DocumentCode
3599413
Title
Determining the strength of a decoy system: a paradox of deception and solicitation
Author
Jordan, Christonher J. ; Zhang, Oiang ; Roves, Jason
fYear
2004
Firstpage
138
Lastpage
145
Abstract
This paper examines the effectiveness of two shallow decoys, Deception Toolkit (DTK) and Honeyd. A series of attacks, ranging in complexity, were used to examine how these systems interact with key anomalies differently than actual services do. Analysis of these tests shows that shallow decoys not only have difficulty with normal Web traffic, but they also show significant deviation from normal Web services while interacting with malicious code. This paper also discusses the difficulties inherent in developing effective shallow decoys and demonstrates that, contrary to what might be expected, when implemented in less covertly deceptive ways, shallow decoys may actually be more likely to solicit interaction from the malicious systems they are designed to study.
Keywords
security of data; system monitoring; Deception Toolkit; Honeyd; honeypots; malicious software; security; shallow decoy system; Analysis of variance; Application software; Documentation; Humans; Intelligent networks; Research and development; Testing; Web services;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Assurance Workshop, 2004. Proceedings from the Fifth Annual IEEE SMC
Print_ISBN
0-7803-8572-1
Type
conf
DOI
10.1109/IAW.2004.1437809
Filename
1437809
Link To Document