首页> 外文会议>ACM symposium on Operating systems principles >Scalability, fidelity, and containment in the potemkin virtual honeyfarm
【24h】

Scalability, fidelity, and containment in the potemkin virtual honeyfarm

机译:Potemkin Virtual Omarm中的可扩展性,保真度和遏制

获取原文
获取外文期刊封面目录资料

摘要

The rapid evolution of large-scale worms, viruses and bot-nets have made Internet malware a pressing concern. Such infections are at the root of modern scourges including DDoS extortion, on-line identity theft, SPAM, phishing, and piracy. However, the most widely used tools for gathering intelligence on new malware -- network honeypots -- have forced investigators to choose between monitoring activity at a large scale or capturing behavior with high fidelity. In this paper, we describe an approach to minimize this tension and improve honeypot scalability by up to six orders of magnitude while still closely emulating the execution behavior of individual Internet hosts. We have built a prototype honeyfarm system, called Potemkin, that exploits virtual machines, aggressive memory sharing, and late binding of resources to achieve this goal. While still an immature implementation, Potemkin has emulated over 64,000 Internet honeypots in live test runs, using only a handful of physical servers.
机译:大规模蠕虫,病毒和机器人的快速演变使互联网恶意软件成为紧迫的问题。这种感染是现代祸害的根源,包括DDOS敲诈勒索,在线身份盗窃,垃圾邮件,网络钓鱼和盗版。但是,在新恶意软件 - 网络蜜罐上采集智能的最广泛使用的工具 - 已强制调查人员在大规模或捕获高保真度的大规模或捕获行为之间进行选择。在本文中,我们描述了一种最大限度地减少这种张力的方法,并通过最多六个数量级,而提高蜜罐可扩展性,同时仍然密切模拟各个互联网主机的执行行为。我们已经建立了一个称为 Potemkin的原型蜂蜜系统,它利用虚拟机,积极的内存共享和资源的后期绑定来实现这一目标。虽然仍然是一个不成熟的实现,但Potemkin在实时测试运行中仿效了64,000次互联网蜜罐,只使用少数物理服务器。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号