论文标题
底漆 - 测试蜜罐有效性测量的工具
Primer -- A Tool for Testing Honeypot Measures of Effectiveness
论文作者
论文摘要
蜜罐是一种用于捕获恶意活动的欺骗性技术。该技术对于研究攻击者的行为,工具和技术很有用,但可能难以实施和维护。从历史上看,缺乏有效性的措施使研究人员无法评估蜜罐的实施。后果是实施无效,导致绩效差,模仿合法服务有缺陷以及攻击者的过早发现。以前,我们开发了一种分类法,以衡量动态蜜罐实施中的有效性。这些措施量化了动态的蜜罐在指纹环境中的有效性,从对手那里捕获有效数据,欺骗对手,并明智地监视自身及其周围环境。作为开发自动化有效性测试的一步,这项工作引入了一种用于启动目标蜜罐进行评估的工具。我们概述了工具的设计,并以定量校准数据的形式提供结果。
Honeypots are a deceptive technology used to capture malicious activity. The technology is useful for studying attacker behavior, tools, and techniques but can be difficult to implement and maintain. Historically, a lack of measures of effectiveness prevented researchers from assessing honeypot implementations. The consequence being ineffective implementations leading to poor performance, flawed imitation of legitimate services, and premature discovery by attackers. Previously, we developed a taxonomy for measures of effectiveness in dynamic honeypot implementations. The measures quantify a dynamic honeypot's effectiveness in fingerprinting its environment, capturing valid data from adversaries, deceiving adversaries, and intelligently monitoring itself and its surroundings. As a step towards developing automated effectiveness testing, this work introduces a tool for priming a target honeypot for evaluation. We outline the design of the tool and provide results in the form of quantitative calibration data.