Attractive Hazard: Entrapment or Forensic Tool?

Ralph Spencer Poore · Information Systems Security · 2003

According to Lance Spitzner in his book Honeypots: Tracking Hackers!,1 a honeypot is “a security resource [whose] value lies in being probed, attacked or compromised.”2 Thus, whether for research or production,3 an organization uses a honeypot as an intentional exposure available for exploitation. To be effective, the honeypot must be visible and attractive. The use of a honeypot to catch a hacker raises several ethical issues (which may also prove to be legal challenges). In this column I discuss some of these issues and the design considerations to position your enterprise to defend the use of a honeypot. While both legal and ethical issues are discussed, I am not an attorney (and do not even play one on TV). Before acting on any legal matter, obtain the advice of an attorney of competent jurisdiction.

Read the paper · More papers on PaperTik