Collection and analysis of attack data based on honeypots deployed on the Internet

Alata, Eric; Dacier, Marc; Deswarte, Yves; Kaaniche, Mohamed; Kortchinsky, Kostya; Nicomette, Vincente; Pham, Van Hau; Pouget, Fabien
QOP 2005, 1st Workshop on Quality of Protection (collocated with ESORICS and METRICS), September 15, 2005, Milano, Italy / Also published in "Quality Of Protection, Security Measurements and Metrics", Springer Series: Advances in Information Security, Volume 23, Gollmann, Dieter; Massacci, Fabio; Yautsiukhin, Artsiom (Eds.), 2006, XII, 197 p, ISBN: 0-387-29016-8

The CADHo project (Collection and Analysis of Data from Honeypots) is an ongoing research action funded by the French ACI "Securiteé & Informatique" [1]. It aims at building an environment to better understand threats on the Internet and also at providing models to analyze the observed phenomena. Our approach consists in deploying and sharing with the scientific community a distributed platform based on honeypots that gathers data suitable to analyze the attack processes targeting machines connected to the Internet. This distributed platform, called Leurreé.com and administrated by Institut Eurecom, offers each partner collaborating to this initiative access to all collected data in order to carry out statistical analyzes and modeling activities. So far, about thirty honeypots have been operational for several months in twenty countries of the five continents. This paper presents a brief overview of this distributed platform and examples of results derived from the data. It also outlines the approach investigated to model observed attack processes and to describe the intruders behaviors once they manage to get access to a target machine.


DOI
HAL
Type:
Conference
City:
Milano
Date:
2005-09-15
Department:
Digital Security
Eurecom Ref:
1869
Copyright:
© Springer. Personal use of this material is permitted. The definitive version of this paper was published in QOP 2005, 1st Workshop on Quality of Protection (collocated with ESORICS and METRICS), September 15, 2005, Milano, Italy / Also published in "Quality Of Protection, Security Measurements and Metrics", Springer Series: Advances in Information Security, Volume 23, Gollmann, Dieter; Massacci, Fabio; Yautsiukhin, Artsiom (Eds.), 2006, XII, 197 p, ISBN: 0-387-29016-8 and is available at : http://dx.doi.org/10.1007/978-0-387-36584-8_7

PERMALINK : https://www.eurecom.fr/publication/1869