Honeycomb
Honeycomb
复制标题
DOI:
10.1145/972374.972384
复制
发表时间:
2004-01
影响因子:
2.8
通讯作者:
C. Kreibich;J. Crowcroft
中科院分区:
文献类型:
--
作者:
C. Kreibich;J. Crowcroft
This paper describes a system for automated generation of attack signatures for network intrusion detection systems. Our system applies pattern-matching techniques and protocol conformance checks on multiple levels in the protocol hierarchy to network traffic captured a honeypot system. We present results of running the system on an unprotected cable modem connection for 24 hours. The system successfully created precise traffic signatures that otherwise would have required the skills and time of a security officer to inspect the traffic manually.