Deception Using an SSH Honeypot

Abstract

The number of devices vulnerable to unauthorized cyber access has been increasing at an alarming rate. A honeypot can deceive attackers trying to gain unauthorized access to a system; studying their interactions with vulnerable networks helps better understand their tactics. We connected an SSH honeypot responding to secure-shell commands to the Naval Postgraduate School network, bypassing the firewall. During four phases of testing, we altered the login credential database and observed the effects on attackers using the honeypot. We used different deception techniques during each phase to encourage more interaction with the honeypot. Results showed that different attackers performed different activities on the honeypot. These activities differed in total login attempts, file downloads, and commands used to interact with the honeypot. Attackers also performed TCP/IP requests from our honeypot to direct traffic to other locations. The results from this experiment confirm that testing newer and updated tools, such as honeypots, can be extremely beneficial to the security community by helping to prevent attackers from quickly identifying a network environment.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Sep 01, 2017
Accession Number
AD1046884

Entities

People

  • Ryan J. Mccaughey

Organizations

  • Naval Postgraduate School

Tags

Communities of Interest

  • Cyber
  • Energy and Power Technologies
  • Materials and Manufacturing Processes

DTIC Thesaurus Topics

  • Application Protocols
  • Computer Programs
  • Countermeasures
  • Cybersecurity
  • Data Analysis
  • Databases
  • Deception
  • Detectors
  • Environment
  • Internet Of Things
  • Network Protocols
  • Operating Systems
  • Security
  • Shell Scripts
  • United States
  • Virtual Machines
  • Virtual Reality

Fields of Study

  • Computer science

Readers

  • Computer Networking
  • Irregular Warfare and Special Operations Cyberspace Operations against Adversarial Threats.
  • Nuclear Non-Proliferation and International Security

Technology Areas

  • Cyber