Re: RES: Protocol Anomaly Detection IDS - Honeypots

From: Lance Spitzner (lance@honeynet.org)
Date: 02/21/03

  • Next message: Mike Shaw: "Re: RES: Protocol Anomaly Detection IDS - Honeypots"
    Date: Fri, 21 Feb 2003 10:36:56 -0600 (CST)
    From: Lance Spitzner <lance@honeynet.org>
    To: Augusto Paes de Barros <augusto@paesdebarros.com.br>
    
    

    On Fri, 21 Feb 2003, Augusto Paes de Barros wrote:

    > Lance's point can be expanded in very interesting views. Why use only
    > honeypots "hosts" or "nets", when whe can use accounts, documents, info,
    > etc? I was developing an idea that I call "honeytokens", to use on Windows
    > networks. Basically, information that shouldn't be flowing over the network
    > and, if you can detect it, something wrong is happening.

    Ohh, ooh! Very cool suggestion Augusto! This is something I never
    thought of. Create documents, webpages, or resources that no one should
    be accessing. You create these resources with specific, obvious signatures
    so your detections mechanisms (logs, IDS sensors, etc) can easily pick
    them up. If you detect these resources being moved around your network,
    you know something is up!

    For example, you create a word document that has the title of payroll
    or 'research and development'. You put whatever fluff you want in the
    document, and give it a "tracking number", such as 14A8478bG98734T90AAZ.
    Now, you simply create a signature looking for that "tracking number".
    The concept would be to create resources that no one should be accessing
    (the honeytoken) but is easily detectable if they do. You would have to
    ensure the signature, as in this case the tracking number, is unique enough
    that it minizimes, if not eliminate, false positives.

    This potentially opens a whole new world to honeypot concepts :)

    very cool :)

    lance

    -----------------------------------------------------------
    Does your IDS have Intelligent Attack Profiling?
    If not, see what you're missing.
    Download a free 15-day trial of StillSecure Border Guard.
    http://www.securityfocus.com/stillsecure



    Relevant Pages

    • Re: Resource Work Completed PWA
      ... Given your tracking needs, I believe that using the % Work Complete method ... In the Time period settings section, select the "Resources should report ... you will need to ask each of your project managers to ... timesheet for every task in every project. ...
      (microsoft.public.project.pro_and_server)
    • RE: RES: Protocol Anomaly Detection IDS - Honeypots
      ... and other openable items for an internal honeypot. ... Create documents, webpages, or resources that no one should ... > document, and give it a "tracking number", such as 14A8478bG98734T90AAZ. ... > Does your IDS have Intelligent Attack Profiling? ...
      (Focus-IDS)
    • RE: RES: Protocol Anomaly Detection IDS - Honeypots
      ... I was thinking about tracking info too. ... Encryption and the compression are ... Assunto: RE: RES: Protocol Anomaly Detection IDS - Honeypots ... Create documents, webpages, or resources that no one ...
      (Focus-IDS)
    • Planning and tracking project
      ... I have some "beginners" questions on planning and tracking, ... My project has roughly a dozen team ... So I thought, well some of the resources have very similar skills, why ... increased the availability of "Developer" to 200%. ...
      (microsoft.public.project)
    • Re: Start versus Actual Start...
      ... Your questioon has a simple answer. ... Always ask for remaining work and enter that when tracking as well. ... > estimated, resources assigned at 100%, resources leveled ... > neither of these dates are the "Baseline Date". ...
      (microsoft.public.project)