Application of divide-and-conquer algorithm paradigm to improve the detection speed of high interaction client honeypots
Christian Seifert, Ian S. Welch, Peter Komisarczuk · 2008
We present the design and analysis of a new algorithm for high interaction client honeypots for finding malicious servers on a network. The algorithm uses the divide-and-conquer paradigm and results in a considerable performance gain over the existing sequential algorithm. The performance gain not only allows the client honeypot to inspect more servers with a given set of identical resources, but it also allows researchers to increase the classification delay to investigate false negatives incurred by the use of artificial time delays in current solutions.