DocumentCode
1952886
Title
An FPGA-based scalable platform for high-speed malware collection in large IP networks
Author
Mühlbach, Sascha ; Koch, Andreas
Author_Institution
Secure Things Group, Center for Adv. Security Res. Darmstadt (CASED), Darmstadt, Germany
fYear
2010
fDate
8-10 Dec. 2010
Firstpage
474
Lastpage
478
Abstract
With the growing diversity of malware, researchers must be able to quickly collect many representative samples for study. This is commonly achieved by harvesting the malware from honeypots: Insecure systems presenting a wide attack surface to the public Internet, aiming to attract attackers. However, software-based honeypots have both performance issues in light of 10+ Gb/s networks, as well as difficulties in preventing the compromise of the honeypot system itself. We present an architecture for a honeypot using dedicated hardware instead of a general-purpose processor. Our system is fast enough to keep up with high-speed networks and more resilient against subversion attempts than existing software solutions. It consists of a high-speed implementation of the Internet protocol stack attached to hardware-based emulations of vulnerable applications. A specialized implementation of the TCP protocol, capable of managing hundreds of thousands of simultaneous connections, allows the system to span large honeynets. The practical feasibility of the approach has been demonstrated on a real FPGA platform connected to a 10 Gb/s network interface.
Keywords
IP networks; Internet; computer network security; field programmable gate arrays; invasive software; transport protocols; FPGA; Internet protocol stack; TCP protocol; bit rate 10 Gbit/s; general-purpose processor; hardware-based emulations; high-speed malware collection; high-speed networks; large IP networks; network interface; public Internet; software-based honeypots; Emulation; IP networks; Malware; Protocols; Web server;
fLanguage
English
Publisher
ieee
Conference_Titel
Field-Programmable Technology (FPT), 2010 International Conference on
Conference_Location
Beijing
Print_ISBN
978-1-4244-8980-0
Type
conf
DOI
10.1109/FPT.2010.5681462
Filename
5681462
Link To Document