Skip to main navigation Skip to search Skip to main content

Detecting malicious web servers with honeyclients

  • School of Computer Science and Technology, Harbin Institute of Technology

Research output: Contribution to journalArticlepeer-review

Abstract

Using malicious sites to launch attacks against client user applications is a growing threat in recent years. This led to emergence of new technologies to counter and detect attacks against end user. One of these technologies is honeyclient (aka client honeypot). Honeyclients crawl the Internet to find and identify web servers that exploit clientside vulnerabilities. In this paper, we address honeyclients by studying and analyzing low-interaction and highinteraction honeyclients. We introduce a comparison attributes to evaluate honeyclients by comparing between the two types. Moreover, we present techniques can be used by malicious websites to evade and fingerprint honeyclients, and we make recommendations to overcome these evasion techniques. By analyzing characteristics of honeyclients, we introduce factors to define and measure honeyclients effectiveness.

Original languageEnglish
Pages (from-to)145-152
Number of pages8
JournalJournal of Networks
Volume6
Issue number1
DOIs
StatePublished - 2011
Externally publishedYes

Keywords

  • 0-day Attack
  • Client-side attacks
  • Crawler
  • Honeyclient
  • Malicious website

Fingerprint

Dive into the research topics of 'Detecting malicious web servers with honeyclients'. Together they form a unique fingerprint.

Cite this