پدافند الکترونیکی و سایبری

پدافند الکترونیکی و سایبری

دالون: دفاع فرافعال سایبری با چارچوب تله سایبری هجومی

نوع مقاله : مقاله پژوهشی

نویسندگان
1 دانشجوی دکتری، دانشگاه جامع امام حسین (ع)، تهران،ایران
2 استادیار، دانشگاه جامع امام حسین (ع)، تهران، ایران
چکیده
امروزه شناسایی، تعقیب و اقدام بازدارنده علیه مهاجمین سایبری، یکی از چالش‌های اصلی در حوزه امنیت و دفاع سایبری است. سازوکار‌های سنتی تشخیص حملات به دلیل رویکرد واکنشی به مسئله دفاع و نرخ بالای هشدارهای مثبت نادرست، فرایند تشخیص را پیچیده کرده است. روش‌های متعددی برای حل این چالش ارائه شده است و استفاده از تله‌های سایبری، یکی از روش‌های مؤثری است که در تشخیص هدفمند و پیش از موعد تهدیدات درحال‌توسعه و بهره‌برداری است. راهکارهای موجود تله‌های سایبری به دلیل ساختار منفعلانه و یک‌طرفه عمل نمودن، منجر به بازدارندگی و شناسایی منشأ وقوع حمله نمی‌گردند. در این مقاله، یک چارچوب توسعه‌یافته شبکه تله ترکیبی به نام دالون پیشنهاد می‌شود. دالون از طریق بخش «تله وب انفجاری»، قابلیت ضد حمله و نفوذ معکوس علیه مهاجمین به‌دام‌افتاده را فراهم می‌کند و ضمن شناسایی و تعقیب مهاجم، امکان اقدام تنبیهی که منجر به بازدارندگی سایبری می‌شود را فراهم می‌کند. دالون با طراحی تله وب جعلی و شبیه‌سازی HMI سامانه کنترل صنعتی اسکادا و آلوده‌سازی آن به آسیب‌پذیری جعلی و عمدی تزریق کد و چندین آسیب‌پذیری دیگر پیاده‌سازی شده است. نتایج آزمایش‌ها نشان می‌دهد که دالون عملکرد موفقی در شناسایی و برخورد با سه مورد از روش‌های تهاجمی دارد و اقدام نفوذ معکوس و «ضد حمله» را با موفقیت انجام داده است. طرح پیشنهادی تله ترکیبی دالون، باقابلیت نفوذ معکوس، منجر به اتخاذ رویکرد دفاع فرا فعال سایبری یعنی دفاع حین حمله می‌شود و علاوه بر کاهش فرایند مثبت غلط در تحلیل حملات، فرایند یک‌طرفه تله‌های سایبری معمول را که صرفاً دفاعی و منفعل هستند، به فرایند دوطرفه که هجومی و بازدارنده هستند، تبدیل می‌کند.
کلیدواژه‌ها
موضوعات

عنوان مقاله English

Dalon: Proactive Cyber Defence with a Counter Attack Honypot Framework

نویسندگان English

morteza kheiry 1
Reza Jalaei 2
1 PhD Student, Imam Hossein (AS) University, Tehran, Iran
2 Assistant Professor, Imam Hossein (AS) University, Tehran, Iran
چکیده English

Today, detecting, tracking, and taking deterrent action against cyber attackers is one of the main challenges in the field of cybersecurity and cyber defense. Traditional attack detection mechanisms, due to their reactive approach to defense and the high rate of false-positive alerts, have complicated the detection process.Various methods have been proposed to address this challenge, and the use of cyber deception traps is one of the effective approaches currently being developed and utilized for targeted and proactive detection of emerging threats. Existing cyber trap solutions, due to their passive structure and one-directional operation, do not lead to deterrence or identification of the origin of the attack. In this article, an enhanced hybrid trap-network framework called Daloon is proposed. Daloon, through its “Explosive Web Trap” component, enables counterattack and reverse intrusion against trapped attackers and, while identifying and tracking the attacker, provides the capability for punitive action that results in cyber deterrence. Daloon is implemented by designing a fake web trap and simulating the HMI of a SCADA industrial control system and contaminating it with a fake and intentionally crafted code-injection vulnerability as well as several other vulnerabilities. Experimental results show that Daloon performs successfully in detecting and responding to three types of offensive techniques and has successfully carried out reverse intrusion and “counterattack.” The proposed Daloon hybrid trap, with reverse-intrusion capability, leads to the adoption of a proactive cyber defense approach—i.e., defense during the attack—and, in addition to reducing false positives in attack analysis, transforms the one-way process of traditional cyber traps, which are purely defensive and passive, into a two-way process that is offensive and deterrent

کلیدواژه‌ها English

Honeypot
Honeynet
Cyber Trap
Reverse Intrusion
Active Defense
Cyber Deception
ProActive cyber Defense
Counterattack
HackBack
1].   Kott, A., Intelligent autonomous agents are key to cyber defense of the future army networks. The Cyber Defense Review, 2018. 3(3): p. 57-70.
[2].  Fan, W., et al., Enabling an anatomic view to investigate honeypot systems: A survey. IEEE Systems Journal, 2017. 12(4): p. 3906-3919.
[3].  Dewar, R.S., Active cyber defense. CSS Cyberdefense Trend Analyses, 2017. 1.
[4].  Company, r.c. Overview of Distributed Deception Platforms (DDP) 2019; Available from: https://en.blog.roi4cio.com/2019/01/overview-of-distributed-deception.html.
[5].  Dewar, R., ‘The “triptych of cyber security”: a classification of active cyber defence.’6th Intl conference on cyber conflict. 2014, NATO CCD COE Publications Tallinn.
[6].  Flowers, A. and S. Zeadally, US policy on active cyber defense. Journal of Homeland Security and Emergency Management, 2014. 11(2): p. 289-308.
[8].  Rehman, Z., et al., Proactive defense mechanism: Enhancing IoT security through diversity-based moving target defense and cyber deception. Computers & Security, 2024. 139: p. 103685.
[9].  DEFENSE, P.C., Active Cyber Defense: Applying Air Defense to the Cyber Domain1. Cyber Analogies, 2014.
[10].David Poarch, D.O.L., Jason Nelson, Anne Grahn, 6 Ways to Deceive Cyber Attackers. 2017.
[11].Almeshekah, M.H. and E.H. Spafford, Cyber security deception, in Cyber deception. 2016, Springer. p. 23-50.
[14].Rowe, N.C. and J. Rrushi, Introduction to Cyberdeception. 2016: Springer.
[15].Couillard, M., J. Lindsay, and J.J. Arquilla, The Role of Deceptive Defense in Cyber Strategy. 2023.
[16].Chinn, R., Botnet Detection: Honeypots and the Internet of Things. Unpublished doctoral dissertation. University of Arizona, 2015.
[17].Chesney, R., Hackback is Back: Assessing the Active Cyber Defense Certainty Act. Lawfare (14 June 2019): https://www. lawfareblog. com/hackback-back-assessing-active-cyber-defense-certainty-act. (21 February 2021, date last accessed), 2019.
[18].Couzigou, I., Hacking-Back by Non-State Actors and the Rule of Law. Heidelberg Journal of International Law, 2020.
[19].Prakash, H.O., Monitoring and Tracking Hackers’ Activities Using Honeynets. 2015. https://electronicsforu.com.
[20].Grudziecki, T., et al., Proactive detection of security incidents. Honeypots. ENISA, 2012.
[21].Soóky, P., Design of new honeypot implementing basic concept of HoneyD honeypot. Masaryk University Faculty of Informatics, Brno, Spring 2017.
[22].Jain, A. and D.B. Buksh, Advance Trends in Network Security with Honeypot and its Comparative Study with other Techniques. International Journal of Engineering Trends and Technology, 2015. 29: p. 304-312.
[23].Almeshekah, M.H., CERIAS Tech Report 2015-11 Using Deception to Enhance Security: A Taxonomy, Model, and Novel Uses. 2015.
[25].Knudsen, M., J. Løvbråten, and A. Dalmo, Deploying a Virtualised High-Interaction Honeynet. 2014.
[26].Sokol, P., P. Pekarčík, and T. Bajtoš, Data collection and data analysis in honeypots and honeynets. Proceedings of the Security and Protection of Information. University of Defence, 2015.
[27].Harikrishnan, V. and G. Kumar, Advanced Persistent Threat Analysis using Splunk. International Journal of Pure and Applied Mathematics, 2018. 118(20): p. 3761-3768.
[28].team, S.  Suricata Open Source IDS / IPS / NSM engine 2019; Available from: https://suricata-ids.org/.
[29].Sanders, C. and J. Smith, Applied network security monitoring: collection, detection, and analysis. 2013: Elsevier.
[30].Wang, B., K. Lu, and P. Chang. Design and implementation of Linux firewall based on the frame of Netfilter/IPtable. in 2016 11th International Conference on Computer Science & Education (ICCSE). 2016. IEEE.
[31].ROBERTSON, W., Using Web Honeypots to Study the Attackers Behavior. 2017, TELECOM ParisTech.
[32].Fan, W., D. Fernández, and Z. Du. Adaptive and flexible virtual honeynet. in International Conference on Mobile, Secure and Programmable Networking. 2015. Springer.
[33].Abbasi, F.H. and R. Harris. Experiences with a generation iii virtual honeynet. in Telecommunication Networks and Applications Conference (ATNAC), 2009 Australasian. 2009. IEEE.
[34].Aliyev, V., Using honeypots to study skill level of attackers based on the exploited vulnerabilities in the network. 2010.
[35].T-Pot 17.10 - Multi-Honeypot Platform rEvolution. 2017; Available from: https://dtag-dev-sec.github.io/mediator/feature/2017/11/07/t-pot-17.10.html.
[36].Wahono, S. and S. Alif Subardono, Analisis dan Implementasi Honeypot Terdistribusi sebagai Deteksi Aktivitas Blackhat pada Jaringan. 2017, Universitas Gadjah Mada.
[37].Koniaris, I. HoneyDrive  Honeypot Bundle Linux. 2014; Available from: https://bruteforce.gr/honeydrive/.
[38].Jigneshkumar, S.M., Modern Honey Network. International Journal of Research in Advent Technology (E-ISSN: 2321-9637) Special Issue, 2016. E-ISSN: 2321-9637(National Conference “NCPCI-2016”, 19 March 2016).
[39].Oosterhof, M., Cowrie honeypot. Security Intelligence, 2014.
[40].Müter, M., et al., A generic toolkit for converting web applications into high-interaction honeypots. University of Mannheim, 2008. 280: p. 6.1.
[41].Crane, S., et al. Booby trapping software. in Proceedings of the 2013 New Security Paradigms Workshop. 2013. ACM.
[42].Itkin, E. Reverse RDP Attack: Code Execution on RDP Clients. 2019; Available from: https://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/.
[43].Sintsov, A. Honeypot that can bite: Reverse penetration. in Black Hat Europe Conference. 2013.
[44]  (@debasishm89), D.M., Browser Exploits. MCAFEE 2017.
[45].Singh, E.G. and M. Kaur, Armitage: A Penetration testing tool to evaluate Destructive Vulnerabilities.
[46].Brandis, R.A.S., Luke. Threat Modelling Adobe Pdf. Edinburgh South Australia : Dsto Defence Science And Technology Organisation 2012.
[47].Ramirez-Silva, E., and Marc Dacier. "Empirical study of the impact of metasploit-related attacks in 4 years of attack traces." Annual Asian Computing Science Conference. Springer Berlin Heidelberg, 2007.
[48].O'Leary, M., Cyber operations: building, defending, and attacking modern computer networks. 2015: Apress.
[49].Choudhary, R. and M. Khurana, Exploitation of PDF Reader Vulnerabilities using Metasploit Tool. 2017.
[50].Zarghoon, A., et al., Evaluation of AV Systems Against Modern Malware.
[51].kyREcon. Shellter 2017  cited 2017; Available from: https://www.shellterproject.com/introducing-shellter/.
[52].D, D., Anti-Virus Bypass with Shellter 5.1 on Kali Linux. 2015.
[53].Ge, M., et al., Proactive defense for internet-of-things: moving target defense with cyberdeception. ACM Transactions on Internet Technology (TOIT), 2021. 22(1): p. 1-31.
[54].Reworr and D. Volkov, LLM Agent Honeypot: Monitoring AI Hacking Agents in the Wild. ArXiv, 2024. abs/2410.13919.
[55].Zeltser, L., Experimenting with Honeypots Using The Modern Honey Network 20 Feb 2015. Electron Resource. Access mode: https://zeltser. com/modern-honey-network-experiments.
[56].Lin, K. and L. Kyaw, Hybrid Honeypot System for Network Security. 2008.
دوره 13، شماره 4 - شماره پیاپی 52
زمستان
زمستان 1404
صفحه 125-144

  • تاریخ دریافت 16 مهر 1404
  • تاریخ بازنگری 03 آذر 1404
  • تاریخ پذیرش 28 آذر 1404
  • تاریخ انتشار 01 دی 1404