Detection and Classification of Malicious Access using a Dionaea Honeypot

Koki Saikawa, Vitaly V. Klyuev · 2019

Nowadays, cyber attacks are becoming ingenious. Their goal is to leak confidential information or break the normal work of target servers. A Honeypot exposes the server or network that has vulnerabilities to the Internet and obtains the attack information by observing and investigating the attacking methods. In this study, we use a Dionaea Honeypot installed on the Sakura Cloud located in Japan to cache malicious access, analyze attack information, understand the current trend in attack mechanisms in the Japanese segment of the network, and test mechanisms preventing Honeypot detection. The obtained results are compared with the results of a global gathering completed by multiple Honeypots and results from the Malaysian segment of the Internet. The results can be helpful for improving security technology.

Read the paper · More papers on PaperTik