Client Honeypot - High Interaction

High Interaction

High interaction client honeypots are fully functional systems comparable to real systems with real clients. As such, no functional limitations (besides the containment strategy) exist on high interaction client honeypots. Attacks on high interaction client honeypots are detected via inspection of the state of the system after a server has been interacted with. The detection of changes to the client honeypot may indicate the occurrence of an attack against that has exploited a vulnerability of the client. An example of such a change is the presence of a new or altered file.

High interaction client honeypots are very effective at detecting unknown attacks on clients. However, the tradeoff for this accuracy is a performance hit from the amount of system state that has to be monitored to make an attack assessment. Also, this detection mechanism is prone to various forms of evasion by the exploit. For example, an attack could delay the exploit from immediately triggering (time bombs) or could trigger upon a particular set of conditions or actions (logic bombs). Since no immediate, detectable state change occurred, the client honeypot is likely to incorrectly classify the server as safe even though it did successfully perform its attack on the client. Finally, if the client honeypots are running in virtual machines, then an exploit may try to detect the presence of the virtual environment and cease from triggering or behave differently.

Read more about this topic:  Client Honeypot

Famous quotes containing the words high and/or interaction:

    For thou, O Spring! canst renovate
    All that high God did first create.
    Be still his arm and architect,
    Rebuild the ruin, mend defect.
    Ralph Waldo Emerson (1803–1882)

    Just because multiples can turn to each other for companionship, and at times for comfort, don’t be fooled into thinking you’re not still vital to them. Don’t let or make multiples be parents as well as siblings to each other. . . . Parent interaction with infants and young children has everything to do with how those children develop on every level, including how they develop their identities.
    Pamela Patrick Novotny (20th century)