Analysis of the Global Attack Landscape Using Data from a Telnet Honeypot

Analysis of the Global Attack Landscape Using Data from a Telnet Honeypot
复制标题

使用来自 Telnet 蜜罐的数据分析全球攻击格局

DOI:
10.11610/isij.4320
复制
发表时间:
2019
期刊:
Information & Security: An International Journal
影响因子:
--
通讯作者:
V. Yosifova
V. Yosifova
中科院分区:
--
文献类型:
--
作者:
V. Bontchev;V. Yosifova

文献摘要

被引文献

相似文献

在2016年发现米拉伊僵尸网络后,我们决定为它建立一个蜜罐,看看它的传播范围有多广。在这个过程中,我们发现许多其他恶意攻击者也在使用类似的攻击向量。本文概述了我们选择正确的蜜罐和支持基础设施(后端数据库,可视化)的过程。本文介绍了我们从这个蜜罐收集的统计数据,我们从这些统计数据中得出的结论,以及我们开发的共享数据的工具。A R T I C L E I N F O:接收日期:2019年8月21日修订日期:2019年9月13日在线日期:2019年9月22日K E Y W O R D S:honeypot,malware,米拉伊,僵尸网络,病毒Creative Commons BY-NC 4.0
After the Mirai botnet was discovered in 2016, we decided to set up a honeypot for it and see how widespread it really was. In the process we discovered that many other malicious attackers were using similar attack vectors. This paper outlines the process we went through to pick the right honeypot and the supporting infrastructure (backend database, visualization). This article presents the statistics we have collected from this honeypot, the conclusions we have drawn from these statistics, as well as the tools we have developed to share the data. A R T I C L E I N F O : RECEIVED: 21 AUG 2019 REVISED: 13 SEP 2019 ONLINE: 22 SEP 2019 K E Y W O R D S : honeypot, malware, Mirai, botnet, Telnet Creative Commons BY-NC 4.0