Design and Implementation of Modular Honeynet System Based on SDN

Yan Li, Bin Wu · 2019

Traditional honeynets cannot dynamically migrate traffic. The flexibility of SDN can solve this problem. At the same time, the traditional honeynets have the disadvantages of complicated alarm logs and inability to carry out targeted analysis, and lacks protection for the honeypot. It is easy to completely destroy the honeypot and make it a jumper for the attacker to launch the next attack on the intranet. This paper proposes a modular honeynet system based on SDN, which can respond to the scanning probe-exploit-worm injected attack chain, reducing the complexity of the alarm log and improving the efficiency of the researchers in analyzing attacks. Also, a honeypot switching strategy based on the detection of the attack tree phase is proposed in the module of vulnerability response, which can delay the attacker's attack progress and reduces the risk of the honeypot. The experiment also verified the feasibility of the modular system.

Read the paper · More papers on PaperTik