<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">
<channel>
    <title>honeyblog - paper</title>
    <link>http://honeyblog.org/</link>
    <description>honeynet-related news and more...</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.1.2 - http://www.s9y.org/</generator>
    
    <image>
        <url>http://honeyblog.org/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: honeyblog - paper - honeynet-related news and more...</title>
        <link>http://honeyblog.org/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>LEET'08: Measurements and Mitigation of Peer-to-Peer-based Botnets: A Case Study on Storm Worm</title>
    <link>http://honeyblog.org/archives/170-LEET08-Measurements-and-Mitigation-of-Peer-to-Peer-based-Botnets-A-Case-Study-on-Storm-Worm.html</link>
            <category>malware</category>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/170-LEET08-Measurements-and-Mitigation-of-Peer-to-Peer-based-Botnets-A-Case-Study-on-Storm-Worm.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=170</wfw:comment>

    <slash:comments>2</slash:comments>
    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=170</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    Next week at the First USENIX Workshop on Large-Scale Exploits and Emergent Threats (&lt;a href=&quot;http://www.usenix.org/events/leet08/&quot;&gt;LEET&#039;08&lt;/a&gt;), I will present our work on Storm Worm and the measurement results. The full paper is now &lt;a href=&quot;http://honeyblog.org/junkyard/paper/storm-leet08.pdf&quot;&gt;available&lt;/a&gt;. See you at LEET next week!&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Abstract&lt;/b&gt;:&lt;br /&gt;
Botnets, i.e., networks of compromised machines under a common control infrastructure, are commonly controlled by an attacker with the help of a central server: all compromised machines connect to the central server and wait for commands.&lt;br /&gt;
&lt;br /&gt;
However, the first botnets that use peer-to-peer networks for remote control of the compromised machines appeared in the wild recently. In this paper, we introduce a methodology to analyze and mitigate peer-to-peer botnets. In a case study, we examine in detail the Storm Worm botnet, the most wide-spread peer-to-peer botnet currently propagating in the wild. We were able to infiltrate and analyze in-depth the botnet, which allows us to estimate the total number of compromised machines. Furthermore, we present two different ways to disrupt the communication channel between controller and compromised machines in order to mitigate the botnet and evaluate the effectiveness of these mechanisms. 
    </content:encoded>

    <pubDate>Fri, 11 Apr 2008 11:24:41 +0200</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/170-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>SSAC Advisory on Fast Flux Hosting and DNS</title>
    <link>http://honeyblog.org/archives/163-SSAC-Advisory-on-Fast-Flux-Hosting-and-DNS.html</link>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/163-SSAC-Advisory-on-Fast-Flux-Hosting-and-DNS.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=163</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=163</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    The Security and Stability Advisory Committee (SSAC) of ICANN released an advisory regarding &quot;&lt;a href=&quot;http://www.icann.org/committees/security/sac025.pdf&quot;&gt;Fast Flux Hosting and DNS&lt;/a&gt;&quot;, in which they detail ICANN&#039;s view of FFSNs. Thanks Jose for the heads-up!&lt;br /&gt;
&lt;br /&gt;
Introduction&lt;br /&gt;
&lt;br /&gt;
&quot;Fast flux&quot; is an evasion technique that cyber-criminals and Internet miscreants use to evade identification and to frustrate law enforcement and anticrime efforts aimed at locating and shutting down web sites used for illegal purposes. Fast flux hosting is an application of technology that supports a wide variety of cyber-crime activities (fraud, identity theft, online scams) and is considered one of the most serious threats to online activities today. Basic fast flux hosting uses rapid modification of IP addresses associated with a system that hosts a malicious activity to evade detection and take down efforts. This technique is also used to rapidly modify the IP addresses of the name servers that resolve the domain names of the fluxed malicious hosts (this variant is sometimes called NS fast flux). A particularly troublesome variant of fast flux hosting, &quot;double flux&quot;, fluxes addresses of both name servers and malicious (web server) hosts.&lt;br /&gt;
&lt;br /&gt;
This Advisory describes the technical aspects of fast flux hosting and fast flux service networks.  It explains how the DNS is exploited to abet criminal activities that employ fast flux hosting, identifying the impacts of fast flux hosting, and calling particular attention to the way such attacks extend the malicious or profitable lifetime of the illegal activities conducted using these fast flux techniques.  It describes current and possible methods of mitigating fast flux hosting at various points in the Internet. The Advisory discusses the pros and cons of these mitigation methods, identifies those methods that SSAC considers practical and sensible, and recommends that appropriate bodies consider policies that would make the practical mitigation methods universally available to registrants, ISPs, registrars and registries (where applicable for each).&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Thu, 13 Mar 2008 08:31:00 +0100</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/163-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>NDSS'08 Presentation</title>
    <link>http://honeyblog.org/archives/162-NDSS08-Presentation.html</link>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/162-NDSS08-Presentation.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=162</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=162</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    Yesterday I forgot to post the link to my presentation :-/&lt;br /&gt;
The presentation I gave at NDSS&#039;08 is available at &lt;a href=&quot;http://honeyblog.org/junkyard/paper/08_ff_NDSS.pdf&quot;&gt;http://honeyblog.org/junkyard/paper/08_ff_NDSS.pdf&lt;/a&gt;. If you have comments or questions, please let me know! 
    </content:encoded>

    <pubDate>Wed, 12 Mar 2008 09:02:00 +0100</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/162-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>&quot;Measuring and Detecting Fast-Flux Service Networks&quot;</title>
    <link>http://honeyblog.org/archives/161-Measuring-and-Detecting-Fast-Flux-Service-Networks.html</link>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/161-Measuring-and-Detecting-Fast-Flux-Service-Networks.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=161</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=161</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    One of the projects at our lab focuses on &lt;a href=&quot;http://honeynet.org/papers/ff/&quot;&gt;fast-flux service networks&lt;/a&gt; (FFSNs), a mechanism used by attackers to build an overlay network on top of compromised machines. FFSNs are for example used to host scam pages or malicious content. Our findings were published in a paper at &lt;a href=&quot;http://www.isoc.org/isoc/conferences/ndss/08/&quot;&gt;NDSS&#039;08&lt;/a&gt;. The full paper is also &lt;a href=&quot;https://pi1.informatik.uni-mannheim.de/filepool/research/publications/fast-flux-ndss08.pdf&quot;&gt;available&lt;/a&gt; since a couple of weeks.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Abstract&lt;/b&gt;:&lt;br /&gt;
We present the first empirical study of fast-flux service networks (FFSNs), a newly emerging and still not widely-known phenomenon in the Internet. FFSNs employ DNS to establish a proxy network on compromised machines through which illegal online services can be hosted with very high availability. Through our measurements we show that the threat which FFSNs pose is significant: FFSNs occur on a worldwide scale and already host a substantial percentage of online scams. Based on analysis of the principles of FFSNs, we develop a metric with which FFSNs can be effectively detected. Considering our detection technique we also discuss possible mitigation strategies.&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;https://pi1.informatik.uni-mannheim.de/filepool/research/publications/fast-flux-ndss08.pdf&quot;&gt;Full paper&lt;/a&gt; 
    </content:encoded>

    <pubDate>Tue, 11 Mar 2008 16:42:22 +0100</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/161-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>Collecting Autonomous Spreading Malware Using High-Interaction Honeypots</title>
    <link>http://honeyblog.org/archives/158-Collecting-Autonomous-Spreading-Malware-Using-High-Interaction-Honeypots.html</link>
            <category>honeynets</category>
            <category>malware</category>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/158-Collecting-Autonomous-Spreading-Malware-Using-High-Interaction-Honeypots.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=158</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=158</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    Together with a few researchers from the &lt;a href=&quot;http://www.honeynet.org.cn/index.php?lang=en&quot;&gt;Chinese Honeynet Project&lt;/a&gt;, we published a paper about capturing autonomous spreading malware with high-interaction honeypots at the 9th International Conference on                                      Information and Communications Security (&lt;a href=&quot;http://www.icics2007.org.cn/&quot;&gt;ICICS 2007&lt;/a&gt;) which is now &lt;a href=&quot;http://honeyblog.org/junkyard/paper/honeybow-ICICS07.pdf&quot;&gt;available&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Abstract&lt;/b&gt;: Autonomous spreading malware in the form of worms or bots has become a severe threat in today’s Internet. Collecting the sample as early as possible is a necessary precondition for the further treatment of the spreading malware, e.g., to develop antivirus signatures. In this paper, we present an integrated toolkit called HoneyBow, which is able to collect autonomous spreading malware in an automated manner using high-interaction honeypots. Compared to low-interaction honeypots, HoneyBow has several advantages due to a wider range of captured samples and the capability of collecting malware which propagates by exploiting new vulnerabilities. We validate the properties of HoneyBow with experimental data collected during a period of about nine months, in which we collected thousands of malware binaries. Furthermore, we demonstrate the capability of collecting new malware via a case study of a certain bot.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Keywords&lt;/b&gt;: Honeypots - Intrusion Detection Systems - Malware&lt;br /&gt;
&lt;br /&gt;
Full Paper: &lt;a href=&quot;http://honeyblog.org/junkyard/paper/honeybow-ICICS07.pdf&quot;&gt;Collecting Autonomous Spreading Malware Using High-Interaction Honeypots&lt;/a&gt; (&lt;a href=&quot;http://www.springerlink.com/content/978-3-540-77047-3/&quot;&gt;LNCS 4861&lt;/a&gt;) 
    </content:encoded>

    <pubDate>Fri, 11 Jan 2008 09:43:56 +0100</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/158-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>Technical Report: Studying Malicious Websites and the Underground Economy on the Chinese Web</title>
    <link>http://honeyblog.org/archives/147-Technical-Report-Studying-Malicious-Websites-and-the-Underground-Economy-on-the-Chinese-Web.html</link>
            <category>honeynets</category>
            <category>malware</category>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/147-Technical-Report-Studying-Malicious-Websites-and-the-Underground-Economy-on-the-Chinese-Web.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=147</wfw:comment>

    <slash:comments>2</slash:comments>
    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=147</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    Together with the researchers from the &lt;a href=&quot;http://www.honeynet.org.cn/index.php?lang=en&quot;&gt;Chinese Honeynet Project&lt;/a&gt;, we also examined the extend of malicious websites on the Chinese Web. Using high- and low-interaction honeyclients, we were able to find about 2,500 sites (1,49% of overall examined sites) that tried to compromise an unpatched system. Furthermore, we also studied the underground black market which is used to trade exploits, malware, and stolen virtual goods. Several measurements provide an insight into the black market on the Chinese Web and show that the attackers are organized pretty well. We published our findings as a &lt;a href=&quot;http://honeyblog.org/junkyard/reports/www-china-TR.pdf&quot;&gt;technical report&lt;/a&gt; to share the lessons we learned.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Abstract:&lt;/b&gt;&lt;br /&gt;
&lt;blockquote&gt;The World Wide Web gains more and more popularity within China with more than 1.31 million websites on the Chinese Web in June 2007.  Driven by the economic profits, cyber criminals are on the rise and use the Web to exploit innocent users. In fact, a real underground black market with thousand of participants has developed which brings together malicious users who trade exploits, malware, virtual assets, stolen credentials, and more. In this paper, we provide a detailed overview of this underground black market and present a model to describe the market. We substantiate our model with the help of measurement results within the Chinese Web. First, we show that the amount of virtual assets traded on this underground market is huge.  Second, our research proofs that a significant amount of websites within China&#039;s part of the Web are malicious: our measurements reveal that about 1.49% of the examined sites contain some kind of malicious content.&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
The complete report is available as &lt;a href=&quot;http://honeyblog.org/junkyard/reports/www-china-TR.pdf&quot;&gt;TR-2007-011&lt;/a&gt;. 
    </content:encoded>

    <pubDate>Tue,  4 Dec 2007 08:16:00 +0100</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/147-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>Technical Report: Characterizing the IRC-based Botnet Phenomenon</title>
    <link>http://honeyblog.org/archives/146-Technical-Report-Characterizing-the-IRC-based-Botnet-Phenomenon.html</link>
            <category>honeynets</category>
            <category>malware</category>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/146-Technical-Report-Characterizing-the-IRC-based-Botnet-Phenomenon.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=146</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=146</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    Together with a few researchers from China, we studied IRC-based botnets in order to understand the extent of this phenomenon. Using different kinds of honeypots and several sensors deployed across different regions in China, we were able to collect thousands of bot binaries. With the help of a behavior-based analysis mechanism similar to &lt;a href=&quot;http://www.cwsandbox.org&quot;&gt;CWSandbox&lt;/a&gt;, we could extract the Command &amp;amp; Control (C&amp;C) server in an automated way. In a third step, we used this information to connect to the actual C&amp;C server and passively monitored the activity in the channel. Furthermore, we also actively probed the C&amp;C servers to find out other characteristics of these machines. The complete setup and our results are described in a &lt;a href=&quot;http://honeyblog.org/junkyard/reports/botnet-china-TR.pdf&quot;&gt;technical report&lt;/a&gt; we just published.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Abstract&lt;/b&gt;:&lt;br /&gt;
&lt;blockquote&gt;Botnets, networks of compromised machines that can be remotely controlled by an attacker, are one of the most common attack platforms nowadays. They can, for example, be used to launch distributed denial-of-service (DDoS) attacks, steal sensitive information, or send spam emails. A long-term measurement study of botnet activities is useful as a basis for further research on global botnet mitigation and disruption techniques. We have built a distributed and fully-automated botnet measurement system which allows us to collect data on the botnet activity we observe in China. Based on the analysis of tracking records of 3,290 IRC-based botnets during a period of almost twelve months, this paper presents several novel results of botnet activities which can only be measured via long-term  easurements. These include.  amongst others, botnet lifetime, botnet discovery trends and distributions, command and control channel distributions, botnet size and end-host distributions. Furthermore, our measurements confirm and extend several previous results from this area.&lt;br /&gt;
&lt;br /&gt;
Our results show that the botnet problem is of global scale, with a scattered distribution of the control infrastructure and also a scattered distribution of the victims. Furthermore, the control infrastructure itself is rather flexible, with an average lifetime of a Command &amp;amp; Control server of about 54 days. These results can also leverage research in the area of botnet detection, mitigation, and disruption: only by understanding the problem in detail, we can develop efficient counter measures.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
The complete report is available as &lt;a href=&quot;http://honeyblog.org/junkyard/reports/botnet-china-TR.pdf&quot;&gt;TR-2007-010&lt;/a&gt;. And more information regarding the Chinese Honeynet Project is available at the website of the &lt;a href=&quot;http://www.honeynet.org.cn/index.php?lang=en&quot;&gt;Artemis Project&lt;/a&gt;. 
    </content:encoded>

    <pubDate>Mon,  3 Dec 2007 14:02:00 +0100</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/146-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>New KYE paper: Malicious Web Servers</title>
    <link>http://honeyblog.org/archives/134-New-KYE-paper-Malicious-Web-Servers.html</link>
            <category>administrativa</category>
            <category>honeynets</category>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/134-New-KYE-paper-Malicious-Web-Servers.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=134</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=134</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    The Honeynet Project &amp;amp; Research Alliance are excited to announce the release of a new paper in our Know Your Enemy series, &quot;&lt;a href=&quot;http://www.honeynet.org/papers/mws/index.html&quot;&gt;KYE: Malicious Web Servers&lt;/a&gt;&quot;. In this paper, we take an in-depth look at malicious web servers that attack web browsers, and we evaluate several defensive strategies that can be employed to counter this threat of client-side attacks. All the malicious web servers identified in this study were found with our client honeypot &lt;a href=&quot;http://www.nz-honeynet.org/capture.html&quot;&gt;Capture-HPC&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Besides providing the information of this paper, we also publish the &lt;a href=&quot;http://www.nz-honeynet.org/kye/mws/complete_data_set.zip&quot;&gt;complete data set&lt;/a&gt;. We hope that Capture-HPC and the data enable the security community to easily become involved in studying the phenomenon of malicious servers.  
    </content:encoded>

    <pubDate>Tue, 14 Aug 2007 20:04:14 +0200</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/134-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>&quot;Exploring Multiple Execution Paths for Malware Analysis&quot;</title>
    <link>http://honeyblog.org/archives/122-Exploring-Multiple-Execution-Paths-for-Malware-Analysis.html</link>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/122-Exploring-Multiple-Execution-Paths-for-Malware-Analysis.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=122</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=122</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    The upcoming &lt;a href=&quot;http://www.ieee-security.org/TC/SP2007/oakland07.html&quot;&gt;2007 IEEE Symposium on Security and Privacy&lt;/a&gt; has some interesting papers. The paper by Andreas Moser, Christopher Kruegel, and Engin Kirda from the &lt;a href=&quot;http://www.seclab.tuwien.ac.at/&quot;&gt;Secure Systems Lab&lt;/a&gt; on &quot;&lt;a href=&quot;http://www.auto.tuwien.ac.at/~chris/research/doc/oakland07_explore.pdf&quot;&gt;Exploring Multiple Execution Paths for Malware Analysis&lt;/a&gt;&quot; deals with dynamic enumeration of execution paths. Such an approach can help to detect execution paths that are only triggered on certain conditions and helps with behavior-based analysis of malware.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Abstract&lt;/strong&gt;&lt;br /&gt;
Malicious code (or malware) is defined as software that fulfills the deliberately harmful intent of an attacker. Malware analysis is the process of determining the behavior and purpose of a given malware sample (such as a virus, worm, or Trojan horse). This process is a necessary step to be able to develop effective detection techniques and removal tools. Currently, malware analysis is mostly a manual process that is tedious and time-intensive. To mitigate this problem, a number of analysis tools have been proposed that automatically extract the behavior of an unknown program by executing it in a restricted environment and recording the operating system calls that are invoked. &lt;br /&gt;
The problem of dynamic analysis tools is that only a single program execution is observed. Unfortunately, however, it is possible that certain malicious actions are only triggered under specific circumstances (e.g., on a particular day, when a certain file is present, or when a certain command is received). In this paper, we propose a system that allows us to explore multiple execution paths and identify malicious actions that are executed only when certain conditions are met. This enables us to automatically extract a more complete view of the program under analysis and identify under which circumstances suspicious actions are carried out. Our experimental results demonstrate that many malware samples show different behavior depending on input read from the environment. Thus, by exploring multiple execution paths, we can obtain a  more complete picture of their actions. 
    </content:encoded>

    <pubDate>Wed,  9 May 2007 11:14:00 +0200</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/122-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>Security of virtual machines</title>
    <link>http://honeyblog.org/archives/109-Security-of-virtual-machines.html</link>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/109-Security-of-virtual-machines.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=109</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=109</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    Tavis Ormandy just gave an interesting presentation at &lt;a href=&quot;http://cansecwest.com/agenda.html&quot;&gt;CanSecWest&#039;07&lt;/a&gt; about the security of virtual machines (QEMU, VMware, Bochs, ...) entitled &quot;An Empirical Study into the Security Exposure to Hosts of Hostile Virtualized Environment&quot;. Using fuzzing and other techniques, he managed to find quite a few bugs in popular VMs, amongst others:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;heap overflow in QEMU&#039;s NE2000 network device&lt;/li&gt;&lt;br /&gt;
&lt;li&gt;heap overflow in QEMU&#039;s VGA code&lt;/li&gt;&lt;br /&gt;
&lt;li&gt;vulnerability in VMware&#039;s power management code&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;
For example, his summary for the security of QEMU is:&lt;br /&gt;
&lt;blockquote&gt;An attacker with access to a QEMU virtualized environment could potentially compromise the virtual machine process and execute arbitrary code with the privileges of the emulator. Malware being studied inside QEMU, even in an unprivileged state, can terminate the virtual machine safely and reliably.&lt;/blockquote&gt;&lt;br /&gt;
Regarding malware analysis, these results presumably mean that the malware analysis process should be carried out on a native machine with some kind of &lt;a href=&quot;http://www.coreprotect.com/&quot;&gt;restore cards&lt;/a&gt; since we can not trust the malware code. We use such a setup within CWSandbox and the results look promising. &lt;br /&gt;
&lt;br /&gt;
Tavis also released a &lt;a href=&quot;http://taviso.decsystem.org/virtsec.pdf&quot;&gt;paper&lt;/a&gt; describing the results in detail. The paper also includes some proof-of-concept demos. Soon you can also find his presentation at the CanSec website.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Abstract&lt;/b&gt; &lt;br /&gt;
As virtual machines become increasingly commonplace as a method of separating hostile or hazardous code from commodity systems, the potential security exposure from implementation flaws has increased dramatically. This paper investigates the state of popular virtual machine implementations for x86 systems, employing a combination of source code auditing and blackbox random testing to assess the security &lt;br /&gt;
exposure to the hosts of hostile virtualized environment. 
    </content:encoded>

    <pubDate>Fri, 20 Apr 2007 23:24:44 +0200</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/109-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>Rishi: Identify Bot Contaminated Hosts </title>
    <link>http://honeyblog.org/archives/107-Rishi-Identify-Bot-Contaminated-Hosts.html</link>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/107-Rishi-Identify-Bot-Contaminated-Hosts.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=107</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=107</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.usenix.org/events/hotbots07/&quot;&gt;HotBots&#039;07&lt;/a&gt; took place last week in Boston. The paper by Jan Göbel and me is now &lt;a href=&quot;http://honeyblog.org/junkyard/paper/2007-rishi-hotbots.pdf&quot;&gt;available&lt;/a&gt; and I also publish the &lt;a href=&quot;http://honeyblog.org/junkyard/paper/2007-rishi-hotbots-talk.pdf&quot;&gt;slides&lt;/a&gt; from my talk.&lt;br /&gt;
This workshop was by invitation only. As a courtesy, USENIX made the accepted papers &lt;a href=&quot;http://www.usenix.org/events/hotbots07/tech/&quot;&gt;available to everyone&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;&lt;a href=&quot;http://honeyblog.org/archives/107-Rishi-Identify-Bot-Contaminated-Hosts.html#extended&quot;&gt;Continue reading &quot;Rishi: Identify Bot Contaminated Hosts &quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Thu, 19 Apr 2007 17:54:00 +0200</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/107-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>Program for HotBots'07 / Rishi</title>
    <link>http://honeyblog.org/archives/105-Program-for-HotBots07-Rishi.html</link>
            <category>administrativa</category>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/105-Program-for-HotBots07-Rishi.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=105</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=105</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    The program for the &lt;a href=&quot;http://www.usenix.org/events/hotbots07/tech/&quot;&gt;First Workshop on Hot Topics in Understanding Botnets&lt;/a&gt; is now online. The program committee accepted 11 papers from 32 submissions. Together with Jan Göbel, I also submitted a paper which was accepted. The paper entitled &quot;&lt;em&gt;Rishi: Identify Bot Contaminated Hosts by IRC Nickname Evaluation&lt;/em&gt;&quot;, describes a simple, yet effective methods to detect bot-contaminated hosts within a given network. It tries to detect suspicious IRC nicknames and preliminary results show the usefulness. I will upload the paper once the workshop is over.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Abstract&lt;/strong&gt;:&lt;br /&gt;
In this paper, we describe a simple, yet effective method to detect bot-infected machines within a given network that relies on detection	of the communication channel between bot and Command &amp;amp; Control server (C&amp;C server). The presented techniques are mainly based on passively monitoring network traffic for unusual or suspicious IRC nicknames, IRC servers, and uncommon server ports.  By using n-gram analysis and a scoring system, we are able to detect bots that use uncommon communication channels, which are commonly not detected by classical intrusion detection systems.  Upon detection, it is possible to determine the IP address of the C\&amp;C server, as well as, the channels a bot joined and the additional parameters which were set. The software &quot;Rishi&quot; implements the mentioned features and is able to automatically generate warning emails to report infected machines to an administrator. Within the 10 GBit network of RWTH Aachen university, we detected 82 bot-infected machines within two weeks, some of them using communication channels not picked up by other intrusion detection systems. 
    </content:encoded>

    <pubDate>Thu,  5 Apr 2007 08:50:00 +0200</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/105-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>&quot;Puppetnets: Misusing Web Browsers as a Distributed Attack Infrastructure&quot;</title>
    <link>http://honeyblog.org/archives/87-Puppetnets-Misusing-Web-Browsers-as-a-Distributed-Attack-Infrastructure.html</link>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/87-Puppetnets-Misusing-Web-Browsers-as-a-Distributed-Attack-Infrastructure.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=87</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=87</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    The recent ACM Conference on Computer and Communications Security (&lt;a href=&quot;http://www.acm.org/sigs/sigsac/ccs/CCS2006/&quot;&gt;CCS&#039;06&lt;/a&gt;) had some interesting papers. One of them deals with so called &lt;em&gt;Puppetnets&lt;/em&gt;. A puppetnet is created by malicious web sites which exploit a visiting web browser and take control of it. Similar to a botnet, these puppetnets can be used to mount DDoS attacks, reconnaissance probes, or other nefarious purposes. Presumably the threat posed by these networks is way lower than botnets, but nevertheless they could pose a problem in the future due to the prevalance of client-side exploits. The whole paper is entitled &quot;&lt;a href=&quot;http://s3g-mirror.malware-dmz.org/papers/puppetnets-ccs06.pdf&quot;&gt;Puppetnets: Misusing Web Browsers as a Distributed Attack Infrastructure&lt;/a&gt;&quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Abstract&lt;/strong&gt;&lt;br /&gt;
Most of the recent work on Web security focuses on preventing attacks that directly harm the browser’s host machine and user. In this paper we attempt to quantify the threat of browsers being indirectly misused for attacking third parties. Specifically, we look at how the existing Web infrastructure (e.g., the languages, protocols, and security policies) can be exploited by malicious Web sites to remotely instruct browsers to orchestrate actions including denial of service attacks, worm propagation and reconnaissance scans. We show that, depending mostly on the popularity of a maliciousWeb site and user browsing patterns, attackers are able to create powerful botnet-like infrastructures that can cause significant damage. We explore the effectiveness of countermeasures including anomaly detection and more fine-grained browser security policies.&lt;br /&gt;
 &lt;br /&gt;&lt;a href=&quot;http://honeyblog.org/archives/87-Puppetnets-Misusing-Web-Browsers-as-a-Distributed-Attack-Infrastructure.html#extended&quot;&gt;Continue reading &quot;&amp;quot;Puppetnets: Misusing Web Browsers as a Distributed Attack Infrastructure&amp;quot;&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Mon,  5 Mar 2007 12:17:00 +0100</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/87-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>Advanced Honeypot-Based Intrusion Detection</title>
    <link>http://honeyblog.org/archives/96-Advanced-Honeypot-Based-Intrusion-Detection.html</link>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/96-Advanced-Honeypot-Based-Intrusion-Detection.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=96</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=96</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    Together with Jan Göbel and Jens Hektor from the &lt;a href=&quot;http://www.rz.rwth-aachen.de/rztop/english/index.php&quot;&gt;Center for Computing and Communication&lt;/a&gt; at RWTH Aachen University, I published an article entitled &quot;&lt;em&gt;Advanced Honeypot-Based Intrusion Detection&lt;/em&gt;&quot; in the recent &lt;a href=&quot;http://www.usenix.org/publications/login/2006-12/index.html&quot;&gt;;login: (Volume 31, Number 6)&lt;/a&gt; magazine.&lt;br /&gt;
&lt;br /&gt;
The paper describes a custom network intrusion detection system called Blast-o-Mat based on different sensors, one of them being nepenthes. We describe the system and give an overview of the lessons learned, some quantitative results, and an example of a Haxdoor infection detected via the system.&lt;br /&gt;
&lt;br /&gt;
A live demo of Blast-o-Mat is available at the &lt;a href=&quot;http://www.rz.rwth-aachen.de/kommunikation/betrieb/auto/status/blast-o-mat.php&quot;&gt;Blast-o-mat Status&lt;/a&gt; page.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Abstract&lt;/strong&gt;:&lt;br /&gt;
At RWTH Aachen University, with about 40,000 computer-using people to support, we have built a system to detect infected machines based on honeypots.  One important building block of Blast-o-Mat is Nepenthes, which we use both to detect malware-infected systems and to collect malware. Nepenthes is a&lt;br /&gt;
low-interaction honeypot that appears as vulnerable software but instead decodes attack code and downloads malware. We have been successful at uncovering and quarantining infected systems with sensors listening at 0.1% of our address space.  Investigation of collected malware has led to discovery of many infected systems and even a huge cache of stolen identity information. 
    </content:encoded>

    <pubDate>Sun, 28 Jan 2007 21:52:00 +0100</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/96-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>Stock Spam</title>
    <link>http://honeyblog.org/archives/93-Stock-Spam.html</link>
            <category>paper</category>
    
    <comments>http://honeyblog.org/archives/93-Stock-Spam.html#comments</comments>
    <wfw:comment>http://honeyblog.org/wfwcomment.php?cid=93</wfw:comment>

    <slash:comments>2</slash:comments>
    <wfw:commentRss>http://honeyblog.org/rss.php?version=2.0&amp;type=comments&amp;cid=93</wfw:commentRss>
    

    <author>nospam@example.com (Thorsten Holz)</author>
    <content:encoded>
    This morning I took a closer look at the 500 last messages of my spam inbox at the gmail account (about the last five days). 106 of them were stock spam, thus a little more than 20% of the spam I receive is related to this kind of spam. These messages target only eight different ticker symbols:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://finance.yahoo.com/q?s=PHYA.PK&quot;&gt;PHYA.PK&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://finance.yahoo.com/q?s=CICG.PK&quot;&gt;CICG.PK&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://finance.yahoo.com/q?s=QCPC.PK&quot;&gt;QCPC.PK&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://finance.yahoo.com/q?s=MISJ.PK&quot;&gt;MISJ.PK&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://finance.yahoo.com/q?s=AFML.PK&quot;&gt;AFML.PK&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://finance.yahoo.com/q?s=APPM.PK&quot;&gt;APPM.PK&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://finance.yahoo.com/q?s=HXPN.PK&quot;&gt;HXPN.PK&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://finance.yahoo.com/q?s=HLUN.PK&quot;&gt;HLUN.PK&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;
As you can see, all of these ticker symbols are traded at &lt;a href=&quot;http://en.wikipedia.org/wiki/Pink_sheet&quot;&gt;Pink Sheets&lt;/a&gt;, an electronic system for trading &lt;a href=&quot;http://en.wikipedia.org/wiki/Penny_stock&quot;&gt;penny stocks&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
When taking a look at the reaction of the stock quotes, you can see some influence, some of the stocks being currently in their &quot;&lt;a href=&quot;http://en.wikipedia.org/wiki/Pump_and_dump&quot;&gt;pump&lt;/a&gt;&quot; phase:&lt;br /&gt;
&lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://honeyblog.org/uploads/stuff/hlun.png&#039;&gt;&lt;img width=&#039;110&#039; height=&#039;62&#039; style=&quot;border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://honeyblog.org/uploads/stuff/hlun.serendipityThumb.png&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://honeyblog.org/uploads/stuff/hxpn.png&#039;&gt;&lt;img width=&#039;110&#039; height=&#039;62&#039; style=&quot;border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://honeyblog.org/uploads/stuff/hxpn.serendipityThumb.png&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://honeyblog.org/uploads/stuff/appm.png&#039;&gt;&lt;img width=&#039;110&#039; height=&#039;62&#039; style=&quot;border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://honeyblog.org/uploads/stuff/appm.serendipityThumb.png&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://honeyblog.org/uploads/stuff/afml.png&#039;&gt;&lt;img width=&#039;110&#039; height=&#039;62&#039; style=&quot;border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://honeyblog.org/uploads/stuff/afml.serendipityThumb.png&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://honeyblog.org/uploads/stuff/misj.png&#039;&gt;&lt;img width=&#039;110&#039; height=&#039;62&#039; style=&quot;border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://honeyblog.org/uploads/stuff/misj.serendipityThumb.png&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://honeyblog.org/uploads/stuff/qcpc.png&#039;&gt;&lt;img width=&#039;110&#039; height=&#039;62&#039; style=&quot;border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://honeyblog.org/uploads/stuff/qcpc.serendipityThumb.png&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://honeyblog.org/uploads/stuff/cicg.png&#039;&gt;&lt;img width=&#039;110&#039; height=&#039;62&#039; style=&quot;border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://honeyblog.org/uploads/stuff/cicg.serendipityThumb.png&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://honeyblog.org/uploads/stuff/phya.png&#039;&gt;&lt;img width=&#039;110&#039; height=&#039;62&#039; style=&quot;border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://honeyblog.org/uploads/stuff/phya.serendipityThumb.png&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Presumably we will see a drop in the quotes in the next few days.&lt;br /&gt;
&lt;br /&gt;
Most of the stock spam messages nowadays are image-based: only two ticker symbols are advertized via plain-text messages, the other six use images. Common &lt;a href=&quot;http://en.wikipedia.org/wiki/Optical_character_recognition&quot;&gt;OCR&lt;/a&gt; is pretty weak at recognizing the image content since it is scrambled in order to make filtering harder:&lt;br /&gt;
&lt;blockquote&gt;$ gocr personnel.gif&lt;br /&gt;
&lt;u&gt;                              &lt;/u&gt;   _&lt;br /&gt;
H&#039;LuN,.pK . H &#039;% BIopH, ARMAcE%IcAL s_ocK!, , _&lt;br /&gt;
HEA%HeuNIv,E\RsE,I&#039;nc&lt;br /&gt;
S_b&#039;ol:  HLU_               ,         ,&lt;br /&gt;
Price: $o.o8 &#039; &#039;                     ,  &#039;&lt;br /&gt;
5.day Target: , $O.50  ,&#039;       ,&lt;br /&gt;
Rating: Strong Buy              ,,&lt;br /&gt;
HLU_.PH .$15 billion, plastic _cosmetic surgey m,a_ket!&lt;br /&gt;
H L U &lt;u&gt;. P H .,G ETrl &lt;/u&gt; G &lt;u&gt; READY TO E X P L O&#039; D,E ! ! !   &lt;/u&gt; _&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
For more background at this kind of attacks, take a look at our study on stock spam (&quot;&lt;a href=&quot;http://papers.ssrn.com/sol3/papers.cfm?abstract_id=897431&quot;&gt;The Effect of Stock Spam on Financial Markets&lt;/a&gt;&quot;). 
    </content:encoded>

    <pubDate>Wed, 10 Jan 2007 13:36:00 +0100</pubDate>
    <guid isPermaLink="false">http://honeyblog.org/archives/93-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>

</channel>
</rss>