S
S
SergioMaroni2017-03-20 11:02:30
Information Security
SergioMaroni, 2017-03-20 11:02:30

Does it make sense to put a Honeypot on a corporate network?

Good afternoon!
Interested in the opinion of experienced administrators, especially security guards. Does it make sense to set up a honeypot on a local corporate network? I myself think that there is a point, but I doubt it, I want to hear more opinions.
What I understand by Honeypot is the iron Wondows 7 / xp, without the necessary patches, if necessary, you can raise any servers (FTP, SMB, HTTP, etc.). On this machine, we start monitoring everything and everything (we look at the network - who connects from where, we look at processes, connected users, system logs, file access, etc.) In parallel, we set up a mirror of the port on which this machine sits and send all traffic either to IDS or just collect it with some kind of software. Further, if one of the triggers fires, we cut down our dummy machine and analyze the logs - we find the attacker, or at least find out that there are such and think what to do next.
Here are the benefits I see:
1) If an attacker somehow penetrated the network thanks to the Honeypot, we have a chance to detect him (due to the fact that we will see any access to our bait)
2) By installing such a bait, we do not reduce the security of our network. I proceed from the fact that the attacker is already in our network (somehow he got into it), we simply do not know about him. This bait is not available from the Internet, only on the local network, so it can only be accessed from the inside from any device on the local network.
3) This solution, as it were, complements the existing protection methods (Firewall, ids, antivirus, etc.)
If anyone knows anything similar from commercial or free systems, or someone has done something similar.

Answer the question

In order to leave comments, you need to log in

4 answer(s)
C
CityCat4, 2017-03-20
@CityCat4

Is there a person for this? Here, as with the NSR and classic video surveillance - if you want to get the most out of it - a separate person sits down, who only does what he looks at (TV / monitor / logs). A person needs a salary etc. If the return to the business covers the costs - why not?

S
Sergey, 2017-03-20
@edinorog

what's the point?) look... the enemy entered the internal network through the gateway. Did you sleep! he entrenched himself on one of the computers. you slept again! he started scanning your network. you are sleeping again! and then he suddenly chooses your bag of poop from hundreds of computers and you woke up?)

S
SergioMaroni, 2017-03-23
@SergioMaroni

In total, it turns out that you think that this decision does not make sense and a waste of time and effort, since the "exhaust" from it is negligible. Did I understand correctly?

M
morgan, 2017-03-23
@morgane

Quite a promising direction with the right approach.
Helps to detect stray Trojans, clients of botnet networks and security enthusiasts in the company.
Implemented on the basis of our own development, it helps to complement the essence of what is happening in the corporate network.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question