Core Concepts
A Network Honeypot is a simulated business system that runs on the internet and does not actually carry any real business traffic. Its core functions are:
Deployed in the user's network through probes, when a probe is triggered by an attacker, the system proactively records the attacker's information and traces the attack techniques.
It provides accurate attacker intelligence and countermeasure traceability capabilities for the defense of real business systems.
In guarantee for important periods, this buys enough time for real business systems to achieve a successful defense.
How It Works
Architecture Components
|
Honeypot service | Deployed in Tencent Cloud honeypot, it does not occupy user network space. Different VPCs are used to isolate honeypot services from each other, preventing lateral movement even if attackers gain access. |
Exposed probe | Deployed in the user's network as an IP address or domain name. It forwards traffic from specified ports/paths to different honeypot services, deploying "traps" in the business system. |
Workflow
1. Probes are exposed in the user's network in the form of IP addresses or domain names.
2. After detecting a probe, the attacker launches an attack.
3. Traffic is forwarded to the high-fidelity honeypot service in the honeypot farm.
4. The honeypot system records attacker information and attack techniques.
5. Provides intelligence support and traceability capabilities for the defense side.
Key Features
With a high degree of fidelity, it is not easily detected by attackers.
The security of a business system is directly proportional to the number of probes.
It does not consume excessive network resources of the user.
By using high-fidelity simulation services in the honeypot farm, it achieves the goal of deceiving attackers.
VPC-level isolation prevents attackers from moving laterally.
Usage Process
Alarms and Logs
Attack Deception Event Alarms
On the Alarm Center > Honeypot events page, you can view details of attack deception events detected by Network Honeypot. Network Honeypot Deception Logs
On the Log Auditing > Intrusion Defense logs > Honeypot page, you can view log information about attack deception events detected by Network Honeypot. Network Honeypot operation logs
On the Log Auditing > Operation logs > Network Honeypot page, you can view operation details and the associated accounts for the Network Honeypot feature. Version Support Notes
The CFW Premium, Enterprise, and Ultimate editions all support purchasing honeypot service quotas. For details, see Purchase Method.