论文部分内容阅读
论文主要针对蜜罐技术中日志分析的薄弱环节,引入了日志分析工具Log Parser,利用Log Parser支持众多日志格式的输入和输出,能够对不同日志格式进行统一和数据融合,并提供灵活的日志过滤规则的自定义,研究了运用Log Parser来分析蜜罐日志进行主动防御的方法和优势。同时,对于日志分析技术来说,蜜罐日志的低噪声级别让日志分析结果更加准确有效。
This dissertation focuses on the weaknesses of log analysis in honeypot technology. Log Parser, a log analysis tool, is used to support the input and output of many log formats with Log Parser. It can unify different log formats and merge data and provide flexible log filtering Rules customization, studied the methods and benefits of using Log Parser to analyze honeypots for proactive defense. At the same time, the low noise level of honeypot logs makes log analysis more accurate and effective for log analysis techniques.