HoneyBow: an Automated Malware Collection Tool Based on the High-Interaction Honeypot Principle

ZHUGE Jian-wei,HAN Xin-hui,ZHOU Yong-lin,SONG Cheng-yu,GUO Jin-peng,ZOU Wei
DOI: https://doi.org/10.3321/j.issn:1000-436x.2007.12.002
2007-01-01
Abstract:Malware has become one of the severest threats to the public Internet. To deal with the malware breakout ef- fectively as early as possible, an automated malware collection solution must be implemented as a precondition. An automated malware collection tool was presented based on the high-interaction honeypot principle called HoneyBow. Comparing with the Nepenthes platform based on the low-interaction honeypot principle, HoneyBow has its advantages on wilder range of captured malware samples and the capability of collecting unknown malware samples, which are vali- dated by the experiment results from wild malware collection and the case of Mocbot dealment.
What problem does this paper attempt to address?