网络伪装--网络安全

首页 » 技术文章 » 蜜罐技术
蜜罐技术

蜜罐技术 (13)

使用 QEMU 进行系统仿真

作者 Dr.H 2008-10-29 13:06 阅读 5626
QEMU 是一个面向完整 PC 系统的开源仿真器。除了仿真处理器外,QEMU 还允许仿真所有必要的子系统,如连网硬件和视频硬件。它还允许实现高级概念上的仿真(如对称多处理系统(多达 255 个 CPU)和其他处理器架构(如 ARM 和 PowerPC)。本文将研究 QEMU 及其架构,并展示了如何在 Linux® 主机上仿真来宾操作系统。

 

最后修改日期: 2011-05-07 17:50

HoneySpot: The Wireless Honeypot

作者 Dr.H 2008-04-15 10:52 阅读 3794

homepage

Monitoring the Attacker’s Activities in Wireless Networks
A design and architectural overview

We’ve been developing a paper to create awareness and help to guide the deployment of wireless honeypots, mainly centered on 802.11 (WiFi) technologies. The paper is focused on providing a design and architectural overview for the deployment of wireless honeypots, coined as HoneySpots.

We’re currently involved in deploying these technologies, capture attacks and related information, develop analysis tools, and will publish a future paper with the findings. Meanwhile, we would like to publicly promote the deployment of these technologies by releasing this paper. If you are interested in developing or/and deploying wireless honeynets, contact us at project at (removethis)honeynet.org.es. The Spanish Honeynet Project wants to promote this research area, including multiple wireless technologies, mainly 802.11 and Bluetooth today, with future additions such as WiMAX.

 

最后修改日期: 2008-04-16 23:04

Know your Enemy:Web Application Threats

作者 Dr.H 2008-04-15 08:45 阅读 6070
最后修改日期: 2011-05-07 17:52

GHH: Google Hack Honeypot

作者 Dr.H 2008-04-15 08:40 阅读 2819

Link to Homepage

What is GHH?
Google Hack Honeypot is the reaction to a new type of malicious web traffic: search engine hackers. GHH is a “Google Hack” honeypot. It is designed to provide reconaissance against attackers that use search engines as a hacking tool against your resources. GHH implements honeypot theory to provide additional security to your web presence. 

最后修改日期: 2011-05-07 17:52

Kojoney - A honeypot for the SSH Service

作者 Dr.H 2008-04-15 08:27 阅读 3393

Link To Homepage

Download

What is kojoney?

Kojoney is a low level interaction honeypot that emulates an SSH server. The daemon is written in Python using the Twisted Conch libraries.

最后修改日期: 2011-05-07 17:53

HIHAT: High Interaction Honeypot Analysis Toolkit

作者 Dr.H 2008-04-12 16:51 阅读 2694
The High Interaction Honeypot Analysis Toolkit (HIHAT) allows to transform arbitrary PHP applications into web-based high-interaction Honeypots. Furthermore a graphical user interface is provided which supports the process of monitoring the Honeypot and analysing the acquired data.
最后修改日期: 2008-04-12 17:13

About Honey@Home project

作者 Dr.H 2008-04-07 21:03 阅读 3832
Honey At Home is the "@home" implementation of the NoAH project, aiming to facilitate the gathering of information on cyber-attacks. It is designed to be simple to manage and lightweight on system resource usage .Many broadband connections offer the end user an option that was not available up until now: allocating more than one IP addresses for one connection. Bussiness connectivity packages available to small-to-medium enterprises usually make available blocks of four up to eight IP addresses. However, not all of them are used, creating an opportunity for NoAH to manage this space. An increased geographical coverage enables researchers in the NoAH project to better understand the spread of malware. Just like other "@home" approaches, which take advantage of processing power available on idle desktops, honey@home takes advantage of "idle" IP address.
最后修改日期: 2008-04-07 21:14

About NoAh Project

作者 Dr.H 2008-04-07 20:59 阅读 4751

Introduction

NoAH is a three-year project to gather and analyse information about the nature of Internet cyberattacks. It will also develop an infrastructure to detect and provide early warning of such attacks, so that appropriate countermeasures may be taken to combat them.

最后修改日期: 1999-11-30 08:00

Argos: an emulator for Capturing Zero-day attacks

作者 Dr.H 2008-04-07 20:39 阅读 4526

  Download Atgos

  What is Argos? 

   Argos is a full and secure system emulator designed for use in honeypots. It is based on Qemu, an open source emulator that uses dynamic translation to achieve a fairly good emulation speed.

最后修改日期: 2008-04-08 16:17

Nepenthes 构建蜜罐,模拟漏洞

作者 Dr.H 2007-11-21 23:29 阅读 2887

 

gz libemu-0.1.0.tar1195629932 21/11/2007,15:25 549.31 Kb

gz nepenthes-0.2.0.tar1195629940 21/11/2007,15:25 891.87 Kb

1. What is Nepenthes?

    Nepenthes is a low interaction honeypot like honeyd or mwcollect. Low Interaction Honeypots emulate _known_ vulnerabilities to collect information about potential attacks. Nepenthes is designed to emulate vulnerabilties worms use to spread, and to capture these worms. As there are many possible ways for worms to spread, Nepenthes is modular. There are module interface to

  • resolve dns asynchronous
  • emulate vulnerabilities
  • download files
  • submit the downloaded files
  • trigger events (sounds abstract and it is abstract but is still quite useful)
  • shellcode handler
最后修改日期: 2007-11-22 17:46
页数 1 / 2