Leveraging Research Honeypots for Generating Credible Threat Intelligence and Advanced Threat Analytics
Praveen Pathak, Mayank Jaiswal, Mudit Kumar Gupta, Suraj Kumar Sharma, Ranjit Singhnayak · River Publishers eBooks · 2022
This chapter discusses in depth how SSH and HTTP honeypots can be set up using the open-source tools Cowrie (SSH) and Glastopf (HTTP) simulators. The authors provide insights into deployment journeys, building real-time analytics capabilities, and using advanced threat analytics to understand adversaries’ objectives and TTPs. The chapter also uncovers typical attacks faced by cloud deployments in Indian geography and illustrates attacker profiles generated from over 60 days of deployment in exposed environment.