Snort mailing list archives

Re: VERY simple 'virtual' honeypot


From: "Marcus J. Ranum" <mjr () nfr com>
Date: Fri, 08 Mar 2002 09:37:17 -0500

Lance Spitzner wrote:
However, I was just thinking, why bother deploying the box?
Why not create a list of Snort rules that generate an alert
whenever a TCP/SYN packet or UDP packet is sent to an IP
address that has no system?  This could incidate a probe,
scan or attack, the same principles of a honeypot, but
without deploying an actual system.

For that matter, couldn't you _almost_ put something like that together
using filtering rules in a router?  Syslog 'em off the router and process 'em
on a backend system.

mjr.


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: