Investigating the attack process followed by automated scripts, tools or botnets and their threat actors is a widely researched area in the cyber security. There has also been emphasis on differentiating attacks performed by humans considering their adaptability which poses a greater threat. Limited number of features such as slower typing speed and typing mistakes in commands issued by human attackers on the compromised systems have been used to detect their presence. This paper presents a study of human attackers by deploying 15 honeypots in five locations worldwide, collecting and analysing attack data for two months. We propose a comprehensive feature set based on characteristics and patterns of issued commands and the usage of alphanumeric, modifiers, cursor and other keys in the attack process. We used these features to distinguish human attackers interacting with honeypots. Moreover, five case studies are discussed to provide insights into actions performed in the attack process. The results show various actions performed by human attackers ranging from executing basic commands for getting device information to more advanced actions such as downloading files, running scripts and removing traces of their activities.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Feature Identification and Study of Attackers’ Behaviours Using Honeypots

  • Junaid Haseeb,
  • Masood Mansoori,
  • Ian Welch

摘要

Investigating the attack process followed by automated scripts, tools or botnets and their threat actors is a widely researched area in the cyber security. There has also been emphasis on differentiating attacks performed by humans considering their adaptability which poses a greater threat. Limited number of features such as slower typing speed and typing mistakes in commands issued by human attackers on the compromised systems have been used to detect their presence. This paper presents a study of human attackers by deploying 15 honeypots in five locations worldwide, collecting and analysing attack data for two months. We propose a comprehensive feature set based on characteristics and patterns of issued commands and the usage of alphanumeric, modifiers, cursor and other keys in the attack process. We used these features to distinguish human attackers interacting with honeypots. Moreover, five case studies are discussed to provide insights into actions performed in the attack process. The results show various actions performed by human attackers ranging from executing basic commands for getting device information to more advanced actions such as downloading files, running scripts and removing traces of their activities.