Mimic honeypot based on dual mimicry mechanism
Xiangyu Lǚ, Peng Yi, Youjun Bu, Bo Chen · Third International Conference on Electronics and Communication; Network and Computer Technology (ECNCT 2021) · 2022
Active defense is currently a key technology to reverse the asymmetry of offensive and defense in cyberspace. Honeypots, as one of the active defense technologies, are deployed in the internal network to attract attackers’ attacks, consume the attackers’ energy, and discover the attackers’ attack methods and attack intent. But at the same time, if there are security loopholes in the honeypot itself, the honeypot becomes the entrance for the attacker to attack the intranet, which will harm the security of the intranet. In this paper, aiming at the virtual machine escape scenario in the honeypot system, based on the mimicry defense idea, a dual mimicry mechanism and the honeypot architecture under this mechanism are proposed. This mechanism uses the heterogeneity of the underlying virtualization platform to resist the escaping vulnerabilities of the virtualization platform, and achieves level heterogeneity through honeypots to attract attackers, which is conducive to the complete collection of attackers' attack behaviors. Finally, the security test and performance test were carried out through the web implementation of the mimic honeypot.