<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://honeynet.org" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Chinese  Chapter</title>
 <link>http://honeynet.org/chapters/china</link>
 <description>Chinese Chapter led by Jianwei Zhuge; Research focus: client honeypot, high-interaction honeypot, malware col and analysis</description>
 <language>en</language>
<item>
 <title>Chinese Chapter Status Report For 2012 (Sep 2011 - Aug 2012)</title>
 <link>http://honeynet.org/node/971</link>
 <description>&lt;p&gt;&lt;strong&gt;ORGANIZATION&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;cite&gt;The Chinese Chapter was founded in 2008 based on Artemis research team in PKU and currently consists of the following people:&lt;/cite&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Dr. Jianwei Zhuge, Chapter Leader, Tsinghua Asso. Prof.&lt;/li&gt;
&lt;li&gt;Chengyu Song, Gatech ph.d. student&lt;/li&gt;
&lt;li&gt;Zhijie Chen, Berkeley ph.d. student&lt;/li&gt;
&lt;li&gt;Dr. Xinhui Han, PKU Asso. Prof.&lt;/li&gt;
&lt;li&gt;Dr. Yong Tang, NUDT Asso. Prof. &lt;/li&gt;
&lt;li&gt;Huilin Zhang, PKU ph.d. student&lt;/li&gt;
&lt;li&gt;Lingfeng Sun, Huawei engineer&lt;/li&gt;
&lt;li&gt;Jian Jiang, Tsinghua phd. student&lt;/li&gt;
&lt;li&gt;Cong Zheng, PKU ms. student&lt;/li&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/china&quot; class=&quot;og_links&quot;&gt;Chinese  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/971&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/china" xmlns="http://drupal.org/project/og">Chinese  Chapter</group>
 <pubDate>Tue, 30 Oct 2012 23:39:39 -0500</pubDate>
 <dc:creator>jianwei.zhuge</dc:creator>
 <guid isPermaLink="false">971 at http://honeynet.org</guid>
</item>
<item>
 <title>The Honeynet Project Chinese Chapter - Status Report 2011</title>
 <link>http://honeynet.org/node/701</link>
 <description>&lt;p&gt;ORGANIZATION&lt;/p&gt;
&lt;p&gt;The Chinese Chapter consists of the following people:&lt;br /&gt;
* Jianwei Zhuge, Tsinghua&lt;br /&gt;
* Chengyu Song, Gatech&lt;br /&gt;
* Zhijie Chen, Berkeley&lt;br /&gt;
* Xinhui Han, PKU&lt;br /&gt;
* Yong Tang, NUDT&lt;br /&gt;
* Huilin Zhang, PKU&lt;br /&gt;
* Zhongjie Wang, PKU&lt;br /&gt;
* Lingfeng Sun, HuaweiSymantec&lt;br /&gt;
* Jian Jiang, Tsinghua&lt;br /&gt;
* Youzhi Bao, PKU&lt;br /&gt;
* Cong Zheng, PKU&lt;/p&gt;
&lt;p&gt;The Chapter members are interested in research projects covering the following topics:&lt;/p&gt;
&lt;p&gt;1. Low-interaction/high-interaction client honeypots&lt;br /&gt;
2. Distributed honeynet deployment, operation and data analysis&lt;br /&gt;
3. Automated malware collection and analysis systems&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/china&quot; class=&quot;og_links&quot;&gt;Chinese  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/701&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/china" xmlns="http://drupal.org/project/og">Chinese  Chapter</group>
 <pubDate>Thu, 30 Jun 2011 21:16:47 -0500</pubDate>
 <dc:creator>jianwei.zhuge</dc:creator>
 <guid isPermaLink="false">701 at http://honeynet.org</guid>
</item>
<item>
 <title>Know Your Tools: Qebek - Conceal the Monitoring has been published</title>
 <link>http://honeynet.org/node/588</link>
 <description>&lt;p&gt;Christian Seifert (CPRO of The Honeynet Project) has just announced publication of our Know Your Tools series: Qebek - Conceal the Monitoring,  authored by Chengyu Song and Jianwei Zhuge from the Chinese Chapter and Brian Hay from the Alaskan Chapter. The paper is based on Chengyu&#039;s hard work during the GSoC 2009, Brian Hay and me acted as his mentors for the Qebek GSoC Project. Congrats to Chengyu and Chinese Chapter. &lt;/p&gt;
&lt;p&gt;The paper is available from http://honeynet.org/papers/KYT_qebek.&lt;/p&gt;
&lt;p&gt;Paper abstract&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/china&quot; class=&quot;og_links&quot;&gt;Chinese  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/588&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/china" xmlns="http://drupal.org/project/og">Chinese  Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/113">KYE</category>
 <category domain="http://honeynet.org/taxonomy/term/114">KYT</category>
 <category domain="http://honeynet.org/taxonomy/term/156">White Paper</category>
 <pubDate>Fri, 05 Nov 2010 00:56:24 -0500</pubDate>
 <dc:creator>jianwei.zhuge</dc:creator>
 <guid isPermaLink="false">588 at http://honeynet.org</guid>
</item>
<item>
 <title>TraceExploit: Replaying method dissection</title>
 <link>http://honeynet.org/node/568</link>
 <description>&lt;p&gt;I&#039;ve been working on the GSOC Project 14 in recent months. We are meant to start a new tool which can replay the collected exploit traces. &lt;/p&gt;
&lt;p&gt;We know that during the process of exploit replay, there&#039;re many fields need to be changed in the original application messages. Some of them are platform independent, and the others are platform specific. Platform-independent variables are those changed each time we exploit, like timestamp, cookie, length, etc. And platform-specific variables are those changed only if the target system is changed, like target address, return address point to the shellcode.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/china&quot; class=&quot;og_links&quot;&gt;Chinese  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/568&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/china" xmlns="http://drupal.org/project/og">Chinese  Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/141">exploit replay</category>
 <category domain="http://honeynet.org/taxonomy/term/140">traceexploit</category>
 <pubDate>Tue, 17 Aug 2010 04:08:13 -0500</pubDate>
 <dc:creator>zhongjie.wang</dc:creator>
 <guid isPermaLink="false">568 at http://honeynet.org</guid>
</item>
<item>
 <title>The Honeynet Project取证分析挑战中文版启航，欢迎华语世界安全人士参与</title>
 <link>http://honeynet.org/node/556</link>
 <description>&lt;p&gt;&lt;a href=&quot;https://honeynet.org/&quot;&gt;The Honeynet Project&lt;/a&gt;是一个国际知名的开源信息安全研究团队，致力于提升Internet的安全。&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/china&quot; class=&quot;og_links&quot;&gt;Chinese  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/556&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/china" xmlns="http://drupal.org/project/og">Chinese  Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/120">Forensic Challenge</category>
 <category domain="http://honeynet.org/taxonomy/term/130">Simpilified Chinese</category>
 <pubDate>Tue, 01 Jun 2010 20:40:11 -0500</pubDate>
 <dc:creator>jianwei.zhuge</dc:creator>
 <guid isPermaLink="false">556 at http://honeynet.org</guid>
</item>
<item>
 <title>What&#039;s new on PHoneyC (4): Try it out!</title>
 <link>http://honeynet.org/node/484</link>
 <description>&lt;p&gt;Hi all:&lt;br /&gt;
       I have finished almost all the coding stuff of Project #1, now you can try out the new PHoneyC with shellcode/heapspray detection here:&lt;br /&gt;
 &lt;br /&gt;
&lt;a href=&quot;http://code.google.com/p/phoneyc/source/browse/phoneyc#phoneyc/branches/phoneyc-honeyjs&quot;&gt;http://code.google.com/p/phoneyc/source/browse/phoneyc#phoneyc/branches/phoneyc-honeyjs&lt;/a&gt;&lt;br /&gt;
 &lt;br /&gt;
        Please feel free to report any bug or suggestion on shellcode/heapspray detection to me.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/china&quot; class=&quot;og_links&quot;&gt;Chinese  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/484&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/gsoc/project1" xmlns="http://drupal.org/project/og">GSoC Project #1 - Develop and Improve PhoneyC</group>
 <group domain="http://honeynet.org/chapters/china" xmlns="http://drupal.org/project/og">Chinese  Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/44">gsoc</category>
 <category domain="http://honeynet.org/taxonomy/term/18">libemu</category>
 <category domain="http://honeynet.org/taxonomy/term/57">phoneyc</category>
 <category domain="http://honeynet.org/taxonomy/term/19">shellcode</category>
 <category domain="http://honeynet.org/taxonomy/term/58">spidermonkey</category>
 <pubDate>Mon, 10 Aug 2009 14:19:38 -0500</pubDate>
 <dc:creator>zhijie.chen</dc:creator>
 <guid isPermaLink="false">484 at http://honeynet.org</guid>
</item>
<item>
 <title>NtDeviceIoControlFile</title>
 <link>http://honeynet.org/node/471</link>
 <description>&lt;p&gt;As the console spy is almost finished, the next stage is mainly for network activities. Sebek Win32 version uses TDI hook to get this done. However, since getting driver object in virtualization layer is hard and TDI is TDI is on the path to deprecation, I need to find another way. The best solution seems to be hooking NtDeviceIoControlFile, the API Windows uses to do network related stuff and has been widely mentioned in malware behavior analysis papers. After some days of searching, I encounter a very useful resources today, a master thesis from TTAnalyze team:&lt;br /&gt;
 &lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/china&quot; class=&quot;og_links&quot;&gt;Chinese  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/471&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/gsoc/project3" xmlns="http://drupal.org/project/og">GSoC Project #3 - Qebek: QEMU Based Sebek</group>
 <group domain="http://honeynet.org/chapters/china" xmlns="http://drupal.org/project/og">Chinese  Chapter</group>
 <category domain="http://honeynet.org/taxonomy/term/99">qebek windows socket network</category>
 <pubDate>Thu, 30 Jul 2009 11:01:41 -0500</pubDate>
 <dc:creator>chengyu.song</dc:creator>
 <guid isPermaLink="false">471 at http://honeynet.org</guid>
</item>
<item>
 <title>Chinese Chapter Status Report (Period Apr 2007 to Dec 2008)</title>
 <link>http://honeynet.org/node/336</link>
 <description>&lt;p&gt;&lt;strong&gt;The Honeynet Project Chinese Chapter Status Report (Period Apr 2007 to Dec 2008)&lt;/strong&gt;&lt;br /&gt;
&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;strong&gt;ORGANIZATION &lt;/strong&gt;&lt;br /&gt;
&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;
1. Changes in the structure of your organization.&lt;br /&gt;
All members of Chinese Chapter (i.e. The Artemis Project) are still from ERCIS, Institute of Computer Science and Technology, Peking University, China. Although we are seaking for contributors from other organizations.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/china&quot; class=&quot;og_links&quot;&gt;Chinese  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/node/336&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/china" xmlns="http://drupal.org/project/og">Chinese  Chapter</group>
 <pubDate>Wed, 14 Jan 2009 06:35:49 -0600</pubDate>
 <dc:creator>jianwei.zhuge</dc:creator>
 <guid isPermaLink="false">336 at http://honeynet.org</guid>
</item>
<item>
 <title>About The Honeynet Project</title>
 <link>http://honeynet.org/about</link>
 <description>&lt;p&gt;The Honeynet Project  is a leading international 501c3 non-profit security research organization, dedicated to investigating the latest attacks and developing open source security tools to improve Internet security. With Chapters around the world, our volunteers have contributed to fight again malware (such as Confickr), discovering new attacks and creating security tools used by businesses and government agencies all over the world.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li  class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/chapters/alaska&quot; class=&quot;og_links&quot;&gt;Alaskan  Chapter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://honeynet.org/about&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <group domain="http://honeynet.org/chapters/westpoint" xmlns="http://drupal.org/project/og">West Point Chapter</group>
 <group domain="http://honeynet.org/chapters/unam" xmlns="http://drupal.org/project/og">UNAM Chapter</group>
 <group domain="http://honeynet.org/chapters/uk" xmlns="http://drupal.org/project/og">UK Chapter</group>
 <group domain="http://honeynet.org/chapters/taiwan" xmlns="http://drupal.org/project/og">Taiwan Chapter</group>
 <group domain="http://honeynet.org/chapters/spartandevils" xmlns="http://drupal.org/project/og">Spartan Devils Chapter</group>
 <group domain="http://honeynet.org/chapters/singapore" xmlns="http://drupal.org/project/og">Singapore Chapter</group>
 <group domain="http://honeynet.org/chapters/pakistan" xmlns="http://drupal.org/project/og">Pakistan Chapter</group>
 <group domain="http://honeynet.org/chapters/norway" xmlns="http://drupal.org/project/og">Norwegian Chapter</group>
 <group domain="http://honeynet.org/chapters/newzealand" xmlns="http://drupal.org/project/og">New Zealand Chapter</group>
 <group domain="http://honeynet.org/chapters/mexico" xmlns="http://drupal.org/project/og">Mexican Chapter</group>
 <group domain="http://honeynet.org/chapters/hongkong" xmlns="http://drupal.org/project/og">Hong Kong Chapter</group>
 <group domain="http://honeynet.org/chapters/hawaii" xmlns="http://drupal.org/project/og">Hawaii Chapter</group>
 <group domain="http://honeynet.org/chapters/global" xmlns="http://drupal.org/project/og">Global Chapter</group>
 <group domain="http://honeynet.org/chapters/giraffe" xmlns="http://drupal.org/project/og">Giraffe Chapter</group>
 <group domain="http://honeynet.org/chapters/germany" xmlns="http://drupal.org/project/og">German Chapter</group>
 <group domain="http://honeynet.org/chapters/france" xmlns="http://drupal.org/project/og">French  Chapter</group>
 <group domain="http://honeynet.org/chapters/czech" xmlns="http://drupal.org/project/og">Czech Chapter</group>
 <group domain="http://honeynet.org/chapters/malaysia2" xmlns="http://drupal.org/project/og">CyberSecurity Malaysia Chapter</group>
 <group domain="http://honeynet.org/chapters/china" xmlns="http://drupal.org/project/og">Chinese  Chapter</group>
 <group domain="http://honeynet.org/chapters/chicago" xmlns="http://drupal.org/project/og">Chicago  Chapter</group>
 <group domain="http://honeynet.org/chapters/canada" xmlns="http://drupal.org/project/og">Canadian Chapter</group>
 <group domain="http://honeynet.org/chapters/brazil" xmlns="http://drupal.org/project/og">Brazilian  Chapter</group>
 <group domain="http://honeynet.org/chapters/australia" xmlns="http://drupal.org/project/og">Australian Chapter</group>
 <group domain="http://honeynet.org/chapters/alaska" xmlns="http://drupal.org/project/og">Alaskan  Chapter</group>
 <pubDate>Sun, 10 Aug 2008 19:54:48 -0500</pubDate>
 <dc:creator>drupal</dc:creator>
 <guid isPermaLink="false">67 at http://honeynet.org</guid>
</item>
</channel>
</rss>
