PhoneyC: A Virtual Client Honeypot

PhoneyC: A Virtual Client Honeypot
复制标题

DOI:
--
复制
发表时间:
2009-04
期刊:
--
影响因子:
--
通讯作者:
Jose Nazario
Jose Nazario
中科院分区:
其他
文献类型:
--
作者:
Jose Nazario

文献摘要

被引文献

相似文献

在过去几年中,客户端攻击的数量显著增加,将重点从可攻击的位置转移到充满脆弱客户端的广泛,防御薄弱的空间。就像蜜罐可以深入研究服务器端攻击一样,蜜客也可以深入研究客户端攻击。作为蜜罐的补充,蜜罐客户端是一种旨在模仿用户驱动的网络客户端应用程序(如Web浏览器)的行为并被攻击者的内容利用的工具。这些系统被用来发现发生了什么以及如何发生的。本文介绍了PhoneyC,这是一个蜜客户端工具,可以提供对新的和复杂的客户端攻击的可见性。PhoneyC是一个虚拟的honeyclient,这意味着它不是一个真实的应用程序,而是一个模拟的客户端。通过使用动态分析,PhoneyC能够从许多恶意页面中删除混淆。此外,PhoneyC模拟特定的漏洞,以查明攻击向量。PhoneyC是一个模块化框架,可以研究恶意HTTP页面,并了解现代漏洞和攻击者技术。
The number of client-side attacks has grown significantly in the past few years, shifting focus away from defendable positions to a broad, poorly defended space filled with vulnerable clients. Just as honeypots enabled deep research into server-side attacks, honeyclients can permit the deep study of client-side attacks. A complement to honeypots, a honeyclient is a tool designed to mimic the behavior of a user-driven network client application, such as a web browser, and be exploited by an attacker's content. These systems are instrumented to discover what happened and how. This paper presents PhoneyC, a honeyclient tool that can provide visibility into new and complex client-side attacks. PhoneyC is a virtual honeyclient, meaning it is not a real application but rather an emulated client. By using dynamic analysis, PhoneyC is able to remove the obfuscation from many malicious pages. Furthermore, PhoneyC emulates specific vulnerabilities to pinpoint the attack vector. PhoneyC is a modular framework that enables the study of malicious HTTP pages and understands modern vulnerabilities and attacker techniques.