Research and Design about Honeynet Based on Two-level Redirect Mechanism

Fengbin Zhang · Computer Technology and Development · 2009

There are two defects in the current honeynet deployment.Firstly,if the hackers know of the existence of honeynet,thus bypassing it to attack non-honeynet host,so there will be no value;secondly,if hackers use compromised honeypot to attack the non-honeynet host,now popular way is taking network gateway simply to restrict connect on the number,there are two fatal weaknesses:(1) outside connections probably cause harm and honeypot maybe be mistaken for attackers;(2) hackers know that they were restricted from outside connections,then the honeynet could be exposed,are more likely to use error messages to confuse honeynet deployer.Therefore recommand two-level redirect mechanisms can make up for deficiencies.First-layer redirect mechanism by setting up non-honeynet host to redirect attack stream to honeynet,the second-layer mechanism redirect attack stream from a honeypot to another honeypot.

Read the paper · More papers on PaperTik