ResearchSpace

Utilisation of a virtual honeynet to proactively secure the South African National Research and Education Network against cyberattacks

Show simple item record

dc.contributor.author Meyer, Heloise
dc.contributor.author Barbour, Graham D
dc.contributor.author McDonald, Andre M
dc.contributor.author Badenhorst, Danielle P
dc.contributor.author Gertenbach, Wian P
dc.date.accessioned 2024-07-22T08:35:55Z
dc.date.available 2024-07-22T08:35:55Z
dc.date.issued 2024-07
dc.identifier.citation Meyer, H., Barbour, G.D., McDonald, A.M., Badenhorst, D.P. & Gertenbach, W.P. 2024. Utilisation of a virtual honeynet to proactively secure the South African National Research and Education Network against cyberattacks. <i>Communications in Computer and Information Science, 2159.</i> http://hdl.handle.net/10204/13732 en_ZA
dc.identifier.issn 1865-0929
dc.identifier.issn 1865-0937
dc.identifier.uri https://doi.org/10.1007/978-3-031-64881-6_24
dc.identifier.uri http://hdl.handle.net/10204/13732
dc.description.abstract South Africa is witnessing a significant increase in cyberattacks. Although such an increase in cyberattacks can be attributed to various factors, poor investment in cybersecurity technology and lack of awareness are causing South Africa to be a target of interest. While cyberattacks are targeting various sectors, it is the cyberattacks impacting critical infrastructure that are a growing concern. The South African National Research and Education Network (SA NREN) is a high-speed network dedicated to science, research, education and innovation traffic. With the growth of the SA NREN and the continuous increase in cyberattacks affecting South African institutions, proactive steps are required to secure and protect the SA NREN. This responsibility lies with the SA NREN Cybersecurity Incident Response Team (CSIRT), which was established in 2016 to offer protection against cyberattacks. While various proactive measures are currently in place to monitor the SA NREN, the CSIRT continues to explore alternative cost-effective solutions to secure the NREN. This paper investigates the benefits of utilising a novel low-interaction secure shell (SSH) honeynet, referred to as the Virtual Honeynet, to monitor and proactively secure the SA NREN. The Virtual Honeynet uses virtual containers to reduce resource requirements and improve performance. The investigation involved the experimental deployment of the Virtual Honeynet on the SA NREN over a twelve-day period and the evaluation of the captured data. The evaluation conducted focused on extracting behavioural and geographical intelligence from the raw data to guide the deployment of cyber measures to secure the SA NREN. The results presented in this paper confirm the value the Virtual Honeynet offers to the SA NREN as a technology to proactively secure the network. en_US
dc.format Abstract en_US
dc.language.iso en en_US
dc.relation.uri https://link.springer.com/chapter/10.1007/978-3-031-64881-6_24 en_US
dc.source Communications in Computer and Information Science, 2159 en_US
dc.subject Cyberattacks en_US
dc.subject Cybersecurity en_US
dc.subject Honeynet en_US
dc.subject Network security en_US
dc.title Utilisation of a virtual honeynet to proactively secure the South African National Research and Education Network against cyberattacks en_US
dc.type Article en_US
dc.description.pages 404–420 en_US
dc.description.note © 2024 The Author(s), under exclusive license to Springer Nature Switzerland AG. Due to licensing restrictions, the attached PDF file only contains the abstract of the full text item. For access to the full text item, please consult the publisher's website: https://link.springer.com/chapter/10.1007/978-3-031-64881-6_24 en_US
dc.description.cluster National Integrated Cyber InfraStructure en_US
dc.description.cluster Defence and Security en_US
dc.description.impactarea Inf and Cybersecurity Centre en_US
dc.description.impactarea SANReN en_US
dc.identifier.apacitation Meyer, H., Barbour, G. D., McDonald, A. M., Badenhorst, D. P., & Gertenbach, W. P. (2024). Utilisation of a virtual honeynet to proactively secure the South African National Research and Education Network against cyberattacks. <i>Communications in Computer and Information Science, 2159</i>, http://hdl.handle.net/10204/13732 en_ZA
dc.identifier.chicagocitation Meyer, Heloise, Graham D Barbour, Andre M McDonald, Danielle P Badenhorst, and Wian P Gertenbach "Utilisation of a virtual honeynet to proactively secure the South African National Research and Education Network against cyberattacks." <i>Communications in Computer and Information Science, 2159</i> (2024) http://hdl.handle.net/10204/13732 en_ZA
dc.identifier.vancouvercitation Meyer H, Barbour GD, McDonald AM, Badenhorst DP, Gertenbach WP. Utilisation of a virtual honeynet to proactively secure the South African National Research and Education Network against cyberattacks. Communications in Computer and Information Science, 2159. 2024; http://hdl.handle.net/10204/13732. en_ZA
dc.identifier.ris TY - Article AU - Meyer, Heloise AU - Barbour, Graham D AU - McDonald, Andre M AU - Badenhorst, Danielle P AU - Gertenbach, Wian P AB - South Africa is witnessing a significant increase in cyberattacks. Although such an increase in cyberattacks can be attributed to various factors, poor investment in cybersecurity technology and lack of awareness are causing South Africa to be a target of interest. While cyberattacks are targeting various sectors, it is the cyberattacks impacting critical infrastructure that are a growing concern. The South African National Research and Education Network (SA NREN) is a high-speed network dedicated to science, research, education and innovation traffic. With the growth of the SA NREN and the continuous increase in cyberattacks affecting South African institutions, proactive steps are required to secure and protect the SA NREN. This responsibility lies with the SA NREN Cybersecurity Incident Response Team (CSIRT), which was established in 2016 to offer protection against cyberattacks. While various proactive measures are currently in place to monitor the SA NREN, the CSIRT continues to explore alternative cost-effective solutions to secure the NREN. This paper investigates the benefits of utilising a novel low-interaction secure shell (SSH) honeynet, referred to as the Virtual Honeynet, to monitor and proactively secure the SA NREN. The Virtual Honeynet uses virtual containers to reduce resource requirements and improve performance. The investigation involved the experimental deployment of the Virtual Honeynet on the SA NREN over a twelve-day period and the evaluation of the captured data. The evaluation conducted focused on extracting behavioural and geographical intelligence from the raw data to guide the deployment of cyber measures to secure the SA NREN. The results presented in this paper confirm the value the Virtual Honeynet offers to the SA NREN as a technology to proactively secure the network. DA - 2024-07 DB - ResearchSpace DP - CSIR J1 - Communications in Computer and Information Science, 2159 KW - Cyberattacks KW - Cybersecurity KW - Honeynet KW - Network security LK - https://researchspace.csir.co.za PY - 2024 SM - 1865-0929 SM - 1865-0937 T1 - Utilisation of a virtual honeynet to proactively secure the South African National Research and Education Network against cyberattacks TI - Utilisation of a virtual honeynet to proactively secure the South African National Research and Education Network against cyberattacks UR - http://hdl.handle.net/10204/13732 ER - en_ZA
dc.identifier.worklist 28097 en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record