Unveiling Malicious Activities in LAN with Honeypot
Zhiqing Zhang, Hiroshi Esaki, Hideya Ochiai · 2019
Security monitoring of remote local area network (LAN) is getting more and more important these days as the cyber attacks shifts the target to the hosts in LANs. However, just the monitoring cannot recognize the differences between vulnerability tests and malware attacks, which may cause confusion among network operators. This paper proposes an architecture of cloud-based LAN-security monitoring system that can differentiate vulnerability tests and malware attacks happens in the remote LANs. We also design the algorithm to classify those activities into (1) ARP scan, (2) TCP port scan, (3) application-level connection establishment and (4) intrusion - the latter two activities are mostly caused by malware not by vulnerability testing. We demonstrate with our prototype implementation that our system can differentiate those behaviors: i.e., vulnerability tests and malware attacks.