Design and Implementation of A Machine Learning Enhanced Web Honeypot System
Kui Jiang, Haocheng Zheng · 2020
Web attacks are one of the main threats to network information security, and these threats are also increasing. Firewalls and IDSs are signature-based security system devices, it is difficult for them to identify new attack methods adopted by attackers, but honeypots can deal with this problem. Our honeypot is based on crawler technology, which have a well performance in deception. Traditional honeypots cannot help us eliminate some noise and useless data, because it does not have the ability to analyze data. This paper proposed a machine learning enhanced honeypot to reduce the labor cost in data analysis and address this problem. In order to purify the attack data in the honeypot better, we present an ensemble algorithm called regret, which can be used to heterogeneous ensemble. This method could improve the detection performance.