| |
| | Know Your Enemy: Honeynets |
 | | Once a system is compromised, flhats will often require Internet connectivity, such as retrieving toolkits, setting up IRC connections, etc. We have to give them the flexibility to execute these actions, as these are the very steps we want to learn and analyze. |
 | | So, the trick is to give the flhat flexibility to execute whatever they need, but without allowing them to use the compromised system to attacks others, such as Denial of Service attacks, system scans, and exploits. |
 | | Blackhats are continually developing methods to avoid detection, such as anti-IDS techniques or encryption. |
| www.securitydocs.com /go/1979 (4697 words) |
|