• DocumentCode
    1392099
  • Title

    Agent-based honeynet framework for protecting servers in campus networks

  • Author

    Kim, Ihn Seok ; Kim, Min H.

  • Author_Institution
    Sch. of Comput. Sci. & Eng., Soongsil Univ., Seoul, South Korea
  • Volume
    6
  • Issue
    3
  • fYear
    2012
  • Firstpage
    202
  • Lastpage
    211
  • Abstract
    Intrusion detection systems (IDSs) and intrusion prevention systems (IPSs) that use signatures cannot protect servers from new types of internet worms. Therefore it is important to collect information about new attacks because the detection rules employed by IDSs and IPSs are formulated using this information. Honeypots are valuable security resources that act as baits for attackers. They can monitor intrusions by being probed, attacked or compromised and can detect zero-day attacks and provide researchers intending to improve security with information about the attacks. However, it is almost impossible to immediately generate detection rules from the information collected by honeypots. This study presents an agent-based honeynet framework for protecting servers in a campus network. In this framework, agents remove malicious processes and executable files on servers infected by zero-day attacks as soon as the honeynet detects them. The proposed framework provides a novel defense mechanism that protects servers from new types of internet worms effectively, without the use of signatures.
  • Keywords
    Internet; security of data; software agents; Honeypots; IDS; IPS; Internet worms; agent based honeynet framework; campus networks; intrusion detection systems; intrusion prevention systems; malicious processes; protecting servers; zero-day attacks;
  • fLanguage
    English
  • Journal_Title
    Information Security, IET
  • Publisher
    iet
  • ISSN
    1751-8709
  • Type

    jour

  • DOI
    10.1049/iet-ifs.2011.0154
  • Filename
    6397165