Member Login

E-mail:    Password:  


Vendor : Georgia Institute of Technology


Email  E-mail this page

Related Content  Related Content

Remember  Remember this item

 

Format: PDF

Date: 14/06/2006


An Investigation of a Compromised Host on a Honeynet Being Used to Increase the Security of a Large Enterprise Network

WORTHWHILE?

0

0 votes


Overview

The growth of network intrusions on large enterprise networks continues to increase, creating an epidemic of compromised hosts. The deployment of firewalls and intrusion detection systems has not slowed the growth of intrusions to an acceptable rate. Investigating the compromise of a production machine is both difficult and time-consuming due to the mixing of attack and production traffic, while similar investigations of compromised machines on honeynets are much less complex since there is no real production traffic. This paper discusses why these investigations are easier on a honeynet and how honeynets may be used to make investigations of compromised production machines faster and recovery easier.