DocumentCode :
2143069
Title :
Design and implementation of honeypot systems based on open-source software
Author :
Yeh, Chao-Hsi ; Yang, Chung-Huang
Author_Institution :
Grad. Inst. of Inf. & Comput. Educ., Nat. Kaohsiung Normal Univ., Kaohsiung
fYear :
2008
fDate :
17-20 June 2008
Firstpage :
265
Lastpage :
266
Abstract :
A honeypot is a type of information system that is used to obtain information on intruders in a network. When a honeypot is deployed in front of a firewall, it can serve as an early warning system. When deployed behind the firewall, it can serve as part of a defense-in-depth system and can be used to detect attackers who bypass the firewall and the intrusion detection system (IDS) or threats from insiders. Honeyd is an open-source honeypot; however, it uses a command-line interface and its configuration is difficult for beginners. The purpose of this study is to use the open-source tool to construct a graphic user interface (GUI) for honeyd. For the sake of portability and easy deployment, the whole system will be installed in a live USB stick. The end user can create a honeyd template by using the GUI or the result of the Nmap scan of a target computer. Moreover, the system will provide a log-review interface and real-time SMS functionality. Finally, we deployed the designed system in a campus network and presented an analytic result of a 60-day period with a Web-based data analysis system.
Keywords :
authorisation; computer networks; graphical user interfaces; public domain software; Nmap scan; command-line interface; defense-in-depth system; firewall; graphic user interface; honeyd; honeypot system; information system; intrusion detection system; network intruder; open-source software; Alarm systems; Computer graphics; Data analysis; Graphical user interfaces; Information systems; Intrusion detection; Open source software; Real time systems; Universal Serial Bus; User interfaces;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Intelligence and Security Informatics, 2008. ISI 2008. IEEE International Conference on
Conference_Location :
Taipei
Print_ISBN :
978-1-4244-2414-6
Electronic_ISBN :
978-1-4244-2415-3
Type :
conf
DOI :
10.1109/ISI.2008.4565077
Filename :
4565077
Link To Document :
بازگشت