DocumentCode
1392099
Title
Agent-based honeynet framework for protecting servers in campus networks
Author
Kim, Ihn Seok ; Kim, Min H.
Author_Institution
Sch. of Comput. Sci. & Eng., Soongsil Univ., Seoul, South Korea
Volume
6
Issue
3
fYear
2012
Firstpage
202
Lastpage
211
Abstract
Intrusion detection systems (IDSs) and intrusion prevention systems (IPSs) that use signatures cannot protect servers from new types of internet worms. Therefore it is important to collect information about new attacks because the detection rules employed by IDSs and IPSs are formulated using this information. Honeypots are valuable security resources that act as baits for attackers. They can monitor intrusions by being probed, attacked or compromised and can detect zero-day attacks and provide researchers intending to improve security with information about the attacks. However, it is almost impossible to immediately generate detection rules from the information collected by honeypots. This study presents an agent-based honeynet framework for protecting servers in a campus network. In this framework, agents remove malicious processes and executable files on servers infected by zero-day attacks as soon as the honeynet detects them. The proposed framework provides a novel defense mechanism that protects servers from new types of internet worms effectively, without the use of signatures.
Keywords
Internet; security of data; software agents; Honeypots; IDS; IPS; Internet worms; agent based honeynet framework; campus networks; intrusion detection systems; intrusion prevention systems; malicious processes; protecting servers; zero-day attacks;
fLanguage
English
Journal_Title
Information Security, IET
Publisher
iet
ISSN
1751-8709
Type
jour
DOI
10.1049/iet-ifs.2011.0154
Filename
6397165
Link To Document