Title :
Towards Simulating a Virtual Distributed Honeynet at KFUPM: A Case Study
Author :
Sqalli, M. ; Al-Shaikh, Raed ; Ahmed, Erfan
Author_Institution :
Dept. of Comput. Eng., King Fahd Univ. of Pet. & Miner., Dhahran, Saudi Arabia
Abstract :
In recent years, there has been a growing interest in information protection and security for large organizations. This has led to a growing demand for more aggressive forms of security to complement the existing techniques. One of these security methods involves the use of distributed honey nets. Honey nets are network systems deployed for the sole purpose of being compromised, in order to assess adversaries. In this paper, we conduct a comprehensive survey for implementing distributed honey nets and explain their architecture and design. We also present our experience in simulating a virtual distributed honey net environment at King Fahd University of Petroleum and Minerals (KFUPM) using Honey wall CDROM, Snort and Sebek tools. Our experience shows that Honey wall CDROM proved to be a solid tool that is capable of capturing great deal of information and assisting in analyzing traffic on the distributed honey pots. The honey net designer, nevertheless, needs to consider few issues related to scalability and resource utilization.
Keywords :
computer network security; KFUPM; distributed honey nets; distributed honey pots; honey net designer; information protection; network systems; security; virtual distributed honey net environment; virtual distributed honeynet; Computers; Forensics; IP networks; Monitoring; Organizations; Security; Servers; Honeynets; Honeypots; IDS;
Conference_Titel :
Computer Modeling and Simulation (EMS), 2010 Fourth UKSim European Symposium on
Conference_Location :
Pisa
Print_ISBN :
978-1-4244-9313-5
DOI :
10.1109/EMS.2010.58