邪恶八进制信息安全团队技术讨论组's Archiver

EvilOctal 2006-1-21 02:37

[转载]Sebek v3:tracking the attackers (第一部分)

原始连接:[url]http://www.securityfocus.com/print/infocus/1855[/url]
信息来源:邪恶八进制信息安全团队([url]www.eviloctal.com[/url])

It has become increasingly important for security professionals to deploy new detection mechanisms to track and capture an attacker's activities. Third Generation (GenIII) Honeynets provide all the components and tools required to gather this information at the deepest level. Sebek is the primary data capture tool for GenIII Honeynets. The first of this two-part series will discuss what Sebek is and what makes it so interesting. We'll start by looking at the latest Sebek release, version 3, its new capabilities, the Sebek protocol specification and how it integrates with GenIII Honeynet infrastructures. The second article will briefly address how to install and use Sebek on Linux and Windows. It will then focus on a Sebek patch developed by this article's author that makes possible not only to watch what the attacker types but also the response received.

页: [1]
© 1999-2008 EvilOctal Security Team