首页> 外文期刊>International Journal of Engineering Science and Technology >EXTENDED HONEYPOT FRAMEWORK TO DETECT OLD/NEW CYBER ATTACKS
【24h】

EXTENDED HONEYPOT FRAMEWORK TO DETECT OLD/NEW CYBER ATTACKS

机译:扩展的HONEYPOT框架可检测旧/新网络攻击

获取原文
           

摘要

In cyber space, a hot problem is to detect the newly emerged malicious objects. There are significant methodologies to detect the early detected malicious objects but not for newly emerged malicious objects. Generally, the widely applicable approach to detect the early detected malicious objects is signaturebased detection. But for new malicious objects no signature is existed in the history, therefore, they can not detected by using this approach. New malicious objects can only be detected by using signature-based approach after a significant loss of the assets, as the signature is generated in between the duration. The paper deals to propose an approach to detect the new malicious objects with an optimal cost. Honeypots are generally used to detect the new malicious objects. The available honeypot frameworks are too costly to be afforded by an average organization. Therefore, we are proposing a low cost honeypot framework to detect malicious objects named extended honeypot. The approach is not only cost effective but also better than other approaches in some situations such as in the Intranet which is having more than one LANs and every LAN is having double honeypot.
机译:在网络空间中,一个热门的问题是检测新出现的恶意对象。有很多方法可以检测早期检测到的恶意对象,但不能检测新出现的恶意对象。通常,检测早期检测到的恶意对象的广泛应用的方法是基于签名的检测。但是对于新的恶意对象,历史记录中不存在签名,因此,使用这种方法无法检测到它们。在资产大量损失之后,只能使用基于签名的方法来检测新的恶意对象,因为签名是在持续时间之间生成的。本文旨在提出一种以最佳成本检测新恶意对象的方法。蜜罐通常用于检测新的恶意对象。可用的蜜罐框架过于昂贵,普通组织无法负担。因此,我们提出了一种低成本蜜罐框架来检测名为扩展蜜罐的恶意对象。该方法不仅具有成本效益,而且在某些情况下(例如在Intranet中具有多个LAN,并且每个LAN具有双蜜罐的情况)也比其他方法更好。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号