Honeypots and Honeynets
José Manuel Fernández Marín, J. A. M. Naranjo, L. G. Casado · Advances in digital crime, forensics, and cyber terrorism book series · 2014
This chapter presents a review and a case of study of honeypots and honeynets. First, some of the most important and widely used honeypots in the current market are selected for comparative analysis, evaluating their interaction capacity with an attacker. Second, a self-contained honeynet architecture is implemented with virtual machines. An intrusion test is performed against the honeynet to observe the quality and quantity of the information collected during the attack. The final goal of this analysis is to assess the capacity of monitoring and threat detection of the honeynets and honeypots.