当前位置: X-MOL 学术Complex Intell. Syst. › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
A computational intelligence enabled honeypot for chasing ghosts in the wires
Complex & Intelligent Systems ( IF 5.8 ) Pub Date : 2020-11-02 , DOI: 10.1007/s40747-020-00209-5
Nitin Naik , Paul Jenkins , Nick Savage , Longzhi Yang

A honeypot is a concealed security system that functions as a decoy to entice cyberattackers to reveal their information. Therefore, it is essential to disguise its identity to ensure its successful operation. Nonetheless, cyberattackers frequently attempt to uncover these honeypots; one of the most effective techniques for revealing their identity is a fingerprinting attack. Once identified, a honeypot can be exploited as a zombie by an attacker to attack others. Several effective techniques are available to prevent a fingerprinting attack, however, that would be contrary to the purpose of a honeypot, which is designed to interact with attackers to attempt to discover information relating to them. A technique to discover any attempted fingerprinting attack is highly desirable, for honeypots, while interacting with cyberattackers. Unfortunately, no specific method is available to detect and predict an attempted fingerprinting attack in real-time due to the difficulty of isolating it from other attacks. This paper presents a computational intelligence enabled honeypot that is capable of discovering and predicting an attempted fingerprinting attack by using a Principal components analysis and Fuzzy inference system. This proposed system is successfully tested against the five popular fingerprinting tools Nmap, Xprobe2, NetScanTools Pro, SinFP3 and Nessus.



中文翻译:

支持计算智能的蜜罐,用于追踪电线中的鬼影

蜜罐是一种隐藏的安全系统,可以诱骗网络攻击者泄露其信息。因此,必须掩盖其身份以确保其成功运行。但是,网络攻击者经常试图发现这些蜜罐。揭示其身份的最有效技术之一是指纹攻击。一旦被识别,蜜罐就可以被攻击者当作僵尸攻击他人。有几种有效的技术可用来防止指纹攻击,但这与蜜罐的目的相反,蜜罐的目的是与攻击者进行交互以尝试发现与他们有关的信息。对于蜜罐,在与网络攻击者进行交互时,非常需要一种发现任何尝试的指纹攻击的技术。不幸,由于很难将指纹攻击与其他攻击隔离开,因此没有特定的方法可以实时检测和预测尝试的指纹攻击。本文提出了一种具有计算智能功能的蜜罐,该蜜罐能够通过使用主成分分析和模糊推理系统来发现和预测尝试的指纹攻击。该提议的系统已针对五个流行的指纹识别工具Nmap,Xprobe2,NetScanTools Pro,SinFP3和Nessus成功进行了测试。本文提出了一种具有计算智能功能的蜜罐,该蜜罐能够通过使用主成分分析和模糊推理系统来发现和预测尝试的指纹攻击。该提议的系统已针对五个流行的指纹识别工具Nmap,Xprobe2,NetScanTools Pro,SinFP3和Nessus成功进行了测试。本文提出了一种具有计算智能能力的蜜罐,该蜜罐能够通过使用主成分分析和模糊推理系统来发现和预测未遂指纹攻击。该提议的系统已针对五个流行的指纹识别工具Nmap,Xprobe2,NetScanTools Pro,SinFP3和Nessus成功进行了测试。

更新日期:2020-11-02
down
wechat
bug