HoneyCloud: elastic honeypots - On-attack provisioning of high-interaction honeypots - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2012

HoneyCloud: elastic honeypots - On-attack provisioning of high-interaction honeypots

Résumé

This paper presents HoneyCloud: a large-scale high-interaction honeypots architecture based on a cloud infrastructure. The paper shows how to setup and deploy on-demand virtualized honeypot hosts on a private cloud. Each attacker is elastically assigned to a new virtual honeypot instance. HoneyCloud offers a high scalability. With a small number of public IP addresses, HoneyCloud can multiplex thousands of attackers. The attacker can perform malicious activities on the honeypot and launch new attacks from the compromised host. The HoneyCloud architecture is designed to collect operating system logs about attacks, from various IDS, tools and sensors. Each virtual honeypot instance includes network and especially system sensors that gather more useful information than traditional network oriented honeypots. The paper shows how are collected the activities of attackers into the cloud storage mechanism for further forensics. HoneyCloud also addresses efficient attacker's session storage, long term session management, isolation between attackers and fidelity of hosts.
Fichier non déposé

Dates et versions

hal-00721415 , version 1 (27-07-2012)

Identifiants

  • HAL Id : hal-00721415 , version 1

Citer

Patrice Clemente, Jean-François Lalande, Jonathan Rouzaud-Cornabas. HoneyCloud: elastic honeypots - On-attack provisioning of high-interaction honeypots. SECRYPT 2012, Jul 2012, Rome, Italy. pp.434-439. ⟨hal-00721415⟩
367 Consultations
0 Téléchargements

Partager

Gmail Facebook X LinkedIn More