The honeytank: a scalable approach to collect malicious Internet traffic

Vanderavero, Nicolas;Brouckaert, Xavier;Bonaventure, Olivier;Le Charlier, Baudouin
(2008) International Journal of Critical Infrastructures — Vol. 4, n° 1-2, p. 185-205 (2008)

Files

No attached file found for this publication.

Details

Authors
  • Vanderavero, Nicolas
    Author
  • Brouckaert, Xavier
    Author
  • Author
  • Le Charlier, BaudouinUCLouvain
    Author
Abstract
In this paper, we propose an efficient method for collecting large amounts of malicious Internet traffic. The key advantage of our method is that it does not need to maintain any state to emulate TCP services running on a large number of emulated end-systems. We implemented a prototype on the ASAX intrusion detection system and we provide several examples of the malicious activities that were collected on a campus network attached to the internet. We explain how we implemented various protocols in a stateless way. We also discuss how our method can be improved to make an accurate but still stateless emulation of stateful protocols.
Affiliations

Citations

Vanderavero, N., Brouckaert, X., Bonaventure, O., & Le Charlier, B. (2008). The honeytank: a scalable approach to collect malicious Internet traffic. International Journal of Critical Infrastructures, 4(1-2), 185-205. https://doi.org/10.1504/IJCIS.2008.016100 (Original work published 2008)