<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>UK Honeynet Project &#187; Events</title>
	<atom:link href="http://www.ukhoneynet.org/category/events/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ukhoneynet.org</link>
	<description>News and information from the UK Honeynet Project</description>
	<lastBuildDate>Sun, 20 Feb 2011 21:28:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>FIRST 2008</title>
		<link>http://www.ukhoneynet.org/2008/07/01/first-2008/</link>
		<comments>http://www.ukhoneynet.org/2008/07/01/first-2008/#comments</comments>
		<pubDate>Tue, 01 Jul 2008 13:15:43 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[UK presentations]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/07/01/first-2008/</guid>
		<description><![CDATA[The Honeynet Project were asked to present at the 20th FIRST conference in Vancouver last week, as part of their Network Monitoring Special Interest Group on Fast Flux Service Networks. We set up a two hour session broken down into three equal sections: An introduction to the basic mechanics of fast flux (David Watson, UKHP) [...]]]></description>
			<content:encoded><![CDATA[<p>The Honeynet Project were asked to present at the <a href="http://www.first.org/conference/2008/">20th FIRST conference in Vancouver</a> last week, as part of their <a href="http://www.first.org/conference/2008/program/presentations.html#p985">Network Monitoring Special Interest Group on Fast Flux Service Networks</a>. We set up a two hour session broken down into three equal sections:</p>
<ol>
<li>An introduction to the basic mechanics of fast flux (David Watson, <a href="http://www.ukhoneynet.org">UKHP</a>)</li>
<li>Current <a href="http://atlas.arbor.net/summary/fastflux">ATLAS</a> fast flux statistics (Jose Nazario, <a href="http://www.arbor.net">Arbor</a>)</li>
<li>Detection and mitigation (Christian Gorecki, <a href="http://pi1.informatik.uni-mannheim.de/index.php?pagecontent=site/Research.menu/Honeynet.page">University of Mannheim</a>)</li>
</ol>
<p>The NM-SG session was open to FIRST members only, so the slides are not publicly available, but we hope to have a public release of similar material shortly. We had a number of questions, and feedback from the attendees seems to have been positive.</p>
<p>There were three additional short demos:</p>
<ol>
<li>Florian Weimer of <a href="http://cert.uni-stuttgart.de/stats/dns-replication.php">RUS-CERT</a> showed some new passive DNS tracking information</li>
<li>Tillmann Werner from the German <a href="http://ghp.mwcollect.org/">Giraffe Honeynet Project Chapter</a> demonstrated how <a href="http://honeytrap.mwcollect.org/">Honeytrap</a>, <a href="http://libemu.mwcollect.org/">LibEmu</a> and <a href="http://nebula.mwcollect.org/">Nebula</a> can be used to <a href="http://honeytrap.mwcollect.org/whatfor">analyze unknown attacks</a>, which is looking very promising as a long term replacement for Nepenthes</li>
<li>Piotr Kijewski of the <a href="http://www.nask.pl/nask_en/">Polish CERT/NASK</a> gave a brief demonstration of their still under development HoneySpider web interface, which shares many of the features of client honeypot systems that we are currently working on but instead uses Java and Rhino instead of Python and SpiderMonkey</li>
</ol>
<p>Overall it was an interesting event, with some good talks and lot of opportunities to meet up with a different group of people very active in the security operations and incident response fields. Quiet a few <a href="http://www.honeynet.org">Honeynet Project</a> members were also present, which always encourages a little extra R&amp;D discussion. Hopefully we&#8217;ll see some spin off activity in the coming weeks.</p>
<p>Many thanks to Carol Overes from <a href="http://www.govcert.nl/">GovCERT</a> in Holland for the invite.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/07/01/first-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>EuSecWest08 roundup</title>
		<link>http://www.ukhoneynet.org/2008/05/23/eusecwest08-roundup/</link>
		<comments>http://www.ukhoneynet.org/2008/05/23/eusecwest08-roundup/#comments</comments>
		<pubDate>Fri, 23 May 2008 13:20:10 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[UK presentations]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/05/23/eusecwest08-roundup/</guid>
		<description><![CDATA[EuSecWest08 is over and seems to have been another success. The change of venue from the Victoria Park Plaza to Leicester Square and the Sound nightclub was an interesting move, which could of gone either way but seemed to work for most people and gave the event a slightly more underground, edgy feel. It was [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.eusecwest.org">EuSecWest08</a> is over and seems to have been another success. The change of venue from the Victoria Park Plaza to Leicester Square and the Sound nightclub was an interesting move, which could of gone either way but seemed to work for most people and gave the event a slightly more underground, edgy feel. It was also a great location for after hours socialising.</p>
<p>The standard of presentations and content was generally good, with a number of interesting topics and useful new tools being released. Highlights for me were:</p>
<ul>
<li><strong>Saumil Shah&#8217;s</strong> Teflon browser extension, which hooks javascript system calls such as document.write and replaces evil Javascript with harmless divs. This fits well with some of the recent evil JS research we have been doing, and we are going to do some collaboration here in the coming months.</li>
<li><strong>Alberto Revelli</strong> gave an excellent talk on taking SQL Injection vulnerabilities on Windows platform to the next level and using <a href="http://http://sqlninja.sourceforge.net/">SQLNinja</a> to establish a working remote graphical desktop. Good to see old techniques like building executables from ASCII HTTP requests plus debug.exe coming back into fashion, and an excellent example of how to escalate control from an initial foothold.</li>
<li><strong>Martyn Ruk&#8217;s</strong> review of IBM&#8217;s MQ middleware and identication of some surprisingly simple potential vulnerabilities in a number of areas. Good to see someone looking at MQ security and building tools for auditing MQ systems.</li>
</ul>
<p>Hot topics for the press were <strong>Justin Ferguson&#8217;s</strong> talk on exploiting interpreted languages like Python and PERL, resulting in potentially remotely exploitable vulnerabilities in services like the recently released Google App Engine, and <strong>Sebastian Muniz&#8217;s</strong> talk on developing the first public Cisco IOS rootkit. Both were impressive and it will be interesting to see what happens in this space over the next few months.</p>
<p>I gave another lightning talk on <a href="http://www.ukhoneynet.org/EuSecWest08_David_Watson_EvilJS.pdf">Evil Javascript and SpamMonkey</a>, which we hope to start making public soon. You can find the slides <a href="http://www.ukhoneynet.org/EuSecWest08_David_Watson_EvilJS.pdf">here</a>.</p>
<p>As always, one of the best things about the event was the opportunity to meet up with interesting people in a relaxed environment and discuss what they were working on. It was also good to get a chance to catch up with friends and various industry people. Lots of interesting contacts and discussions, and hopefully we&#8217;ll release some research in the coming months that will have benefited from them. All in all, another interesting and enjoyable (sleep deprived) SecWest event.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/05/23/eusecwest08-roundup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>EuSecWest08</title>
		<link>http://www.ukhoneynet.org/2008/05/20/eusecwest08/</link>
		<comments>http://www.ukhoneynet.org/2008/05/20/eusecwest08/#comments</comments>
		<pubDate>Tue, 20 May 2008 10:32:49 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[UK News]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/05/20/eusecwest08/</guid>
		<description><![CDATA[I&#8217;m in London this week for EuSecWest08, the European version of the excellent CanSec and PacSec series of conferences, which is happening tomorrow and Thursday in Leicester Square. A couple of scheduled talks are generating interest on the net already: Sebastian Muniz&#8217;s &#8220;Da IOS Rootkit&#8221; talk will review his reverse engineering and kernel hooking approach [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m in London this week for <a href="http://www.eusecwest.com/">EuSecWest08</a>, the European version of the excellent CanSec and PacSec series of conferences, which is happening tomorrow and Thursday in Leicester Square. A couple of scheduled talks are generating interest on the net already:</p>
<ul>
<li>Sebastian Muniz&#8217;s &#8220;<a href="http://www.eusecwest.com/sebastian-muniz-da-ios-rootkit.html">Da IOS Rootkit</a>&#8221; talk will review his reverse engineering and kernel hooking approach to building a reliable Cisco IOS rootkit</li>
<li>Justin Ferguson&#8217;s &#8220;<a href="http://www.eusecwest.com/justin-ferguson-interpreter-vm-attacks.html">Advances in attacking interpreted languages</a>&#8221; will cover the attack surface and potential vulnerabilities in Google&#8217;s recently release App Engine.</li>
</ul>
<p>Hopefully EuSec will be another interesting and entertaining event, with any honeynet-related news and events to follow.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/05/20/eusecwest08/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>First WOMBAT workshop</title>
		<link>http://www.ukhoneynet.org/2008/04/25/first-wombat-workshop/</link>
		<comments>http://www.ukhoneynet.org/2008/04/25/first-wombat-workshop/#comments</comments>
		<pubDate>Fri, 25 Apr 2008 15:19:05 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[UK presentations]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/04/25/first-wombat-workshop/</guid>
		<description><![CDATA[Jamie and myself from the UK Honeynet Project plus Max Kilger and Thorsten Holz from the UNCC and German Honeynet Project Chapters were in Amsterdam this week for the first workshop held by the European Commission&#8217;s 7th Framework WOMBAT project (see previous posts for more details). The workshop was held at Vrije University south of [...]]]></description>
			<content:encoded><![CDATA[<p>Jamie and myself from the UK Honeynet Project plus Max Kilger and Thorsten Holz from the <a href="http://honeynet.uncc.edu/">UNCC</a> and <a href="http://pi1.informatik.uni-mannheim.de/index.php?pagecontent=site/Research.menu/Honeynet.page">German</a> Honeynet Project Chapters were in Amsterdam this week for the first workshop held by the European Commission&#8217;s 7th Framework <a href="http://www.wombat-project.eu/">WOMBAT project</a> (see <a href="http://www.ukhoneynet.org/2008/04/04/wombat-2008-papers-accepted">previous</a> <a href="http://www.ukhoneynet.org/2008/02/20/wombat-workshop-2008">posts</a> for more details).</p>
<p>The workshop was held at Vrije University south of the city centre and included members of the WOMBAT consortium and invited guests who were active in the fields of honeynet deployments, malware analysis and large scale data collection. Over two days we were introduced to the three year WOMBAT project, its goals and members and a number of short presentations were given by the invited guests from the EU, US, Asia and Australia. David spoke about the Honeynet Project&#8217;s various data collection initiatives, including the Global Distributed Honeynet Project (<a href="http://www.ukhoneynet.org/PacSec07_David_Watson_Global_Distributed_Honeynet.pdf">GDH</a>), and Max spoke about attacker profiling models. The proceedings will be published in the journals of <a href="http://www.computer.org/security">IEEE Computer Society</a> later in the year and we&#8217;ll post them when we are able to.</p>
<p>Overall an interesting event with lots of opportunity for collaboration and information sharing that will hopefully come to fruition. Of particular interest was the honeyclient work that the Polish CERT <a href="http://www.nask.pl/nask_en/">NASK</a> were involved in, which was remarkably similar to our own recent activity on <a href="http://www.ukhoneynet.org/CanSec08_David_Watson_EvilJS.pdf">Evil Javascript and SpamMonkey</a> that I gave a lightning talk on at <a href="http://www.ukhoneynet.org/2008/04/03/cansecwest08/">CanSecWest08</a> last month. Like us, they hope to release their code as open source in the coming weeks and months, so we are look forward to seeing it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/04/25/first-wombat-workshop/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CanSecWest08</title>
		<link>http://www.ukhoneynet.org/2008/04/03/cansecwest08/</link>
		<comments>http://www.ukhoneynet.org/2008/04/03/cansecwest08/#comments</comments>
		<pubDate>Thu, 03 Apr 2008 14:41:39 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[UK presentations]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/04/03/cansecwest08/</guid>
		<description><![CDATA[I was in Vancouver last week as a backup speaker for CanSecWest08 . Once again, this was an good event, with plenty to keep me interested. It was also a great chance to catch up with Honeynet Project members, various friends in the security community and also to meet up with new people and exchange [...]]]></description>
			<content:encoded><![CDATA[<p>I was in Vancouver last week as a backup speaker for <a href="http://cansecwest.com/agenda.html">CanSecWest08</a> . Once again, this was an good event, with plenty to keep me interested. It was also a great chance to catch up with Honeynet Project members, various friends in the security community and also to meet up with new people and exchange ideas. Kudos to Dragos for another excellent event, and also to Honeynet Project alumni Shane for winning the Pwn20wn contest for the second year in a row. Presentations should be on the web site shortly.</p>
<p>In the end, and for the first time ever, all the speakers made it to the event and I didn&#8217;t need to give a repeat performance of my <a href="http://www.ukhoneynet.org/2007/12/03/global-distributed-honeynet-talk-at-pacsec07/">PacSec07 GDH presentation</a>. However, I did give a lightning talk entitled <a   href="http://www.ukhoneynet.org/CanSec08_David_Watson_EvilJS.pdf">Evil Javascript and SpamMonkey</a> that introduced a couple of projects the UK Honeynet Project team have been working on recently. You can find the slides <a href="http://www.ukhoneynet.org/CanSec08_David_Watson_EvilJS.pdf">here</a> and hopefully we&#8217;ll be releasing the code and some sample results in the coming months.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/04/03/cansecwest08/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Honeynet Project annual workshop</title>
		<link>http://www.ukhoneynet.org/2007/12/10/honeynet-project-annual-workshop/</link>
		<comments>http://www.ukhoneynet.org/2007/12/10/honeynet-project-annual-workshop/#comments</comments>
		<pubDate>Mon, 10 Dec 2007 21:24:11 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[UK News]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2007/12/10/honeynet-project-annual-workshop/</guid>
		<description><![CDATA[The Honeynet Project holds an annual workshop every year, which is always an excellent opportunity for members from all around the world to get together in person and discuss their research. For the first time, this year&#8217;s event was hosted by members of the Costa Rican Honeynet Project and held outside of the US, in [...]]]></description>
			<content:encoded><![CDATA[<p>The Honeynet Project holds an annual workshop every year, which is always an excellent opportunity for members from all around the world to get together in person and discuss their research.</p>
<p>For the first time, this year&#8217;s event was hosted by members of the <a href="http://www.honeynetcr.org/en/">Costa Rican Honeynet Project</a> and held outside of the US, in <a href="http://www.hb.co.cr/">Heredia</a>, Costa Rica. Thirty five members of the Honeynet Project met for four days, including Jamie and David from the UK group. As part of the first day&#8217;s shared presentations, David updated the group on the current state of our Global Distributed Honeynet (GDH). The last two days were spent on various R&#038;D tracks, of which the largest was the initial planning session for GDH Phase Two in 2008. </p>
<p>Overall the event was excellent, with many participants feeling that this was the best annual workshop yet, and hopefully we&#8217;ll see the fruits of our collective activities next year.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2007/12/10/honeynet-project-annual-workshop/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Global Distributed Honeynet talk at PacSec07</title>
		<link>http://www.ukhoneynet.org/2007/12/03/global-distributed-honeynet-talk-at-pacsec07/</link>
		<comments>http://www.ukhoneynet.org/2007/12/03/global-distributed-honeynet-talk-at-pacsec07/#comments</comments>
		<pubDate>Mon, 03 Dec 2007 14:05:41 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[UK presentations]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2007/12/03/global-distributed-honeynet-talk-at-pacsec07/</guid>
		<description><![CDATA[I was the first international speaker at PacSec07 in Tokyo last week, and gave our initial public talk about the first phase of our Global Distributed Honeynet (GDH) research. The abstract for the talk was: A review of Phase One of the Honeynet Project&#8217;s latest research initiative, the deployment and operation of a global network [...]]]></description>
			<content:encoded><![CDATA[<p>I was the first international speaker at <a href="http://pacsec.jp/")>PacSec07</a> in Tokyo last week, and gave our initial public talk about the first phase of our Global Distributed Honeynet (GDH) research. </p>
<p>The abstract for the talk was:</p>
<p><i>A review of Phase One of the Honeynet Project&#8217;s latest research<br />
initiative, the deployment and operation of a global network of<br />
distributed high interaction research honeypots. An overview of the<br />
architecture, challenges faced, technical tools and new<br />
analysis/reporting procedures developed. Discussion of observed<br />
malicious activity during operation of eleven high interaction research<br />
honeynets around the world for six months (Jan-Jun 2007), including<br />
attacker activity, malware collection summary, etc. Sharing of practical<br />
operational experiences gained to date, unsolved issues and goals for<br />
the future.</p>
<p>GDH was the first (publicly declared) real world distributed high<br />
interaction research honeynet with nodes on most continents, designed<br />
and operated by the Honeynet Project. It enables the rapid deployment of<br />
identical honeypots over wide ranges of IP network space, monitoring of<br />
network activity and analysis of attacks against a range of distributed<br />
systems. The techniques and operational experience should be useful to<br />
many organizations interested in global sensor networks and better<br />
understanding the threats posed to their networks. A &#8220;Know Your Enemy:<br />
GDH&#8221; white paper and other supporting material will be released in 2008.</i></p>
<p>Slides will be available online from the both the <a href="http://www.pacsec.jp/psj07archive.html/">PacSec07</a> and <a href="http://www.honeynet.org">Honeynet Project</a> web sites shortly, or they can be downloaded directly from <a href="http://www.ukhoneynet.org/PacSec07_David_Watson_Global_Distributed_Honeynet.pdf">here</a>.  </p>
<p>The presentation was an hour long, and hopefully provided an introduction to what GDH Phase One was, why and how we built and operated it, then summarized some of our initial results and plans for the future. The audience questions were of a good standard, as were follow-up discussions at the party afterwards. Any offline feedback or questions are also welcome.</p>
<p>Overall the conference was enjoyable, with good presentations in a number of areas and an interesting mix of both Japanese and international attendees (and the obligatory late night social activities). Hopefully we&#8217;ll see some spin off honeynet research in 2008 in a couple of areas. It was also great to have the opportunity to visit Tokyo and meet local security researchers, plus presenting to a Japanese audience with live translation was entertaining. I&#8217;d particularly like to thank Ryo Hirosawa and the other translators for all their last minute help with slide translation. Thanks once again guys!</p>
<p>You can find further coverage and some photographs of the event here:</p>
<li><a href="http://translate.google.com/translate?u=http%3A%2F%2Fsid.rstack.org%2Fblog%2Findex.php%2F240-pacsec-2007-cinquime-du-nom&#038;langpair=fr%7Cen&#038;hl=en&#038;ie=UTF-8">Cedric Blancher&#8217;s Blog</a></li>
<li><a href="http://sid.rstack.org/gallery/?galerie=200711_Tokyo">Cedric Blancher&#8217;s Photos</a></li>
<li><a href="http://flickr.com/photos/hirosan/collections/72157603341201950/">Ryo Hirosawa&#8217;s Photos</a></li>
<li><a href="http://picasaweb.google.co.jp/haradats/PacSec2007">Toshiharu Harada&#8217;s Photos</a></li>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2007/12/03/global-distributed-honeynet-talk-at-pacsec07/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lance Spitzner HITB keynote</title>
		<link>http://www.ukhoneynet.org/2007/09/06/lance-spitzner-hitb-keynote/</link>
		<comments>http://www.ukhoneynet.org/2007/09/06/lance-spitzner-hitb-keynote/#comments</comments>
		<pubDate>Thu, 06 Sep 2007 14:07:55 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2007/09/06/lance-spitzner-hitb-keynote/</guid>
		<description><![CDATA[Lance Spitzner was one of the keynote speakers at Hack-In-The-Box 2007 in Malaysia this week, and talked about some of the research we have been involved in recently (including the Honeynet Project’s Global Distributed Honeynet initiative &#8211; GDH, which David led). More details can be found at the conference web site.]]></description>
			<content:encoded><![CDATA[<p>Lance Spitzner was one of the keynote speakers at Hack-In-The-Box 2007 in Malaysia this week, and talked about some of the research we have been involved in recently (including the Honeynet Project’s Global Distributed Honeynet initiative &#8211; GDH, which David led). More details can be found at the <a href="http://conference.hackinthebox.org/hitbsecconf2007kl/?page_id=65">conference web site</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2007/09/06/lance-spitzner-hitb-keynote/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISOI workshop</title>
		<link>http://www.ukhoneynet.org/2007/08/29/isoi-workshop/</link>
		<comments>http://www.ukhoneynet.org/2007/08/29/isoi-workshop/#comments</comments>
		<pubDate>Wed, 29 Aug 2007 15:06:11 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[UK News]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2007/08/29/isoi-workshop/</guid>
		<description><![CDATA[Members of the UK Honeynet Project and Honeynet Project were again attendees at the 3rd Internet Security Operations and Intelligence workshop in Washington DC this week, which provided an another excellent opportunity to catch up with other researchers and discuss the latest online threats. Press coverage.]]></description>
			<content:encoded><![CDATA[<p>Members of the UK Honeynet Project and Honeynet Project were again attendees at the 3rd Internet Security Operations and Intelligence workshop in Washington DC this week, which provided an another excellent opportunity to catch up with other researchers and discuss the latest online threats. <a href="http://www.darkreading.com/document.asp?doc_id=132400">Press coverage</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2007/08/29/isoi-workshop/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blackhat USA 2007 honeynet data analysis talk</title>
		<link>http://www.ukhoneynet.org/2007/08/01/blackhat-usa-2007-honeynet-data-analysis-talk/</link>
		<comments>http://www.ukhoneynet.org/2007/08/01/blackhat-usa-2007-honeynet-data-analysis-talk/#comments</comments>
		<pubDate>Wed, 01 Aug 2007 17:25:10 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2007/08/01/blackhat-usa-2007-honeynet-data-analysis-talk/</guid>
		<description><![CDATA[Mark Ryan Talabis from the Philippine / Hawaii Honeynet Project presented today at Blackhat USA 2007 (http://www.blackhat.com/html/bh-usa-07/bh-usa-07-speakers.html#Talabis). His presentation titled &#8220;The Security Analytics Project: Alternatives in Analysis&#8221; covered data analysis related topics, which is an area of honeynet research where progress is still sorely lacking, and it included coverage of some of recent UK Honeynet [...]]]></description>
			<content:encoded><![CDATA[<p>Mark Ryan Talabis from the Philippine / Hawaii Honeynet Project presented today at Blackhat USA 2007 (http://www.blackhat.com/html/bh-usa-07/bh-usa-07-speakers.html#Talabis). His presentation titled &#8220;The Security Analytics Project: Alternatives in Analysis&#8221; covered data analysis related topics, which is an area of honeynet research where progress is still sorely lacking, and it included coverage of some of recent UK Honeynet Project activity such as GDH and Honeysnap. Slides should eventually be available online at the Blackhat website. Some press coverage of his talk can be found <a href="http://www.darkreading.com/document.asp?doc_id=130719">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2007/08/01/blackhat-usa-2007-honeynet-data-analysis-talk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

