Loading...
Cyber Threat Intelligence from Honeypot Data using Elasticsearch
Al-Mohannadi, Hamad ; Awan, Irfan U. ; Al Hamar, J. ; Cullen, Andrea J. ; Disso, Jules P. ; Armitage, Lorna
Al-Mohannadi, Hamad
Awan, Irfan U.
Al Hamar, J.
Cullen, Andrea J.
Disso, Jules P.
Armitage, Lorna
Publication Date
2018-05-18
End of Embargo
Supervisor
Rights
© 2018IEEE. Reproduced in accordance with the publisher's self-archiving policy.
Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.
Peer-Reviewed
n/a
Open Access status
Accepted for publication
Institution
Department
Awarded
Embargo end date
Additional title
Abstract
Cyber attacks are increasing in every aspect of daily
life. There are a number of different technologies around to
tackle cyber-attacks, such as Intrusion Detection Systems (IDS),
Intrusion Prevention Systems (IPS), firewalls, switches, routers
etc., which are active round the clock. These systems generate
alerts and prevent cyber attacks. This is not a straightforward
solution however, as IDSs generate a huge volume of alerts that
may or may not be accurate: potentially resulting in a large
number of false positives. In most cases therefore, these alerts
are too many in number to handle. In addition, it is impossible to
prevent cyber-attacks simply by using tools. Instead, it requires
greater intelligence in order to fully understand an adversary’s
motive by analysing various types of Indicator of Compromise
(IoC). Also, it is important for the IT employees to have enough
knowledge to identify true positive attacks and act according to
the incident response process.
In this paper, we have proposed a new threat intelligence
technique which is evaluated by analysing honeypot log data to
identify behaviour of attackers to find attack patterns. To achieve
this goal, we have deployed a honeypot on an AWS cloud to
collect cyber incident log data. The log data is analysed by using
elasticsearch technology namely an ELK (Elasticsearch, Logstash
and Kibana) stack.
Version
Accepted Manuscript
Citation
AL-Mohannad H, Awan I, Al Hamar J, Cullen A,
Disso JP and Armitage L (2018) Cyber Threat Intelligence from Honeypot Data
using Elasticsearch. 32nd IEEE International Conference on Advanced Information Networking and Applications (IEEE AINA-2018) Pedagogical University of Cracow, Poland, May 16-18, 2018.
Link to publisher’s version
Link to published version
Link to Version of Record
Type
Conference paper