Design and Implementation of High Interaction Client Honeypot for Drive-by-Download Attacks
スポンサーリンク
概要
- 論文の詳細を見る
Nowadays, the number of web-browser targeted attacks that lead users to adversaries web sites and exploit web browser vulnerabilities is increasing, and a clarification of their methods and countermeasures is urgently needed. In this paper, we introduce the design and implementation of a new client honeypot for drive-by-download attacks that has the capacity to detect and investigate a variety of malicious web sites. On the basis of the problems of existing client honeypots, we enumerate the requirements of a client honeypot: 1) detection accuracy and variety, 2) collection variety, 3) performance efficiency, and 4) safety and stability. We improve our system with regard to these requirements. The key features of our developed system are stepwise detection focusing on exploit phases, multiple crawler processing, tracking of malware distribution networks, and malware infection prevention. Our evaluation of our developed system in a laboratory experiment and field experiment indicated that its detection variety and crawling performance are higher than those of existing client honeypots. In addition, our system is able to collect information for countermeasures and is secure and stable for continuous operation. We conclude that our system can investigate malicious web sites comprehensively and support countermeasures.
- 2010-05-01
著者
-
ITOH Mitsutaka
NTT Information Sharing Platform Laboratories, NTT Corporation
-
Itoh Mitsutaka
Ntt Information Sharing Platform Laboratories Ntt Corporation
-
Iwamura Makoto
Ntt Information Sharing Platform Laboratories Ntt Corporation
-
AKIYAMA Mitsuaki
NTT Information Sharing Platform Laboratories, NTT Corporation
-
KAWAKOYA Yuhei
NTT Information Sharing Platform Laboratories, NTT Corporation
-
AOKI Kazufumi
NTT Information Sharing Platform Laboratories, NTT Corporation
-
Aoki Kazufumi
Ntt Information Sharing Platform Laboratories Ntt Corporation
-
Kawakoya Yuhei
Ntt Information Sharing Platform Laboratories Ntt Corporation
-
Akiyama Mitsuaki
Ntt Information Sharing Platform Laboratories Ntt Corporation
関連論文
- Design of Provider-Provisioned Website Protection Scheme against Malware Distribution
- Investigation and Evaluation of Attack Monitoring Methods Using Web Honeypots
- Design and Implementation of High Interaction Client Honeypot for Drive-by-Download Attacks
- Intelligent High-Interaction Web Honeypots Based on URL Conversion Scheme