Attack Processes Found on the Internet
Marc Daciér, Fabien Pouget, Hervé Debar · 2004
In this paper, we show that simple, cheap and easily deployable honeypots can help to get a better understanding of the attack processes that machines in unclassified networks are facing. Acquiring this knowledge is a prerequisite for the sound design and implementation of efficient intrusion tolerant systems. We propose some in depth analyses carried out on data gathered during a 10 months period by several honeypots. We highlight the need for a well defined set up of honeypots, replicated in many diverse locations. Such an environment would enable the scientific community to answer the remaining open issues described here after. Recently, several papers have explained how so-called “Internet telescopes ” can be used to get a better understanding of worms propagations ([44, 45]). As a follow up to large scale DdoS attacks, the scientific community has shown a growing interest for a pragmatic analysis of real data streams to identify the various attack processes threatening Internet users. For instance, three papers where devoted to these