Advanced Attacker Detection and Understanding with Emerging Honeynet Technologies

Ronald C. Dodge Jr., Thorsten Holz, Anton A. Chuvakin · Wiley Handbook of Science and Technology for Homeland Security · 2008

Abstract The world is more and more reliant on information technology in every sector. Power interconnects rely on it to balance generation and transmission, hospitals use it to manage patient care, and financial businesses rely on it in virtually every transaction. The IT infrastructure that runs the services that we rely on is a tempting target. The attacker community is motivated by many factors, but the common thread is financial gain. The attacker continues to morph its tactics and techniques, attacking both infrastructure and end users with firewall and intrusion detection system ( IDS ) evading attacks. The first imperative in defending our infrastructure is understanding how the attacker operates. One of the most innovative technologies for the past decade is the honeynet. The current and emerging honeynet technologies can provide network security personnel with advance warning and attack understanding, beyond the capability of other security technologies.

Read the paper · More papers on PaperTik