首页> 外文期刊>Operating systems review >Scalability, Fidelity, and Containment in the Potemkin Virtual Honeyfarm
【24h】

Scalability, Fidelity, and Containment in the Potemkin Virtual Honeyfarm

机译:Potemkin虚拟Honeyfarm中的可伸缩性,保真度和包容性

获取原文
获取原文并翻译 | 示例
           

摘要

The rapid evolution of large-scale worms, viruses and bot-nets have made Internet malware a pressing concern. Such infections are at the root of modern scourges including DDoS extortion, on-line identity theft, SPAM, phishing, and piracy. However, the most widely used tools for gathering intelligence on new malware — network honeypots — have forced investigators to choose between monitoring activity at a large scale or capturing behavior with high fidelity. In this paper, we describe an approach to minimize this tension and improve honeypot scalability by up to six orders of magnitude while still closely emulating the execution behavior of individual Internet hosts. We have built a prototype honeyfarm system, called Potemkin, that exploits virtual machines, aggressive memory sharing, and late binding of resources to achieve this goal. While still an immature implementation, Potemkin has emulated over 64,000 Internet honeypots in live test runs, using only a handful of physical servers.
机译:大规模蠕虫,病毒和僵尸网络的迅速发展使Internet恶意软件成为迫切关注的问题。这种感染是包括DDoS勒索,在线身份盗用,SPAM,网络钓鱼和盗版在内的现代祸害的根源。但是,用于收集有关新恶意软件情报的最广泛使用的工具(网络蜜罐)已迫使调查人员在大规模监视活动或高保真捕获行为之间做出选择。在本文中,我们描述了一种方法,可以最大程度地减少这种压力并提高蜜罐可扩展性达六个数量级,同时仍然可以紧密模拟单个Internet主机的执行行为。我们已经建立了一个称为Potemkin的原型蜜农场系统,该系统利用虚拟机,积极的内存共享和后期资源绑定来实现此目标。尽管仍然不成熟,但Potemkin仅使用少量物理服务器就在实时测试中模拟了超过64,000个Internet蜜罐。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号