本文使用VMWare 以弱化系统方式在宿主机配置高交互的蜜罐系统。配置过程包括 安装虚拟操作系统、系统补丁和杀毒程序、系统监视、数据包捕获软件等。利用该系统捕获了一种网络病毒,通过对捕获到的蠕虫病毒的攻击过程的记录和分析,了解了其特征和网络病毒运行机制,为进一步采取防范措施提供参考。 关键词:虚拟机;弱化系统;蜜罐;蠕虫病毒 Abstract: Honeypot of high interactive weakened system is configured with VMWare on host. Configure progresses include installing of virtual OS, patches, antivirus program, system monitor program, recorders and packets capture program, etc. A kind of worm virus is captured with the honeypot system, by recording and analyzing the progresses of the worm virus captured, attack characters and mechanisms of the worm virus is discovered and known, which gives references for protection. Key words: VMWare; Weakened System; Honeypot; Worm Virus