EUSecWest: Security Masters Dojo London
| Next Session Dates: | May 19-20 2008 |
| Venue: |
To Be Announced London, U.K. |
| Duration: |
One Day Courses. Sessions begin at 10:00 a.m. and go to 6 p.m. (Unless otherwise stated.) |
|
Registration Maximum: |
10 Students per course session. |
| Price: |
GBP1000£ CAD$2000 Full day course (25% discount for early registration) |
Course: Advanced Honeypot Tactics
Instructor:
Thorsten Holz <thorsten.holz@mmweg.rwth-aachen.de>
Register For This Course
Description
This course shows how to use honeypot technologies as a concrete improvement to your organisations security defences. This course will concentrate on low-interaction honeynet technology.
PREREQUISITE WARNING Each class has prerequisites for software loads and a laptop is mandatory. These individual class guides will list material the students are expected have knowledge about coming in and software tools that need to be pre-installed before attending so you get the maximum benefit from the focused intermediate or advanced level course. Please pay particular attention to the prerequisites, as the material listed there will not be reviewed in the courses, and will be necessary to get the maximum benefit out of these educational programs.
- honeyd
- workings of honeyd
- routing traffic to honeyd
- simulation
- simulation tcp/ip stacks
- simulation of network infrastructure
- simulation of applications
- advanced honeyd configuration
- centralized data collection with honeyd
- traditional methods
- honeyd collectorr/mustard
- writing honeyd plugins
- honeyd to protect cooperate infrastructure
- malware collection
- Collecting malware with honeypots
- Techniques used
- mwcollect / nepenthes
- How they work
- Writing own modules
- Analyzing the received shellcodes
- Analyzing the captured binaries
- Results
- Bots/Botnets
- Intro to bots and demo
- Reverse engineering of bot
- Basic techniques
- Sandboxes
- Ollydbg and/or IDA
- Botnet 101
- How they work
- What you need to know
- Observing them
- Live botnet observation
- Results
Prerequisites
Students should be familiar with honeypot concepts and have a good understanding of TCP/IP networking and analysis tools like Ethereal.



