Experiences with honey-patching in active cyber security education
Frederico Araujo, Mohammad Shapouri, Sonakshi Pandey, Kevin W. Hamlen · 2015
Modern cyber security educational programs that empha-size technical skills often omit or struggle to effectively teach the increasingly important science of cyber decep-tion. A strategy for effectively communicating deceptive technical skills by leveraging the new paradigm of honey-patching is discussed and evaluated. Honey-patches mis-lead attackers into believing that failed attacks against software systems were successful. This facilitates a new form of penetration testing and capture-the-flag style ex-ercise in which students must uncover and outwit the deception in order to successfully bypass the defense. Ex-periences creating and running the first educational lab to employ this new technique are discussed, and educational outcomes are examined. 1