Investigating Characteristics of Attacks on Public Cloud Systems
Davide Bove, Tilo Müller · 2019
In this work, honeypots were set up on several public cloud infrastructures of Amazon, Microsoft and Google located in different regions around the world, including North America, Asia and Europe. The honeypots, simulating different popular services like SSH and VNC, were used to collect data over a period of two month, resulting in over 170 million log entries. Further analysis of the log entries regarding attack patterns and geographic characteristics are presented in this paper. For example, the attacks originated from 216 countries involving 268,614 unique IPs, dominated by China with a share of 25.83%.