Slashdot Mirror


User: Jonnie

Jonnie's activity in the archive.

Stories
0
Comments
1
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 1

  1. Deception Toolkit: check it out on Security-Why Not Watch The Crackers? · · Score: 1
    A flexible toolkit already exists for putting together honeypots and distributing honeypot-ish services through a cluster of servers. I use it and have had some success with it, and not just script kiddies wind up on the other side of the Fickle Finger of Fate. The bottom line is that a honeypot is part of an overall security strategy, not a replacement for good firewall policies and other access controls. Like any tool, they must be wielded competantly to avoid doing harm. That being said, I won't often recommend them to clients unless they have a pretty savvy staff.

    One other point is that honeypots are not 'lightening rods,' but are part of your last line of defense. Like Tripwire and other intrusion detection systems, they exist to let you know the game is going badly after your other countermeasures have failed. Certainly the majority of a security effort should be spend on making sure no one gets past security controls in the first place, but if they did you'd like to know abut it, wouldn't you?

    Hit http://all.net/dtk for the goodies.

    -- Jonnie