...
首页> 外文期刊>Journal of electrical and computer engineering >Strengthening MT6D Defenses with LXC-Based Honeypot Capabilities
【24h】

Strengthening MT6D Defenses with LXC-Based Honeypot Capabilities

机译:基于LXC的蜜罐功能增强MT6D防御

获取原文
获取原文并翻译 | 示例
           

摘要

Moving Target IPv6 Defense (MT6D) imparts radio-frequency hopping behavior to IPv6 networks by having participating nodes periodically hop onto new addresses while giving up old addresses. Our previous research efforts implemented a solution to identify and acquire these old addresses that are being discarded by MT6D hosts on a local network besides being able to monitor and visualize the incoming traffic on these addresses. This was essentially equivalent to forming a darknet out of the discarded MT6D addresses, but the solution presented in the previous research effort did not include database integration for it to scale and be extended. This paper presents a solution with a new architecture that not only extends the previous solution in terms of automation and database integration but also demonstrates the ability to deploy a honeypot on a virtual LXC (Linux Container) on-demand based on any interesting traffic pattern observed on a discarded address. The proposed architecture also allows an MT6D host to query the solution database for network activity on its relinquished addresses as a JavaScript Object Notation (JSON) object. This allows an MT6D host to identify suspicious activity on its discarded addresses and strengthen the MT6D scheme parameters accordingly. We have built a proof-of-concept for the proposed solution and analyzed the solution's feasibility and scalability.
机译:移动目标IPv6防御(MT6D)通过让参与节点在放弃旧地址的同时定期跳到新地址上,从而向IPv6网络赋予射频跳频行为。我们以前的研究工作实施了一种解决方案,以识别和获取这些旧地址,这些旧地址除了可以监视和可视化这些地址上的传入流量外,还被局域网上的MT6D主机丢弃。从本质上讲,这相当于从被丢弃的MT6D地址中形成一个暗网,但是先前的研究工作中提出的解决方案并未包括数据库集成以进行扩展和扩展。本文提出了一种具有新架构的解决方案,该解决方案不仅在自动化和数据库集成方面扩展了先前的解决方案,而且还展示了根据观察到的任何有趣流量模式按需在虚拟LXC(Linux容器)上部署蜜罐的能力。在一个废弃的地址上。所提出的体系结构还允许MT6D主机在解决方案数据库中查询其放弃的地址上的网络活动,作为JavaScript对象符号(JSON)对象。这使MT6D主机可以识别其丢弃地址上的可疑活动,并相应地增强MT6D方案参数。我们已经为提出的解决方案建立了概念验证,并分析了该解决方案的可行性和可扩展性。

著录项

  • 来源
    《Journal of electrical and computer engineering》 |2016年第1期|5212314.1-5212314.13|共13页
  • 作者单位

    Bradley Department of Electrical and Computer Engineering, Virginia Tech, Blacksburg, VA 24061, USA;

    Bradley Department of Electrical and Computer Engineering, Virginia Tech, Blacksburg, VA 24061, USA;

    Bradley Department of Electrical and Computer Engineering, Virginia Tech, Blacksburg, VA 24061, USA;

    Bradley Department of Electrical and Computer Engineering, Virginia Tech, Blacksburg, VA 24061, USA;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号