TY - GEN
T1 - HoneyMix
T2 - 2016 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, SDN-NFV Security 2016, Co-located with CODASPY 2016
AU - Han, Wonkyu
AU - Zhao, Ziming
AU - Doupe, Adam
AU - Ahn, Gail-Joon
N1 - Publisher Copyright:
© 2016 ACM.
PY - 2016/3/11
Y1 - 2016/3/11
N2 - Honeynet is a collection of honeypots that are set up to at- tract as many attackers as possible to learn about their pat- terns, tactics, and behaviors. However, existing honeypots suffer from a variety of fingerprinting techniques, and the current honeynet architecture does not fully utilize features of residing honeypots due to its coarse-grained data control mechanisms. To address these challenges, we propose an SDN-based intelligent honeynet called HoneyMix. HoneyMix leverages the rich programmability of SDN to cir- cumvent attackers' detection mechanisms and enables fine- grained data control for honeynet. To do this, HoneyMix simultaneously establishes multiple connections with a set of honeypots and selects the most desirable connection to inspire attackers to remain connected. In this paper, we present the HoneyMix architecture and a description of its core components.
AB - Honeynet is a collection of honeypots that are set up to at- tract as many attackers as possible to learn about their pat- terns, tactics, and behaviors. However, existing honeypots suffer from a variety of fingerprinting techniques, and the current honeynet architecture does not fully utilize features of residing honeypots due to its coarse-grained data control mechanisms. To address these challenges, we propose an SDN-based intelligent honeynet called HoneyMix. HoneyMix leverages the rich programmability of SDN to cir- cumvent attackers' detection mechanisms and enables fine- grained data control for honeynet. To do this, HoneyMix simultaneously establishes multiple connections with a set of honeypots and selects the most desirable connection to inspire attackers to remain connected. In this paper, we present the HoneyMix architecture and a description of its core components.
KW - Honeynet
KW - Honeypot
KW - Network function virtualiza-tion
KW - Software-defined networking
UR - https://www.scopus.com/pages/publications/84966461425
UR - https://www.scopus.com/pages/publications/84966461425#tab=citedBy
U2 - 10.1145/2876019.2876022
DO - 10.1145/2876019.2876022
M3 - Conference contribution
AN - SCOPUS:84966461425
T3 - SDN-NFV Security 2016 - Proceedings of the 2016 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, co-located with CODASPY 2016
SP - 1
EP - 6
BT - SDN-NFV Security 2016 - Proceedings of the 2016 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, co-located with CODASPY 2016
PB - Association for Computing Machinery
Y2 - 11 March 2016 through 11 March 2016
ER -