Honeypots
Honeypots are fake services you set to catch attackers. You intentionally put a service up with the intention of luring attackers, tricking them into thinking the service is real and contains some kind of sensitive information. Often, the honeypot is disguised to look like an old, outdated, and vulnerable server. Logging or alerts can be attached to the honeypot to quickly identify a potential attacker. Having a honeypot on your internal network may alert you of an attacker before any systems are compromised.
When attackers compromise a machine, they often use the compromised machine to continue enumerating, attacking, and pivoting. If a honeypot on your network detects strange behavior coming from another machine on your network, ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access