|
Honeypots
Moving forward with defintion of honeypots May 20 2003 03:23AM Lance Spitzner (lance honeynet org) (17 replies) Re: Moving forward with defintion of honeypots May 24 2003 04:47AM Bill McCarty (bmccarty apu edu) (1 replies) Re: Moving forward with defintion of honeypots May 24 2003 07:38PM Scarecrow (scarecrow runeweaver com) Honeypot Defintion - Almost There! May 23 2003 02:30PM Lance Spitzner (lance honeynet org) (6 replies) Re: Honeypot Defintion - Almost There! May 24 2003 02:29AM Erik S. Johansen (security sperling no) (1 replies) Re: Honeypot Defintion - Almost There! May 23 2003 03:58PM Jack McCarthy (lists jackmccarthy com) (1 replies) Re: Honeypot Defintion - Almost There! May 23 2003 03:05PM Marc Dacier (marc dacier eurecom fr) (2 replies) Re: Honeypot Defintion - Almost There! May 23 2003 02:48PM Volker Tanger (volker tanger discon de) (1 replies) Re: Honeypot Defintion - Almost There! May 23 2003 02:40PM Richard La Bella \(Florida Honeynet\) (richard sfhn org) Re: Moving forward with defintion of honeypots May 21 2003 06:36PM Chris Burton (cyberhiker99 yahoo com) RE: Moving forward with defintion of honeypots May 21 2003 08:37AM Fabien Pouget (Fabien Pouget eurecom fr) Re: Moving forward with defintion of honeypots May 21 2003 01:22AM Per Gustav Ousdal (pgo-ml ousdal com) Re: Moving forward with defintion of honeypots May 20 2003 09:37PM Graeme Thompson (gdthompson optushome com au) Re: Moving forward with defintion of honeypots May 20 2003 07:56PM David Goldsmith (dgoldsmith sans org) Re: Moving forward with defintion of honeypots May 20 2003 05:49PM Richard H. Cotterell (seec mail retina ar) Re: Moving forward with defintion of honeypots May 20 2003 05:06PM Jeremy Bennett (jeremy_f_bennett yahoo com) Re: Moving forward with defintion of honeypots May 20 2003 03:37PM Bernie, CTA (cta hcsin net) (1 replies) RE: Moving forward with defintion of honeypots May 21 2003 04:38AM John McCracken (john mccrackenassociates com) Re: Moving forward with defintion of honeypots May 20 2003 03:30PM Harish Pillay (harish maringotree com) Re: Moving forward with defintion of honeypots May 20 2003 02:36PM Richard La Bella \(Florida Honeynet\) (richard sfhn org) (1 replies) Re: Moving forward with defintion of honeypots May 20 2003 04:52PM Jeremy Bennett (jeremy_f_bennett yahoo com) Re: Moving forward with defintion of honeypots May 20 2003 02:24PM Christian Kreibich (christian whoop org) (1 replies) RE: Moving forward with defintion of honeypots May 20 2003 02:08PM John McCracken (john mccrackenassociates com) Re: Moving forward with defintion of honeypots May 20 2003 01:56PM Christian Kreibich (christian whoop org) Re: Moving forward with defintion of honeypots May 20 2003 01:46PM Etaoin Shrdlu (shrdlu deaddrop org) |
|
|
Privacy Statement |
> I'll be a little bit provocative ... no offense please,
> I'm trying to get things moving :-}
I hope you'll accept this response in the same spirit.
> For instance, suppose that I install a honeypot behind my
> firewall where it should -hopefully- see nothing. I don't
> want to use that honeypot to monitor anything but, instead,
> to be a simplistic intrusion detection system. My policy
> states that, as soon as a single packet reaches the honeypot,
> my network must be disconnected from the internet because
> something is wrong with the firewall (ok, it's a silly
> example and a rather stupid reaction but bare with me :-) ).
>
> Based on this "usage", is this "information system resource"
> a honeypot ? I would tend to say yes but your definition
> leads me to believe that you would say no.
If all you use the system for is a *tripwire*, I can only see
one value-add in calling it a "honeypot": You may need to get
funding approval from someone whose whole knowledge of honeypots
is that "they're the latest cool security technology". That's
a purely local problem, not something the rest of the
world has to cope with....
Based on your usage above, I'd say that the definition you're
really suggesting is something like
A honeypot is an information resource that incorporates
elements whose creators intended them to be used as part
of something called a "honeypot", regardless of how that
resource is actually used in any particular instance.
A functional definition can only really be based on one or both
of two criteria:
(a) what it does
(b) what we do with it
If you cut away those supports, then it just means what the speaker
chooses it to mean at any given moment.
David Gillett
[ reply ]