The Leurre.com Project: Collecting Internet Threats Information Using a Worldwide Distributed Honeynet

Corrado Leita, V. Pham, Olivier Thonnard, E. S. Ramírez, F. Pouget, E. Kirda, M. Dacier
{"title":"The Leurre.com Project: Collecting Internet Threats Information Using a Worldwide Distributed Honeynet","authors":"Corrado Leita, V. Pham, Olivier Thonnard, E. S. Ramírez, F. Pouget, E. Kirda, M. Dacier","doi":"10.1109/WISTDCS.2008.8","DOIUrl":null,"url":null,"abstract":"This paper aims at presenting in some depth the Leurre.com project and its data collection infrastructure. Launched in 2003 by the Institut Eurecom, this project is based on a worldwide distributed system of honeypots running in more than 30 different countries. The main objective of the project is to get a more realistic picture of certain classes of threats happening on the Internet, by collecting unbiased quantitative data in a long-term perspective. In the first phase of the project, the data collection infrastructure relied solely on low-interaction sensors based on Honeyd to collect unsolicited traffic on the Internet. Recently, a second phase of the project was started with the deployment of medium-interaction honeypots based on the ScriptGen technology, in order to enrich the network conversations with the attackers. All network traces captured on the platforms are automatically uploaded into a centralized database accessible by the partners via a convenient interface. The collected traffic is also enriched with a set of contextual information (e.g. geographical localization and reverse DNS lookups). This paper presents this complex data collection infrastructure, and offers some insight into the structure of the central data repository. The data access interface has been developed to facilitate the analysis of today's Internet threats, for example by means of data mining tools. Some concrete examples are presented to illustrate the richness and the power of this data access interface. By doing so, we hope to encourage other researchers to share with us their knowledge and data sets, to complement or enhance our ongoing analysis efforts, with the ultimate goal of better understanding Internet threats.","PeriodicalId":142886,"journal":{"name":"2008 WOMBAT Workshop on Information Security Threats Data Collection and Sharing","volume":"133 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2008-04-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"46","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2008 WOMBAT Workshop on Information Security Threats Data Collection and Sharing","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/WISTDCS.2008.8","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 46

Abstract

This paper aims at presenting in some depth the Leurre.com project and its data collection infrastructure. Launched in 2003 by the Institut Eurecom, this project is based on a worldwide distributed system of honeypots running in more than 30 different countries. The main objective of the project is to get a more realistic picture of certain classes of threats happening on the Internet, by collecting unbiased quantitative data in a long-term perspective. In the first phase of the project, the data collection infrastructure relied solely on low-interaction sensors based on Honeyd to collect unsolicited traffic on the Internet. Recently, a second phase of the project was started with the deployment of medium-interaction honeypots based on the ScriptGen technology, in order to enrich the network conversations with the attackers. All network traces captured on the platforms are automatically uploaded into a centralized database accessible by the partners via a convenient interface. The collected traffic is also enriched with a set of contextual information (e.g. geographical localization and reverse DNS lookups). This paper presents this complex data collection infrastructure, and offers some insight into the structure of the central data repository. The data access interface has been developed to facilitate the analysis of today's Internet threats, for example by means of data mining tools. Some concrete examples are presented to illustrate the richness and the power of this data access interface. By doing so, we hope to encourage other researchers to share with us their knowledge and data sets, to complement or enhance our ongoing analysis efforts, with the ultimate goal of better understanding Internet threats.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Leurre.com项目:使用全球分布式蜜网收集互联网威胁信息
本文旨在较深入地介绍Leurre.com项目及其数据收集基础设施。该项目于2003年由Eurecom研究所发起,它基于一个分布在全球30多个不同国家的蜜罐系统。该项目的主要目标是通过从长远的角度收集公正的定量数据,对互联网上发生的某些类别的威胁有一个更现实的了解。在项目的第一阶段,数据收集基础设施仅依靠基于Honeyd的低交互传感器来收集互联网上未经请求的流量。最近,该项目的第二阶段开始了,部署了基于ScriptGen技术的中等交互蜜罐,以丰富与攻击者的网络对话。在平台上捕获的所有网络痕迹都自动上传到一个集中的数据库中,合作伙伴可以通过一个方便的界面访问该数据库。收集的流量还丰富了一组上下文信息(例如地理定位和反向DNS查找)。本文介绍了这种复杂的数据收集基础设施,并对中央数据存储库的结构提供了一些见解。数据访问接口的开发是为了便于分析当今的互联网威胁,例如通过数据挖掘工具。给出了一些具体的例子来说明这个数据访问接口的丰富性和强大功能。通过这样做,我们希望鼓励其他研究人员与我们分享他们的知识和数据集,以补充或加强我们正在进行的分析工作,最终目标是更好地了解互联网威胁。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
The Honeynet Project: Data Collection Tools, Infrastructure, Archives and Analysis Cooperation of Intelligent Honeypots to Detect Unknown Malicious Codes nicter: An Incident Analysis System Toward Binding Network Monitoring with Malware Analysis Techcrafters and Makecrafters: A Comparison of Two Populations of Hackers The Leurre.com Project: Collecting Internet Threats Information Using a Worldwide Distributed Honeynet
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1