The analysis of dynamic honeypot and its design

Zhitang Li,Xiaodan Xu
DOI: https://doi.org/10.3321/j.issn:1671-4512.2005.02.028
2005-01-01
Abstract:Aiming at the deployment and maintenance of honeypot, an idea of dynamic honeypot was proposed and analyzed. The dynamic honeypot is a kind of plug and play system by using passive fingerprinting and virtual honeypots. The dynamic honeypot can monitor and self-study real-time network environment, retrieves information and automatically determine how many honeypots to deploy and how to deploy them. The passive fingerprinting is based on the principle that every operating system's IP stack has its own idiosyncrasies and determines the type operating system by capturing, analyzing packets in the network. By using the virtual honeypots technology multiple honeypots can be deployed on a single physical device. Combined these two kinds of technology, a model of dynamic, honeypot was designed. The deficiency of this model was also analyzed. The results of research show that dynamic honeypot can radically revolutionize the deployment and maintenance of honeypots.
What problem does this paper attempt to address?