Javascript must be enabled to continue!
Analysis of Cyber Attacks Using Honeypot
View through CrossRef
In the cybersecurity world, the concept of a honeypot is generally referred to as trap systems that have real system behaviors, intentionally leave a security gap, and aim to collect information about cybercriminals who want to access them. It is a computer system that sets itself as a target to attract cyberattacks like bait. It is used to imitate a target such as cyberattackers and to learn about attack attempts, ways of working, or to distract them from other targets. In this study, a VoIP-based honeypot was used to determine the profiles of cyberattacks and attackers. A network environment was created using a low-interaction honeypot to analyze the behavior of cyberattackers and identify the services frequently preferred by these individuals. The honeypot in the network environment was monitored for a period of 90 days. 105,308 events were collected regarding protocols such as Telnet, SIP, SSH, SMB, and HTTP. There was no complex malware attack on the observed system. The service that was most attacked was determined to be Telnet. It was determined that many attacks occurred from the same IP address, indicating that automatic scanning tools were used. According to the results obtained, the proposed method performed a detailed analysis of the services from which cyberattacks came and the behaviors of the people who carried out these attacks. In addition, the highest level of understanding of user interaction was achieved thanks to the VoIP-based honeypot.
Black Sea Journal of Engineering and Science
Title: Analysis of Cyber Attacks Using Honeypot
Description:
In the cybersecurity world, the concept of a honeypot is generally referred to as trap systems that have real system behaviors, intentionally leave a security gap, and aim to collect information about cybercriminals who want to access them.
It is a computer system that sets itself as a target to attract cyberattacks like bait.
It is used to imitate a target such as cyberattackers and to learn about attack attempts, ways of working, or to distract them from other targets.
In this study, a VoIP-based honeypot was used to determine the profiles of cyberattacks and attackers.
A network environment was created using a low-interaction honeypot to analyze the behavior of cyberattackers and identify the services frequently preferred by these individuals.
The honeypot in the network environment was monitored for a period of 90 days.
105,308 events were collected regarding protocols such as Telnet, SIP, SSH, SMB, and HTTP.
There was no complex malware attack on the observed system.
The service that was most attacked was determined to be Telnet.
It was determined that many attacks occurred from the same IP address, indicating that automatic scanning tools were used.
According to the results obtained, the proposed method performed a detailed analysis of the services from which cyberattacks came and the behaviors of the people who carried out these attacks.
In addition, the highest level of understanding of user interaction was achieved thanks to the VoIP-based honeypot.
Related Results
Deception-Based Security Framework for IoT: An Empirical Study
Deception-Based Security Framework for IoT: An Empirical Study
<p><b>A large number of Internet of Things (IoT) devices in use has provided a vast attack surface. The security in IoT devices is a significant challenge considering c...
Cyber Operations and the Threshold for Cyber Warfare: Ethical and Anticipated Ethical Issues
Cyber Operations and the Threshold for Cyber Warfare: Ethical and Anticipated Ethical Issues
Determining whether a cyber operation meets the threshold for being designated cyber warfare involves ethical, technical, and strategic criteria. These are primarily derived from i...
Honeypot in the Cyber Space
Honeypot in the Cyber Space
In today’s world a large number of devices are connected to the network, which indicates that there could exist more access nodes than before from where an intruder can try to atta...
Comprehensive Analysis of Cyber-Manufacturing Attacks Using a Cyber-Manufacturing Testbed
Comprehensive Analysis of Cyber-Manufacturing Attacks Using a Cyber-Manufacturing Testbed
Abstract
Cyber-Manufacturing Systems (CMS) are vulnerable to cyber-manufacturing attacks ironically because of its very beneficial advance: seamless integration with...
Implementasi Ansible pada Otomasi Honeypot Deployment Berbasis Web
Implementasi Ansible pada Otomasi Honeypot Deployment Berbasis Web
Dalam era digital yang semakin kompleks ini, keamanan sistem informasi menjadi masalah penting bagi organisasi di berbagai industri. Peningkatan serangan siber serta polanya yang s...
Cyber Resilience Implications for the Financial System
Cyber Resilience Implications for the Financial System
In August of 2008, cyber-attacks began to affect the Georgian public and private sectors. The cyber-attacks coincided with the Russian Invasion of Georgia, which is also known as t...
An Empirical Study on Cyber Crimes Against Women and Children in India
An Empirical Study on Cyber Crimes Against Women and Children in India
The aim of the study is to understand the Cyber-crimes against women and Children in India for a period of five years from 2017 to 2021. The study is based on Secondary data collec...
Localisation of Attacks, Combating Browser-Based Geo-Information and IP Tracking Attacks
Localisation of Attacks, Combating Browser-Based Geo-Information and IP Tracking Attacks
<p>Accessing and retrieving users’ browser and network information is a common practice used by advertisers and many online services to deliver targeted ads and explicit impr...

