Title
Honeypot Detection In Advanced Botnet Attacks
Keywords
Botnets; Honeypots; Liability; Modelling; P2P; Peer-to-peer
Abstract
Botnets have become one of the major attacks in the internet today due to their illicit profitable financial gain. Meanwhile, honeypots have been successfully deployed in many computer security defence systems. Since honeypots set up by security defenders can attract botnet compromises and become spies in exposing botnet membership and botnet attacker behaviours, they are widely used by security defenders in botnet defence. Therefore, attackers constructing and maintaining botnets will be forced to find ways to avoid honeypot traps. In this paper, we present a hardware and software independent honeypot detection methodology based on the following assumption: security professionals deploying honeypots have a liability constraint such that they cannot allow their honeypots to participate in real attacks that could cause damage to others, while attackers do not need to follow this constraint. Attackers could detect honeypots in their botnets by checking whether compromised machines in a botnet can successfully send out unmodified malicious traffic. Based on this basic detection principle, we present honeypot detection techniques to be used in both centralised botnets and Peer-to-Peer (P2P) structured botnets. Experiments show that current standard honeypots and honeynet programs are vulnerable to the proposed honeypot detection techniques. At the end, we discuss some guidelines for defending against general honeypot-aware attacks. Copyright © 2010 Inderscience Enterprises Ltd.
Publication Date
1-1-2010
Publication Title
International Journal of Information and Computer Security
Volume
4
Issue
1
Number of Pages
30-51
Document Type
Article
Personal Identifier
scopus
DOI Link
https://doi.org/10.1504/IJICS.2010.031858
Copyright Status
Unknown
Socpus ID
77649311672 (Scopus)
Source API URL
https://api.elsevier.com/content/abstract/scopus_id/77649311672
STARS Citation
Wang, Ping; Wu, Lei; Cunningham, Ryan; and Zou, Cliff C., "Honeypot Detection In Advanced Botnet Attacks" (2010). Scopus Export 2010-2014. 1850.
https://stars.library.ucf.edu/scopus2010/1850