首页> 外文会议>International Conference on Cyber Security and Protection of Digital Services >Introducing Falcom: A Multifunctional High-Interaction Honeypot Framework for Industrial and Embedded Applications
【24h】

Introducing Falcom: A Multifunctional High-Interaction Honeypot Framework for Industrial and Embedded Applications

机译:Falcom简介:适用于工业和嵌入式应用的多功能,高交互蜜罐框架

获取原文

摘要

Falcom is a high-interaction honeypot that provides a full fledged operating system, maximizing its interaction with an attacker and aiming at embedded architectures. Since poorly secured embedded devices and Internet of Things applications form a profitable matrix for criminal activity, a deeper understanding of the existent risks is needed. Threat intelligence is crucial to increase the security in terms of prevention, detection and mitigation of attacks. Honeypots are a well establish technology that provide more insights about the behavior of adversaries by luring attacks into a monitored decoy. Any interaction with this decoy is suspicious and forwarded for further investigation. By analyzing the observed attack parameters it is possible to reveal recent trends, new attack vectors and ongoing intrusion attempts. Since embedded systems are the focus of the proposed honeypot, CPU architectures, as well as system resources are chosen to imitate embedded devices. In the reference implementation, the authentication mechanism is prone to brute-force and dictionary attacks.
机译:Falcom是一种高交互性蜜罐,可提供完整的操作系统,从而最大程度地与攻击者进行交互,并针对嵌入式体系结构。由于安全性差的嵌入式设备和物联网应用程序构成犯罪活动的有利可图矩阵,因此需要对存在的风险有更深入的了解。威胁情报对于提高预防,检测和缓解攻击的安全性至关重要。蜜罐技术是一种成熟的技术,它通过将攻击引诱到受监视的诱饵中来提供有关敌人行为的更多见解。与该诱饵的任何互动都是可疑的,并转发给进一步调查。通过分析观察到的攻击参数,可以揭示最新趋势,新的攻击媒介和正在进行的入侵尝试。由于嵌入式系统是拟议蜜罐的重点,因此选择了CPU体系结构以及系统资源来模仿嵌入式设备。在参考实现中,身份验证机制易于受到暴力攻击和字典攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号