DocumentCode :
1707135
Title :
Virtual honeynets revisited
Author :
Yan, Lok Kwong
Author_Institution :
Air Force Res. Lab., Rome, NY, USA
fYear :
2005
Firstpage :
232
Lastpage :
239
Abstract :
A new user-mode Linux based virtual honeynet architecture is presented in this paper. The new architecture has improved functionality that is difficult to realize in the GenII honeynet. Two new honeynet capabilities in particular are introduced. Honeypot controller is a new virtual honeynet component that assists in data control. The honeywall promises to have finer control over the honeypots through signal and system call redirections. The second new capability is the disk imager. The disk imager is capable of making forensic images of the virtual machine´s file systems for further analysis. Since security for virtual honeynets is a big concern, the new virtual honeynet architecture utilizes security enhanced Linux to isolate the untrusted honeypots from the completely trusted honeywall. SELinux and other research work done in this field made the new honeynet architecture a viable alternative to GenII honeynets. A file system logging mechanism, FSLog, has been developed for the UML based virtual honeynet. In conjunction with the built-in tty logger, UML based honeynets have logging capabilities that are equivalent to their GenII honeynet counterparts. The current version of FSLog successfully logs eighteen virtual file systems system calls including the common, read(), write(), open() and close() functions. Its current functionality and how it pieces into the new architecture is also discussed. This work provides researchers with an alternative honeynet platform. The new virtual honeynet architecture is more portable, easier to setup, more cost effective and as secure as the GenII honeynet. The addition of the honeypot controller and disk imager components also makes the new virtual honeynet architecture more capable.
Keywords :
Linux; computer networks; data handling; network operating systems; security of data; virtual machines; virtual private networks; FSLog; GenII honeynet; Linux; SELinux; UML; data control; disk imager; file system logging; forensic images; honeypot controller; system call redirection; trusted honeywall; virtual honeynet architecture; virtual honeynet security; virtual machine; Computer architecture; Control systems; Costs; File systems; Forensics; Image analysis; Linux; Security; Unified modeling language; Virtual machining;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Assurance Workshop, 2005. IAW '05. Proceedings from the Sixth Annual IEEE SMC
Print_ISBN :
0-7803-9290-6
Type :
conf
DOI :
10.1109/IAW.2005.1495957
Filename :
1495957
Link To Document :
بازگشت