loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Second IEEE International Information Assurance Workshop (IWIA'04)
Defeating Internet Attacks Using Risk Awareness and Active Honeypots
Charlotte, North Carolina
April 08-April 09
ISBN: 0-7695-2117-7
Lawrence Teo, University of North Carolina at Charlotte; Calyptix Security Corporation, Charlotte, NC
Yu-An Sun, University of North Carolina at Charlotte
Gail-Joon Ahn, University of North Carolina at Charlotte
New forms of Internet attacks, such as SQL Slammer, have become increasingly sophisticated. Although coded in a simple way, the SQL Slammer worm propagated all over the world at an extremely high speed in a short period of time, rendering it impossible for humans to counter it using manual intervention. In this paper, we propose a security framework called Japonica to detect and respond to unknown attacks at the early stage through the dynamic orchestration of prevention, detection, and response mechanisms. We identify important requirements to support the proposed framework and corresponding system entities. Also, we describe our model using Colored Petri Nets to discover a uniform message exchange format among the entities. One unique characteristic of Japonica is an active response coordinator and we demonstrate its feasibility in a proof-of-concept prototype, utilizing a honeypot as an active entity. Our results indicate that Japonica can successfully prevent the spread of SQL Slammer without human intervention. We are currently extending the framework to counter other forms of sophisticated Internet attacks.
Index Terms:
Japonica, Honeypots, Risk Awareness, Colored Petri Nets
Citation:
Lawrence Teo, Yu-An Sun, Gail-Joon Ahn, "Defeating Internet Attacks Using Risk Awareness and Active Honeypots," iwia, pp.155, Second IEEE International Information Assurance Workshop (IWIA'04), 2004
Usage of this product signifies your acceptance of the Terms of Use.