Honeypots

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

1 comments

Comments 1 - 1 of 1 previous next Post a comment

  • + ssharLudena ssharLudena 2 years ago
    I never had heard about reconfiguring a tcp stream to determine the operating system, this slide is very interesting.

Post a comment
Embed Video
Edit your comment Cancel

1 Favorite

Honeypots - Presentation Transcript

  1. Honeypots Jayant Kumar Gandhi - www.jkg.in Himanshu Bhatnagar Sachin Gajjar Sameek Banerjee Shashwat Agrawal http://www.jkg.in/eel702/presentation.ppt
  2. Agenda
    • Motivation
    • Definition
    • Advantages/ Disadvantages
    • Types
  3. Motivation
    • Key to effective intrusion detection is information
      • Learn more about past attacks
      • Detect currently occurring attacks
      • Identify new types of attacks
      • Do all this in real time
  4. Definition
    • “ Any security resource who’s value lies in being probed, attacked, or compromised” – L. Spitzner, Honeypots: Tracking Hackers , ISBN 0-321-10895-7
  5. How honeypots work
    • A resource that expects no data, so any traffic to or from it is most likely unauthorized activity
  6. Advantages
    • Reduce false positives and false negatives
    • Data value
    • Resources
    • Simplicity
  7. Disadvantages
    • Narrow Field of View
    • Fingerprinting
    • Risk
  8. Types
    • Production (Law enforcement)
    • Research (Counter-intelligence)
  9. Production Honeypots
    • Prevention
    • Detection
    • Response
  10. Research Honeypots
    • Early warning and prediction
    • Discover new tools and tactics
    • Understanding motives, behavior and organization
    • Develop analysis and forensic skills
  11. Level of Interaction
    • Level of interaction determines the amount of functionality a honeypot provides
      • Low Interaction
        • Less learning, complexity and risk
      • High Interaction
        • High learning, complexity and risk
  12. Risk
    • Attacker can compromise your honeypot to harm, attack or infiltrate other systems and organizations
  13. Low Interaction
    • Provide emulated services
    • No operating system to access
    • Information limited to transactional information and attackers activities with the emulated services
  14. High Interaction
    • Provides actual Operating Systems
    • Learn extensive amount of information
    • Extensive risk
  15. Honeyd
    • Low-interaction honeypot
    • Runs on a single computer
      • Simulates a group of virtual machines
      • Simulates the physical network between them
    • Simulates only the network stack of each machine
    • Intended primarily to fool fingerprinting tools
  16. Honeyd
    • Fingerprinting
      • Attackers often try to learn more about a system before attacking it
      • Can determine a machine’s operating system by “testing” its network behavior
        • How the initial TCP sequence number is created
        • Response packets for open and closed ports
        • Configuration of packet headers
      • Common fingerprinting tools: Nmap, Xprobe
  17. Honeynets
    • High-interaction honeypots
    • Network of real machines (honeypots)
    • Honeywall – a gateway between honeypots and rest of the world
  18. Legal issues
    • Privacy
    • Entrapment
    • Liability
  19. Legal Mumbo Jumbo
    • Design template is Copyright © 2006 Jayant Kumar Gandhi (www.jkg.in)
    • Clip art is Copyright © 2006 Microsoft Corporation
    • All trademarks, registered trademarks are acknowledged and are property of their respective owners
  20. Bibliography
    • Robert Graham, Network intrusion detection systems, 2000. http://www.robertgraham.com/pubs/network-intrusion-detection.html
    • David Klug, Honeypots and intrusion detection. http://www.sans.org./infosecFAQ/intrusion/honeypots.htm
    • Christian Plattner Reto Baumann, White paper: Honeypots. http://www.rbaumann.net,http://www.christianplattner.net
    • Lance Spitzner, Honeypots: Tracking hackers ISBN: 0-321-10895-7
    • Lance Spitzner, Intrusion detection, 2000. http://www.enteract.com/lspitz/ids.html
    • Lance Spitzner, Know your enemy: I, ii and iii, 2000 http://www.project.honeynet.org/papers
  21. Questions?
  22. http://www.jkg.in/contact-me/ Uploaded on SlideShare.net for the public.

+ jayantjayant, 3 years ago

custom

2683 views, 1 favs, 0 embeds more stats

First draft of a presentation I gave to students al more

More Info

© All Rights Reserved

Go to text version
  • Total Views 2683
    • 2683 on SlideShare
    • 0 from embeds
  • Comments 1
  • Favorites 1
  • Downloads 0
Most viewed embeds

more

All embeds

less

Flagged as inappropriate Flag as inappropriate
Flag as innappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel

Categories