Locally-Hosted Fidelity-Adaptive Honeypots with Connection-Preserving Capabilities

Jaime C. Acosta · MILCOM 2022 - 2022 IEEE Military Communications Conference (MILCOM) · 2022

The attack lifecycle starts with the intelligence gathering stage. Network scanning tools are commonly used during this stage to enumerate devices and their services. These tools may be used in various ways depending on the adversary's motivations. The trade-off is between stealth and potential information gain. Some tools may simply identify live hosts, while others may fully connect to remote devices and interact with their services. Traditionally, the choice of honeypot deployment locations and their fidelity are mostly static and they rely on an abundance of resources for hosting and redirection. This is inefficient and, especially in resource-constrained environments, not suitable. Technologies that enable efficient and adaptive honeypots are critical. This paper describes the multi-fidelity honeypot system (mfhoney) that runs on a local device. The system is capable of suspending and switching to different honeypot processes, on-the-fly, while carrying over their active network connections. An evaluation of mfhoney on a constrained virtual machine indicates that the switchover behavior is seamless and delays are negligible: the behavior and reporting of the Nmap scanning tool, as well as legitimate client applications, does not change when interacting with mfhoney.

Read the paper · More papers on PaperTik