Published January 1, 2014 | Version v1
Conference paper Open

An Automated Bot Detection System through Honeypots for Large-Scale

  • 1. Sci & Technol Res Council Turkey, Cyber Secur Inst, Ankara, Turkey
  • 2. TOBB Univ Econ & Technol, Comp Engn, Ankara, Turkey

Description

One of the purposes of active cyber defense systems is identifying infected machines in enterprise networks that are presumably root cause and main agent of various cyber-attacks. To achieve this, researchers have suggested many detection systems that rely on host-monitoring techniques and require deep packet inspection or which are trained by malware samples by applying machine learning and clustering techniques. To our knowledge, most approaches are either lack of being deployed easily to real enterprise networks, because of practicability of their training system which is supposed to be trained by malware samples or dependent to host-based or deep packet inspection analysis which requires a big amount of storage capacity for an enterprise. Beside this, honeypot systems are mostly used to collect malware samples for analysis purposes and identify coining attacks.

Files

bib-2efe4ff9-bbdb-4603-bc01-d66184d50b11.txt

Files (196 Bytes)

Name Size Download all
md5:4c2704288166d1bd11b055c2ca310a81
196 Bytes Preview Download