A First Look: Using Linux Containers for Deceptive Honeypots

A First Look: Using Linux Containers for Deceptive Honeypots
复制标题

DOI:
10.1145/3140368.3140371
复制
发表时间:
2017-11
期刊:
Proceedings of the 2017 Workshop on Automated Decision Making for Active Cyber Defense
影响因子:
--
通讯作者:
Alexander Kedrowitsch;D. Yao;G. Wang;K. Cameron
Alexander Kedrowitsch;D. Yao;G. Wang;K. Cameron
中科院分区:
其他
文献类型:
--
作者:
Alexander Kedrowitsch;D. Yao;G. Wang;K. Cameron

文献摘要

被引文献

相似文献

恶意软件的不断增长使恶意二进制收集和分析是积极防御的绝对必要性。同时,恶意软件作者试图通过合并环境检测技术来使其二进制文件防止分析,以确定二进制文件是在虚拟环境中还是在有监视工具的情况下执行。对于安全研究人员而言,关于如何从虚拟机中删除工件以有效地构建欺骗性的“蜜罐”以进行恶意软件收集和分析,这仍然是一个悬而未决的问题。在本文中,我们通过使用Linux容器探索了一种完全不同但有希望的方法。从理论上讲,Linux容器具有最小的虚拟化工件,并且很容易在低功率设备上部署。我们的工作执行了第一个受控的实验,以将Linux容器与裸机和5种主要类型的虚拟机进行比较。我们试图衡量Linux容器提供的欺骗能力以击败主流虚拟环境检测技术。此外,我们从经验上探讨了Linux容器中的潜在弱点,以帮助防御者做出更明智的设计决策。
The ever-increasing sophistication of malware has made malicious binary collection and analysis an absolute necessity for proactive defenses. Meanwhile, malware authors seek to harden their binaries against analysis by incorporating environment detection techniques, in order to identify if the binary is executing within a virtual environment or in the presence of monitoring tools. For security researchers, it is still an open question regarding how to remove the artifacts from virtual machines to effectively build deceptive "honeypots" for malware collection and analysis. In this paper, we explore a completely different and yet promising approach by using Linux containers. Linux containers, in theory, have minimal virtualization artifacts and are easily deployable on low-power devices. Our work performs the first controlled experiments to compare Linux containers with bare metal and 5 major types of virtual machines. We seek to measure the deception capabilities offered by Linux containers to defeat mainstream virtual environment detection techniques. In addition, we empirically explore the potential weaknesses in Linux containers to help defenders to make more informed design decisions.