Back to list
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Re: DNS honeypots?
Mar 03 2010 02:20PM
Brent Huston (lbhlists gmail com)
One of the tactics our clients use is that they stand up one of our HoneyPoint Agents on a decoy box and then send all malicious and failed queries to that IP address. The HoneyPoint Agent then absorbs the traffic for analysis.
You can find a little bit about it from one of our customers here, they...
[ more ]
Copyright 2010, SecurityFocus