Information Gathering
Honeyd is designed for information gathering at two sources: syslogd and a sniffer system. By default, the Honeyd process logs all attempted and established TCP connections to syslogd. It also logs all ICMP echo replies to syslogd. Currently, UDP is not logged by the Honeyd process to syslogd. This is the only information the honeypot logs, and it is limited to transactional information, specifically source and destination IP address, source and destination port, and the timestamp of the activity. Some of the attacker’s activities may be logged if the emulated service has any additional logging capabilities. Figure 8-10 shows the Telnet connection to the Cisco router from Figure 8-6 being logged to syslogd. The connection ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access