HOME - NEWS EVENTS - MAILING LISTS - OPST/OPSA TRAINING & EXAMS - ABOUT US - CORE TEAM - MEDIA KIT - CONTACT - OPEN LICENSES 




 


 

  TEAM ACCESS
     Beta Releases
     Gold Team Updates

  PROJECTS & RESEARCH

     Business Integrity Testing
     Compromise Detection
     Jack of All Trades
     Hacker Highschool
     Hacker's Profiling Project
     Protocol Database
     Security Incident Policy Enforcement
     Security Metrics
     Security Maturity Model
     Secure Programming
     Security Testing Methodology
     Software Quality Testing
     Security Tools
     Trusted Computing
     XML
     Graduate Projects

  ACCREDITED TRAINING

     ISESTORM Event 
     OPSA - Security Analyst 
     OPST - Security Tester 
     OPSE - OSSTMM Expert 
     OWSE - OSSTMM Wireless Expert 
     Hacker Highschool Teacher
     Training Material Accreditation 
     Trainer & Training Certification
     Training & Exam Schedule

  ASSOCIATIONS 

     ISECOM Associates
     ISECOM Affiliates
     ISECOM Partners
     ISECOM Auditors
     Sponsors

  SERVICES 

     Security Test Review
     Gold/Silver Subscriptions 
ISECOM - Institute for Security and Open Methodologies

www.isecom.org - PROJECTS & RESEARCH - HACKER’S PROFILING PROJECT - HPP

Hacker’s Profiling Project (HPP)
Project Managers: Raoul Chiesa  raoul@ISECOM.org

The goal of this presentation document is to resume the first 2 years of the HPP results, as well as define the core of a methodology that will allow the use of the attacker’s profiling techniques in computer-based IT and ICT attacks. The document gives a strong consideration to the first two developed phases of the Hacker’s Profiling Project, defining at the same time the next steps for the core-asset of the methodology itself.

The original idea started back in 2004, after many researches related to Criminal and Hacker’s Profiling: most of the available data and studies have been carried out basically focusing on single “points of view”: the criminal analysis of the computer intrusion on one side, the technical analysis of the computer intrusion on the other side. In no cases we have seen a synergic approach of the above-mentioned points of view.

Also, the hacking panorama has always been described as a world populated by data thieves, modern Robin Hood and criminals, rather than the “good & bad guys” general definitions. Our research project aims to identify the real actors’ behaviours of this particular technological environment and social culture, driving away from the cliché often (ab)used by the media and by the classic company’s “security culture”, helping in better identifying the reasons of IT/ICT attacks and the real modus operandi, determining a better counter-measures approach.

At the moment (June 2006), the available documents will focus on describing “how it works” side more than the “how to use” aspect. This methodology will serve those who need to identify attackers’ typologies and better understanding the (different) motivations that lead to a computer intrusion scene.

Among the next steps, as the Honeynet module will be defined (2007), we are expecting to produce various detailed technical papers, on which basis we will outline the profiling methodology itself.

The final goal of HPP consists in developing an open methodology that – when applied to log files or computer forensics dumps - will enable the analysts to analyze the data from a different point of view, supplying them with a profiling methodology that will identify the kind of attacker that has performed the attack(s) itself, including as well security and privacy weaknesses, circumventions, corruption, fraud, embezzlement, theft, and other deceptive, illegal, or unethical practices.

If you are interested in helping us with this project, please, contact us at hpp<at>isecom.org.

Download HPP General Overview, Basic Presentation v.1.0_eng: 

            

Spain

USA

HPP.general_overview_Basic.v.1.0_eng.pdf

 

 

Download HPP General Overview, Compact Presentation v.1.0_eng:   

            

Spain

USA

HPP.general_overview_Compact.v.1.0_eng.pdf

 

 

 10253 visits (5 today, 52 this week)

 

 

Formerly the Ideahamster Organization - www.isecom.org - www.osstmm.orgwww.hackerhighschool.org - www.isestorm.org
 If you have any comments, questions, or to note broken links on this website send e-mail to the
Webmaster
. 
 All contents copyright © 2000 - 2006 - ISECOM - Institute for Security and Open Methodologies. All rights reserved.