SDN Honeynet by combining Docker with SDN technology. Under the premise of ensuring that the honeypot systems are isolated from each other, Docker technology simplifies and reduces the difficulty of Honeynet deployment, reduces resource consumption and realizes the dynamic allocation of resources. At the same time, SDN technology is used to decouple data forwarding and control, which effectively realizes flexible control of data flow. Experiment results showed that the proposed Honeynet architecture is of great value in large-scale rapid deployment scenarios with high degree of automation.

Key words: SDN honeynet, active defense, dynamic Docker, rapid deployment

CLC Number: