VTmig.OpenSource Software
VTmig OpenSource Software
 
Home
 
Downloads
  Daisy v2.2
  Self-Service v2.3
  OU Admin v1.0
  AuthAD v1.4
  Portinator v1.0
  Faith v1.01
  Ivy v1.0.2.2
  SafetyNet v1.0
  DictionaryFilter v2.1
  NeWa POC v1.1
  Win32_Perms v0.2
  VT WSUS v1.0
 
Links
  www.w2k.vt.edu
  vtmig.w2k.vt.edu
  opensource.isc.vt.edu

NeWa POC - Neighborhood Watch Proof Of Concept

Description:
A client application that runs as a local service. It collates and analyzes local firewall logs (currently supporting Windows Firewall, ZoneLabs ZoneAlarm and Integrity Client, and ISS Black Ice Protection). It attempts to apply advanced security logic to the logs, correlates the allowed and disallowed network packets flowing to the machine. It then scores these inbound flows with a numeric number from 0 to AVLN (a very large number). Based on these scores, it is theoretically possible to determine whether the client is being passively scanned or actively attacked. Output is in the form of a useful html page which automatically refreshes, has basic statistical diagrams, and allows users to do a detailed lookup of potential evil doer's machines. This application is a proof of concept for a greater overall project. The larger project would take these client based metrics, combine them centrally and provide administrators with an overarching viewpoint of the network. The full package would allow proactive BL (blacklisting) of attackers, WL (whitelisting) of good machines and give administrator fine grain control over their installed client base and IPSEC rules.

  • Development Status: Proof of Concept
  • Environment: Win32 Service
  • Intended Audience: System Administrators, Developers, Security Auditors
  • License: N/A for Proof of Concept
  • Operating System: MS Windows 2000/XP/2003
  • Programming Language: Python
  • Topic: Security
Author Name:
Zeb Bowden
Marc DeBonis
Steve Warrick
Cathy Winfrey
Secondary Authors Names:
Brad Tilley
Homepage Link:
None
Demo Link:
http://newa-poc.w2k.vt.edu/
Download links:
Currently Unavailable
Send Questions to:
Marc DeBonis
Screen Shots:
None
Responsible Department:
Microsoft Implementation Group (MIG)
Documentation:
Included in install
Latest Product Version:
1.1 (Proof of Concept - will deadline July 1, 2005)