Live data from Hacker News

Viewing profile — ddiinn2

ddiinn2

HN member
Joined
Mon, Mar 23, 2015, 1:05 PM UTC
HN karma
4
Public activity
9 items

About ddiinn2

Interested in everything. Knows a lot about cyber security. Co-Founder/CTO of Cymmetria.

Recent public activity

  1. comment
    Comment #12063641

    There are two main advancements beyond "classic" honeypots: 1. Honeypots are easy to fingerprint (see our blackhat talk, https://www.youtube.com/watch?v=Pjvr25lMKSY ) 2. Most honey…

  2. comment
    Comment #12063101

    Any questions, we'd be happy to answer

  3. comment
    Comment #9795973

    The trick is to make the breadcrumbs the type of data that an attacker is interested in, but a regular user will never be aware of. For example in windows there is a cache of used …

  4. comment
    Comment #9795959

    Like was said before, you have to attack the decoy to recognize it and that enables catching the attack traffic. Also the mere fact that they recount every single action 10 times o…

  5. comment
    Comment #9795947

    When you get one alert that you realize isn't false and has the forensic data tied to it, you can use it as a harness against the loads of information from all the other sensors (f…

  6. comment
    Comment #9791944

    - What is alerted on (or "attack") is configurable and can range from code being executed (which is the true positive alert) to connecting to ports(which has more noise) - It needs…

  7. comment
    Comment #9791639

    Each decoy is configured to look exactly the way that makes sense for the network it's in. An example is a git server with interesting code or an employees pc that shares files tha…

  8. comment
    Comment #9791582

    Hi, dean here (Cymmetria CTO). Two great questions: 1. The concept being that from looking at the machine on the network we don't do anything different then regular machines, so th…

  9. story