首页> 外文会议>International Conference on ICT Systems Security and Privacy Protection >Advanced Cowrie Configuration to Increase Honeypot Deceptiveness
【24h】

Advanced Cowrie Configuration to Increase Honeypot Deceptiveness

机译:高级COWRIE配置增加蜜罐欺骗性

获取原文

摘要

Cowrie is a medium-interaction SSH, and Telnet honeypot used to record brute force attacks and SSH requests. Cowrie utilizes a Python codebase, which is maintained and publicly available on GitHub. Since its source code is publicly released, not only security specialists but cybercriminals can also analyze it. Nonetheless, cybersecurity specialists deploy most honeypots with default configurations. This outcome is because modern computer systems and infrastructures do not provide a standard framework for optimal deployment of these honeypots based on the various configuration options available to produce a non-default configuration. This option would allow them to act as effective deceptive systems. Honeypot deployments with default configuration settings are easier to detect because cybercriminals have known scripts and tools such as NMAP and Shodan for identifying them. This research aims to develop a framework that enables for the customized configuration of the Cowrie honeypot, thereby enhancing its functionality to achieve a high degree of deceptiveness and realism when presented to the Internet. A comparison between the default and configured deployments is further conducted to prove the modified deployments' effectiveness.
机译:Cowrie是一种中型互动SSH,而且用于记录蛮力攻击和SSH要求的Telnet蜜罐。 Cowrie利用Python CodeBase,在Github上维护和公开可用。由于其源代码公开发布,不仅是安全专家,而且网络犯罪分子也可以分析它。尽管如此,网络安全专家使用默认配置部署大多数蜜罐。这一结果是因为现代计算机系统和基础架构不提供基于可用于产生非默认配置的各种配置选项的这些蜜互其幅点的标准框架。此选项将允许它们作为有效的欺骗系统。蜜罐部署具有默认配置设置更易于检测,因为网络犯罪分子具有已知的脚本和工具,例如NMAP和Shodan用于识别它们。该研究旨在开发一个框架,使COWRIE蜜罐的定制配置能够加强其功能,以在呈现到互联网时实现高度欺骗性和现实主义。进一步进行了默认和配置的部署之间的比较以证明修改后的部署效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号