Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ ZENODOarrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Article . 2012
License: CC BY
Data sources: Datacite
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Article . 2012
License: CC BY
Data sources: Datacite
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Article . 2012
License: CC BY
Data sources: ZENODO
versions View all 2 versions
addClaim

Behavioral Signature Generation Using Shadow Honeypot

Authors: Maros Barabas; Michal Drozd; Petr Hanacek;

Behavioral Signature Generation Using Shadow Honeypot

Abstract

{"references": ["Garcia-Teodoro, P., D\u251c\u00a1az-Verdejo, J. E., Maci\u251c\u00edFern\u251c\u00edndez, G., V\u251c\u00edzquez,\nE., Anomaly-based network intrusion detection: Techniques, systems\nand challenges\", p. 18-28, 2009.", "C. Cowan, P. Wagle, C. Pu, S. Beattie, J. Walpole, BufferOverflows:\nAttacks and Defenses for the Vulnerability of the Decade, Oasis, p.227,\nFoundations of Intrusion Tolerant Systems (OASIS'03)2003.", "Ke Wang, Salvatore J. Stolfo, Anomalous Payload-Based Network\nIntrusion Detection\", 2004.", "L. Ertoz, E. Eilertson, A. Lazarevic, P.-Ning Tan, P. Dokas, V. Kumar,\nJ. Srivastava, Detection and Summarization of Novel Network Attacks\nUsing Data Mining\", 2004.", "\"NetFlow\", Cisco Systems, Inc, 2011, URL: www.cisco.com/\ngo/netflow.", "W. Lee and S. Stolfo, \"A Framework for Constructing Features and\nModels for Intrusion Detection Systems\", ACM Transactions on\nInformation and System Security, 3(4), November 2000.", "M. Mahoney, P. K. Chan, \"An Analysis of the 1999 DARPA/Lincoln\nLaboratory Evaluation Data for Network Anomaly Detection\", RAID\n2003, 220-237.", "P. Porras and P. Neumann, \"EMERALD: Event Monitoring Enabled\nResponses to Anomalous Live Disturbances\", National Information\nSystems Security Conference, 1997.", "G. Vigna and R. Kemmerer, \"NetSTAT: A Network-based intrusion\ndetection approach\", Computer Security Application Conference, 1998.\n[10] M. Mahoney, P. K. Chan, \"Learning Nonstationary Models of Normal\nNetwork Traffic for Detecting Novel Attacks\", Proc. SIGKDD 2002,\n376-385.\n[11] G. Portokalidis, A. Slowinska, H. Bos, \"Argos: an Emulator for\nFingerprinting Zero-Day Attacks\", in Proc. ACM\nSIGOPSEUROSYS'2006, 2006.\n[12] J. Berg, E. Teran, S. Stover, \"Investigating Argos\", an Article in\nUSENIX Magazine: ;login, 2008.\n[13] KDD Cup 1999, October 2007, URL: http://kdd.ics.uci.edu/\ndatabases/kddcup99/kddcup99.html.\n[14] Stack-based buffer overflow in CesarFTP 0.99g, , URL:\nhttp://cve.mitre.org/cgi-bin/cvename.cgi?name=2006-2961.\n[15] Server Service Vulnerability, URL: http://cve.mitre.org/cgi-bin/\ncvename.cgi?name=2008-4250."]}

A novel behavioral detection framework is proposed to detect zero day buffer overflow vulnerabilities (based on network behavioral signatures) using zero-day exploits, instead of the signature-based or anomaly-based detection solutions currently available for IDPS techniques. At first we present the detection model that uses shadow honeypot. Our system is used for the online processing of network attacks and generating a behavior detection profile. The detection profile represents the dataset of 112 types of metrics describing the exact behavior of malware in the network. In this paper we present the examples of generating behavioral signatures for two attacks – a buffer overflow exploit on FTP server and well known Conficker worm. We demonstrated the visualization of important aspects by showing the differences between valid behavior and the attacks. Based on these metrics we can detect attacks with a very high probability of success, the process of detection is however very expensive.

Keywords

metrics, behavioral signatures, security design, network

  • BIP!
    Impact byBIP!
    selected citations
    These citations are derived from selected sources.
    This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    0
    popularity
    This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
    Average
    influence
    This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    Average
    impulse
    This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
    Average
    OpenAIRE UsageCounts
    Usage byUsageCounts
    visibility views 2
    download downloads 2
  • 2
    views
    2
    downloads
    Powered byOpenAIRE UsageCounts
Powered by OpenAIRE graph
Found an issue? Give us feedback
visibility
download
selected citations
These citations are derived from selected sources.
This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Citations provided by BIP!
popularity
This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
BIP!Popularity provided by BIP!
influence
This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Influence provided by BIP!
impulse
This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
BIP!Impulse provided by BIP!
views
OpenAIRE UsageCountsViews provided by UsageCounts
downloads
OpenAIRE UsageCountsDownloads provided by UsageCounts
0
Average
Average
Average
2
2
Green