The investigation on cowrie honeypot logs in establishing rule signature snort

7Citations
Citations of this article
37Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

The attack of brute force is still one of the popular attacks used to hack into your account unauthorized by a computer system. Brute force is also the most crucial attack and has a high risk of the system being taken over. Investigating brute force attacks is useful for building strong computer network defense systems. In this study, Snort acts as an intrusion prevention system and Cowrie Honeypot as a tool to investigate anomalous behavior that occurs when a brute force attack happened. The aim of this research is to improve Snort's rule signature performance from brute force attacks by relying on the results of the Cowrie Honeypot log investigation. The results obtained, namely Snort rule signature successfully improved detection capabilities with performance in matching the same packet only requires a short processing time, respectively: 3.5 microsecs in Hydra attacks, 3.8 microsecs in Medusa attacks and 2.3 microsecs in Ncrack attacks.

Cite

CITATION STYLE

APA

Satria, E., Huda, T. P. S., Iqbal, M., & Sarjana, F. W. (2021). The investigation on cowrie honeypot logs in establishing rule signature snort. In IOP Conference Series: Earth and Environmental Science (Vol. 644). IOP Publishing Ltd. https://doi.org/10.1088/1755-1315/644/1/012031

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free