A hybrid honeypot framework for improving intrusion detection systems in protecting organizational networks

被引:59
|
作者
Artail, Hassan
Safa, Haidar
Sraj, Malek
Kuwatly, Iyad
Al-Masri, Zaid
机构
[1] Amer Univ Beirut, Dept Elect & Comp Engn, Beirut 1107 2020, Lebanon
[2] Amer Univ Beirut, Dept Comp Sci, Beirut 1107 2020, Lebanon
关键词
intrusion detection; network security; computer security; organizational networks; honeypots; snort;
D O I
10.1016/j.cose.2006.02.009
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper proposes a hybrid and adaptable honeypot-based approach that improves the currently deployed IDSs for protecting networks from intruders. The main idea is to deploy low-interaction honeypots that act as emulators of services and operating systems and have them direct malicious traffic to high-interaction honeypots, where hackers engage with real services. The setup permits for recording and analyzing the intruder's activities and using the results to take administrative actions toward protecting the network. The paper describes the basic components, design, operation, implementation and deployment of the proposed approach, and presents several performance and load testing scenarios. Implementation and performance plus load testing show the adaptability of the proposed approach and its effectiveness in reducing the probability of attacks on production computers. (C) 2006 Elsevier Ltd. All rights reserved.
引用
收藏
页码:274 / 288
页数:15
相关论文
共 50 条
  • [21] Alarm clustering for intrusion detection systems in computer networks
    Giacinto, G
    Perdisci, R
    Roli, F
    MACHINE LEARNING AND DATA MINING IN PATTERN RECOGNITION, PROCEEDINGS, 2005, 3587 : 184 - 193
  • [22] A flow-based intrusion detection framework for internet of things networks
    Santos, Leonel
    Goncalves, Ramiro
    Rabadao, Carlos
    Martins, Jose
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2023, 26 (01): : 37 - 57
  • [23] A flow-based intrusion detection framework for internet of things networks
    Leonel Santos
    Ramiro Gonçalves
    Carlos Rabadão
    José Martins
    Cluster Computing, 2023, 26 : 37 - 57
  • [24] A framework for intrusion detection systems by social network analysis methods in ad hoc networks
    Wang, Wei
    Man, Hong
    Liu, Yu
    SECURITY AND COMMUNICATION NETWORKS, 2009, 2 (06) : 669 - 685
  • [25] A novel intrusion detection framework for wireless sensor networks
    Ashfaq Hussain Farooqi
    Farrukh Aslam Khan
    Jin Wang
    Sungyoung Lee
    Personal and Ubiquitous Computing, 2013, 17 : 907 - 919
  • [26] A lightweight intrusion detection framework for wireless sensor networks
    Hai, Tran Hoang
    Huh, Eui-Nam
    Jo, Minho
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2010, 10 (04) : 559 - 572
  • [27] Improving the IDS Performance through Early Detection Approach in Local Area Networks Using Industrial Control Systems of Honeypot
    Pashaei, Abbasgholi
    Akbari, Mohammad Esmail
    Lighvan, Mina Zolfy
    Teymorzade, Hamzeh Ali
    2020 20TH IEEE INTERNATIONAL CONFERENCE ON ENVIRONMENT AND ELECTRICAL ENGINEERING AND 2020 4TH IEEE INDUSTRIAL AND COMMERCIAL POWER SYSTEMS EUROPE (EEEIC/I&CPS EUROPE), 2020,
  • [28] A novel intrusion detection framework for wireless sensor networks
    Farooqi, Ashfaq Hussain
    Khan, Farrukh Aslam
    Wang, Jin
    Lee, Sungyoung
    PERSONAL AND UBIQUITOUS COMPUTING, 2013, 17 (05) : 907 - 919
  • [29] Hybrid intrusion detection system for wireless sensor networks
    Hai, Tran Hoang
    Khan, Faraz
    Huh, Eui-Nam
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2007, PT 2, PROCEEDINGS, 2007, 4706 : 383 - 396
  • [30] Hybrid Architecture for Intrusion Prevention and Detection in IoT Networks
    da Mata, Rafael Z. A.
    de Caldas Filho, Francisco L.
    Mendonca, Fabio L. L.
    Fares, Awatef A. Y. R.
    de Sousa Jr, Rafael T.
    2021 WORKSHOP ON COMMUNICATION NETWORKS AND POWER SYSTEMS (WCNPS), 2021,