Worm Detection Using Honeypots
This thesis describes a project that utilizes honeypots to detect worms. A detailed description of existing worm detection techniques using honeypots is given, as well as a study of existing worm propagation models. Simulations using some of these worm propagation models are also conducted. Althoug...
Main Authors: | , |
---|---|
Format: | Others |
Language: | English |
Published: |
Norges teknisk-naturvitenskapelige universitet, Institutt for telematikk
2006
|
Subjects: | |
Online Access: | http://urn.kb.se/resolve?urn=urn:nbn:no:ntnu:diva-9454 |
id |
ndltd-UPSALLA1-oai-DiVA.org-ntnu-9454 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-UPSALLA1-oai-DiVA.org-ntnu-94542013-01-08T13:26:35ZWorm Detection Using HoneypotsengChristoffersen, DagMauland, Bengt JonnyNorges teknisk-naturvitenskapelige universitet, Institutt for telematikkNorges teknisk-naturvitenskapelige universitet, Institutt for telematikkInstitutt for telematikk2006ntnudaimSIE7 kommunikasjonsteknologiTelematikkThis thesis describes a project that utilizes honeypots to detect worms. A detailed description of existing worm detection techniques using honeypots is given, as well as a study of existing worm propagation models. Simulations using some of these worm propagation models are also conducted. Although the results of the simulations coincide with the collected data from the actual outbreak of a network worm, they also conclude that it is difficult to produce realistic results prior to a worm outbreak. A worm detection mechanism called HoneyComb is incorporated in the honeypot setup installed at NTNU, and experiments are conducted to evaluate its effectiveness and reliability. The mechanism generated a large amount of false positives in these experiments, possibly due to an error discovered in the implementation of the detection algorithm. An architecture using honeypots for detection of unknown worms is proposed. This architecture is based on a combination of two recently published systems with the extension referred to as a Known-Attack (KA) filter. By using this filter, it is believed that the amount of traffic needed to be processed by the honeypot sensors will be considerably reduced. Student thesisinfo:eu-repo/semantics/bachelorThesistexthttp://urn.kb.se/resolve?urn=urn:nbn:no:ntnu:diva-9454Local ntnudaim:1349application/pdfinfo:eu-repo/semantics/openAccess |
collection |
NDLTD |
language |
English |
format |
Others
|
sources |
NDLTD |
topic |
ntnudaim SIE7 kommunikasjonsteknologi Telematikk |
spellingShingle |
ntnudaim SIE7 kommunikasjonsteknologi Telematikk Christoffersen, Dag Mauland, Bengt Jonny Worm Detection Using Honeypots |
description |
This thesis describes a project that utilizes honeypots to detect worms. A detailed description of existing worm detection techniques using honeypots is given, as well as a study of existing worm propagation models. Simulations using some of these worm propagation models are also conducted. Although the results of the simulations coincide with the collected data from the actual outbreak of a network worm, they also conclude that it is difficult to produce realistic results prior to a worm outbreak. A worm detection mechanism called HoneyComb is incorporated in the honeypot setup installed at NTNU, and experiments are conducted to evaluate its effectiveness and reliability. The mechanism generated a large amount of false positives in these experiments, possibly due to an error discovered in the implementation of the detection algorithm. An architecture using honeypots for detection of unknown worms is proposed. This architecture is based on a combination of two recently published systems with the extension referred to as a Known-Attack (KA) filter. By using this filter, it is believed that the amount of traffic needed to be processed by the honeypot sensors will be considerably reduced. |
author |
Christoffersen, Dag Mauland, Bengt Jonny |
author_facet |
Christoffersen, Dag Mauland, Bengt Jonny |
author_sort |
Christoffersen, Dag |
title |
Worm Detection Using Honeypots |
title_short |
Worm Detection Using Honeypots |
title_full |
Worm Detection Using Honeypots |
title_fullStr |
Worm Detection Using Honeypots |
title_full_unstemmed |
Worm Detection Using Honeypots |
title_sort |
worm detection using honeypots |
publisher |
Norges teknisk-naturvitenskapelige universitet, Institutt for telematikk |
publishDate |
2006 |
url |
http://urn.kb.se/resolve?urn=urn:nbn:no:ntnu:diva-9454 |
work_keys_str_mv |
AT christoffersendag wormdetectionusinghoneypots AT maulandbengtjonny wormdetectionusinghoneypots |
_version_ |
1716520514975956992 |