SlideShare a Scribd company logo
Honeypots and Security
Data Gathering BoF
Honeynet
• APNIC (adli@apnic.net) has set up a honeynet using
Modern Honeypot Network (MHN)
• Looking for more volunteers to join
– All you need is a VM and a public IP address
– The more the merrier!
2
Honeynet
3
Honeynet
4
Honeynet
5
Passive DNS
• Malware and e-crime rely heavily on the DNS, and so-
called "fast flux botnets" abuse the DNS with frequent
updates and low TTLs.
Passive DNS databases can answer questions that are
difficult or impossible to answer with the standard DNS
protocol, such as:
– Where did this domain name point to in the past?
– What domain names are hosted by a given nameserver?
– What domain names point into a given IP network?
– What subdomains exist below a certain domain name?
6
Passive DNS
• Farsight (wwww.farsightsecurity.com) is running a large
PDNS network, participants are allowed to view data
• FIRST Passive DNS Exchange SIG working on a standard
for Common Output Format
– https://datatracker.ietf.org/doc/draft-dulaunoy-dnsop-passive-dns-cof/
• What would you do with the data from 200,000 DNS
resolutions per second?
7
CyberGreen
• Collects data and provides metrics on risk indicators around
DDoS potential
– Open DNS
– Open NTP
– Open SSDP
– Open SNMP
8
CyberGreen
9
CyberGreen
10
Censys
• The Censys Projects publishes daily snapshots of what we
know about each IPv4 host, Alexa Top Million website, and
known X.509 certificate.
• These datasets contain structured, non-ephemeral JSON
records that identify a host's configuration.
• https://scans.io/
• https://www.censys.io/
11
Censys
12
Questionnaires
• APNIC does a survey every 2 years to shape direction
• What about faster surveys for smaller corners of APNIC?
• Small optional surveys, anonymous if desired/possible
13
Questionnaires
• Do we need to encourage you to participate?
• Maybe offer chocolates or invites to the Whisky BoF for
regular contributors? (BYO whiskey ;) )
14
Next steps
• Should we do more?
• How to do more?
• What else should we do?
15
16

More Related Content

PDF
PacNOG 29: Routing security is more than RPKI
PDF
Rolling the Root Zone DNSSEC Key Signing Key
PDF
ION Islamabad - Deploying DNSSEC
PDF
2nd ICANN APAC-TWNIC Engagement Forum: Why RPKI Matters
PDF
DNSSEC Deployment for .VN and share information of DNSSEC's plan in 2017
PDF
HKNOG 1.0 - DDoS attacks in an IPv6 World
PDF
2nd ICANN APAC-TWNIC Engagement Forum: DNS Oblivion
PDF
ION Islamabad - DANE/DNSSEC/TLS Testing in the go6lab
PacNOG 29: Routing security is more than RPKI
Rolling the Root Zone DNSSEC Key Signing Key
ION Islamabad - Deploying DNSSEC
2nd ICANN APAC-TWNIC Engagement Forum: Why RPKI Matters
DNSSEC Deployment for .VN and share information of DNSSEC's plan in 2017
HKNOG 1.0 - DDoS attacks in an IPv6 World
2nd ICANN APAC-TWNIC Engagement Forum: DNS Oblivion
ION Islamabad - DANE/DNSSEC/TLS Testing in the go6lab

What's hot (18)

PDF
CNIT 124: Ch 7: Capturing Traffic
PDF
DEVNET-1007 Network Infrastructure as Code with Chef and Cisco
PPTX
Copia de presentación1
PPTX
ION Hangzhou - How to Deploy DNSSEC
PDF
2016 COSCUP SDN Introduction
PPTX
DoH, DoT and ESNI
PDF
Encrypted DNS - DNS over TLS / DNS over HTTPS
PPTX
ONOS intent introduction
PDF
Spotify: P2P music-on-demand streaming
PDF
23rd PITA AGM and Conference: DNS Security - A holistic view
PDF
CNIT 121: 14 Investigating Applications
PPTX
Web identity part1
PDF
Tutorial: IPv6-only transition with demo
PDF
CNIT 152: 9 Network Evidence
PDF
2016 COSCUP ONOS
PDF
Silicon Valley Code Camp 2016 - MongoDB in production
PPTX
WHOIS the Master
CNIT 124: Ch 7: Capturing Traffic
DEVNET-1007 Network Infrastructure as Code with Chef and Cisco
Copia de presentación1
ION Hangzhou - How to Deploy DNSSEC
2016 COSCUP SDN Introduction
DoH, DoT and ESNI
Encrypted DNS - DNS over TLS / DNS over HTTPS
ONOS intent introduction
Spotify: P2P music-on-demand streaming
23rd PITA AGM and Conference: DNS Security - A holistic view
CNIT 121: 14 Investigating Applications
Web identity part1
Tutorial: IPv6-only transition with demo
CNIT 152: 9 Network Evidence
2016 COSCUP ONOS
Silicon Valley Code Camp 2016 - MongoDB in production
WHOIS the Master
Ad

Similar to Honeypots and Security (20)

PDF
DNS in IR: Collection, Analysis and Response
PPTX
Infrastructure Tracking with Passive Monitoring and Active Probing: ShmooCon ...
PDF
12 Years in DNS Security As a Defender
PPTX
Infoblox - turning DNS from security target to security tool
PDF
May The Data Stay with U! Network Data Exfiltration Techniques - Brucon 2017.
PDF
DNS как линия защиты/DNS as a Defense Vector
PPTX
( Ethical hacking tools ) Information grathring
PDF
Dns firewalls null-may2020
PDF
Passive DNS Collection -- the 'dnstap' approach, by Paul Vixie [APNIC 38 / AP...
PDF
CNIT 40: 4: Monitoring and detecting security breaches
PDF
OSINT for Attack and Defense
PDF
CNIT 40: 4: Monitoring and detecting security breaches
PPTX
Grehack2013-RuoAndo-Unraveling large scale geographical distribution of vulne...
PDF
OSMC 2016 - DNS Monitoring from Several Vantage Points by Stéphane Bortzmeyer
PDF
Denial of Service - Service Provider Overview
PPTX
Distributed Sensor Data Contextualization for Threat Intelligence Analysis
PDF
OSINT: Open Source Intelligence - Rohan Braganza
PDF
DNS – Strategies for Reducing Data Leakage & Protecting Online Privacy – Hack...
PPTX
The DNS of Things
PDF
Measurement Study of Open Resolvers and DNS Server Version
DNS in IR: Collection, Analysis and Response
Infrastructure Tracking with Passive Monitoring and Active Probing: ShmooCon ...
12 Years in DNS Security As a Defender
Infoblox - turning DNS from security target to security tool
May The Data Stay with U! Network Data Exfiltration Techniques - Brucon 2017.
DNS как линия защиты/DNS as a Defense Vector
( Ethical hacking tools ) Information grathring
Dns firewalls null-may2020
Passive DNS Collection -- the 'dnstap' approach, by Paul Vixie [APNIC 38 / AP...
CNIT 40: 4: Monitoring and detecting security breaches
OSINT for Attack and Defense
CNIT 40: 4: Monitoring and detecting security breaches
Grehack2013-RuoAndo-Unraveling large scale geographical distribution of vulne...
OSMC 2016 - DNS Monitoring from Several Vantage Points by Stéphane Bortzmeyer
Denial of Service - Service Provider Overview
Distributed Sensor Data Contextualization for Threat Intelligence Analysis
OSINT: Open Source Intelligence - Rohan Braganza
DNS – Strategies for Reducing Data Leakage & Protecting Online Privacy – Hack...
The DNS of Things
Measurement Study of Open Resolvers and DNS Server Version
Ad

More from APNIC (20)

PPTX
APNIC Report, presented at APAN 60 by Thy Boskovic
PDF
APNIC Update, presented at PHNOG 2025 by Shane Hermoso
PDF
RPKI Status Update, presented by Makito Lay at IDNOG 10
PDF
The Internet -By the Numbers, Sri Lanka Edition
PDF
Triggering QUIC, presented by Geoff Huston at IETF 123
PDF
DNSSEC Made Easy, presented at PHNOG 2025
PDF
BGP Security Best Practices that Matter, presented at PHNOG 2025
PDF
APNIC's Role in the Pacific Islands, presented at Pacific IGF 2205
PDF
IPv6 Deployment and Best Practices, presented by Makito Lay
PDF
Cleaning up your RPKI invalids, presented at PacNOG 35
PDF
The Internet - By the numbers, presented at npNOG 11
PDF
Transmission Control Protocol (TCP) and Starlink
PDF
DDoS in India, presented at INNOG 8 by Dave Phelan
PDF
Global Networking Trends, presented at the India ISP Conclave 2025
PDF
Make DDoS expensive for the threat actors
PDF
Fast Reroute in SR-MPLS, presented at bdNOG 19
PDF
DDos Mitigation Strategie, presented at bdNOG 19
PDF
ICP -2 Review – What It Is, and How to Participate and Provide Your Feedback
PDF
APNIC Update - Global Synergy among the RIRs: Connecting the Regions
PDF
Measuring Starlink Protocol Performance, presented at LACNIC 43
APNIC Report, presented at APAN 60 by Thy Boskovic
APNIC Update, presented at PHNOG 2025 by Shane Hermoso
RPKI Status Update, presented by Makito Lay at IDNOG 10
The Internet -By the Numbers, Sri Lanka Edition
Triggering QUIC, presented by Geoff Huston at IETF 123
DNSSEC Made Easy, presented at PHNOG 2025
BGP Security Best Practices that Matter, presented at PHNOG 2025
APNIC's Role in the Pacific Islands, presented at Pacific IGF 2205
IPv6 Deployment and Best Practices, presented by Makito Lay
Cleaning up your RPKI invalids, presented at PacNOG 35
The Internet - By the numbers, presented at npNOG 11
Transmission Control Protocol (TCP) and Starlink
DDoS in India, presented at INNOG 8 by Dave Phelan
Global Networking Trends, presented at the India ISP Conclave 2025
Make DDoS expensive for the threat actors
Fast Reroute in SR-MPLS, presented at bdNOG 19
DDos Mitigation Strategie, presented at bdNOG 19
ICP -2 Review – What It Is, and How to Participate and Provide Your Feedback
APNIC Update - Global Synergy among the RIRs: Connecting the Regions
Measuring Starlink Protocol Performance, presented at LACNIC 43

Recently uploaded (20)

PDF
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
PPTX
E -tech empowerment technologies PowerPoint
PPTX
Mathew Digital SEO Checklist Guidlines 2025
PPTX
Slides PPTX: World Game (s): Eco Economic Epochs.pptx
PPT
415456121-Jiwratrwecdtwfdsfwgdwedvwe dbwsdjsadca-EVN.ppt
PPTX
t_and_OpenAI_Combined_two_pressentations
PPTX
June-4-Sermon-Powerpoint.pptx USE THIS FOR YOUR MOTIVATION
PDF
simpleintnettestmetiaerl for the simple testint
PPTX
Funds Management Learning Material for Beg
PDF
The New Creative Director: How AI Tools for Social Media Content Creation Are...
PPTX
Layers_of_the_Earth_Grade7.pptx class by
PPT
Ethics in Information System - Management Information System
PPTX
Internet Safety for Seniors presentation
PDF
📍 LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1 TERPOPULER DI INDONESIA ! 🌟
PDF
The Evolution of Traditional to New Media .pdf
PDF
SASE Traffic Flow - ZTNA Connector-1.pdf
PPTX
1402_iCSC_-_RESTful_Web_APIs_--_Josef_Hammer.pptx
PDF
The Ikigai Template _ Recalibrate How You Spend Your Time.pdf
PPT
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
PDF
SlidesGDGoCxRAIS about Google Dialogflow and NotebookLM.pdf
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
E -tech empowerment technologies PowerPoint
Mathew Digital SEO Checklist Guidlines 2025
Slides PPTX: World Game (s): Eco Economic Epochs.pptx
415456121-Jiwratrwecdtwfdsfwgdwedvwe dbwsdjsadca-EVN.ppt
t_and_OpenAI_Combined_two_pressentations
June-4-Sermon-Powerpoint.pptx USE THIS FOR YOUR MOTIVATION
simpleintnettestmetiaerl for the simple testint
Funds Management Learning Material for Beg
The New Creative Director: How AI Tools for Social Media Content Creation Are...
Layers_of_the_Earth_Grade7.pptx class by
Ethics in Information System - Management Information System
Internet Safety for Seniors presentation
📍 LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1 TERPOPULER DI INDONESIA ! 🌟
The Evolution of Traditional to New Media .pdf
SASE Traffic Flow - ZTNA Connector-1.pdf
1402_iCSC_-_RESTful_Web_APIs_--_Josef_Hammer.pptx
The Ikigai Template _ Recalibrate How You Spend Your Time.pdf
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
SlidesGDGoCxRAIS about Google Dialogflow and NotebookLM.pdf

Honeypots and Security

  • 2. Honeynet • APNIC (adli@apnic.net) has set up a honeynet using Modern Honeypot Network (MHN) • Looking for more volunteers to join – All you need is a VM and a public IP address – The more the merrier! 2
  • 6. Passive DNS • Malware and e-crime rely heavily on the DNS, and so- called "fast flux botnets" abuse the DNS with frequent updates and low TTLs. Passive DNS databases can answer questions that are difficult or impossible to answer with the standard DNS protocol, such as: – Where did this domain name point to in the past? – What domain names are hosted by a given nameserver? – What domain names point into a given IP network? – What subdomains exist below a certain domain name? 6
  • 7. Passive DNS • Farsight (wwww.farsightsecurity.com) is running a large PDNS network, participants are allowed to view data • FIRST Passive DNS Exchange SIG working on a standard for Common Output Format – https://datatracker.ietf.org/doc/draft-dulaunoy-dnsop-passive-dns-cof/ • What would you do with the data from 200,000 DNS resolutions per second? 7
  • 8. CyberGreen • Collects data and provides metrics on risk indicators around DDoS potential – Open DNS – Open NTP – Open SSDP – Open SNMP 8
  • 11. Censys • The Censys Projects publishes daily snapshots of what we know about each IPv4 host, Alexa Top Million website, and known X.509 certificate. • These datasets contain structured, non-ephemeral JSON records that identify a host's configuration. • https://scans.io/ • https://www.censys.io/ 11
  • 13. Questionnaires • APNIC does a survey every 2 years to shape direction • What about faster surveys for smaller corners of APNIC? • Small optional surveys, anonymous if desired/possible 13
  • 14. Questionnaires • Do we need to encourage you to participate? • Maybe offer chocolates or invites to the Whisky BoF for regular contributors? (BYO whiskey ;) ) 14
  • 15. Next steps • Should we do more? • How to do more? • What else should we do? 15
  • 16. 16