蜜罐
僵尸网络
恶意软件
计算机安全
计算机科学
服务器
互联网
入侵检测系统
加密
入侵
网络安全
特洛伊木马
恶意软件分析
计算机网络
操作系统
地球化学
地质学
作者
Mandy Knöchel,Sandro Wefel
标识
DOI:10.1109/apcc55198.2022.9943718
摘要
Attackers and malware are a major threat to the growing number of servers and devices on the internet. Therefore, it is essential to study characteristics of malicious activities which can be used to aid future security mechanisms in finding and preventing these threats. Honeypots are a powerful tool to get insight into current attack techniques, malware and botnets. In this paper, we present our findings from observing the behaviour of attackers on a high-interaction Linux honeypot. We focused on attacks targeting the SSH service and analysed all steps of the intrusions, starting from the initial dictionary attack and leading to the final intrusion executing commands or malware on the honeypot. Further, we present our approach on how to decrypt and analyse the encrypted network traffic.
科研通智能强力驱动
Strongly Powered by AbleSci AI