318 Honeypots
3. A framework for attack patterns’ discovery in Honeynet data
Another framework was developed for attack patterns’ discovery in
Honeynet data ped by Thonnard and Dacier [24]. The aim of this
framework is to fi nd groups of network traces sharing various
kinds of highly similar patterns within an attack data set. The
design has a fl exible clustering tool to analyze the time series of the
attacks. Malicious network traffi c is obtained from the distributed
set of Honeynet responders. Time signature is used as a primary
clustering feature and attack patterns are discovered using attack
trace similarity. Attacks are detected as a series of connections,
zero-day and polymorphic attacks are detected based on similarity
to other attacks ...