首页> 外文会议>Asia Joint Conference on Information Security >Wamber: Defending Web Sites on Hosting Services with Self-Learning Honeypots
【24h】

Wamber: Defending Web Sites on Hosting Services with Self-Learning Honeypots

机译:Wamber:使用自学习蜜罐在托管服务上捍卫网站

获取原文

摘要

Web sites have been great diversity because of their purposes and structures today and many web sites are working on hosting services. A hosting service is one of the network services for outsourcing construction and maintenance of the servers. Thus, the web site operators are free from hardware setting and server maintenance. On the other hand, web sites have been exposed to cyber attacks. To counter those web site attacks, hosting service providers should monitor their web sites. However, in many cases, it is difficult for the service providers to analyze such attacks with full information because of contracts about a protection of personal information. As another approach, it is effective to construct server side honeypots and observe malicious access to them. Unfortunately, honeypots could not always observe all type of attacks because of the diversity of web sites. In this paper, we propose a novel approach for keeping up security intelligence and strengthening countermeasures against web attacks on a hosting service. Our approach helps the service providers to protect their customers web sites by combining the analysis of IDS logs and web access logs provided from these sites and dedicated honeypots for observing web attacks. The honeypots keep learning interactions from the actual hosted sites, and attract attackers by mimicking the sites to gain the intelligence on malicious web attacks. We also describe the case study in a hosting service on our university, in which suspicious requests are confirmed to be malicious by our approach.
机译:由于当今的目的和结构,网站已经具有很大的多样性,并且许多网站都在致力于托管服务。托管服务是用于外包服务器构建和维护的网络服务之一。因此,网站运营商无需进行硬件设置和服务器维护。另一方面,网站已受到网络攻击。为了应对那些网站攻击,托管服务提供商应监视其网站。但是,在许多情况下,由于有关保护个人信息的合同,服务提供商很难用完整的信息来分析此类攻击。作为另一种方法,构造服务器端蜜罐并观察对其的恶意访问是有效的。不幸的是,由于网站的多样性,蜜罐不能总是观察到所有类型的攻击。在本文中,我们提出了一种新颖的方法来保持安全情报并加强针对托管服务上的Web攻击的对策。我们的方法通过结合IDS日志和从这些站点提供的Web访问日志以及专用的蜜罐来观察Web攻击,来帮助服务提供商保护其客户的Web站点。蜜罐不断从实际托管的站点学习交互,并通过模仿站点来获取攻击者的恶意信息,从而吸引攻击者。我们还将在我们大学的托管服务中描述该案例研究,其中通过我们的方法确认可疑请求是恶意的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号