Reactive IDS with a honeypot
"Raffael Marty" <[email protected]>
| Newsgroups | gmane.comp.security.ids,gmane.comp.security.honeypots |
|---|---|
| Message-ID | <000701c25849$fbf130e0$428990d5@cygnus> |
[cross-posted on focus-ids and honeypots]
Assuming I have a honepot set up in my network. The honeypot only
consists of a machine answering TCP handshakes, maybe emulating certain
fake services. Nothing more. Further the assumption is that the honeypot
is not compromisable (this is not the focus of this post! Let's just
assume this).
Assume further that I have an IDS in my network and want to make it a
reactive one by having it set dynamic filters on the border firewall.
This I would do such that everyone who tries to connect to the honeypot
is blocked at the border firewall to the _entire_ network.
Maybe someone has experience with defining "everyone" in this context.
Probably it is not really wise to block everyone who tries to connect to
the honeypot. But where is the boundary of letting people in and
blocking them?
There are many more questions in this area which would be very
interesting to be discussed. Is there any (research-) information on
this topic?
Raffy
--
Raffael Marty
security.raffy.ch