Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Bait and Switch Honeypot System
by Violating Networks
Platforms: Linux, POSIX
Categories: Evasion, Intrusion Detection, Monitoring, Network Utilities
Version: v2.0b
URL: http://baitnswitch.sourceforge.net/
The Bait and Switch Honeypot System combines the snort Intrusion Detection System (IDS) with honeypot technology to create a system that reacts to hostile intrusion attempts by marking and then redirecting all "bad" traffic to a honeypot that partially mirrors your production system. Once switched, the would-be hacker is unknowingly attacking your honeypot instead of the real data, while your clients and/or users are still safely accessing the real system. Life goes on, your data is safe, and you get to learn about the bad guy as an added benefit.

Comments Mode:
Bait and Switch Honeypot System 2003-02-26
Anonymous (1 replies)
Bait and Switch Honeypot System 2003-10-03
Anonymous
How does this not ward off bad traffic and malformed traffic? It can do anything with the traffic that snort can do, and as far as actually blocking traffic through firewall modification - snortsam already does an excellent job of it.

[ reply ]







 

Privacy Statement
Copyright 2008, SecurityFocus