Adaptive Observation of Emerging Cyber Attacks targeting Various IoT Devices

Seiya Kato, Rui Tanabe, Katsunari Yoshioka, Tsutomu Matsumoto · Integrated Network Management · 2021

For years, honeypots have been a valuable tool for observing cyber attacks. But in the age of Internet-of-Things (IoT), where various kinds of devices are being connected to the Internet, honeypots need to achieve diversity and interactivity. In this paper, we propose X-POT, an adaptive honeypot framework that emulates various IoT devices while maintaining a certain level of interactivity. We use components to observe attacks on all TCP ports and by conducting an Internet-wide scan of relevant hosts, we collect responses from real devices. We then selectively choose them as honeypot responses and observe attacks targeting vulnerable IoT devices. We implemented an HTTP honeypot with X-POT framework and exposed it on the Internet for 2 months. We observed 4,729,097 HTTP requests on 64,912 ports and captured 1,276 malware samples. Moreover, we were successful in observing attacks targeting different services such as Docker API and CouchDB. We compared our system with well-known monitoring systems and obtained 669 types of attack defined by an open source Intrusion Detection System, which is up to 2.2 times higher than other systems, and collected 284 malware samples, which is up to 3.5 times higher than other systems. To this end, we reveal our malware datasets for interested researchers.

Read the paper · More papers on PaperTik