HoneyCloud: Elastic Honeypots - On-attack Provisioning of High-interaction Honeypots

Patrice Clemente, Jean-Francois Lalande, Jonathan Rouzaud-Cornabas

2012

Abstract

This paper presents HoneyCloud: a large-scale high-interaction honeypots architecture based on a cloud infrastructure. The paper shows how to setup and deploy on-demand virtualized honeypot hosts on a private cloud. Each attacker is elastically assigned to a new virtual honeypot instance. HoneyCloud offers a high scalability. With a small number of public IP addresses, HoneyCloud can multiplex thousands of attackers. The attacker can perform malicious activities on the honeypot and launch new attacks from the compromised host. The HoneyCloud architecture is designed to collect operating system logs about attacks, from various IDS, tools and sensors. Each virtual honeypot instance includes network and especially system sensors that gather more useful information than traditional network oriented honeypots. The paper shows how are collected the activities of attackers into the cloud storage mechanism for further forensics. HoneyCloud also addresses efficient attacker’s session storage, long term session management, isolation between attackers and fidelity of hosts.

Download


Paper Citation


in Harvard Style

Clemente P., Lalande J. and Rouzaud-Cornabas J. (2012). HoneyCloud: Elastic Honeypots - On-attack Provisioning of High-interaction Honeypots . In Proceedings of the International Conference on Security and Cryptography - Volume 1: SECRYPT, (ICETE 2012) ISBN 978-989-8565-24-2, pages 434-439. DOI: 10.5220/0004129604340439

in Bibtex Style

@conference{secrypt12,
author={Patrice Clemente and Jean-Francois Lalande and Jonathan Rouzaud-Cornabas},
title={HoneyCloud: Elastic Honeypots - On-attack Provisioning of High-interaction Honeypots},
booktitle={Proceedings of the International Conference on Security and Cryptography - Volume 1: SECRYPT, (ICETE 2012)},
year={2012},
pages={434-439},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0004129604340439},
isbn={978-989-8565-24-2},
}


in EndNote Style

TY - CONF
JO - Proceedings of the International Conference on Security and Cryptography - Volume 1: SECRYPT, (ICETE 2012)
TI - HoneyCloud: Elastic Honeypots - On-attack Provisioning of High-interaction Honeypots
SN - 978-989-8565-24-2
AU - Clemente P.
AU - Lalande J.
AU - Rouzaud-Cornabas J.
PY - 2012
SP - 434
EP - 439
DO - 10.5220/0004129604340439