Detecting Emerging Large-Scale Vulnerability Scanning Activities by Correlating Low-Interaction Honeypots with Darknet

Ryoh Akiyoshi, Daisuke Kotani, Yasuo Okabe · 2018

Cyberattacks such as scanning by botnet worms, falsification of web pages, and security breaches happen on the Internet every day. To minimize damage caused by such attacks, early discovery of new attack trends and quick response to incidents are essential since detection delays and slow responses to incidents will cause further damage. Typical methods to detect new large-scale attacks are: (1) analyzing data collected by the darknet, (2) analyzing data collected by honeypots, and (3) summarizing alerts made by intrusion detection systems (IDSs). A darknet is a reachable and unused address space on the Internet, and we can figure out coarse-grained attack trends, such as volume of scans to each TCP/UDP port, by analyzing packets arrived at the darknet. However, darknet traffic usually cannot provide enough payloads to analyze attacks in detail although there are various scans to applications running on one TCP/UDP port, such as Web applications. A honeypot system can intentionally be attacked so that the attack codes and attacker behaviors can be observed after they are attracted to it. A drawback is that honeypots cannot be deployed so large because attackers are very likely to become aware of honeypots whey they are deployed on a network scale like darknet. IDS alerts provide information about attacks, but in recent years attacks the are resistant to be detected by IDS are increasing. In this paper, we present a system that automatically detects new scan activities and estimates the scale of each attack by correlating the data obtained by both low-interaction honeypots and the darknet. A low-interaction honeypot collects payload in TCP stream to find attacks without depending on a specific protocol and classify attack codes in the context of applications. By analyzing the cooccurrence of attacks observed at honeypots and darknet by various features, the system estimates the scale of attacks per each attack. The evaluation result suggests that many attacks can be observed at both honeypots and darknet, so it may be useful to correlate both data by observed time.

Read the paper · More papers on PaperTik