학술논문

Honey Plotter and the Web of Terror
Document Type
Conference
Source
2007 16th International Conference on Computer Communications and Networks Computer Communications and Networks, 2007. ICCCN 2007. Proceedings of 16th International Conference on. :1262-1266 Aug, 2007
Subject
Computing and Processing
Communication, Networking and Broadcast Technologies
Components, Circuits, Devices and Systems
Photonics and Electrooptics
Signal Processing and Analysis
Telecommunication traffic
Computer hacking
Internet
Information security
Data visualization
Relational databases
Aggregates
Statistical distributions
Intrusion detection
Monitoring
Language
ISSN
1095-2055
Abstract
Honeypots are a useful tool for discovering the distribution of malicious traffic on the Internet and how that traffic evolves over time. In addition, they allow an insight into new attacks appearing. One major problem is analysing the large amounts of data generated by such honeypots and correlating between multiple honeypots. Honey Plotter is a web-based query and visualisation tool to allow investigation into data gathered by a distributed honeypot network. It is built on top of a relational database, which allows great flexibility in the questions that can be asked and has automatic generation of visualisations based on the results of queries. The main focus is on aggregate statistics but individual attacks can also be analysed. Statistical comparison of distributions is also provided to assist with detecting anomalies in the data; helping separate out common malicious traffic from new threats and trends. Two short case studies are presented to give an example of the types of analysis that can be performed.