Sciweavers

DSN
2006
IEEE

Honeypot-Aware Advanced Botnet Construction and Maintenance

14 years 5 months ago
Honeypot-Aware Advanced Botnet Construction and Maintenance
Because “botnets” can be used for illicit financial gain, they have become quite popular in recent Internet attacks. “Honeypots” have been successfully deployed in many defense systems. Thus, attackers constructing and maintaining botnets will be forced to find ways to avoid honeypot traps. In this paper, we present a hardware and software independent honeypot detection methodology based on the following assumption: security professionals deploying honeypots have liability constraints such that they cannot allow their honeypots to participate in real (or too many real) attacks. Based on this assumption, attackers can detect honeypots in their botnet by checking whether the compromised machines in the botnet can successfully send out unmodified malicious traffic to attackers’ sensors or whether the bot controller in their botnet can successfully relay potential attack commands. In addition, we present a novel “two-stage reconnaissance” worm that can automatically cons...
Cliff Changchun Zou, Ryan Cunningham
Added 11 Jun 2010
Updated 11 Jun 2010
Type Conference
Year 2006
Where DSN
Authors Cliff Changchun Zou, Ryan Cunningham
Comments (0)