Title : 
Scalable and Performance-Efficient Client Honeypot on High Interaction System
         
        
            Author : 
Akiyama, Mitsuaki ; Kawakoya, Yuhei ; Hariu, Takeo
         
        
            Author_Institution : 
Secure Platform Labortories, NTT Corp., Musashino, Japan
         
        
        
        
        
        
            Abstract : 
We investigated client honeypots for detecting and circumstantially analyzing drive-by download attacks. A client honeypot requires both improved inspection performance and in-depth analysis for inspecting and discovering malicious websites. However, OS overhead in recent client honeypot operation cannot be ignored for improving honeypot multiplication performance. We propose a client honeypot client system that uses our proposed multi-OS and multi-process honeypot multiplication approaches and implemented this system to evaluate its performance. Our process sandbox mechanism, a security measure for our multi-process approach, creates a virtually isolated environment for each web browser. In a field trial, we confirmed that the use of our multi-process approach was three or more times faster than that of a single process and [our multi-OS approach lineally improved system performance according to the number of honeypot instances. Thus, our proposed multiplication approaches improve performance efficiency and enables in-depth analysis on high interaction systems.
         
        
            Keywords : 
Web sites; online front-ends; operating systems (computers); security of data; OS overhead; Web browser; drive-by download attacks; high interaction system; inspection performance; malicious Websites; multiOS; multiprocess honeypot multiplication approaches; performance-efficient client honeypot; process sandbox mechanism; scalable client honeypot; security measure; virtually isolated environment; Browsers; Inspection; Kernel; Malware; Monitoring; Process control; Rendering (computer graphics); client honeypot; intrusion detection; malware; sandbox;
         
        
        
        
            Conference_Titel : 
Applications and the Internet (SAINT), 2012 IEEE/IPSJ 12th International Symposium on
         
        
            Conference_Location : 
Izmir
         
        
            Print_ISBN : 
978-1-4673-2001-6
         
        
            Electronic_ISBN : 
978-0-7695-4737-4
         
        
        
            DOI : 
10.1109/SAINT.2012.15