ACM Home Page
Please provide us with feedback. Feedback
Honeycomb: creating intrusion detection signatures using honeypots
Full text PdfPdf (110 KB)
Source ACM SIGCOMM Computer Communication Review archive
Volume 34 ,  Issue 1  (January 2004) table of contents
COLUMN: Papers from Hotnets-II table of contents
Pages: 51 - 56  
Year of Publication: 2004
ISSN:0146-4833
Authors
Christian Kreibich  University of Cambridge Computer Laboratory, Cambridge, United Kingdom
Jon Crowcroft  University of Cambridge Computer Laboratory, Cambridge, United Kingdom
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 43,   Downloads (12 Months): 263,   Citation Count: 9
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues   peer to peer  

Tools and Actions: Review this Article  
Save this Article to a Binder    Display Formats: BibTex  EndNote ACM Ref   
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/972374.972384
What is a DOI?

ABSTRACT

This paper describes a system for automated generation of attack signatures for network intrusion detection systems. Our system applies pattern-matching techniques and protocol conformance checks on multiple levels in the protocol hierarchy to network traffic captured a honeypot system. We present results of running the system on an unprotected cable modem connection for 24 hours. The system successfully created precise traffic signatures that otherwise would have required the skills and time of a security officer to inspect the traffic manually.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
 
2
 
3
C. Stoll, The Cuckoo's Egg. Addison-Wesley, 1986.
 
4
W. R. Cheswick, "An Evening with Berferd, in which a Cracker is lured, endured, and studied," in Proceedings of the 1992 Winter USENIX Conference, 1992.
 
5
 
6
N. Provos, "Honeyd - A Virtual Honeypot Daemon," in 10th DFN-CERT Workshop, Hamburg, Germany, February 2003.
 
7
 
8
P. Weiner, "Linear pattern matching algorithms," in Proceedings of the 14th IEEE Symposium on Switching and Automata Theory, 1973, pp. 1--11.
9
 
10
E. Ukkonen, "On-line construction of suffix trees," Algorithmica, no. 14, pp. 249--260, 1995.
 
11
S. McCanne, C. Leres, and V. Jacobson, "tcpdump/libpcap," http://www.tcpdump.org/, 1994.
 
12
M. Handley, C. Kreibich, and V. Paxson, "Network Intrusion Detection: Evasion, Traffic Normalization, end End-to-End Protocol Semantics," in Proceedings of the 9th USENIX Security Symposium, 2000.
 
13
T. H. Ptacek and T. N. Newsham, "Insertion, Evasion and Denial of Service: Eluding Network Intrusion Detection," Secure Networks, Inc., Tech. Rep., 1998.

CITED BY  9
 
 
 

Collaborative Colleagues:
Christian Kreibich: colleagues
Jon Crowcroft: colleagues

Peer to Peer - Readers of this Article have also read: