Observation of Human-Operated Accesses Using Remote Management Device Honeypot

1Citations
Citations of this article
9Readers
Mendeley users who have this article in their library.

Abstract

In recent years, cyber attacks against infrastructure have become more serious. Unfortunately, infrastructures with vulnerable remote management devices, which allow attackers to control the infrastructure, have been reported. Targeted attacks against infrastructure are conducted manually by human attackers rather than automated scripts. Here, open questions are how often the attacks against such infrastructure happen and what attackers do after intrusions. In this empirical study, we observe the accesses, including attacks and security investigation activities, using the customized infrastructure honeypot. The proposed honeypot comprises (1) a platform that easily deploys real devices as honeypots, (2) a mechanism to increase the number of fictional facilities by changing the displayed facility names on the WebUI for each honeypot instance, (3) an interaction mechanism with visitors to infer their purpose, and (4) tracking mechanisms to identify visitors for long-term activities. We implemented and deployed the honeypot for 31 months. Our honeypot observed critical operations, such as changing configurations of a remote management device. We also observed long-term access to WebUI and Telnet service of the honeypot.

Cite

CITATION STYLE

APA

Sasaki, T., Kawaguchi, M., Kumagai, T., Yoshioka, K., & Matsumoto, T. (2024). Observation of Human-Operated Accesses Using Remote Management Device Honeypot. IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences, E107.A(3), 291–305. https://doi.org/10.1587/transfun.2023CIP0018

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free