Andrew van der Stock Alternatives to Honeypots
Andrew van der Stock, Senior Architect - e-Secure
Alternatives to honeypots or the dtk
Honeypots have a long history and undeserved high profile in the securityindustry. Andrew discusses flaws with honeypots, and popular sites like honeynet who host honeypots, from a technical and risk perspective. However, as their use is moderately common in many sites, a safer replacement should be found.
Andrew will be introducing a new passive intrusion detection tool to assist with providing advanced sites with additional information they require to track down careless attackers. In addition, common sense security advice is given to help reduce the risk profile for the majority of sites.
Andrew van der Stock is a Senior Architect at e-Secure, one of Australia's largest IT specialist security consultancy firms. e-Secure only delivers their core competency: consultancy services, and do not align themselves with any vendor. Andrew has been in security for over six years, and in IT for over eleven. He is a NT/2k/XP sorta guy (dual MCSE, fwiw (not much)), with a strong open source background. He helped develop the matrox drivers in XFree86 and is the current maintainer of pnm2ppa, which allows Unix people to print to HP's worst-ever printers.
Andrew sits on a government panel on the future of DNS competition in Australia, giving technical and security advice (he is one of three tech dudes on a panel of 30, and the only unbiased one ;-). He is the current immediate past President of SAGE-AU.
Black Hat - USA - 2001 Hacking conference
#hacking, #hackers, #infosec, #opsec, #IT, #honeypot