Medium Interaction Honeypots
Medium Interaction Honeypots
复制标题
中等交互蜜罐
DOI:
--
复制
发表时间:
2006
期刊:
影响因子:
--
通讯作者:
Georg Wicherski
中科院分区:
文献类型:
--
作者:
Georg Wicherski
Autonomously spreading malware has been a global threat to the Internet Community ever since the existence of the Internet as a large-scale computer network. A specialization of this threat are botnets; recent trends towards commercialization of botnets made the situation even worse. This document outlines the weaknesses of different existing approaches to catch malware – especially bots – and shows how Medium Interaction Honeypots solved these problems. It evaluates the success of Medium Interaction Honeypots so far and additionally points out some other related work. 1 The Problem: Botnets One of the biggest problems the Internet is facing today – besides spam – is autonomously spreading malware. Some malware was written solely for proof of concept or education of the author, other malware was written with solely destructive intentions in mind. The biggest threat is however posed by remotely controllable backdoors. They not only allow commercial industry espionage on a highly advanced level, recent threats have become critical even to the end customer’s computer. Controllable networks of many infected nodes are currently referred to as botnets [1] as most of these are even today still based upon the IRC control and an early term for non-human, controllable IRC servants (even though not malicious) was bot. However, new protocols are now emerging for command and control of such botnets, with the most widespread alternative to IRC being HTTP. Another interesting trend is to use DNS as command and control protocol, although this is not in widespread use yet. Botnets pose a severe threat to today’s Internet community for two main reasons: first of all, the sum of resources available by a single botnet is so immense that they can cause severe damages. A botnet of 5,000 DSL 6MBit bots with a common upstream of 576 kbit/s has a total theoretical bandwidth of 2812.5 MBit/s. Now that there are botnets controling up to 50,000 hosts which yields to a practical bandwidth of 20 GBit/s, it is obvious that any webhoster or even upstream provider can be taken down with a Distributed Denial of Service attack. This type of abuse through botnets was the most common from 1997 through 2003 as it did not require any real technical sophistication. Another critical risk created by the control of so many resources is the sending and delivering huge amounts of spam.