Set-up and deployment of a high-interaction honeypot: experiment and lessons learned - Université Toulouse III - Paul Sabatier - Toulouse INP Accéder directement au contenu
Article Dans Une Revue Journal in Computer Virology Année : 2011

Set-up and deployment of a high-interaction honeypot: experiment and lessons learned

Résumé

This paper presents the lessons learned from an empirical analysis of attackers behaviours based on the deployment on the Internet of a high-interaction honeypot for more than one year. We focus in particular on the attacks performed via the SSH service and the activities performed by the attackers once they gain access to the system and try to progress in their intrusion. The first part of the paper describes: i) the global architecture of the honeypot and the mechanisms used to capture the implementation details so that we can observe attackers behaviours and ii) the details of the experiment itself (duration, data captured, overview of the attackers activity). The second part presents the results of the observation of the attackers. It includes: i) the description of the global attack process, constituted of two main steps, dictionary attacks and intrusions and ii) the detailed analysis of these two main steps.
Fichier principal
Vignette du fichier
final_auteurs.pdf (613.59 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00762596 , version 1 (07-12-2012)

Identifiants

Citer

Vincent Nicomette, Mohamed Kaâniche, Eric Alata, Matthieu Herrb. Set-up and deployment of a high-interaction honeypot: experiment and lessons learned. Journal in Computer Virology, 2011, 7 (2), pp.143-157. ⟨10.1007/s11416-010-0144-2⟩. ⟨hal-00762596⟩
366 Consultations
3818 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More