A Comparison of Record and Play Honeypot Designs
Comparison_of_Record_and_Play_Honeypot_Implementations31032017.pdf - 445.06 KB
Lataukset86
Pysyvä osoite
Verkkojulkaisu
Tiivistelmä
Record and play -honeypots mimic the normal TCP traffic and fool the adversary with fake data
while simultaneously keeping the setting realistic. In this paper, we propose several designs for such honeypots.
Two important aspects of honeypot design are considered. First, we compare named entity recognition systems
in order to recognize the entities in the messages the honeypot modifies. Second, we consider methods to
fake these entities consistently. Pros and cons of each approach – varying from the better accuracy of the fake
responses to the possibility of causing side effects on the real services – are discussed.
Sarja
ACM International Conference Proceedings Series