|
Security Boot Camp Series Day 9 |
|
|
Thursday, 31 December 2009 10:14 |
Day 9: Set up a honeypot
YOUR ASSIGNMENT TODAY
Set up a honeypot.
WHY DO IT
It's one of the best ways to get early warning of internal attackers on your network.
HOW TO DO IT
Keep the project secret. Then, take a few computers that are destined for de-provisioning or the scrap heap and turn them into your honeypots. Without a doubt, my favorite honeypot software program is KFSensor. No other honeypot software is as easy to use and feature rich. Be sure to block all connections from the honeypot to destinations outside your network to prevent illegitimate use of a compromised asset against an innocent third party.
RECOMMENDED READING
"Honeypots: A sweet solution to the insider threat," Infoworld.com
A honeypot can be a cheap, easy, and effective warning system against the trusted insider gone bad.
|
|
Last Updated on Thursday, 31 December 2009 10:23 |