Improving Honeynet Data Analysis
Camilo H. Viecco · 2007
The honeywall's hflow and walleye interface first introduced in[1] vastly improved honeynet data analysis by integrating different data sources and thus reducing the time required for analyzing honeynet data. However, there are some open architectural questions. This paper answers some of these questions by introducing a packet processing language that allows a modular architecture. This architecture not only solves the immediate problems but is also applicable to a wide range of problems. We present data regarding the problems of the old architecture and present our solution. We also present some of performance envelopes of both architectures.