SDN-based hybrid honeypot for attack capture

被引:0
|
作者
Wang, He [1 ,2 ]
Wu, Bin [2 ,3 ]
机构
[1] Beijing Univ Posts & Telecommun, Sch Comp Sci, Beijing, Peoples R China
[2] Beijing Univ Posts & Telecommun, Natl Disaster Recovery Technol Engn Lab, Beijing, Peoples R China
[3] Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing, Peoples R China
关键词
CyberSecurity; Honeypot; SDN; Traffic migration; Topology simulation;
D O I
10.1109/itnec.2019.8729425
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Honeypots have become an important tool for capturing attacks. Hybrid honeypots, including the front end and the back end, are widely used in research because of the scalability of the front end and the high interactivity of the back end. However, traditional hybrid honeypots have some problems that the flow control is difficult and topology simulation is not realistic. This paper proposes a new architecture based on SDN applied to the hybrid honeypot system for network topology simulation and attack traffic migration. Our system uses the good expansibility and controllability of the SDN controller to simulate a large and realistic network to attract attackers and redirect high-level attacks to a high-interaction honeypot for attack capture and further analysis. It improves the deficiencies in the network spoofing technology and flow control technology in the traditional honeynet. Finally, we set up the experimental environment on the mininet and verified the mechanism. The test results show that the system is more intelligent and the traffic migration is more stealthy.
引用
收藏
页码:1602 / 1606
页数:5
相关论文
共 50 条
  • [31] BDF-SDN: A Big Data Framework for DDoS Attack Detection in Large-Scale SDN-Based Cloud
    Phuc Trinh Dinh
    Park, Minho
    2021 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (DSC), 2021,
  • [32] SDN-based Service Automation for IoT
    Uddin, Mostafa
    Mukherjee, Sarit
    Chang, Hyunseok
    Lakshman, T. V.
    2017 IEEE 25TH INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2017,
  • [33] SDN-based IaaS for Mobile Computing
    Ekanayake, Wijaya
    Amarasinghe, Heli
    Karmouch, Ahmed
    2017 14TH IEEE ANNUAL CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE (CCNC), 2017, : 179 - 184
  • [34] A Case for SDN-based Network Virtualization
    Yang, Gyeongsik
    Shin, Changyong
    Yoo, Yeonho
    Yoo, Chuck
    29TH INTERNATIONAL SYMPOSIUM ON THE MODELING, ANALYSIS, AND SIMULATION OF COMPUTER AND TELECOMMUNICATION SYSTEMS (MASCOTS 2021), 2021, : 158 - 165
  • [35] A proposal for an SDN-based SIEPON architecture
    Khalili, Hamzeh
    Sallent, Sebastia
    Ramon Piney, Jose
    Rincon, David
    OPTICS COMMUNICATIONS, 2017, 403 : 9 - 21
  • [36] A Hybrid Entropy and Blockchain Approach for Network Security Defense in SDN-Based IIoT
    SU Jian
    JIANG Mengnan
    Chinese Journal of Electronics, 2023, 32 (03) : 531 - 541
  • [37] A Hybrid Entropy and Blockchain Approach for Network Security Defense in SDN-Based IIoT
    Su Jian
    Jiang Mengnan
    CHINESE JOURNAL OF ELECTRONICS, 2023, 32 (03) : 531 - 541
  • [38] SDN-based cyber defense: A survey
    Yurekten, Ozgur
    Demirci, Mehmet
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 115 : 126 - 149
  • [39] A QoS framework for SDN-based Networks
    Ghalwash, Haitham
    Huang, Chun-Hsi
    2018 4TH IEEE INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING (CIC 2018), 2018, : 98 - 105
  • [40] A Resilient Mechanism for Multi-Controller Failure in Hybrid SDN-based Networks
    Guillen, Luis
    Izumi, Satoru
    Abe, Toru
    Suganuma, Takuo
    2021 22ND ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS), 2021, : 285 - 290