NCSC One: IoT Honeypot
Pieter Jansen & Jurriaan Bremer
NCSC One: IoT Honeypot Pieter Jansen & Jurriaan Bremer On the - - PowerPoint PPT Presentation
NCSC One: IoT Honeypot Pieter Jansen & Jurriaan Bremer On the agenda: 1. Introduction 2. SBIR 3. Cuckoo Sandbox 4. Project 5. Architecture 6. Offline demo 7. Roadmap Introduction Pieter Jansen - CEO @ Cybersprint -
Pieter Jansen & Jurriaan Bremer
1. Introduction 2. SBIR 3. Cuckoo Sandbox 4. Project 5. Architecture 6. Offline demo 7. Roadmap
This SBIR project is co-funded by the Internal Security Fund
Balancing Security and Mobility
You are here
honeypot framework
[1/2]
Hajime Botnet Makes a Comeback With Massive Scan for MikroTik Routers
1. Connect to an IoT device 2. Store the conversation (example: HTML files) 3. Spin up a service on the same port/protocol 4. Playback the earlier captured conversation
Easy to set up fake environments Did not go past login screen Was not convincing enough for attackers Would only capture attempts, not infections
[2/2]
Loading of firmware non-trivial:
Instrumentation of QEMU interesting:
/home/jbr/git/quailbox-qemu/build/mips-softmmu/qemu-system-mips
rw root=/dev/sda init=/sbin/init
X X
scale/automated testing for any firmware
1. Share your firmware 2. Provide testing grounds 3. Spread the word!
The HoneyNED project team Andrei Costin (ancostin@jyu.fi) Assistant Professor in Cybersecurity/IoT - welcomes research and collaboration opportunities
pj@cybersprint.com | jbr@hatching.io