期刊文献+

ArkHoney:基于协同机制的Web蜜罐 被引量:12

ArkHoney:A Web Honeypot Based on Collaborative Mechanisms
下载PDF
导出
摘要 基于Web技术的互联网应用的迅速发展引起了黑客的关注,针对Web的攻击成为互联网上的主要威胁之一.Web蜜罐技术可以帮助人们收集攻击信息从而使得人们能够更好的应对此类威胁,因而受到安全研究人员的重视.然而,蜜罐只能捕获针对自身的攻击,如果攻击者发现想要攻击的应用不在蜜罐系统中,那么攻击者将不会进行下一步动作,蜜罐系统也就不能捕获到攻击数据.为了提高攻击者攻击Web蜜罐成功的概率,文中提出了一种在Web蜜罐系统中部署多个不同应用的方案.首先,提出了蜜罐簇的概念,由多个不同的应用蜜罐组成蜜罐簇;然后设计了蜜罐簇协同算法,通过协同算法使得整个蜜罐簇作为一个Web蜜罐发挥作用;最后使用四种不同的应用实现了基于协同机制的蜜罐原型ArkHoney.在两个月的部署中,ArkHoney蜜罐系统捕获到来自985个不同IP的7933次请求.通过分析捕获到的数据,人工已确认针对四种应用的26次攻击.文中对捕获到的总体数据进行了统计,然后选取蜜罐簇中不同蜜罐捕获到的案例进行分析,实验表明文中提出的基于协同机制的Web蜜罐能有效增加蜜罐系统对攻击的捕获能力. With the rapid development and increasing growth of network services on Websites,Web attack has drawn significant attention from attackers,making it one of the major threats on the Internet.Such attack has caused great loss of financial and intellectual property.High interaction honeypots can attract attackers,detect attacks and suspicious behaviors on the Internet and collect information about what attackers do during and after their attacks.The information collected by a honeypot can effectively help security vendors and services providers to learn the threats websites faced and thus protect websites from attacks.However,what attack information can be collected depend on the type and version of web applications installed in the web honeypot.High interaction Web honeypots can only collect limited information from attacks if the targetapplication is not deployed in a honeypot,due to the fact that the attacks will failed.In order to increase probability that a Web honeypot will be successfully attacked,It's better to deploy various Web applications in one single Web honeypot.This paper proposes a design scheme for high interaction Web honeypot,intending for the obvious promotion of success probability of a Web honeypot be attacked,so that to enhance attack information collection on high-interaction Web honeypot.First,we analysis the process of Web attacks against honeypot and introduced a concept called honeypot-cluster which consists of several Web honeypots and a cooperative control unit.In each of the Web honeypot,different kinds of Web applications have been installed.Then,a collaborative algorithm is designed.The cooperative control unit uses collaborative algorithm to determine which application in the honeypot-cluster is the attacker'desire.By using the collaborative algorithm,a honeypot-cluster performance as if it is a single Web honeypot.When the honeypot-cluster get an attack,it will forward the attack to the application selected by collaborative algorithm.In this way,a Web honeypot can collect more att
出处 《计算机学报》 EI CSCD 北大核心 2018年第2期413-425,共13页 Chinese Journal of Computers
基金 本课题得到东莞市引进创新科研团队计划(201636000100038)、国家重点研发计划(2016YFB0801604)资助.
关键词 蜜罐 蜜罐簇 Web蜜罐 WEB应用 协同 honeypot honeypot-cluster Web honeypot Web application collaborative
  • 相关文献

参考文献3

二级参考文献26

  • 1程杰仁,殷建平,刘运,钟经伟.蜜罐及蜜网技术研究进展[J].计算机研究与发展,2008,45(z1):375-378. 被引量:35
  • 2陈启璋,林国恩,李建彬.一种基于动态蜜罐和实时仿真的蜜网设计[J].微计算机信息,2006(12X):28-30. 被引量:4
  • 3BAECHER P, HOLZ T, KOETTER M, et al. Know your enemy: tracking botnets, using honeynets to learn more about bots[EB/OL]. http://www.honeynet.org/papers/ bots/, 2005. Accessed March 2007. 被引量:1
  • 4WATSON D, HOLZ T, MUELLER S. Know your enemy: phishing[EB/OL], http://www.honeynet.org/papers/phishing/,2005. Accessed March 2007. 被引量:1
  • 5PROVOS N. A virtual honeypot framework[A]. Proceedings of 13th USENIX Security Symposium[C]. San Diego, CA, USA, 2004. 1-14. 被引量:1
  • 6BALAS E, VIECCO C. Towards a third generation data capture architecture for honeynets[A]. Proceeedings of the 6th IEEE Information Assurance Workshop[C]. West Point, NY, USA, 2005. 被引量:1
  • 7BAECHER P, KOETTER M, HOLZ T, et al. The nepenthes platform: an efficient approach to collect malware[J]. Lecture Notes in Computer Science 4219, 2006, 165-184. 被引量:1
  • 8ZIMMER D. Multipot[EB/OL]. http://labs.idefense.com/software/malcode. php, 2006. Accessed March 2007. 被引量:1
  • 9LEVINE J, GRIZZARD J, OWEN H. Application of a methodology to characterize rootkits retrieved from honeynets[A]. Proceedings of the Fifth Annual Information Assurance Workshop[C]. West Point, NY, USA, 2004. 15-21. 被引量:1
  • 10肖军弼,刘广祎.分布式蜜罐系统的设计与实现[J].计算机工程与设计,2007,28(19):4628-4630. 被引量:9

共引文献54

同被引文献109

引证文献12

二级引证文献62

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部