An Open-Source Honeynet System to Study System Banner Message Effects on Hackers
Mark I. Stockman, Robert Heile, Anthony Rein · 2015
A honeynet system deploys a series of honeypots to answer vital questions about the activities of hackers on a network and can be used as a platform for direct experimentation to test criminological theory in an online environment. Often however, such systems can be hard to set up, generate large amounts of unfiltered data, and must be carefully monitored to prevent their being used as a platform for further attacks. This paper discusses the development of a honeynet system that computing professionals and researchers can set up, scale, and use with relative ease. The system monitors intruders' activities on individual honeypots then aggregates their movements into a single database, making the data easily accessible and searchable for study through a graphical front-end. To test this open-source solution, the authors replicate a portion of a seminal criminological study by Maimon et al. [4] finding corroborating evidence that system warning banner messages can produce significant effects limiting hackers' time spent on compromised computer systems.