George,
You could also try googling 'honeyclient' or 'client-side honeypot'
for even more references and starting points.
Kathy
Mon, Sep 18, 2006 at 02:42:25PM +1200, Jamie Riden <jamesr (AT) europe (DOT) comstated:
17/09/06, George <george.p123 (AT) gmail (DOT) comwrote:
>>Hello!
>>I wold like to setup a honeypot for collecting spyware and adware. As
>>you know, spayware require user action, so i can't use the classic
>>honeypot method to connect it on the internet and let the "bad guys"
>>attack it.
>>
>>I google a little bit on this project and i didn't find a point of
>>starting this project. Can you help me with some ideas or some links
>>about how can i deploy this kind of honeypot in a such way that it
>>should receive fresh spayware and adware?
>
>I've been wondering about this myself - I think the main steps would be:
>
>* mechanism to trawl URLs - e.g. crawl everything that you get in your spam
>* detection of compromise, and analysis
>
>You could do this in a VM and use snort to alert when the thing gets
>compromised and do a manual analysis. There are also low interaction
>solutions - here are a couple of references:
>
>
>http://honeyc.sourceforge.net/
>
>
>
>
>cheers,
>Jamie
>Jamie Riden, CISSP / jamesr (AT) europe (DOT) com / jamie.riden (AT) gmail (DOT) com
>NZ Honeynet project - http://www.nz-honeynet.org/