首页> 外文期刊>International Journal of Engineering Research and Applications >Design and Implementation of Linux Based Hybrid Client Honeypot Incorporating Multi Layer Detection
【24h】

Design and Implementation of Linux Based Hybrid Client Honeypot Incorporating Multi Layer Detection

机译:结合多层检测的基于Linux的混合客户端蜜罐的设计与实现

获取原文
       

摘要

In current global internet cyber space, the number of targeted client side attacks are increasing that lead users to adversaries' w eb sites and exploit web browser vulnerabilities is increasing, therefore there is requirement of strong mechanisms to fight against these kinds of attacks. In this paper, w e present the design and implementation of a client honeypot which incorporate the functionality of both low and high interaction honeyclient solution and incorporate the multi layer detection mechanisms to fight against client side targeted attacks. As low interaction client honeypot are fast in processing of websites but unable to detect zero-day attacks whereas high interaction client honeypots are able to detect zero day attacks but very high resource intensiv e. On the basis of the problems of existing client honeypots, we formulate the requirements of this hybrid honeyclient solution in terms of defending client side attacks. Our system is tested by visiting of various malicious websites and detection of malwares dropped on the system is detected. Also an approach is also been discussed to deploy the hybrid honeyclient solution for detection of malicious websites and collections of malw ares embedded into malicious websites. We are ensuring that most of software tools used in our implementation are open source
机译:在当前的全球互联网网络空间中,有针对性的客户端攻击的数量正在增加,从而导致用户访问对手的网站并利用Web浏览器漏洞,因此,需要有强大的机制来对抗此类攻击。在本文中,我们将介绍客户端蜜罐的设计和实现,该蜜罐结合了低交互和高交互honeyclient解决方案的功能,并结合了多层检测机制来抵抗客户端定向攻击。由于低交互性客户端蜜罐能够快速处理网站,但无法检测到零日攻击,而高交互性客户端蜜罐能够检测到零日攻击,但是资源强度很高。基于现有客户端honeypot的问题,我们在防御客户端攻击方面制定了此混合honeyclient解决方案的要求。我们的系统通过访问各种恶意网站进行了测试,并且检测到丢弃在系统上的恶意软件。还讨论了一种方法,用于部署混合honeyclient解决方案以检测恶意网站和嵌入恶意网站的恶意软件集合。我们确保实施中使用的大多数软件工具都是开源的

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号