9.25.2007

Project Goals

  1. To implement a Linux Gen III HoneyNet setup using the Honeynet Roo CD in the CSUS RVR 2003 lab
  2. To simulate an attack and demonstrate the basic capabilities of the Honeynet like -
    1. Data Control
      1. Firewall capabilities towards access control
      2. Intrusion Prevention capabilities towards examining outgoing packets for malicious signatures
      3. Connection rate limiting
      4. Dropping packets with malicious signatures
      5. Modifying malicious packets
    2. Data Capture
      1. Sources and times of attacks
      2. Network packets
      3. Attack signatures
      4. App and system logs
      5. Keystrokes
    3. Data Analysis
      1. Inbound and Outbound Connection patterns
      2. Activity signatures
      3. Network activity
      4. Keystrokes
  1. To enhance the capabilities of the setup using IDS
    1. Using anomaly-based IDS to detect new attack signatures
  2. To simulate an attack and demonstrate the enhancements that IDS brings to the setup
    1. Detect new attack signature
  3. To produce reports from analysis of the systems compromised during the attack
    1. Sources and times of attacks
    2. Network packets
    3. Attack signatures
    4. App and system logs
    5. Keystrokes
Links

http://www.nku.edu/~waldenj1/talks/honeynets.html
http://www.honeynet.org/alliance/requirements.html
http://www.blackhat.com/presentations/bh-usa-05/bh-us-05-harper.pdf
http://seclists.org/focus-ids/2003/Mar/0038.html
http://www.securityfocus.com/infocus/1663