Towards systematic honeytoken fingerprinting

Shreyas Srinivasa, Jens Myrup Pedersen, Emmanouil Vasilomanolakis

Publikation: Bidrag til bog/antologi/rapport/konference proceedingKonferenceartikel i proceedingForskningpeer review

3 Citationer (Scopus)

Abstract

With the continuous rise in the numbers and sophistication of cyber-attacks, defenders are moving towards more proactive lines of defense. Deception methods such as honeypots and moving target defense paradigms, are nowadays utilized in a multitude of ways. A honeytoken is an umbrella term that describes honeypot-like entities/resources that can be inserted into a network or system. The moment an adversary interacts with a honeytoken, an alert is raised. Similar to honeypots, the value of honeytokens lies in their indistinguishability; if an attacker can detect them, e.g. via a fingerprinting tool, they can easily evade them. In this paper, we propose and discuss honeytoken fingerprinting methods. To the best of our knowledge, this is the first paper to examine honeytoken-specific fingerprinting. Furthermore, we showcase a proof of concept that is able to successfully detect a number of honeytoken types.

OriginalsprogEngelsk
TitelInternational Conference on Security of Information and Networks (ACM SIN)
RedaktørerBerna Ors, Atilla Elci
Antal sider5
ForlagAssociation for Computing Machinery
Publikationsdato2020
Sider1-5
Artikelnummer28
ISBN (Elektronisk)978-1-4503-8751-4
DOI
StatusUdgivet - 2020
BegivenhedSIN 2020: 13th International Conference on Security of Information and Networks - Istanbul, Tyrkiet
Varighed: 4 nov. 20206 nov. 2020

Konference

KonferenceSIN 2020: 13th International Conference on Security of Information and Networks
Land/OmrådeTyrkiet
ByIstanbul
Periode04/11/202006/11/2020

Fingeraftryk

Dyk ned i forskningsemnerne om 'Towards systematic honeytoken fingerprinting'. Sammen danner de et unikt fingeraftryk.

Citationsformater