Using PFSense and commodity hardware as a medium interaction honey-net

Chlapoutakis, G. (Georgios), Laskos, A. (Anastasios), Brooke, P. J. (Phillip), Mark Truran · 2010

Honey-pots and honey-nets are network-accessible decoy resources designed to attract unauthorized users, thereby deflecting their attention from security-critical systems. Combined with a process known as a LaBrea tar pit, honey-net and honey-pots can effectively entrap suspicious connection attempts and prevent the proliferation of further attacks via the host network. Use of these ‘sticky’ honey-pots and honey-nets is quite common within the network security community, and several ‘off the shelf’ solutions are available to individuals and commercial clients alike. In this paper we describe a LaBrea tar-pit honey-net solution specifically designed for researchers interested in network security. Unlike the various honey net solutions mentioned above, this solution gives the user direct access to raw, packet-level data. Our reference implementation is built around a customized firewall distribution which acts as the honey-net bridge. This bridge uses an BSD-based firewall distribution known as PFSense in combination with a highly customizable network packet capturing facility called tcpdump. The contribution of this work is twofold. Firstly, our reference implementation will enable researchers to quickly deploy a medium interaction honey-net network (with LaBrea Tar-pit functionality) that is more secure, more adaptable and more upgradeable than comparable systems. Secondly, our reference implementation will allow researchers to transparently gather raw, live-traffic data without the additional overhead of performing on-site traffic analysis. It is hoped that this will stimulate higher quality dataset collection throughout the network security field. School of Computing, Teesside University, United Kingdom, [email protected] School of Computing, University of Sunderland, United Kingdom, [email protected] School of Computing, Teesside University, United Kingdom, [email protected] School of Computing, Teesside University, United Kingdom, [email protected]

Read the paper · More papers on PaperTik