Using Reinforcement Learning to Conceal Honeypot Functionality

Using Reinforcement Learning to Conceal Honeypot Functionality
复制标题

使用强化学习隐藏蜜罐功能

DOI:
--
复制
发表时间:
2018
期刊:
ECML/PKDD
影响因子:
--
通讯作者:
E. Barrett
E. Barrett
中科院分区:
--
文献类型:
--
作者:
Seamus Dowling;M. Schukat;E. Barrett

文献摘要

被引文献

相似文献

自动化恶意软件在其代码中使用蜜罐检测机制。一旦蜜罐功能被暴露,诸如僵尸网络之类的恶意软件将停止尝试危害。随后的恶意软件变体采用类似的技术来逃避已知蜜罐的检测。这减少了捕获的数据集和后续分析的潜在大小。本文介绍了使用强化学习部署蜜罐的结果,以隐藏功能。自适应蜜罐通过实现奖励函数来学习最佳响应,以克服初始检测尝试,目标是最大化攻击者命令转换。该文件表明,蜜罐快速识别最佳响应,以克服初始检测,随后增加攻击命令的转换。它还检查了捕获的僵尸网络的结构,并绘制了重复自动化恶意软件的蜜罐的学习演变。最后,它建议改变现有的分类管理蜜罐的发展,基于自适应蜜罐的学习进化。与本文相关的代码可在https://github.com/sosdow/RLHPot上获得。
Automated malware employ honeypot detecting mechanisms within its code. Once honeypot functionality has been exposed, malware such as botnets will cease the attempted compromise. Subsequent malware variants employ similar techniques to evade detection by known honeypots. This reduces the potential size of a captured dataset and subsequent analysis. This paper presents findings on the deployment of a honeypot using reinforcement learning, to conceal functionality. The adaptive honeypot learns the best responses to overcome initial detection attempts by implementing a reward function with the goal of maximising attacker command transitions. The paper demonstrates that the honeypot quickly identifies the best response to overcome initial detection and subsequently increases attack command transitions. It also examines the structure of a captured botnet and charts the learning evolution of the honeypot for repetitive automated malware. Finally it suggests changes to an existing taxonomy governing honeypot development, based on the learning evolution of the adaptive honeypot. Code related to this paper is available at: https://github.com/sosdow/RLHPot.