Detecting and Analyzing Zero-Day Attacks Using Honeypots

Detecting and Analyzing Zero-Day Attacks Using Honeypots
复制标题

使用蜜罐检测和分析零日攻击

DOI:
--
复制
发表时间:
2013
期刊:
Computer Science in Cars Symposium
影响因子:
--
通讯作者:
R. Deaconescu
R. Deaconescu
中科院分区:
--
文献类型:
--
作者:
Constantin Musca;Emma Mirica;R. Deaconescu

文献摘要

被引文献

相似文献

计算机网络被自我传播的恶意软件(蠕虫、病毒、特洛伊木马)淹没。虽然安全漏洞的数量每天都在增长,但防御方法的数量却不能说是一样的。但信息安全领域最微妙的问题仍然是检测被称为零日攻击的未知攻击。为了自动生成Snort入侵检测/防御系统的攻击特征,提出了一种利用蜜罐系统对恶意流量进行隔离和分析的方法。蜜罐被部署为一个虚拟机,它的工作是尽可能多地记录有关攻击的信息。然后,使用受保护的机器,通过安全连接远程收集日志以进行分析。挑战是减轻我们面临的风险,同时搜索未知的攻击。
Computer networks are overwhelmed by self propagating malware (worms, viruses, trojans). Although the number of security vulnerabilities grows every day, not the same thing can be said about the number of defense methods. But the most delicate problem in the information security domain remains detecting unknown attacks known as zero-day attacks. This paper presents methods for isolating the malicious traffic by using a honeypot system and analyzing it in order to automatically generate attack signatures for the Snort intrusion detection/prevention system. The honeypot is deployed as a virtual machine and its job is to log as much information as it can about the attacks. Then, using a protected machine, the logs are collected remotely, through a safe connection, for analysis. The challenge is to mitigate the risk we are exposed to and at the same time search for unknown attacks.