Scalable and Performance-Efficient Client Honeypot on High Interaction System

被引:4
作者
Akiyama, Mitsuaki [1 ]
Kawakoya, Yuhei [1 ]
Hariu, Takeo [1 ]
机构
[1] NTT Corp, Secure Platform Labs, Musashino, Tokyo 1808585, Japan
来源
2012 IEEE/IPSJ 12TH INTERNATIONAL SYMPOSIUM ON APPLICATIONS AND THE INTERNET (SAINT) | 2012年
关键词
malware; client honeypot; intrusion detection; sandbox;
D O I
10.1109/SAINT.2012.15
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
We investigated client honeypots for detecting and circumstantially analyzing drive-by download attacks. A client honeypot requires both improved inspection performance and in-depth analysis for inspecting and discovering malicious websites. However, OS overhead in recent client honeypot operation cannot be ignored for improving honeypot multiplication performance. We propose a client honeypot client system that uses our proposed multi-OS and multi-process honeypot multiplication approaches and implemented this system to evaluate its performance. Our process sandbox mechanism, a security measure for our multi-process approach, creates a virtually isolated environment for each web browser. In a field trial, we confirmed that the use of our multi-process approach was three or more times faster than that of a single process and [our multi-OS approach lineally improved system performance according to the number of honeypot instances. Thus, our proposed multiplication approaches improve performance efficiency and enables in-depth analysis on high interaction systems.
引用
收藏
页码:40 / 50
页数:11
相关论文
共 8 条
[1]  
Akiyama M., 2011, P 11 IEEE IPSJ INT S
[2]   Design and Implementation of High Interaction Client Honeypot for Drive-by-Download Attacks [J].
Akiyama, Mitsuaki ;
Iwamura, Makoto ;
Kawakoya, Yuhei ;
Aoki, Kazufumi ;
Itoh, Mitsutaka .
IEICE TRANSACTIONS ON COMMUNICATIONS, 2010, E93B (05) :1131-1139
[3]  
Alexa, TOP 100 SIT WEB
[4]  
[Anonymous], 3 USENIX WIND NT S
[5]  
Lu L., 2010, 17 ACM C COMP COMM S
[6]  
MSDN, IWEBBROWSER2 INT
[7]  
Seifert C., 2008, CAPTURE HONEYPOT CLI
[8]  
Stokes J.W., 2010, LEET 10 P 3 US WORKS