<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>UK Honeynet Project &#187; Whitepapers</title>
	<atom:link href="http://www.ukhoneynet.org/category/whitepapers/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ukhoneynet.org</link>
	<description>News and information from the UK Honeynet Project</description>
	<lastBuildDate>Tue, 05 Aug 2008 12:58:40 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Global Browser Vulnerability Survey</title>
		<link>http://www.ukhoneynet.org/2008/07/04/global-browser-vulnerability-survey/</link>
		<comments>http://www.ukhoneynet.org/2008/07/04/global-browser-vulnerability-survey/#comments</comments>
		<pubDate>Fri, 04 Jul 2008 11:40:29 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Whitepapers]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/07/04/global-browser-vulnerability-survey/</guid>
		<description><![CDATA[A lot of current computer security threat research activity today occurs in the client space, with honeyclients such as Capture-HPC and PhoneyC regularly being used to study attacks against web browsers. Often these attacks occur through malicious obfuscated javascript and exploitation of vulnerable plugins or media extensions to allow fully automated &#8216;drive by download&#8217; infections. [...]]]></description>
			<content:encoded><![CDATA[<p>A lot of current computer security threat research activity today occurs in the client space, with honeyclients such as <a href="http://projects.honeynet.org/capture-hpc">Capture-HPC</a> and <a href="https://svn.mwcollect.org/phoneyc">PhoneyC</a> regularly being used to study attacks against web browsers. Often these attacks occur through malicious obfuscated javascript and exploitation of vulnerable plugins or media extensions to allow fully automated &#8216;drive by download&#8217; infections. The <a href="http://www.honeynet.org">Honeynet Project</a> have published a number of <a href="http://www.honeynet.org/papers/kye.html">Know Your Enemy whitepapers</a> in this area over the past year, and continue to actively research in this area. We have also <a href="http://www.ukhoneynet.org/EuSecWest08_David_Watson_EvilJS.pdf">previously</a> <a href="http://www.ukhoneynet.org/2007/07/18/new-javascript-tool-released/">blogged</a> about some of the ideas the <a href="http://www.ukhoneynet.org">UK Honeynet Project</a> have been experimenting with in this area.</p>
<p>One of the biggest challenges with client based threats is assessing the real world scale of the potential problem. For traditional server based threats, it was fair simple to survey the entire IPv4 space and determine what versions of a particular application or operating system were in active use at a particular time.  However, for client threats, you need a client application to come to you and interact with a service before any assessment of potential client vulnerabilities can be performed. This is a significant challenge for both attackers and researchers (hence the continued use of indiscriminate spamming and malicious advert serving at the same time as more targeted attacks are also being developed).</p>
<p>As the world&#8217;s most popular search engine, Google record the user agent client version data from the billions of web searches made by an estimated 75% of Internet users, and is therefore one of the organisations most likely to be able to provide an assessment of the current state of web browser security (Microsoft&#8217;s MSRT also has excellent data, but only for the ~450 million users regularly running Windows Automatic Updates). However, for obvious privacy reasons, this data has not been made available to the public.</p>
<p>An <a href="http://www.techzoom.net/publications/insecurity-iceberg/index.en">interesting survey</a> was released yesterday by Google Switzerland, IBM ISS and the Computer Engineering and Networks Laboratory of the University of Zurich, which provides the first systematic study of the browser data from around 1.4 billion Google users during the first half of 2008. They analysed Google&#8217;s client version data and correlated this with vulnerability data from sources such as Secunia&#8217;s PSI, in an attempt to assess how many vulnerable browsers were in circulation at a particular time.</p>
<p>The results are very interesting, with Internet Explorer taking 78% (1.1 billion) of the browser share and Firefox getting 16% (227 million). Drilling down deeper into the IE market share shows roughly half of IE users have now moved to IE7, whilst most FF users run the latest release. More worryingly, less that 50% of IE uses had the most secure version of their browser (rising to 83% in FF). For the month of June 2008, the authors suggest that over 45% web surfers (roughly some 637 million people) accessed Google with a browser that contained unpatched security vulnerabilities. There is also some interesting analysis of the exposure to plugged in as well as inbuilt vulnerabilities, plus some good recommendations for potential improvements to web browser security. In particular, the concept of web sites checking a browser&#8217;s agent strings and displaying a highly visible &#8220;expiry date&#8221; warning on every page (in an attempt to enforce a maximum shelf life) is worth further investigation.</p>
<p>The very welcome <a href="http://www.techzoom.net/publications/insecurity-iceberg/index.en">paper</a> is definitely worth a read, but is unlikely to cause too much immediate worry to the cyber criminals who are actively targeting web users through the thousands of mass compromised web servers, phishing emails and instant message spam we encounter each day.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/07/04/global-browser-vulnerability-survey/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;Web application attacks&#8221; article published in Network Security (Part 2)</title>
		<link>http://www.ukhoneynet.org/2007/11/20/web-application-attacks-article-published-in-network-security-part-2/</link>
		<comments>http://www.ukhoneynet.org/2007/11/20/web-application-attacks-article-published-in-network-security-part-2/#comments</comments>
		<pubDate>Tue, 20 Nov 2007 13:57:54 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[UK presentations]]></category>
		<category><![CDATA[Whitepapers]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2007/11/20/web-application-attacks-article-published-in-network-security-part-2/</guid>
		<description><![CDATA[The November edition of Elsevier’s Network Security publication contains the second part of an article on web application attacks written by David Watson of the UK Honeynet Project and can be downloaded as part of their current free online trial (as can a previous article on Honeynets as Counter-intelligence tools).
]]></description>
			<content:encoded><![CDATA[<p>The November edition of Elsevier’s <a href="http://www.sciencedirect.com/science/journal/13534858">Network Security</a> publication contains the second part of an article on web application attacks written by David Watson of the UK Honeynet Project and can be downloaded as part of their current free online trial (as can a previous article on Honeynets as Counter-intelligence tools).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2007/11/20/web-application-attacks-article-published-in-network-security-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>KYE: &#8220;Behind the Scenes of Malicious Web Servers&#8221; released</title>
		<link>http://www.ukhoneynet.org/2007/11/07/kye-behind-the-scenes-of-malicious-web-servers-released/</link>
		<comments>http://www.ukhoneynet.org/2007/11/07/kye-behind-the-scenes-of-malicious-web-servers-released/#comments</comments>
		<pubDate>Wed, 07 Nov 2007 16:59:46 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Whitepapers]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2007/11/07/kye-behind-the-scenes-of-malicious-web-servers-released/</guid>
		<description><![CDATA[The Honeynet Project released a new Know Your Enemy: &#8220;Behind the Scenes of Malicious Web Servers&#8221; white paper today, which follows up on recent publications about malicious web sites and attacks against common web clients. 
Abstract:
&#8220;In this paper, we increase our understanding of malicious web servers through analysis of several web exploitation kits that have [...]]]></description>
			<content:encoded><![CDATA[<p>The Honeynet Project released a new <a href="http://www.honeynet.org/papers/wek/">Know Your Enemy: &#8220;Behind the Scenes of Malicious Web Servers&#8221;</a> white paper today, which follows up on recent publications about malicious web sites and attacks against common web clients. </p>
<p>Abstract:</p>
<p>&#8220;In this paper, we increase our understanding of malicious web servers through analysis of several web exploitation kits that have appeared in 2006/07: WebAttacker, MPack, and IcePack. Our discoveries will necessitate adjustments on how we think about malicious web servers and will have direct implications on client honeypot technology and future studies.&#8221;</p>
<p>Lots of cross over with recent UKHP activity and well worth a read.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2007/11/07/kye-behind-the-scenes-of-malicious-web-servers-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;Web application attacks&#8221; article published in Network Security (Part 1)</title>
		<link>http://www.ukhoneynet.org/2007/10/23/web-application-attacks-article-published-in-network-security/</link>
		<comments>http://www.ukhoneynet.org/2007/10/23/web-application-attacks-article-published-in-network-security/#comments</comments>
		<pubDate>Tue, 23 Oct 2007 14:47:40 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[UK News]]></category>
		<category><![CDATA[Whitepapers]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2007/10/23/web-application-attacks-article-published-in-network-security/</guid>
		<description><![CDATA[The October edition of Elsevier&#8217;s Network Security publication contains part one of an article on web application attacks written by David Watson of the UK Honeynet Project, with the second part to follow in November.
]]></description>
			<content:encoded><![CDATA[<p>The October edition of Elsevier&#8217;s <a href="http://www.sciencedirect.com/science/journal/13534858">Network Security</a> publication contains part one of an article on web application attacks written by David Watson of the UK Honeynet Project, with the second part to follow in November.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2007/10/23/web-application-attacks-article-published-in-network-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;KYE: Malicious Websites&#8221; released</title>
		<link>http://www.ukhoneynet.org/2007/08/14/kye-malicious-websites-release/</link>
		<comments>http://www.ukhoneynet.org/2007/08/14/kye-malicious-websites-release/#comments</comments>
		<pubDate>Tue, 14 Aug 2007 14:57:52 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Whitepapers]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2007/08/14/kye-malicious-websites-release/</guid>
		<description><![CDATA[The Honeynet Project has released a new Know Your Enemy white paper on malicious websites and attacks against web browsers: &#8220;In this paper, we take an in-depth look at malicious web servers that attack web browsers, and we evaluate several defensive strategies that can be employed to counter this threat of client-side attacks. All the [...]]]></description>
			<content:encoded><![CDATA[<p>The Honeynet Project has released a new Know Your Enemy white paper on malicious websites and attacks against web browsers: &#8220;In this paper, we take an in-depth look at malicious web servers that attack web browsers, and we evaluate several defensive strategies that can be employed to counter this threat of client-side attacks. All the malicious web servers identified in this study were found with our client honeypot Capture-HPC&#8221;. This paper contains lots of interesting web attack related material.</p>
<p>http://www.honeynet.org/papers/mws/</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2007/08/14/kye-malicious-websites-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New KYE white paper released</title>
		<link>http://www.ukhoneynet.org/2007/07/17/new-kye-white-paper-release/</link>
		<comments>http://www.ukhoneynet.org/2007/07/17/new-kye-white-paper-release/#comments</comments>
		<pubDate>Tue, 17 Jul 2007 16:21:11 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Whitepapers]]></category>

		<guid isPermaLink="false">http://ukhoneynet.dev2.isotoma.com/2007/07/17/new-kye-white-paper-release/</guid>
		<description><![CDATA[The Honeynet Project have released a new KYE white paper. KYE: Fast-Flux Service Networks describes how attackers are developing more robust and scalable networks for delivering cyber-crime, based on networks of compromises hosts with rapidly changing DNS records and layers of proxy server redirection.
]]></description>
			<content:encoded><![CDATA[<p>The Honeynet Project have released a new KYE white paper. <a href="http://www.honeynet.org/papers/ff/index.html">KYE: Fast-Flux Service Networks</a> describes how attackers are developing more robust and scalable networks for delivering cyber-crime, based on networks of compromises hosts with rapidly changing DNS records and layers of proxy server redirection.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2007/07/17/new-kye-white-paper-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Honeynets: a tool for counterintelligence</title>
		<link>http://www.ukhoneynet.org/2007/01/01/010107/</link>
		<comments>http://www.ukhoneynet.org/2007/01/01/010107/#comments</comments>
		<pubDate>Mon, 01 Jan 2007 00:00:00 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[UK News]]></category>
		<category><![CDATA[Whitepapers]]></category>

		<guid isPermaLink="false">http://ukhoneynet.dev2.isotoma.com/?p=238</guid>
		<description><![CDATA[&#8216;Honeynets: a tool for counterintelligence&#8217; published by Elsevier&#8217;s Network Security magazine (David Watson &#8211; item #4).
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.sciencedirect.com/science?_ob=PublicationURL&amp;_tockey=%23TOC%236094%232007%23979929998%23643544%23FLA%23&amp;_cdi=6094&amp;_pubType=J&amp;view=c&amp;_auth=y&amp;_acct=C000050221&amp;_version=1&amp;_urlVersion=0&amp;_userid=10&amp;md5=8b9c219a24160e890c472b1c29f70736%22">&#8216;Honeynets: a tool for counterintelligence&#8217;</a> published by Elsevier&#8217;s Network Security magazine (David Watson &#8211; item #4).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2007/01/01/010107/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Camouflaging HoneyD</title>
		<link>http://www.ukhoneynet.org/2005/07/26/260705/</link>
		<comments>http://www.ukhoneynet.org/2005/07/26/260705/#comments</comments>
		<pubDate>Tue, 26 Jul 2005 00:00:00 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Whitepapers]]></category>

		<guid isPermaLink="false">http://ukhoneynet.dev2.isotoma.com/?p=280</guid>
		<description><![CDATA[Camouflaging Honeyd: A method for camouflaging honeyd has been released by Bryan Graham and Xinwen Fu: http://students.cs.tamu.edu/xinwenfu/honeyd_tamu/
]]></description>
			<content:encoded><![CDATA[<p>Camouflaging Honeyd: A method for camouflaging honeyd has been released by Bryan Graham and Xinwen Fu: <a href="http://students.cs.tamu.edu/xinwenfu/honeyd_tamu/">http://students.cs.tamu.edu/xinwenfu/honeyd_tamu/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2005/07/26/260705/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Honeypots Against Spam</title>
		<link>http://www.ukhoneynet.org/2005/07/05/050705-a/</link>
		<comments>http://www.ukhoneynet.org/2005/07/05/050705-a/#comments</comments>
		<pubDate>Tue, 05 Jul 2005 00:01:00 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Whitepapers]]></category>

		<guid isPermaLink="false">http://ukhoneynet.dev2.isotoma.com/?p=288</guid>
		<description><![CDATA[Honeypots against Spam: Details of a second warrant for a case where proxypot/honeypot information was significant: http://www.proxypot.org/yui.pdf
]]></description>
			<content:encoded><![CDATA[<p>Honeypots against Spam: Details of a second warrant for a case where proxypot/honeypot information was significant: <a href="http://www.proxypot.org/yui.pdf">http://www.proxypot.org/yui.pdf</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2005/07/05/050705-a/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>KYE: Phishing released</title>
		<link>http://www.ukhoneynet.org/2005/05/17/17505/</link>
		<comments>http://www.ukhoneynet.org/2005/05/17/17505/#comments</comments>
		<pubDate>Tue, 17 May 2005 00:00:00 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Whitepapers]]></category>

		<guid isPermaLink="false">http://ukhoneynet.dev2.isotoma.com/?p=261</guid>
		<description><![CDATA[New Honeynet Project Know Your Enemy paper, KYE: Phishing, released. This paper is based on combined phishing research by the UK and German Honeynet Projects and details real world phishing incidents, including tools and techniques used, incident timelines and common trends.
]]></description>
			<content:encoded><![CDATA[<p>New Honeynet Project Know Your Enemy paper, <a href="http://www.honeynet.org/papers/phishing/">KYE: Phishing</a>, released. This paper is based on combined phishing research by the UK and German Honeynet Projects and details real world phishing incidents, including tools and techniques used, incident timelines and common trends.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2005/05/17/17505/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
