Improved self adaptive honeypots capable of detecting rootkit malware

Improved self adaptive honeypots capable of detecting rootkit malware
复制标题

改进的自适应蜜罐能够检测 Rootkit 恶意软件

DOI:
10.1109/iccomm.2012.6262612
复制
发表时间:
2012
期刊:
2012 9th International Conference on Communications (COMM)
影响因子:
--
通讯作者:
Adrian Pauna
Adrian Pauna
中科院分区:
--
文献类型:
--
作者:
Adrian Pauna

文献摘要

被引文献

相似文献

高交互性蜜罐的最新发展趋势表明,自适应蜜罐通过改变攻击者的行为来引诱攻击者,是收集尽可能多的攻击者信息的可行解决方案。基于博弈论的自适应蜜罐系统正处于发展阶段,到目前为止创建的系统主要集中在将博弈论概念应用于高交互蜜罐的配置和相互作用[1]。本文提出了一个经过测试的概念系统,集成了动态污点分析与现有的自适应蜜罐,以检测攻击者安装的rootkit恶意软件的证明。
The latest trends in the development of high interaction honeypots show that adaptive honeypots, which lure attackers by changing their behavior, are a feasible solution for gathering of as much information as possible about them. Adaptive Honeypot systems based on Game theory are in a development stage and the systems created until now are focused mostly on applying game-theoretic concepts for the configuration and reciprocal actions of high-interaction honeypots [1]. The paper presents a tested proof of concept system that integrates dynamic taint analysis with an existing adaptive honeypot in order to detect the rootkit malware that the attacker installs.