Over the years, honeypots emerged as an important security tool to understand attacker intent and deceive attackers to spend time and resources. Recently, honeypots are being deployed for Internet of things (IoT) devices to lure attackers, and learn their behavior. However, most of the existing IoT honeypots, even the high interaction ones, are easily detected by an attacker who can observe honeypot traffic due to lack of real network traffic originating from the honeypot. This implies that, to build better honeypots and enhance cyber deception capabilities, IoT honeypots need to generate realistic network traffic flows. To achieve this goal, we propose a novel deep learning based approach for generating traffic flows that mimic real network traffic due to user and IoT device interactions. A key technical challenge that our approach overcomes is scarcity of device-specific IoT traffic data to effectively train a generator. We address this challenge by leveraging a core generative adversarial learning algorithm for sequences along with domain specific knowledge common to IoT devices. Through an extensive experimental evaluation with 18 IoT devices, we demonstrate that the proposed synthetic IoT traffic generation tool significantly outperforms state of the art sequence and packet generators in remaining indistinguishable from real traffic even to an adaptive attacker.
翻译:多年来,蜜罐作为一种重要的安全工具出现,用于理解攻击者意图并诱使攻击者消耗时间和资源。近年来,蜜罐被部署在物联网设备上以引诱攻击者并学习其行为。然而,现有的物联网蜜罐(即便是高交互型蜜罐)大多容易被攻击者通过观察蜜罐流量而检测到,原因是蜜罐缺乏真实网络流量。这意味着,为了构建更优蜜罐并增强网络欺骗能力,物联网蜜罐需要生成逼真的网络流量流。为此,我们提出一种基于深度学习的新方法,用于生成模拟用户与物联网设备交互所产生的真实网络流量流。该方法克服的一个关键技术挑战是:设备特定的物联网流量数据稀缺,难以有效训练生成器。我们通过结合序列生成的核心生成对抗学习算法与物联网设备通用的领域特定知识来应对这一挑战。基于对18种物联网设备的广泛实验评估,我们证明所提出的合成物联网流量生成工具在保持与真实流量不可区分方面显著优于最先进的序列和包生成器,即使面对自适应攻击者也是如此。