Improving Honeyd for Automatic Generation of Attack Signatures
International Journal of Intelligent Information Systems
Volume 3, Issue 6-1, December 2014, Pages: 23-27
Received: Oct. 7, 2014; Accepted: Oct. 11, 2014; Published: Oct. 20, 2014
Views 3677      Downloads 159
Motahareh Dehghan, Department of Computer Engineering and Information Technology, Amirkabir University of Technology (AUT), Tehran, Iran
Babak Sadeghiyan, Department of Computer Engineering and Information Technology, Amirkabir University of Technology (AUT), Tehran, Iran
In this paper, we design and implement a new Plugin to Honeyd which generates attack signature, automatically. Current network intrusion detection systems work on misuse detectors, where the packets in the monitored network are compared against a repository of signatures. But, we focus on automatic signature generation from malicious network traffic. Our proposed system inspects honeypot traffic and generates intrusion signatures for unknown traffic.The signature is based on traffic patterns, using Longest Common Substring (LCS) algorithm. It is noteworthy that our system is a plugin to honeyd - a low interaction honeypot. The system's output is a file containing honeypot intrusion signatures in pseudo-snort format. Signature generation system has been implemented for Linux Operating System (OS) but due to the common use of Windows OS, we implement for Windows OS, using C programming language.
Honeypot, Honeyd, Signature, Intrusion Detection System (IDS), Longest Common Substring (LCS) Algorithm
To cite this article
Motahareh Dehghan, Babak Sadeghiyan, Improving Honeyd for Automatic Generation of Attack Signatures, International Journal of Intelligent Information Systems. Special Issue: Research and Practices in Information Systems and Technologies in Developing Countries. Vol. 3, No. 6-1, 2014, pp. 23-27. doi: 10.11648/j.ijiis.s.2014030601.14
