A Taxonomy for Dynamic Honeypot Measures of Effectiveness

05/26/2020
by   Jason M. Pittman, et al.
0

Honeypots are computing systems used to capture unauthorized, often malicious, activity. While honeypots can take on a variety of forms, researchers agree the technology is useful for studying adversary behavior, tools, and techniques. Unfortunately, researchers also agree honeypots are difficult to implement and maintain. A lack of measures of effectiveness compounds the implementation issues specifically. In other words, existing research does not provide a set of measures to determine if a honeypot is effective in its implementation. This is problematic because an ineffective implementation may lead to poor performance, inadequate emulation of legitimate services, or even premature discovery by an adversary. Accordingly, we have developed a taxonomy for measures of effectiveness in dynamic honeypot implementations. Our aim is for these measures to be used to quantify a dynamic honeypot's effectiveness in fingerprinting its environment, capturing valid data from adversaries, deceiving adversaries, and intelligently monitoring itself and its surroundings.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/01/2020

Primer – A Tool for Testing Honeypot Measures of Effectiveness

Honeypots are a deceptive technology used to capture malicious activity....
research
11/11/2022

Investigating co-occurrences of MITRE ATT&CK Techniques

Cyberattacks use adversarial techniques to bypass system defenses, persi...
research
05/11/2021

Survey and Taxonomy of Adversarial Reconnaissance Techniques

Adversaries are often able to penetrate networks and compromise systems ...
research
03/20/2023

A Comparative Analysis of Port Scanning Tool Efficacy

Port scanning refers to the systematic exploration of networked computin...
research
08/28/2018

Adversaries monitoring Tor traffic crossing their jurisdictional border and reconstructing Tor circuits

We model and analyze passive adversaries that monitors Tor traffic cross...
research
08/30/2018

Asheetoxy: A Taxonomy for Classifying Negative Spreadsheet-related Phenomena

Spreadsheets (sometimes also called Excel programs) are powerful tools w...
research
04/23/2021

Predicting Adversary Lateral Movement Patterns with Deep Learning

This paper develops a predictive model for which host, in an enterprise ...

Please sign up or login with your details

Forgot password? Click here to reset