Honeynet based distributed adaptive network forensics and active real time investigation.

Wei Ren,Hai Jin
DOI: https://doi.org/10.1145/1066677.1066749
2005-01-01
Abstract:ABSTRACTNetwork forensics and honeynet systems have the same features of collecting information about the computer misuses. Honeynet system can lure attackers and gain information about new types of intrusions. Network forensics system can analysis and reconstruct the attack behaviors. These two systems integrating together can help to build an active self-learning and response system to profile the intrusion behavior features and investigate the attack original source. In this paper, we present a design of honeynet based active network intrusion response system. The features of our system are distributed adaptive network forensics and active real time network investigation.
What problem does this paper attempt to address?