Honeypots mailing list archives

Re: Need your helping defining honeypots


From: "Todd A. Jacobs" <nospam () codegnome org>
Date: Sun, 18 May 2003 00:12:50 -0700 (PDT)

On Fri, 16 May 2003, Lance Spitzner wrote:

Option 1:
---------
A honeypot is a security resource who's value lies in being
probed, attacked, or compromised.

I like this one best, because it describes what the honeypot is for rather
than discussing the status of the people connecting to it. For example,
one might set up a honeypot and then invite specific individuals to attack
it. Those individuals are not "unauthorized" in any sense except that they
do not have privelege on the target system.

I'd probably also add that a *good* honeypot is both disposable and easily
restored. That's not central to the definition, of course, but a honeypot 
that's labor-intensive to reconstruct after each attack is unlikely to be 
very useful in the long run.

-- 
The DMCA is anti-consumer. The RIAA has no right to rewrite copyright
laws to suit themselves.


Current thread: