78 Honeypots
One of the requirements for data control is to have two layers
of control. This redundancy ensures that there is no single point
of failure. The two layers also give organizations fl exibility in
containing an attacker’s activity. With GenI Honeynets, the second
layer is a router placed in between the fi rewall and the honeypots
as in Figure 3.1. The purpose of the router is to both screen the
fi rewall from attackers and act as a second data-control mechanism.
The router screens the fi rewall by preventing attackers from seeing
the fi rewall. Once a honeypot is compromised, the bad guys will
attempt to make outbound connections. However, they will not
see the fi rewall that is controlling them but a router, which is most
likely what ...