An Advanced Honeypot System for Efficient Capture and Analysis of Network Attack Traffic

Balaji Darapareddy, Vijayadeep Gummadi · 2012

A Honeypot is an information system resource used to divert attackers and hackers away from critical resources as well as a tool to study an attacker’s methods. One of the most widely used tools is honeyd for creating honeypots. The logs generated by honeyd can grow very large in size when there is heavy attack traffic in the system, thus consuming a lot of disk space. The huge log size poses difficulty when they are processed and analyzed by security analysts as they consume a lot of time and resources. We propose a system which addresses these issues. It has two important modules. The first module is to capture packets in the network ie either lan or web. The second module is a analyzer the captured packets in order to generate summarized captured packet information and graphs for the security administrators. This application also monitors packet information regarding web traffic. The experimental results show that the space required by log file reduces significantly and reports generated dynamically as per user needs.

Read the paper · More papers on PaperTik