PhantomFS: File-Based Deception Technology for Thwarting Malicious Users

被引:7
|
作者
Lee, Junghee [1 ]
Choi, Jione [1 ]
Lee, Gyuho [2 ]
Shim, Shin-Woo [2 ]
Kim, Taekyu [2 ]
机构
[1] Korea Univ, Sch Cybersecur, Seoul 02841, South Korea
[2] LIG NEX1 Co Ltd, Cyber Warfare Res & Dev Lab, Seongnam 13488, South Korea
来源
IEEE ACCESS | 2020年 / 8卷 / 08期
关键词
Libraries; Virtual machining; Monitoring; Intrusion detection; Containers; Electronic mail; Deception technology; file system; honeypot; SYSTEM;
D O I
10.1109/ACCESS.2020.2973700
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
File-based deception technologies can be used as an additional security barrier when adversaries have successfully gained access to a host evading intrusion detection systems. Adversaries are detected if they access fake files. Though previous works have mainly focused on using user data files as decoys, this concept can be applied to system files. If so, it is expected to be effective in detecting malicious users because it is very difficult to commit an attack without accessing a single system file. However, it may suffer from excessive false alarms by legitimate system services such as file indexing and searching. Legitimate users may also access fake files by mistake. This paper addresses this issue by introducing a hidden interface. Legitimate users and applications access files through the hidden interface which does not show fake files. The hidden interface can also be utilized to hide sensitive files by hiding them from the regular interface. By experiments, we demonstrate the proposed technique incurs negligible performance overhead, and it is an effective countermeasure to various attack scenarios and practical in that it does not generate false alarms for legitimate applications and users.
引用
收藏
页码:32203 / 32214
页数:12
相关论文
共 50 条
  • [21] IMDBfs: Bridging the Gap between In-Memory Database Technology and File-Based Tools for Life Sciences
    Schapranow, Matthieu-P.
    Kraus, Milena
    Danner, Marius
    Plattner, Hasso
    2016 IEEE INTERNATIONAL CONFERENCE ON BIOINFORMATICS AND BIOMEDICINE (BIBM), 2016, : 1133 - 1139
  • [22] A Research Environment for Evaluating File-based Cryptojacking Detection Techniques
    Pietraszek, Lukasz
    Mazurczyk, Wojciech
    20TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE, IWCMC 2024, 2024, : 915 - 920
  • [23] File-based closed captioning system without captioning delay
    Kim, Yunhyoung
    Han, Sunghee
    Choi, Sungwoo
    Jung, Byunghee
    ABU Technical Review, 2015, (264): : 7 - 10
  • [24] New developments in file-based infrastructure for ATLAS event selection
    van Gemmeren, P.
    Malon, D. M.
    Nowak, M.
    17TH INTERNATIONAL CONFERENCE ON COMPUTING IN HIGH ENERGY AND NUCLEAR PHYSICS (CHEP09), 2010, 219
  • [25] Case Study: File-Based Workflow from Acquisition to Air
    Foti, Michael
    SMPTE MOTION IMAGING JOURNAL, 2010, 119 (04): : 64 - 67
  • [26] How Metadata Enables Enriched File-Based Production Workflows
    Van Rijsselbergen, Dieter
    Verwaest, Maarten
    Mannens, Erik
    Van de Walle, Rik
    SMPTE MOTION IMAGING JOURNAL, 2010, 119 (04): : 27 - 38
  • [27] File-based localization of numerical perturbations in data analysis pipelines
    Salari, Ali
    Kiar, Gregory
    Lewis, Lindsay
    Evans, Alan C.
    Glatard, Tristan
    GIGASCIENCE, 2020, 9 (12):
  • [28] Utilizing monte carlo for log file-based delivery QA
    Stanhope, C.
    Drake, D.
    Alber, M.
    Sohn, M.
    Liang, J.
    Habib, C.
    Yan, D.
    RADIOTHERAPY AND ONCOLOGY, 2017, 123 : S509 - S510
  • [29] A File-Based Linked Data Fragments Approach to Prefix Search
    Dedecker, Ruben
    Delva, Harm
    Colpaert, Pieter
    Verborgh, Ruben
    WEB ENGINEERING, ICWE 2021, 2021, 12706 : 53 - 67
  • [30] Prototype of a File-Based High-Level Trigger in CMS
    Bauer, G.
    Bawej, T.
    Behrens, U.
    Branson, J.
    Chaze, O.
    Cittolin, S.
    Coarasa, J. A.
    Darlea, G-L
    Deldicque, C.
    Dobson, M.
    Dupont, A.
    Erhan, S.
    Gigi, D.
    Glege, F.
    Gomez-Ceballos, G.
    Gomez-Reino, R.
    Hartl, C.
    Hegeman, J.
    Holzner, A.
    Masetti, L.
    Meijers, F.
    Meschi, E.
    Mommsen, R. K.
    Morovic, S.
    Nunez-Barranco-Fernandez, C.
    O'Dell, V.
    Orsini, L.
    Ozga, W.
    Paus, C.
    Petrucci, A.
    Pieri, M.
    Racz, A.
    Raginel, O.
    Sakulin, H.
    Sani, M.
    Schwick, C.
    Spataru, A. C.
    Stieger, B.
    Sumorok, K.
    Veverka, J.
    Wakefiled, C. C.
    Zejdl, P.
    20TH INTERNATIONAL CONFERENCE ON COMPUTING IN HIGH ENERGY AND NUCLEAR PHYSICS (CHEP2013), PARTS 1-6, 2014, 513