English
Related papers

Related papers: Characterizing Large-Scale Adversarial Activities …

200 papers

Honeypots are designed to trap the attacker with the purpose of investigating its malicious behavior. Owing to the increasing variety and sophistication of cyber attacks, how to capture high-quality attack data has become a challenge in the…

Cryptography and Security · Computer Science 2024-02-12 Wenjun Fan , Zhihui Du , Max Smith-Creasey , David Fernández

How users adapt after being sandwiched remains unclear; this paper provides an empirical quantification. Using transaction level data from November 2024 to February 2025, enriched with mempool visibility and ZeroMEV labels, we track user…

Cryptography and Security · Computer Science 2025-12-22 Davide Mancino , Davide Rezzoli

Detecting cyber attacks in the network environments used by Internet-of-things (IoT) and preventing them from causing physical perturbations play an important role in delivering dependable services. To achieve this goal, we propose…

Cryptography and Security · Computer Science 2019-06-03 Hui Lin

In the Internet age, cyber-attacks occur frequently with complex types. Traffic generated by access activities can record website status and user request information, which brings a great opportunity for network attack detection. Among…

Cryptography and Security · Computer Science 2018-11-01 Yuqi Yu , Hanbing Yan , Hongchao Guan , Hao Zhou

In recent years, Ethereum gained tremendously in popularity, growing from a daily transaction average of 10K in January 2016 to an average of 500K in January 2020. Similarly, smart contracts began to carry more value, making them appealing…

Cryptography and Security · Computer Science 2021-01-18 Christof Ferreira Torres , Antonio Ken Iannillo , Arthur Gervais , Radu State

Question-and-answer agents like ChatGPT offer a novel tool for use as a potential honeypot interface in cyber security. By imitating Linux, Mac, and Windows terminal commands and providing an interface for TeamViewer, nmap, and ping, it is…

Cryptography and Security · Computer Science 2023-01-11 Forrest McKee , David Noever

Network telescopes serve as a critical passive monitoring tool for capturing unsolicited Internet traffic, providing insights into global scanning and reconnaissance behavior. This study analyzes a 10-day dataset during January 2025…

Cryptography and Security · Computer Science 2026-05-05 Shereen Ismail , Taelyn Dyer , Raul Martinez , Garrett Gastman , Yozelyn Chavez , Asma Jodeiri Akbarfam

Receiving timely and relevant security information is crucial for maintaining a high-security level on an IT infrastructure. This information can be extracted from Open Source Intelligence published daily by users, security organisations,…

Cryptography and Security · Computer Science 2019-04-04 Fernando Alves , Aurélien Bettini , Pedro M. Ferreira , Alysson Bessani

Advanced persistent threats (APTs) are stealthy attacks which make use of social engineering and deception to give adversaries insider access to networked systems. Against APTs, active defense technologies aim to create and exploit…

Cryptography and Security · Computer Science 2019-01-24 Jeffrey Pawlick , Thi Thu Hang Nguyen , Edward Colbert , Quanyan Zhu

Ethereum holds multiple billions of U.S. dollars in the form of Ether cryptocurrency and ERC-20 tokens, with millions of deployed smart contracts algorithmically operating these funds. Unsurprisingly, the security of Ethereum smart…

Cryptography and Security · Computer Science 2021-06-01 Nikolay Ivanov , Jianzhi Lou , Ting Chen , Jin Li , Qiben Yan

We quantify the threat of network adversaries to inducing \emph{network overload} through \emph{routing attacks}, where a subset of network nodes are hijacked by an adversary. We develop routing attacks on the hijacked nodes for two…

Networking and Internet Architecture · Computer Science 2024-11-07 Xinyu Wu , Eytan Modiano

Identifying the "heavy hitter" flows or flows with large traffic volumes in the data plane is important for several applications e.g., flow-size aware routing, DoS detection, and traffic engineering. However, measurement in the data plane…

Networking and Internet Architecture · Computer Science 2017-07-20 Vibhaalakshmi Sivaraman , Srinivas Narayana , Ori Rottenstreich , S. Muthukrishnan , Jennifer Rexford

Historically, enterprise network reconnaissance is an active process, often involving port scanning. However, as routers and switches become more complex, they also become more susceptible to compromise. From this vantage point, an attacker…

Cryptography and Security · Computer Science 2020-08-10 Iffat Anjum , Mu Zhu , Isaac Polinsky , William Enck , Michael K. Reiter , Munindar Singh

We introduce EtherBee, a global dataset integrating detailed Ethereum node metrics, network traffic metadata, and honeypot interaction logs collected from ten geographically diverse vantage points over three months. By correlating node data…

Networking and Internet Architecture · Computer Science 2025-05-27 Scott Seidenberger , Anindya Maiti

Cloud computing has dramatically changed service deployment patterns. In this work, we analyze how attackers identify and target cloud services in contrast to traditional enterprise networks and network telescopes. Using a diverse set of…

Cryptography and Security · Computer Science 2023-10-02 Liz Izhikevich , Manda Tran , Michalis Kallitsis , Aurore Fass , Zakir Durumeric

Critical Infrastructure (CI) is prone to cyberattacks. Several techniques have been developed to protect CI against such attacks. In this work, we describe a honeypot based on a cyber twin for a water treatment plant. The honeypot is…

Cryptography and Security · Computer Science 2025-09-12 Muhammad Azmi Umer , Zhan Xuna , Yan Lin Aung , Aditya P. Mathur , Jianying Zhou

In cloud environments, conventional firewalls rely on predefined rules and manual configurations, limiting their ability to respond effectively to evolving or zero-day threats. As organizations increasingly adopt platforms such as Microsoft…

Cryptography and Security · Computer Science 2025-12-08 Darren Malvern Chin , Bilal Isfaq , Simon Yusuf Enoch

The Internet Threat Monitoring (ITM) is an efficient monitoring system used globally to measure, detect, characterize and track threats such as denial of service (DoS) and distributed Denial of Service (DDoS) attacks and worms. . To block…

Networking and Internet Architecture · Computer Science 2012-02-22 K. Munivara Prasad , A. Rama Mohan Reddy , V Jyothsna

Honeypot is an important cyber defense technique that can expose attackers new attacks. However, the effectiveness of honeypots has not been systematically investigated, beyond the rule of thumb that their effectiveness depends on how they…

Cryptography and Security · Computer Science 2024-01-15 Md Mahabub Uz Zaman , Liangde Tao , Mark Maldonado , Chang Liu , Ahmed Sunny , Shouhuai Xu , Lin Chen

Honeypots are used in IT Security to detect and gather information about ongoing intrusions, e.g., by documenting the approach of an attacker. Honeypots do so by presenting an interactive system that seems just like a valid application to…

Cryptography and Security · Computer Science 2015-07-14 Christoph Pohl , Michael Meier , Hans-Joachim Hof