September 2002
Intermediate to advanced
480 pages
11h 47m
English
We have seen that there are a variety of different ways to build and deploy honeypots. How you architect your honeypot depends on what you want to do with it. Are you hoping to catch the attackers in action and learn about their tools and tactics? If so, you need to build a complex honeypot that gives the attacker a complete operating system with which to interact. Are you primarily interested in detecting unauthorized activity, such as scanning? For this you can build a simple honeypot that merely emulates a variety of services in operation. If someone connects to these servers, then you know it is most likely unauthorized activity. Are you hoping to capture the latest worm for analysis? ...
Read now
Unlock full access