首页> 外文会议>NSS 2013 >Towards Hybrid Honeynets via Virtual Machine Introspection and Cloning
【24h】

Towards Hybrid Honeynets via Virtual Machine Introspection and Cloning

机译:通过虚拟机的内省和克隆致杂交蜜肿

获取原文

摘要

We present a scalable honeynet system built on Xen using virtual machine introspection and cloning techniques to efficiently and effectively detect intrusions and extract associated malware binaries. By melding forensics tools with live memory introspection, the system is resistant to prior in-guest detection techniques of the monitoring environment and to subversion attacks that may try to hide aspects of an intrusion. By utilizing both copy-on-write disks and memory to create multiple identical high-interaction honeypot clones, the system relaxes the linear scaling of hardware requirements typically associated with scaling such setups. By employing a novel routing approach our system eliminates the need for post-cloning network reconfiguration, allowing the clone honeypots to share IP and MAC addresses while providing concurrent and quarantined access to the network. We deployed our system and tested it with live network traffic, demonstrating its effectiveness and scalability.
机译:我们介绍了一个可扩展的HoneyNet系统,使用虚拟机的内省和克隆技术在Xen内置,以有效且有效地检测入侵和提取相关的恶意软件二进制文件。通过使用实时内存内部融合的取证工具,该系统对监视环境的现有访客检测技术以及可能试图隐藏入侵方面的颠覆攻击。通过利用副本写入磁盘和内存来创建多个相同的高交互蜜罐克隆,系统可以放松通常与缩放这种设置相关联的硬件要求的线性缩放。通过采用新颖的路由方法,我们的系统消除了对克隆后网络重新配置的需求,允许克隆蜜孔在提供对网络的并发和隔离访问的同时共享IP和MAC地址。我们部署了我们的系统并通过实时网络流量测试了它,展示了其有效性和可扩展性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号