Title :
Scalable and Performance-Efficient Client Honeypot on High Interaction System
Author :
Akiyama, Mitsuaki ; Kawakoya, Yuhei ; Hariu, Takeo
Author_Institution :
Secure Platform Labortories, NTT Corp., Musashino, Japan
Abstract :
We investigated client honeypots for detecting and circumstantially analyzing drive-by download attacks. A client honeypot requires both improved inspection performance and in-depth analysis for inspecting and discovering malicious websites. However, OS overhead in recent client honeypot operation cannot be ignored for improving honeypot multiplication performance. We propose a client honeypot client system that uses our proposed multi-OS and multi-process honeypot multiplication approaches and implemented this system to evaluate its performance. Our process sandbox mechanism, a security measure for our multi-process approach, creates a virtually isolated environment for each web browser. In a field trial, we confirmed that the use of our multi-process approach was three or more times faster than that of a single process and [our multi-OS approach lineally improved system performance according to the number of honeypot instances. Thus, our proposed multiplication approaches improve performance efficiency and enables in-depth analysis on high interaction systems.
Keywords :
Web sites; online front-ends; operating systems (computers); security of data; OS overhead; Web browser; drive-by download attacks; high interaction system; inspection performance; malicious Websites; multiOS; multiprocess honeypot multiplication approaches; performance-efficient client honeypot; process sandbox mechanism; scalable client honeypot; security measure; virtually isolated environment; Browsers; Inspection; Kernel; Malware; Monitoring; Process control; Rendering (computer graphics); client honeypot; intrusion detection; malware; sandbox;
Conference_Titel :
Applications and the Internet (SAINT), 2012 IEEE/IPSJ 12th International Symposium on
Conference_Location :
Izmir
Print_ISBN :
978-1-4673-2001-6
Electronic_ISBN :
978-0-7695-4737-4
DOI :
10.1109/SAINT.2012.15