A Review-Honeypots on Networks-

Ashutosh Chaudhary · International Journal of Emerging Trends in Engineering and Development · 2018

Cybersecurity is the need of an hour.One of the techniques to ensure this is a honeypot technique.A honeypot is a closely monitored computer resource that imitates activities of production host within a network in order to decoy the attackers.A honeypot is a trap set to detect, deflect or in some manner counteract attempts at illegal use of information systems.In this paper,a detailed analysis of production honeypots and research honeypots isspecified.The widecategorization of honeypots their ideal characteristics, advantages, anddisadvantages are further presented.It also presents the concept of intelligent honeypots. Introduction-A honeypot is a computing resource installed in the network in which it is meant to be searched, attacked or compromised by attackers.It is an information resource that is designed to be scanned, attacked andcompromised.By default, a honeypot should have no communication activities towards it.It is a resource that has no production charge.Any interactions spotted on a honeypot will be automatically considered as malicious.The value of a honeypot lies in it being probed, scanned, or compromised.The information taken by the honeypot will be used by network administrators to overcome the attacks be constructed in many forms, either in the form of physical machines, virtual machines (VMs), or emulated virtual hosts.A physical a honeypot is a real computing platform that has its own valid IP address.For example, a computer installed with Fedora Linux or Windows 7 with running network services like FTP, Telnet, or SMTP.A honeypot VM can be built by using virtualization software like VMWare Workstation, QemuKVM, VirtualBox, Parallels Desktop, or User Mode Linux.By using either of these tools, honeypot VM can be twisted with any type of operating system.This software is installed on a computing platform and users can generate single or multiple VMs running on the same host platform.[2], [4].A honeypot can also be built in the form of emulated virtual hosts.By using tools like Honeypot, we can emulate thousands of virtual hosts running different types of operating system on top of a single machine.Each of these virtual hosts is configured with a certain behaviour and personality which defines how the virtual host will respond to attackers' interactions.For example, a virtual host can be programmed to contain a Perl script that is emulating a Sendmail service.There are two types of honeypots: Low -interaction and Highinteraction honeypots.The use of the wordinteractionhere means the degree of interaction allowed between the honeypots and the attackers.The level of interaction defines how much damage an attacker can do towards a honeypot. Types of Honeypot-Types of Honeypots can be classified based on their purpose and level of interaction.We examine each type in more detail below.

Read the paper · More papers on PaperTik