Fingerprinting Bots in a Hybrid Honeypot
Willie Bythwood, Andrew Kien, Iman Vakilinia · 2023
Honeypot is an effective security tool to study attackers’ tactics, techniques, and procedure. However, advanced attackers can easily detect low/medium interaction honeypots. On the other hand, the implementation of high interaction honeypots is expensive. As a big portion of malicious network traffic is initiated from botnets, it is necessary to not waste high interaction honeypot resources for these known traffic. To solve this issue, hybrid honeypot can be used to manage attack traffic toward low/medium, and high interaction honeypots based on the attackers’ characteristics. In this paper, we propose a new hybrid honeypot scheme in which we use multiple threat intelligence information including HASSH1, IP reputation, OS, CVEs, and open ports of the attacker to identify bots and make the decision for the attack traffic. The experiment results show the effectiveness of our proposed method.