首页> 外文会议>Annual Institute of Electrical and Electronics Engineers SMC Information Assurance Workshop >A mechanism for automatic digital evidence collection on high-interaction honeypots
【24h】

A mechanism for automatic digital evidence collection on high-interaction honeypots

机译:高互动蜜罐上自动数字证据收集的机制

获取原文

摘要

Honeypots are computational resources whose value resides in being probed, attacked or compromised by invaders. This makes it possible to obtain information about their methods, tools and motivations. On high-interaction honeypots this is done, among other ways, by collecting digital evidence. This collection is traditionally done manually and statically, demanding time and not always generating good results. In this paper, we describe an automatic, dynamic and transparent mechanism for collecting digital evidence from the filesystem of honeypots, eliminating the flaws found in the traditional methods. The mechanism consists of two modules: an interceptor module, that intercepts some preselected system calls on the honeypot and transmits the argument data to the honeynet; and a receiver module, that captures the transmitted data and reconstructs on the honey wall the evidence produced by an intruder during an invasion. A prototype based on the mechanism was implemented and tested in real intrusion situations. The mechanism's behavior in one of these situations is also described, followed by an analysis of the results.
机译:蜜罐是计算资源,其价值驻留在被入侵者探测,攻击或损害。这使得可以获得有关其方法,工具和动机的信息。在高互动蜜罐上,通过收集数字证据,在其他方面是在其他方面完成的。该系列传统上是手动和静态的,苛刻的时间,并不总是产生良好的效果。在本文中,我们描述了一种用于从蜜罐文件系统中收集数字证据的自动,动态和透明机制,消除了传统方法中发现的缺陷。该机制由两个模块组成:拦截模块,该模块拦截蜜罐上的一些预选的系统调用,并将参数数据传输到HoneyNet;和一个接收器模块,其捕获发送的数据并重建蜂蜜墙上,该壁在入侵期间由入侵者产生的证据。基于该机制的原型在实际入侵情况下实施和测试。该机制在这些情况之一中的行为也被描述,其次是对结果的分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号