• DocumentCode
    3580735
  • Title

    Aggressive web application honeypot for exposing attacker´s identity

  • Author

    Djanali, Supeno ; Arunanto, F.X. ; Pratomo, Baskoro Adi ; Baihaqi, Abdurrazak ; Studiawan, Hudan ; Shiddiqi, Ary Mazharuddin

  • Author_Institution
    Dept. of Inf., Inst. Teknol. Sepuluh Nopember, Surabaya, Indonesia
  • fYear
    2014
  • Firstpage
    212
  • Lastpage
    216
  • Abstract
    Attackers are most likely to exploit invalidated and unsanitized user input with several attacks such as cross-site scripting (XSS) or SQLinjection. Many methods were proposed to prevent those attacks. Some of them were created to learn about pattern and behavior of the attacker. That is honeypot. Honeypot is classified into two types based on the simulation that honeypot can do : low interaction and high interaction. In this paper, we propose a low-interaction honeypot for emulating vulnerabilities that can be exploited using XSS and SQL injection attacks. But this honeypot not only records attacker´s request, but also try to expose attacker identity by using some browser exploitation techniques. Some attackers would use techniques to hide their identity, thus they couldn´t be tracked. Our proposed honeypot was trying to overcome this problem by giving them malicious JavaScript codes. The malicious JavaScript codes will be run when an attacker open the honeypot´s website. We have conducted several test to see how our honeypot´s performance. Our honeypot could catch more useful information about the HTTP request than popular web-based honeypot, Glastopf. Moreover, there were attacker´s social media accounts caught by using LikeJacking technique although they might have used proxy or TOR to hide their identity.
  • Keywords
    Internet; Java; SQL; security of data; social networking (online); Glastopf; HTTP request; LikeJacking technique; SQL injection attacks; TOR; Web-based honeypot; XSS; aggressive Web application honeypot; attacker identity; browser exploitation techniques; cross-site scripting; honeypot Website; invalidated user input; malicious JavaScript codes; social media accounts; unsanitized user input; Browsers; Cities and towns; Databases; Fingerprint recognition; IP networks; Lead; LikeJacking; SQL injection; cross-site scripting; web application honeypot;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Technology, Computer and Electrical Engineering (ICITACEE), 2014 1st International Conference on
  • Print_ISBN
    978-1-4799-6431-4
  • Type

    conf

  • DOI
    10.1109/ICITACEE.2014.7065744
  • Filename
    7065744