• DocumentCode
    1804258
  • Title

    Amber: A zero-interaction honeypot and network enforcer with modular intelligence

  • Author

    Schoeman, Adam

  • Author_Institution
    Dept. of Comput. Sci., Rhodes Univ., Grahamstown, South Africa
  • fYear
    2013
  • fDate
    14-16 Aug. 2013
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    For the greater part, security controls are based around the principle of Decision through Detection (DtD). The exception to this is a Honeypot, which analyses interactions between a third party and itself, while occupying a piece of unused information space. As honeypots are not located on productive information resources, any interaction with it can be assumed to be non-productive. This allows the honeypot to make decisions based simply on the presence of data, rather than on the behaviour of the data. But due to limited resources in human capital, honeypots´ uptake in the South African market has been underwhelming. Amber attempts to change this by offering a zero-interaction security system, which will use the honeypot approach of Decision through Presence (DtP) to generate a blacklist of third parties, which can be passed on to a network enforcer. Empirical testing has been done proving the usefulness of this alternative and low cost approach in defending networks. The functionality of the system was also extended by installing nodes in different geographical locations, and streaming their detections into the central Amber hive.
  • Keywords
    computer network security; decision making; DtD; DtP; South African market; central Amber hive; decision making; decision through detection; decision through presence; geographical locations; human capital; modular intelligence; network enforcer; security control; zero-interaction honeypot; zero-interaction security system; Context; IP networks; Information security; Internet; Mathematical model; Ports (Computers); Honeypot; Security Models;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Security for South Africa, 2013
  • Conference_Location
    Johannesburg
  • Type

    conf

  • DOI
    10.1109/ISSA.2013.6641053
  • Filename
    6641053