Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Honeypots
Moving forward with defintion of honeypots May 20 2003 03:23AM
Lance Spitzner (lance honeynet org) (17 replies)
Re: Moving forward with defintion of honeypots May 24 2003 04:47AM
Bill McCarty (bmccarty apu edu) (1 replies)
Re: Moving forward with defintion of honeypots May 24 2003 07:38PM
Scarecrow (scarecrow runeweaver com)
Honeypot Defintion - Almost There! May 23 2003 02:30PM
Lance Spitzner (lance honeynet org) (6 replies)
Re: Honeypot Defintion - Almost There! May 24 2003 02:29AM
Erik S. Johansen (security sperling no) (1 replies)
Re: Honeypot Defintion - Almost There! May 25 2003 12:27AM
Jon Price (jon nytimes com)
Re: Honeypot Defintion - Almost There! May 23 2003 03:58PM
Jack McCarthy (lists jackmccarthy com) (1 replies)
Re: Honeypot Defintion - Almost There! May 23 2003 05:24PM
Valdis Kletnieks vt edu
Re: Honeypot Defintion - Almost There! May 23 2003 03:37PM
Steve Barnet (barnet chem wisc edu)
Re: Honeypot Defintion - Almost There! May 23 2003 03:05PM
Marc Dacier (marc dacier eurecom fr) (2 replies)
RE: Honeypot Defintion - Almost There! May 23 2003 04:07PM
David Gillett (gillettdavid fhda edu)
Re: Honeypot Defintion - Almost There! May 23 2003 03:35PM
Valdis Kletnieks vt edu
Re: Honeypot Defintion - Almost There! May 23 2003 02:48PM
Volker Tanger (volker tanger discon de) (1 replies)
Re: Honeypot Defintion - Almost There! May 23 2003 03:28PM
Tora (tagetora users sourceforge net)
Re: Honeypot Defintion - Almost There! May 23 2003 02:40PM
Richard La Bella \(Florida Honeynet\) (richard sfhn org)
Re: Moving forward with defintion of honeypots May 21 2003 06:36PM
Chris Burton (cyberhiker99 yahoo com)
RE: Moving forward with defintion of honeypots May 21 2003 08:37AM
Fabien Pouget (Fabien Pouget eurecom fr)
Re: Moving forward with defintion of honeypots May 21 2003 01:22AM
Per Gustav Ousdal (pgo-ml ousdal com)
On Tuesday 20 May 2003 05:23, Lance Spitzner wrote:
> In the past week we have received over thirty postings
> about the definition of honeypots, each posting suggesting
> a different defintion. I think we are all beginning to
> realize just how tough it is to define this technology.
> Honeypots are an extremely powerful tool that can
> accomplish many different things. Some trends I've noticed.
>
> First, many people are including the term 'decoy' in the
> definition. While honeypots can 'decoy', I don't think
> that should be in the definition. The term decoy implies
> "to lure or entrap". Often honeypots don't lure. You just
> put them out there and the bad guys find them on their own
> intiative, nothing special is done to insare the attacker.
> The Honeynet Project has being doing this for years now.

Well, I disagree with this point. Although my mother tounge is not English, I
still hope I am entitled to an opinion. I've always felt that honeypot is a
bad name for these things, (unless they actually DO implement luring or
entraping technics). And the point your making suggests that also. In my
world a honeypot is pretty much bait (specialized bait for bees, ants and
other animals who likes honey).

This fits pretty good with the lawenforcment senario (i.e. fake warz site):
Warz dudes "feeds" on warz, right? ;) Although, even the lawenforcement use
fits nicely in under the term decoy as well.

A decoy *can* be combined with luring technics, (but often at the price of
raising suspicion if faced with an intelligent and calculating enemy, and
especially if you over do it). Placing one of those plastic ducks on a lake
is hardly luring, (once you start making quack, quack noises it's a different
story) but it is a decoy. Placing an empty tent camp in the woods is a decoy.
A decoy is something that appears to be something, but it's not (i.e Company
HQ/empty tents, legimate production system/"honeypot" system). And it is a
decoy regardless of wether you lure the enemy to it or not.

I feel your use of decoy fits more with what I would call a trap (or atleast
part of a trap). A trap to me is getting (luring) the enemy to where you want
them to be. (Waiting at the enemy at terrain that gives you an advantage is
also a trap).

I rather liked the definition which included decoy. In fact in many situations
I envision myself using this definition: "A honeypot is a decoy". Or, if it
was not clear from the context; "A honeypot is a computer resource that
functions as a decoy". If it still was not clear I would analyse the
situation, and adopt it to context: "A honeypot is a computer resource that
functions as a decoy, we will use it to.../or it may be used for.... etc"

IMHO: decoy would be a much more appropriate name than honeypot.

> Second, many people are including in the definition how
> honeypots are used to learn or research. Once again, while
> honeypots can do this, they can do so much more. They
> can be used for preventing attacks (such as LaBrea Tarpit)
> or be used purely for detection similar to an IDS
> system (such as Honeyd). We have to be very careful
> in our defintion to ensure we do not imply why we would
> want to use a honeypot.

Just like a decoys may be used for numerous things:
- draw/(waste) enemy fire
- slow the enemy down
- give them false impresion on our numbers
- trap/ambush
etc, etc

Regards,

Per

[ reply ]
Re: Moving forward with defintion of honeypots May 20 2003 09:37PM
Graeme Thompson (gdthompson optushome com au)
Re: Moving forward with defintion of honeypots May 20 2003 07:56PM
David Goldsmith (dgoldsmith sans org)
Re: Moving forward with defintion of honeypots May 20 2003 05:49PM
Richard H. Cotterell (seec mail retina ar)
Re: Moving forward with defintion of honeypots May 20 2003 05:06PM
Jeremy Bennett (jeremy_f_bennett yahoo com)
Re: Moving forward with defintion of honeypots May 20 2003 03:37PM
Bernie, CTA (cta hcsin net) (1 replies)
RE: Moving forward with defintion of honeypots May 21 2003 04:38AM
John McCracken (john mccrackenassociates com)
Re: Moving forward with defintion of honeypots May 20 2003 03:30PM
Harish Pillay (harish maringotree com)
RE: Moving forward with defintion of honeypots May 20 2003 02:46PM
Rick Hayes (rhayes vicor com)
Re: Moving forward with defintion of honeypots May 20 2003 02:36PM
Richard La Bella \(Florida Honeynet\) (richard sfhn org) (1 replies)
Re: Moving forward with defintion of honeypots May 20 2003 04:52PM
Jeremy Bennett (jeremy_f_bennett yahoo com)
Re: Moving forward with defintion of honeypots May 20 2003 02:24PM
Christian Kreibich (christian whoop org) (1 replies)
Re: Moving forward with defintion of honeypots May 21 2003 07:13AM
Perraju (perrajukv ideasp com)
RE: Moving forward with defintion of honeypots May 20 2003 02:08PM
John McCracken (john mccrackenassociates com)
Re: Moving forward with defintion of honeypots May 20 2003 01:56PM
Christian Kreibich (christian whoop org)
Re: Moving forward with defintion of honeypots May 20 2003 01:46PM
Etaoin Shrdlu (shrdlu deaddrop org)







 

Privacy Statement
Copyright 2009, SecurityFocus