<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>UK Honeynet Project</title>
	<atom:link href="http://www.ukhoneynet.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ukhoneynet.org</link>
	<description>News and information from the UK Honeynet Project</description>
	<pubDate>Thu, 08 May 2008 13:08:58 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<item>
		<title>Embedded Nepenthes - malware collection using OpenWRT</title>
		<link>http://www.ukhoneynet.org/2008/05/07/embedded-nepenthes-malware-collection-using-openwrt/</link>
		<comments>http://www.ukhoneynet.org/2008/05/07/embedded-nepenthes-malware-collection-using-openwrt/#comments</comments>
		<pubDate>Wed, 07 May 2008 15:22:08 +0000</pubDate>
		<dc:creator>david</dc:creator>
		
		<category><![CDATA[HOWTO]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/?p=399</guid>
		<description><![CDATA[For Phase Two of our Global Distributed Honeynet Project (GDH) I&#8217;ve been continuing to explore how to extend our sensor deployment footprint at minimum cost. Mixed High and low interaction nodes will always require real server / PC hardware, but for a number of years I&#8217;ve been interested in using &#8220;plug and play&#8221; low interaction-only [...]]]></description>
			<content:encoded><![CDATA[<p>For Phase Two of our Global Distributed Honeynet Project (<a href="http://www.ukhoneynet.org/PacSec07_David_Watson_Global_Distributed_Honeynet.pdf">GDH</a>) I&#8217;ve been continuing to explore how to extend our sensor deployment footprint at minimum cost. Mixed High and low interaction nodes will always require real server / PC hardware, but for a number of years I&#8217;ve been interested in using &#8220;plug and play&#8221; low interaction-only honeypots such as <a href="http://nepenthes.mwcollect.org">Nepenthes</a> malware collectors via bootable or embedded devices. These devices are much easier to mass produce and distribute to project members, and with consumer device price levels continuing to fall it has become practical to distribute such sensors on a larger scale internationally (ie hundreds rather than tens of live sensor nodes).</p>
<p>Deployment options are generally based around two models:</p>
<ol>
<li>Local sensor, with honeypot software running locally on the sensor.</li>
<li>Gateway sensor, with no honeypot software running locally and instead some form of tunnelling solution (GRE, IPSEC, OpenVPN, Honeymole, etc) being used to transparently bridge IP traffic to a central honeyfarm.</li>
</ol>
<p>I won&#8217;t go into too much detail here at this stage, but as we plan to roll out an expanded data collection system along these lines during 2008 you can expect to see more information here in the future.</p>
<p>As part of the background research into building reliable low cost low interaction honeypots, I&#8217;ve recently needed to port a number of tools such as Nepenthes to various embedded devices for testing. As this turned out to be a little more time consuming than originally expected, I&#8217;ve posted a <a href="http://www.ukhoneynet.org/research/building-nepenthes-on-the-openwrt-embedded-platform/">HOWTO guide for building Nepenthes on the OpenWRT embedded platform</a>. Hopefully this information might help anyone else interested in similar research save a few hours of confusion.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/05/07/embedded-nepenthes-malware-collection-using-openwrt/feed/</wfw:commentRss>
		</item>
		<item>
		<title>First WOMBAT workshop</title>
		<link>http://www.ukhoneynet.org/2008/04/25/first-wombat-workshop/</link>
		<comments>http://www.ukhoneynet.org/2008/04/25/first-wombat-workshop/#comments</comments>
		<pubDate>Fri, 25 Apr 2008 15:19:05 +0000</pubDate>
		<dc:creator>david</dc:creator>
		
		<category><![CDATA[Events]]></category>

		<category><![CDATA[UK presentations]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/04/25/first-wombat-workshop/</guid>
		<description><![CDATA[Jamie and myself from the UK Honeynet Project plus Max Kilger and Thorsten Holz from the UNCC and German Honeynet Project Chapters were in Amsterdam this week for the first workshop held by the European Commission&#8217;s 7th Framework WOMBAT project (see previous posts for more details).
The workshop was held at Vrije University south of the [...]]]></description>
			<content:encoded><![CDATA[<p>Jamie and myself from the UK Honeynet Project plus Max Kilger and Thorsten Holz from the <a href="http://honeynet.uncc.edu/">UNCC</a> and <a href="http://pi1.informatik.uni-mannheim.de/index.php?pagecontent=site/Research.menu/Honeynet.page">German</a> Honeynet Project Chapters were in Amsterdam this week for the first workshop held by the European Commission&#8217;s 7th Framework <a href="http://www.wombat-project.eu/">WOMBAT project</a> (see <a href="http://www.ukhoneynet.org/2008/04/04/wombat-2008-papers-accepted">previous</a> <a href="http://www.ukhoneynet.org/2008/02/20/wombat-workshop-2008">posts</a> for more details).</p>
<p>The workshop was held at Vrije University south of the city centre and included members of the WOMBAT consortium and invited guests who were active in the fields of honeynet deployments, malware analysis and large scale data collection. Over two days we were introduced to the three year WOMBAT project, its goals and members and a number of short presentations were given by the invited guests from the EU, US, Asia and Australia. David spoke about the Honeynet Project&#8217;s various data collection initiatives, including the Global Distributed Honeynet Project (<a href="http://www.ukhoneynet.org/PacSec07_David_Watson_Global_Distributed_Honeynet.pdf">GDH</a>), and Max spoken about attacker profiling models. The proceedings will be published in the journals of <a href="http://www.computer.org/security">IEEE Computer Society</a> later in the year and we&#8217;ll post them when we are able to.</p>
<p>Overall an interesting event with lots of opportunity for collaboration and information sharing that will hopefully come to fruition. Of particular interest was the honeyclient work that the Polish CERT <a href="http://www.nask.pl/nask_en/">NASK</a> were involved in, which was remarkably similar to our own recent activity on <a href="http://www.ukhoneynet.org/CanSec08_David_Watson_EvilJS.pdf" ">Evil Javascript and SpamMonkey</a> that I gave a lightning talk on at <a href="http://www.ukhoneynet.org/2008/04/03/cansecwest08/">CanSecWest08</a> last month. Like us, they hope to release their code as open source in the coming weeks and months, so we are look forward to seeing it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/04/25/first-wombat-workshop/feed/</wfw:commentRss>
		</item>
		<item>
		<title>WOMBAT 2008 papers accepted</title>
		<link>http://www.ukhoneynet.org/2008/04/04/wombat-2008-papers-accepted/</link>
		<comments>http://www.ukhoneynet.org/2008/04/04/wombat-2008-papers-accepted/#comments</comments>
		<pubDate>Fri, 04 Apr 2008 14:06:05 +0000</pubDate>
		<dc:creator>david</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[UK News]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/04/04/wombat-2008-papers-accepted/</guid>
		<description><![CDATA[We were happy to be informed that both papers submitted by The Honeynet Project to the upcoming WOMBAT honeynet workshop in Amsterdam this month have been accepted. Max Kilger and Tom Holt from the UNCC Honeynet Project Chapter will be presenting a paper on Techcrafters and Makecrafters: A Comparison of Two Populations of Hackers and [...]]]></description>
			<content:encoded><![CDATA[<p>We were happy to be informed that both papers submitted by <a href="http://www.honeynet.org">The Honeynet Project</a> to the upcoming <a href="http://wombat-project.eu/">WOMBAT</a> honeynet workshop in Amsterdam this month have been accepted. Max Kilger and Tom Holt from the <a href="http://honeynet.uncc.edu/">UNCC Honeynet Project Chapter</a> will be presenting a paper on <b>Techcrafters and Makecrafters: A Comparison of Two Populations of Hackers</b> and I will be presenting <b>Honeynet Project: Data Collection and Data Analysis</b> (with Jamie also attending). We&#8217;ll post the paper here once it has completed the review and the IEEE pre-publication process.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/04/04/wombat-2008-papers-accepted/feed/</wfw:commentRss>
		</item>
		<item>
		<title>CanSecWest08</title>
		<link>http://www.ukhoneynet.org/2008/04/03/cansecwest08/</link>
		<comments>http://www.ukhoneynet.org/2008/04/03/cansecwest08/#comments</comments>
		<pubDate>Thu, 03 Apr 2008 14:41:39 +0000</pubDate>
		<dc:creator>david</dc:creator>
		
		<category><![CDATA[Events]]></category>

		<category><![CDATA[UK presentations]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/04/03/cansecwest08/</guid>
		<description><![CDATA[I was in Vancouver last week as a backup speaker for CanSecWest08 . Once again, this was an good event, with plenty to keep me interested. It was also a great chance to catch up with Honeynet Project members, various friends in the security community and also to meet up with new people and exchange [...]]]></description>
			<content:encoded><![CDATA[<p>I was in Vancouver last week as a backup speaker for <a href="http://cansecwest.com/agenda.html">CanSecWest08</a> . Once again, this was an good event, with plenty to keep me interested. It was also a great chance to catch up with Honeynet Project members, various friends in the security community and also to meet up with new people and exchange ideas. Kudos to Dragos for another excellent event, and also to Honeynet Project alumni Shane for winning the Pwn20wn contest for the second year in a row. Presentations should be on the web site shortly.</p>
<p>In the end, and for the first time ever, all the speakers made it to the event and I didn&#8217;t need to give a repeat performance of my <a href="http://www.ukhoneynet.org/2007/12/03/global-distributed-honeynet-talk-at-pacsec07/">PacSec07 GDH presentation</a>. However, I did give a lightning talk entitled <a   href="http://www.ukhoneynet.org/CanSec08_David_Watson_EvilJS.pdf">Evil Javascript and SpamMonkey</a> that introduced a couple of projects the UK Honeynet Project team have been working on recently. You can find the slides <a href="http://www.ukhoneynet.org/CanSec08_David_Watson_EvilJS.pdf">here</a> and hopefully we&#8217;ll be releasing the code and some sample results in the coming months.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/04/03/cansecwest08/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Global Distributed Honeynet (GDH) Phase Two starting</title>
		<link>http://www.ukhoneynet.org/2008/04/02/global-distributed-honeynet-gdh-phase-two-starting/</link>
		<comments>http://www.ukhoneynet.org/2008/04/02/global-distributed-honeynet-gdh-phase-two-starting/#comments</comments>
		<pubDate>Wed, 02 Apr 2008 14:33:16 +0000</pubDate>
		<dc:creator>david</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[UK News]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/04/02/global-distributed-honeynet-gdh-phase-two-starting/</guid>
		<description><![CDATA[After doing a lot of work leading phase one of The Honeynet Project&#8217;s Global Distributed Honeynet (GDH) last year, I&#8217;m please to announce that internal development has begun on GDH Phase Two today. Initially this will result in new public Honeywall releases (version 1.4 this month integrates a second generation of our Hflow data fusion [...]]]></description>
			<content:encoded><![CDATA[<p>After doing a lot of work leading phase one of <a href="http://www.honeynet.org">The Honeynet Project&#8217;s</a> <a href="http://www.ukhoneynet.org/2007/12/03/global-distributed-honeynet-talk-at-pacsec07/">Global Distributed Honeynet (GDH)</a> last year, I&#8217;m please to announce that internal development has begun on <b>GDH Phase Two</b> today. Initially this will result in new public <a href="https://projects.honeynet.org/honeywall">Honeywall</a> releases (<b>version 1.4</b> this month integrates a second generation of our <a href="https://projects.honeynet.org/hflow">Hflow</a> data fusion tool, followed by <b>version 1.5 </b> which will hopefully support attacker source IP to keystroke mapping in all <a href="https://projects.honeynet.org/sebek">Sebek</a> related tools at last! Hopefully the three month kick start phase will be extended throughout 2008 and we&#8217;ll be releasing lots of interesting research data once an expanded global sensor network is operational. GDH Phase Two will include also client honeypots (based on <a href="https://projects.honeynet.org/capture">Capture-HPC</a>) and should also see some long overdue improvements to our <a href="https://projects.honeynet.org/honeysnap">Honeysnap</a> reporting tool too.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/04/02/global-distributed-honeynet-gdh-phase-two-starting/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Capture-HPC version 2.1 released</title>
		<link>http://www.ukhoneynet.org/2008/03/27/capture-hpc-version-21-released/</link>
		<comments>http://www.ukhoneynet.org/2008/03/27/capture-hpc-version-21-released/#comments</comments>
		<pubDate>Thu, 27 Mar 2008 15:16:45 +0000</pubDate>
		<dc:creator>Steve</dc:creator>
		
		<category><![CDATA[Tool Releases]]></category>

		<category><![CDATA[attacks]]></category>

		<category><![CDATA[capture-hpc]]></category>

		<category><![CDATA[client-side]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/03/27/capture-hpc-version-21-released/</guid>
		<description><![CDATA[A new release of Capture-HPC has been made available: 
&#8220;The Honeynet Project (http://www.honeynet.org) and School of Mathematics, Statistics and Computer Science at Victoria University of Wellington (http://www.mcs.vuw.ac.nz/) are excited to announce the release of Capture-HPC v2.1. Capture-HPC is an innovative security product that is able to find and investigate the increasing problem of client-side computer [...]]]></description>
			<content:encoded><![CDATA[<p>A new release of Capture-HPC has been made available: </p>
<p><i>&#8220;The Honeynet Project (<a href="http://www.honeynet.org">http://www.honeynet.org</a>) and School of Mathematics, Statistics and Computer Science at Victoria University of Wellington (<a href="http://www.mcs.vuw.ac.nz/">http://www.mcs.vuw.ac.nz/</a>) are excited to announce the release of Capture-HPC v2.1. Capture-HPC is an innovative security product that is able to find and investigate the increasing problem of client-side computer attacks. This new software release increases the features and speeds performance allowing anyone to investigate a larger range and quantity of client-side computer attacks. Capture-HPC is freely available from our web site at:  <a href="https://projects.honeynet.org/capture-hpc/wiki">https://projects.honeynet.org/capture-hpc/wiki</a>. It is written and distributed under the GNU General Public License, v2.&#8221;</b></i></p>
<p>Improvements include better performance, increased data capture and a new client plug-in framework.</p>
<p>The full press release can be found here:</p>
<p><a href="http://www.honeynet.org/press/honeynet-project-press-release-capture-hpc.pdf">http://www.honeynet.org/press/honeynet-project-press-release-capture-hpc.pdf</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/03/27/capture-hpc-version-21-released/feed/</wfw:commentRss>
		</item>
		<item>
		<title>New version of Argos honeypot released</title>
		<link>http://www.ukhoneynet.org/2008/03/11/new-version-of-argos-honeypot-released/</link>
		<comments>http://www.ukhoneynet.org/2008/03/11/new-version-of-argos-honeypot-released/#comments</comments>
		<pubDate>Tue, 11 Mar 2008 12:59:35 +0000</pubDate>
		<dc:creator>david</dc:creator>
		
		<category><![CDATA[Tool Releases]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/04/11/new-version-of-argos-honeypot-released/</guid>
		<description><![CDATA[The team over at Vrije University in Amsterdam (the location for the upcoming invite-only WOMBAT honeynet data sharing workshop) have released a new version of their Argos honeypot tool:
http://www.few.vu.nl/argos/
This interesting honeypot system uses dynamic taint analysis to track network data and identify unknown malware. So far we&#8217;ve only experimented with it, but it looks like [...]]]></description>
			<content:encoded><![CDATA[<p>The team over at Vrije University in Amsterdam (the location for the upcoming invite-only <a href="http://www.wombat-project.eu/">WOMBAT</a> honeynet data sharing workshop) have released a new version of their Argos honeypot tool:</p>
<p><a href="http://www.few.vu.nl/argos/">http://www.few.vu.nl/argos/</a></p>
<p>This interesting honeypot system uses dynamic taint analysis to track network data and identify unknown malware. So far we&#8217;ve only experimented with it, but it looks like a promising project and an ideal companion to <a href="http://nepenthes.sourceforge.net">Nepenthes</a> based capture of known malware variants.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/03/11/new-version-of-argos-honeypot-released/feed/</wfw:commentRss>
		</item>
		<item>
		<title>UKHP attend ISOI4</title>
		<link>http://www.ukhoneynet.org/2008/03/04/ukhp-attend-isoi4/</link>
		<comments>http://www.ukhoneynet.org/2008/03/04/ukhp-attend-isoi4/#comments</comments>
		<pubDate>Tue, 04 Mar 2008 12:45:54 +0000</pubDate>
		<dc:creator>david</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/03/04/ukhp-attend-isoi4/</guid>
		<description><![CDATA[I was one of the attendees at the fourth ISOI workshop last week, which this time was held in sunny San Jose. Once again, the event had an interesting range of presentations and discussions, mostly focused around what system defenders could do now to make a difference to the continuing tide of cybercrime observed every [...]]]></description>
			<content:encoded><![CDATA[<p>I was one of the attendees at the fourth <a href="http://www.isotf.org/isoi4.html">ISOI</a> workshop last week, which this time was held in sunny San Jose. Once again, the event had an interesting range of presentations and discussions, mostly focused around what system defenders could do now to make a difference to the continuing tide of cybercrime observed every day. There was also plenty of opportunity to catch up with people in the security community, and put faces to names, so thanks to Gadi and co for the continued invites. I also got a bit of time to hang out with various <a href="http://www.honeynet.org">Honeynet Project</a> people and some of the guys from <a href="http://www.shadowserver.org">Shadowserver</a>, and hopefully we&#8217;ll see some interesting spin offs in the coming months. Being from the UK, the obligatory Silicon Valley geek tourism was also fun too.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/03/04/ukhp-attend-isoi4/feed/</wfw:commentRss>
		</item>
		<item>
		<title>WOMBAT Workshop 2008</title>
		<link>http://www.ukhoneynet.org/2008/02/20/wombat-workshop-2008/</link>
		<comments>http://www.ukhoneynet.org/2008/02/20/wombat-workshop-2008/#comments</comments>
		<pubDate>Wed, 20 Feb 2008 12:59:36 +0000</pubDate>
		<dc:creator>david</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/02/20/wombat-workshop-2008/</guid>
		<description><![CDATA[The Honeynet Project have been invited to submit a paper to the upcoming invite-only Worldwide Observatory of Malicious Behaviors and Attack Threats (a href=&#8221;http://wombat-project.eu&#8221;>WOMBAT) honeynet workshop at Vrije University in Amsterdam on the 21st and 22nd of April. David and Jamie from the UKHP will be organising the Honeynet Project&#8217;s submissions, and we hope to [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.honeynet.org">The Honeynet Project</a> have been invited to submit a paper to the upcoming invite-only Worldwide Observatory of Malicious Behaviors and Attack Threats (a href=&#8221;http://wombat-project.eu&#8221;>WOMBAT</a>) honeynet workshop at Vrije University in Amsterdam on the 21st and 22nd of April. David and Jamie from the UKHP will be organising the Honeynet Project&#8217;s submissions, and we hope to have at least one presentation accepted for publication in the journal of the IEEE.</p>
<p>For more details see <a href="http://wombat-project.eu/2008/04/wombat-closed-workshop-april-2.html">http://wombat-project.eu/2008/04/wombat-closed-workshop-april-2.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/02/20/wombat-workshop-2008/feed/</wfw:commentRss>
		</item>
		<item>
		<title>New release of the Honeywall CDROM</title>
		<link>http://www.ukhoneynet.org/2008/01/04/new-release-of-the-honeywall-cdrom/</link>
		<comments>http://www.ukhoneynet.org/2008/01/04/new-release-of-the-honeywall-cdrom/#comments</comments>
		<pubDate>Fri, 04 Jan 2008 14:01:57 +0000</pubDate>
		<dc:creator>arthur</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[Tool Releases]]></category>

		<guid isPermaLink="false">http://www.ukhoneynet.org/2008/01/04/new-release-of-the-honeywall-cdrom/</guid>
		<description><![CDATA[There&#8217;s a new (beta) release of the Honeynet Project&#8217;s &#8220;Honeywall&#8221; CDROM out. This release (1.3b) fixes some bugs but the main change is a move from the no longer supported Fedora Core 6 platform to CentOS 5. This should give us less work keeping the base platform up to date and more time to work [...]]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s a new (beta) release of the Honeynet Project&#8217;s &#8220;Honeywall&#8221; CDROM out. This release (1.3b) fixes some bugs but the main change is a move from the no longer supported Fedora Core 6 platform to CentOS 5. This should give us less work keeping the base platform up to date and more time to work on adding cool new features <img src='http://www.ukhoneynet.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>We&#8217;ve also moving to a more open development model for the CDROM. Although it&#8217;s always been GPL&#8217;d, the development processes has been closed and it&#8217;s been hard for outsiders to add features/hack code. I&#8217;m pleased to say that that&#8217;s now changed, and there&#8217;s a new <a href="https://projects.honeynet.org/honeywall">Trac site</a> with a svn tree, wiki and all the usual stuff. The <a href="https://public.honeynet.org/mailman/listinfo/honeywall">Honeywall public mailing list</a> is also still available.</p>
<p>Cool stuff that will be coming in the future includes a move to <a href="http://www.cs.indiana.edu/~cviecco/oscode/hflow2.htm"> hflow2</a> for better flow decoding and analysis and changes to the build processes to make it easier to use.</p>
<p>Credits: Earl Sammons, Rob McMillen and myself did the CentOS port. Steve Mumford and Dave Watson did all the work in setting up our new infrastructure to enable more open development.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukhoneynet.org/2008/01/04/new-release-of-the-honeywall-cdrom/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
