[00:00.000 --> 00:03.600] And I want to say by just first, that it's a really big honor to be here. [00:04.920 --> 00:13.300] The security community is really awesome and you guys are awesome, so thanks a lot for keeping it up and you keep doing your thing, I'll keep doing my thing. [00:14.080 --> 00:18.540] All right, so this talk is called Network Anti-Reconnaissance Messing with NMAP Through Smoke and Mirrors. [00:19.940 --> 00:20.780] I'm going to start it. [00:20.900 --> 00:28.340] So I'm going to start by taking a bit of a look back and talk about what I'm going to talk about and also by contrast what I'm not going to be speaking of. [00:29.320 --> 00:32.960] So consider like three main phases of a network attack. [00:33.340 --> 00:37.380] You're not going to find this in like a textbook anywhere because I completely made it up. [00:37.540 --> 00:41.240] But you can think of it as gaining access to some network, right? [00:41.680 --> 00:49.980] So gaining access could mean like exploiting an externally facing computer or maybe you're like literally crawling through the air ducts of like the Gibson Corporation, right? [00:51.340 --> 00:52.320] We don't really care. [00:52.420 --> 00:55.240] So from our perspective like we don't care like how you gain access to it. [00:55.300 --> 00:56.340] We assume you gain access to it. [00:56.340 --> 00:59.340] You bypass the firewall, you bypass everything else on the border security. [00:59.920 --> 01:01.460] So step two is perform reconnaissance. [01:01.580 --> 01:02.980] This is what we're actually going to be concerned about here. [01:03.240 --> 01:07.460] So you want to find out everything you can about the network that it is you want to attack, right? [01:07.480 --> 01:11.800] You want to find out how many systems there are, what types of systems there are, operating systems, ports, everything, right? [01:12.180 --> 01:16.640] So we're going to be talking about what we can do to detect that presence, detect that reconnaissance and also prevent it. [01:17.760 --> 01:19.280] Three is exploiting the vulnerability. [01:20.380 --> 01:28.560] In the process of performing reconnaissance, you hope to find some vulnerability that you're going to exploit and then you actually send the payload. [01:28.740 --> 01:33.880] We're not going to be talking about intrusion detection in the classical sense like Snort does. [01:34.520 --> 01:37.360] Looking for the blaster worm as it goes across your network. [01:37.520 --> 01:38.960] We're not going to be trying to get into that game. [01:39.520 --> 01:40.640] We're just going to be concentrating on number two. [01:41.100 --> 01:42.080] So focus on the second phase. [01:42.600 --> 01:43.000] Antireconnaissance. [01:43.800 --> 01:49.060] So we're talking about skewering your network Or more specifically, obfuscating it, or more technically speaking. [01:49.920 --> 01:54.040] So we're not going to be talking about intrusion detection or prevention, nor access control. [01:54.400 --> 01:54.700] Right? [01:54.860 --> 01:58.640] So if you think, like, all right, well, we found a bad guy, let's kick him from the network. [01:58.780 --> 02:00.220] Like, that's not really what we're trying to do here. [02:00.380 --> 02:03.660] And we're trying to provide anti-reconstance. [02:04.520 --> 02:06.760] This applies to private networks. [02:07.140 --> 02:10.180] So print networks that are not normally publicly accessible. [02:10.920 --> 02:13.200] So that would mean, like, not public networks. [02:13.200 --> 02:15.980] So, like, your university, I think, like, library. [02:16.560 --> 02:16.940] Like, right? [02:17.060 --> 02:19.260] Like, you can just walk around and look at the computers in the library. [02:19.440 --> 02:19.480] Right? [02:19.600 --> 02:23.460] Like, there's not really much I can do against that, like, from a software perspective. [02:24.420 --> 02:29.220] Also, like, external machines, like, Google's web server, like, can't be helped by anything I'm about to talk about. [02:29.340 --> 02:29.380] Right? [02:29.460 --> 02:32.720] Because you need to know where Google's web server is and that port 80 is open. [02:33.020 --> 02:34.360] Like, I can't help you there. [02:35.600 --> 02:37.620] Also, it doesn't help anything against social engineering. [02:37.720 --> 02:44.140] So, like, if you're able to phone up, like, an operator and schmooze them into telling you all your details, like, there's nothing I can do about that. [02:44.500 --> 02:45.660] And also just plain stupidity. [02:45.900 --> 02:49.300] Like, if you post a picture of your network onto the Internet, nothing I can do about that. [02:49.600 --> 02:49.880] Okay. [02:50.180 --> 02:51.800] Let's move on to stuff that we're actually going to be talking about. [02:51.920 --> 02:55.640] So, before we talk about anti-reconnaissance, talk a little bit about reconnaissance. [02:55.840 --> 02:57.640] And a little bit why... how it works. [02:57.800 --> 02:59.980] And a little bit why... how it's hard to prevent. [03:00.900 --> 03:06.960] So, one of the, like, most basic things you want to find out when you first gain access and trying to perform reconnaissance is how many systems are there? [03:07.100 --> 03:08.300] Like, what computers are up? [03:08.900 --> 03:10.800] So, you're going to use an ARP sweep scan for this. [03:11.020 --> 03:12.180] It's one of the most basic techniques. [03:12.340 --> 03:14.060] So, ARP is the address resolution protocol. [03:14.400 --> 03:18.520] It's a way of finding out what MAC address is associated with a given IP address. [03:18.740 --> 03:20.300] So, if you know the IP, you can find out the MAC address. [03:20.540 --> 03:25.240] So, you send out an ARP pack that says, hey, 192.168.1.1, what's your MAC address? [03:25.880 --> 03:29.100] And if he responds and says, here's my MAC address, that means he exists. [03:29.500 --> 03:31.620] Or, you know, at least there's a computer up there, right? [03:31.860 --> 03:34.420] And if he doesn't respond, that probably means that he doesn't exist. [03:34.520 --> 03:35.980] Or at least he's more than a hop away or whatever, right? [03:36.020 --> 03:37.160] You can use this pretty commonly. [03:38.460 --> 03:40.400] Another easy way of doing that is just using a ping. [03:40.540 --> 03:41.640] I think everybody knows ping, right? [03:41.680 --> 03:43.420] You send a ping request, you send a ping reply. [03:43.560 --> 03:45.360] You get a reply back, then he's there. [03:46.620 --> 03:50.080] Though, ping ICMP in general is often blocked a network. [03:50.240 --> 03:54.200] So, a negative response for ping sometimes just means that ICMP is being filtered. [03:56.020 --> 03:59.740] So, then, now you know what ports or what machines exist on this network, right? [03:59.880 --> 04:03.200] So, you found out, like, what IP addresses have machines behind them and what don't. [04:03.440 --> 04:05.940] So, now you want to find some more information, like what ports are open. [04:06.320 --> 04:08.800] Since ports are, like, a really big thing for network security, right? [04:08.880 --> 04:10.000] Like, that's your attack surface. [04:10.340 --> 04:15.880] Like, the more ports that are open on a machine, the more things that could possibly go wrong, which is really good for you as an attacker. [04:16.300 --> 04:17.960] So, you send a TCP packet, right? [04:18.040 --> 04:22.640] You send a SYN packet out to try to connect to the server, to try to connect to the service, right? [04:22.860 --> 04:25.320] If you get a SYN/ACK back, then that means the port's open. [04:25.500 --> 04:27.400] If you get a TCP reset, that means the port's closed. [04:27.600 --> 04:28.900] And there's some other details in here. [04:29.000 --> 04:30.080] There's lots of other weird things that happen. [04:30.180 --> 04:31.620] But that's, like, the two most obvious ones, right? [04:32.580 --> 04:33.880] For UDP, UDP is connectionless. [04:34.860 --> 04:36.080] So, you just send data. [04:36.320 --> 04:37.600] Since there's no connection, right? [04:37.620 --> 04:38.660] You just send a data packet. [04:38.840 --> 04:40.780] And if you get a data packet back, that means it's open. [04:41.800 --> 04:44.780] If you get an TCP port and reach it, that means it's closed. [04:45.080 --> 04:46.820] Of course there's lots of other situations that can happen. [04:46.980 --> 04:51.920] If you don't get a packet back, that could mean that it's open but you haven't gotten a packet back yet. [04:52.760 --> 04:54.560] Or it could mean that it's closed or maybe there's a firewall. [04:54.740 --> 04:56.660] So there's lots of other things but this is the basic idea, right? [04:58.660 --> 04:59.540] So operating systems. [04:59.620 --> 05:00.880] Operating systems are a little bit more interesting. [05:07.460 --> 05:09.900] So NMAP at least detects operating systems. [05:10.000 --> 05:11.260] I'll just talk a little bit about NMAP. [05:11.260 --> 05:15.320] What we're doing here, later on I'll show you a tool we made. [05:15.700 --> 05:22.080] It doesn't specifically target NMAP, but NMAP is just of course the canonical tool that you use to do network mapping. [05:22.680 --> 05:28.040] So specifically what NMAP does to figure out what operating system is running on a computer is really quite ingenious. [05:29.260 --> 05:32.180] They sent out an illegal TCP/IP packet. [05:32.280 --> 05:34.760] They use ICMP, TCP, and UDP. [05:34.760 --> 05:36.580] This is an illegal packet. [05:36.800 --> 05:37.840] So some packet work. [05:37.860 --> 05:41.360] If you have the TCP/IP spec typed out right in front of you. [05:41.760 --> 05:47.060] And you're the programmer of like the TCP/IP stack for an operating system. [05:47.240 --> 05:49.140] You say, what should I do when I get this packet? [05:49.560 --> 05:50.740] The answer is that it's not on there. [05:50.860 --> 05:51.820] It's like it's not in the spec. [05:52.220 --> 05:55.940] So you just have to make up, you have to figure out a way to write it right. [05:56.160 --> 05:57.240] So you're going to respond somehow. [05:57.560 --> 05:58.700] But everyone's going to do it differently. [05:59.140 --> 06:01.780] And so all the operating systems wind up responding differently. [06:02.260 --> 06:05.220] And in fact, different versions of different operating systems wind up responding differently. [06:05.380 --> 06:06.360] Because it's undefined behavior. [06:06.360 --> 06:09.100] So we can use this to figure out what operating system is running. [06:09.280 --> 06:11.380] So we send some weird shaped packet right. [06:11.680 --> 06:13.500] That kind of looks like Australia apparently. [06:15.300 --> 06:19.100] And like Windows will respond in this very unique kind of ugly way. [06:19.380 --> 06:21.720] And Linux will respond in this very nice shapely sort of way. [06:22.720 --> 06:23.700] But they're unique. [06:23.860 --> 06:24.640] That's the important right. [06:24.820 --> 06:26.800] Like you can tell the difference between those two things. [06:27.760 --> 06:29.460] And then we can find out what operating system is running. [06:30.660 --> 06:33.100] So network topology is another thing you want to find right. [06:33.160 --> 06:34.200] You don't want to find not just that. [06:34.200 --> 06:36.020] You can find the exact topology of the networks. [06:36.180 --> 06:37.260] Use trace route to do this. [06:37.700 --> 06:39.860] I won't go through the details of exactly how trace route works. [06:40.000 --> 06:41.100] Because that's like pretty standard, I think. [06:41.680 --> 06:42.280] But that's actually... [06:42.280 --> 06:45.820] That picture right there is actually an output from the Zen map. [06:45.980 --> 06:47.980] The visualization tool inside of Nmap. [06:48.380 --> 06:51.200] So like that's an actual like picture you can get from Nmap. [06:51.400 --> 06:52.300] Like looking at somebody's network. [06:52.660 --> 06:56.580] So you can find like who's behind exactly what router and stuff like that. [06:56.680 --> 06:58.160] Which is all really important information. [06:58.840 --> 06:59.840] You know, for an attacker. [07:00.940 --> 07:04.120] So the next thing you want to find is what services are actually running on... [07:06.580 --> 07:10.700] For the most part this kind of follows naturally from what port they're on. [07:11.460 --> 07:13.980] But also you want to find out what versions of services they're running. [07:14.140 --> 07:15.340] Since that's, you know, highly important. [07:15.440 --> 07:17.760] If they're running a really old version of some service. [07:17.940 --> 07:19.380] Then that's something you want to find out. [07:19.720 --> 07:21.980] And so this works really similar to operating system detection. [07:22.640 --> 07:24.260] Where you can like send unique packets. [07:24.460 --> 07:26.360] And like different versions will send you different stuff back. [07:26.620 --> 07:31.240] Though in fact most of the time the services and the operating systems are just given to you for free. [07:31.240 --> 07:33.500] Like if you just go to a web server. [07:33.960 --> 07:37.820] Like the HTTP banner on it will just say, hey, I'm Windows version this. [07:38.400 --> 07:39.500] Running Apache version this. [07:40.120 --> 07:41.280] Or like if you go to a Telnet server. [07:41.380 --> 07:42.960] It will say, hey, this is a Telnet server. [07:43.160 --> 07:43.320] Exactly. [07:43.680 --> 07:45.080] Like 1.3.3.1. [07:45.320 --> 07:46.700] Like running Windows this. [07:46.900 --> 07:46.960] Right? [07:47.180 --> 07:49.900] So there are some ways of like scrubbing those. [07:50.060 --> 07:51.180] And there's tools for scrubbing those. [07:51.320 --> 07:53.680] But I think in general, like they're not used. [07:53.860 --> 07:55.020] Or people don't know about them. [07:55.660 --> 07:56.640] So, you know. [07:56.980 --> 07:59.840] And so the canonical tool, like I said, for doing all this stuff is NMAP. [08:00.020 --> 08:02.880] So the tool that I have here that I'll show. [08:03.440 --> 08:06.740] And a lot of the research that we've done isn't targeting NMAP specifically. [08:06.940 --> 08:07.520] Like it won't work. [08:07.600 --> 08:08.940] Like anything else except NMAP. [08:10.200 --> 08:12.520] But yeah, that's the obvious thing to talk about. [08:14.140 --> 08:16.300] So why is detecting reconnaissance hard? [08:17.100 --> 08:22.660] I think I won't back up this assertion with any like hard proof in these slides. [08:22.920 --> 08:25.540] But I think that most people just kind of give up on reconnaissance. [08:25.600 --> 08:27.620] People just say, alright, well, we're going to try to find the blaster worm. [08:27.720 --> 08:29.760] I'm going to put an IDS on my network. [08:29.980 --> 08:33.560] And I'll put some like firewalls at the edge of my network to keep people from getting in. [08:33.780 --> 08:34.660] And that's it, right? [08:35.160 --> 08:39.000] And then, well, you know, like how many computers I have isn't a secret. [08:39.000 --> 08:41.020] So I shouldn't try to prevent that. [08:41.220 --> 08:42.960] And so people just give up on reconnaissance. [08:43.860 --> 08:45.420] And I think there's a couple of reasons why. [08:45.420 --> 08:46.320] But one is that it's hard. [08:46.460 --> 08:47.520] So signatures fail, right? [08:47.820 --> 08:49.980] Signatures are how we work at the security community. [08:50.120 --> 08:50.900] We love signatures. [08:51.120 --> 08:52.860] Because they work from a monetization standpoint. [08:53.040 --> 08:54.480] And they also like kind of work. [08:55.040 --> 08:56.880] At least when they do work, they work well. [08:57.820 --> 09:01.200] But all the stuff that I talked about before are identical at the packet level. [09:01.500 --> 09:04.600] Like there's no difference between an art packet that's being used to scan you. [09:04.780 --> 09:08.320] And an actual art packet that people use because networks use them, right? [09:09.040 --> 09:10.560] Ping can be sometimes blocked. [09:10.800 --> 09:14.160] But even then like that is really annoying when you're on a network where ping is blocked. [09:14.160 --> 09:15.500] People complain about it. [09:16.060 --> 09:18.040] I mean and like ping is a... [09:18.040 --> 09:19.060] It's what it's made for. [09:19.200 --> 09:21.720] It's made to like to find out what computers are there. [09:21.880 --> 09:22.980] It's a reconnaissance tool. [09:24.400 --> 09:25.360] So all that stuff, right? [09:25.560 --> 09:26.280] Like TCP sins. [09:26.760 --> 09:35.300] Like in a perfect world, we might think like, oh, well maybe if somebody sends a TCP sin but then doesn't finish the connection, like then we can consider that hostile. [09:35.420 --> 09:38.540] But that's not, you know, in academia that might sound like a good thing to do. [09:38.540 --> 09:41.720] But in the real world, networks have like weird stuff that goes on. [09:41.820 --> 09:43.560] You see strays in packets like all the time. [09:43.740 --> 09:53.460] If you put a signature that says like anytime I see like only two of the three TCP handshake packets and I want to get like an alert for that, you'd be getting alerts constantly. [09:55.520 --> 09:56.920] So speed is another issue, right? [09:56.980 --> 09:58.880] You can be like really, really slow and that can be stealthy. [09:59.020 --> 10:02.520] Like send a packet per hour or per day or even less, right? [10:02.520 --> 10:03.320] And that can be stealthy. [10:04.040 --> 10:05.840] Or being super fast can be stealthy. [10:06.100 --> 10:08.000] Like you can be like finished before anyone notices, right? [10:09.740 --> 10:10.460] And also... [10:10.460 --> 10:11.580] Was that a question? [10:12.100 --> 10:13.200] Oh, I think it was a sneeze or something. [10:14.120 --> 10:17.800] Also because the attacker is already inside your network kind of by definition of this, right? [10:18.040 --> 10:19.700] So all of your border security is pointless. [10:20.060 --> 10:28.380] Like your firewall, if you have your firewall at the top of your network only covering Internet traffic, then it doesn't work because none of the traffic is getting hit by it. [10:28.440 --> 10:30.520] Even if you did have signatures that worked here, right? [10:30.520 --> 10:35.040] You'd have to have like a firewall like on each of the hosts or between all the network connections. [10:35.180 --> 10:35.380] I don't know. [10:41.350 --> 10:43.730] But there's something more fundamental going on here as well. [10:44.050 --> 10:46.590] Is the fact that what we're talking about isn't data. [10:47.030 --> 10:47.450] It's metadata. [10:48.270 --> 10:50.030] And metadata can't be encrypted. [10:50.270 --> 10:58.210] So one of the like main ways that we like security people deal with security issues is by encrypting it. [10:58.350 --> 10:59.430] Because encryption is awesome, right? [11:00.530 --> 11:03.350] So if you consider yourself, you have a packet, right? [11:03.450 --> 11:04.990] Or some message that you want to send. [11:05.190 --> 11:06.730] You can encrypt the contents of the data. [11:07.050 --> 11:09.650] And we can, you know, provide systems that do this. [11:09.730 --> 11:15.250] And we can say with a high degree of security that like the contents of the data is secure. [11:15.350 --> 11:19.110] That's like one of the best things that like our security community has done is like encryption. [11:19.290 --> 11:20.290] We're like really proud of encryption. [11:20.850 --> 11:24.310] But what you can't do is encrypt the metadata of the packet, right? [11:24.310 --> 11:26.410] You can't encrypt when the packet was arrived. [11:26.790 --> 11:28.490] You can't encrypt the size of the packet. [11:28.630 --> 11:29.370] Although you can pad it. [11:29.530 --> 11:33.650] But even then like right, the act, how it's received isn't encrypted. [11:34.590 --> 11:37.690] You can't encrypt the direction that the traffic, that the packet was going. [11:37.790 --> 11:38.590] All this stuff is metadata. [11:40.030 --> 11:45.090] And so I might have equally titled the talk network steganography, right? [11:45.690 --> 11:48.690] In many ways what I'm going to be talking about is very similar to steganography. [11:48.830 --> 11:50.290] I might have called it like network steganography. [11:50.490 --> 11:50.830] But I don't know. [11:51.190 --> 11:52.270] Anti-reconnaissance sounds cool. [11:53.470 --> 11:54.750] And so what we can do is this. [11:55.010 --> 11:56.110] I love that animation by the way. [11:56.570 --> 11:58.670] We just throw in a lot of other data. [11:58.850 --> 12:00.550] And now you don't know which one is real. [12:01.070 --> 12:06.010] And even if you did know which or if you want to find out which one is real, you have to like open all the messages. [12:06.070 --> 12:07.370] And it's a very cumbersome process. [12:07.610 --> 12:08.610] It's a really intrusive process. [12:08.870 --> 12:10.630] And it wasn't as easy as it was before, right? [12:10.990 --> 12:12.310] Before you just knew what it was. [12:12.750 --> 12:14.610] And so this is what steganography does, right? [12:14.610 --> 12:15.390] Like if you were... [12:15.390 --> 12:19.030] The canonical example being like if you're a prisoner inside of a jail. [12:19.250 --> 12:21.690] And you want to send a message to somebody outside the jail. [12:22.350 --> 12:24.270] You can't just write an encrypted message. [12:24.470 --> 12:25.850] And have like that get out. [12:26.030 --> 12:27.670] Because the warden is just going to take your message. [12:27.770 --> 12:28.510] And say, oh, this is encrypted. [12:28.670 --> 12:29.230] Throw it out. [12:29.610 --> 12:31.330] And you can go on when you'd be able to send a message. [12:31.650 --> 12:35.590] So the only way to do it is to have lots of other messages that seem perfectly benign. [12:35.930 --> 12:38.550] And then have your actual message hidden inside of it. [12:39.450 --> 12:41.650] That's what we're going to be talking about doing with a network. [12:41.790 --> 12:43.090] Rather than, you know, a message. [12:44.770 --> 12:47.890] So what we're going to be talking about is trying to make a needle in a haystack. [12:48.010 --> 12:51.390] Or make your like actual nodes in your... [12:51.390 --> 12:52.270] On your computer network. [12:52.550 --> 12:53.970] Just one of... [12:53.970 --> 12:55.810] Just a needle inside of a much larger haystack. [12:55.950 --> 12:59.070] So we're talking about drowning out your actual nodes on network. [12:59.290 --> 13:01.310] With realistic looking fake ones. [13:03.230 --> 13:04.890] So to do this, we're going to be using HoneyD. [13:05.410 --> 13:08.330] Which is a really awesome tool written by a guy named Niels Provost. [13:08.870 --> 13:11.870] Who, if he happens to like be here, like totally like owe him a drink or something. [13:13.110 --> 13:14.830] We had to make some additions to it. [13:15.190 --> 13:16.070] So I think I have... [13:16.070 --> 13:20.070] Actually, I'll talk about HoneyD more specifically in a few slides later. [13:20.490 --> 13:21.530] So I'll wait to do that. [13:22.110 --> 13:23.190] So we're going to have two goals here. [13:23.390 --> 13:24.470] Two primary goals. [13:25.130 --> 13:27.290] One is to obfuscate the network. [13:27.490 --> 13:30.590] Which, you know, makes reconnaissance more difficult. [13:31.190 --> 13:32.290] Makes it less effective. [13:35.580 --> 13:37.120] But we also want to identify reconnaissance. [13:37.640 --> 13:39.780] We want to say it's not enough just to prevent it. [13:39.920 --> 13:41.260] Or just to, you know, make it harder. [13:41.500 --> 13:42.920] But we actually want to find out when it happens. [13:43.020 --> 13:43.620] We want to get an alert. [13:43.980 --> 13:44.180] Right? [13:44.280 --> 13:45.500] Like when this stuff goes down. [13:46.780 --> 13:51.120] And so this is a key part of like our research that we were figuring out. [13:51.300 --> 13:53.200] Is that once you have these decoys. [13:53.300 --> 13:54.780] This big set of fake machines. [13:54.780 --> 13:58.280] That really helps you figure out when reconnaissance is occurring. [13:59.260 --> 14:00.640] Because these are decoys. [14:00.780 --> 14:01.340] They're honeypots. [14:01.920 --> 14:05.000] And, you know, people kind of by definition shouldn't be talking to the honeypots. [14:05.740 --> 14:06.440] Like they... [14:06.440 --> 14:08.240] Any traffic to them is presumptively hostile. [14:08.420 --> 14:09.720] Like why are you talking to the honeypots? [14:09.880 --> 14:12.640] Why did you send exactly one SIN packet to all of the honeypots? [14:12.920 --> 14:14.280] Like there's this very specific... [14:14.280 --> 14:15.040] Not only just that. [14:15.260 --> 14:16.920] Talking to them is a bad way... [14:16.920 --> 14:17.660] Is a bad thing. [14:17.800 --> 14:21.120] But reconnaissance is a very telltale signature from the network level. [14:21.480 --> 14:23.040] That we'll look at in a bit. [14:24.980 --> 14:27.360] So the tool that we're going to be using to do this. [14:27.480 --> 14:31.220] That I wrote and my small team that I'm working with. [14:31.620 --> 14:33.160] It's an open-source project called Nova. [14:33.800 --> 14:36.220] Our website is projectnova.org. [14:37.180 --> 14:38.440] I have some stats there. [14:38.640 --> 14:39.460] It's written C, C++. [14:40.080 --> 14:41.580] It runs on GNUX systems. [14:41.580 --> 14:44.660] About 44,000 lines of code. [14:45.240 --> 14:48.500] We have a small team that's working with me on a SBIR grant. [14:49.540 --> 14:51.040] So if you have any questions about like... [14:51.040 --> 14:52.060] Like that sort of thing. [14:52.280 --> 14:56.080] I think the SBIR project is a really cool way to start... [14:56.080 --> 14:59.540] Getting some funding for lots of other security related open-source projects. [15:00.520 --> 15:01.900] So do check us out there. [15:02.200 --> 15:03.040] You can download the code. [15:03.040 --> 15:08.520] I think I have some Debian packages that are up that could be considered highly alpha. [15:08.780 --> 15:08.960] I don't know. [15:09.060 --> 15:09.700] I made them myself. [15:09.840 --> 15:11.560] I'm not really like a Debian packaging guy. [15:11.780 --> 15:15.460] So maybe if somebody knows more about packaging than me, then that would be really helpful. [15:16.400 --> 15:19.060] So yeah, please download the source. [15:19.580 --> 15:20.920] Run it on your network and see how things work. [15:21.060 --> 15:22.900] I'd really like to get some feedback from it. [15:23.980 --> 15:24.460] Okay. [15:24.940 --> 15:33.680] So since we're talking about honeypots, I figured I'd talk a little bit about like how honeypots are used and how they're usually used and how we're using them that's different than the typical use case. [15:34.300 --> 15:40.340] So a high fidelity, in air quotes, honeypot is usually used in small numbers. [15:40.440 --> 15:41.780] So they're like real machines. [15:42.040 --> 15:58.760] So like it's not atypical for like a large organization to have their IT guide and say, hey, set up an actual box with real hardware and put it over there in the corner and run it with like Windows XP no service packs, which like gets rooted if a light breeze comes through, [15:58.900 --> 15:59.000] right? [16:00.280 --> 16:06.640] And that way we'll have like an early warning system because presumably bad guys will see that and they'll exploit it first and yada yada, right? [16:06.840 --> 16:08.080] That's the whole point of a honeypot. [16:08.720 --> 16:10.680] Or sometimes you use a virtual machine for this. [16:10.800 --> 16:11.760] Like you want to have real hardware. [16:11.920 --> 16:12.660] You have a virtual machine. [16:12.760 --> 16:21.360] That way if it gets rooted or completely destroyed, then you can like wipe it and hope that like the attacker isn't able to escape from the jail that is the virtual machine. [16:21.900 --> 16:23.120] To certain degrees of success. [16:24.360 --> 16:27.440] But they're essentially the same thing at least in terms of purpose and concept. [16:28.020 --> 16:32.740] They run real software services that really do get exploited because that's their whole purpose. [16:33.500 --> 16:35.640] And they're very useful forensically. [16:35.920 --> 16:41.840] So like if you're trying to figure out after the fact like what happened like in a network intrusion. [16:42.160 --> 16:43.160] That's really useful. [16:43.300 --> 16:49.760] You can say, hey, like I saw the same payload that happened that came through on the box that actually did get exploited. [16:49.840 --> 16:50.740] I saw it on the honeypot too. [16:51.000 --> 16:53.960] So we can maybe try to, you know, go backwards that way. [16:54.460 --> 16:55.720] And they're also really useful. [16:56.200 --> 16:56.880] Yeah, you can... [16:56.880 --> 16:58.100] They're really useful academically. [16:58.720 --> 17:00.280] So there's like the Honeynet project. [17:00.420 --> 17:07.200] And there's lots of cool programs like that that try to find like, hey, like what, you know, viruses are actually going out on the Internet right now. [17:07.340 --> 17:10.320] And so you'd set up a whole network of honeypots that get exploited. [17:10.320 --> 17:14.940] And so you can, you know, give people a heads up before like their network gets hit by it. [17:16.440 --> 17:18.560] So in a way they're kind of used to distract attention. [17:18.760 --> 17:22.180] But it's not really, not really anti-reconnaissance in the way that we're talking about them. [17:22.740 --> 17:27.040] Because by the, by the sheer fact that they're like high fidelity, you can't make many of them. [17:28.160 --> 17:31.760] So low fidelity honeypots is the concern is here. [17:31.860 --> 17:32.860] So they're not real machines. [17:33.060 --> 17:38.980] At least not virtual machines like as you know them in the VMware or virtual box sort of sense, right? [17:39.500 --> 17:41.900] So they can't be exploited like a virtual machine can. [17:42.040 --> 17:46.080] I understand the danger of saying that something can't be exploited in front of a group of hackers. [17:46.420 --> 17:58.560] But there's an order of magnitude of simplicity difference between like a virtual machine, which has like, it's actually emulating a real machine, and just a service that's throwing out packets to pretend like it is. [18:00.060 --> 18:03.060] So you can make these things en masse, which is really the important part. [18:03.200 --> 18:07.300] You can make an order of magnitude more of them than you have real machines. [18:07.300 --> 18:13.800] So a single computer can have hundreds or thousands of these fake machines that look real from the network. [18:14.300 --> 18:19.960] But you know, don't have all the trappings of a regular virtual machine like their own hard disk or their own RAM or something like that. [18:21.400 --> 18:26.360] So one of the problems with Honeyd, though, if anybody's been following it, is it hasn't gotten an update in like five years. [18:27.940 --> 18:32.880] And since then, Nmap has gotten a whole new suite of operating system probes. [18:32.980 --> 18:34.600] And so it just responded wrong. [18:34.600 --> 18:41.660] And so like all of the operating system results and a lot of even just the normal results were just like off, right? [18:42.360 --> 18:44.020] So we had to give that some attention. [18:44.240 --> 18:45.440] So if you go to... [18:45.440 --> 18:45.740] Oh, yeah. [18:46.620 --> 18:47.420] Nmap OSDB. [18:47.540 --> 18:55.940] So if you go to our GitHub page, then we have some new code for Honeyd that responds properly to the new Nmap probe. [18:55.940 --> 18:58.960] So it'll actually like work with the new Nmap probes. [19:02.260 --> 19:03.220] I'm gonna run out of water. [19:03.820 --> 19:04.300] Let's see. [19:06.060 --> 19:07.180] So Honeyd services. [19:07.360 --> 19:12.000] This is an important part about how Honeyd works is that it uses scripts as services. [19:12.780 --> 19:15.300] So these services can be really, really simple. [19:15.580 --> 19:26.880] So like when the... your virtual machine, your fake machine gets data, when it gets like a packet, rather than running an actual like telnet server, it's just a shell script that responds however complex or as simple as you want it to be. [19:27.180 --> 19:32.920] So we have like a service that's a telnet autofail, where like you just... it's like a 20-line script, right? [19:32.980 --> 19:34.960] That takes input and then says, nope, you failed. [19:35.100 --> 19:35.640] Can't log in. [19:35.780 --> 19:36.840] Like, login denied. [19:37.180 --> 19:39.080] And you can just spend like hours on this, right? [19:39.200 --> 19:40.120] Like trying to log in. [19:40.260 --> 19:40.900] Like, ah! [19:42.500 --> 19:43.720] Or you can make them really complex. [19:43.900 --> 19:47.620] There's things like that pretend to be infected machines, like by my doom, right? [19:47.700 --> 19:52.040] Because these are like viruses that open up a port in your service and like listen for command and control signals. [19:52.040 --> 19:55.580] And like they'll pretend to be like command and control signals. [19:55.700 --> 19:57.660] They'll like accept like responses, right? [19:57.860 --> 20:00.740] And then pretend to be like infected by those machines. [20:01.360 --> 20:02.120] So there's really... [20:02.120 --> 20:03.340] Those are more complex, right? [20:03.360 --> 20:04.160] Those are kind of cool things. [20:05.100 --> 20:05.960] Like there's others... [20:05.960 --> 20:06.840] Like we have like... [20:06.840 --> 20:08.400] I think like FTP server? [20:08.540 --> 20:08.680] No. [20:08.900 --> 20:13.380] I think we have an SSH server that like allows log in, where you can actually log in to the service, right? [20:14.220 --> 20:14.740] And it's like... [20:15.160 --> 20:17.220] Every once in a while, it'll like your... [20:17.220 --> 20:20.900] It'll tell you permissions denied, so you can't like go too far, because it doesn't want to be too complex. [20:21.960 --> 20:27.440] So these are relatively safe, because they're just shell scripts running at like a super low privileged level. [20:28.740 --> 20:30.360] And I mean, not... [20:30.360 --> 20:31.100] It wouldn't be the... [20:31.100 --> 20:38.820] I mean, of course shell scripts could be possibly exploitable, but there's an order of magnitude of simplicity between like a hundred line shell script and like an actual running service. [20:39.080 --> 20:40.720] So these are fairly safe to run. [20:42.580 --> 20:49.200] Okay, so take a step back now and look at like kind of where we're at in terms of from the attacker's perspective, right? [20:49.480 --> 20:53.700] So you're an attacker, you gain access to some network that's running this Nova system, right? [20:54.260 --> 21:00.640] And you see some massive network that has like thousands of machines on it in some crazy, complex topology. [21:01.660 --> 21:04.620] Most of these machines are fake, but you don't know that. [21:04.620 --> 21:12.120] And you can spend hours, you know, trying their individual services, like trying to log into them, seeing if they're exploitable. [21:13.300 --> 21:18.320] And so reconnaissance itself becomes ineffective, becomes cumbersome and obvious. [21:18.600 --> 21:21.100] And so I'm going to try to talk a little bit about the obvious part. [21:21.420 --> 21:30.680] So I think we can see how like reconnaissance becomes more difficult, like just the process itself becomes like really annoying and you don't know what machines are fake. [21:30.680 --> 21:34.840] And trying to find out what's actually exploitable becomes really, really hard. [21:35.500 --> 21:36.760] But we don't want just that, right? [21:36.800 --> 21:38.640] We want to have like a heads up on the attacker. [21:38.800 --> 21:44.240] We want to have like some like alert and like the IT administrators like smartphone, right? [21:44.340 --> 21:46.160] So it's like, hey, somebody's doing something bad. [21:47.940 --> 21:48.440] I'm sorry. [21:48.500 --> 21:48.840] Sure, yeah. [21:48.920 --> 21:52.740] Each of these fake machines... [21:52.740 --> 21:53.660] I'm sorry, what was that? [21:53.740 --> 21:56.720] Each of these fake machines needs to have an IP address. [21:57.080 --> 21:57.400] I'm sorry, yeah. [21:57.500 --> 21:59.520] I have to repeat the questions because I don't think he's going to be on the mic. [21:59.520 --> 22:02.900] So the question was, each of the machines have like a real IP address. [22:03.040 --> 22:03.940] And that's great, yes. [22:04.340 --> 22:06.480] So you can set them statically or using DHCP. [22:09.520 --> 22:10.040] Let's see. [22:10.420 --> 22:10.660] Oh, yeah. [22:10.780 --> 22:12.280] So one of the downsides... [22:12.280 --> 22:14.880] I'll try to take questions at the end just because I think it gets kind of chaotic. [22:14.980 --> 22:18.860] Usually I accept questions during the thing, but like we have like probably too many people. [22:20.540 --> 22:21.140] What was I saying? [22:21.240 --> 22:21.420] Oh, yeah. [22:21.580 --> 22:29.320] So since there's like hundreds of these things, like these fake nodes, well, one of the troubles with them is actually setting them up, like configuring them. [22:29.760 --> 22:37.780] And that was one of the very early things we discovered about HoneyD was that like the overhead in terms of manpower of like setting up these fake machines is really, really high. [22:38.080 --> 22:41.480] Since you have to go through config files and like do them manually by hand. [22:42.060 --> 22:43.520] It's also a dangerous process. [22:44.000 --> 22:45.700] Dangerous, I say, in the way of... [22:45.700 --> 22:48.180] Actually, I didn't put a new thing there. [22:48.380 --> 22:51.660] It's dangerous in the sense that it's easy to misconfigure, right? [22:51.660 --> 22:54.840] Because the whole point of these fake machines they have to look real. [22:55.100 --> 22:56.380] They have to look believable to an attacker. [22:57.080 --> 23:04.600] And so if you have like a BSD box, like a fake machine that pretends to be BSD that's running MSRPC, then that's like probably bad, right? [23:04.740 --> 23:05.540] Like it's kind of a giveaway. [23:06.080 --> 23:07.520] There's lots of other subtle things, too. [23:07.740 --> 23:16.420] Like if your network is all just like a Linux server farm and then you have like an entire section of like Windows machines, and those are your fake ones. [23:16.560 --> 23:19.040] The fake machines are all Windows, and all of your real ones are Linux. [23:19.240 --> 23:20.100] And that's probably bad, too. [23:20.100 --> 23:21.920] You've got an obvious separation. [23:22.360 --> 23:25.600] You want something that looks like your network but a little bit different. [23:26.320 --> 23:28.140] So we deal with this as well. [23:29.220 --> 23:36.080] So a lot of what we do is try to provide an easy front end for HoneyDee. [23:36.080 --> 23:39.780] So you can create these virtual honeypots with a nice pretty gooey and stuff like that. [23:40.640 --> 23:44.900] Really we have one of the neat things we just finished actually is this autoconfig utility. [23:45.160 --> 23:47.860] I put an asterisk here because when I say just finished I mean like last week. [23:48.040 --> 23:49.700] So I'm not demoing it because it's like really fresh. [23:50.820 --> 23:53.460] And so what it does is it end maps your network or you put like a button, right? [23:53.540 --> 23:54.260] You give it a subnet. [23:54.780 --> 23:55.740] It end maps your network. [23:55.860 --> 23:59.500] It finds out like what computers are there, what operating systems you're running, ports and stuff like that, right? [23:59.760 --> 24:06.960] And then it generates an entire haystack for these things or saves it to XML and then parses it into an ID config file. [24:07.260 --> 24:10.060] So now you have, then it like randomizes it to a certain extent. [24:10.160 --> 24:10.960] So you have like a slider bar. [24:11.080 --> 24:13.560] You can say I want it like really random or slightly less random. [24:14.060 --> 24:17.080] And then it makes one of these fake networks for you. [24:17.160 --> 24:18.880] That looks like your network but a little bit different. [24:19.320 --> 24:21.760] Or you know, how different depending on how much you want it to. [24:22.340 --> 24:24.880] So that like makes the setting this up super easy. [24:25.320 --> 24:25.740] Which is kind of neat. [24:26.100 --> 24:32.040] And of course, you know, the irony of using Nmap to then prevent Nmap is not lost on me. [24:34.080 --> 24:35.040] Oh, adding salt. [24:35.300 --> 24:37.240] You know, the randomness like I mentioned. [24:38.480 --> 24:38.860] All right. [24:38.980 --> 24:39.440] So classification. [24:39.440 --> 24:42.780] Some of the neat, like crunchy part of the topic here. [24:45.340 --> 24:49.680] So with high fidelity honeypots, classification is done like manually, right? [24:49.860 --> 24:51.180] With like inspecting log files. [24:51.420 --> 24:58.140] So if you're the IT guy at like a network and your boss comes to you and says, hey, catch any bad guys today? [24:58.520 --> 24:59.940] Like how would you answer that question? [25:00.120 --> 25:01.600] If you've got like a high fidelity honeypot? [25:01.680 --> 25:03.300] Well, you've got to go through the log files. [25:03.440 --> 25:05.540] And I don't know, maybe you've got some automated tools. [25:05.760 --> 25:09.980] Maybe you've got something that like tells if the shadow file changed or something like that, right? [25:10.320 --> 25:12.560] But for the most part, it's a really manual process. [25:12.700 --> 25:13.440] It's really annoying. [25:13.600 --> 25:14.420] It takes a lot of time. [25:15.880 --> 25:21.660] Because like signatures like IDS, antivirus sort of things help, but not really in the sense of reconnaissance. [25:22.580 --> 25:24.920] And signatures mostly fail in this case. [25:26.320 --> 25:28.420] So what we're going to be doing is machine learning. [25:28.780 --> 25:31.840] So this is like a, you know, really cool sort of part about this. [25:31.980 --> 25:32.940] I really wanted to get in. [25:33.180 --> 25:38.500] So the algorithm we're using for machine learning is called the k-nearest neighbors algorithm for statistical learning. [25:39.000 --> 25:44.860] This is a totally normal like algorithm that lots of people use for lots of things that have absolutely nothing to do with network security. [25:45.700 --> 25:51.720] So it's actually one of the more simple algorithms for machine learning that you'll find, which is one of the reasons that we went for it. [25:52.460 --> 25:58.100] So the idea is that you have n statistical features that are scalar values. [25:58.380 --> 26:00.960] So we're not talking about like deep pack inspection. [26:01.100 --> 26:03.740] In fact, I think our tool only captures the like the headers. [26:03.900 --> 26:05.560] I think we go 100 bytes into packets. [26:06.040 --> 26:06.900] We only recognize that. [26:07.600 --> 26:18.740] So you're looking at scalar values like packet timing, like number of IPs contacted per suspect, like ports, like number of ports contacted, like what percentage of this haystack to the thing contact, right? [26:19.160 --> 26:23.060] And you plot all of these scalar values per suspect in n dimensional space. [26:23.240 --> 26:26.100] Only two dimensions due to budget cuts are showed on the screen. [26:27.040 --> 26:35.460] And so you imagine like percentage of haystack nodes contacted on the x-axis and some other value on the y-axis, right? [26:35.660 --> 26:37.860] And you have some training data that's set. [26:38.060 --> 26:39.700] And so just like a spam filter, right? [26:39.820 --> 26:40.740] You have to have training data. [26:40.860 --> 26:43.580] You have to tell the system what's good and what's bad. [26:43.680 --> 26:45.940] Like what hostile data looks like, what benign data looks like. [26:46.040 --> 26:47.240] And you plot it on a graph like this. [26:48.640 --> 26:50.080] I got ahead of myself there. [26:51.660 --> 26:54.960] Yeah, so you plot all this data in n dimensional space. [26:56.140 --> 26:57.220] And then you have a query point. [26:57.340 --> 26:59.720] This green guy with a question mark in the center, right? [26:59.820 --> 27:00.840] You say, all right, here's a point. [27:01.140 --> 27:02.280] Is he good or is he bad? [27:02.400 --> 27:03.340] Like I found a new suspect. [27:03.500 --> 27:04.980] I calculated this data for him. [27:05.080 --> 27:06.060] I plotted him on my graph. [27:06.140 --> 27:07.000] Is he good or is he bad? [27:07.060 --> 27:08.000] How do you answer that question? [27:08.360 --> 27:09.620] Well, it's fairly simple here. [27:09.800 --> 27:13.620] You just search for its k nearest neighbors where k is some constant that you choose. [27:13.880 --> 27:15.520] So the inner circle there is three. [27:15.740 --> 27:20.560] And we say, all right, well, there's two red triangles and one blue square. [27:21.100 --> 27:26.600] And so majority vote, he's going to be a red triangle, which maybe means hostile in this system, right? [27:27.620 --> 27:31.820] In reality, we use a distance metric to try to get a... so we don't just use the majority vote. [27:31.920 --> 27:37.420] We don't get a value of zero to one where zero means almost surely benign and one means almost surely hostile. [27:38.480 --> 27:42.020] And to do this, we use a library called liband, which is awesome. [27:42.200 --> 27:43.500] It's in the Ubuntu repos. [27:44.380 --> 27:47.900] It's the approximate nearest neighbors algorithm library. [27:48.160 --> 27:53.520] It's one of those things where they introduce some very small amount of error that's actually configurable. [27:53.720 --> 27:56.460] And it introduces some big performance gains. [27:58.780 --> 28:07.900] And so if your data points are selected well, or rather if your features are selected well, these points in your n-dimensional space should naturally tend to cluster up. [28:08.080 --> 28:15.640] Like if they're spread evenly about, more or less without any order, that means your data is not correlating to anything. [28:16.180 --> 28:25.960] If your data is chosen well, or I keep saying data, if your features are chosen well, then like the hostile guys should all kind of clump up in one area and the benign guys should kind of clump up in one area. [28:26.180 --> 28:27.880] Because that's what the data suggests. [28:29.340 --> 28:30.340] All right, so then response. [28:30.560 --> 28:32.460] What do we do when we actually find a bad guy? [28:33.120 --> 28:37.760] So like I said before, we don't want to do things like ejecting them from the network or blacklisting them. [28:37.840 --> 28:38.820] No, we don't want to do that stuff. [28:39.260 --> 28:41.800] Since A, we don't have the authority to do that, right? [28:41.800 --> 28:47.520] Since we're probably just gonna be some piece of software running somewhere in the network and we don't have the ability to eject them from the network. [28:47.680 --> 28:48.960] But also because we don't want to. [28:49.280 --> 29:02.480] Because if the attacker knows that our system is on here, right, and they suddenly get ejected from the network, then like hey, like that gives them some information about like the stuff that I scanned was enough to know that I'm hostile, so they can use that against us. [29:02.860 --> 29:04.020] So we don't want to do that. [29:04.160 --> 29:05.620] So we're not playing the role of an IDS. [29:06.020 --> 29:08.320] So you want to make an alert, which is one thing that we don't want to do. [29:08.520 --> 29:14.540] So we have a couple ways of doing that with like email or viewing in a log file or inside of our user interface and stuff like that. [29:14.860 --> 29:16.760] But we also want to fool the attacker further. [29:18.340 --> 29:24.860] So we're gonna use something which I call the doppelganger, which is a way of denying access to real nodes. [29:26.240 --> 29:31.220] So when you find somebody that's an attacker, you've determined that he's hostile according to the system. [29:31.720 --> 29:38.960] What you're going to do is you're going to reroute any traffic from him only that was going to go to a real host out to one of these fake nodes. [29:39.560 --> 29:42.660] So you have a new node that you made specifically that's called a doppelganger. [29:42.840 --> 29:43.900] That's one of these fake machines. [29:44.080 --> 29:44.080] Right? [29:45.220 --> 29:46.700] And you're going to... I like that transition too. [29:47.020 --> 29:49.960] And you're going to move him over to like this fake machine. [29:50.060 --> 29:55.560] Now when he tries to access the rest of it, so figure we catch him like a quarter of the way through the scanning. [29:55.860 --> 29:59.240] And now the rest of the three quarters, he's not going to get any real nodes. [29:59.840 --> 30:03.160] Even now when he does try to scan a real node, he's just going It's going to get rerouted to a fake one. [30:03.620 --> 30:05.420] So almost all the data that he's going to be seeing is fake. [30:06.740 --> 30:08.840] I'm going to use some IT tables magic to do this. [30:11.860 --> 30:12.640] What did I say? [30:12.960 --> 30:13.800] Oh yeah, intercepts that. [30:14.000 --> 30:14.540] I think I already said that. [30:14.920 --> 30:18.880] So one of the important things you want to do here is make sure that the information is different than the real host. [30:19.140 --> 30:31.100] So it's a really easy thing to try to say like, oh well why don't we just make the real host and the doppelganger look the same and that way when he tries to exploit like some service that on there, then he'll just be exploiting the fake machine and not the real one. [30:31.560 --> 30:36.120] And that's, it sounds good but like you have to resist that by saying we're not an IDS, right? [30:36.200 --> 30:37.200] We don't want to try to do that. [30:37.760 --> 30:42.880] Because then when he, like he can find out that's a fake machine, then he, that's bad from our perspective. [30:43.260 --> 30:45.780] What we want to do is provide different information. [30:47.440 --> 30:54.320] This is, this, this feature is also possibly dangerous since any false positives then turn into a denial of service. [30:54.580 --> 31:04.680] So like if your file server gets determined as hostile, then it's not just a matter of like your, your administrator getting like an alert, an annoying alert, the file server then just gets denial of service, right? [31:04.780 --> 31:07.840] Like he, all of his traffic gets rerouted to these fake nodes and that would be bad. [31:08.180 --> 31:10.360] So by default, this feature is disabled. [31:11.120 --> 31:17.340] And you also want to like, do things like probably increase the threshold of classification on him as well. [31:17.540 --> 31:19.000] But it's a really neat feature nonetheless. [31:20.280 --> 31:22.600] So we have some other features that I'm just going to go through quickly of course. [31:23.280 --> 31:32.700] So like training, like there's a way of in-band like training the system, like press the train button, um, get through a bunch of data and you can say, all right, all that trait, all that data you just saw was benign. [31:33.040 --> 31:34.400] And then it goes into the system, right? [31:34.480 --> 31:38.760] Or you can say, oh, actually I was end mapping in the middle of there and this IP address was bad. [31:38.880 --> 31:39.760] He was an end map scan. [31:40.020 --> 31:41.320] Like, you know, you put that into your data. [31:41.480 --> 31:43.100] And you can train the system that way. [31:43.300 --> 31:51.360] Um, so we have a bunch of UIs and we have a web interface, um, a local QT interface and a terminal that's, uh, interface that's really good for scripting. [31:51.880 --> 31:54.200] Um, um, you can import and export training data. [31:54.300 --> 31:56.660] So if somebody else gets data, you can like import it, export it. [31:57.060 --> 32:01.420] Um, it's really highly multi-threaded and free software, of course, because free software is the way to go. [32:02.720 --> 32:04.720] Um, now I have a demo. [32:11.430 --> 32:12.310] Everybody likes that dog. [32:13.050 --> 32:15.190] Um, I'm not gonna be able to talk while I'm sitting here. [32:16.030 --> 32:16.690] Can I take this? [32:19.310 --> 32:20.650] Oh, this is gonna fail miserably. [32:20.930 --> 32:20.990] Okay. [32:27.130 --> 32:27.590] All right. [32:27.770 --> 32:31.350] So I've got, um, a few virtual machines running. [32:31.770 --> 32:33.970] So I've got, uh, you know, I get, you guys can see all that. [32:34.150 --> 32:37.230] So I've got, um, uh, three virtual machines running. [32:37.370 --> 32:38.350] There's two that are victims. [32:38.650 --> 32:44.270] You can see their names are victim one and hapless victim two, and then an end map guy here. [32:44.370 --> 32:45.590] So this takes like a minute to run. [32:45.750 --> 32:46.570] So I'm gonna go ahead and start it. [32:46.570 --> 32:51.390] So this, uh, has some pretty default, um, uh, uh, some pretty default options on it. [32:52.370 --> 32:55.430] Uh, he's running an operating system scan run with O. [32:55.850 --> 33:03.510] He's running the fuzzy, uh, option to say, like, try to guess the operating system if you don't get it exactly since end map rarely gets a hundred percent result. [33:03.730 --> 33:11.130] Uh, this just says just, uh, save it to, uh, an XML file so we can look at it in another UI and randomizing hosts is pretty normal too. [33:11.810 --> 33:13.990] Um, so he's doing some of the things that we, we talked about before. [33:14.070 --> 33:15.350] This should take about like 70 seconds. [33:15.570 --> 33:23.930] Um, so he's first, he's sending out a bunch of art packets to try to find and figure out what, um, machines are out on this virtual network that I have set up, um, on my laptop right now. [33:24.190 --> 33:30.990] And then he's gonna do a default, uh, TCP port scan of some of the commonly used ports that are on machines. [33:31.570 --> 33:36.250] Um, and then he's, uh, going to, uh, look at operating systems to see what operating systems are running. [33:36.970 --> 33:38.930] Um, so this, I'm gonna do a before and after. [33:39.130 --> 33:40.290] So like this is the before. [33:40.530 --> 33:42.730] So this is gonna show you like what the network actually looks like. [33:42.890 --> 33:46.730] Um, then I'm gonna like apply the tool that we have and then see what it looks like right after that. [33:46.990 --> 33:47.310] Uh, [33:50.890 --> 33:51.750] hopefully he will finish. [33:51.870 --> 33:54.250] It usually takes like 72 or four seconds. [33:55.170 --> 33:56.350] Not that I've tried this before. [33:57.950 --> 33:58.690] There we go. [33:59.910 --> 34:04.230] Let's look at this in Zenmap because Zenmap is a nice little front end for presentations like this. [34:05.010 --> 34:08.430] So he's got a few, uh, machines that he saw on this network. [34:08.710 --> 34:13.210] Um, 182.168.56.1 is my laptop, the host machine. [34:13.410 --> 34:15.650] It's got like a NetBIOS server on it, whatever running. [34:16.270 --> 34:19.970] Um, presence, this is a chat server because these guys you can see here are running empathy. [34:21.690 --> 34:24.130] Um, and then, uh, 101 is himself. [34:24.350 --> 34:25.430] So he doesn't see anything there. [34:25.590 --> 34:27.550] Uh, since it's a backtrack, doesn't have any open ports. [34:27.670 --> 34:32.170] And then 100 is the like default DHCP server that this like virtual box thing sets up. [34:32.470 --> 34:35.350] So he sees all the real machines, um, and it was pretty easy. [34:35.510 --> 34:36.090] It was pretty straightforward. [34:36.590 --> 34:38.510] Um, and he got all the real data. [34:38.650 --> 34:42.510] And now you can start looking deeper into these services and see what you can exploit, right? [34:43.230 --> 34:45.330] So let's run. [34:49.170 --> 34:49.730] Nuva. [34:50.670 --> 34:54.350] I have this awesome like eyeball, um, logo thing. [34:54.910 --> 34:58.530] But since when does, did logos and software projects ever have to make sense? [35:00.830 --> 35:03.570] It's going to turn on system. [35:04.810 --> 35:07.190] Oh, I have some old data there cleared out. [35:11.400 --> 35:14.420] And then I will run the scan second time. [35:15.260 --> 35:22.020] This will take a little bit longer, um, since he has a whole bunch of these fake nodes to scan as well, which is kind of by design too, right? [35:22.140 --> 35:31.260] I mean, um, taking a little bit longer, um, in this, uh, in the scan, like making the attacker take longer, sending more packets, um, is definitely an advantage, um, for us. [35:31.760 --> 35:39.080] So we should see, actually, if we hop over to the defender, we should see this guy pick up on the, uh, bad guy at some point. [35:39.240 --> 35:41.300] And he'll, uh, probably show up as green first. [35:41.520 --> 35:43.720] Um, green means that he's detected as benign. [35:43.860 --> 35:53.920] Um, since the system has to get a few packets, uh, a bit more information before it'll finally come to the conclusion that he's bad since he, you know, tries to be nice to people before, um, figuring out that they're bad. [35:54.100 --> 35:56.700] Um, so he popped up there as green. [35:56.940 --> 35:58.580] Plus, Nmap tends to, like, burst packets. [35:58.740 --> 36:00.080] It's really bursty for some reason. [36:00.180 --> 36:03.480] It doesn't, like, send packets, like, really evenly throughout for some reason. [36:04.860 --> 36:07.300] I wish there was an easy option to, like, make it less bursty. [36:07.440 --> 36:14.440] So it makes it, it makes it a little bit more entertaining to watch and demo, because we're just, like, watching a blinking cursor right now while I desperately try to talk over it. [36:19.740 --> 36:24.160] Um, to, uh, I, could you repeat that? [36:31.770 --> 36:33.310] Can I, uh, I, I missed that. [36:33.430 --> 36:34.670] Can I, can I, can I, what to it? [36:37.310 --> 36:37.650] No. [36:37.650 --> 36:39.590] I don't think I'm, I quite understand the question. [36:48.350 --> 36:48.990] Still running. [36:50.670 --> 36:51.730] This guy's still running. [36:53.030 --> 36:55.650] I should have come up with something more interesting to talk about while this is going on. [36:56.290 --> 36:56.690] Well, there he is. [36:56.830 --> 36:57.650] He finally came up as red. [36:58.350 --> 37:00.670] I guess Nmap was coming to the end of his scanning. [37:01.290 --> 37:08.110] So he, uh, like I said, we have a system that comes up with a number between zero and one, where zero is almost surely benign, and one is almost really hostile. [37:08.270 --> 37:10.610] So he has a, a 0.911 something. [37:11.110 --> 37:14.350] Um, so that's pretty hostile. [37:14.510 --> 37:16.710] And this guy's still finishing up scanning now. [37:20.540 --> 37:23.520] And in a minute, he'll finish, hopefully. [37:23.800 --> 37:24.840] So I can show you the results. [37:29.340 --> 37:29.620] Um, [37:32.860 --> 37:34.240] and these guys can still talk, by the way. [37:37.320 --> 37:38.760] They can, like, get up here and, like, hey. [37:43.260 --> 37:44.380] And he'll pop up and say, [37:52.370 --> 37:53.390] you can read that. [38:08.520 --> 38:09.680] Just talking to myself. [38:11.160 --> 38:12.120] All right, Nmap's taking a while. [38:12.340 --> 38:16.440] I wonder if I can, if I cancel this, does it, can I still look at the output XML? [38:16.840 --> 38:17.900] I'm afraid to do that. [38:21.400 --> 38:22.260] Sure, I'll let it go. [38:26.980 --> 38:28.100] It's definitely taking a lot longer. [38:29.440 --> 38:30.260] This is zero hops. [38:30.360 --> 38:31.400] It's not doing a trace route, so. [38:32.020 --> 38:32.380] Trace route. [38:32.560 --> 38:34.060] Trace route, by the way, takes a long time. [38:34.200 --> 38:39.060] Any time you try to run, uh, trace route scan, like, doubles or more your, uh, your scanning time for some reason. [38:39.300 --> 38:45.040] Well, I, not for some reason, because it has to go through all the different hops of doing, of the presentation, or the, uh, of the connection. [38:48.290 --> 38:51.310] Well, I, I think I'll look through some of the, um, configuration options then here. [38:51.310 --> 38:55.030] Uh, so I can go into preferences for our system. [38:55.270 --> 39:00.530] And so you can, uh, uh, define a set of profiles, um, here. [39:00.690 --> 39:02.470] Hopefully you guys can see what's on the screen. [39:02.850 --> 39:05.190] Um, so you can define, like, an operating system or whatever, right? [39:05.290 --> 39:06.810] So we have, like, a Linux server. [39:06.990 --> 39:09.030] And you can give it what Ethernet vendor you want. [39:09.210 --> 39:10.610] So you can set the Ethernet vendor. [39:10.790 --> 39:11.570] So I can say clear. [39:12.430 --> 39:16.350] And here's the, like, a huge database that we found of, like, Ethernet vendors. [39:16.710 --> 39:19.630] So you can say, I want a secure base machine, right? [39:19.630 --> 39:20.930] You can say select. [39:21.450 --> 39:28.750] And then that'll have the first, um, three, uh, I think bytes it is, of the, the first half of the MAC address is the vendor area. [39:28.930 --> 39:32.450] And then the, the, the second half of it is just random for the individual device. [39:32.630 --> 39:36.590] And so it'll take the first half and say, sure, this is a secure base vendor, right? [39:37.070 --> 39:38.670] And then it'll just give you a random MAC address. [39:38.790 --> 39:39.890] Or you can specify it from there. [39:40.090 --> 39:41.370] You can set drop rates. [39:41.550 --> 39:46.610] You can say, like, I want this to pretend to be a Wi-Fi link that drops 16% of all the packets that go by it. [39:47.190 --> 39:52.610] Um, um, um, you can look at, uh, operating system. [39:53.910 --> 39:55.290] Oh, so ports and stuff like that. [39:55.450 --> 39:57.530] So you can set, um, like, what ports are open. [39:57.690 --> 40:02.530] So you can say, just this, I want, like, a particular port to be open or closed or have an actual service running on it. [40:02.530 --> 40:03.250] Um, [40:06.330 --> 40:07.910] uh, here's the operating system. [40:08.190 --> 40:10.930] So similar before, this is the end map OSDB. [40:11.250 --> 40:13.750] Um, so you can pretend to be any operating system that's on here. [40:14.010 --> 40:18.910] So this is like a lot of operating systems, pretty much like every device that's ever been made ever. [40:19.150 --> 40:24.770] So this IBM, like AIX, like every version of the server that's ever been made by them. [40:25.230 --> 40:26.390] Or, uh, Kodak. [40:26.450 --> 40:27.170] Kodak makes stuff. [40:27.270 --> 40:28.250] Oh, printers, of course, right? [40:28.650 --> 40:29.230] Network printers. [40:30.310 --> 40:30.570] Um, [40:36.780 --> 40:38.880] yeah, I think the end map is like frozen or something. [40:41.300 --> 40:43.420] Oh, it says 20, does this say 22 minutes remaining? [40:43.560 --> 40:44.000] What is it doing? [40:44.940 --> 40:47.140] All right, I'm going to... I know. [40:47.280 --> 40:48.560] All right, so I'm going to, I'm going to cancel that. [40:48.620 --> 40:49.760] I'm not going to let it run for 22 minutes. [40:49.880 --> 40:53.300] Let's see if it... No, it didn't, it didn't save a file. [40:55.280 --> 41:00.860] All right, so I'm going to go in, I'm going to try this again, and I'm just going to continue, and I'm going to come back to it, and so I can show you the results of that. [41:01.260 --> 41:04.240] Uh, of all the things that could have failed, I didn't think that end map was going to be the one that would fail. [41:07.530 --> 41:07.810] Okay. [41:08.890 --> 41:09.850] Well, there's not... Let's see. [41:16.820 --> 41:22.760] Um, I think I only have... Yep, I have questions and contact information, so I got, um, uh, my email address. [41:23.060 --> 41:28.300] Um, if you're into, like, social networks, I have a Twitter-identic account, or Diaspora, if you're into that sort of thing. [41:28.880 --> 41:39.360] Um, our, uh, our software project, uh, website, again, is at, uh, projectnova.org, um, and our actual source code is up on GitHub, um, GitHub slash Datasoft, um, the company I work for, that I do this with. [41:39.940 --> 41:43.280] Um, and, uh, IRC, like, um, come and hit us up at any time. [41:43.560 --> 41:49.460] Um, IRC on OFTC, Channel Nova, and, uh, if you ever want to see me in person, I'm in Phoenix, uh, 2600. [41:49.600 --> 41:50.480] We meet, uh, first Fridays. [41:50.840 --> 41:59.080] Um, our meeting spots are kind of in flux a lot lately, so, um, just go to the website, um, phx2600.org, to, um, figure out, uh, where we're at. [42:00.060 --> 42:01.680] And, uh, okay, I can do questions. [42:03.540 --> 42:04.880] If you can, like, raise your hand or shout out. [42:04.980 --> 42:05.480] I saw a hand. [42:05.760 --> 42:06.040] Um, [42:13.810 --> 42:17.710] okay, the question was, like, do we integrate with DHCP so we can, like, whitelist off hosts? [42:18.050 --> 42:22.530] Um, we do have a whitelisting feature, um, that's based off of, um, static addresses currently. [42:22.650 --> 42:27.090] So, the current incarnation of the tool, um, you can give it a whitelist on an address, and you say, this address is good. [42:27.410 --> 42:29.670] Like, don't, you know, do anything bad to the file server. [42:29.670 --> 42:31.910] Um, but it's not tied to DHCP. [42:32.190 --> 42:35.470] Um, so, we could actually also give it a MAC address, um, equivalently. [42:35.590 --> 42:36.670] I think that would be a good feature, actually. [42:37.390 --> 42:40.130] Um, so, currently, the whitelisting, um, ability is based off of IP. [42:41.390 --> 42:42.090] I saw a hand here. [42:42.230 --> 42:43.670] It's probably a pretty rudimentary for [42:47.810 --> 42:48.430] a similar thing. [42:48.630 --> 42:48.870] Mm-hmm. [42:50.010 --> 42:52.610] Is that effective without using something like Nova? [42:53.190 --> 42:56.010] Yeah, so, the question was about, uh, Tor. [42:56.210 --> 43:03.390] Like, Tor, like, you know, I think everybody knows that Tor is, like, how does, um, our system, uh, react, or, I don't know, react to, or integrate with Tor, perhaps? [43:16.140 --> 43:20.160] Yeah, so, I guess, just broadly, like, how does our system and Tor, like, relate, or interact? [43:20.460 --> 43:22.900] Um, I think they're just fairly different, fundamentally. [43:23.080 --> 43:24.920] Like, Tor isn't necessarily about reconnaissance. [43:25.060 --> 43:30.340] Tor is, um, just about, um, trying to hide, like, the original location of your data. [43:30.840 --> 43:32.600] Um, so, it's more like a privacy tool. [43:32.980 --> 43:37.580] Um, whereas, like, I don't, I don't think that, uh, necessarily relates much to, um, anti-reconnaissance. [43:39.220 --> 43:39.660] Um... [43:39.660 --> 43:41.860] How large a network have you run this time? [43:42.140 --> 43:48.560] Um, so, I know that, um, HoneyD, um, has been run with as many as a thousand twenty-four nodes on a single computer. [43:49.180 --> 43:52.740] Um, and, of course, that's going to depend on how fast your computer is. [43:53.340 --> 43:55.300] Um, the software itself can handle at least a few thousand. [43:55.520 --> 43:57.680] How many have I personally done, um, a few hundred? [43:57.680 --> 44:02.300] How many have you created on a network of 5,000 computers? [44:02.580 --> 44:04.360] How many have you added to it? [44:04.820 --> 44:06.300] Um, let's see. [44:06.500 --> 44:11.640] So, well, we're running it on, um, uh, at Datasoft, we're running it on our own, um, internal, like, corporate intranet. [44:11.760 --> 44:13.720] And we have probably about a hundred. [44:14.060 --> 44:16.720] And so, we, you know, have probably about a hundred fake nodes as well. [44:17.360 --> 44:21.060] Um, and, uh, you know, and that works reasonably well. [44:21.280 --> 44:24.640] Though, the, there's, there's fun ways of us, um, uh, working our system. [44:24.760 --> 44:27.520] Like, we, we accidentally were running a test network. [44:28.160 --> 44:31.820] And we would, like, get a new, like, we'd randomly find a new, um, MAC address. [44:31.980 --> 44:33.040] And then we'd DHCP for it. [44:33.340 --> 44:35.460] And then we would, like, start and stop this a whole bunch of times. [44:35.540 --> 44:37.280] And we'd quickly ran out of DHCP allocations. [44:37.540 --> 44:38.560] Um, so that was annoying. [44:38.800 --> 44:40.940] So, there's a few things like that, you know, we, we have to watch out for. [44:41.880 --> 44:42.560] Yes, up there. [44:42.760 --> 44:45.400] Uh, how much of a limiting factor is... [44:49.040 --> 44:50.060] That's a good question. [44:50.240 --> 44:55.040] Um, so, the, the question is, like, how much of a bottleneck is the approximate nearest neighbors, like, classification algorithm? [44:55.640 --> 44:59.180] Um, and that's a big bottleneck in terms of computational, um, uh, ability, right? [44:59.180 --> 45:02.260] Since, uh, that's, like, a pretty heavy duty thing. [45:02.400 --> 45:08.560] Once you start talking about, like, like, 12 dimensional space and thousands of data points, this becomes a really crazy thing. [45:09.000 --> 45:12.300] Um, and it can be parallelized to a certain extent. [45:12.460 --> 45:13.180] So, that's really helpful. [45:13.480 --> 45:19.580] Um, but in, uh, in our current tests, um, we wind up with, um, a large bottleneck of just, like, capturing data. [45:19.840 --> 45:27.400] It turns out that, like, having to run CPU cycles on every packet, um, when you're receiving, like, gigabit Ethernet or more, right? [45:27.760 --> 45:29.420] Didn't be, like, a really limiting factor. [45:29.600 --> 45:34.600] So, at least in the software, testing we've done with our software, in practice, it's been the packet capturing. [45:34.780 --> 45:35.460] That's the bottleneck. [45:35.580 --> 45:36.920] Um, as opposed to the classification. [45:37.280 --> 45:40.380] Though, in anticipation of that, what we do is we have a classification timeout. [45:40.460 --> 45:44.140] So, we say, let's only do it, like, once every five seconds, like, classification. [45:44.360 --> 45:45.900] Or, maybe, let's only do it, like, every second. [45:46.020 --> 45:46.840] And that's configurable. [45:48.000 --> 45:48.780] So, the question here. [45:49.640 --> 45:49.960] The [45:58.270 --> 46:11.690] question was, like, um, if, like, an attacker was able to get, um, like, your ARP data and see, like, all the ARP data was coming from one machine, like, would they, like, wouldn't that kind of give you away? [46:11.970 --> 46:22.110] Um, so, the, uh, the machines, uh, uh, that are, uh, the, when you, when you request, like, an ARP, uh, uh, uh, when you were requesting, like, a new, uh, IP address, right? [46:22.250 --> 46:25.170] Like, for, like, via DHCP. [46:25.870 --> 46:28.990] Um, uh, all the fake machines have their own MAC addresses. [46:29.290 --> 46:33.210] And so, if you're just looking at data, um, there, they'll appear to be different machines. [46:33.370 --> 46:35.710] Like, they won't all be appearing to be coming from one source. [46:36.090 --> 46:39.950] Unless you have, like, several wiretaps across the network, right? [46:40.030 --> 46:45.470] And are able to see every link and actually see, like, all these machines actually are funneling all down to this one guy. [46:46.090 --> 46:52.470] Um, at which point, then, maybe the solution is to not run, you know, NOVA once in one place, but to run it in several different locations. [46:54.050 --> 46:55.090] Let's take a question over here. [47:11.560 --> 47:11.900] Um, [47:16.090 --> 47:20.470] can we, uh, so the question was, like, uh, can we detect a fake machine, like, traffic analysis? [47:20.810 --> 47:27.530] Um, you know, you're saying, like, um, if an, can an attacker tell the difference between a real and a fake machine based off of traffic analysis? [47:27.790 --> 47:35.290] So, one of the things that we don't have right now that we, um, as a feature in the future is, um, to make, uh, like, data, like, shaft, right? [47:35.670 --> 47:40.290] Like, to have these fake nodes sending data out amongst one another, or also maybe to fake machines. [47:52.700 --> 47:54.020] Oh, I see what you mean. [47:54.140 --> 47:57.740] Like, so, like, the frequency analysis like that, they're sending data back to the attacker. [47:57.880 --> 47:59.900] Like, maybe there's a latency involved with it. [48:00.020 --> 48:04.320] Like, maybe, like, the fake machines, like, have, I don't know, some other signature like that. [48:04.320 --> 48:06.280] Um, uh, we've tried to look for that, right? [48:06.420 --> 48:09.880] I mean, but, like, by kind of definition, like, there's only so much that I can do. [48:10.080 --> 48:19.400] Um, so, that's the sort of thing that we're hoping to get from the community, is, like, maybe there is some super easy thing, like, a half a second of latency is always added on from all of our fake nodes, and that's, that's a vulnerability, right? [48:19.560 --> 48:20.780] That would be bad if that were true. [48:21.220 --> 48:24.640] Um, so that's, um, I can't give you any hard data to say, like, no, that isn't true. [48:25.040 --> 48:28.100] Um, but, uh, yeah, hopefully we can get that some from the crowd. [48:28.360 --> 48:30.880] Actually, let me see if, I'm gonna see really quick if this end map thing finished. [48:32.900 --> 48:33.880] And then I think I have to end. [48:35.180 --> 48:35.620] It did. [48:38.660 --> 48:39.220] It didn't. [48:41.720 --> 48:42.880] No, that's the old end map result. [48:43.020 --> 48:46.480] All right, so, um, now I can scroll up. [48:50.640 --> 48:52.200] No, oh, I think I closed it. [48:52.680 --> 48:53.580] I turned it off. [48:54.060 --> 48:54.160] Yeah. [48:55.400 --> 48:58.000] All right, well, I guess I'll have to show you some other time. [49:03.520 --> 49:05.520] All right, and, uh, I think that's all I have time for. [49:06.140 --> 49:06.620] So, thanks a lot.