计算机科学 ›› 2011, Vol. 38 ›› Issue (8): 121-124.

• 计算机网络与信息安全 • 上一篇    下一篇

蜜罐取证的技术及法律问题研究

王剑虹,何晓行   

  1. (西南政法大学法学院 重庆401120);(重庆邮电大学法学院 重庆400065)
  • 出版日期:2018-11-16 发布日期:2018-11-16
  • 基金资助:
    本文受西南政法大学校级重点项目((2010-XZZD25)资助。

Research on the Technical and Legal Issues of Collecting Evidence by Honeypot

WANG Jian-bong,He Xiao-xing   

  • Online:2018-11-16 Published:2018-11-16

摘要: 蜜罐作为新兴的网络防御及动态取证技术,不仅能够主动防御网络攻击,而且还可以收集入侵者实施攻击的重要证据。它通过网络欺骗、端口重定向、报警、数据控制和数据捕获等技术,增强动态防护体系的检测与反应能力,提高网络的安全防护水平。蜜罐运行会产生一定的技术风险,而选择低风险蜜罐、强化系统的数据获取和报警功能以及增加连接控制和路由控制等能有效实现风险控制。对于蜜罐取证可能产生的陷阱、隐私权及责任等法律问题,则可采取避免过度主动引诱、隐私权提示及审慎监控等方式加以克服。

关键词: 蜜罐,风险,欺骗,取证,责任

Abstract: Honeypot is a new kind of the defense technology, which can defend the Internet attack actively and collect the important evidence of the attackers. The techniques of realizing collecting evidence by honeypot include Internet deception, port reaction, data seizure, data analysis and data control etc, which help to improve the detection level and reactivity of dynamic protection system. Running honeypot may result in some technical risks, therefore, it is necessary to control the risks by choosing low-risk honcypot, intensifying data seizure and alarm function and increasing the link control and route control therefore etc. As to the legal problems, including entrapment, privacy right and liability, we can solve them by undue-temptation prohibition, privacy right hint and cautious supervision.

Key words: Honeypot, Risk, Deception, Collecting evidence, Liability

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!