SlideShare une entreprise Scribd logo
1  sur  1
Télécharger pour lire hors ligne
Modern	
  Honey	
  Network	
  
Internal Breach Monitoring & Detection
with the Modern Honey Network
Jason	
  Trost	
  
Director	
  of	
  ThreatStream	
  Labs	
  
FloCon	
  2015	
  
January	
  12-­‐15	
  2015	
  |	
  Portland,	
  OR	
  	
  
	
  
Enterprise	
  Deployment	
  DMZ	
  Deployment	
  
Enterprise	
  
Network	
  
Modern	
  Honey	
  Network	
  (MHN)	
  
-­‐	
  Free	
  and	
  Open	
  Source	
  (GPLv3)	
  PlaIorm	
  for	
  
deploying	
  and	
  managing	
  Honeypots.	
  
-­‐	
  Makes	
  deploying	
  honeypots	
  easy	
  
-­‐	
  Includes	
  APIs	
  for	
  leveraging	
  all	
  data	
  collected	
  
-­‐	
  Leverages:	
  Python/Flask,	
  hpfeeds,	
  
mnemosyne,	
  honeymap,	
  and	
  MongoDB	
  
-­‐	
  Sensors	
  Supported:	
  Dionaea,	
  Conpot,	
  Snort,	
  
Kippo,	
  Glastopf,	
  Amun,	
  Wordpot,	
  Shockpot,	
  p0f	
  
	
  
-­‐	
  Deploy	
  honeypots	
  on	
  DMZ	
  LAN	
  
-­‐	
  Accessible	
  by	
  other	
  DMZ	
  hosts,	
  but	
  not	
  exposed	
  to	
  the	
  
public	
  Internet	
  (reduces	
  noise)	
  
-­‐	
  Aims	
  to	
  catch	
  compromises	
  of	
  DMZ	
  hosts	
  if	
  they	
  start	
  
scanning	
  
-­‐	
  Meant	
  to	
  augment	
  exisYng	
  detecYon	
  and	
  monitoring	
  
technologies,	
  not	
  replace	
  them	
  
-­‐	
  Low	
  Noise:	
  Compromised	
  systems,	
  Lateral	
  movement	
  
aZempts,	
  misconfigured	
  systems,	
  misbehaving	
  internal	
  
hosts,	
  penetraYon	
  testers	
  
-­‐	
  Deploy	
  alongside	
  enterprise	
  workstaYons	
  and	
  servers	
  
-­‐	
  Configure	
  to	
  mimic	
  real	
  systems	
  as	
  much	
  as	
  possible	
  
including	
  DNS	
  entries	
  
-­‐	
  Only	
  discoverable	
  by	
  network	
  probes	
  or	
  DNS	
  zone	
  transfers	
  
(i.e.	
  don’t	
  adverYse	
  that	
  they	
  are	
  there)	
  
-­‐	
  Low	
  Noise:	
  Compromised	
  systems,	
  Lateral	
  movement	
  
aZempts,	
  misconfigured	
  systems,	
  misbehaving	
  internal	
  hosts,	
  
penetraYon	
  testers	
  
-­‐	
  Any	
  interacYon	
  with	
  honeypots	
  should	
  be	
  invesYgated	
  
Ingest	
   Viz	
  
Architecture	
  
APIs	
  
syslog	
   SIEM	
  alerts	
  
hZps://github.com/threatstream/mhn	
  
-­‐	
  Sensors	
  report	
  events	
  in	
  real-­‐Yme	
  via	
  hpfeeds	
  
-­‐	
  Events	
  are	
  enriched,	
  indexed,	
  and	
  stored	
  in	
  MongoDB	
  
-­‐	
  MHN	
  Web	
  app	
  enables	
  exploraYon	
  and	
  visualizaYon	
  
-­‐	
  JSON	
  APIs	
  expose	
  events	
  for	
  integraYon	
  with	
  other	
  systems	
  
	
  
DMZ	
  Internet	
   Internal	
  
Network	
  

Contenu connexe

En vedette

En vedette (9)

BSidesNYC 2016 - An Adversarial View of SaaS Malware Sandboxes
BSidesNYC 2016 - An Adversarial View of SaaS Malware SandboxesBSidesNYC 2016 - An Adversarial View of SaaS Malware Sandboxes
BSidesNYC 2016 - An Adversarial View of SaaS Malware Sandboxes
 
Deploying, Managing, and Leveraging Honeypots in the Enterprise using Open So...
Deploying, Managing, and Leveraging Honeypots in the Enterprise using Open So...Deploying, Managing, and Leveraging Honeypots in the Enterprise using Open So...
Deploying, Managing, and Leveraging Honeypots in the Enterprise using Open So...
 
SANS CTI Summit 2016 Borderless Threat Intelligence
SANS CTI Summit 2016 Borderless Threat IntelligenceSANS CTI Summit 2016 Borderless Threat Intelligence
SANS CTI Summit 2016 Borderless Threat Intelligence
 
Modern Honey Network (MHN)
Modern Honey Network (MHN)Modern Honey Network (MHN)
Modern Honey Network (MHN)
 
Anomali Detect 2016 - Borderless Threat Intelligence
Anomali Detect 2016 - Borderless Threat IntelligenceAnomali Detect 2016 - Borderless Threat Intelligence
Anomali Detect 2016 - Borderless Threat Intelligence
 
R-CISC Summit 2016 Borderless Threat Intelligence
R-CISC Summit 2016 Borderless Threat IntelligenceR-CISC Summit 2016 Borderless Threat Intelligence
R-CISC Summit 2016 Borderless Threat Intelligence
 
Anomaly Detection - New York Machine Learning
Anomaly Detection - New York Machine LearningAnomaly Detection - New York Machine Learning
Anomaly Detection - New York Machine Learning
 
Anomaly detection in deep learning (Updated) English
Anomaly detection in deep learning (Updated) EnglishAnomaly detection in deep learning (Updated) English
Anomaly detection in deep learning (Updated) English
 
Sosyal Medyada Anonim Hesaplar Nasıl Tespit Edilir? - NETSEC
Sosyal Medyada Anonim Hesaplar Nasıl Tespit Edilir? - NETSECSosyal Medyada Anonim Hesaplar Nasıl Tespit Edilir? - NETSEC
Sosyal Medyada Anonim Hesaplar Nasıl Tespit Edilir? - NETSEC
 

Dernier

Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
gajnagarg
 
怎样办理圣地亚哥州立大学毕业证(SDSU毕业证书)成绩单学校原版复制
怎样办理圣地亚哥州立大学毕业证(SDSU毕业证书)成绩单学校原版复制怎样办理圣地亚哥州立大学毕业证(SDSU毕业证书)成绩单学校原版复制
怎样办理圣地亚哥州立大学毕业证(SDSU毕业证书)成绩单学校原版复制
vexqp
 
Top profile Call Girls In Begusarai [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In Begusarai [ 7014168258 ] Call Me For Genuine Models...Top profile Call Girls In Begusarai [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In Begusarai [ 7014168258 ] Call Me For Genuine Models...
nirzagarg
 
Top profile Call Girls In Vadodara [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Vadodara [ 7014168258 ] Call Me For Genuine Models ...Top profile Call Girls In Vadodara [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Vadodara [ 7014168258 ] Call Me For Genuine Models ...
gajnagarg
 
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi ArabiaIn Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
ahmedjiabur940
 
Sonagachi * best call girls in Kolkata | ₹,9500 Pay Cash 8005736733 Free Home...
Sonagachi * best call girls in Kolkata | ₹,9500 Pay Cash 8005736733 Free Home...Sonagachi * best call girls in Kolkata | ₹,9500 Pay Cash 8005736733 Free Home...
Sonagachi * best call girls in Kolkata | ₹,9500 Pay Cash 8005736733 Free Home...
HyderabadDolls
 
Abortion pills in Jeddah | +966572737505 | Get Cytotec
Abortion pills in Jeddah | +966572737505 | Get CytotecAbortion pills in Jeddah | +966572737505 | Get Cytotec
Abortion pills in Jeddah | +966572737505 | Get Cytotec
Abortion pills in Riyadh +966572737505 get cytotec
 
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
wsppdmt
 
Computer science Sql cheat sheet.pdf.pdf
Computer science Sql cheat sheet.pdf.pdfComputer science Sql cheat sheet.pdf.pdf
Computer science Sql cheat sheet.pdf.pdf
SayantanBiswas37
 
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
gajnagarg
 
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
nirzagarg
 

Dernier (20)

Charbagh + Female Escorts Service in Lucknow | Starting ₹,5K To @25k with A/C...
Charbagh + Female Escorts Service in Lucknow | Starting ₹,5K To @25k with A/C...Charbagh + Female Escorts Service in Lucknow | Starting ₹,5K To @25k with A/C...
Charbagh + Female Escorts Service in Lucknow | Starting ₹,5K To @25k with A/C...
 
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
 
怎样办理圣地亚哥州立大学毕业证(SDSU毕业证书)成绩单学校原版复制
怎样办理圣地亚哥州立大学毕业证(SDSU毕业证书)成绩单学校原版复制怎样办理圣地亚哥州立大学毕业证(SDSU毕业证书)成绩单学校原版复制
怎样办理圣地亚哥州立大学毕业证(SDSU毕业证书)成绩单学校原版复制
 
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
 
Top profile Call Girls In Begusarai [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In Begusarai [ 7014168258 ] Call Me For Genuine Models...Top profile Call Girls In Begusarai [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In Begusarai [ 7014168258 ] Call Me For Genuine Models...
 
Digital Transformation Playbook by Graham Ware
Digital Transformation Playbook by Graham WareDigital Transformation Playbook by Graham Ware
Digital Transformation Playbook by Graham Ware
 
Top profile Call Girls In Vadodara [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Vadodara [ 7014168258 ] Call Me For Genuine Models ...Top profile Call Girls In Vadodara [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Vadodara [ 7014168258 ] Call Me For Genuine Models ...
 
Top Call Girls in Balaghat 9332606886Call Girls Advance Cash On Delivery Ser...
Top Call Girls in Balaghat  9332606886Call Girls Advance Cash On Delivery Ser...Top Call Girls in Balaghat  9332606886Call Girls Advance Cash On Delivery Ser...
Top Call Girls in Balaghat 9332606886Call Girls Advance Cash On Delivery Ser...
 
High Profile Call Girls Service in Jalore { 9332606886 } VVIP NISHA Call Girl...
High Profile Call Girls Service in Jalore { 9332606886 } VVIP NISHA Call Girl...High Profile Call Girls Service in Jalore { 9332606886 } VVIP NISHA Call Girl...
High Profile Call Girls Service in Jalore { 9332606886 } VVIP NISHA Call Girl...
 
Gomti Nagar & best call girls in Lucknow | 9548273370 Independent Escorts & D...
Gomti Nagar & best call girls in Lucknow | 9548273370 Independent Escorts & D...Gomti Nagar & best call girls in Lucknow | 9548273370 Independent Escorts & D...
Gomti Nagar & best call girls in Lucknow | 9548273370 Independent Escorts & D...
 
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi ArabiaIn Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
 
Gulbai Tekra * Cheap Call Girls In Ahmedabad Phone No 8005736733 Elite Escort...
Gulbai Tekra * Cheap Call Girls In Ahmedabad Phone No 8005736733 Elite Escort...Gulbai Tekra * Cheap Call Girls In Ahmedabad Phone No 8005736733 Elite Escort...
Gulbai Tekra * Cheap Call Girls In Ahmedabad Phone No 8005736733 Elite Escort...
 
Sonagachi * best call girls in Kolkata | ₹,9500 Pay Cash 8005736733 Free Home...
Sonagachi * best call girls in Kolkata | ₹,9500 Pay Cash 8005736733 Free Home...Sonagachi * best call girls in Kolkata | ₹,9500 Pay Cash 8005736733 Free Home...
Sonagachi * best call girls in Kolkata | ₹,9500 Pay Cash 8005736733 Free Home...
 
Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...
Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...
Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...
 
Abortion pills in Jeddah | +966572737505 | Get Cytotec
Abortion pills in Jeddah | +966572737505 | Get CytotecAbortion pills in Jeddah | +966572737505 | Get Cytotec
Abortion pills in Jeddah | +966572737505 | Get Cytotec
 
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
 
Computer science Sql cheat sheet.pdf.pdf
Computer science Sql cheat sheet.pdf.pdfComputer science Sql cheat sheet.pdf.pdf
Computer science Sql cheat sheet.pdf.pdf
 
Dubai Call Girls Peeing O525547819 Call Girls Dubai
Dubai Call Girls Peeing O525547819 Call Girls DubaiDubai Call Girls Peeing O525547819 Call Girls Dubai
Dubai Call Girls Peeing O525547819 Call Girls Dubai
 
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In bhavnagar [ 7014168258 ] Call Me For Genuine Models...
 
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Purnia [ 7014168258 ] Call Me For Genuine Models We...
 

Augmenting Netflow with the Honeypot Data for Internal Breach Monitoring and Detection

  • 1. Modern  Honey  Network   Internal Breach Monitoring & Detection with the Modern Honey Network Jason  Trost   Director  of  ThreatStream  Labs   FloCon  2015   January  12-­‐15  2015  |  Portland,  OR       Enterprise  Deployment  DMZ  Deployment   Enterprise   Network   Modern  Honey  Network  (MHN)   -­‐  Free  and  Open  Source  (GPLv3)  PlaIorm  for   deploying  and  managing  Honeypots.   -­‐  Makes  deploying  honeypots  easy   -­‐  Includes  APIs  for  leveraging  all  data  collected   -­‐  Leverages:  Python/Flask,  hpfeeds,   mnemosyne,  honeymap,  and  MongoDB   -­‐  Sensors  Supported:  Dionaea,  Conpot,  Snort,   Kippo,  Glastopf,  Amun,  Wordpot,  Shockpot,  p0f     -­‐  Deploy  honeypots  on  DMZ  LAN   -­‐  Accessible  by  other  DMZ  hosts,  but  not  exposed  to  the   public  Internet  (reduces  noise)   -­‐  Aims  to  catch  compromises  of  DMZ  hosts  if  they  start   scanning   -­‐  Meant  to  augment  exisYng  detecYon  and  monitoring   technologies,  not  replace  them   -­‐  Low  Noise:  Compromised  systems,  Lateral  movement   aZempts,  misconfigured  systems,  misbehaving  internal   hosts,  penetraYon  testers   -­‐  Deploy  alongside  enterprise  workstaYons  and  servers   -­‐  Configure  to  mimic  real  systems  as  much  as  possible   including  DNS  entries   -­‐  Only  discoverable  by  network  probes  or  DNS  zone  transfers   (i.e.  don’t  adverYse  that  they  are  there)   -­‐  Low  Noise:  Compromised  systems,  Lateral  movement   aZempts,  misconfigured  systems,  misbehaving  internal  hosts,   penetraYon  testers   -­‐  Any  interacYon  with  honeypots  should  be  invesYgated   Ingest   Viz   Architecture   APIs   syslog   SIEM  alerts   hZps://github.com/threatstream/mhn   -­‐  Sensors  report  events  in  real-­‐Yme  via  hpfeeds   -­‐  Events  are  enriched,  indexed,  and  stored  in  MongoDB   -­‐  MHN  Web  app  enables  exploraYon  and  visualizaYon   -­‐  JSON  APIs  expose  events  for  integraYon  with  other  systems     DMZ  Internet   Internal   Network