Deployment of honeypot cluster system HoneyPool

Dong Ma,Yongjun Wang,Haiyan Yu,Feng Huang
2010-01-01
Abstract:As a kind of active technique for security in the field of internet security research, honeypot is attached more and more importance by researchers. However, with the flooding network threats becoming much more covert, installing honeypots locally can hardly deal with this situation. In face of botnet, DDoS, spams, etc, we must take the technique for deployment in large scale so that we can monitor and track these threats; also, users of enterprises would like to deploy honeypots for the reason of security. In order to solve the problem of deploying honeypots in large scale, the paper proposed a parallel algorithm HPDA. HPDA can deploy honeypots in large scale and on demand, and make these honeypots a network. Based on HPDA, in order to deal with the management problem for large scale net of honeypots, a prototype called HoneyPool is implemented. HoneyPool not only can create honeypots on demand swiftly and transparently, but also provides a visual web interface for integrated management. The paper also made some simulations to test the performance of HPDA and system of HoneyPool. Also realised a prototype system called HoneyPool. According to the result of simulations, HPDA has an enhanced performance compared with serialized methods; also, HoneyPool can deploy honeypots according to the workload of hosts, which improved the load balance and performance.
What problem does this paper attempt to address?