10.17.2007

Table of Contents


  1. Introduction (2)
  2. Honeypots, Honeynets and Honeywalls
  3. Advantages of Honeypots
  4. Disadvantages of Honeypots
  5. IDS
  6. Advantages of IDS
  7. Disadvantages of IDS
  8. How can IDS help Honeypots?
  9. The Suggested Architecture
  10. Possible extensions to this Architecture
  11. Conclusions
  12. Appendices

Report Outline


Introduction (1P 4L)

Report Format


CSUS Project/Thesis Resources Link
http://www.csus.edu/gradstudies/forms.htm#Thesis

Introduction

In today's age, Information and Data are the most valuable assets for any organization. Industries and Organizations worldwide invest greatly in the technologies of today to procure such data and ensure its availability to benefit businesses. With the accelerating advancements in Networking and growing Internet technologies, Information can be made available to virtually anyone anywhere in the world connected through a wired or wireless communication point. Governments, military, financial institutions, hospitals, and private businesses gather and consume a great deal of confidential information that needs to be available to authorized personnel and system via controlled access. Protecting confidential information is, in several business scenarios, a legal requirement. For the individual, information security could have a significant impact on Privacy.

While such enabling technologies greatly aid businesses, they also pose the difficult challenge of securing and safekeeping such valuable Information and Data from hackers or other malicious software programs. Information security is the process of protecting data and information systems from unauthorized access, use or destruction.

Traditionally, network security consisted of tools and methods to restrict access to known attack patterns and signatures. The effectiveness of such a system heavily relied on keeping the attack patterns database up to date and demanded continuous upgrades to the security implementation as more and more attack patterns were discovered.

Information security has grown and evolved significantly in the recent years. Today's strategy is targeted at building a trainable security architecture that will learn and enhance its attack signatures and patterns storehouse progressively and apply it, thereby making the system better with every attack or intrusion attempt. These systems typically work on a Prevention-Detection-Response mechanism. They are architected with -

  1. Prevention interfaces - that prevent attackers from gaining access to protected systems
  2. Detection interfaces - that detect that the request in an intrusion attempt using the access signature or pattern
  3. Response interfaces - that send expected responses to intrusion requests, thereby acting as a decoy system
This type of mechanism enables befriending enemies to learn their attack mechanisms and signatures to enhance the capabilities of the security infrastructure and to apply it back at them to detect and prevent intrusion attempts.

Although intrusion and hacking attempts to a network or data store can never be eliminated altogether, they can be significantly reduced by building a security infrastructure using the tools and techniques of today in a manner most effective for the organization targeted.