首页> 外文会议>International Carnahan Conference on Security Technology >The art of false alarms in the game of deception: Leveraging fake honeypots for enhanced security
【24h】

The art of false alarms in the game of deception: Leveraging fake honeypots for enhanced security

机译:欺骗游戏中的错误警报艺术:利用伪造的蜜罐提高安全性

获取原文

摘要

The great popularity of the Internet increases the concern for the safety of its users as many malicious Web pages pop up in daily basis. Client honeypots are tools, which are able to detect malicious Web pages, which aim to infect their visitors. These tools are widely used by researchers and anti-virus companies in their attempt to protect Internet users from being infected. Unfortunately, cyber-criminals are becoming aware of this type of detection and create evasion techniques that allow them to behave in a benign way when they feel to be threatened. This bi-faceted behavior enables them to operate for a longer period, which translates in more profit. Hence, these deceptive Web pages pose a significant challenge to existing client honeypot approaches, making them incapable to detect them when exhibit the aforementioned behavior. In this paper, we mitigate this problem by designing and developing a framework that benefits from this bi-faceted behavior. Our main goal is to protect users from being infected. More precisely, we leverage the evasion techniques used by cyber-criminals and implement a prototype, called Scarecrow, which triggers false alarms in the cases of deceptive Web pages. Consequently, the users that use Scarecrow for Web surfing can remain protected, even if they visit a malicious Website. We evaluate our implementation against malicious URLs provided by a large anti-virus company and show that when Scarecrow is deployed, malicious Websites with bi-faceted behavior do not launch their attacks against normal users.
机译:由于每天都会弹出许多恶意网页,因此Internet的广泛普及增加了对其用户安全的担忧。客户端蜜罐是能够检测旨在感染其访问者的恶意网页的工具。研究人员和反病毒公司广泛使用这些工具来保护Internet用户免遭感染。不幸的是,网络犯罪分子正在意识到这种类型的检测,并创建了规避技术,使他们在受到威胁时能够以良性的方式行事。这种双向的行为使他们可以经营更长的时间,从而获得更多的利润。因此,这些欺骗性网页对现有的客户端蜜罐方法提出了重大挑战,使其在表现出上述行为时无法检测到它们。在本文中,我们通过设计和开发可从这种双向行为中受益的框架来缓解此问题。我们的主要目标是保护用户免受感染。更准确地说,我们利用网络犯罪分子使用的逃避技术,并实现了一个名为“稻草人”的原型,该原型在具有欺骗性的Web页面中会触发错误警报。因此,即使他们访问了恶意网站,使用稻草人进行网络冲浪的用户也可以受到保护。我们根据大型反病毒公司提供的恶意URL评估了我们的实施,并表明部署稻草人时,具有双向行为的恶意网站不会对普通用户发起攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号