High Interaction
High interaction client honeypots are fully functional systems comparable to real systems with real clients. As such, no functional limitations (besides the containment strategy) exist on high interaction client honeypots. Attacks on high interaction client honeypots are detected via inspection of the state of the system after a server has been interacted with. The detection of changes to the client honeypot may indicate the occurrence of an attack against that has exploited a vulnerability of the client. An example of such a change is the presence of a new or altered file.
High interaction client honeypots are very effective at detecting unknown attacks on clients. However, the tradeoff for this accuracy is a performance hit from the amount of system state that has to be monitored to make an attack assessment. Also, this detection mechanism is prone to various forms of evasion by the exploit. For example, an attack could delay the exploit from immediately triggering (time bombs) or could trigger upon a particular set of conditions or actions (logic bombs). Since no immediate, detectable state change occurred, the client honeypot is likely to incorrectly classify the server as safe even though it did successfully perform its attack on the client. Finally, if the client honeypots are running in virtual machines, then an exploit may try to detect the presence of the virtual environment and cease from triggering or behave differently.
Read more about this topic: Client Honeypot
Famous quotes containing the words high and/or interaction:
“The high wore away, the chromed skeleton corroding hourly, flesh growing solid, the drug-flesh replaced with the meat of his life. He couldnt think. He liked that very much, to be conscious and unable to think.”
—William Gibson (b. 1948)
“Our rural village life was a purifying, uplifting influence that fortified us against the later impacts of urbanization; Church and State, because they were separated and friendly, had spiritual and ethical standards that were mutually enriching; freedom and discipline, individualism and collectivity, nature and nurture in their interaction promised an ever stronger democracy. I have no illusions that those simpler, happier days can be resurrected.”
—Agnes E. Meyer (18871970)