OPSEC for honeypots
xiphosresearch.com
OPSEC for honeypots
1–9 of 9 posts
Re: OPSEC for honeypots
#2My Friday brain is steering me very much toward the latter, I must confess.
Re: OPSEC for honeypots
#3Re: OPSEC for honeypots
#4I know security by obscurity doesn't work in the real world, but what if some of those honeypots are actual ICS systems made to look like a poorly configured honeypot? One could host a mock service (representing a poorly configured ICS) on the cloud that acts as a wall to turn away those who don't dig deeper, but the required services are redirected to a legitimate ICS on the ground.
Re: OPSEC for honeypots
#5I know security by obscurity doesn't work in the real world, but what if some of those honeypots are actual ICS systems made to look like a poorly configured honeypot? One could host a mock service (representing a poorly configured ICS) on the cloud that acts as a wall to turn away those who don't dig deeper, but the required services are redirected to a legitimate ICS on the ground.
In this case, I think the engineering effort required to proxy a real one to make it look like a poorly-configured honeypot would be greater than actually implementing some proper security measures, like a firewall plus a VPN for any needed external access.
Re: OPSEC for honeypots
#6I know security by obscurity doesn't work in the real world, but what if some of those honeypots are actual ICS systems made to look like a poorly configured honeypot? One could host a mock service (representing a poorly configured ICS) on the cloud that acts as a wall to turn away those who don't dig deeper, but the required services are redirected to a legitimate ICS on the ground.
In this case, I think the engineering effort required to proxy a real one to make it look like a poorly-configured honeypot would be greater than actually implementing some proper security measures, like a firewall plus a VPN for any needed external access.
Re: OPSEC for honeypots
#7Re: OPSEC for honeypots
#8I know security by obscurity doesn't work in the real world, but what if some of those honeypots are actual ICS systems made to look like a poorly configured honeypot? One could host a mock service (representing a poorly configured ICS) on the cloud that acts as a wall to turn away those who don't dig deeper, but the required services are redirected to a legitimate ICS on the ground.
In this case, I think the engineering effort required to proxy a real one to make it look like a poorly-configured honeypot would be greater than actually implementing some proper security measures, like a firewall plus a VPN for any needed external access.
It better for everyone if honeypots and normal systems looks as similar as possible.
Re: OPSEC for honeypots
#9Earlier quoted context omitted.
In this case, I think the engineering effort required to proxy a real one to make it look like a poorly-configured honeypot would be greater than actually implementing some proper security measures, like a firewall plus a VPN for any needed external access.
I had the same thought as GP as well. Could you not implement some of the "disguise-as-honeypot" features (such as setting the name to "HoneyTrap" or "Error: rand...") in addition to the normal security features?