| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
3.4.3 Honey Pots (Page 2 of 2) Honey Pot Projects Entire Internet projects such as Lance Spitzners Honeynet Project341 revolve around using honey pots to study black hats in their native habitat (out in what looks like the wild). For more information about the Honeynet Project, including recounts of some attacks staged against it and how the Honeynet team reacted to them, see Know Your Enemy342, by The Honeynet Project.
While most honey pots, including those at the Honeynet Project, have traditionally been UNIX-based, there are also tools for setting up honey pots on Windows systems, which even include servers such as the free-for-personal-use BackOfficer Friendly from NFR343) which simulate popular Trojan servers like BackOrifice, but log, instead of act on, their requests. Luring? Deliberately going out of your way to create a target to attract neer-do-wells? Whats our legal department going to say? The only answer we can give is: we dont know. Some have claimed that honey pots are a form of entrapment. Others have pointed out that entrapment can only be committed by law enforcement, so random net administrators and security researchers arent affected by that regulation. Additionally, if your honey pot is compromised, and the attacker does make off with information you wish he hadnt what do you do then? Does the fact that you set the honey pot up specifically for use by such individuals imply that they might have been (in some legally-defensible way) authorized users of that system and thus broke no privacy rules? Its tough to say, since were still in the early stages of legal precedents in this area. There are enough questions here that, before you set up a honey pot of your own, you would be wise to confer with your legal counsel to determine potential legal ramifications344. For more information on honey pots, check the paper by Lance Spitzner mentioned in the footnotes, as well as the http://www.honeynet.org site. __________________ 341. http://www.honeynet.org 342. The Honeynet Project, Know Your Enemy, Addison-Wesley, September, 2001, http://www.nerdbooks.com/item.html?id=0201746131 343. http://www.nfr.net/products/bof 344. Spitzner, Lance, Honeypots: Definitions and Value of Honeypots, http://www.enteract.com/~lspitz/honeypot.html
Home - Table Of Contents - Contact Us CertiGuide for Security+ (http://www.CertiGuide.com/secplus/) on CertiGuide.com Version 1.0 - Version Date: November 15, 2004 Adapted with permission from a work created by Tcat Houser et al. CertiGuide.com Version © Copyright 2004 Charles M. Kozierok. All Rights Reserved. Not responsible for any loss resulting from the use of this site. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||