论文部分内容阅读
蜜罐是一种精心设计的诱骗系统,只有受到攻击,它的价值才能发挥出来。在网络证据的收集中,蜜罐技术可以采取主动的方式,用特有的特征吸引攻击者,同时对攻击者的各种攻击行为进行收集并分析获取最有效的犯罪信息。另外,蜜罐技术收集数据的保真度高并且不需要强大的资源支持,这使通过蜜罐收集网络证据的必要性和可行性得到了保障。在其证据效力上,蜜罐技术与机会提供型诱惑侦查具有一定的相似性,但它不存在法律意义上的引诱,它只是一个存在漏洞、与其他计算机系统无异虚假系统,并无主动引诱任何人对其进行攻击同时,从证据的法律属性上分析,它符合证据的三性,故蜜罐收集到的网络证据可以作为诉讼证据使用。
A honeypot is a well-designed decoy that can only be played out if it is attacked. In the collection of network evidence, honeypot technology can take the initiative to attract attackers with unique characteristics, and at the same time, collect and analyze various attack behaviors of attackers to obtain the most effective criminal information. In addition, the honeypot technology collects data with high fidelity and does not require strong resource support, which guarantees the necessity and feasibility of collecting cyber evidence through honeypots. In terms of its evidence validity, honeypot technology has some similarities with opportunistic offer temptation detection, but it has no legal temptation. It is only a loophole and has no false system with other computer systems and has no active seduction Anyone attacking him at the same time, from the legal attributes of the evidence, it is in accordance with the nature of the evidence, so the network evidence collected by honeypot can be used as evidence.