Measuring Honeypots based on CTF game

Máté Érsok, Ádám Balogh, László Erdődi, Miklós Kozlovszky, Eszter Kail, Anna Bánáti · 2022

Defensive deception is increasingly being used in cybersecurity, both to improve the effectiveness of defensive methods and to analyse attack techniques and attacker behaviour. One of the oldest and most common tools of defensive deception is the honeypot, which is a lightweight but fake target disguised to distract attackers from real services and targets, while detecting an ongoing attack and sending alert about intrusion. However, due to their frequent deployment, there is a need to measure the effectiveness and performance of these systems for comparability and optimisation. The main objective of our research is to identify indicators, based on different criteria, that allow to measure the performance of honeypot systems and to compare them. Since our honeypot system is implemented in a university environment, we test it through capture the flag games and use the log data collected to measure the effectiveness of honeypot and analyse the behaviour of the attackers and the techniques used.

Read the paper · More papers on PaperTik