Multi Platform Honeypot for Generation of Cyber Threat Intelligence
Sanjeev Kumar, B. Janet, R. Eswari · 2019
The threat landscape is exponentially increasing which become more worsen when a greater number of emerging devices are connected to internet such as Internet of Things (IoTs), Embedded Systems, Cyber Physical devices etc. To control the damage of cyber threats, there is a need to monitor the cyber criminals continuously to understand the tools and technique used by the attackers in order to develop cyber defense mechanism to protect cyber Eco-systems. In this research, a multi-Honeypot platform as a tool is presented for cyber threat intel generation to implement the multiple classes of Honeypots such as Windows, IoTs, Embedded etc. Honeypot is widely used by the security researchers, security companies to understand the tools and tactics about the attackers but these are quite complex to deploy and maintain especially due to diverse set of IT systems and intensive resource requirements to deploy High Interaction Honeypots. This complexity is reduced in this research by implementation of Para-Virtualization based approach to enable multiple classes of Honeypot sensors of different platforms on a light weight hardware. It is addressed that time window to collect the data and to conclude it as a cyber threat intel with support of evidences should be probabilistically determined. After applying the analysis such as behavior analysis and deep learning methods to determine about the unknown threat patterns, the attack data sets are correlated into different cyber threat events and converted into an actionable cyber threat intelligence to disseminate the information in an automated manner. In the end, threat intelligence is generated and experiments are documented. The deep learning-based analysis inspired by neural networks is integrated in the design to determine the unknown classified threat events.