Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector Background.

39
Honey Inspector Mike Clark Honeynet Project
  • date post

    21-Dec-2015
  • Category

    Documents

  • view

    226
  • download

    0

Transcript of Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector Background.

Page 1: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Honey Inspector

Mike Clark

Honeynet Project

Page 2: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Honeynet Inspector

Background

Page 3: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

What is it?

Set of Perl CGI Scripts Firewall/IDS Logs MySQL IDS

Page 4: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

How it Works

Fisq script imports firewall logs IDS(Snort) logs to the DB IDS(Snort) also records traffic in pcap format Inspector drills down using all of these

Page 5: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Inspector High Level

Shows connections and drill down options 4 methods of alerting

Packet Count Connection size (byte) IDS(Snort) alerts Inbound/Outbound

Page 6: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Drilling Down

Connection View Arin/whois/dig lookup Snort alerts p0f Plugins

Page 7: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Plugins

Honey Extractor IRC View

Page 8: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Advantages

Quick Easily extendable High chance of detecting activity Web based

Page 9: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Disadvantages

Not scalable Not very nice looking

Page 10: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Future

Perl module Nicer interface Graphing Customizable Report Engine

Page 11: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Questions?

Page 12: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Enterprise Security Console

Jeff Dell

Activeworx, Inc.

Page 13: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Speaker

Jeff Dell, Florida Honeynet Project Florida Honeynet: Responsible Network

Forensics Honeynet Alliance: Central Database

Page 14: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Problem

How do we look at different datasets from different data sources and correlate the information?

Page 15: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

1st Problem

The Data

Page 16: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

FW Logs

Page 17: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Snort Logs

Page 18: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

TCPDump

Page 19: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

2nd Problem

Data Sources

Page 20: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Different Data Sources

DMZ TCPDump

DMZ Firewalls

Internal IDS

DMZ Syslog

Internal Syslog

External IDS

Page 21: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Solution

Centralizing Honeynet Data Enterprise Security Console to view data

Page 22: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Data Centralization

Centralized Database

IDS Logs Firewall Logs System Logs TCPDump Logs

Page 23: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

What Next?

Page 24: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Enterprise Security Console

Advantages Easy to View Data Very flexible and powerful GUI Strong Data Correlation Capabilities Built with Honeynets in mind

Disadvantages Windows 2000/XP Only

Page 25: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Enterprise Security Console

Console to view Databases Fully Database Driven Supports multiple ESC Databases Supports multiple Data Databases

Laptop

FW Database

ESC Database

Snort Database TCPDump Database

FW Database

ESC Database

Snort Database TCPDump Database

Page 26: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Types of Data

Firewall Logs Snort IDS Logs TCPDump Logs Syslog Prelude (Hybrid IDS) Others…

Page 27: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Easy to View Data

Page 28: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Data Search Correlation

Correlate between any the following data types:

FirewallS

yslo

g

TCPDump

IDS

Page 29: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Data Correlation (Cont)

View Firewall Logs Advantages

Easy Fast Have some interesting information

Disadvantages Limited information

Page 30: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Data Correlation (Cont)

View IDS Logs Advantages

More interesting events Alert on attacks

Disadvantages Does not pick up all attacks Only see a single packet

Page 31: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Data Correlation (Cont)

TCPDump Logs Advantages

All packets

Disadvantages Lots of data

Page 32: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Data Decode

Full Packet Decode

Page 33: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

IRC Decode

Full IRC PrivMsg Decode

Page 34: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Packet Analysis

Page 35: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Flexible/Powerful GUI

Actions speak louder then words:

Page 36: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Future

Increase functionality Reporting Passive Application Fingerprinting Increase Search Capabilities Extend Data Correlation Capabilities

Page 37: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Summary

Enterprise Security Console open up Security Analysis and makes our jobs easier

Uses existing databases

Page 38: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

Questions?

Page 39: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background.

More information:

Web:http://www.activeworx.com

Email:[email protected]