论文部分内容阅读
针对当前互联网客户端攻击频发的态势,首先阐述了基于本地程序漏洞的客户端攻击概念,着重讲解了网站挂马攻击的特征。其次阐明了客户端蜜罐系统的基本原理,并介绍了一种高效的客户端蜜罐系统HoneyClient。随后通过对网站挂马攻击的特征分析提出了使用HoneyClient对其进行有效检测的方案,并对该方案进行了事实验证。最后通过对实验结果的分析与总结,提出了对网页木马型客户端攻击进行检测的改进策略和展望。
In view of the current situation of frequent attacks on Internet clients, the concept of client attacks based on local program vulnerabilities is expounded firstly, and the characteristics of the attacks on websites are mainly explained. Secondly, it clarifies the basic principle of client honeypot system and introduces HoneyClient, an efficient client honeypot system. Then through the analysis of the characteristics of the web site hanged attack, this paper puts forward the scheme of using HoneyClient to detect it effectively, and verifies the scheme. Finally, through the analysis and conclusion of the experimental results, this paper proposes an improved strategy and prospect for detecting Trojan attacks on web pages.