A Method to Prevent Known Attacks and Their Variants by Combining Honeypots and IPS
Yudai Yamamoto, Shingo Yamaguchi · 2022 IEEE 11th Global Conference on Consumer Electronics (GCCE) · 2022
We propose a method to detect and prevent not only known attacks using HTTP but also their variants. The method is characterized by using honeypot and IPS in combination to respond to the latest attacks. We can prevent attacks by obtaining data about latest attacks using honeypots and generating rules for IPS based on data collected then applying them. As a result of the experiment, we confirmed that the proposed method could detect variants with a probability of at least 12% higher than the method using only the Suricata official rule.