Honeypots: A Sticky Legal Landscape?

Ian Walden, Anne Flanagan · Rutgers computer & technology law journal · 2003

I. INTRODUCTION With today's enhanced focus on cybersecurity, governments and businesses are looking for effective tools to prevent and detect attacks on their critical information systems. Effectiveness needs to be measured not only in terms of technological feasibility but also in terms of legality. One innovative technique is the use of so-called honeypots: vulnerable computer systems or networks designed to be attractive to hackers as target for intrusion. Honeypots can not only deflect the attention of hackers from an organization's system, but they can also provide investigators with the ability to gather detailed and contemporaneous forensic evidence about the hackers. An intruder into honeypot may be obtaining access simply as an intellectual challenge or in order to facilitate more serious criminal activities, such as the storage of child pornography or the launching of denial-of-service attacks against other systems. Whatever the ultimate purpose of the intrusion, under the laws of most industrialized nations, obtaining unauthorized access to the honeypot should itself be criminal offense. Concerns have been raised in technical literature and chat rooms, however, about the legal risks associated with the operation of honeypot. Uncertainty about the legality of honeypots may deter their use as tool in the fight against criminal and terrorist attacks against critical information systems. This Article examines two key areas of concern: entrapment and privacy. As with much technological development, there is need to apply existing legal rules to the innovative scenario to assess the legal risks involved in such activities. As is obvious from its moniker, honeypots are designed to attract visitors. By attracting potential criminal or terrorist, however, honeypot may be viewed as form of entrapment. (1) Such finding would render the use of honeypot as an evidential tool ineffective. Section II of this article reviews the doctrine of entrapment from comparative law perspective. The operation of honeypot also enables access to communications between hackers when carried out via the honeypot. (2) Such access raises questions concerning lawful interception or other privacy concerns. Section III examines the relevant privacy rules in the United States and the United Kingdom. Key problems when pursuing those engaged in criminal activities across the Internet are identifying the perpetrator and obtaining sufficient evidence to commence legal proceedings. Honeypots can be an effective tool in addressing these problems. The legal implications of such techniques, however, need to be considered during the design and implementation of the honeypot; section IV makes some recommendations for those considering using honeypot. II. WHAT IS A HONEYPOT? A honeypot or deception host is designated area within computer system or network that has been designed specifically with the expectation that it will be attacked by unauthorized users, whether internal or external to the organization operating the honeypot; it is a resource whose value is [in] being [sic] attacked or compromised. (3) A honeypot can be configured from hardware with weaknesses known to hackers or with software that emulates the hardware with weaknesses. In each case, the honeypot appears to be target that the hacker can easily break into, but its decoy status is not obvious. Honeypots can range from simple systems that emulate few of the services that would be provided on server to highly complex networks of honeypots. (4) The function of the honeypot can vary. It can serve as decoy to deflect the hacker from breaking into the real system, as research tool for systems administrators merely to observe and learn how hackers operate and about weaknesses in their systems, or as tool to monitor and document evidence for criminal prosecution. …

Read the paper · More papers on PaperTik