Archive for the ‘Whitepapers’ Category

“Web application attacks” article published in Network Security (Part 2)

Tuesday, November 20th, 2007

The November edition of Elsevier’s Network Security publication contains the second part of an article on web application attacks written by David Watson of the UK Honeynet Project and can be downloaded as part of their current free online trial (as can a previous article on Honeynets as Counter-intelligence tools).

KYE: “Behind the Scenes of Malicious Web Servers” released

Wednesday, November 7th, 2007

The Honeynet Project released a new Know Your Enemy: “Behind the Scenes of Malicious Web Servers” white paper today, which follows up on recent publications about malicious web sites and attacks against common web clients.

Abstract:

“In this paper, we increase our understanding of malicious web servers through analysis of several web exploitation kits that have appeared in 2006/07: WebAttacker, MPack, and IcePack. Our discoveries will necessitate adjustments on how we think about malicious web servers and will have direct implications on client honeypot technology and future studies.”

Lots of cross over with recent UKHP activity and well worth a read.

“Web application attacks” article published in Network Security (Part 1)

Tuesday, October 23rd, 2007

The October edition of Elsevier’s Network Security publication contains part one of an article on web application attacks written by David Watson of the UK Honeynet Project, with the second part to follow in November.

“KYE: Malicious Websites” released

Tuesday, August 14th, 2007

The Honeynet Project has released a new Know Your Enemy white paper on malicious websites and attacks against web browsers: “In this paper, we take an in-depth look at malicious web servers that attack web browsers, and we evaluate several defensive strategies that can be employed to counter this threat of client-side attacks. All the malicious web servers identified in this study were found with our client honeypot Capture-HPC”. This paper contains lots of interesting web attack related material.

http://www.honeynet.org/papers/mws/

New KYE white paper released

Tuesday, July 17th, 2007

The Honeynet Project have released a new KYE white paper. KYE: Fast-Flux Service Networks describes how attackers are developing more robust and scalable networks for delivering cyber-crime, based on networks of compromises hosts with rapidly changing DNS records and layers of proxy server redirection.

Honeynets: a tool for counterintelligence

Monday, January 1st, 2007

‘Honeynets: a tool for counterintelligence’ published by Elsevier’s Network Security magazine (David Watson - item #4).

Camouflaging HoneyD

Tuesday, July 26th, 2005

Camouflaging Honeyd: A method for camouflaging honeyd has been released by Bryan Graham and Xinwen Fu: http://students.cs.tamu.edu/xinwenfu/honeyd_tamu/

Honeypots Against Spam

Tuesday, July 5th, 2005

Honeypots against Spam: Details of a second warrant for a case where proxypot/honeypot information was significant: http://www.proxypot.org/yui.pdf