When an attacker breaks into your network, you have a home-field advantage. But how do you use it?
Intrusion Detection Honeypots is the foundational guide to building, deploying, and monitoring honeypots -- security resources whose value lies in being probed and attacked. These fake systems, services, and tokens lure attackers in, enticing them to interact. Unbeknownst to the attacker, those interactions generate logs that alert you to their presence and educate you about their tradecraft.
Intrusion Detection Honeypots teaches you how
Use the See-Think-Do framework to integrate honeypots into your network and lure attackers into your traps. Leverage honey services that mimic HTTP, SSH, and RDP. Hide honey tokens amongst legitimate documents, files, and folders. Entice attackers to use fake credentials that give them away. Create honey commands, honey tables, honey broadcasts, and other unique detection tools that leverage deception Monitor honeypots for interaction and investigate the logs they generate
With the techniques in this book, you can safely use honeypots inside your network to detect adversaries before they accomplish their goals.
This took me FAR longer to finish reading than I expected it to, after eagerly awaiting delivery of my pre-order.
And I FLEW through the first ~25% of the book, until Chris started to introduce problems in the material. What were these problems you ask? Trigger my inner geek and making me want to try a different t project with every topic discussed.
This DEFINITELY got my creative juices flowing. Despite me thinking I knew deception tech, having run honeypots for over a decade, and been up on stage many times evangelising the benefits I learnt lots, from Chris’ writings, have a backlog of projects I want to sink my teeth into, and suspect I’ll be keeping this time near by as a handy reference for some time to come.
Very Information and timely. This is a good book for beginners and veterans in information security. There is a good breakdown by topic and ease of implementation.