Unveiling Attack Patterns: A Study of Adversary Behavior from Honeypot Data
Abstract
As our reliance on digital infrastructure and the transmission of sensitive information grows, the importance of effective cybersecurity measures becomes increasingly urgent. This study explores the efficacy of honeypots and the MITRE ATT& CK framework in detecting adversary behaviors in ethereum, smtp, ftp, and ldap attacks. By deploying honeypots, we gathered a diverse range of attack data, revealing prevalent patterns like phishing, scamming, account hijacking in ethereum, bruteforce in ftp, and port scanning in ldap. Mapping this data to the MITRE ATT& CK framework enabled the identification of adversary TTPs (Tactics, Techniques, and Procedures), informing security strategies and mitigating future attacks. Our findings highlight the significance of employing honeypots to identify and analyze adversary tactics, techniques, and procedures (TTPs). This underscores the importance of continual research to further improve our comprehension of evolving cyber threats. –
Community
0 commentsNo discussion yet
Be the first to share a question or observation.