Reading PAGE
Peer Evaluation activity
| Trusted by | 1 |
| Downloads | 2 |
| Views | 14 |
| Followed by | 1 |
Total impact ?
Send a 
Angelos has...
| Trusted | 0 |
| Reviewed | 0 |
| Emailed | 0 |
| Shared/re-used | 0 |
| Discussed | 0 |
| Invited | 0 |
| Collected | 0 |
This was brought to you by:
Baiting Inside Attackers Using Decoy Documents
Oh la la
Your session has expired but don’t worry, your message
has been saved.Please log in and we’ll bring you back
to this page. You’ll just need to click “Send”.
Your evaluation is of great value to our authors and readers. Many thanks for your time.
Your mailing list is currently empty.
It will build up as you send messages
and links to your peers.
Enter the e-mail addresses of your recipients in the box below. Note: Peer Evaluation will NOT store these email addresses log in
Your message has been sent.
Description
Title : Baiting Inside Attackers Using Decoy Documents
Area : Computer Science
Language : English
Url : http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.150.1361&rep=rep1&type=pdf
Doi : 10.1.1.150.1361
Abstract : Abstract — The insider threat remains one of the most vexing problems in computer security. A number of approaches have been proposed to detect nefarious insider actions including user modeling and profiling techniques, policy and access enforcement techniques, and misuse detection. In this work we propose trap-based defense mechanisms and a deployment platform for addressing the problem of insiders attempting to exfiltrate and use sensitive information. The goal is to confuse and confound an adversary requiring more effort to identify real information from bogus information and provide a means of detecting when an attempt to exploit sensitive information has occurred. “Decoy Documents ” are automatically generated and stored on a file system by the D 3 System with the aim of enticing a malicious user. We introduce and formalize a number of properties of decoys as a guide to design trap-based defenses to increase the likelihood of detecting an insider attack. The decoy documents contain several different types of bogus credentials that when used, trigger an alert. We also embed “stealthy beacons ” inside the documents that cause a signal to be emitted to a server indicating when and where the particular decoy was opened. We evaluate decoy documents on honeypots penetrated by attackers demonstrating the feasibility of the method. I.
Subject : unspecifiedArea : Computer Science
Language : English
| Affiliations : |
Doi : 10.1.1.150.1361
Leave a comment
This contribution has not been reviewed yet. review?
You may receive the Trusted member label after :
• Reviewing 10 uploads, whatever the media type.
• Being trusted by 10 peers.
• If you are blocked by 10 peers the "Trust label" will be suspended from your page. We encourage you to contact the administrator to contest the suspension.
Please select an affiliation to sign your evaluation:
Please select an affiliation:
Angelos's Peer Evaluation activity
| Trusted by | 1 |
- FPeer Evaluation, Publisher, Peer Evaluation.
| Downloads | 2 |
| Views | 14 |
- 4 Implementing a Distributed Firewall
- 3 A Secure Active Network Environment Architecture -- Realization in SwitchWare
- 2A Dynamic Mechanism for Recovering from Buffer Overflow Attacks
- 11 LETTER On the Deployment of Dynamic Taint Analysis for Application Communities ?
- 12009 International Conference on Availability, Reliability and Security Capturing Information Flowwith ConcatenatedDynamicTaint Analysis
- 1A 2 M: Access-Assured Mobile Desktop Computing
- 1A Cooperative Immunization System for an Untrusting Internet
- 1A Holistic Approach to Service Survivability
| Followed by | 1 |
- FAdrian Ebsary, Student, Master Level, University of Ottawa, McGill University.
Angelos has...
| Trusted | 0 |
| Reviewed | 0 |
| Emailed | 0 |
| Shared/re-used | 0 |
| Discussed | 0 |
| Invited | 0 |
| Collected | 0 |
Full Text request
Your request will be sent.
Please enter your email address to be notified
when this article becomes available
Your email