A novel SDN based stealthy TCP connection handover mechanism for hybrid honeypot systems

Wenjun Fan, David Fernandez

Research output: Chapter in Book or Report/Conference proceedingConference Proceedingpeer-review

24 Citations (Scopus)

Abstract

Honeypots have been largely used to capture and investigate malicious behavior through deliberately sacrificing their own resources in order to be attacked. Hybrid honeypot architectures consisting of frontends and backends are widely used in the research area, specially due to the benefits of their high scalability and fidelity for detailed attacking data collection. A hybrid honeypot system often needs a facility aimed to tightly control the network traffic, for purposes such as redirecting the traffic from the frontends to the backends for in-depth attack analysis. However, the current traffic redirection approaches, particularly the TCP connection handover mechanisms, are not stealthy and they can be easily detected by attackers. This paper proposes an SDN based network data controller for hybrid honeypot systems that uses a transparent TCP connection handover mechanism and provides a traffic filtering approach based on the Snort alert functionality. The controller is implemented as an application based on the open-source Ryu SDN framework. It allows the users to configure their own network data control rules, which based on the Snort alert messages will forward or redirect the traffic to the corresponding honeypots. The experiments validate the proposed mechanism and the testing results show that the controller can efficiently perform the stealthy TCP connection handover as well.

Original languageEnglish
Title of host publication2017 IEEE Conference on Network Softwarization
Subtitle of host publicationSoftwarization Sustaining a Hyper-Connected World: en Route to 5G, NetSoft 2017
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages1-9
Number of pages9
ISBN (Electronic)9781509060085
DOIs
Publication statusPublished - 2017
Externally publishedYes
Event2017 IEEE Conference on Network Softwarization, NetSoft 2017 - Bologna, Italy
Duration: 3 Jul 20177 Jul 2017

Publication series

Name2017 IEEE Conference on Network Softwarization: Softwarization Sustaining a Hyper-Connected World: en Route to 5G, NetSoft 2017

Conference

Conference2017 IEEE Conference on Network Softwarization, NetSoft 2017
Country/TerritoryItaly
CityBologna
Period3/07/177/07/17

Keywords

  • Cyber Security
  • Honeypots
  • Intrusion Detection
  • SDN
  • Traffic Redirection
  • Virtualization

Fingerprint

Dive into the research topics of 'A novel SDN based stealthy TCP connection handover mechanism for hybrid honeypot systems'. Together they form a unique fingerprint.

Cite this