Io IoT Ho T Hone neyBot yBot
Haris Šemić and Saša Mrdović
Cryptacus: Workshop and MC meeting Nijmegen, Netherlands, 2017
Io IoT Ho T Hone neyBot yBot Haris emi and Saa Mrdovi - - PowerPoint PPT Presentation
Io IoT Ho T Hone neyBot yBot Haris emi and Saa Mrdovi Cryptacus: Workshop and MC meeting Nijmegen, Netherlands, 2017 Honeypots Honeypots Emulation of a network resource Built to be discovered, attacked and compromised
Cryptacus: Workshop and MC meeting Nijmegen, Netherlands, 2017
IoT HoneyBot
Emulation of a network resource Built to be discovered, attacked and compromised Data collection with goal to:
IoT HoneyBot
Billions of special-purpose devices connected to
Automatization of all aspects of modern life Remote control of IoT devices using distant
30+ billion IoT devices expected by year 2020
IoT HoneyBot
Client-server botnets
Peer to peer botnets
IoT HoneyBot
IoT HoneyBot
Manual component
Mirai component
IoT HoneyBot
IoT HoneyBot
IoT HoneyBot
Mass-deployment of IoT honeypots Malware research Anti-botnet Propagation observation Employment of machine learning to handle new
Encrypted communication
IoT HoneyBot
IoT HoneyBot
Implemented using Node.js Interacts with malicious traffic and supports:
Interaction with central server includes:
IoT HoneyBot Stores and reports captured data:
Contains:
Implements machine learning to handle new types of
Threaded implementation
IoT HoneyBot
IoT HoneyBot
IoT HoneyBot
Hundreds (thousands!) of honeypot nodes present
IoT HoneyBot
IoT HoneyBot
A single central server with static IP address and
Some resilience techniques from existing botnets
IoT HoneyBot