CIVILICA We Respect the Science
(ناشر تخصصی کنفرانسهای کشور / شماره مجوز انتشارات از وزارت فرهنگ و ارشاد اسلامی: ۸۹۷۱)

Automatic Generation of Attack Signatures for implementing anew Plugin to Honeyd

عنوان مقاله: Automatic Generation of Attack Signatures for implementing anew Plugin to Honeyd
شناسه ملی مقاله: SASTECH07_095
منتشر شده در هفتمین سمپوزیوم بین المللی پیشرفتهای علوم و تکنولوژی در سال 1391
مشخصات نویسندگان مقاله:

Motahareh Dehghan - Department of Computer Engineering and Information TechnologyAmirkabir University of Technology (AUT), Tehran, Iran
Babak Sadeghiyan - Department of Computer Engineering and Information TechnologyAmirkabir University of Technology (AUT), Tehran, Iran

خلاصه مقاله:
In this paper, we design and implement an automated signature generation system. Currentnetwork intrusion detection systems work on misuse detectors, where the packets in themonitored network are compared against a repository of signatures. But, we focus onautomatic signature generation from malicious network traffic. Our proposed systeminspects honeypot traffic and generates intrusion signatures for unknown traffic.The signature is based on traffic patterns, using Longest Common Substring (LCS)algorithm. It is noteworthy that our system is a plugin to honeyd - a low interactionhoneypot. The system's output is a file containing honeypot intrusion signatures in pseudosnortformat.Signature generation system has been implemented for Linux Operating System (OS) butdue to the common use of Windows OS, we implement for Windows OS, using Cprogramming language.Keywords: honeypot, honeyd, Intrusion Detection System (IDS), Longest CommonSubstring (LCS) algorithm, signature

کلمات کلیدی:
honeypot, honeyd, Intrusion Detection System (IDS), Longest CommonSubstring (LCS) algorithm, signature

صفحه اختصاصی مقاله و دریافت فایل کامل: https://civilica.com/doc/205231/