honey inspector mike clark honeynet project. honeynet inspector background

39
Honey Inspector Mike Clark Honeynet Project

Post on 21-Dec-2015

230 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Honey Inspector

Mike Clark

Honeynet Project

Page 2: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Honeynet Inspector

Background

Page 3: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

What is it?

Set of Perl CGI Scripts Firewall/IDS Logs MySQL IDS

Page 4: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

How it Works

Fisq script imports firewall logs IDS(Snort) logs to the DB IDS(Snort) also records traffic in pcap format Inspector drills down using all of these

Page 5: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Inspector High Level

Shows connections and drill down options 4 methods of alerting

Packet Count Connection size (byte) IDS(Snort) alerts Inbound/Outbound

Page 6: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Drilling Down

Connection View Arin/whois/dig lookup Snort alerts p0f Plugins

Page 7: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Plugins

Honey Extractor IRC View

Page 8: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Advantages

Quick Easily extendable High chance of detecting activity Web based

Page 9: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Disadvantages

Not scalable Not very nice looking

Page 10: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Future

Perl module Nicer interface Graphing Customizable Report Engine

Page 11: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Questions?

Page 12: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Enterprise Security Console

Jeff Dell

Activeworx, Inc.

Page 13: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Speaker

Jeff Dell, Florida Honeynet Project Florida Honeynet: Responsible Network

Forensics Honeynet Alliance: Central Database

Page 14: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Problem

How do we look at different datasets from different data sources and correlate the information?

Page 15: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

1st Problem

The Data

Page 16: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

FW Logs

Page 17: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Snort Logs

Page 18: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

TCPDump

Page 19: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

2nd Problem

Data Sources

Page 20: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Different Data Sources

DMZ TCPDump

DMZ Firewalls

Internal IDS

DMZ Syslog

Internal Syslog

External IDS

Page 21: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Solution

Centralizing Honeynet Data Enterprise Security Console to view data

Page 22: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Data Centralization

Centralized Database

IDS Logs Firewall Logs System Logs TCPDump Logs

Page 23: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

What Next?

Page 24: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Enterprise Security Console

Advantages Easy to View Data Very flexible and powerful GUI Strong Data Correlation Capabilities Built with Honeynets in mind

Disadvantages Windows 2000/XP Only

Page 25: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Enterprise Security Console

Console to view Databases Fully Database Driven Supports multiple ESC Databases Supports multiple Data Databases

Laptop

FW Database

ESC Database

Snort Database TCPDump Database

FW Database

ESC Database

Snort Database TCPDump Database

Page 26: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Types of Data

Firewall Logs Snort IDS Logs TCPDump Logs Syslog Prelude (Hybrid IDS) Others…

Page 27: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Easy to View Data

Page 28: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Data Search Correlation

Correlate between any the following data types:

FirewallS

yslo

g

TCPDump

IDS

Page 29: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Data Correlation (Cont)

View Firewall Logs Advantages

Easy Fast Have some interesting information

Disadvantages Limited information

Page 30: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Data Correlation (Cont)

View IDS Logs Advantages

More interesting events Alert on attacks

Disadvantages Does not pick up all attacks Only see a single packet

Page 31: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Data Correlation (Cont)

TCPDump Logs Advantages

All packets

Disadvantages Lots of data

Page 32: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Data Decode

Full Packet Decode

Page 33: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

IRC Decode

Full IRC PrivMsg Decode

Page 34: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Packet Analysis

Page 35: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Flexible/Powerful GUI

Actions speak louder then words:

Page 36: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Future

Increase functionality Reporting Passive Application Fingerprinting Increase Search Capabilities Extend Data Correlation Capabilities

Page 37: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Summary

Enterprise Security Console open up Security Analysis and makes our jobs easier

Uses existing databases

Page 38: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

Questions?

Page 39: Honey Inspector Mike Clark Honeynet Project. Honeynet Inspector  Background

More information:

Web:http://www.activeworx.com

Email:[email protected]