Honeypot optimization based on CTF game

Ádám Balogh, Máté Érsok, László Erdődi, Anikó Szarvák, Eszter Kail, Anna Bánáti · 2022

Today’s complex and disguised cyber attacks can only be tackled with complex and centralised defence solutions. One possible solution for centralised defence is to implement a security operation centre (SOC) to support all the security tools and techniques available to the Blue Team (defence side). By extending the SOC with one or more honeypot systems, we can gain two additional advantages over adversaries: 1. we gain time to detect the attack and counter further threats; 2. we can collect data on adversaries’ methods and attack characteristics to develop additional AI-based defence techniques. In this paper, we are going to show the first aspect of the importance of honeypots, which goal we have reached by announcing a capture the flag (CTF) game at the Óbuda University. During the competition we have sought to answer the question of how much time can be saved for detection and defence using one or more honeypot with a few fake network services, and how to optimise our honeypot to achieve more efficient results.

Read the paper · More papers on PaperTik