Using Honeypots in Network Intelligence Architectures – The University of Trás-os- Montes e Alto Douro Case Study
José Bessa1, Hugo Coelho1, Pedro Monteiro1, José Brito1, António Costa1
1University of Trás-os-Montes e Alto Douro
Architectures The University of Trs -os- Montes e Alto Douro Case - - PowerPoint PPT Presentation
Using Honeypots in Network Intelligence Architectures The University of Trs -os- Montes e Alto Douro Case Study Jos Bessa 1 , Hugo Coelho 1 , Pedro Monteiro 1 , Jos Brito 1 , Antnio Costa 1 1 University of Trs -os-Montes e Alto Douro
Using Honeypots in Network Intelligence Architectures – The University of Trás-os- Montes e Alto Douro Case Study
José Bessa1, Hugo Coelho1, Pedro Monteiro1, José Brito1, António Costa1
1University of Trás-os-Montes e Alto Douro
2
Network Intelligence Architecture (NIA) Case Study & Proposed Architecture Tests and Results Final Considerations & Future Work
3
4
“Knowledge is the combination of instincts, ideas, rules and procedures that guide the actions and decisions.” (Rascão, 2011)
5
NARSON Technical Software
6
Volume Variety Velocity Value Veracity
7
8
DevExpress Software
9
A Honeypot is a security resource without production value and whose true value lies in being probed, attacked or compromised
– Spitzner, 2002
Any traffic directed to a Honeypot is considered abnormal Who’s attacking? How’s attacking? What resources?
10
Interaction Level Low Medium High Deployment & Maintenance Simple Advanced Complex Collected Data Detail Low Medium High Risk Low Low High
11
Defines its Value Research Prevention, Detection, Reaction External Attack Sources Detection, Reaction Internal Attack Sources
12
13
University of Trás-os-Montes e Alto Douro (UTAD)
IT and Communications Services (SIC-UTAD) – Division of Infrastructures, Communications and Support
Douro Region UTAD
14
15
16
DMZ
17
18
19
20
21
22
23
24
25
Organization’s data is important Monitoring is vital Knowledge on attacks NIA with Elastic Stack Low interaction honeypot deployed on UTAD’s Network Improvement of network services
26
Continue research Network Intelligence New dashboards for decision support Include other event sources Improve honeypot
27
28
University of Trás-os-Montes e Alto Douro:
Address: Quinta de Prados, 5000-801 Vila Real, Portugal Phone Number: 259 350 000 Fax: 259 350 480 Site: http://www.utad.pt
Authors:
José Bessa: jmiguelbessa16@gmail.com Hugo Coelho: coelho.hu@gmail.com Pedro Monteiro: monteiro.p@outlook.pt José Brito: jbrito@utad.pt António Costa: acosta@utad.pt www.linkedin.com/in/jmiguelbessa www.linkedin.com/in/coelhohu www.linkedin.com/in/monteirop www.linkedin.com/in/josepedrobrito www.linkedin.com/in/ariocosta