<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Monitoring on Laboratoire de Haute Sécurité</title>
    <link>https://lhs.inria.fr/tags/monitoring/index.html</link>
    <description>Recent content in Monitoring on Laboratoire de Haute Sécurité</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <managingEditor>frederic.beck@inria.fr (Frederic Beck)</managingEditor>
    <webMaster>frederic.beck@inria.fr (Frederic Beck)</webMaster>
    <lastBuildDate>Thu, 06 Jun 2024 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://lhs.inria.fr/tags/monitoring/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Darknet</title>
      <link>https://lhs.inria.fr/datasets/darknet/index.html</link>
      <pubDate>Thu, 06 Jun 2024 00:00:00 +0000</pubDate><author>frederic.beck@inria.fr (Frederic Beck)</author>
      <guid>https://lhs.inria.fr/datasets/darknet/index.html</guid>
      <description>&lt;link href=&#34;../css/tile.css&#34; rel=&#34;stylesheet&#34;&gt;
&lt;link href=&#34;../../css/tile.css&#34; rel=&#34;stylesheet&#34;&gt;



    
    &lt;span class=&#34;badge cstyle info&#34;&gt;
        &lt;span class=&#34;badge-title&#34;&gt;&lt;i class=&#34;fas fa-tag&#34;&gt;&lt;/i&gt;&lt;/span&gt;
        &lt;span class=&#34;badge-content&#34; style=&#34;background-color: #048B9A;&#34;&gt;&lt;a style=&#34;color:#FFFFFF;&#34; href=&#34;../../tags/internet&#34;&gt;Internet&lt;/a&gt;&lt;/span&gt;
    &lt;/span&gt;

    
    &lt;span class=&#34;badge cstyle info&#34;&gt;
        &lt;span class=&#34;badge-title&#34;&gt;&lt;i class=&#34;fas fa-tag&#34;&gt;&lt;/i&gt;&lt;/span&gt;
        &lt;span class=&#34;badge-content&#34; style=&#34;background-color: #048B9A;&#34;&gt;&lt;a style=&#34;color:#FFFFFF;&#34; href=&#34;../../tags/monitoring&#34;&gt;Monitoring&lt;/a&gt;&lt;/span&gt;
    &lt;/span&gt;

    
    &lt;span class=&#34;badge cstyle info&#34;&gt;
        &lt;span class=&#34;badge-title&#34;&gt;&lt;i class=&#34;fas fa-tag&#34;&gt;&lt;/i&gt;&lt;/span&gt;
        &lt;span class=&#34;badge-content&#34; style=&#34;background-color: #048B9A;&#34;&gt;&lt;a style=&#34;color:#FFFFFF;&#34; href=&#34;../../tags/passive-listening&#34;&gt;Passive listening&lt;/a&gt;&lt;/span&gt;
    &lt;/span&gt;

    
    &lt;span class=&#34;badge cstyle info&#34;&gt;
        &lt;span class=&#34;badge-title&#34;&gt;&lt;i class=&#34;fas fa-tag&#34;&gt;&lt;/i&gt;&lt;/span&gt;
        &lt;span class=&#34;badge-content&#34; style=&#34;background-color: #048B9A;&#34;&gt;&lt;a style=&#34;color:#FFFFFF;&#34; href=&#34;../../tags/pcap&#34;&gt;PCAP&lt;/a&gt;&lt;/span&gt;
    &lt;/span&gt;

    
    &lt;span class=&#34;badge cstyle info&#34;&gt;
        &lt;span class=&#34;badge-title&#34;&gt;&lt;i class=&#34;fas fa-tag&#34;&gt;&lt;/i&gt;&lt;/span&gt;
        &lt;span class=&#34;badge-content&#34; style=&#34;background-color: #048B9A;&#34;&gt;&lt;a style=&#34;color:#FFFFFF;&#34; href=&#34;../../tags/csv&#34;&gt;CSV&lt;/a&gt;&lt;/span&gt;
    &lt;/span&gt;


&lt;br&gt;


    &lt;center&gt;
        &lt;div style=&#39;width:500px; margin-bottom:25px; margin-top:25px;&#39;&gt;
            &lt;img class=&#34;resizableImage&#34; src=&#34;../images/darknet01.png&#34; style=&#34;width:&#39;&#39;&#34; alt=&#34;Darknet&#34;/&gt;
        &lt;/div&gt;
    &lt;/center&gt;

&lt;h1&gt;Darknet&lt;/h1&gt;


    &lt;p&gt;
        Monitoring unused address space, or Darknet, consist in capturing all traffic towards a set of ip adresses directly connected to Internet, without any active computer connected. All inbound traffic is unsolicited.
    &lt;/p&gt;

    &lt;p&gt;
        Thanks to our Darknet using 4096 contiguous public IP addresses, we can mesure networks attack on internet in real time, and especially large scale phenomena such as Internet wide port scanning, DDoS backscatter or DNS amplification attempts.
    &lt;/p&gt;</description>
    </item>
    <item>
      <title>Darknet</title>
      <link>https://lhs.inria.fr/platforms/darknet/index.html</link>
      <pubDate>Wed, 05 Jun 2024 00:00:00 +0000</pubDate><author>frederic.beck@inria.fr (Frederic Beck)</author>
      <guid>https://lhs.inria.fr/platforms/darknet/index.html</guid>
      <description>&lt;link href=&#34;../css/tile.css&#34; rel=&#34;stylesheet&#34;&gt;
&lt;link href=&#34;../../css/tile.css&#34; rel=&#34;stylesheet&#34;&gt;



    
    &lt;span class=&#34;badge cstyle info&#34;&gt;
        &lt;span class=&#34;badge-title&#34;&gt;&lt;i class=&#34;fas fa-tag&#34;&gt;&lt;/i&gt;&lt;/span&gt;
        &lt;span class=&#34;badge-content&#34; style=&#34;background-color: #048B9A;&#34;&gt;&lt;a style=&#34;color:#FFFFFF;&#34; href=&#34;../../tags/internet&#34;&gt;Internet&lt;/a&gt;&lt;/span&gt;
    &lt;/span&gt;

    
    &lt;span class=&#34;badge cstyle info&#34;&gt;
        &lt;span class=&#34;badge-title&#34;&gt;&lt;i class=&#34;fas fa-tag&#34;&gt;&lt;/i&gt;&lt;/span&gt;
        &lt;span class=&#34;badge-content&#34; style=&#34;background-color: #048B9A;&#34;&gt;&lt;a style=&#34;color:#FFFFFF;&#34; href=&#34;../../tags/monitoring&#34;&gt;Monitoring&lt;/a&gt;&lt;/span&gt;
    &lt;/span&gt;

    
    &lt;span class=&#34;badge cstyle info&#34;&gt;
        &lt;span class=&#34;badge-title&#34;&gt;&lt;i class=&#34;fas fa-tag&#34;&gt;&lt;/i&gt;&lt;/span&gt;
        &lt;span class=&#34;badge-content&#34; style=&#34;background-color: #048B9A;&#34;&gt;&lt;a style=&#34;color:#FFFFFF;&#34; href=&#34;../../tags/passive-listening&#34;&gt;Passive listening&lt;/a&gt;&lt;/span&gt;
    &lt;/span&gt;


&lt;br&gt;



&lt;center&gt;
    &lt;div style=&#39;width:500px; margin-bottom:25px; margin-top:25px;&#39;&gt;
        &lt;img class=&#34;resizableImage&#34; src=&#34;../images/darknet01.png&#34; style=&#34;width:&#39;&#39;&#34; alt=&#34;Darknet&#34;/&gt;
    &lt;/div&gt;
&lt;/center&gt;

&lt;h1&gt;Passive Internet monitoring&lt;/h1&gt;


    &lt;p&gt;
        Monitoring unused address space, or Darknet, consist in capturing all traffic towards a set of ip adresses directly connected to Internet, without any active computer connected. All inbound traffic is unsolicited.
    &lt;/p&gt;

    &lt;p&gt;
        Thanks to our Darknet using 4096 contiguous public IP addresses, we can mesure networks attack on internet in real time, and especially large scale phenomena such as Internet wide port scanning, DDoS backscatter or DNS amplification attempts.
    &lt;/p&gt;</description>
    </item>
    <item>
      <title>Distributed honeypots</title>
      <link>https://lhs.inria.fr/platforms/honeypots/index.html</link>
      <pubDate>Wed, 05 Jun 2024 00:00:00 +0000</pubDate><author>frederic.beck@inria.fr (Frederic Beck)</author>
      <guid>https://lhs.inria.fr/platforms/honeypots/index.html</guid>
      <description>&lt;link href=&#34;../css/tile.css&#34; rel=&#34;stylesheet&#34;&gt;
&lt;link href=&#34;../../css/tile.css&#34; rel=&#34;stylesheet&#34;&gt;



    
    &lt;span class=&#34;badge cstyle info&#34;&gt;
        &lt;span class=&#34;badge-title&#34;&gt;&lt;i class=&#34;fas fa-tag&#34;&gt;&lt;/i&gt;&lt;/span&gt;
        &lt;span class=&#34;badge-content&#34; style=&#34;background-color: #048B9A;&#34;&gt;&lt;a style=&#34;color:#FFFFFF;&#34; href=&#34;../../tags/internet&#34;&gt;Internet&lt;/a&gt;&lt;/span&gt;
    &lt;/span&gt;

    
    &lt;span class=&#34;badge cstyle info&#34;&gt;
        &lt;span class=&#34;badge-title&#34;&gt;&lt;i class=&#34;fas fa-tag&#34;&gt;&lt;/i&gt;&lt;/span&gt;
        &lt;span class=&#34;badge-content&#34; style=&#34;background-color: #048B9A;&#34;&gt;&lt;a style=&#34;color:#FFFFFF;&#34; href=&#34;../../tags/monitoring&#34;&gt;Monitoring&lt;/a&gt;&lt;/span&gt;
    &lt;/span&gt;

    
    &lt;span class=&#34;badge cstyle info&#34;&gt;
        &lt;span class=&#34;badge-title&#34;&gt;&lt;i class=&#34;fas fa-tag&#34;&gt;&lt;/i&gt;&lt;/span&gt;
        &lt;span class=&#34;badge-content&#34; style=&#34;background-color: #048B9A;&#34;&gt;&lt;a style=&#34;color:#FFFFFF;&#34; href=&#34;../../tags/honeypots&#34;&gt;Honeypots&lt;/a&gt;&lt;/span&gt;
    &lt;/span&gt;


&lt;br&gt;



&lt;center&gt;
    &lt;div style=&#39;width:500px; margin-bottom:25px; margin-top:25px;&#39;&gt;
        &lt;img class=&#34;resizableImage&#34; src=&#34;../images/honeypots.png&#34; style=&#34;width:&#39;&#39;&#34; alt=&#34;Distributed honeypots&#34;/&gt;
    &lt;/div&gt;
&lt;/center&gt;

&lt;h1&gt;Distributed honeypots platform&lt;/h1&gt;


    &lt;p&gt;
        Our distributed honeypot platform based on Tpot allows us to operate various sensors running up to 20&amp;#43; honeypots each, centralizing the collect traces, logs and binaries in the LHS. The collected data is indexed in realtime in an Elasticsearch cluster.
    &lt;/p&gt;

    &lt;p&gt;
        Probes are placed on various dedicated network connections in the LHS, in the cloud or in our partners networks, thanks to the CyberGenAI joint project with DFKI (Germany) and OMU (Japan).
    &lt;/p&gt;</description>
    </item>
    <item>
      <title>Network Telescope</title>
      <link>https://lhs.inria.fr/platforms/telescope/index.html</link>
      <pubDate>Wed, 05 Jun 2024 00:00:00 +0000</pubDate><author>frederic.beck@inria.fr (Frederic Beck)</author>
      <guid>https://lhs.inria.fr/platforms/telescope/index.html</guid>
      <description>&lt;link href=&#34;../css/tile.css&#34; rel=&#34;stylesheet&#34;&gt;
&lt;link href=&#34;../../css/tile.css&#34; rel=&#34;stylesheet&#34;&gt;



    
    &lt;span class=&#34;badge cstyle info&#34;&gt;
        &lt;span class=&#34;badge-title&#34;&gt;&lt;i class=&#34;fas fa-tag&#34;&gt;&lt;/i&gt;&lt;/span&gt;
        &lt;span class=&#34;badge-content&#34; style=&#34;background-color: #048B9A;&#34;&gt;&lt;a style=&#34;color:#FFFFFF;&#34; href=&#34;../../tags/internet&#34;&gt;Internet&lt;/a&gt;&lt;/span&gt;
    &lt;/span&gt;

    
    &lt;span class=&#34;badge cstyle info&#34;&gt;
        &lt;span class=&#34;badge-title&#34;&gt;&lt;i class=&#34;fas fa-tag&#34;&gt;&lt;/i&gt;&lt;/span&gt;
        &lt;span class=&#34;badge-content&#34; style=&#34;background-color: #048B9A;&#34;&gt;&lt;a style=&#34;color:#FFFFFF;&#34; href=&#34;../../tags/monitoring&#34;&gt;Monitoring&lt;/a&gt;&lt;/span&gt;
    &lt;/span&gt;

    
    &lt;span class=&#34;badge cstyle info&#34;&gt;
        &lt;span class=&#34;badge-title&#34;&gt;&lt;i class=&#34;fas fa-tag&#34;&gt;&lt;/i&gt;&lt;/span&gt;
        &lt;span class=&#34;badge-content&#34; style=&#34;background-color: #048B9A;&#34;&gt;&lt;a style=&#34;color:#FFFFFF;&#34; href=&#34;../../tags/passive-listening&#34;&gt;Passive listening&lt;/a&gt;&lt;/span&gt;
    &lt;/span&gt;


&lt;br&gt;



&lt;center&gt;
    &lt;div style=&#39;width:500px; margin-bottom:25px; margin-top:25px;&#39;&gt;
        &lt;img class=&#34;resizableImage&#34; src=&#34;../images/telescope01.jpg&#34; style=&#34;width:&#39;&#39;&#34; alt=&#34;Network Telescope&#34;/&gt;
    &lt;/div&gt;
&lt;/center&gt;

&lt;h1&gt;Passive Internet monitoring&lt;/h1&gt;


    &lt;p&gt;
        The network telescope allows to deploy passive probes directly on the Internet, and capture traces (traffic, application logs...), whatever the size of the data.
    &lt;/p&gt;

    &lt;p&gt;
        Probes are placed on a dedicated network connection on which we control the firewall.
    &lt;/p&gt;

    &lt;p&gt;
        Collected data can be stored, replicated and indexed in realtime.
    &lt;/p&gt;



&lt;h2&gt;Links&lt;/h2&gt;

&lt;ul&gt;

    &lt;li&gt;
        &lt;a href=&#34;https://concordia-btc-p2p.lhs.inria.fr/&#34;&gt;https://concordia-btc-p2p.lhs.inria.fr/&lt;/a&gt;
    &lt;/li&gt;

    &lt;li&gt;
        &lt;a href=&#34;https://concordia-eth-p2p.lhs.inria.fr/&#34;&gt;https://concordia-eth-p2p.lhs.inria.fr/&lt;/a&gt;
    &lt;/li&gt;

&lt;/ul&gt;

&lt;h2&gt;Contact&lt;/h2&gt;

&lt;div class=&#34;customTileBox&#34;&gt;
    &lt;a href=&#34;mailto:frederic.beck@inria.fr&amp;body=&#34;&gt;
        &lt;div class=&#34;customTile emailTile&#34;&gt;
            &lt;i class=&#39;fas fa-paper-plane&#39;&gt;&lt;/i&gt;
            &lt;div&gt;
                &lt;div&gt;
                    Frederic Beck
                &lt;/div&gt;
                &lt;div class=&#34;italic&#34;&gt;
                    frederic.beck@inria.fr
                &lt;/div&gt;
            &lt;/div&gt;
        &lt;/div&gt;
    &lt;/a&gt;
&lt;/div&gt;</description>
    </item>
  </channel>
</rss>