TY - GEN
T1 - ShadowNet
T2 - 12th International Conference on Computational Science and Its Applications, ICCSA 2012
AU - Cui, Xiaohui
AU - Gasior, Wade
AU - Beaver, Justin
AU - Treadwell, Jim
PY - 2012
Y1 - 2012
N2 - The ShadowNet infrastructure for insider cyber attack prevention is comprised of a tiered server system that is able to dynamically redirect dangerous/suspicious network traffic away from production servers that provide web, ftp, database and other vital services to cloned virtual machines in a quarantined environment. This is done transparently from the point of view of both the attacker and normal users. Existing connections, such as SSH sessions, are not interrupted. Any malicious activity performed by the attacker on a quarantined server is not reflected on the production server. The attacker is provided services from the quarantined server, which creates the impression that the attacks performed are successful. The activities of the attacker on the quarantined system are able to be recorded much like a honeypot system for forensic analysis.
AB - The ShadowNet infrastructure for insider cyber attack prevention is comprised of a tiered server system that is able to dynamically redirect dangerous/suspicious network traffic away from production servers that provide web, ftp, database and other vital services to cloned virtual machines in a quarantined environment. This is done transparently from the point of view of both the attacker and normal users. Existing connections, such as SSH sessions, are not interrupted. Any malicious activity performed by the attacker on a quarantined server is not reflected on the production server. The attacker is provided services from the quarantined server, which creates the impression that the attacks performed are successful. The activities of the attacker on the quarantined system are able to be recorded much like a honeypot system for forensic analysis.
UR - http://www.scopus.com/inward/record.url?scp=84863936359&partnerID=8YFLogxK
U2 - 10.1007/978-3-642-31128-4_48
DO - 10.1007/978-3-642-31128-4_48
M3 - Conference contribution
AN - SCOPUS:84863936359
SN - 9783642311277
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 646
EP - 653
BT - Computational Science and Its Applications - 12th International Conference, ICCSA 2012, Proceedings
Y2 - 18 June 2012 through 21 June 2012
ER -