Friday | 10 July, 2009
CSO
Why virtual honeypots are sweet
Honeypot technology can be used for botnet-tracking or malicious code collection
Ellen Messmer (Network World) 13/08/2007 12:20:48

And what about two other tools you mention, Collapsar and the Potemkin Virtual Honeyfarm?

Provos: With Collapsar, from Purdue, the idea is being able to deploy nodes all over the Internet but the analysis is centralized. The Potemkin Virtual Honeyfarm, developed by researchers at the University of California, offers a lot of addresses on a network and provides high-profile addresses for all of them. It's a lightweight system of honeypots, of cloned honeypots. I don't believe it's open source at this point.

And what's the Honeywall for?

Holz: With Honeywall, you have a device to mitigate risk. If a cracker compromises your honeypot, you want to contain him within that honeynet. It's a kind of intrusion-prevention system that prevents outgoing attacks.

So does Google use a honeypot to watch for attacks?

Provos: I can't say anything about Google.

As you point out in your book, there may be legal reasons -- the legal concept of entrapment is sometime brought up -- that may discourage use of honeypots even for protective purposes.

Provos: We're not lawyers so we're suggesting you talk with your legal counsel if you want to use honeypots. But we'd like to see a top-notch lawyer really look at this area.

There don't seem to be a lot of commercial honeypot products and you don't hear people talk about honeypots much.

Provos: Many antivirus companies use honeypots. A lot of the time, people don't want to discuss something they've put out there to catch problems. Even if you don't plan to deploy a honeypot, in our book you'll get insights into botnets and insider attacks.

More about Wang, VMware, Google, IBM

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
Syndicate content
 
Whitepaper

The business justification for data security

In the information security world we face two major types of threats: "noisy" threats which directly interfere with our ability to do business and "quiet" threats which cause real damage, but don't necessarily prevent people from doing their jobs. Read on to discover how to combat both types of threats and to justify the use of data security within your business.

Sponsored Links