DocumentCode
2858799
Title
The Leurre.com Project: Collecting Internet Threats Information Using a Worldwide Distributed Honeynet
Author
Leita, C. ; Pham, V.H. ; Thonnard, O. ; Ramirez-Silva, E. ; Pouget, F. ; Kirda, E. ; Dacier, M.
Author_Institution
Inst. Eurecom, Sophia Antipolis
fYear
2008
fDate
21-22 April 2008
Firstpage
40
Lastpage
57
Abstract
This paper aims at presenting in some depth the Leurre.com project and its data collection infrastructure. Launched in 2003 by the Institut Eurecom, this project is based on a worldwide distributed system of honeypots running in more than 30 different countries. The main objective of the project is to get a more realistic picture of certain classes of threats happening on the Internet, by collecting unbiased quantitative data in a long-term perspective. In the first phase of the project, the data collection infrastructure relied solely on low-interaction sensors based on Honeyd to collect unsolicited traffic on the Internet. Recently, a second phase of the project was started with the deployment of medium-interaction honeypots based on the ScriptGen technology, in order to enrich the network conversations with the attackers. All network traces captured on the platforms are automatically uploaded into a centralized database accessible by the partners via a convenient interface. The collected traffic is also enriched with a set of contextual information (e.g. geographical localization and reverse DNS lookups). This paper presents this complex data collection infrastructure, and offers some insight into the structure of the central data repository. The data access interface has been developed to facilitate the analysis of today´s Internet threats, for example by means of data mining tools. Some concrete examples are presented to illustrate the richness and the power of this data access interface. By doing so, we hope to encourage other researchers to share with us their knowledge and data sets, to complement or enhance our ongoing analysis efforts, with the ultimate goal of better understanding Internet threats.
Keywords
Internet; information retrieval; security of data; Honeyd; Internet threats information; Leurre.com project; ScriptGen technology; data access interface; data collection; data mining tool; unsolicited traffic; worldwide distributed Honeynet; Data mining; Databases; Information retrieval; Information security; Information systems; Internet; Monitoring; Protection; Telecommunication traffic; Telescopes; Internet threats collection; honeynet; threats analysis;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Security Threats Data Collection and Sharing, 2008. WISTDCS '08. WOMBAT Workshop on
Conference_Location
Amsterdam
Print_ISBN
978-0-7695-3347-6
Type
conf
DOI
10.1109/WISTDCS.2008.8
Filename
4627314
Link To Document