A hybrid honeypot framework for improving intrusion detection systems in protecting organizational networks

被引:59
|
作者
Artail, Hassan
Safa, Haidar
Sraj, Malek
Kuwatly, Iyad
Al-Masri, Zaid
机构
[1] Amer Univ Beirut, Dept Elect & Comp Engn, Beirut 1107 2020, Lebanon
[2] Amer Univ Beirut, Dept Comp Sci, Beirut 1107 2020, Lebanon
关键词
intrusion detection; network security; computer security; organizational networks; honeypots; snort;
D O I
10.1016/j.cose.2006.02.009
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper proposes a hybrid and adaptable honeypot-based approach that improves the currently deployed IDSs for protecting networks from intruders. The main idea is to deploy low-interaction honeypots that act as emulators of services and operating systems and have them direct malicious traffic to high-interaction honeypots, where hackers engage with real services. The setup permits for recording and analyzing the intruder's activities and using the results to take administrative actions toward protecting the network. The paper describes the basic components, design, operation, implementation and deployment of the proposed approach, and presents several performance and load testing scenarios. Implementation and performance plus load testing show the adaptability of the proposed approach and its effectiveness in reducing the probability of attacks on production computers. (C) 2006 Elsevier Ltd. All rights reserved.
引用
收藏
页码:274 / 288
页数:15
相关论文
共 50 条
  • [31] Intrusion Detection based on "Hybrid" Propagation in Bayesian Networks
    Jemili, Farah
    Zaghdoud, Montaceur
    Ben Ahmed, Mohamed
    ISI: 2009 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS, 2009, : 137 - 142
  • [32] DroneGuard: An Explainable and Efficient Machine Learning Framework for Intrusion Detection in Drone Networks
    Ihekoronye, Vivian Ukamaka
    Ajakwe, Simeon Okechukwu
    Lee, Jae Min
    Kim, Dong-Seong
    IEEE INTERNET OF THINGS JOURNAL, 2025, 12 (07): : 7708 - 7722
  • [33] Improving energy efficiency in distributed intrusion detection systems
    Migliardi, Mauro
    Merlo, Alessio
    JOURNAL OF HIGH SPEED NETWORKS, 2013, 19 (03) : 251 - 264
  • [34] Improving the Detection Rate of Rarely Appearing Intrusions in Network-Based Intrusion Detection Systems
    Yang, Eunmok
    Joshi, Gyanendra Prasad
    Seo, Changho
    CMC-COMPUTERS MATERIALS & CONTINUA, 2021, 66 (02): : 1647 - 1663
  • [35] A Survey of Intrusion Detection Systems for Mobile Ad-Hoc Networks
    Alriyami, Qasim M.
    Asimakopoulou, Eleana
    Bessis, Nik
    2014 INTERNATIONAL CONFERENCE ON INTELLIGENT NETWORKING AND COLLABORATIVE SYSTEMS (INCOS), 2014, : 427 - 432
  • [36] A Linear Systems Perspective on Intrusion Detection for Routing in Reconfigurable Wireless Networks
    Zuniga-Mejia, Jaime
    Villalpando-Hernandez, Rafaela
    Vargas-Rosales, Cesar
    Spanias, Andreas
    IEEE ACCESS, 2019, 7 : 60486 - 60500
  • [37] Autonomous Federated Learning for Distributed Intrusion Detection Systems in Public Networks
    Mahmoodi, Alireza Bakhshi Zadi
    Sheikhi, Saeid
    Peltonen, Ella
    Kostakos, Panos
    IEEE ACCESS, 2023, 11 : 121325 - 121339
  • [38] An Explainable Machine Learning Framework for Intrusion Detection Systems
    Wang, Maonan
    Zheng, Kangfeng
    Yang, Yanqing
    Wang, Xiujuan
    IEEE ACCESS, 2020, 8 : 73127 - 73141
  • [39] Intrusion Detection Systems in MANETs using Hybrid Techniques
    Joshi, Vaishnavi Bheemarao
    Goudar, R. H.
    PROCEEDINGS OF THE 2017 INTERNATIONAL CONFERENCE ON SMART TECHNOLOGIES FOR SMART NATION (SMARTTECHCON), 2017, : 534 - 538
  • [40] An efficient intrusion detection and prevention framework for ad hoc networks
    Korba, Abdelaziz Amara
    Nafaa, Mehdi
    Ghanemi, Salim
    INFORMATION AND COMPUTER SECURITY, 2016, 24 (04) : 298 - 325