IEEE Internet of Things Journal · 2019 · 81 citations · 21 references
EngineeringInformation SecurityCapturing Iot AttacksIot CommunicationIot ProtocolIot SecurityIot SystemMultiport HoneypotsMultiport HoneypotDenial-of-service AttackHoneynet SystemInternet Of ThingsNetwork SecurityDefense SystemsNetworked Computer SystemsComputer ScienceData SecurityHoneypot RespondIot Honeynet
Internet of Things (IoT) devices are vulnerable against attacks because of their limited network resources and complex operating systems. Thus, a honeypot is a good method of capturing malicious requests and collecting malicious samples but is rarely used on the IoT. Accordingly, this article implements three kinds of honeypots to capture malicious behaviors. First, on the basis of the CVE-2017–17215 vulnerability, we implement a medium-high interaction honeypot that can simulate a specific series of router UPnP services. It has functions, such as service simulation, log recording, malicious sample download, and service self-check. Second, given the limited details available for the simulated UPnP service and to help the honeypot respond to unrecognizable malicious requests, we use the actual IoT device firmware that matches the vulnerability to build a high-interaction honeypot. In addition, we investigate the most exposed SOAP service ports and design corresponding multiport honeypot to improve the capacity of the honeynet, providing a hybrid service from a real device and simulating honeypots. The Docker in the honeynet, which reduces the volume of the honeypot and realizes the rapid deployment of the honeynet, encapsulates all these honeypots. Moreover, the honeynet control center is simultaneously designed to distribute commands and transfer files to each physical node in the honeynet. We implemented the proposed honeynet system and deployed it in practice. We have successfully caught many unknown malicious attacks excluded in the VT, which proved the effectiveness of the proposed framework.
21
Niels Provos · Deep Blue (University of Michigan) · 2004 · 609 citations · Full text
A Large-Scale Analysis of the Security of Embedded Firmwares
Andrei Costin, Jonas Zaddach, Aurélien Francillon et al. · 2014 · 311 citations
Can We Beat DDoS Attacks in Clouds?
Shui Yu, Yonghong Tian, Song Guo et al. · IEEE Transactions on Parallel and Distributed Systems · 2013 · 253 citations
IoTPOT: A Novel Honeypot for Revealing Current IoT Threats
Yin Minn Pa Pa, Shogo Suzuki, Katsunari Yoshioka et al. · Journal of Information Processing · 2016 · 225 citations · Full text