Honeynets: foundations for the development of early warning information systems. Pouget, F, Dacier, M, Pham, V., & Debar, H In Kowalik, J., Gorski, J., & Sachenko, A., editors, Cyberspace Security and Defense: Research Issues, volume 196, of NATO Science Series II: Mathematics, Physics and Chemistry, pages 231--257. Springer Netherlands, 2005. 00016 bibtex: pouget2005honeynets
Honeynets: foundations for the development of early warning information systems [link]Paper  abstract   bibtex   
This paper aims at presenting in some depth the “Leurré.com” project and its first results. The project aims at deploying so-called low level interaction honeypot platforms all over the world to collect in a centralized database a set of information amenable to the analysis of today's Internet threats. At the time of this writing, around two dozens platforms have been deployed in the five continents. The paper offers some insight into the findings that can be derived from such data set. More importantly, the design and the structure of the repository are presented and justified by means of several examples that highlight the simplicity and efficiency of extracting useful information out of it. We explain why such low cost, largely distributed system represents an important, foundational element, towards the building of early warning information systems.
@incollection{ pouget_honeynets:_2005,
  series = {{NATO} {Science} {Series} {II}: {Mathematics}, {Physics} and {Chemistry}},
  title = {Honeynets: foundations for the development of early warning information systems},
  volume = {196},
  isbn = {978-1-4020-3379-7},
  url = {http://link.springer.com/chapter/10.1007%2F1-4020-3381-8_13},
  abstract = {This paper aims at presenting in some depth the “Leurré.com” project and its first results. The project aims at deploying so-called low level interaction honeypot platforms all over the world to collect in a centralized database a set of information amenable to the analysis of today's Internet threats. At the time of this writing, around two dozens platforms have been deployed in the five continents. The paper offers some insight into the findings that can be derived from such data set. More importantly, the design and the structure of the repository are presented and justified by means of several examples that highlight the simplicity and efficiency of extracting useful information out of it. We explain why such low cost, largely distributed system represents an important, foundational element, towards the building of early warning information systems.},
  booktitle = {Cyberspace {Security} and {Defense}: {Research} {Issues}},
  publisher = {Springer Netherlands},
  author = {Pouget, F and Dacier, M and Pham, VH and Debar, H},
  editor = {Kowalik, Janusz and Gorski, Janusz and Sachenko, Anatoly},
  year = {2005},
  note = {00016 bibtex: pouget2005honeynets},
  keywords = {Cybercrime, Database, Honeynet, Internet Attacks, malware},
  pages = {231--257}
}

Downloads: 0