Title :
Defeating Internet attacks using risk awareness and active honeypots
Author :
Teo, Lawrence ; Sun, Yu-An ; Ahn, Gail-Joon
Author_Institution :
Lab. of Inf. Integration, Security & Privacy, North Carolina Univ., Charlotte, NC, USA
Abstract :
New forms of Internet attacks, such as SQL Slammer, have become increasingly sophisticated. Although coded in a simple way, the SQL Slammer worm propagated all over the world at an extremely high speed in a short period of time, rendering it impossible for humans to counter it using manual intervention. Here, we propose a security framework called Japonica to detect and respond to unknown attacks at the early stage through the dynamic orchestration of prevention, detection, and response mechanisms. We identify important requirements to support the proposed framework and corresponding system entities. Also, we describe our model using colored Petri nets to discover a uniform message exchange format among the entities. One unique characteristic of Japonica is an active response coordinator and we demonstrate its feasibility in a proof-of-concept prototype, utilizing a honeypot as an active entity. Our results indicate that Japonica can successfully prevent the spread of SQL Slammer without human intervention. We are currently extending the framework to counter other forms of sophisticated Internet attacks.
Keywords :
Internet; Petri nets; authorisation; invasive software; risk analysis; Internet attack; Japonica security framework; SQL Slammer worm; active honeypot; colored Petri net; message exchange format; risk awareness; Computer worms; Counting circuits; Humans; Information security; Internet; Intrusion detection; Laboratories; Petri nets; Privacy; Sun;
Conference_Titel :
Information Assurance Workshop, 2004. Proceedings. Second IEEE International
Print_ISBN :
0-7695-2117-7
DOI :
10.1109/IWIA.2004.1288045