期刊论文详细信息
Computer Science and Information Systems
Using honeynet data and a time series to predict the number of cyber attacks
article
Matej Zuzčák1  Petr Bujok1 
[1] Department of Informatics and Computers, Faculty of Science, University of Ostrava 30. dubna 22
关键词: cyber attacks;    honeynet;    honeypot;    SSH;    time series;    prediction;   
DOI  :  10.2298/CSIS200715040Z
学科分类:土木及结构工程学
来源: Computer Science and Information Systems
PDF
【 摘 要 】

A large number of cyber attacks are commonly conducted against home computers, mobile devices, as well as servers providing various services. One such prominently attacked service, or a protocol in this case, is the Secure Shell (SSH) used to gain remote access to manage systems. Besides human attackers, botnets are a major source of attacks on SSH servers. Tools such as honeypots allow an effective means of recording and analysing such attacks. However, is it also possible to use them to effectively predict these attacks? The prediction of SSH attacks, specifically the prediction of activity on certain subjects, such as autonomous systems, will be beneficial to system administrators, internet service providers, and CSIRT teams. This article presents multiple methods for using a time series, based on real-world data, to predict these attacks. It focuses on the overall prediction of attacks on the honeynet and the prediction of attacks from specific geographical regions. Multiple approaches are used, such as ARIMA, SARIMA, GARCH, and Bootstrapping. The article presents the viability, precision and usefulness of the individual approaches for various areas of IT security.

【 授权许可】

CC BY-NC-ND   

【 预 览 】
附件列表
Files Size Format View
RO202307150003261ZK.pdf 908KB PDF download
  文献评价指标  
  下载次数:6次 浏览次数:0次