作者
Corrado Leita, Ken Mermoud, Marc Dacier
发表日期
2005/12/5
研讨会论文
21st Annual Computer Security Applications Conference (ACSAC'05)
页码范围
12 pp.-214
出版商
IEEE
简介
Honeyd (N. Provos, 2004) is a popular tool developed by Niels Provos that offers a simple way to emulate services offered by several machines on a single PC. It is a so called low interaction honeypot. Responses to incoming requests are generated thanks to ad hoc scripts that need to be written by hand. As a result, few scripts exist, especially for services handling proprietary protocols. In this paper, we propose a method to alleviate these problems by automatically generating new scripts. We explain the method and describe its limitations. We analyze the quality of the generated scripts thanks to two different methods. On the one hand, we have launched known attacks against a machine running our scripts; on the other hand, we have deployed that machine on the Internet, next to a high interaction honeypot during two months. For those attackers that have targeted both machines, we can verify if our scripts have …
引用总数
2005200620072008200920102011201220132014201520162017201820192020202120222023151721251317162381514171781615815
学术搜索中的文章
C Leita, K Mermoud, M Dacier - 21st Annual Computer Security Applications …, 2005