首页> 外文会议>International Symposium on Recent Advances in Intrusion Detection(RAID 2006); 20060920-22; Hamburg(DE) >Automatic Handling of Protocol Dependencies and Reaction to 0-Day Attacks with ScriptGen Based Honeypots
【24h】

Automatic Handling of Protocol Dependencies and Reaction to 0-Day Attacks with ScriptGen Based Honeypots

机译:使用基于ScriptGen的蜜罐自动处理协议依赖性和对0天攻击的反应

获取原文
获取原文并翻译 | 示例

摘要

Spitzner proposed to classify honeypots into low, medium and high interaction ones. Several instances of low interaction exist, such as honeyd, as well as high interaction, such as GenII. Medium interaction systems have recently received increased attention. ScriptGen and Role-Player, for instance, are as talkative as a high interaction system while limiting the associated risks. In this paper, we do build upon the work we have proposed on ScriptGen to automatically create honeyd scripts able to interact with attack tools without relying on any a-priori knowledge of the protocols involved. The main contributions of this paper are threefold. First, we propose a solution to detect and handle so-called intra-protocol dependencies. Second, we do the same for inter-protocols dependencies. Last but not least, we show how, by modifying our initial refinement analysis, we can, on the fly, generate new scripts as new attacks, i.e. 0-day, show up. As few as 50 samples of attacks, i.e. less than one per platform we have currently deployed in the world, is enough to produce a script that can then automatically enrich all these platforms.
机译:Spitzner建议将蜜罐分为低互动,中互动和高互动。存在一些低交互作用的实例(例如,honeyd)以及一些高交互作用(例如GenII)。媒体交互系统最近受到越来越多的关注。例如,ScriptGen和Role-Player与高交互系统一样健谈,同时限制了相关风险。在本文中,我们确实基于在ScriptGen上提出的工作来自动创建能够与攻击工具进行交互的Honeyd脚本,而无需依赖于所涉及协议的任何先验知识。本文的主要贡献是三方面的。首先,我们提出一种解决方案,用于检测和处理所谓的协议内依赖性。其次,我们对协议间的依赖关系也做同样的事情。最后但并非最不重要的一点是,我们展示了如何通过修改我们的初始优化分析,动态地生成新脚本,作为新攻击的出现,即0天。至少有50个攻击样本,即我们目前在全球部署的每个平台少于一个,足以生成一个脚本,然后可以自动丰富所有这些平台。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号