Ubiquitous Redirection as Access Control Response.

George Bakos, Sergey Bratus · 2005

Rule-based access control mechanisms, network firewalls and application input validation all serve to enforce security policy. When violating the acceptable conditions these defenses mandate, an unauthorized requester is generally turned away. We make an argument for a modification to traditional access limitation through redirection and deceptive completion across many layers of data communication. Ubiquitous redirection provides additional information on attacker behavior, consumes attacker resources, improving defender awareness and, ultimately, site security. We describe a variety of network-based techniques for deception implemented in our honeypots, and undertake a study of OS-level deception practiced by rootkit writers with the view towards prospective use of similar techniques for defensive applications.

Read the paper · More papers on PaperTik