A Virtual Honeypot Framework

A Virtual Honeypot Framework
复制标题

DOI:
--
复制
发表时间:
2004-08
期刊:
--
影响因子:
--
通讯作者:
Niels Provos
Niels Provos
中科院分区:
其他
文献类型:
--
作者:
Niels Provos

文献摘要

被引文献

相似文献

蜜罐是一种受到严密监控的网络诱饵,有几个目的:它可以分散对手对网络上更有价值的机器的注意力,提供有关新攻击和利用趋势的早期警告,或者允许在利用蜜罐期间和之后对对手进行深入检查。部署物理蜜罐通常是时间密集型和昂贵的,因为不同的操作系统需要专门的硬件,每个蜜罐都需要自己的物理系统。本文介绍了Honeyd,一个虚拟蜜罐,模拟虚拟计算机系统在网络级的框架。模拟的计算机系统似乎在未分配的网络地址上运行。为了欺骗网络指纹工具,Honeyd模拟不同操作系统的网络堆栈,并可以为任意数量的虚拟系统提供任意的路由拓扑和服务。本文讨论了Honeyd的设计,并展示了Honeyd框架如何在系统安全的许多领域提供帮助,例如检测和禁用蠕虫,分散对手的注意力,或防止垃圾邮件的传播。
A honeypot is a closely monitored network decoy serving several purposes: it can distract adversaries from more valuable machines on a network, provide early warning about new attack and exploitation trends, or allow in-depth examination of adversaries during and after exploitation of a honeypot. Deploying a physical honeypot is often time intensive and expensive as different operating systems require specialized hardware and every honeypot requires its own physical system. This paper presents Honeyd, a framework for virtual honeypots that simulates virtual computer systems at the network level. The simulated computer systems appear to run on unallocated network addresses. To deceive network fingerprinting tools, Honeyd simulates the networking stack of different operating systems and can provide arbitrary routing topologies and services for an arbitrary number of virtual systems. This paper discusses Honeyd's design and shows how the Honeyd framework helps in many areas of system security, e.g. detecting and disabling worms, distracting adversaries, or preventing the spread of spam email.