- 1、本文档共8页,可阅读全部内容。
- 2、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。
- 3、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 4、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
查看更多
Honey@home A New Approach to Large-Scale Threat Monitoring
Honey@home: A New Approach to Large-Scale Threat
Monitoring
S. Antonatos, E. P. Markatos
Institute of Computer Science
Foundation for Research and Technology, Hellas
PO Box 1385, Heraklion, Crete, Greece
{antonat,markatos}@ics.forth.gr
K. G. Anagnostakis
Cryptography and Security Department
Institute for Infocomm Research
21 Heng Mui Keng Terrace, Singapore
kostas@.sg
ABSTRACT
Honeypots have been shown to be very useful for accurately
detecting attacks, including zero-day threats, at a reason-
able cost and without false positives. However, there are
two pressing problems with existing approaches. The first
problem is that timely detection requires deployment of hon-
eypots in a large fraction of the network address space, many
organizations cannot afford. The second problem is that at-
tackers are evolving, and it has been shown that it is not
difficult for them to identify honeypots and develop black-
lists to avoid them when launching an attack.
In response to these problems, we propose a new architec-
ture that enables large-scale deployment at low cost, while
making it harder for attackers to maintain accurate black-
lists. The Honey@home architecture relies on communities
of regular users installing a lightweight honeypot that moni-
tors unused addresses and ports. Because it does not require
the static allocation of valuable chunks of network address
space, and considering the success of other community-based
approaches such as seti@home, our approach is well-suited
for creating a large-scale honeypot infrastructure at low cost.
Since participation in the system is dynamic as users come
and go, it becomes harder for attackers to maintain accurate
blacklists.
In this paper we discuss the current design of the Honey@home
architecture, a preliminary implementation and describe the
design issues that we faced especially with respect to infras-
tructure robustness, the challenges we have to deal with and
the effectiveness of our approach.
Categories and Subject De
您可能关注的文档
- factory pic.pdf
- FactoryTalk Batch 产品概述.pdf
- F8-Task 4-2.pdf
- FactoryTalk ViewPoint 人机界面Web发布软件概述及演示.ppt
- Factory Layout e Assembly Lines.ppt
- Facts about the Plastic Bag Pandemic.doc
- Fan noise-风扇的寿命,噪声计算.pdf
- FANUC简要说明书.doc
- FactoryTalkViewStudio项目设计教程.pdf
- Fast Marching Simulation of Two-Dimensional Lithography Process.pdf
文档评论(0)