ApiPot: A Novelty API Honeypot for Exhaustive Attack Feature Detection in HTTP Protocol

Kalpin Erlangga Silaen, Benfano Soewito, Maria Susan Anggreainy, Aditya Kurniawan · 2024

This paper introduces a novel honeypot called Apipot, specifically designed to emulate API services over the HTTP protocol, with the main purpose of capturing the feature set of each HTTP request more than what is typically recorded in standard web server logs. Web server limitations in logging HTTP requests to API-based applications from visitors mean that critical data required for comprehensive threat analysis and attacker profiling is lost. Apipot overcomes this problem by simulating API services and capturing all the features of HTTP requests. We expected that capturing more features in HTTP requests would enable deeper insight into attacker methods, thereby significantly improving sophisticated cyber attack detection and the ability to more accurately profile attackers, thereby contributing to identifying attackers behind cyber attacks. Our experiment result shows that Apipot can capture 119 unique HTTP headers and 491 unique queries, along with IP source, body, URL, host, and other HTTP request features, from 196,206 requests toward Apipot in 61 days. This result proves that Apipot can capture more features from an HTTP request compared to a web server. As far as we know, Apipot is the first honeypot that mimics an API to capture HTTP request features.

Read the paper · More papers on PaperTik