defense And AnAlysis teChniques 277
in the wild. is lack of visibility requires a reactive approach to a
security incident, which is a norm within the IT security field as a
whole. An ideal approach involves proactive measures using knowl-
edge and information of upcoming vulnerabilities, malicious code,
and attackers to build up defenses prior to an incident. One method of
obtaining the necessary data to create safeguards requires sacrificing a
specially configured system, known as a honeypot, to lure in malicious
activity for analysis.
A honeypot is an information system resource whose value lies in
unauthorized or illicit use of that resource.
8
A honeypot is a concept that
capitalizes on the isolation of a resource and subsequent activi