DocumentCode :
1804258
Title :
Amber: A zero-interaction honeypot and network enforcer with modular intelligence
Author :
Schoeman, Adam
Author_Institution :
Dept. of Comput. Sci., Rhodes Univ., Grahamstown, South Africa
fYear :
2013
fDate :
14-16 Aug. 2013
Firstpage :
1
Lastpage :
7
Abstract :
For the greater part, security controls are based around the principle of Decision through Detection (DtD). The exception to this is a Honeypot, which analyses interactions between a third party and itself, while occupying a piece of unused information space. As honeypots are not located on productive information resources, any interaction with it can be assumed to be non-productive. This allows the honeypot to make decisions based simply on the presence of data, rather than on the behaviour of the data. But due to limited resources in human capital, honeypots´ uptake in the South African market has been underwhelming. Amber attempts to change this by offering a zero-interaction security system, which will use the honeypot approach of Decision through Presence (DtP) to generate a blacklist of third parties, which can be passed on to a network enforcer. Empirical testing has been done proving the usefulness of this alternative and low cost approach in defending networks. The functionality of the system was also extended by installing nodes in different geographical locations, and streaming their detections into the central Amber hive.
Keywords :
computer network security; decision making; DtD; DtP; South African market; central Amber hive; decision making; decision through detection; decision through presence; geographical locations; human capital; modular intelligence; network enforcer; security control; zero-interaction honeypot; zero-interaction security system; Context; IP networks; Information security; Internet; Mathematical model; Ports (Computers); Honeypot; Security Models;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Security for South Africa, 2013
Conference_Location :
Johannesburg
Type :
conf
DOI :
10.1109/ISSA.2013.6641053
Filename :
6641053
Link To Document :
بازگشت