______________________________________________________________________________ HONEYNET/HONEYPOT PROJECT ______________________________________________________________________________ Meeting: 4/24/06 7:00pm, ITL Attendees: Leslie, Todd, Patty, Creigh Meeting Duration: Approx. 2 hours ______________________________________________________________________________ Accomplishments: ______________________________________________________________________________ 1) Bought a single license of Tripwire with the lab budget. Read the EULA (we can use either Windows or Linux version of Tripwire, one at a time). 2) Downloaded and installed Tripwire on Windows on a test machine - need to configure it. To initialize the database, use the command: tripwire --init To do an integrity check, use the command: tripwire --check 3) Organize/make plan for project goals and deadlines for the next few days. ______________________________________________________________________________ TO-DO List: ______________________________________________________________________________ 1) Leslie report on configuration of Tripwire. 2) Creigh report on Snort rules. 3) Todd report on Regmon. 4) Patty report on attacks for Windows. ***** Patty and Todd will create a diagram of VMware virtual networks. ***** ______________________________________________________________________________ Honey Project Goals: ______________________________________________________________________________ 1) Determine Windows or Linux for monitoring on. 2) Tripwire (vs. Filemon) (config) - Leslie. 3) Snort (rules, etc) - Creigh. 4) Regmon (everything) - Todd. 5) Attacks (testing) - Patty. 6) Docs (user level, flowchart for attack analysis, and howto) - Patty. 7) Design a GUI for our system (Snort-Win/Lin, Tripwire-MFC,PyGTK?).