home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers



  C O L U M N 

Honeypots: Security Means Sticky Business

April 3, 2000
By: Mike Fratto


Imagine Winnie the Pooh struggling to free his big paw from a honey jar. Poor Pooh, very distressed, tries to free himself, but not before Christopher Robbins, Eyore or Piglet catches him in the act. Well, honeypots, in terms of network security, are not much different.

A honeypot is a network server designed to trap would-be attackers before they invade your real servers and services. Take a linux or Unix workstation, create an environment where you can fool attackers into thinking they have root access when they really don't, and monitor their every move. If the honeypot gets trashed, so what. Better that than your servers, right?

Now I may catch hell for saying this, but installing a honeypot should be close to the bottom of your list of network security priorities. Let's face it. You have better things to do with your time. You must maintain your firewall, monitor your IDS (Intrusion Detection System), recover lost passwords, keep track of the latest security patches and schedule the updates. Why tackle these chores, when you have a hundred other tasks that directly effect your network's security?

In fact, honeypots don't add to security in any fundamental way; they complicate it. Now you have one, or more, servers that must be doubly secured. That is because a honeypot needs to be secured with one or two well-placed holes so attackers can get in. The host server also must be secured and constantly monitored, so intruders can't break out of the honeypot.

Even if you could jump through all of these hoops, your first and foremost goal in network security should be to only allow authorized users access to network resources. All others should be denied access. This is an example of the "default deny security" stance: All that is not allowed is denied. The implication of this is that you have to actively allow access to users and violations should be clearly visible. Yet honeypots violate that stance by inviting unknown attackers to access one of your systems. Once an attacker has access to even one system, they are one step closer to your network. Remember, it isn't the known attacks that will put your network in the hands of an intruder.

Now, as network folk are prone to do, let me equivocate and say that while honeypots should be near the bottom of your priority list there's really only one good reason to have one and that's to prosecute crackers. But beware that the law is very unclear about the use of honeypots for legal prosecution and you'll need to check with your lawyer and local FBI about their uses. Education, distraction and obscurity are not good reasons for a honeypot, --because you can learn more at Packet Storm (an online security site), crackers will leave an uninteresting server, and there isn't much you can hide from a knowledgeable cracker.

Send your comments on this column to Mike Fratto at mfratto@nwc.com.



 





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Aneesh Chopra is looking to other CIOs to advise him on fleshing out a more detailed agenda to best serve the president's IT agenda.

IT spending is expected to decline by 3.8 percent in 2009 according to Gartner.










2009 IT Salary Survey: Meager Raises, Solid Prospects
Though raises are notably smaller than a year ago, and job security’s shrinking, IT careers are looking safer than many others in this economic downturn. Get all the findings in InformationWeek's 2009 IT Salary Survey. Available FREE for a limited time.
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



Techweb
Informationweek Business Technology Network
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
space
TechWeb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
space
Light Reading Communications Network
Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service