Honeyv: A Virtualized Honeynet System Based On Network Softwarization

NOMS 2018 - 2018 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM(2018)

引用 3|浏览0
暂无评分
摘要
Intrusion detection in modern enterprise networks faces challenges due to the increasing large volume of data and insufficient training data for anomaly detections. In this work, we propose a novel network topology for improved intrusion detection through multi-phase data monitoring system. Rather than the all-or-nothing approach to terminate all sessions identified as suspicious, the topology route traffic to different servers replicas with different monitoring intensity level based on their likelihood of attacks. This topology leverages recent advances in software-defined networking (SDN) to dynamically route such sessions into risk-appropriate computing environments. These environments offer enhanced training opportunities intrusion detection systems (IDSes) by exposing data streams that would not have been observable had the session merely been terminated at the first sign of maliciousness. They also afford defenders finer-grained risk management by supporting a continuum of endpoint environments, ranging from fully trusted, to semi-trusted, to fully untrusted, for example.
更多
查看译文
关键词
HoneyV,virtualized honeynet system,network softwarization,anomaly detections,multiphase data monitoring system,topology route traffic,software-defined networking,risk-appropriate computing environments,enhanced training opportunities intrusion detection systems,enterprise networks,network topology,intrusion detection system,data streaming,intensity level monitoring,SDN,IDSe,risk management
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要