Defeating Internet Attacks Using Risk Awareness and Active Honeypots

  • Authors:
  • Lawrence Teo;Yu-An Sun;Gail-Joon Ahn

  • Affiliations:
  • -;-;-

  • Venue:
  • IWIA '04 Proceedings of the Second IEEE International Information Assurance Workshop (IWIA'04)
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

New forms of Internet attacks, such as SQL Slammer,have become increasingly sophisticated. Although codedin a simple way, the SQL Slammer worm propagated allover the world at an extremely high speed in a short periodof time, rendering it impossible for humans to counterit using manual intervention. In this paper, we proposea security framework called Japonica to detect and respondto unknown attacks at the early stage through the dynamicorchestration of prevention, detection, and responsemechanisms. We identify important requirements to supportthe proposed framework and corresponding system entities.Also, we describe our model using Colored Petri Netsto discover a uniform message exchange format among theentities. One unique characteristic of Japonica is an activeresponse coordinator and we demonstrate its feasibilityin a proof-of-concept prototype, utilizing a honeypot as anactive entity. Our results indicate that Japonica can successfullyprevent the spread of SQL Slammer without humanintervention. We are currently extending the framework tocounter other forms of sophisticated Internet attacks.