Scalability, fidelity, and containment in the potemkin virtual honeyfarm

Scalability, fidelity, and containment in the potemkin virtual honeyfarm
复制标题

DOI:
10.1145/1095810.1095825
复制
发表时间:
2005-10
期刊:
--
影响因子:
--
通讯作者:
Michael Vrable;Justin Ma;Jay Chen;D. Moore;Erik Vandekieft;A. Snoeren;G. Voelker;S. Savage
Michael Vrable;Justin Ma;Jay Chen;D. Moore;Erik Vandekieft;A. Snoeren;G. Voelker;S. Savage
中科院分区:
其他
文献类型:
--
作者:
Michael Vrable;Justin Ma;Jay Chen;D. Moore;Erik Vandekieft;A. Snoeren;G. Voelker;S. Savage

文献摘要

被引文献

相似文献

大规模蠕虫、病毒和僵尸网络的快速发展使互联网恶意软件成为一个紧迫的问题。这些感染是现代攻击的根源,包括DDoS勒索,在线身份盗窃,垃圾邮件,网络钓鱼和盗版。然而,最广泛使用的收集新恶意软件情报的工具-网络蜜罐-迫使调查人员在大规模监控活动或高保真捕获行为之间做出选择。在本文中,我们描述了一种方法,以尽量减少这种紧张局势,提高蜜罐的可扩展性高达六个数量级,同时仍然密切模仿个别互联网主机的执行行为。我们已经建立了一个原型honeyfarm系统,称为波将金,利用虚拟机,积极的内存共享,并晚绑定的资源来实现这一目标。虽然仍然是一个不成熟的实现,但波将金已经在现场测试运行中模拟了超过64,000个互联网蜜罐,仅使用少数物理服务器。
The rapid evolution of large-scale worms, viruses and bot-nets have made Internet malware a pressing concern. Such infections are at the root of modern scourges including DDoS extortion, on-line identity theft, SPAM, phishing, and piracy. However, the most widely used tools for gathering intelligence on new malware -- network honeypots -- have forced investigators to choose between monitoring activity at a large scale or capturing behavior with high fidelity. In this paper, we describe an approach to minimize this tension and improve honeypot scalability by up to six orders of magnitude while still closely emulating the execution behavior of individual Internet hosts. We have built a prototype honeyfarm system, called Potemkin, that exploits virtual machines, aggressive memory sharing, and late binding of resources to achieve this goal. While still an immature implementation, Potemkin has emulated over 64,000 Internet honeypots in live test runs, using only a handful of physical servers.