HoneyC - The low-interaction client honeypot
Christian Seifert, Ian S. Welch, Peter Komisarczuk · UWL Repository (University of West London) · 2006
Abstract. Client honeypots crawl the Internet to find and identify servers that exploit client-side vulnerabilities. Traditionally, these servers are identified by the client honeypot monitoring state changes that result from a server interaction. These, so called high-interaction, client honeypots are slow and expensive to operate because they require an entire operating system to be hosted. We have developed a componentbased low-interaction client honeypot that emulates only the essential features of our target clients and that applies signature matching to allow fast static analysis of server responses. Performance measurements of a prototype implementation targeting clients using the HTTP 1.1 protocol indicate that low-interaction client honeypots are faster and cheaper than high-interaction client honeypots. The difference in false negatives suggests that these technologies may be complementary rather than competitive in nature.