<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Italian Honey Project &#187; Project News</title>
	<atom:link href="http://www.honeynet.it/category/project-news/feed" rel="self" type="application/rss+xml" />
	<link>http://www.honeynet.it</link>
	<description>The Italian chapter of the Honeynet Research Alliance</description>
	<lastBuildDate>Wed, 11 Jan 2012 11:44:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Congratulation to Domenico Chiarito!</title>
		<link>http://www.honeynet.it/project-news/congratulation-to-domenico-chiarito</link>
		<comments>http://www.honeynet.it/project-news/congratulation-to-domenico-chiarito#comments</comments>
		<pubDate>Thu, 20 Oct 2011 14:34:01 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Project News]]></category>
		<category><![CDATA[The Dorothy Project]]></category>
		<category><![CDATA[The Italian Honeynet Project]]></category>
		<category><![CDATA[Fellows]]></category>
		<category><![CDATA[JDrone]]></category>
		<category><![CDATA[Thesis]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=436</guid>
		<description><![CDATA[
Folks, I&#8217;d like to say &#8220;Congrats!&#8221; to Domenico Chiarito who has just completed his Bachelor studies in &#8220;System and Network Security&#8221; @ the University of Milan (DTI). Domenico made his Thesis on the JDrone project. He drastically improved our botnet monitoring software by integrating a relational database  with the existing JDrone components (Client, and Server). His [...]
]]></description>
			<content:encoded><![CDATA[<p>Folks,</p>
<p>I&#8217;d like to say &#8220;Congrats!&#8221; to Domenico Chiarito who has just completed his Bachelor studies in &#8220;System and Network Security&#8221; @ the University of Milan (DTI).</p>
<p>Domenico made his Thesis on the JDrone project. He drastically improved our botnet monitoring software by integrating a relational database  with the existing JDrone components (Client, and Server).</p>
<p>His work could be downloaded <a title="JDrone 2.0" href="Thesis Chiarito Jdrone2 Nd">here</a>.</p>
<p>Thank you Domenico, the Honeynet.it project was pleased to mentor you during your work, and we really hope that you will continue to help us on such project.</p>
<p>m4rco-</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/project-news/congratulation-to-domenico-chiarito/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>First-ever Honeynet Project Public Conference–Paris 2011</title>
		<link>http://www.honeynet.it/media/first-ever-honeynet-project-public-conference%e2%80%93paris-2011</link>
		<comments>http://www.honeynet.it/media/first-ever-honeynet-project-public-conference%e2%80%93paris-2011#comments</comments>
		<pubDate>Mon, 21 Mar 2011 10:07:09 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Media]]></category>
		<category><![CDATA[Project News]]></category>
		<category><![CDATA[Conferences]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=406</guid>
		<description><![CDATA[
It is with great pleasure I announce the first-ever Honeynet Project Public Conference, held alongside with the traditional Honeynet Project Annual Workshop. The event will be held on March 21, 2011 in Paris. For those who just want to register now, go here. Date: 21 March 2011 (Monday) 8:30AM ~ 18:00PM (GMT+1) Location: ESIEA Paris, [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>It is with great pleasure I announce the first-ever Honeynet Project Public Conference, held alongside with the traditional Honeynet Project Annual Workshop. The event will be held on March 21, 2011 in Paris. For those who just want to register now, go here.</p>
<p>Date:  21 March 2011 (Monday)</p>
<p>8:30AM ~ 18:00PM (GMT+1)</p>
<p>Location:</p>
<p>ESIEA Paris, 9 rue Vesale 75005 Paris</p>
<p>(Nearest subway station: Les Gobelins(line #7))</p>
<p>About the event:</p>
<p>The 2011 Project Honeynet Security Workshop brings together experts in the field of information security from around the world to share the latest advances and threats in information security research. Organized by the not-for-profit Honeynet Project and co-sponsored by the ESIEA Engineering School, this full day workshop creates opportunities for networking, collaboration and lessons-learned featuring a rare, outstanding line-up of international security professionals who will present on the latest research tools and findings in the field.</p>
<p>This year’s workshop will be held in Paris, France on 21 March 2011 and is the first time that the workshop has opened a day to the public. Starting at 9:00 GMT+1, the workshop program features a format that includes presentations in five sessions and two bonus hands-on activities. The bonus activities include a technically challenging capture-the-flag (CTF) session and a tough forensics challenge (FC) that will allow attendees to apply their expertise and compete for prizes. If you’re looking to attend a high quality and challenging security workshop, then we encourage you to take advantage of this rare opportunity.</p></blockquote>
<p>More info <a href="http://www.honeynet.org/node/602">here</a>.</p>
<p>Enjoy!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/media/first-ever-honeynet-project-public-conference%e2%80%93paris-2011/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Comprehensive report on Botnets released by ENISA : we&#8217;ve made our contribution too</title>
		<link>http://www.honeynet.it/botnet/comprehensive-report-on-botnets-released-by-enisa-weve-made-our-contribution-too</link>
		<comments>http://www.honeynet.it/botnet/comprehensive-report-on-botnets-released-by-enisa-weve-made-our-contribution-too#comments</comments>
		<pubDate>Mon, 14 Mar 2011 17:11:04 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Project News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[The Dorothy Project]]></category>
		<category><![CDATA[The Italian Honeynet Project]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[ENISA]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=403</guid>
		<description><![CDATA[
Last week ENISA has released two interesting documents totally dedicated on the Botnet threat. We&#8217;re glad to notice that Dorothy has been mentioned in the &#8220;Botnets: Measurement, Detection, Disinfection and Defence&#8221; report These documents were also presented last week during a dedicated workshop hosted in Cologne, where different experts from various sectors has attended the [...]
]]></description>
			<content:encoded><![CDATA[<p>Last week <a href="http://www.enisa.europa.eu/">ENISA</a> has released <a href="http://www.enisa.europa.eu/act/res/botnets">two</a> interesting documents totally dedicated on the Botnet threat.<br />
We&#8217;re glad to notice that Dorothy has been mentioned in the  &#8220;Botnets: Measurement, Detection, Disinfection and Defence&#8221; report <img src='http://www.honeynet.it/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>These documents were also presented last week during a dedicated workshop hosted in Cologne, where different experts from various sectors has attended the event.  </p>
<pre>
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/comprehensive-report-on-botnets-released-by-enisa-weve-made-our-contribution-too/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When Dorothy meets Ruby, and other nice friends&#8230;</title>
		<link>http://www.honeynet.it/project-news/when-dorothy-meets-ruby-and-other-nice-friends</link>
		<comments>http://www.honeynet.it/project-news/when-dorothy-meets-ruby-and-other-nice-friends#comments</comments>
		<pubDate>Thu, 16 Dec 2010 11:15:13 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Project News]]></category>
		<category><![CDATA[The Dorothy Project]]></category>
		<category><![CDATA[The Italian Honeynet Project]]></category>
		<category><![CDATA[Banking Trojan]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Dorothive]]></category>
		<category><![CDATA[Dorothy]]></category>
		<category><![CDATA[Financial Botnet]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=373</guid>
		<description><![CDATA[
I would like to inform you about our recent progresses. We are working hard for releasing the  new version  of our framework for botnet tracking(Dorothive). Below you can find some new features: + Postgres database + the analysis coore is being developed in pure ruby language (OO oriented, easy addition of new detection rules ex. [...]
]]></description>
			<content:encoded><![CDATA[<p>I would like to inform you about our recent progresses.</p>
<p>We are working hard for releasing the  new version  of our framework for botnet tracking(Dorothive).</p>
<p>Below you can find some new features:</p>
<p>+ Postgres database</p>
<p>+ the analysis coore is being developed in pure ruby language (OO oriented, easy addition of new detection rules ex. zeus,spyeyes,etc)</p>
<p>+ New visualization techniques : Realtime Charts (hightcharts, or opencharts), and AJAX google APIs for maps. That&#8217;s the way.</p>
<p>+ Drone completely coded from the scratch in Java: multi-platform, PKI based, TOR/proxy connection, IRC/HTTP compatibility.We are close to launch our first beta.  Let me know who is interested in participating as beta-tester.</p>
<p>+ The analysis engine will be able to detect financial botnet as presented at the APWG conference , here at Barcelona Digital we are going to begin the test phase to acquire some interesting results.</p>
<p>+ and lot more.. <img src='http://www.honeynet.it/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>More status updates will be released more often, I promise.</p>
<p>stay tuned!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/project-news/when-dorothy-meets-ruby-and-other-nice-friends/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dorothy @APWG in Dallas</title>
		<link>http://www.honeynet.it/botnet/dorothy-apwg-in-dallas</link>
		<comments>http://www.honeynet.it/botnet/dorothy-apwg-in-dallas#comments</comments>
		<pubDate>Thu, 14 Oct 2010 09:16:18 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Paper]]></category>
		<category><![CDATA[Project News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[APWG]]></category>
		<category><![CDATA[Banking Trojan]]></category>
		<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Dorothy]]></category>
		<category><![CDATA[Financial Botnet]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=366</guid>
		<description><![CDATA[
On next Tuesday (October 19) I&#8217;m going to present a research in progress paper that I wrote with the e-Crime team of Barcelona Digital and Marco Cremonini from Department of Information Technology of the Università degli Studi di Milano. The title of our paper is &#8220;A Framework For Financial Botnet Analysis&#8220;  and will be presented [...]
]]></description>
			<content:encoded><![CDATA[<p>On next Tuesday (October 19) I&#8217;m going to present a research in progress paper that I wrote with the e-Crime team of <a href="http://www.bdigital.org/EN/rdi/Pages/Security.aspx" target="_blank">Barcelona Digital</a> and Marco Cremonini from <a href="http://dti.unimi.it/"><em>Department of Information Technology</em></a> of the Università degli Studi di  <em>Milano.</em></p>
<p>The title of our paper is &#8220;<em>A Framework For Financial Botnet Analysis</em>&#8220;  and will be presented at the Anti Phishing Working Group (<a href="http://apwg.org/events/2010_gm.html#agenda">APWG</a>) conference that this year will be held in Dallas.  Our work  represents a research study that is still in progress that is  based on developing new detection and mitigation strategies to cope with financial botnets.</p>
<p>The proposed research partially relies on a customized version of the <em>Dorothy Framework</em> by improving its overall development status. The Italian Chapter of the <a href="http://www.honeynet.org/">Honeynet Project</a> is proud to see that its work is going to be useful also for such purpose, and this publication will encourage its future research.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/dorothy-apwg-in-dallas/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Time for summer</title>
		<link>http://www.honeynet.it/project-news/time-for-summer</link>
		<comments>http://www.honeynet.it/project-news/time-for-summer#comments</comments>
		<pubDate>Tue, 10 Aug 2010 12:54:12 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Project News]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=335</guid>
		<description><![CDATA[
Folks, We would like to hope you all a nice summer holidays ! We will back at work on September  releasing new updates about our current projects . See you there!
]]></description>
			<content:encoded><![CDATA[<p>Folks,</p>
<p>We would like to hope you all a nice summer holidays !</p>
<p>We will back at work on September  releasing new updates about our current projects .</p>
<p>See you there!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/project-news/time-for-summer/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Marry Christmas and Happy new year!</title>
		<link>http://www.honeynet.it/project-news/marry-christmas-and-happy-new-year</link>
		<comments>http://www.honeynet.it/project-news/marry-christmas-and-happy-new-year#comments</comments>
		<pubDate>Thu, 24 Dec 2009 10:01:34 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Project News]]></category>
		<category><![CDATA[The Italian Honeynet Project]]></category>
		<category><![CDATA[Christmas]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=164</guid>
		<description><![CDATA[
Folks, I would like to wish you a beautiful christmas ave! Special wishes to our team, focusly to who is daily devoting its time contributing in our project. Claudio Guarnieri, Andrea Cavenago, and Patrizia Martemucci recentrly worked hard for developing new modules of Dororthy framework (a malware analysis module, and the new dorothy-drone), really thanks [...]
]]></description>
			<content:encoded><![CDATA[<p>Folks,</p>
<p>I would like to wish you a beautiful christmas ave!<br />
Special wishes to our team, focusly to who is daily devoting its time contributing in our project.<br />
Claudio Guarnieri, Andrea Cavenago, and Patrizia Martemucci recentrly worked hard for developing new modules of Dororthy framework (a malware analysis module, and the new dorothy-drone), really thanks for their support, I wish that during next year they will continue to give their fruitful contribution.</p>
<p>Next year we well back in action,  and relasing the new version of Dorothy (Dorothive) will be the primary project goal. So stay tuned!</p>
<p>Best Regards,</p>
<p>m4rco-</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/project-news/marry-christmas-and-happy-new-year/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chapter updates..</title>
		<link>http://www.honeynet.it/project-news/chapter-updates</link>
		<comments>http://www.honeynet.it/project-news/chapter-updates#comments</comments>
		<pubDate>Wed, 16 Dec 2009 09:38:51 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Project News]]></category>
		<category><![CDATA[The Dorothy Project]]></category>
		<category><![CDATA[The Italian Honeynet Project]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=159</guid>
		<description><![CDATA[
Folks, I would like to inform you all about our recent activities that we are attempting to achieve. First of all, we have totally rebuilt our web site. This new ones aim to be a central repository of all the (external/internal) news concerning botnets (mainly) and malwares (secondary). We will use the blog for posting [...]
]]></description>
			<content:encoded><![CDATA[<p>Folks,</p>
<p>I would like to inform you all about our recent activities that we are attempting to achieve.</p>
<p>First of all, we have totally rebuilt our web site. This new ones aim to be a central repository of all the (external/internal) news concerning botnets (mainly) and malwares (secondary).<br />
We will use the blog for posting about our project developments, and for commenting/reporting interesting news concerning the field that we are currently treating, so you can now add a new entry to your feeds reader <img src='http://www.honeynet.it/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
The repository section aims to maintain a complete library of all the publications redacted (by us or others) until today about botnets. Each one can be tagged and classified for giving an easy way for searching what a researcher needs.  If you have a paper/doc about botnets, we will be proud to upload it here!<br />
The Dorothy section is the web GUI of the framework developed by me about irc-botnet tracking through interactive visualization. Maybe you have seen it before (I’ve posted the link in this mailing list some months ago), since that I’ve improved the GUI adding a “malwares” task for each C&amp;C, and providing an afterglow graph for each malware and for each C&amp;C .<br />
We are also maintaining a Wiki, here you can find all information about our tools/activities: you are all invited to contribute on it. The wiki has been recently &#8220;plugged&#8221; with the GUI giving the possibility to create a new page for each C&amp;C, in this way, every researcher can write about his own investigation about it.</p>
<p>Then I would like to introduce two new chapter members:  Emanuele Goldoni , and Davide Cavalca.<br />
I’ve ask them to join in our team after reading  their research work regarding a development of an automated  framework for malware analysis and irc/web botnet tracking.<br />
Their  tool “HIVE” is really similar to the ones developed by me , but present a more robust data architecture. Dorothy and HIVE was developed to achieve the same goal, whereas the first ones focus on the visualization methods as its straight point, the second treats the acquisition process in a more engineering manner: the data repository has been designed for being capable for receiving data for a wide sensor deployment.<br />
We are currently defining the details of a possible collaboration between the Information Technology Department of the University of Milan  and the Networking Lab of the University of Pavia (where Emanuele works as researcher) . Both universities are current offering their graduating students for conducting their diploma thesis about the improvement of our framework.  Currently, we are following the work of three students: one is developing a new multiplatform drone for irc botnet tracking, and the others are developing a dedicated framework for malware analysis (static and dynamic).<br />
Currently, me and Davide are developing a new integrated framework (Dorothive) that inherit all the goodness of our previous tools.<br />
Thanks to Davide and Emanuele’s contribution, our chapter is growing fast, they are a very skilled people and they are so motivated as me to make our chapter more interesting as possible: working with them is a real pleasure.</p>
<p>I ask you all to view our new site, for accessing to the private sections (wiki, Dorothy) you need to register.<br />
Currently registrations are not open to the wide public, so if you want an account please let me know and I will provide you one.</p>
<p>Please to give us your  feeds/comments/suggestions/criticisms/anything , we will consider it as a treasure !</p>
<p>Best Regars,</p>
<p>m4rco-</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/project-news/chapter-updates/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>We have joined to the mwcollect alliance!</title>
		<link>http://www.honeynet.it/malware/we-have-joined-to-the-mwcollect-alliance</link>
		<comments>http://www.honeynet.it/malware/we-have-joined-to-the-mwcollect-alliance#comments</comments>
		<pubDate>Tue, 29 Sep 2009 18:27:29 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Project News]]></category>

		<guid isPermaLink="false">http://74.207.225.214/?p=118</guid>
		<description><![CDATA[
I&#8217;m glad to annunce that recently our chapter has becoming a member of the mwcollect alliance. This partnership will improve our malware acquisition module, offering a more sofisticated source. Thanks to Mark Schlößer for the registration support!
]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m glad to annunce that recently our chapter has becoming a member of the <a href="https://alliance.mwcollect.org/">mwcollect alliance</a>.<br />
This partnership will improve our malware acquisition module, offering a more sofisticated source. </p>
<pre>
</pre>
<p>Thanks to Mark Schlößer for the registration support!</p>
<pre>
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/malware/we-have-joined-to-the-mwcollect-alliance/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>News about the project developement</title>
		<link>http://www.honeynet.it/project-news/news-about-the-project-developement</link>
		<comments>http://www.honeynet.it/project-news/news-about-the-project-developement#comments</comments>
		<pubDate>Mon, 13 Apr 2009 21:35:00 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Project News]]></category>

		<guid isPermaLink="false">http://m4rc00.wordpress.com/2009/04/13/news-about-the-project-developement/</guid>
		<description><![CDATA[
Hi guys, I&#8217;m apologized for the long-time of inactivity but i have been engaged with the planification about the future of this project.The Dorothy Project is being evolving to the official Italian Honeynet Chapter, we are waiting for the correct subscription process accomplishment .Meanwhile, we have formed the official membership of the project.Currently this project [...]
]]></description>
			<content:encoded><![CDATA[<p>Hi guys,</p>
<p>I&#8217;m apologized for the long-time of inactivity but i have been engaged with the planification about the future  of this project.<br /><span style="font-style:italic;">The Dorothy Project</span> is being evolving to the official <span style="font-style:italic;font-weight:bold;">Italian Honeynet Chapter</span>, we are waiting for the correct subscription process accomplishment .<br />Meanwhile, we have formed the official membership of the project.<br />Currently this project count 5 official members, as soon as possible we will make available our profile for letting you all to meet us better .<br />We are defining the work to do in the next weeks, and planning the date for the official release of the web platform .</p>
<p>Here will be published every news about the project/chapter progress, and every interesting thing about the project research area (IT Security, Botnet, Malware Analysis, etc) so stay tunes, and post your opinions/comments!</p>
<p>See you soon</p>
<p>m4rco-</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/project-news/news-about-the-project-developement/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

