DocumentCode :
3233779
Title :
Comparative survey of local honeypot sensors to assist network forensics
Author :
Chen, P.T. ; Laih, C.S. ; Pouget, F. ; Dacier, M.
Author_Institution :
Nat. Cheng Kung Univ., Tainan, Taiwan
fYear :
2005
fDate :
7-9 Nov. 2005
Firstpage :
120
Lastpage :
132
Abstract :
This paper intends to illustrate the usefulness of deploying multiple simple honeypot sensors in a large variety of locations. Indeed, a permanent identification of anomalies that occur on a single sensor allows pinpointing abnormal local activities. These can be the manifest of misconfiguration issues or highlight attacks particular to some given environments. Both cases are important for administrators in charge of the networks hosting the sensors. We propose in this paper a comparison of simple parameters that reveal to be an easy way to determine these abnormal and particular activities. On the basis of two identical honeypot sensors that we have deployed for more than 6 months in France and in Taiwan, we detail the analysis of some anomalies that have been found against one unique sensor only. This is a preliminary but useful stage for network forensics and we intend in a near future to deploy the method over a large number of sensors. This is an on-going work and we hope that the illustrations we provide all along the paper a good incentive for partners to join this open project.
Keywords :
Internet; security of data; telecommunication security; telecommunication traffic; Internet; local honeypot sensor; network forensics; telecommunication traffic; Forensics; IP networks; Internet; Local activities; Monitoring; Sensor phenomena and characterization; Sensor systems; Telecommunication traffic; Telescopes; Weather forecasting;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Systematic Approaches to Digital Forensic Engineering, 2005. First International Workshop on
Print_ISBN :
0-7695-2478-8
Type :
conf
DOI :
10.1109/SADFE.2005.6
Filename :
1592526
Link To Document :
بازگشت