Bitter Harvest: Systematically Fingerprinting Low- and Medium-interaction Honeypots at Internet Scale

Bitter Harvest: Systematically Fingerprinting Low- and Medium-interaction Honeypots at Internet Scale
复制标题

苦涩的收获:在互联网规模上系统地对中低交互蜜罐进行指纹识别

DOI:
--
复制
发表时间:
2018
期刊:
WOOT @ USENIX Security Symposium
影响因子:
--
通讯作者:
R. Clayton
R. Clayton
中科院分区:
--
文献类型:
--
作者:
Alexander Vetterl;R. Clayton

文献摘要

参考文献

被引文献

相似文献

当前一代的中低交互蜜罐使用现成的库来提供传输层。我们表明,这种架构是致命的缺陷,因为协议的实现微妙地不同于被模仿的系统。我们提出了一个通用的技术,系统地指纹低和中等互动蜜罐在互联网规模只有一个数据包和ERR(等错误率)为0.0183。我们进行互联网范围内的扫描,并确定7 605蜜罐实例在9个不同的蜜罐实现的最重要的网络协议SSH,HTTPS和HTTP。对于SSH蜜罐,我们还确定了它们的补丁级别,发现它们维护得很差- 27%的蜜罐在过去31个月内没有更新,只有39%的蜜罐在7个月前进行了改进。我们相信我们的发现是一个“阶级突破”,因为琐碎的补丁不能解决这个问题。
The current generation of lowand medium interaction honeypots uses off-the-shelf libraries to provide the transport layer. We show that this architecture is fatally flawed because the protocols are implemented subtly differently from the systems being impersonated. We present a generic technique for systematically fingerprinting lowand medium interaction honeypots at Internet scale with just one packet and an ERR (Equal Error Rate) of 0.0183. We conduct Internet-wide scans and identify 7 605 honeypot instances across nine different honeypot implementations for the most important network protocols SSH, Telnet, and HTTP. For SSH honeypots we also determined their patch level and find that they are poorly maintained – 27% of the honeypots have not been updated within the last 31 months and only 39% incorporate improvements from 7 months ago. We believe our findings to be a ‘class break’ in that trivial patches cannot address the issue.
过多的 SSH 密码套件
DOI: 10.1145/2976749.2978364
发表时间: 2016
期刊: --
影响因子: --
作者:
Albrecht M
通讯作者: Albrecht M