Low Interaction Server Honeypot Evolution

Plenary Sessions

Tuesday — December 1st, 2009 16:45

The talk will give an introduction to our new low-interaction server honeypot called 'Dionaea'. Dionaea is meant to be a nepenthes successor, embedding python as scripting language, using libemu to detect shellcodes, supporting ipv6 and tls.

The software is the result of all shortcomings we experienced with nepenthes, therefore it is meant to supersede nepenthes.

Presenters

  • Mark Schloesser (Girraffe Honeynet, DE) DE

    My name is Mark Schloesser and I study Computer Science at the RWTH Aachen University in Germany. I am interested in IT Security topics in general and got a deeper insight into malware and botnets since I joined the team at mwcollect.org. This team also forms the Giraffe Honeynet Project Chapter and I joined that group in late 2008, too.

    So my free time mainly gets consumed by the work on malware collection and botnet monitoring. Besides my studies I currently work for the newly formed IT Security Research Group at the university as a student assistant where we also look into security in mobile communications like GSM/UMTS/WLAN/WiMAX.

    http://www.honeynet.org/chapters/giraffe

    http://itsec.rwth-aachen.de/