Honeypot-Architectures using VMI Techniques

Stefan Floeren · TU München - Informatik · 2013

Honeypots are an eective tool to gain information about sophisticated attacks and zero-day exploits. With rising popularity of virtual machines in the World Wide Web, systems using virtual honeypots also get more interesting. After giving an introduction into traditional honeypot systems, this paper first describes VMScope, a VMI-IDS (virtual-machine-introspection-based intrusion detection system) which focuses on providing a tamper-resistant but thorough honeypot surveillance system. Then Collapsar is described, a system of multiple virtual honeypots that logically resides in dierent networks with the purpose of detecting attacks that span across multiple networks. Finally, a combination of both systems is proposed and the capabilities are discussed.

Read the paper · More papers on PaperTik