Honeynet/Honeypot Project
Leslie Cherian, Todd Deshane, Wenjin Hu, Patty Jablonski, Cyrus Katrak, Creigh Long

The goal for this project is to set up a honeypot virtual machine to research and analyze various attacks. We have installed Microsoft Windows in a virtual machine using VMware and plan to install intrusion detection systems like Snort and Tripwire, the filemon file monitor, the regmon registry monitor, and other monitoring utilities. With this virtual machine appliance, we hope to have a well-documented and easy-to-use "malware analyzer" that reports on the degree of malicious intent of a given piece of software. We have been reading work from a Masters thesis on the honeypot topic for more ideas. We are collecting links and are documenting the creation of the honeypot so that it is easier for others to follow. We have also looked into joining the Honeynet Research Alliance.

Meetings: Thursdays 7:00pm or 8:00pm in the ITL
Background Material:
Honeypot Masters Thesis
DVD Contents |  Read Me

Honeynets & Honeypots:
Honeyblog, Honeynet News
Honeynet Definitions/Value
Honeynets, Tracking Botnets
Honeynet Web Movie
Know Your Enemy Book

Virtual Networks:
VMware Virtual Networks
VMware Server Admin
VMware Server VM Manual

The Honeynet Project:
The Honeynet Project
Join The Research Alliance
Research Alliance Charter
Honeynet Project Presentation

Honeynet Project Tools:
Honeynet Project Tools
Honeywall |  Roo
HoneyMole |  Sebek

Attack Analysis:
Well-known Ports |  Attacks List
Known Attacks on Ports (broken)
Spyware |  Malware |  Secunia
Alexa Toolbar |  NetBus

Intrusion Detection / Monitoring:
Snort Intrusion Detection System:
Snort IDS (Official) |  Winsnort
Snort (Windows) |  Snort Rules
Rules |  Writing Rules |  HowTo
Bleeding Snort |  Rule Mgr |  HowTo
Oinkmaster Rule Manager |  HowTo
Snort Policy Manager (Windows)
Barnyard Log Parser (Windows)

Tripwire Intrusion Detection System:
Tripwire |  Tripwire (Open Source)
Tripwire Flowchart |  TFS Intro

Sysinternals Monitoring Tools:
Filemon |  Regmon |  Utilities

Project Deliverables:
Honeypot Architecture
Research on Snort Rules
Attack Using Nmap (.cap)
Installing Alexa (.cap)
Installing Alexa Report
After Alexa Uninstall
After Manual Uninstall
The Snort Alert Log
NetBus Connection (.cap)
Our DVD Contents
HowTo Documentation
Our Final Presentation

Meetings / Status:
3/23/06 |  3/30/06 |  4/6/06
4/24/06 |  4/25/06 |  4/26/06
4/29/06 |  4/30/06 |  5/1/06