Bee

HoneySpot: The Wireless Honeypot

siles January 15th, 2008

HoneySpot: The Wireless Honeypot

Monitoring the Attacker’s Activities in Wireless Networks
A design and architectural overview

We’ve been developing a paper to create awareness and help to guide the deployment of wireless honeypots, mainly centered on 802.11 (WiFi) technologies. The paper is focused on providing a design and architectural overview for the deployment of wireless honeypots, coined as HoneySpots.

We’re currently involved in deploying these technologies, capture attacks and related information, develop analysis tools, and will publish a future paper with the findings. Meanwhile, we would like to publicly promote the deployment of these technologies by releasing this paper. If you are interested in developing or/and deploying wireless honeynets, contact us at project at (removethis)honeynet.org.es. The Spanish Honeynet Project wants to promote this research area, including multiple wireless technologies, mainly 802.11 and Bluetooth today, with future additions such as WiMAX.

FIST Presentation

dgonzalez February 4th, 2005

Presentation of the Spanish Honeynet Project, describing the Project, what Honeynets are, their value, how they operate, and how they contribute to computer security. 29 slides.[Pic1] [Pic2] (Spanish language).

Scan of The Month 32 Write-up

dgonzalez October 27th, 2004

In this paper we analyze the malware provided for the Scan of the Month 32 released by the Honeynet Project in September 2004. The paper contains not only the answers to the questions of the challenge but also a detailed explanation of the methods and tools used to do the analysis.

Installing a Virtual Honeywall using VMware

dgonzalez September 15th, 2004

If the Honeywall CDROM is installed on a virtual machine, it will also include the many advantages that a virtual machine environment offers. This paper explains how to go about configuring VMware to deploy a Honeywall.

Technorati Tags: , , , ,

Honeywall scripts

dgonzalez August 11th, 2004

The scripts below have been written to make easier the management of the most common tools used in a Honeywall. The logging directories and log file name formats used are similar to the ones used by the Honeywall CDROM tool to preserve compatibility. These scripts are also included in the paper “Building a GenII Honeynet Gateway”.

honeywall.conf: The main configuration file. It is an improved version of honeywall.conf config file included in the Honeywall CDROM by The Honeynet Project. It has two new options: LAN_BLOCK and LAN_ALLOWDED_IP. We suggested this new functionality to the Alliance who integrated it into Roo as whitelisting and blacklisting.

rc.firewall: Script for loading iptables firewall. It is an improved version of the rc.firewall script v0.8 found in Honeywall CDROM that supports the new LAN_BLOCK option. On the other hand, the handlers’ section has been simplified.

snort.sh: Script for managing snort NIDS (config file not provided).

snort_inline.sh: Script for managing snort-inline (config file not provided).

snort_pcap.sh: Script for recording network traffic in binary format using snort in logging mode.

tcpdump.sh: Script for recording network traffic in binary format using tcpdump.

swatch.sh: Script for managing Swatch, used to provide basic alerting capabilites.

swatch.conf: Swatch elemental configuration file.

Next »