|
|||||||||||
|
RES: Honeytokens and Detection
From: Augusto Quadros Paes de Barros <augusto(at)paesdebarros.com.br>
Date: Fri Jul 18 2003 - 09:50:45 EDT Lance, I'm glad to see that there is still interest on this subject. I'm trying to find other uses for it too, and I already elected some of my favourites:
I believe that the most important thing about honeytokens is to make the people responsible for Intrusion Detection aware of it and how it works. As they know the systems and procedures of the company where they work, they are the best people to define what can be a honeytoken and where it should be placed. Incident history and lessons learned can be a good place to start a planning of honeytokens deployment. Regards, Augusto Paes de Barros, CISSP.
-----Mensagem original-----
Honeytokens: The Other Honeypot
I would love any input, ideas, or suggestions on this relatively new tool. Thanks! -- Lance Spitzner http://www.tracking-hackers.com ------------------------------------------------------------------------------- Is your IDS deployed correctly? Find out by easily testing it with real-world attacks from CORE IMPACT. Go to www.coresecurity.com/promos/sf_eids1 to learn more. ------------------------------------------------------------------------------- Augusto Quadros Paes de Barros, CISSP http://www.paesdebarros.com.br ------------------------------------------------------------------------------- Is your IDS deployed correctly? Find out by easily testing it with real-world attacks from CORE IMPACT. Go to www.coresecurity.com/promos/sf_eids1 to learn more. -------------------------------------------------------------------------------Received on Fri Jul 18 20:02:36 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:16 EDT |
||||||||||
|
|||||||||||