Build A Darknet To Capture Naughty Traffic
DM_NeoFLeX writes "Have some routable Address Space lying around? You might want to build a DarkNet. The folks over at Team Cymru have outlined instructions for creating one with FreeBSD and as little as /32 routable space. From the article: 'A Darknet is a portion of routed, allocated IP space in which no active services or servers reside. These are 'dark' because there is, seemingly, nothing within these networks. Any packet that enters a Darknet is by its presence Aberrant.' Darknets can provide useful information for tracking the flow of naughty network traffic."
You can set a honeypot like honeyd to essencially passivly capture all traffic to a subnet, which would log all worms as well. So a darknet is a lot like a honeynet, except you can't do as much with it.
"I use a Mac because I'm just better than you are."
a
A
sig?
It's also called a network telescope. CAIDA has been implementing this type of thing for several months.