[ :: mainpage :: register :: conference :: training :: call for papers (CFP) :: the venue ]
[ :: capture the flag (CTF) :: press/media :: conference agenda :: contact us ]
[ :: forum :: sponsors :: past conferences :: conference kit (PDF) ]

Nguyen Anh Quynh (PhD student of Keio university, Japan)

Filed under: Main Page — Administrator @ 10:26 am

May 19, 2006

Presentation Title: Towards an Invisible Honeypot Monitoring System
Presentation Details:

Honeypot is a decoy system to trap attackers, and data capture tool is one of the core components of the honeypot architecture. The most vital requirement of this component is that it must function as stealthily as possible, so the intruder is not aware of its presence. Currently Sebek is the most sophisticated tool for this purpose. Unfortunately Sebek is rather easy to detect, even with unprivileged right access. This talk discusses the drawbacks of Sebek, then proposes an architecture and implementation of a tool named Xebek. Based on Xen Virtual Machine technology, Xebek aims to address the most outstanding problems of Sebek. While Xebek provides the similar features as Sebek does, our tool is far more “invisible” and harder to uncover. The experimental results also demonstrate that Xebek is more flexible, while the reliability and efficiency are significantly improved over its counterpart.

About Quynh

Nguyen Anh Quynh is a PhD student of Keio university, Japan. His research interests include computer security, networking, forensic, virtualization, robust system and Operating System. He is one of the key contributors of Xen Virtual Machine, and he also contributes to various other open source projects. Currently he is working on security problems of virtual machines, specifically focus on Xen.



Event Organizer


Hack In The Box (M) Sdn. Bhd.

Supported & Endorsed By


Malaysian Communications and Multimedia Commission (MCMC)


Malaysian Administrative Modernisation & Management Planning Unit

Platinum Sponsors


Foundstone - A division of McAfee Inc.

Microsoft Corporation

Main Sponsors

Cisco Systems

Lucent Technologies - Bell Labs Innovations

Official Airline Partner


Internet Bandwidth Sponsor


AIMS - Malaysia's Telecommunications Hub

Official Hotel


Westin Kuala Lumpur

CTF Sponsor


Ascendsys

CTF Prize Sponsor


Scan Associates Berhad.


Our Speakers Are Supported By:


Bellua Asia Pacific


Core Security Technologies

Media Partners:

InfoSec News

(ISN) InfoSec News

Virus Bulletin online magazine is dedicated exclusively to reporting and analysing malicious computer programs and spam. The annual Virus Bulletin conference is cited by many in the industry as the anti-malware event of the year.

Insecure Magazine

Phrack Magazine

Hakin9 Magazine

Supporting Organizations


HERT


ISECOM - Insititue for Security and Open Methodologies


IT Underground


Chaos Computer Club (Germany)


X-Focus China

Zone-H Defacement Mirror


Xatrix Security


SyScan


Special Interest Group in Security & Information InteGrity Singapore