Baiting Inside Attackers Using Decoy Documents

Baiting Inside Attackers Using Decoy Documents
复制标题

使用诱饵文档诱骗内部攻击者

DOI:
--
复制
发表时间:
2009
期刊:
Security and Privacy in Communication Networks
影响因子:
--
通讯作者:
S. Stolfo
S. Stolfo
中科院分区:
--
文献类型:
--
作者:
Brian M. Bowen;Shlomo Hershkop;A. Keromytis;S. Stolfo

文献摘要

被引文献

相似文献

内部威胁仍然是计算机安全中最令人烦恼的问题之一。已经提出了许多方法来检测恶意的内部行为,包括用户建模和分析技术,策略和访问执行技术,以及误用检测。在这项工作中,我们提出了基于陷阱的防御机制和部署平台,以解决内部人员试图泄露和使用敏感信息的问题。其目的是迷惑和迷惑需要更多努力来从虚假信息中识别真实的信息的对手,并提供一种检测何时发生利用敏感信息的尝试的方法。D3系统自动生成并存储在文件系统中,目的是引诱恶意用户。我们介绍并正式确定了一些属性的诱饵作为指导设计陷阱为基础的防御,以增加检测内部攻击的可能性。诱饵文档包含几种不同类型的伪造凭据,使用这些凭据时会触发警报。我们还在文档中嵌入了“隐形信标”,从而向服务器发出信号,指示特定诱饵何时何地被打开。我们评估诱饵文件上的攻击者渗透的蜜罐证明该方法的可行性。
The insider threat remains one of the most vexing problems in computer security. A number of approaches have been proposed to detect nefarious insider actions including user modeling and profiling techniques, policy and access enforcement techniques, and misuse detection. In this work we propose trap-based defense mechanisms and a deployment platform for addressing the problem of insiders attempting to exfiltrate and use sensitive information. The goal is to confuse and confound an adversary requiring more effort to identify real information from bogus information and provide a means of detecting when an attempt to exploit sensitive information has occurred. “Decoy Documents” are automatically generated and stored on a file system by the D3 System with the aim of enticing a malicious user. We introduce and formalize a number of properties of decoys as a guide to design trap-based defenses to increase the likelihood of detecting an insider attack. The decoy documents contain several different types of bogus credentials that when used, trigger an alert. We also embed “stealthy beacons” inside the documents that cause a signal to be emitted to a server indicating when and where the particular decoy was opened. We evaluate decoy documents on honeypots penetrated by attackers demonstrating the feasibility of the method.