<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The NoAH Blog &#187; announcements</title>
	<atom:link href="http://blogs.fp6-noah.org/noah/category/announcements/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.fp6-noah.org/noah</link>
	<description>an ark of honeypot knowledge...</description>
	<lastBuildDate>Tue, 07 Jul 2009 14:35:20 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Argos 0.4.1 released</title>
		<link>http://blogs.fp6-noah.org/noah/argos-041-released/</link>
		<comments>http://blogs.fp6-noah.org/noah/argos-041-released/#comments</comments>
		<pubDate>Wed, 21 May 2008 23:39:34 +0000</pubDate>
		<dc:creator>Vrije Universiteit, Amsterdam</dc:creator>
				<category><![CDATA[announcements]]></category>
		<category><![CDATA[argos]]></category>
		<category><![CDATA[emulator]]></category>
		<category><![CDATA[taint tracking]]></category>

		<guid isPermaLink="false">http://blogs.fp6-noah.org/noah/argos-041-released/</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[<p align="justify">The new version of Argos (0.4.1) contains bug fixes related with taint tracking. It is recommended to update to the latest version of Argos, since it solves issues with reported false positives. Checking the CALL instruction for tainted operands, has also been re-enabled, since it seems it does not cause problems with windows systems anymore. The use of a whitelist is not necessary as well, since the false positives reported by 2.6.* linux kernels are also solved. Finally, crashes reported with windows 2000 guest systems, seem to be also solved.</p>
<p align="justify">If any of the users discovers false positives, after these changes please notify the developers immediately. You can get argos from the VU <a href="https://gforge.cs.vu.nl/frs/?group_id=14">gforge site</a>.</p>
<p align="justify">&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.fp6-noah.org/noah/argos-041-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Update for windows Honey@home software</title>
		<link>http://blogs.fp6-noah.org/noah/update-for-windows-honeyhome-software/</link>
		<comments>http://blogs.fp6-noah.org/noah/update-for-windows-honeyhome-software/#comments</comments>
		<pubDate>Fri, 16 May 2008 11:19:12 +0000</pubDate>
		<dc:creator>FORTH</dc:creator>
				<category><![CDATA[announcements]]></category>
		<category><![CDATA[noah]]></category>
		<category><![CDATA[honey@home]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://blogs.fp6-noah.org/noah/update-for-windows-honeyhome-software/</guid>
		<description><![CDATA[An updated version of windows Honey@home has been released. The new version has been developed using the Microsoft .NET 2.0 framework. New features in this version include an installation wizard, a registration wizard,  settings manager and automatic updating.
The application is available from the Honey@home website. Continue reading for more details on the new features.
List [...]]]></description>
			<content:encoded><![CDATA[<p align="justify"><img src="http://blogs.fp6-noah.org/noah/files/2008/05/honeyhome_256_256.png" alt="Honey@home logo" align="right" vspace="10" width="100" height="100" hspace="10" />An updated version of windows Honey@home has been released. The new version has been developed using the <a href="http://www.microsoft.com/net/">Microsoft .NET 2.0 framework</a>. New features in this version include an installation wizard, a registration wizard,  settings manager and automatic updating.</p>
<p align="justify">The application is available from the <a href="http://www.honeyathome.org/">Honey@home website</a>. Continue reading for more details on the new features.</p>
<h2><span id="more-18"></span>List of improvements</h2>
<p>The new version offers numerous improvements over the previous releases:</p>
<ol>
<li>
<p align="justify"><strong>Installation</strong>: The Honey@home installer now uses the <a href="http://en.wikipedia.org/wiki/Windows_Installer">Microsoft Windows Installer</a> engine. This enables the installer to update existing Honey@home installations, without the user having to uninstall and then reinstall the software.</p>
</li>
<li>
<p align="justify"><strong>Integrated update mechanism</strong>: The software is now capable of identifying when a new version comes out on the Honey@home website. The new version is downloaded as an MSI archive and the software is automatically updated.</p>
</li>
<li>
<p align="justify"><strong>Registration wizard</strong>: The user no longer has to launch a browser to register his Honey@home client. If after the installation it is identified that the software hasn&#8217;t been registered, a registration wizard is started and the user is able to register his client without switching to a different application.</p>
</li>
<li>
<p align="justify"><strong>Settings Manager</strong>: No longer has the user to manually edit the configuration files of the software. Now all required changes to the configuration are made through the Honey@home settings manager GUI.</p>
</li>
<li>
<p align="justify"><strong>Anonymous Routing</strong>: The software now includes the components required to route the traffic it captures over <a href="http://www.torproject.org/">TOR</a>. This enhances the overall security of the NoAH infrastructure, as well as the privacy of the user.</p>
</li>
<li>
<p align="justify"><strong>Improved Visualization</strong>: Honey@home now offers three different charts and graphs. The first one is a pie-chart breakdown of the packets received per protocol (TCP, UDP, ICMP, Other). The second is a speed graph which shows the rate at which traffic is captured and injected. The last one shows the TCP and UDP ports that received the most traffic.</p>
</li>
<li>
<p align="justify"><strong>Misc. Improvements</strong>: The new version has a reduced memory footprint. Also it provides novice users with a recommendation for which of the existing network interfaces is suitable for the software.</p>
</li>
</ol>
<h2>Screenshots</h2>
<p align="center"><img src="http://blogs.fp6-noah.org/noah/files/2008/05/hah-200805-interface-recommendation.png" /><br />
<strong>Network interface recommendation at startup</strong></p>
<hr />
<p align="center"><img src="http://blogs.fp6-noah.org/noah/files/2008/05/hah-200805-settings-manager.png" alt="Honey@home settings manager" /><strong>Honey@home settings manager</strong></p>
<hr />
<p align="center"><img src="http://blogs.fp6-noah.org/noah/files/2008/05/hah-200805-protocol-breakdown.png" alt="Breakdown chart of received traffic per protocol" /><strong>Breakdown chart of received traffic per protocol</strong></p>
<hr />
<p align="center"><img src="http://blogs.fp6-noah.org/noah/files/2008/05/hah-200805-traffic-rate.png" alt="Traffic rate graphs" /><strong>Traffic rate graph</strong></p>
<hr />
<p align="center"><img src="http://blogs.fp6-noah.org/noah/files/2008/05/hah-200805-top-ports.png" alt="Top ports graph" /><strong>Top ports graph</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.fp6-noah.org/noah/update-for-windows-honeyhome-software/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NoAH Router ready to catch attacks</title>
		<link>http://blogs.fp6-noah.org/noah/noah-router-ready-to-catch-attacks/</link>
		<comments>http://blogs.fp6-noah.org/noah/noah-router-ready-to-catch-attacks/#comments</comments>
		<pubDate>Mon, 31 Mar 2008 20:59:48 +0000</pubDate>
		<dc:creator>Alcatel-Lucent</dc:creator>
				<category><![CDATA[announcements]]></category>
		<category><![CDATA[noah]]></category>
		<category><![CDATA[router]]></category>

		<guid isPermaLink="false">http://blogs.fp6-noah.org/noah/noah-router-ready-to-catch-attacks/</guid>
		<description><![CDATA[The NoAH Router developed in the context  of NoAH has successfully passed the last tests and is now ready to catch attacks on the Internet.
 The innovative concept of NoAH Router allows to detect suspicious flows that are currently not seen by the existing Honeypots. Being installed on a router installed at the heart [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">The NoAH Router developed in the context  of NoAH has successfully passed the last tests and is now ready to catch attacks on the Internet.</p>
<p align="justify"> The innovative concept of NoAH Router allows to detect suspicious flows that are currently not seen by the existing Honeypots. Being installed on a router installed at the heart of the Internet, it can identify and redirect flows coming from scanning bots even if the targeted machines are not under monitoring.</p>
<p align="justify">During the next phase, the capacity of the NoAH Router for preventing zero-day attacks will be evaluated in a live environment. Keep an eye on the blog for further updates on the NoAH router.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.fp6-noah.org/noah/noah-router-ready-to-catch-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NoAHDB tool version 0.2 is out!</title>
		<link>http://blogs.fp6-noah.org/noah/noahdb-tool-version-02-is-out/</link>
		<comments>http://blogs.fp6-noah.org/noah/noahdb-tool-version-02-is-out/#comments</comments>
		<pubDate>Thu, 27 Mar 2008 14:00:38 +0000</pubDate>
		<dc:creator>vtrip</dc:creator>
				<category><![CDATA[announcements]]></category>
		<category><![CDATA[noah]]></category>

		<guid isPermaLink="false">http://blogs.fp6-noah.org/noah/noahdb-tool-version-02-is-out/</guid>
		<description><![CDATA[NoAHDB is a command line tool that parses the log files that are emitted by the  		Argos honeypot and populates the tables of a MySQL database.  		The goal of NoAHDB is to assist the network administrator to collect and analyse all that precious 		information emmited by the Argos honeypot.
For more information on NoAHDB [...]]]></description>
			<content:encoded><![CDATA[<p>NoAHDB is a command line tool that parses the log files that are emitted by the  		<a href="http://www.few.vu.nl/argos/">Argos honeypot</a> and populates the tables of a <a href="http://www.mysql.com/">MySQL</a> database.  		The goal of NoAHDB is to assist the network administrator to collect and analyse all that precious 		information emmited by the Argos honeypot.</p>
<p>For more information on NoAHDB tool please visit <a href="http://kxinidis.dyndns.org/project-noahdb.html" title="NOAHDB homepage">NoAHDB homepage</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.fp6-noah.org/noah/noahdb-tool-version-02-is-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NoAH Database Management Interface version 0.0.2 is out!</title>
		<link>http://blogs.fp6-noah.org/noah/noah-database-management-interface-version-002-is-out/</link>
		<comments>http://blogs.fp6-noah.org/noah/noah-database-management-interface-version-002-is-out/#comments</comments>
		<pubDate>Tue, 18 Mar 2008 10:06:50 +0000</pubDate>
		<dc:creator>vtrip</dc:creator>
				<category><![CDATA[announcements]]></category>
		<category><![CDATA[noah]]></category>

		<guid isPermaLink="false">http://blogs.fp6-noah.org/noah/noah-database-management-interface-version-002-is-out/</guid>
		<description><![CDATA[NoAH Database Management Interface (NOAHIF)  is a web application (based on Ruby on Rails web framework) that eases the management of a network of honeypots.  		    	Information concerning the location of the sensors/honeypots, the hardware and software configuration of the 		    	sensors/honeypots and the services running are [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">NoAH Database Management Interface (NOAHIF)  is a web application (based on <a href="http://www.rubyonrails.org/">Ruby on Rails</a> web framework) that eases the management of a network of honeypots.  		    	Information concerning the location of the sensors/honeypots, the hardware and software configuration of the 		    	sensors/honeypots and the services running are easily managed.</p>
<p align="justify">For more information on NOAHIF please visit <a href="http://kxinidis.dyndns.org/project-noahif.html" title="NOAHIF homepage">NOAHIF homepage</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.fp6-noah.org/noah/noah-database-management-interface-version-002-is-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Argos version 0.4.0 released</title>
		<link>http://blogs.fp6-noah.org/noah/argos-version-040-released/</link>
		<comments>http://blogs.fp6-noah.org/noah/argos-version-040-released/#comments</comments>
		<pubDate>Fri, 14 Mar 2008 11:16:01 +0000</pubDate>
		<dc:creator>Vrije Universiteit, Amsterdam</dc:creator>
				<category><![CDATA[announcements]]></category>
		<category><![CDATA[noah]]></category>
		<category><![CDATA[emulator]]></category>
		<category><![CDATA[honeypot]]></category>

		<guid isPermaLink="false">http://blogs.fp6-noah.org/noah/argos-version-040-released/</guid>
		<description><![CDATA[Finally, the long awaited port to QEMU 0.9.* series is here. Argos v0.4.0 is based upon QEMU v0.9.1.
Some useful changes follow:
 version 0.9.1:

 TFTP booting from host directory (Anthony Liguori, Erwan Velu)
 Tap device emulation for Solaris (Sittichai Palanisong)
 Monitor multiplexing to several I/O channels (Jason Wessel)
 CPU model selection support (J. Mayer, Paul Brook, [...]]]></description>
			<content:encoded><![CDATA[<p>Finally, the long awaited port to QEMU 0.9.* series is here. Argos v0.4.0 is based upon QEMU v0.9.1.</p>
<p>Some useful changes follow:</p>
<h3> version 0.9.1:</h3>
<ul>
<li> TFTP booting from host directory (Anthony Liguori, Erwan Velu)</li>
<li> Tap device emulation for Solaris (Sittichai Palanisong)</li>
<li> Monitor multiplexing to several I/O channels (Jason Wessel)</li>
<li> CPU model selection support (J. Mayer, Paul Brook, Herve Poussineau)</li>
<li> Read-only support for Parallels disk images (Alex Beregszaszi)</li>
<li> SVM (x86 virtualization) support (Alexander Graf)</li>
<li> Intel mainstone II board emulation (Armin Kuster)</li>
<li> VMware SVGA II graphics card support (Andrzej Zaborowski)</li>
</ul>
<h3>version 0.9.0:</h3>
<ul>
<li>Support for relative paths in backing files for disk images</li>
<li> Async file I/O API</li>
<li> New qcow2 disk image format</li>
<li>Support of multiple VM snapshots</li>
<li>Linux: specific host CDROM and floppy support</li>
<li>SMM support</li>
<li>Moved PCI init, MP table init and ACPI table init to Bochs BIOS</li>
<li>several x86 and x86_64 emulation fixes</li>
<li>Mouse relative offset VNC extension (Anthony Liguori)</li>
<li>PXE boot support (Anthony Liguori)</li>
<li>&#8216;-daemonize&#8217; option (Anthony Liguori)</li>
</ul>
<p align="justify">Additional changes, besides the port, include a double taintness check before executing a part of code to ensure attackers&#8217; injected code is always detected at the moment it is first executed. The check is performed whenever a TB is scheduled to be executed, as well as within the translated code whenever EIP is modified. This is to cover TB chaining performed by QEMU to speed up emulation. In the future we might consider disabling chaining, if a single check offers a significant performance gain.</p>
<p>For more information on Argos visit: <a href="http://www.few.vu.nl/argos" title="Argos Home">http://www.few.vu.nl/argos</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.fp6-noah.org/noah/argos-version-040-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

