Southern California Honeynet Project
A Chapter of the Honeynet Project


Research
Digital Virology

The current focus of our research is analyzing malware attack vectors, obfuscation mechanisms, and functionality in conjunction with associated behavioral artifacts and evidence associated with the attacker(s). In particular, the goal of the research is to identify infection and packing trends, as well as phylogenetic relationships among malware specimens to gain deeper insight for conducting malware forensics and attributive analysis.  Honeyclients and Nepenthes honeypots will be deployed to collect malware specimens and to identify vectors of attack.

Vector Oriented Repository for Terrorist Exploitation ("VORTEX")

This research examines terrorists' use of malicious code and exploits to conduct asymmetric cyber attacks against critical network infrastructure.  Information gathered and analyzed seeks to gain deeper insight into:

º Skill level of attackers
º Attack Capabilities
º Attacker Characterization
º Motivations and Objectives
º Threat Assessment