A honey pot simulates multiple platforms and services used to attract and contain attackers. To the attacker, it appears to be part of a production network providing services. A honey pot can be one or more hosts deployed within a DMZ or screened sub-net. Honey pots can be used for surveillance, as an early-warning tool, to discover security weaknesses, and to help assess threats. They also will tie up an attacker's resources as they burn time and effort. Honey pots should have no production value, and should not see any legitimate traffic or activity since the traffic is malicious or unauthorized traffic.
This requirement is specifically for the establishment of a honey pot. This is not the function of the firewall. |