The Experts below are selected from a list of 1737 Experts worldwide ranked by ideXlab platform

Regla Cristobalina Jiménez Hernández - One of the best experts on this subject based on the ideXlab platform.

Omar Mar Cornelio - One of the best experts on this subject based on the ideXlab platform.

Nohemy Cardentey Moreno - One of the best experts on this subject based on the ideXlab platform.

Suen Yek - One of the best experts on this subject based on the ideXlab platform.

  • Blackhat fingerprinting of the wired and wireless honeynet
    Edith Cowan University, 2005
    Co-Authors: Suen Yek
    Abstract:

    TCP/IP fingerprinting is a common technique used to detect unique Network stack characteristics of an Operating System (OS). Its usage for Network compromise is renowned for performing host discovery and in aiding the blackhat to determine a tailored exploit of detected OSs. The honeyd honeynet is able to countermeasure blackhats utilising TCP/IP fingerprinting via host device emulation on a virtual Network. Honeyd allows the creation of host personalities that respond to Network stack fingerprinting as a real Network would. The nature of this technique however, has shown to provide inconsistent and unreliable results when performed over wired and wireless Network mediums. This paper presents ongoing research into the TCP/IP fingerprinting capabilities of the popular host discovery tool Network Mapper (NMAP) on the honeyd honeynet. The forensic analysis of raw packet-captures allowed the researcher to identify differences in the modus operandi and outcomes of fingerprinting over the two mediums. The results of this exploratory study show the process of discovery to uncover how TCP/IP fingerprinting with NMAP and honeyd needs to be tested for effective Network countermeasure

  • How to build a faraday cage on the cheap for wireless TCP/IP fingerprinting
    Edith Cowan University, 2005
    Co-Authors: Suen Yek
    Abstract:

    The commonly known security weaknesses associated with the 802.11b wireless standard have introduced a variety of security measures to countermeasure attacks. Using a wireless honeypot, a fake wireless Network may be configured through emulation of devices and the TCP/IP fingerprinting of OS Network stacks. TCP/IP fingerprinting is one of the most popular methods employed to determine the type of OS running on a target and this information can then be used to determine the type of vulnerabilities to target on the host. Testing the effectiveness of this technique to ensure that a wireless honeypot using honeyd may deceive an attacker has been an ongoing study due to problems conducting TCP/IP fingerprinting in the wireless environment. Research conducted in a university laboratory showed that the results were ineffective and the time taken to conduct testing could be as long as 60 hours. The subsequent exploration of different testing methods and locations illuminated on an ideal research facility called a faraday cage. The design and construction of the faraday is discussed in this paper as an affordable solution for controlled and reliable testing of TCP/IP fingerprinting against the scanning tool Network Mapper (NMAP). The results are useful when looking to deploy a deceptive honeypot as a defence mechanism against wireless attackers

Yek Suen - One of the best experts on this subject based on the ideXlab platform.

  • Investigating the Accuracy of Wired and Wireless TCP/IP Fingerprinting on Honeyd
    Edith Cowan University Research Online Perth Western Australia, 2006
    Co-Authors: Yek Suen
    Abstract:

    TCP/IP fingerprinting is a technique used to identify the unique Network stack characteristics of an Operating System (OS) and may identify a digital device by its version, vendor and operating platform. The popular Network scanning tool Network Mapper (NMAP) employs TCP/IP fingerprinting to discover host to a high degree of granularity from the manipulation of flag settings in packets. In this research, the honeyd honeynet was configured to test the accuracy of NMAP OS name resolution over a wired and wireless medium. The results indicated how the TCP/IP spoofing capabilities of honeyd could be a realistic Network countermeasure

  • How to build a faraday on the cheap for wireless security testing
    Edith Cowan University Research Online Perth Western Australia, 2005
    Co-Authors: Yek Suen
    Abstract:

    The commonly known security weaknesses associated with the 802.11b wireless standard have introduced a variety of security measures to countermeasure attacks. Using a wireless honeypot, a fake wireless Network may be configured through emulation of devices and the TCP/IP fingerprinting of OS Network stacks. TCP/IP fingerprinting is one of the most popular methods employed to determine the type of OS running on a target and this information can then be used to determine the type of vulnerabilities to target on the host. Testing the effectiveness of this technique to ensure that a wireless honeypot using honeyd may deceive an attacker has been an ongoing study due to problems conducting TCP/IP fingerprinting in the wireless environment. Research conducted in a university laboratory showed that the results were ineffective and the time taken to conduct testing could be as long as 60 hours. The subsequent exploration of different testing methods and locations illuminated on an ideal research facility called a faraday cage. The design and construction of the faraday is discussed in this paper as an affordable solution for controlled and reliable testing of TCP/IP fingerprinting against the scanning tool Network Mapper (NMAP). The results are useful when looking to deploy a deceptive honeypot as a defence mechanism against wireless attackers