ADVANCED ATTACKER DETECTION AND UNDERSTANDING WITH EMERGING HONEYNET TECHNOLOGIES
RONALD C. DODGE JR.
United States Military Academy, West Point, New York
THORSTEN HOLZ
Aachen University, Aachen, Germany
ANTON CHUVAKIN
LogLogic, San Jose, California
1 HONEYPOT ESSENTIALS
Honeypots and honeynets are well known to security processionals. Newly developed honeynet techniques and technologies are a hot topic in information security. However, the amount of technical information available on their setup, configuration, and maintenance is still sparse as are qualified people with the capability to run them, interpret the activity, and make security recommendations. Higher-level guidelines, such as a need and business case determination, are similarly absent. In addition, honeypot risks, such as legal authority and ethical use, need to be fully evaluated prior to honeynet deployments. In this article, we present a brief introduction to honeynet technologies, a short word on ethical and legal considerations, and then describe four of the most productive honeynet technologies.
What is a honeypot? Lance Spitzner, a founder of Honeynet Project [1] defines a honeypot as “a security resource whose value lies in being probed, attacked or compromised”. Thus, a goal of such a masochistic system is to be compromised and abused. Hopefully, each time a honeypot goes up in smoke, the researcher learns a new technique. For example, you can use a honeypot to find new rootkits, exploits, or backdoors ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access