Ermittlung von Verwundbarkeiten mit elektronischen Koedern
Maximillian Dornseif, Felix C. Gaertner, Thorsten Holz

TL;DR
This paper introduces electronic bait (honeypots and honeynets) as a method for studying attacker behavior in networks, highlighting setup, forensic analysis capabilities, and initial deployment experiences at RWTH Aachen University.
Contribution
It presents the concept, setup, and initial experiences of deploying honeynet networks for enhanced forensic analysis of network attacks.
Findings
Honeynets facilitate detailed attacker behavior analysis.
Deployment at RWTH Aachen provided valuable insights.
Honeypots improve forensic data collection.
Abstract
Electronic bait (honeypots) are network resources whose value consists of being attacked and compromised. These are often computers which do not have a task in the network, but are otherwise indestinguishable from regular computers. Such bait systems could be interconnected (honeynets). These honeynets are equipped with special software, facilitating forensic anylisis of incidents. Taking average of the wide variety of recorded data it is possible to learn considerable more about the behaviour of attackers in networks than with traditional methods. This article is an introduction into electronic bait and a description of the setup and first experiences of such a network deployed at RWTH Aachen University. ----- Als elektronische Koeder (honeypots) bezeichnet man Netzwerkressourcen, deren Wert darin besteht, angegriffen und kompromittiert zu werden. Oft sind dies Computer, die keine…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsDigital and Cyber Forensics · Advanced Malware Detection Techniques · Internet Traffic Analysis and Secure E-voting
