2017•Journal of Physics Conference SeriesOpen access

Enhancing Honeypot Deception Capability Through Network Service Fingerprinting

R N Dahbul, Charles Ci-Wen Lim, James Purnama

Open full text 35 citations

Abstract

Honeypot is designed to lure attackers away from the computer resources the attackers are trying to compromise. In addition, honeypot also tracks attacker's activities and helps researchers learn about their attack patterns. However, honeypot can also be identified by attackers using various fingerprinting methods. In this research, we use threat modeling to identify potential threats that reveal its existence which made honeypot ineffective. Various countermeasures are discussed and the proposed countermeasures have proved effective to enhance the deception capability of the honeypots we tested.

Open-access reader

About this research paper

What this paper is about

Honeypot is designed to lure attackers away from the computer resources the attackers are trying to compromise. In addition, honeypot also tracks attacker's activities and helps researchers learn about their attack patterns. However, honeypot can also be identified by attackers using various fingerprinting methods. In this research, we use threat modeling to identify potential threats that reveal its existence which made honeypot ineffective. Various countermeasures are discussed and the proposed countermeasures have proved effective to enhance the deception capability of the honeypots we tested.

Why it matters

OpenAlex reports 35 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Honeypot is designed to lure attackers away from the computer resources the attackers are trying to compromise. In addition, honeypot also tracks attacker's activities and helps researchers learn about their attack patterns. However, honeypot can also be identified by attackers using various fingerprinting methods. In this research, we use threat modeling to identify potential threats that reveal its existence which made honeypot ineffective. Various countermeasures are discussed and the proposed countermeasures have proved effective to enhance the deception capability of the honeypots we tested.

Key concepts: Honeypot, Deception, Computer security, Computer science, Compromise, Network security, Internet privacy, Psychology

Related papers

Back to paper searchBrowse research topicsOriginal source
Enhancing Honeypot Deception Capability Through Network Service Fingerprinting — Research Paper | ScholarLens