Browse > Article
http://dx.doi.org/10.13067/JKIECS.2013.8.6.863

Cybertrap : Unknown Attack Detection System based on Virtual Honeynet  

Kang, Dae-Kwon (한전KDN(주) 임베디드연구그룹)
Hyun, Mu-Yong (한전KDN(주) SG기반시설보안연구TF)
Kim, Chun-Suk (전남대학교 전자통신공학과)
Publication Information
The Journal of the Korea institute of electronic communication sciences / v.8, no.6, 2013 , pp. 863-871 More about this Journal
Abstract
Recently application of open protocols and external network linkage to the national critical infrastructure has been growing with the development of information and communication technologies. This trend could mean that the national critical infrastructure is exposed to cyber attacks and can be seriously jeopardized when it gets remotely operated or controlled by viruses, crackers, or cyber terrorists. In this paper virtual Honeynet model which can reduce installation and operation resource problems of Honeynet system is proposed. It maintains the merits of Honeynet system and adapts the virtualization technology. Also, virtual Honeynet model that can minimize operating cost is proposed with data analysis and collecting technique based on the verification of attack intention and focus-oriented analysis technique. With the proposed model, new type of attack detection system based on virtual Honeynet, that is Cybertrap, is designed and implemented with the host and data collecting technique based on the verification of attack intention and the network attack pattern visualization technique. To test proposed system we establish test-bed and evaluate the functionality and performance through series of experiments.
Keywords
Zero-day Attack; Virtual Honeynet; High-Interaction Hoenypot; Client Honeypot; Attack Visualization;
Citations & Related Records
연도 인용수 순위
  • Reference