DocumentCode :
2300049
Title :
HoneyLab: Large-Scale Honeypot Deployment and Resource Sharing
Author :
Chin, W.Y. ; Markatos, Evangelos P. ; Antonatos, Spiros ; Ioannidis, Sotiris
Author_Institution :
Cryptography & Security Dept., Inst. for Infocomm Res., Singapore, Singapore
fYear :
2009
fDate :
19-21 Oct. 2009
Firstpage :
381
Lastpage :
388
Abstract :
Honeypots are valuable tools for detecting and analyzing malicious activity on the Internet. Successful and time-critical detection of such activity often depends on large-scale deployment. However, commercial organizations usually do not share honeypot data, and large, open honeypot initiatives only provide read-only alert feeds. As a result, while large and resourceful organizations can afford the high cost of this technology, smaller security firms and security researchers are fundamentally constrained. We propose and build a shared infrastructure for deploying and monitoring honeypots, called HoneyLab, that is similar in spirit to PlanetLab. With an overlay and distributed structure of address space and computing resources, HoneyLab increases coverage and accelerates innovation among security researchers as well as security industry experts relying on honeypot-based attack detection technology. Unlike current honeypot infrastructures, HoneyLab allows security firms and security researchers to deploy their own honeypot services, instrumentation code, and detection algorithms, dispensing the need for setting up a separate honeypot infrastructure whenever a new attack detection method needs to be deployed or tested.
Keywords :
Internet; security of data; Internet; commercial organization; honeypot-based attack detection technology; large-scale deployment; malicious activity; planetlab; read-only alert feed; resource sharing; time-critical detection; Costs; Data security; Distributed computing; Feeds; Internet; Large-scale systems; Monitoring; Resource management; Space technology; Time factors; honeypot; honeypot infrastructures; security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network and System Security, 2009. NSS '09. Third International Conference on
Conference_Location :
Gold Coast, QLD
Print_ISBN :
978-1-4244-5087-9
Electronic_ISBN :
978-0-7695-3838-9
Type :
conf
DOI :
10.1109/NSS.2009.65
Filename :
5319295
Link To Document :
بازگشت