A4 Vertaisarvioitu artikkeli konferenssijulkaisussa

A Comparison of Record and Play Honeypot Designs




TekijätPapalitsas Jarko, Rauti Sampsa, Leppänen Ville

ToimittajaRachev Boris, Smrikarov Angel

Konferenssin vakiintunut nimiInternational Conference on Computer Systems and Technologies

KustannuspaikkaNew York

Julkaisuvuosi2017

Kokoomateoksen nimiProceedings of the 18th International Conference on Computer Systems and Technologies

Sarjan nimiACM International Conference Proceedings Series

Numero sarjassa1369

Aloitussivu133

Lopetussivu140

Sivujen määrä8

ISBN978-1-4503-5234-5

DOIhttps://doi.org/10.1145/3134302.3134307

Verkko-osoitehttps://dl.acm.org/citation.cfm?doid=3134302.3134307

Rinnakkaistallenteen osoitehttps://research.utu.fi/converis/portal/detail/Publication/28531838


Tiivistelmä

Record and play -honeypots mimic the normal TCP traffic and fool the adversary with fake data
while simultaneously keeping the setting realistic. In this paper, we propose several designs for such honeypots.
Two important aspects of honeypot design are considered. First, we compare named entity recognition systems
in order to recognize the entities in the messages the honeypot modifies. Second, we consider methods to
fake these entities consistently. Pros and cons of each approach – varying from the better accuracy of the fake
responses to the possibility of causing side effects on the real services – are discussed.


Ladattava julkaisu

This is an electronic reprint of the original article.
This reprint may differ from the original in pagination and typographic detail. Please cite the original version.





Last updated on 2024-26-11 at 21:19