首页> 外文会议>Information Assurance Workshop, 2004. Proceedings. Second IEEE International >Defeating Internet attacks using risk awareness and active honeypots
【24h】

Defeating Internet attacks using risk awareness and active honeypots

机译:利用风险意识和主动蜜罐战胜互联网攻击

获取原文

摘要

New forms of Internet attacks, such as SQL Slammer, have become increasingly sophisticated. Although coded in a simple way, the SQL Slammer worm propagated all over the world at an extremely high speed in a short period of time, rendering it impossible for humans to counter it using manual intervention. Here, we propose a security framework called Japonica to detect and respond to unknown attacks at the early stage through the dynamic orchestration of prevention, detection, and response mechanisms. We identify important requirements to support the proposed framework and corresponding system entities. Also, we describe our model using colored Petri nets to discover a uniform message exchange format among the entities. One unique characteristic of Japonica is an active response coordinator and we demonstrate its feasibility in a proof-of-concept prototype, utilizing a honeypot as an active entity. Our results indicate that Japonica can successfully prevent the spread of SQL Slammer without human intervention. We are currently extending the framework to counter other forms of sophisticated Internet attacks.
机译:诸如SQL Slammer之类的新型Internet攻击已变得越来越复杂。尽管以简单的方式进行编码,但SQL Slammer蠕虫在短时间内以极高的速度传播到全世界,这使得人类无法通过人工干预来抵抗它。在这里,我们提出了一个称为Japonica的安全框架,可以通过动态协调预防,检测和响应机制来在早期阶段检测和响应未知攻击。我们确定了支持拟议框架和相应系统实体的重要要求。此外,我们使用有色Petri网描述模型,以发现实体之间的统一消息交换格式。粳稻的一个独特特征是主动响应协调器,我们利用蜜罐作为主动实体在概念验证原型中证明了其可行性。我们的结果表明,Japonica可以在无需人工干预的情况下成功阻止SQL Slammer的传播。我们目前正在扩展该框架,以应对其他形式的复杂Internet攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号