Logo image
透過Honeypots來增強瀏覽網站的安全性
Thesis

透過Honeypots來增強瀏覽網站的安全性

Jorge Orlando Murillo Perdomo
Masters, 國立清華大學, 資訊系統與應用研究所
2013

Abstract

客戶端 安全 HTTPS 伺服器 低成本 Client Honeypot Web Security HTTPS Proxy Server Low-Cost
The Internet is now more than a commodity and has transitioned to be a invaluable service for organizations, companies, and general everyday users. With the enormous and continuous growth, attackers are consistent in creating new methods to prey on vulnerable users. It is now a matter of high importance to secure and protect user data, since many attacks are popularly deployed on malicious Websites. Many commercial enterprise solutions are costly and a sophisticated infrastructure is needed to deploy them. Additionally, these solutions often rely on the vendors to constantly provide signatures or blacklists to make sure the system is up-to-date. Therefore, the detection of infection by malware is often really complex. Client honeypots have become a popular choice by researchers that aim to detect and analyze drive-by-download attacks. These systems crawl websites and detect if malware or malicious code is present in these websites. The tools are readily available and are relatively easily to deploy and maintain. An approach that allows users to manage their defense systems has proved inefficient as years have passed by due to performance issues and the complexity of maintaining these solutions individually. In this thesis, we propose a solution to keep networks behind a proxy server secure. Client honeypots can feed the proxy server with newly found malicious websites, the proxy server will access a database of blocked URLs and domains effectively filtering the web access users have. Clients will connect to the proxy server that is coupled with an Internet Content Adaptation Protocol (ICAP). The ICAP system will serve an HTML page when clients visit potentially malicious websites.

Metrics

1 Record Views

Details

Logo image