Google hacking defence based on honey pages
journal contribution
posted on 2013-01-01, 00:00 authored by Y Ren, Yang Xiang, M Xu, J HuaMany web servers contain some dangerous pages (we name them eigenpages) that can indicate their vulnerabilities. Therefore, some worms such as Santy locate their targets by searching for these eigenpages in search engines with well-crafted queries. In this paper, we focus on the modeling and containment of these special worms targeting web applications. We propose a containment system based on honey pots. We make search engines randomly insert a few honey pages that will induce visitors to the pre-established honey pots among the search results for the arriving queries. And then infectious can be detected and reported to the search engines when their malicious scans hit the honey pots. We find that the Santy worm can be well stopped by inserting no more than two honey pages in every one hundred search results. We also solve the challenging issue to dynamically generate matching honey pages for those dynamically arriving queries. Finally, a prototype is implemented to prove the technical feasibility of this system. © 2013 by CESER Publications.
History
Journal
International journal of applied mathematics and statisticsVolume
51Issue
22Pagination
284 - 292Publisher
Centre for Environment, Social and Economic Research PublicationsLocation
Uttarakhand, IndiaISSN
0973-7545Language
engPublication classification
C2 Other contribution to refereed journalUsage metrics
Categories
Licence
Exports
RefWorksRefWorks
BibTeXBibTeX
Ref. managerRef. manager
EndnoteEndnote
DataCiteDataCite
NLMNLM
DCDC