OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Cracked; rootkit - entrapment question?
From: Craig H. Rowland (crowlandPSIONIC.COM)
Date: Thu Mar 09 2000 - 19:24:45 CST


Hi Lamont

On Fri, 3 Mar 2000 lamonticopyright.com wrote:

> On Thu, 2 Mar 2000, Craig H. Rowland wrote:
> > If you are facing a serious compromise situation where an attacker has
> > gained full internal access, and you want to contain and analyze the
> > damage, you may wish to deploy a honey pot. For most cases though I think
> > running a honey pot on your external border is not a good idea.
>
> I've pretty much shared your opinion about honey pots, but one idea I've
> been toying with recently is deploying "canary" systems internally so that
> if someone smarter than me does get through the perimeter, if they hit the
> canary system it'll alert me. I'd probably use just a default redhat 6.0
> install (got enough root holes there to make it east), call it something
> tempting like "cybercash" and then modify sh/bash and csh/tcsh to e-mail a
> warning anytime they are run (and turn off cron jobs to eliminate the
> false positives).

I know several people who do this, but they generally make the systems
hard to crack and just put up a boatload of port monitoring
software/sniffers to detect the probes. It seems to be a little more sane
than leaving a vulnerable system hanging around.

I just get edgy when people want to coax another person into performing a
particular type of action. Unfortunately you just can't rule out the
attacker doing something to surprise you that falls outside of the planned
response that may have been established. Humans have a way of being
unpredictable at times (or lucky -- as the case may have it).

As I posted in a previous message and on my website, I think putting up
honey pots before doing other tangible security measures (filters,
patches, etc.) is just not a good plan of attack. Besides giving an
attacker a potential toe-hold onto your network, you provide the positive
feedback necessary to encourage them into looking further.

The one key item I've found that differentiates a successful attacker from
an unsuccessful one is time. The shorter amount of time you give an
attacker to look/poke/prod your network the less chance they have to find
success. Unfortunately, leaving a vulnerable system around affords an
attacker more time. Not a good thing -- IMHO.

-- Craig