Worm Detection Using Honeypots

This thesis describes a project that utilizes honeypots to detect worms. A detailed description of existing worm detection techniques using honeypots is given, as well as a study of existing worm propagation models. Simulations using some of these worm propagation models are also conducted. Althoug...

Full description

Bibliographic Details
Main Authors: Christoffersen, Dag, Mauland, Bengt Jonny
Format: Others
Language:English
Published: Norges teknisk-naturvitenskapelige universitet, Institutt for telematikk 2006
Subjects:
Online Access:http://urn.kb.se/resolve?urn=urn:nbn:no:ntnu:diva-9454
id ndltd-UPSALLA1-oai-DiVA.org-ntnu-9454
record_format oai_dc
spelling ndltd-UPSALLA1-oai-DiVA.org-ntnu-94542013-01-08T13:26:35ZWorm Detection Using HoneypotsengChristoffersen, DagMauland, Bengt JonnyNorges teknisk-naturvitenskapelige universitet, Institutt for telematikkNorges teknisk-naturvitenskapelige universitet, Institutt for telematikkInstitutt for telematikk2006ntnudaimSIE7 kommunikasjonsteknologiTelematikkThis thesis describes a project that utilizes honeypots to detect worms. A detailed description of existing worm detection techniques using honeypots is given, as well as a study of existing worm propagation models. Simulations using some of these worm propagation models are also conducted. Although the results of the simulations coincide with the collected data from the actual outbreak of a network worm, they also conclude that it is difficult to produce realistic results prior to a worm outbreak. A worm detection mechanism called HoneyComb is incorporated in the honeypot setup installed at NTNU, and experiments are conducted to evaluate its effectiveness and reliability. The mechanism generated a large amount of false positives in these experiments, possibly due to an error discovered in the implementation of the detection algorithm. An architecture using honeypots for detection of unknown worms is proposed. This architecture is based on a combination of two recently published systems with the extension referred to as a Known-Attack (KA) filter. By using this filter, it is believed that the amount of traffic needed to be processed by the honeypot sensors will be considerably reduced. Student thesisinfo:eu-repo/semantics/bachelorThesistexthttp://urn.kb.se/resolve?urn=urn:nbn:no:ntnu:diva-9454Local ntnudaim:1349application/pdfinfo:eu-repo/semantics/openAccess
collection NDLTD
language English
format Others
sources NDLTD
topic ntnudaim
SIE7 kommunikasjonsteknologi
Telematikk
spellingShingle ntnudaim
SIE7 kommunikasjonsteknologi
Telematikk
Christoffersen, Dag
Mauland, Bengt Jonny
Worm Detection Using Honeypots
description This thesis describes a project that utilizes honeypots to detect worms. A detailed description of existing worm detection techniques using honeypots is given, as well as a study of existing worm propagation models. Simulations using some of these worm propagation models are also conducted. Although the results of the simulations coincide with the collected data from the actual outbreak of a network worm, they also conclude that it is difficult to produce realistic results prior to a worm outbreak. A worm detection mechanism called HoneyComb is incorporated in the honeypot setup installed at NTNU, and experiments are conducted to evaluate its effectiveness and reliability. The mechanism generated a large amount of false positives in these experiments, possibly due to an error discovered in the implementation of the detection algorithm. An architecture using honeypots for detection of unknown worms is proposed. This architecture is based on a combination of two recently published systems with the extension referred to as a Known-Attack (KA) filter. By using this filter, it is believed that the amount of traffic needed to be processed by the honeypot sensors will be considerably reduced.
author Christoffersen, Dag
Mauland, Bengt Jonny
author_facet Christoffersen, Dag
Mauland, Bengt Jonny
author_sort Christoffersen, Dag
title Worm Detection Using Honeypots
title_short Worm Detection Using Honeypots
title_full Worm Detection Using Honeypots
title_fullStr Worm Detection Using Honeypots
title_full_unstemmed Worm Detection Using Honeypots
title_sort worm detection using honeypots
publisher Norges teknisk-naturvitenskapelige universitet, Institutt for telematikk
publishDate 2006
url http://urn.kb.se/resolve?urn=urn:nbn:no:ntnu:diva-9454
work_keys_str_mv AT christoffersendag wormdetectionusinghoneypots
AT maulandbengtjonny wormdetectionusinghoneypots
_version_ 1716520514975956992