Honeyfile Camouflage: Hiding Fake Files in Plain Sight

Roelien C. Timmer,David Liebowitz,Surya Nepal,Salil S. Kanhere
DOI: https://doi.org/10.1145/3660354.3660355
2024-05-10
Abstract:Honeyfiles are a particularly useful type of honeypot: fake files deployed to detect and infer information from malicious behaviour. This paper considers the challenge of naming honeyfiles so they are camouflaged when placed amongst real files in a file system. Based on cosine distances in semantic vector spaces, we develop two metrics for filename camouflage: one based on simple averaging and one on clustering with mixture fitting. We evaluate and compare the metrics, showing that both perform well on a publicly available GitHub software repository dataset.
Cryptography and Security,Artificial Intelligence,Computation and Language
What problem does this paper attempt to address?