A honeypot is a kind of security solution. herefore, it is better to explain what the problem is, that is the attacker. By understanding who our threat is and how he operates, we can easily understand the solution better, which is the concept of honeypot [20].
5.2.1 Script Kiddies and Advanced Blackhat Attacks
here are two types of attackers: script kiddies and advanced blackhat.
It does not matter if these threats are coming from the outside, such as the Internet, or from the inside, such as a disgruntled employee. Most threats tend to fall into one of these two categories.
Script kiddies. hese types of attackers usually depend on scripted attacks. Sometimes, these attackers have certain requirements, such as hacking systems with a fast connection to the Internet or a large hard drive for storing iles. In general, however, all they care about are numbers. hey tend to be less sophisti-cated, but they are far more numerous, representing the vast majority of probes, scans, and attacks you see today.
To compromise a device using script kiddies is very sim-ple, and the attacker only needs to follow a number of steps to reach its intended goal. Without script kiddies, the task is much more complicated and may only be performed by experts. For example, steps would be as follows:
• First, an attacker has to identify a vulnerability within an OS or application. his is not an easy task. It requires extensive knowledge of how OSs work, such as memory management, kernel mechanisms, and ile systems’ func-tionality. To identify vulnerabilities in an application, an attacker would have to learn how an application is oper-ated and interacted with both the input and output of information. It could take days, weeks, or even months to identify vulnerabilities.
• However, after a vulnerability is identiied, an attacker would have to develop a tool to exploit it. his requires extensive coding skills, potentially in several diferent computer programming languages.
• After the exploit is developed, the attacker has to ind vul-nerable systems. Often, one scanning tool is used to ind systems that are accessible on the Internet, using such functionality as an ICMP ping or a full TCP connection.
hese tools are used to develop a database of systems that are accessible. hen the attacker has to determine what ser-vices existed on the reachable systems—that is, what was actually running on the targets. Furthermore, the attacker has to determine if any of these services were vulnerable.
• he next step would be launching the exploit against the victim, hacking into and gaining control of the system. Finally, various other tools (often called rootkits) should be used to take over and maintain control of a compromised system.
Each of these steps just described requires the development of a unique tool, and using all those tools takes a lot of time and resources. Once the attack is launched, the tools are often manually operated, requiring a great deal of work from an experienced attacker.
he above-mentioned steps are too diicult and require very skilled attackers with plenty of experience, which was not a common case. Unfortunately, today the story is too dif-ferent. With almost no technical skills or knowledge, anyone can simply download tools from the Internet that can do all the works for them. Sometimes, these tools combine all of the activities that we have just described, into a fully automated weapon that only needs to be pointed at certain systems, or even at an entire network. his is as simple as just clicking a button or pressing a key on the keyboard! An attacker sim-ply downloads these tools, follows the instructions, launches the attacks, and happily hacks his way into hundreds or even thousands of systems. hese tools are rapidly spreading across the Internet, giving access to thousands of attackers, who may do such tasks just for fun. What used to be a highly complex development process is now extremely simple!
Attackers can download the automated tools from a vari-ety of resources or exchange them with their friends. Internet relay chat (IRC) and the World Wide Web enabled blackhats to instantly share new attack tools around the world. hen,
9 7
A T H E O R E T I C A L G U I D E T O H O N E Y P O T S
they simply learn the command-line syntax for the tool. For attackers, who are unfamiliar with command-line syntax, a variety of tools have been designed for Windows with point-and-click capabilities. Some of the exploits even come with well-written, step-by-step instructions.
Advanced blackhat. his type of attacker focuses on targets of choice, may want to compromise a speciic system or systems of high value. hese individuals are most likely highly expe-rienced and knowledgeable attackers. heir attack is usually inancially or nationally motivated, such as state-sponsored terrorism. hey have a speciic target they want to compro-mise, and they focus only on that one. hough less common and fewer in number, these attackers are far more dangerous due to their advanced skill level. Not only can they penetrate highly secured systems, their actions are diicult to detect and trace. Advanced blackhats make little noise when attack-ing systems, and they excel at coverattack-ing their tracks. Even if you have been successfully attacked by such a skilled black-hat, you may never even be aware of it.
While script kiddies and automated attacks represent the largest percentage of attackers, the smaller, more dangerous percentage of attackers are the skilled ones that do not want anyone to know about their existence. hese advanced black-hats do not release their tools. hey only attack and compro-mise systems of high value (i.e., systems of choice). When these attackers are successful, they do not tell the world about it.
Instead, they silently iniltrate organizations, collecting infor-mation, users’ accounts, and access to critical resources. Often, organizations have no idea that they have been compromised.
Advanced attackers can spend months, even years, within a compromised organization without anyone inding out.
hese attackers are interested in a variety of targets. It could be an online banking system, where the attacker is after the database containing millions of credit card information. It could be a case of corporate espionage, where the attacker is attempt-ing to iniltrate a car manufacturer and obtain research designs of future cars. Or it can be as sinister as a foreign government
attempting to access highly conidential government secrets, potentially compromising the security of a country.
hese individuals are highly trained and experienced and they are far more diicult to detect than script kiddies. Even after they have successfully penetrated an organization, they will take advanced steps to ensure that their presence or activity cannot be detected. Very little is known about these attackers. Unlike unskilled attackers, advanced blackhats do not share the same tools or techniques. Each one tends to develop his own skills, methods, and tool sets specialized for speciic activities. As such, when the tools and methods of one advanced attacker are discovered, the information gained may not apply to other advanced blackhats.
We should mention that every computer connected to the Internet is exposed to a great danger. his danger may cost you all your life; for example, what would happen if an attacker uses your hard drive to store all of the stolen credit card infor-mation that he has collected? If the competent authorities for credit cards prosecute thieves, track the attacker traces, and ind that the credit card information is in your computer, what will you do? It may happen that the amount of money that was stolen from the credit cards is too much. In such an embarrassing case, how can you deny the charge against you?
herefore, everyone should take care about this great issue and try to make his computer as much secure as possible.
5.2.2 Attackers’ Motivations
Understanding the motivation of the attackers will help us to under-stand threats better. he following attacks will help for underunder-standing why an attacker would target and attempt to compromise a system [20].
Denial of service attack. Denial of service attacks are those designed to take out the computer systems or networks of a victim. his is commonly done by looding the intended target (such as a Web server) with a barrage of network traic. he more traic that is thrown at a victim, the more efective the attack is. Attackers will often compromise hundreds, if not thousands, of systems to be used for attacks. he more computers they own, the more traic
9 9
A T H E O R E T I C A L G U I D E T O H O N E Y P O T S
they can launch at a target. Many blackhats use denial of service attacks to take out other blackhats. One example is IRC wars, where one individual attempts to knock out another individual from an IRC channel, using denial of service attacks [15].
Internet bots. Robots (BOTs) are automated robots that act on behalf of an individual in a preprogrammed fashion. hey are most commonly used to maintain control of IRC. he more computers one hacks into, the more BOTs one can launch, and the more one can control speciic IRC channels. Using many BOTs protects individuals from losing control of an IRC from denial of service attacks.
Phishing. Phishing is a way of attempting to acquire information (and sometimes, indirectly, money) such as usernames, pass-words, and credit card details by masquerading as a trustwor-thy entity in an electronic communication. Communications purporting to be from popular social websites, auction sites, online payment processors, or IT administrators is commonly used to lure the unsuspecting public. Phishing is typically carried out by email spooing or instant messaging, and it often directs users to enter details at a fake website whose look and feel are almost identical to the legitimate one. Phishing is an example of social engineering techniques used to deceive users, and exploit the poor usability of current web security technologies. Attempts to deal with the growing number of reported phishing incidents include legislation, user training, public awareness, and technical security measures [16].