A Reconfigurable Hardware Platform for Secure and Efficient Malware Collection in Next-Generation High-Speed Networks
Sascha Mühlbach, Andreas Koch · International Journal for Information Security Research · 2012
With the growing diversity of malware, researchers must be able to quickly collect many representative samples for study.This can be done, e.g., by using honeypots.As an alternative to software-based honeypots, we propose a singlechip honeypot appliance that is entirely hardware-based and thus significantly more resilient against compromising attacks.Additionally, it can easily keep up with network speeds of 10+ Gb/s and emulate thousands of vulnerable hosts.As base technology, we employ reconfigurable hardware devices whose functionality is not fixed by the manufacturing process.Furthermore, a special technology available in modern reconfigurable devices allows to alter part of the functionality even during operation and will be used to create a hardware virtualization layer.Beyond the technical aspects, we present improvements to the platform, aiming to simplify management and updates.To this end, we introduce the domain-specific language VEDL, which can be used to describe the honeypot behavior in a high-level manner by security experts not proficient in hardware design.