首页> 外文会议>2017 International Conference On Smart Technologies For Smart Nation >HoneynetTrap: Analysis of insider threat detection using agent oriented PN2 simulator
【24h】

HoneynetTrap: Analysis of insider threat detection using agent oriented PN2 simulator

机译:HoneynetTrap:使用面向代理的PN 2 模拟器分析内部威胁

获取原文
获取原文并翻译 | 示例

摘要

Insider threat is one of the major concerns for an organization that breaches the confidentiality and integrity of enterprise data. Different approaches have been proposed to mitigate this problem but most of them are time consuming and ineffective. In this paper, we have proposed the use of honeytokens to curb this problem. Honeytokens are the fake data items that are created manually or generated in the real database that value lays in using those tokens by an attacker. A honeypot is used at the filtering bridge that comprises of two modules mainly, Honeytoken generation module and insider threat detection module. Malicious outbound requests are transferred to EDoS server and legitimate one is forwarded to the outside destination. We have used Petri-net based agent oriented simulator PN2Sim to simulate the proposed framework. The proposed approach has been verified with reachability property using SPIN tool.
机译:内部威胁是组织违反企业数据的机密性和完整性的主要问题之一。已经提出了不同的方法来减轻该问题,但是大多数方法耗时且无效。在本文中,我们提出了使用honeytokens来解决这个问题。 Honeytokens是伪造的数据项,它们是手动创建的或在真实数据库中生成的,其价值在于攻击者使用这些令牌。蜜罐用于过滤桥,蜜桥主要由两个模块组成,蜜罐生成模块和内部威胁检测模块。恶意的出站请求被传输到esS服务器,合法的请求被转发到外部目的地。我们已经使用了基于Petri-net的面向代理的仿真器PN2Sim来仿真所提出的框架。使用SPIN工具已经验证了所提出的方法具有可达性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号