Honeypot Communities: A Case Study with the Discrete‐Event Simulation Framework
Mohsen Guizani, Ammar Rayes, Bilal Muhammad Khan, Ala Al‐Fuqaha · 2010
In this chapter, the authors design and develop a simulation of a system that will generate malware antivirus signatures using an untrusted multi-domain community of honeypots. Roughly speaking, the honeypot community will act as a “Petri dish” for worms. The chapter provides the reader with a real case study illustrating how to build a simulation using the Discrete Event Simulation Framework. A number of approaches for detecting and responding to worms have been considered. The Worminator system uses alerts that are shared within a distributed intrusion detection system (IDS) in order to detect an attack in progress. Network worms are fast enough to overrun any detector deployed in a single administrative domain, thus making the case for a distributed, collaborative detector. The chapter explains various SimEnt classes that include Machine, Honeypot, Sensor, Env, Worm and Experimenter. Controlled Vocabulary Terms discrete event simulation; invasive software; safety systems