TY - GEN
T1 - Monitoring unused IP addresses on segments managed by DHCP
AU - Mizoguchi, Seiichiro
AU - Hori, Yoshiaki
AU - Sakurai, Kouichi
PY - 2008
Y1 - 2008
N2 - New threats are constantly appearing on the Internet. System administrators have developed many tools to try to mitigate those threats, however, currently available coun-termeasures are still limited. Moreover, it is difficult for system administrators to fully understand what happens in their networks in (near) real time. We focus on the monitoring of network traffic sent to unused IP addresses with honeypot devices to capture information about network activity. More precisely, we consider ways of handling such unused addresses on network segments managed via DHCP (Dynamic Host Configuration Protocol). In this paper, we propose, to exploit that DHCP service to dynamically assign unused IP addresses to honeypot devices, and, discuss the design of such monitoring system.
AB - New threats are constantly appearing on the Internet. System administrators have developed many tools to try to mitigate those threats, however, currently available coun-termeasures are still limited. Moreover, it is difficult for system administrators to fully understand what happens in their networks in (near) real time. We focus on the monitoring of network traffic sent to unused IP addresses with honeypot devices to capture information about network activity. More precisely, we consider ways of handling such unused addresses on network segments managed via DHCP (Dynamic Host Configuration Protocol). In this paper, we propose, to exploit that DHCP service to dynamically assign unused IP addresses to honeypot devices, and, discuss the design of such monitoring system.
UR - http://www.scopus.com/inward/record.url?scp=57849125941&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=57849125941&partnerID=8YFLogxK
U2 - 10.1109/NCM.2008.245
DO - 10.1109/NCM.2008.245
M3 - Conference contribution
AN - SCOPUS:57849125941
SN - 9780769533223
T3 - Proceedings - 4th International Conference on Networked Computing and Advanced Information Management, NCM 2008
SP - 510
EP - 515
BT - Proceedings - 4th International Conference on Networked Computing and Advanced Information Management, NCM 2008
T2 - 4th International Conference on Networked Computing and Advanced Information Management, NCM 2008
Y2 - 2 September 2008 through 4 September 2008
ER -