Towards a Third Generation Data Capture Architecture for Honeynets
| Title | Towards a Third Generation Data Capture Architecture for Honeynets |
| Publication Type | Conference Proceedings |
| Year of Publication | 2005 |
| Authors | Balas, E., and C. Viecco |
| Conference Name | IEEE Information Assurance Workshop |
| Series Title | Proceedings from the Sixth Annual IEEE SMC Information Assurance Workshop, 2005. IAW '05. |
| Pagination | 21-28 |
| Date Published | 06/2005 |
| Publisher | IEEE |
| Conference Location | West Point, New York |
| Publication Language | eng |
| ISBN | 0-7803-9290-6 |
| Keywords | anml |
| Abstract | Honeynets have become an important tool for researchers and network operators. However, their effectiveness has been impeded by a lack of a standard unified honeynet data model which results from having multiple unrelated data sources, each with its own access method and format. In this paper we propose a new data collection architecture that addresses the need for both rapid comprehension and detailed analysis by providing two data access methods: a relational model based fast path, and a canonical slow path. We also present a set of tools based on this architecture. |
|