Open Access Open Access  Restricted Access Subscription or Fee Access

Collaborative Study on Recent Advances and Future Trends in Honeypot, Denial-of-Service Attack (DoS) and Distributed Denial-of-Service Attack (DDoS)

Shilpi Singh, Dr. Sweta Verma, Dr. A.K. Khare

Abstract


This paper presents a collaborative study on recent advances in honeypot research and related topics.  In reviewing the literature, we have covered the following areas: types of honeypots, utilizing honeypot output data, arranging honeypots, counteracting honeypot detections by attackers. Our literature reviews also indicate that the Distributed denial-of-service attack (DDoS) as one of the most common internet attacks. An attempt is made to prevent legitimate network traffic from reaching the target and consequently to disable all services that this resource provides to the victim. DDoS attacks can be labeled in two levels: first one is application-level and another is network-level. Disadvantage in network-based application is that the communication port is commonly open.This allows attackers to possibly launch Denial of Service (DoS) Attacks. It can be solved by using the port hopping technique, which can support many clients without the need of group synchronization in the presence of clock drift. The adaptive algorithm approach enables the synchronization in the presence of clock drift. Thus the honeypot provide the basic approach for network threats. The collaborative studies relate the advance study for the network attack detection and threats and provide multiple solution technique to analyze the same.


Keywords


Honeypot, DDoS, DoS, Computer Security, Network Attack, Clock Drift.

Full Text:

PDF

References


‘Brian Scottberg, William Yurcik, and David Doss “Internet Honeypots: Protection or Entrapment?,” Proceedings of International Symposium on Technology and Society, August 2002, pp. 387-391’.

‘Lance Spitzner, “Honeypots: Catching the Insider Threat,” Proceedings of the Computer Security Applications Conference, December 2003,pp. 170-179’.

‘Christian Kreibichi and Jon Crowcroft,”Honeycomb – Creating Intrusion Detection Signatures Using Honeypots,” ACM SIGCOMM Computer Communication Review, vol. 34, no. 1, January 2004, pp. 51-56’.

‘Sherif M. Khattab, Chatree Sangpachatanaruk, Daniel Moss, Rami Melhem, and Taieb Znati, “Roaming Honeypots for Mitigating Service-Level Denial-of-Service Attacks,“ Proceedings of the International Conference on Distributed Computing Systems, March 2004, pp. 328–337’.

‘K. G. Anagnostakis, S. Sidiroglou, P. Akritidis, K.Xinidis, E. Markatos, and A. D. Keromytis”Detecting Targeted Attacks Using Shadow Honeypots,”Proceedings of the Conference on USENIX Security Symposium, August 2005, pp. 9-23’.

‘ Evan Cooke, Farnam Jahanian, and Danny McPherson, “The Zombie Roundup: Understanding, Detecting, and Disrupting Botnets,”Proceedings of the USENIX Steps to Reducing Unwanted Traffic on the Internet on Steps to Reducing Unwanted Traffic on the Internet Workshop, July 2005, pp. 39-44’.

‘Yong Tang and Shigang Chen, “Defending against Internet Worms: a Signature-based Approach,”Proceedings of IEEE INFOCOM, vol. 2, March 2005, pp. 1384-1394’.

‘Georgios Portokalidis, Asia Slowinska, and Herbert Bos, “Argos: an Emulator for Fingerprinting Zero-Day Attacks,”ACM SIGOPS Operating Systems Review, vol. 40, no. 4, October 2006, pp. 15-27’.

‘Roberto Perdisci, David Dagon, Wenke Lee,Prahlad Fogla, and Monirul Sharif, “Misleading Worm Signature Generators Using Deliberate Noise Injection,” Proceedings of IEEE Symposium on Security and Privacy, May 2006, pp. 15-31’.

‘Cliff C. Zou and Ryan Cunningham, “Honeypot Aware Advanced Botnet Construction and Maintenance,”Proceedings of the International Conference on Dependable Systems and Networks,June 2006, pp. 199-208’.

‘Neil C. Rowe, E. John Custy, Binh T. Duong,”Defending Cyberspace with Fake Honeypots,” Journal of Computers, vol. 2, no. 2, April 2007, pp.25-36’.

‘Ram Dantu, Joao W. Cangussu, and Sudeep Patwardhan, “Fast Worm Containment Using Feedback Control,” IEEE Transactions on Dependable and Secure Computing, vol. 4, no. 2, April-June 2007, pp. 119-136’.

‘Mohssen M. Z. E. Mohammed, H. Anthony Chan, Neco Ventura, Mohsim Hashim, Izzeldin Amin, and Eihab Bashier, “Detection of Zero-Day Polymorphic Worms Using Principal Component Analysis,”Proceedings of International Conference on Networking and Services, March 2007, pp. 277-281’.

‘Cristine Hoepers, Nandamudi L. Vijaykumar,and Antonio Montes, “HIDEF: a data Exchange Format for Information Collected in Honeypots and Honeynets,” INFOCOMP Journal of Computer Science, vol. 7, no. 1, March 2008, pp. 87-96’.

‘Oliver Thonnard and Marc Dadier, “A Framework for Attack Pattern’s Discovery in Honeynet Data,”Digital Investigation, vol. 5, no. 1, September 2008, pp. 128-139’.

‘Gérard Wagener, Alexandre Dulaunoy, and Thomas Engel, “Towards an Estimation of the Accuracy of TCP Reassembly in Network Forensics,”Proceedings of the International Conference on Future Generation Communication and Networking,vol. 2, December 2008, pp. 273-278’.

‘Narisa Zhao and Xianfeng Zhang, “The Worm Propagation Model and Control Strategy Based on Distributed Honeynet,”Proceedings of the International Conference on Computer Science and Software Engineering, vol. 3, December 2008, pp.868-87’.

‘Yu Adachi and Yoshihiro Oyama, “Malware Analysis System using Process-Level Virtualization,” Proceedings of IEEE Symposium on Computers and Communications, July 2009, pp. 550-556’.

‘Vinu V. Das, “Honeypot Scheme for Distributed Denial-of-Service,” Proceedings of the 2009 International Conference on Advanced Computer Control, January 2009, pp. 497-501’.

‘Abdallah Ghourabi, Tarek Abbes, and Adel Bouhoula, “Honeypot Router for Routing Protocols Protection,” Proceedings of the International Conference on Risks and Security of Internet and Systems, October 2009, pp. 127-130’.

‘Jose Nazario, “PhoneyC: A Virtual Client Honeypot,”Proceedings of USENIX Workshop on Large-Scale and Emergent Threats, April 2009, pp. 18’.

‘Anoosha Prathapani, Lakshmi Santhanam, and Dharma P Agrawal, “Intelligent Honeypot Agent for Blackhole Attack Detection in Wireless Mesh Networks,”Proceedings of IEEE International Conference on Mobile Adhoc and Sensor Systems,October 2009, pp. 753-758’.

‘Lin Chen, Zhitang Li, Cuixia Gao, and Lan Liu,”Dynamic Forensics based on Intrusion Tolerance,” Proceedings of IEEE International Symposium on Parallel and Distributed Processing with Applications, August 2009, pp. 469-473’.

‘Kevin D. Fairbanks, Ying H. Xia, and Henry L.Owen III, “A Method for Historical Ext3 Inode to Filename Translation on Honeypots,”Proceedings of the IEEE International Computer Software and Applications Conference, July 2009, pp. 392-397’.

‘Jérémy Briffaut, Jean-François Lalande, and Christian Toinard, “Security and Results of a Large Scale High-Interaction Honeypot,” Journal of Computers Special Issue on Security and High Performance Computer Systems, vol. 4, no. 5, May 2009, pp. 395-404’.

‘Yaser Alosefer and Omer Rana, “Honeyware - Webbased Low Interaction Client Honeypot,” Proceedings of the International Conference on Software Testing, Verification, and Validation Workshops, April 2010,pp. 410-417’.

‘Tobias Lauinger, Veikko Pankakoski, Davide Balzarotti, and Engin Kirda, “Honeybot, Your Man in the Middle for Automated Social Engineering,”Proceedings of USENIX Symposium on Networked Systems Design and Implementation, April 2010.Available: http://portal.acm.org/citation.cfm?id=1855697’.

‘Julia Narvaez, Chiraag Aval, Barbara EndicottPopovsky,Christian Seifert, Ashish Malviya, and Doug Nordwall, “Assessment of Virtualization as a Sensor Technique,” Proceedings of the IEEE International Workshop on Systematic Approaches to Digital Forensic Engineering, May 2010, pp. 61-65’.

‘Ming-Yang Su, “Internet Worms Identification through Serial Episodes Mining,”Proceedings of the International Conference on Electrical Engineering /Electronics Computer Telecommunications and Information, May 2010, pp. 132-136’.

‘Thomas M. Chen and John Buford, “Design Considerations for a Honeypot for SQL Injection Attacks,” Proceedings of IEEE Local Computer Networks, October 2009, pp. 915-921’.

‘Haifeng Wang and Qingkui Chen, “Design of Cooperative Deployment in Distributed Honeynet System,” Proceedings of the International Conference on Computer Supported Cooperative Work in Design,April 2010, pp. 711–716’.

‘Ping Wang, Sherri Sparks, and Cliff C. Zou, “An Advanced Hybrid Peer-to-Peer Botnet,” IEEE Transaction on Dependable and Secure Computing,vol. 7, no. 2, April-June 2010, pp. 113-127’.

’Yang Xiang, Member, IEEE, Ke Li, and Wanlei Zhou, Senior Member, IEEE,” Low-Rate DDoS Attacks Detection and Traceback by Using New Information Metrics,”IEEE Transactions On Information Forensics And Security, VOL. 6, NO. 2, June 2011, pp.426-437’.

‘Zhang Fu, Marina Papatriantafilou, and Philippas Tsigas,” Mitigating Distributed Denial of Service Attacks in Multiparty Applications in the Presence of Clock Drifts”IEEE Transactions on dependable and secure Computing,Vol. 9,No. 3,May/June 2012,pp. 401-413’.

‘C.Kavitha, S.Mohana, Mrs.A.Karmel,” Survey on Mitigation of DOS and DDOS Attacks in the Presence of Clock drift”, Volume 1, Issue 1, March, 2013,ISSN: 232-0-8791’.


Refbacks

  • There are currently no refbacks.


Creative Commons License
This work is licensed under a Creative Commons Attribution 3.0 License.