Publication Details

Exploring Current E-mail Cyber Threats Using Authenticated SMTP Honeypot

ZOBAL Lukáš, KOLÁŘ Dušan and KŘOUSTEK Jakub. Exploring Current E-mail Cyber Threats Using Authenticated SMTP Honeypot. In: Proceedings of the 17th International Conference on Security and Cryptography (SECRYPT 2020). Paris: SciTePress - Science and Technology Publications, 2020, pp. 253-262. ISBN 978-989-758-446-6. Available from: https://www.scitepress.org/PublicationsDetail.aspx?ID=KjbiWwxR+9s=&t=1
Czech title
Zkoumání aktuálních e-mailových hrozeb s využitím SMTP honeypotu vyžadujícícho autentizaci
Type
conference paper
Language
english
Authors
Zobal Lukáš, Ing. (DIFS FIT BUT)
Kolář Dušan, doc. Dr. Ing. (DIFS FIT BUT)
Křoustek Jakub, Ing. (DIFS FIT BUT)
URL
Keywords

Spam, Honeypot, SMTP, E-mail, Malware, Cyber Threat Intelligence

Abstract

Today, spam is a major attack vector hackers use to cause harm. Let it be through phishing or direct malicious attachments, e-mail can be used to steal credentials, distribute malware, or cause other illegal activities. Even nowadays, most users are unaware of such danger, and it is the responsibility of the cybersecurity community to protect them. To do that, we need tools to gain proper threat intelligence in the e-mail cyber landscape. In this work, we show how an e-mail honeypot requiring authentication can be used to monitor current e-mail threats. We study how such honeypot performs in place of an open relay server. The results show this kind of solution provides a powerful tool to collect fresh malicious samples spreading in the wild. We present a framework we built around this solution and show how its users are automatically notified about unknown threats. Further, we perform analysis of the data collected and present a view on the threats spreading in the recent months as captured by this authentication-requiring e-mail honeypot.

Published
2020
Pages
253-262
Proceedings
Proceedings of the 17th International Conference on Security and Cryptography (SECRYPT 2020)
Conference
17th International Conference on Security and Cryptography, Paris, FR
ISBN
978-989-758-446-6
Publisher
SciTePress - Science and Technology Publications
Place
Paris, FR
DOI
UT WoS
000615962200021
EID Scopus
BibTeX
@INPROCEEDINGS{FITPUB12254,
   author = "Luk\'{a}\v{s} Zobal and Du\v{s}an Kol\'{a}\v{r} and Jakub K\v{r}oustek",
   title = "Exploring Current E-mail Cyber Threats Using Authenticated SMTP Honeypot",
   pages = "253--262",
   booktitle = "Proceedings of the 17th International Conference on Security and Cryptography (SECRYPT 2020)",
   year = 2020,
   location = "Paris, FR",
   publisher = "SciTePress - Science and Technology Publications",
   ISBN = "978-989-758-446-6",
   doi = "10.5220/0009591002530262",
   language = "english",
   url = "https://www.fit.vut.cz/research/publication/12254"
}
Back to top