A Walk Through “Sombria”: A Network Surveillance System
by Little eArth Corporation Co., Ltd. - Computer Security Laboratory - Wednesday, 10 September 2003.
Bookmark and Share
Sombria ("shadowy" in Portuguese) is a honeypot system set up in Tokyo, Japan, that is intended for network surveillance and research and not for production purposes. This honeypot system consists of a web server, a firewall and an intrusion detection system. Sombria is a combination of surveillance technologies to watch intruders closely and in real time as they go about their mission without them even noticing it. The intrusion detection system first triggers an alarm whenever an individual breaches security or breaks into the system. Meanwhile, all the commands executed (keystrokes) by the intruder are logged for post-attack analysis. And finally, the firewall drops all packets anytime the intruder attempts to use Sombria as a steppingstone to launch attacks against other systems.

This paper provides some statistics and an overview of the most prominent attacks from May through July 2003.


Download the paper in PDF format here.

Spotlight

The security of WordPress plugins

Posted on 18 June 2013.  |  Checkmarx’s research lab identified that more than 20% of the 50 most popular WordPress plugins are vulnerable to common Web attacks, such as SQL Injection.


Daily digest

By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
  

Weekly newsletter

With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.
  

 

DON'T
MISS

Wed, Jun 19th
    COPYRIGHT 1998-2013 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //