10/29/2008

Leurre.com another honeypot project you can participate in

Platforms are now located all over the world, covering around 30 countries in the 5 continents. We capture all traffic to and from these platforms, store it into a sophisticated SQL database, enrich it with contextual information, such as geographical information of the attackers, os fingerprinting, domain names reverse lookups, etc. We cluster together, thanks to some novel technique, all traces that are likely due to the very same attack tool. We offer access to all our partners to the whole database and provide an easy-to-use graphical interface to query it in a rather intuitive way.This enables our partners to see how differently they are attacked than the others. Is it more or less often, by the same people, using the same techniques, etc.?
The agreement between us and each partner is very simple. To become a partner, an institution simply needs to agree to host one of our platforms. As a consequence, they get access to the whole dataset accumulated throughout the last 3 years. They also need to sign a Non Disclosure Agreement where they commit not to reveal neither the names of the partners nor the names of the attackers.

http://www.leurrecom.org/

14:32 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Post a comment