Beta
125560

WORM DETECTION USING HONEYPOTS FOR WINDOWS ENVIRONMENT

Article

Last updated: 26 Dec 2024

Subjects

-

Tags

Electrical Engineering, Computer Engineering and Electrical power and machines engineering.

Abstract

Recent cybersecurity incidents suggest that internet worms can spread so fast that in-time human-mediated reaction is not possible, and therefore initial response to cyberattacks has to be automated. In this paper we present a system for detecting known and unknown worms using honeypots. The proposed system detects worms by monitoring connection activity and watching for patterns of traffic that are expressions of some of the essential characteristics of worm behavior. The implementation is a signature-based detection as a first tier and an anomaly-based as a second tier in the detection process. At a network's gateway, the proposed system runs a vantage point from which all traffic into and out of the network is visible. The system employs a honeypot to capture traffic, after discarding whitelisted patterns; as it automatically generates worm signatures which are matched with the signatures of the known worms stored in original database. When a signature is matched, the system reports it by issuing an alert that also includes the IP addresses involved in the transaction. Otherwise, the system monitors the changes in the performance of CPU, RAM and changes in files in the gateway which are considered as indicators to the presence of worms. The proposed system was evaluated using a dataset collected from internet for several days, and potentially showed good results for detecting and collecting information about worms from local network. It was noticed that the performance was increased up to 23% more than other systems that uses honeypots.

DOI

10.21608/jesaun.2010.125560

Keywords

honeypot, Worm, Network Security

Authors

First Name

Mansour Ali H

Last Name

Alqubati

MiddleName

-

Affiliation

Student from Yemen NIAS

Email

-

City

-

Orcid

-

First Name

Yousef B

Last Name

Mahdy

MiddleName

-

Affiliation

Vice Dean of Faculty of Computers & Information

Email

-

City

-

Orcid

-

First Name

Hosny M.

Last Name

Ibrahim

MiddleName

-

Affiliation

Dean of Faculty of Computers & Information

Email

-

City

-

Orcid

-

Volume

38

Article Issue

No 4

Related Issue

16876

Issue Date

2010-07-01

Receive Date

2010-06-09

Publish Date

2010-07-01

Page Start

1,013

Page End

1,025

Print ISSN

1687-0530

Online ISSN

2356-8550

Link

https://jesaun.journals.ekb.eg/article_125560.html

Detail API

https://jesaun.journals.ekb.eg/service?article_code=125560

Order

10

Type

Research Paper

Type Code

1,438

Publication Type

Journal

Publication Title

JES. Journal of Engineering Sciences

Publication Link

https://jesaun.journals.ekb.eg/

MainTitle

WORM DETECTION USING HONEYPOTS FOR WINDOWS ENVIRONMENT

Details

Type

Article

Created At

23 Jan 2023