Title

Honeypot Detection In Advanced Botnet Attacks

Keywords

Botnets; Honeypots; Liability; Modelling; P2P; Peer-to-peer

Abstract

Botnets have become one of the major attacks in the internet today due to their illicit profitable financial gain. Meanwhile, honeypots have been successfully deployed in many computer security defence systems. Since honeypots set up by security defenders can attract botnet compromises and become spies in exposing botnet membership and botnet attacker behaviours, they are widely used by security defenders in botnet defence. Therefore, attackers constructing and maintaining botnets will be forced to find ways to avoid honeypot traps. In this paper, we present a hardware and software independent honeypot detection methodology based on the following assumption: security professionals deploying honeypots have a liability constraint such that they cannot allow their honeypots to participate in real attacks that could cause damage to others, while attackers do not need to follow this constraint. Attackers could detect honeypots in their botnets by checking whether compromised machines in a botnet can successfully send out unmodified malicious traffic. Based on this basic detection principle, we present honeypot detection techniques to be used in both centralised botnets and Peer-to-Peer (P2P) structured botnets. Experiments show that current standard honeypots and honeynet programs are vulnerable to the proposed honeypot detection techniques. At the end, we discuss some guidelines for defending against general honeypot-aware attacks. Copyright © 2010 Inderscience Enterprises Ltd.

Publication Date

1-1-2010

Publication Title

International Journal of Information and Computer Security

Volume

4

Issue

1

Number of Pages

30-51

Document Type

Article

Personal Identifier

scopus

DOI Link

https://doi.org/10.1504/IJICS.2010.031858

Socpus ID

77649311672 (Scopus)

Source API URL

https://api.elsevier.com/content/abstract/scopus_id/77649311672

This document is currently not available here.

Share

COinS