Honeypots mailing list archives
Re: search for master of science project topic
From: Nomellames nunca <nomesigas () gmail com>
Date: Sun, 16 Oct 2005 16:10:56 -0400
Hi all, That was a recent paper at USENIX security 05 , so yes *it has been done before*. But still a promising field of research, trying to maximize how this is done practically. The name they gave to such a "switch" is shadow honeypots, which I believe is a trendy name. http://dcs.ics.forth.gr/Activities/papers/replay.pdf Best, Jesus On 10/14/05, Harry Hoffman <hhoffman () ip-solutions net> wrote:
Hmm, I think something similar to this can be done with Xen. http://www.cl.cam.ac.uk/Research/SRG/netos/xen/readmes/user/user.html#SECTION02430000000000000000 Although I believe you have to migrate all processes and memory. This might actually be fun to play with Cheers, Harry Stejerean, Cosmin wrote:What you mentioned sounds a lot like a bait and switch honeypot. Ibelievethe idea is to migrate both the process in question and the connectiontothe honeypot so if a vulnerable server is exploited with a bufferoverflowattack the process will be migrated to the honeypot and any connectionfromthe attack will be redirected to the honeypot. This would be a stepfurtherthan regular network based bait and switch honeypot because the HIDSwouldbe able to detect when a process makes unusual system calls etc, as wellastransfer the process image and everything else to the honeypot. The difficulty is in carefully migrating the process over and decidingwhatcan or cannot be migrated. Cosmin
Current thread:
- search for master of science project topic dewadedw (Oct 09)
- 100% CPU utilization ???? George Kryparos (Oct 12)
- <Possible follow-ups>
- RE: search for master of science project topic Payton, Zack (Oct 11)
- Re: search for master of science project topic Valdis . Kletnieks (Oct 11)
- Re: search for master of science project topic NAHieu (Oct 12)
- Re: search for master of science project topic Valdis . Kletnieks (Oct 12)
- Re: search for master of science project topic Valdis . Kletnieks (Oct 11)
- Re: RE: search for master of science project topic gangadhar npk (Oct 14)
- Re: search for master of science project topic Packet Man (Oct 14)
- RE: search for master of science project topic Stejerean, Cosmin (Oct 14)
- Re: search for master of science project topic Harry Hoffman (Oct 14)
- Re: search for master of science project topic Nomellames nunca (Oct 16)
- Re: search for master of science project topic Harry Hoffman (Oct 14)