Ubiquitous virtual honeypots | |||||||||||||||||
A honeypot is a computer which is setup to be attacked. When it is attacked, it reveals useful information about the attacker. A hypervisor is a program which runs on a computer beneath the operating system, and allows multiple operating systems to run on the same computer at the same time. e.g. you can run Windows and Linux on the same single processor machine at the same time. The idea: is to use a hypervisor to run a honeypot on a normal computer at the same time as normal production software. Any ports unused by the production software are forwarded to the honeypot. Any change to the honeypot reveals a genuine attack and gathers evidence against the attacker, without risking the production system or requiring any additional hardware to be dedicated to security.
nihil, May 18 2005
What do you think of this idea or comment? | |||||||||||||||||
Users who liked this idea also liked: | ||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||
Add your comment