Towards systematic honeytoken fingerprinting

Towards systematic honeytoken fingerprinting
复制标题

迈向系统化的蜜币指纹识别

DOI:
--
复制
发表时间:
2020
期刊:
International Conference on Security of Information and Networks
影响因子:
--
通讯作者:
Emmanouil Vasilomanolakis
Emmanouil Vasilomanolakis
中科院分区:
--
文献类型:
--
作者:
Shreyas Srinivasa;J. Pedersen;Emmanouil Vasilomanolakis

文献摘要

被引文献

相似文献

随着网络攻击的数量和复杂性的不断上升,防御者正在走向更主动的防线。如今,诸如蜜罐和移动目标防御范例之类的欺骗方法被以多种方式使用。蜜令牌是描述可插入到网络或系统中的类似蜜罐的实体/资源的总称。当对手与蜜令牌交互时,就会发出警报。与蜜罐类似,蜜令牌的价值在于它们的不可分辨;如果攻击者可以检测到它们,例如通过指纹工具,他们就可以很容易地避开它们。本文提出并讨论了蜜令牌指纹识别方法。据我们所知,这是第一篇研究蜜令牌特定指纹的论文。此外,我们展示了一个概念证明,它能够成功地检测到许多蜜令牌类型。
With the continuous rise in the numbers and sophistication of cyber-attacks, defenders are moving towards more proactive lines of defense. Deception methods such as honeypots and moving target defense paradigms, are nowadays utilized in a multitude of ways. A honeytoken is an umbrella term that describes honeypot-like entities/resources that can be inserted into a network or system. The moment an adversary interacts with a honeytoken, an alert is raised. Similar to honeypots, the value of honeytokens lies in their indistinguishability; if an attacker can detect them, e.g. via a fingerprinting tool, they can easily evade them. In this paper, we propose and discuss honeytoken fingerprinting methods. To the best of our knowledge, this is the first paper to examine honeytoken-specific fingerprinting. Furthermore, we showcase a proof of concept that is able to successfully detect a number of honeytoken types.