Lessons Learned from the deployment of a high-interaction honeypot
Eric Alata (LAAS), Vincent Nicomette (LAAS), Mohamed Ka\^aniche, (LAAS), Marc Dacier (LAAS), Matthieu Herrb (LAAS)

TL;DR
This paper reports on a six-month experimental study of attacker behavior using a high-interaction honeypot, comparing findings with a global network of low-interaction honeypots to derive practical security insights.
Contribution
It provides new insights into attacker behavior through a long-term deployment of a high-interaction honeypot and compares it with low-interaction honeypots worldwide.
Findings
Attacker behaviors vary significantly over time.
High-interaction honeypots reveal detailed attack techniques.
Comparison highlights differences between high- and low-interaction honeypots.
Abstract
This paper presents an experimental study and the lessons learned from the observation of the attackers when logged on a compromised machine. The results are based on a six months period during which a controlled experiment has been run with a high interaction honeypot. We correlate our findings with those obtained with a worldwide distributed system of lowinteraction honeypots.
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Security and Verification in Computing · Software System Performance and Reliability
