Honeypots mailing list archives

Re: Honeypots: Uses and Features


From: adam <eggroid () hotpop com>
Date: Mon, 02 Jun 2003 20:49:36 -0400

Lance Spitzner wrote:

One of the things that defining honeypots demonstrated for
us was that honeypots come in MANY shapes and sizes, they
can accomplish many different goals.  This got me wondering,
what are individuals and organizations using honeypots
for, what features or capabilities do you consider the
most important?

If you have a moment, post what capabilities you feel
are the most important, and why. My intent here is not only can we share ideas, but this discussion can
potentially help the development of honeypots in general.


Thoughts?

While I recognize the value of spotting a new attack or exploit, I have not yet had the privilege of doing so. Identifying new automated attacks has been very interesting, but not terribly useful yet. Occasionally I am able to gather enough information to add a new rule to the IDS. But as an information security analyst for a Fortune 100 company, being able to show upper management exactly what we're getting hit with, and the frequency at which it occurs has been absolutely priceless.


Current thread: