Developing a modular, high-interaction honeypot using container virtualization

Detta är en Kandidat-uppsats från Göteborgs universitet/Institutionen för data- och informationsteknik

Sammanfattning: A significant increase of attacks combined with companies neglecting cybersecurity posesa problem for the ever-growing number of Internet-connected devices. With honeypottechnology being an invaluable tool for understanding adversaries’ strategies, this projectaims to develop a modular honeypot that is able to evolve. The report focuses on thehoneypot’s design and implementation. Results from deploying the honeypot are usedto evaluate its properties and present a brief analysis of the information collected. Toachieve a modular design, the honeypot is divided into three network-connected components. Container virtualization is utilized to allow easy deployment, imitating systemsthat adversaries interact with, and isolating performed actions. The result of the projectis an easily deployable and distributable high-interaction research honeypot using container virtualization with support for the Secure Shell network protocol. The findings ofthe report indicate that the developed honeypot functions well and may support researchwithin the field of computer security. However, there is room for deeper analysis of collected data to determine whether the honeypot’s data collection capabilities are enoughto draw valuable conclusions.

  HÄR KAN DU HÄMTA UPPSATSEN I FULLTEXT. (följ länken till nästa sida)