Honeypots
Virtual Honeypot

advisable to run HP on linux

can be restored to previous state fast and easily

attacker may detect being in a virtual machine

Client Honeypot

allows detection of malware in client applications

instead of passively waiting simulating human behaviour

other possible client applications to build a client honeypot upon besides web browser

2 kinds

High Interaction

convential computer systems

Attacker gains full Control over System

Complete Analysis of Attack possible

dynamic taint analysis

Physical Honeypot

Low Interaction

emulates services



Hybrid approach

Use lo interaction HP for known attacks

Shadow Honeypots