Research and Implement of Network Deception System Based on Network/host Copy

LAI Hai-ming,ZHANG Jian-zhong
DOI: https://doi.org/10.3969/j.issn.1000-7024.2007.09.009
2007-01-01
Abstract:Current network deception technologies are analyzed and compared.On the basis of adopting network/host copy scheme,a kind of data captured method based on Linux dynamic process shared library injection is proposed.This system is divided into deception client and server.The client is responsible for capturing and sending data;the server will store and display them either on command line or on graphic UI.This system also adopts some technologies such as communications between user space and kernel space,sending package from kernel mode,kernel module hiding,etc.
What problem does this paper attempt to address?