Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
Microsoft details 'Windows on ARM' program
March debut of 'iPad 3' a sure bet, says analyst
FBI unbolts Steve Jobs 1991 investigation file
Cisco boosted profit, sales in Q2 while cutting costs
Macs take on the enterprise
Four crazy tech ideas from Google's Solve for X project
Obama 2012 campaign playlist revealed courtesy of Spotify
Oracle buying Taleo for US$1.9 billion in direct hit at SAP
Amazon attacks Apple: You get 3 Kindle products for price of iPad 2
Pre-rendered pages highlight latest Google Chrome release
Microsoft exec: Lync-Skype integration a 'compelling opportunity'
The future of hypervisors
/

Honeynet looks to sting hackers

Today's breaking news
Send to a friendFeedback


A group of 30 computer security researchers who set up inexpensive "fake" networks to observe how hackers behave as they break into them are finding out about new software vulnerabilities and warning the public.

The security professionals, calling themselves The Honeynet Project, quietly maintain a distributed network of Windows NT, Linux, Sun Sparc servers and desktops accessible via the Internet to monitor how hackers go after various operating systems. As research volunteers operating on a shoestring, they've collected a wealth of data - and at times found out about new attack tools and exploits of the "blackhat" underworld of hackers.

In January, for instance, the Honeynet Project discovered hackers could use a management feature called the CDE Subprocess Control Service to take root control of Solaris.

The Honeynet Project shared that insight with the CERT Coordination Center, which determined the matter was serious enough to issue security alerts advising Solaris users to turn off CDE until the buffer-overflow vulnerability was patched.

But most days, according to Jed Haile, project engineer at Nitro Data Systems and volunteer hacker-watcher, the Honeynet records hacker activity that is of less scientific interest but is astonishing in its intensity and criminality.

Hackers that fall into the Honeynet are seen to swap stolen telephone and credit card numbers, try to break into other possibly more "real" networks and even discuss using the Internet for terrorist attacks.

In general, experience shows that hackers frequently operate as gangs - and they love to talk.

"The 'blackhats' have a compulsive need to chat on IRC [Internet Relay Chat software]," says Haile, who spoke about the two-year experience of The Honeynet Project at the recent InfoSec conference. "The first thing they'll do on a hacked box is set up IRC and invite their buddies over." Then they set up an encrypted route back to another compromised server elsewhere on the Internet.

The goal of the Honeynet Project, started by Sun engineer Lance Spitzer, is not to capture hackers, but to observe their actions and find out about new tools they use.

"A lot of these hackers are not gurus who know everything about computers," Haile says. "They have very good tools. And they talk about doing this for money. There's definitely a market for hired hacking out there."

The Honeynet Project's undisclosed number of servers and desktops, maintained at diverse locations with a minimum of publicity, spans the country. Each server typically gets 20 or more unique scans per day, and the hackers don't have too hard a time breaking into any operating system that isn't up to date on its patches, although they may find new vulnerabilities, too.

As a scientific effort, one of the Honeynet Project's goals is to analyze the collected data to develop software that can detect the probability of a successful attack. The Honeynet Project also would like to be able to pinpoint those who make these hacker tools.

Not so sweet honey
The Honeynet Project was set up to trap, monitor and record hackers. Also known as deception systems or honeypots, such networks are designed to look like real networks with real resources to attack. The driving ideas behind honeypots are:
Help other users and the industry with early warning and prediction data.
Identify new hacking tools and tactics.
Provide forensic evidence to post-attack investigators.

Even as it learned a lot about hackers, the Honeynet Project discovered there are practical obstacles in operating a honeynet, especially in making sure a hacker doesn't use the honeypot as a springboard to break into other systems.

"Suppose hackers break into a honeynet during the weekend and they take down the White House?" Haile says. "There's a tremendous legal liability in all this." If an attacker makes more than five or six outbound attempts at attacks, the honeynet shuts him off. Hailer says no company should set up a honeynet of its own before discussing it with its legal department.

The Honeynet Project has designed a second-generation honeynet that will include an extensive "production-looking" intranet to keep hackers intrigued with trying to break in further. But it will block outbound scanning.

Hackers tend to be an angry lot, particularly when they figure out they are being watched in a honeynet, Haile says. "Hackers will undertake every effort to destroy a honeypot when they find it."

RELATED LINKS

Contact Senior Editor Ellen Messmer

Other recent articles by Messmer

The Honeynet Project

Shoring up security
New security techniques include honeypots, decoys, air gaps, exit controls, self-healing tools and denial-of-service defenses.
Network World, 05/28/01.

Hackers, vendors put camouflage to use
Latest virus relies on trick URL; start-up ForeScout aims to fend off viruses, hackers.
Network World, 02/04/02.

Network World's Security and Bug Patch Alert newsletter
Get the latest information on security and bug alert announcements and fixes from major vendors.

Network World on Security newsletter
Stay current on security challenges and solutions, and get strategic insight into the future of information security.

Security research page
Get up to speed on security issues, including intrusion detection, hackers and other subjects.

Error 404--Not Found

Error 404--Not Found

From RFC 2068 Hypertext Transfer Protocol -- HTTP/1.1:

10.4.5 404 Not Found

The server has not found anything matching the Request-URI. No indication is given of whether the condition is temporary or permanent.

If the server does not wish to make this information available to the client, the status code 403 (Forbidden) can be used instead. The 410 (Gone) status code SHOULD be used if the server knows, through some internally configurable mechanism, that an old resource is permanently unavailable and has no forwarding address.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.