Capture - High Interaction Client Honeypot

Some researchers from Victoria University of Wellington, NZ, have released an initial version of "Capture - A Honeypot Client". This is a high-interaction client-side honeypot that tries to find malicious web sites. It consits of a server part which controlls several client, which actually crawl the Web and search for malicious sites. Everything is based on VMware in order to have a fast way to reset an infected machine. Sounds like an interesting approach - I'll give it a try once I have some hardware available :-)

About:
Only a few high interaction client honeypot clients are available today. Capture differs from existing client honeypots in various ways. First, it is designed to be fast. State changes are being detected using an event based model allowing to react to state changes as they occur. Second, Capture is designed to be scalable. A central Capture server is able to control numerous clients across a network. Third, Capture is suppose to be a framework that allows to utilize different clients. The intitial version of Capture supports Internet Explorer, but additional clients will be supported with upcoming versions of Capture.
taken from http://capture-hpc.sourceforge.net/index.php?n=Main.About

Trackbacks

    No Trackbacks

Comments

Display comments as (Linear | Threaded)

    No comments


Add Comment


Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
E-Mail addresses will not be displayed and will only be used for E-Mail notifications

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

 
Submitted comments will be subject to moderation before being displayed.