DocumentCode
1804258
Title
Amber: A zero-interaction honeypot and network enforcer with modular intelligence
Author
Schoeman, Adam
Author_Institution
Dept. of Comput. Sci., Rhodes Univ., Grahamstown, South Africa
fYear
2013
fDate
14-16 Aug. 2013
Firstpage
1
Lastpage
7
Abstract
For the greater part, security controls are based around the principle of Decision through Detection (DtD). The exception to this is a Honeypot, which analyses interactions between a third party and itself, while occupying a piece of unused information space. As honeypots are not located on productive information resources, any interaction with it can be assumed to be non-productive. This allows the honeypot to make decisions based simply on the presence of data, rather than on the behaviour of the data. But due to limited resources in human capital, honeypots´ uptake in the South African market has been underwhelming. Amber attempts to change this by offering a zero-interaction security system, which will use the honeypot approach of Decision through Presence (DtP) to generate a blacklist of third parties, which can be passed on to a network enforcer. Empirical testing has been done proving the usefulness of this alternative and low cost approach in defending networks. The functionality of the system was also extended by installing nodes in different geographical locations, and streaming their detections into the central Amber hive.
Keywords
computer network security; decision making; DtD; DtP; South African market; central Amber hive; decision making; decision through detection; decision through presence; geographical locations; human capital; modular intelligence; network enforcer; security control; zero-interaction honeypot; zero-interaction security system; Context; IP networks; Information security; Internet; Mathematical model; Ports (Computers); Honeypot; Security Models;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Security for South Africa, 2013
Conference_Location
Johannesburg
Type
conf
DOI
10.1109/ISSA.2013.6641053
Filename
6641053
Link To Document