...
首页> 外文期刊>International Journal of Intelligent Information Systems >Improving honeyd for automatic generation of attack signatures
【24h】

Improving honeyd for automatic generation of attack signatures

机译:改进honeyd以自动生成攻击特征

获取原文
           

摘要

In this paper, we design and implement a new Plugin to Honeyd which generates attack signature, automatically. Current network intrusion detection systems work on misuse detectors, where the packets in the monitored network are compared against a repository of signatures. But, we focus on automatic signature generation from malicious network traffic. Our proposed system inspects honeypot traffic and generates intrusion signatures for unknown traffic.The signature is based on traffic patterns, using Longest Common Substring (LCS) algorithm. It is noteworthy that our system is a plugin to honeyd - a low interaction honeypot. The system's output is a file containing honeypot intrusion signatures in pseudo-snort format. Signature generation system has been implemented for Linux Operating System (OS) but due to the common use of Windows OS, we implement for Windows OS, using C programming language.
机译:在本文中,我们设计并实现了一个新的Honeyd插件,该插件会自动生成攻击签名。当前的网络入侵检测系统在误用检测器上工作,将受监视网络中的数据包与签名库进行比较。但是,我们专注于通过恶意网络流量自动生成签名。我们提出的系统会检查蜜罐流量并为未知流量生成入侵签名,该签名基于流量模式,使用最长公共子串(LCS)算法。值得注意的是,我们的系统是honeyd的插件-低交互蜜罐。系统的输出是一个文件,其中包含伪鼻格式的蜜罐入侵签名。签名生成系统已经为Linux操作系统(OS)实现,但是由于Windows OS的普遍使用,我们使用C编程语言为Windows OS实现了签名生成系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号