Implementation on Honeyd: A system for analysis of network attacks
Dipali S hingade
Abstract
Dipali S hingade
Abstract
Various attacks today are used by attackers to compromise the network security these days. These exploits of attacks are capable of exploiting into any secure networks. So to secure the server in network we are here combining features, functions and methodologies of IDS (Intrusion Detection System), IPS (Intrusion Prevention System) and Honeypot to make Intrusion Detection System more accurate, effective and responsive against these attacks. Honeypots are mirrored servers or host which appear as actual servers for attackers and maintain the logs of intrusions and intrusive activities. IDS detects the attack, and IPS takes actions against these attacks as configured. Intrusion detection system monitors all the data packets coming inward the network and looks for possible attempts of intrusion, when an intrusion event occurs an alarm will automatically be raised. The resulting analysis of captured packets is done and corrective measures are taken by Intrusion Prevention System if there is a necessity. This alarm will activate the Intrusion Prevention System which will take preventive measures depending on the type of attack and exploit used. Featured capturing, logging and analysis into our proposed system will enable security expert to investigate such events even more sophisticatedly.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Various attacks today are used by attackers to compromise the network security these days. These exploits of attacks are capable of exploiting into any secure networks. So to secure the server in network we are here combining features, functions and methodologies of IDS (Intrusion Detection System), IPS (Intrusion Prevention System) and Honeypot to make Intrusion Detection System more accurate, effective and responsive against these attacks. Honeypots are mirrored servers or host which appear as actual servers for attackers and maintain the logs of intrusions and intrusive activities. IDS detects the attack, and IPS takes actions against these attacks as configured. Intrusion detection system monitors all the data packets coming inward the network and looks for possible attempts of intrusion, when an intrusion event occurs an alarm will automatically be raised. The resulting analysis of captured packets is done and corrective measures are taken by Intrusion Prevention System if there is a necessity. This alarm will activate the Intrusion Prevention System which will take preventive measures depending on the type of attack and exploit used. Featured capturing, logging and analysis into our proposed system will enable security expert to investigate such events even more sophisticatedly.
Key concepts: Honeypot, Exploit, Intrusion detection system, Computer security, Host-based intrusion detection system, Computer science, Network packet, Network security