White Papers

Roaming Honeypots for Mitigating Service-Level Denial-of-Service Attacks

Category: Security

Tags: server

Overview Honeypots have been proposed to act as traps for malicious attackers. However, because of their deployment at fixed (thus detectable) locations and on machines other than the ones they are supposed to protect, honeypots can be avoided by sophisticated attacks. The paper proposes roaming honeypots, a mechanism that allows the locations of honeypots to be unpredictable, continuously changing, and disguised within a server pool. A (continuously changing) subset of the servers is active and providing service, while the rest of the server pool is idle and acting as honeypots. The paper utilizes the roaming honeypots scheme to mitigate the effects of service-level DoS attacks, in which many attack machines acquire service from a victim server at a high rate, against back-end servers of private services.

Download White Paper

By downloading you agree to our Terms and Conditions. These include information regarding use of your personal data.

Publisher
University of Pittsburgh
File Format
PDF
Date Published
Oct 14, 2008
Format
White Papers
Topics
Denial of Service, Network Security, Security Management

Similiar White Papers

X-Force®Threat Insight Quarterly Voice over Internet Protocol (VoIP) ? Find out what the threats and challenges are for anyone deploying VoIP

X-Force®Threat Insight Quarterly Voice over Internet Protocol (VoIP) ? Find out what the threats and challenges are for anyone deploying VoIP

The X-Force Threat Insight Quarterly (Threat IQ) highlights the most significant threats and challenges facing security

Publisher: Internet Security Systems  |  Tags: homeland security, security flaws, voip

An independent report by ICSA Labs on the performance of ISS' VoIP-enabled Intrusion Prevention devices

An independent report by ICSA Labs on the performance of ISS' VoIP-enabled Intrusion Prevention devices

This technical product evaluation is focused on the ISS VoIP-enabled Intrusion Prevention devices. These are built to su

Publisher: Internet Security Systems  |  Tags: voip

Cisco - Strategies to Protect Against Distributed Denial of Service (DDoS) Attacks

Cisco - Strategies to Protect Against Distributed Denial of Service (DDoS) Attacks

In order to facilitate Distributed Denial of Service (DDoS), the attackers need to have several hundred to several thous

Publisher: Cisco Systems  |  Tags: ddos, linux

Jargon, jargon, jargon. Find out what the IT industries acronyms really mean

Jargon, jargon, jargon. Find out what the IT industries acronyms really mean

ISS provide you with a simple glossary of major VoIP terms. What do they really mean, when can they be used? Make yourse

Publisher: Internet Security Systems  |  Tags: voip

IT's New Role: Defining and Managing Risk

IT's New Role: Defining and Managing Risk

This article explores how a Security Risk Management (SRM) approach can protect your company from the most severe threat

Publisher: McAfee  |  Tags: srm

University of Pittsburgh White Papers

Automatic VPN Client Recovery From IPsec Pass-Through Failures

Automatic VPN Client Recovery From IPsec Pass-Through Failures

Network Address Translation (NAT) is often used in routers that connect home and small-office networks to the Internet.

Publisher: University of Pittsburgh  |  Tags: routers, vpn

BLAM: An Energy-Aware MAC Layer Enhancement for Wireless Adhoc Networks

BLAM: An Energy-Aware MAC Layer Enhancement for Wireless Adhoc Networks

In wireless adhoc networks channel and energy capacities are scarce resources. However, the design of the IEEE 802.11 DC

Publisher: University of Pittsburgh  |  Tags: data, network

Next Generation Wireless LAN System Design

Next Generation Wireless LAN System Design

An important issue in the widespread deployment of infrastructure based Wireless Local Area Networks (WLANs) is the netw

Publisher: University of Pittsburgh  |  Tags: data, infrastructure, network

PeerNet: A Peer-to-Peer Framework for Large-Scale Service and Application Deployment in MANETs

PeerNet: A Peer-to-Peer Framework for Large-Scale Service and Application Deployment in MANETs

Ad-hoc networks are an emerging technology with enormous potential. Providing support for large-scale service and applic

Publisher: University of Pittsburgh  |  Tags: applications, infrastructure, unified

Collaborative Example Authoring System: The Value of Re-Annotation Based on Community Feedback

Collaborative Example Authoring System: The Value of Re-Annotation Based on Community Feedback

Learning from examples is a common and powerful approach when mastering the art of programming. In the classroom studies

Publisher: University of Pittsburgh