tencent cloud

Tencent Cloud Firewall

Creating a Honeypot Service

ダウンロード
フォーカスモード
フォントサイズ
最終更新日: 2026-09-04 08:57:49
AI翻訳
A Network Honeypot service can run normally only after it is associated with an exposure probe. After creating an exposure probe, you need to create a honeypot service associated with it.
1. Log in to the CFW console. In the left sidebar, click Network Honeypot > Honeypot Service.
2. On the Honeypot Service page, click Create honeypot.
3. In the Create Honeypot Service window, select the desired honeypot service type and click Next.
4. After configuring the honeypot parameters, click Next to configure probe forwarding to the honeypot.
Parameter
Description
Region
Supports all regions in China and cannot be changed after the instance is created.
Instance Name
Customize the instance name.
Honeypot service
Includes ELASTICSEARCH honeypot, MYSQL honeypot, NGINX honeypot, SALTSTACK honeypot, SSH honeypot, STRUTS honeypot, WEBLOGIC honeypot, and WEB honeypot. Except for the WEB honeypot, all other types of honeypots have built-in decoys and vulnerabilities.
Interaction Type
Actual service: a high-interaction type. The backend runs real services and decoys, and responds authentically to every attacker request, thereby fully deceiving attackers and buying time for real protection.
Simulated service: a medium-interaction type. The backend runs simulated services and decoys, which can generate corresponding responses based on some attacker requests and lure attackers into continuing, thereby buying time for real protection.
Bait
ELASTICSEARCH Honeypot: cve-2014-3120.
SALTSTACK Honeypot: cve-2020-11651.
SSH Honeypot: weak password.
STRUTS Honeypot: cve-2017-12611.
WEBLOGIC Honeypot: cve-2017-10271.
Other honeypots: None.
Custom bait
MYSQL Honeypot and SSH Honeypot: you can select a login credential and set a password.
WEB Honeypot: you can select existing SSH/MySQL honeypots as custom baits. If no SSH/MySQL honeypot is available, create one and bind it to a probe first.
Other honeypots: None.
Configure Probe
Select from existing probes: Select the desired probe instance and port number.
Configure later: no probe is bound.
5. Bind an exposure probe.
Select from existing probes: Select the desired probe instance and port number, and click OK.
No probe or do not set now: do not bind a probe and click OK.
Note:
A honeypot service takes effect only after it is bound to a probe. If you select "Do not set now", you can rebind the probe by editing the honeypot after creation, or bind the honeypot on the probe page.
6. You can enable honeypots individually or in batches.
Single: Select the target honeypot, click

in the switch column, and then click OK in the confirmation dialog to enable the honeypot service.
Batch: Select one or more honeypots, click Enable Honeypot, and then click OK in the confirmation dialog to enable the selected honeypot services.

ヘルプとサポート

この記事はお役に立ちましたか?

フィードバック