Honey Infiltrator: Injecting Honeytoken Using Netfilter

Daniel Reti, Tillmann Angeli, H. Schotten
{"title":"Honey Infiltrator: Injecting Honeytoken Using Netfilter","authors":"Daniel Reti, Tillmann Angeli, H. Schotten","doi":"10.1109/EuroSPW59978.2023.00057","DOIUrl":null,"url":null,"abstract":"Deception based cyber security is already well-established in form of honeypots, honeytoken and moving target defense. With these techniques, attacks can be detected, slowed down or prevented. Many techniques to deploy such deception measures have been researched. In this paper, a novel technique is proposed, where honeytoken are deployed in application traffic through a layer 2 network bridge. This way its functions similarly to a reverse-proxy, but is ’invisible’ in the sense that it does not need its own network address. This makes the installation and integration easier, and does not require any alteration of existing systems in the network. This functionality is made possible by the use of various modifications to the iptables firewall on the network bridge and libnetfilter queue and Scapy for capturing packets and passing them to the user space for processing. In this work a proof of concept implementation for injecting decoy web pages into TCP traffic is presented. Thereby it is shown that both simple and complex modifications or inventions of TCP packets on the network bridge are possible. Existing packets can be modified, for example by adding a HTML comment to the response of a requested HTML webpage, and decoy HTML pages can be created.","PeriodicalId":220415,"journal":{"name":"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","volume":"18 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/EuroSPW59978.2023.00057","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Deception based cyber security is already well-established in form of honeypots, honeytoken and moving target defense. With these techniques, attacks can be detected, slowed down or prevented. Many techniques to deploy such deception measures have been researched. In this paper, a novel technique is proposed, where honeytoken are deployed in application traffic through a layer 2 network bridge. This way its functions similarly to a reverse-proxy, but is ’invisible’ in the sense that it does not need its own network address. This makes the installation and integration easier, and does not require any alteration of existing systems in the network. This functionality is made possible by the use of various modifications to the iptables firewall on the network bridge and libnetfilter queue and Scapy for capturing packets and passing them to the user space for processing. In this work a proof of concept implementation for injecting decoy web pages into TCP traffic is presented. Thereby it is shown that both simple and complex modifications or inventions of TCP packets on the network bridge are possible. Existing packets can be modified, for example by adding a HTML comment to the response of a requested HTML webpage, and decoy HTML pages can be created.
蜂蜜渗透者:使用Netfilter注入蜂蜜令牌
基于欺骗的网络安全已经以蜜罐、蜜令牌和移动目标防御的形式建立起来。利用这些技术,可以检测、减缓或阻止攻击。已经研究了许多部署这种欺骗措施的技术。本文提出了一种通过第二层网桥在应用流量中部署蜜令牌的新技术。这样,它的功能类似于反向代理,但它是“不可见的”,因为它不需要自己的网络地址。这使得安装和集成更容易,并且不需要对网络中的现有系统进行任何更改。通过对网桥上的iptables防火墙和libnetfilter队列以及Scapy进行各种修改,可以捕获数据包并将其传递到用户空间进行处理,从而实现此功能。在这项工作中,提出了在TCP流量中注入诱饵网页的概念验证实现。由此表明,在网桥上对TCP数据包进行简单和复杂的修改或发明都是可能的。可以修改现有的数据包,例如,通过向请求的HTML网页的响应添加HTML注释,并且可以创建诱饵HTML页面。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信