From Honeypots to Distributed Deception Platforms: theory and testing of emerging technologies for IT security.

Vincenzo Viola · 2019

The following thesis presents a research on the evolution of the deceptive technologies adopted in cyber-defense. In the first section honeypots are analysed in deep, evaluating their strengths and weaknesses and providing also some peculiar use-cases. The second part of the thesis focuses on the Distributed Deception Platforms (DDP), a brand-new paradigm which has the purpose to overcome honeypot limits and to allow an easier deployment of deceptive tools over the network. Some of the most important distributed deception platforms present on the market are tested along with open-source solutions, and compared with traditional honeypot implementation: the test involves the simulation of an Advanced Persistent Threat (APT) to be used against the platforms under analysis in order to evaluate their efficacy, the depth of information that is possible to retrieve from an attacking pattern and the ease of deployment and management of the adopted solutions.

Read the paper · More papers on PaperTik