Honeynets: Trapping attackers and naming names

security.itworld.com |  Security 1 comment

The Web Honeynet Project, an independent group of Honeynet researchers from Securiteam and the ITOSF have decided to launch web application honeynets with a new twist. The twist is, they plan to name not only the attack details, as is usual, but also to divulge the IP addresses and other tracking information about the attackers themselves.

This approach is not unheard of, as lists of known high-volume attackers have been circulating through the Net for several years, but this is the first time someone has applied the honeynet concept to making attacker IP data publicly known, as far as I know. The team claims that attackers are now compromising web servers for defacement and bot-net activity on a wide scale. They hope to lower the impact of these assaults and help organizations and individuals protect themselves from known attacker IPs.

The project claims that the primary focus of these attackers has been Windows and Linux servers, and that the compromises are largely performed through PHP vulnerabilities that have been commonly known for some time. This fits the usual pattern of large-scale bot-net activity, only this time instead of targeting end-user systems with known weaknesses, the targets are web servers around the world. In the past, huge bot-net infestations have been identified where the compromises were linked to known security issues, some as old as 1998!

Hopefully, the Web Honeynet Project will find an effective means of communicating and managing their data so that they can create a useful list of current attackers that organizations can add to their security systems in an automated fashion. At the very least, maybe the release of tracking and identity data will shame attackers into curbing their behavior, though that seems highly unlikely in most cases.

Honeynets and honeypots are proving to be an interesting technology that many organizations and individuals seem to be embracing. If we are to move forward as infosec practitioners and better protect our assets in an ever more hostile cyber world, we must come to terms with understanding attackers, their techniques and their behaviors. These tools may be the key to that insight, and the Honeynet Projects are a great resource for getting started.

Note: In the interest of full disclosure, my company, MicroSolved, Inc. sells a honeypot solution that we have created for organizations of various sizes.

1 comment

    Anonymous 1 year ago
    Honeynet really provides latest and interesting technology that cannot be compromised by any hackers.Web Design Los Angeles, Ecommerce Web Design Company Los Angeles, Web design Santa Monica

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      SecurityWhite Papers & Webcasts

      White Paper

      Overcome Top 7 Admin Challenges of Active Directory

      As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

      White Paper

      Insiders Can Ruin Your Company. Take Action.

      Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

      White Paper

      Top Solutions and Tools to Prevent Devastating Malware

      Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

      White Paper

      Streamline Compliance and Increase ROI

      Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

      White Paper

      X-Ray of the PCI Process-4 Proactive Steps

      This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

      See more White Papers | Webcasts

      Ask a question

      Ask a Question