Security Basics mailing list archives

Re: Honeypot Server


From: krymson () gmail com
Date: 17 Jan 2008 21:38:24 -0000

"Easy to admin, monitor, alert..." I apologize, but I would first question what your intended purpose for the honeypot 
would be. I get the feeling you want something more like a network tripwire that you don't have to look at. I would 
steer you towards an IDS solution like Snort or some other sort of deep inspection firewall or even just your firewall 
logs.

A honeypot, while fun and interesting, is still largely a measure for malware/hacker research as opposed to any real 
security measure. I know you didn't call it a security measure, but it sounds like you want a security measure...? A 
honeypot has very little value to most shops that are not providing actual research.


<- snip ->
Can you advise what is the best honeypot server available
Open-source or commercial - it doesn't matter as long as it will be easy to
administrate and easy to monitor and alerted ...


Current thread: