DocumentCode :
1392099
Title :
Agent-based honeynet framework for protecting servers in campus networks
Author :
Kim, Ihn Seok ; Kim, Min H.
Author_Institution :
Sch. of Comput. Sci. & Eng., Soongsil Univ., Seoul, South Korea
Volume :
6
Issue :
3
fYear :
2012
Firstpage :
202
Lastpage :
211
Abstract :
Intrusion detection systems (IDSs) and intrusion prevention systems (IPSs) that use signatures cannot protect servers from new types of internet worms. Therefore it is important to collect information about new attacks because the detection rules employed by IDSs and IPSs are formulated using this information. Honeypots are valuable security resources that act as baits for attackers. They can monitor intrusions by being probed, attacked or compromised and can detect zero-day attacks and provide researchers intending to improve security with information about the attacks. However, it is almost impossible to immediately generate detection rules from the information collected by honeypots. This study presents an agent-based honeynet framework for protecting servers in a campus network. In this framework, agents remove malicious processes and executable files on servers infected by zero-day attacks as soon as the honeynet detects them. The proposed framework provides a novel defense mechanism that protects servers from new types of internet worms effectively, without the use of signatures.
Keywords :
Internet; security of data; software agents; Honeypots; IDS; IPS; Internet worms; agent based honeynet framework; campus networks; intrusion detection systems; intrusion prevention systems; malicious processes; protecting servers; zero-day attacks;
fLanguage :
English
Journal_Title :
Information Security, IET
Publisher :
iet
ISSN :
1751-8709
Type :
jour
DOI :
10.1049/iet-ifs.2011.0154
Filename :
6397165
Link To Document :
بازگشت