Summary
In this chapter we have attempted to classify honeypots based on their level of interaction. Level of interaction defines how much functionality or activity an attacker can have with a honeypot. The more interaction available to the attacker, the more you can learn about the attacker. However, the greater the interaction, the more work you’ll have to deploy and maintain the honeypot and, in general, the greater the risk to your systems. A low-interaction honeypot may simply monitor several ports. This capability is easy to deploy and maintain, but it is limited in the information it can capture. High-interaction honeypots are the opposite: There is little or no emulation. Instead, attackers are given access to entire operating systems. ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access