Combining Divide-and-Conquer and Sequential Visitation Algorithms on High-Interaction Client Honeypots
Dong-Jin Kim, Honggeun Kim, Minkyu Park, Seong-je Cho · Jeongbo gwahaghoe nonmunji. si'seu'tem mich i'lon · 2012
A high interaction client honeypot actually visits suspicious web servers and detects malicious web servers by monitoring changes in the client state. We need an algorithm that efficiently visits suspicious web servers in order that this work is useful. When many servers are to be analyzed and a percentage of malicious webpages are very low, we usually use a divide and conquer visitation algorithm. This algorithm concurrently visits suspicious k webpages and then divides k webpages into groups of a fewer number of webpages and revisits these groups recursively. Binary Divide-And-Conquer (BDAC) divides k webpages into two (k/2)-pages groups; Logarithmic Divide-And-Conquer (LDAC) divides webpages into a number of -pages groups. These algorithms incur unnecessary reverts and revisits when a size of the group is small. We propose a new scheme that enhances the performance of divide-and-conquer algorithms. This scheme stops dividing webpages when the size of groups are less than or equal to a certain size (sequential threshold) and visits the rest of them sequentially. We call it Divide-and-Conquer & Sequential (DAC-S) approach. We show that under a simulation configuration similar to the real-world, the proposed approach performs better than existing algorithms.