• DocumentCode
    3599413
  • Title

    Determining the strength of a decoy system: a paradox of deception and solicitation

  • Author

    Jordan, Christonher J. ; Zhang, Oiang ; Roves, Jason

  • fYear
    2004
  • Firstpage
    138
  • Lastpage
    145
  • Abstract
    This paper examines the effectiveness of two shallow decoys, Deception Toolkit (DTK) and Honeyd. A series of attacks, ranging in complexity, were used to examine how these systems interact with key anomalies differently than actual services do. Analysis of these tests shows that shallow decoys not only have difficulty with normal Web traffic, but they also show significant deviation from normal Web services while interacting with malicious code. This paper also discusses the difficulties inherent in developing effective shallow decoys and demonstrates that, contrary to what might be expected, when implemented in less covertly deceptive ways, shallow decoys may actually be more likely to solicit interaction from the malicious systems they are designed to study.
  • Keywords
    security of data; system monitoring; Deception Toolkit; Honeyd; honeypots; malicious software; security; shallow decoy system; Analysis of variance; Application software; Documentation; Humans; Intelligent networks; Research and development; Testing; Web services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Assurance Workshop, 2004. Proceedings from the Fifth Annual IEEE SMC
  • Print_ISBN
    0-7803-8572-1
  • Type

    conf

  • DOI
    10.1109/IAW.2004.1437809
  • Filename
    1437809