Honeypots are a well-known and widely used technology in the cybersecurity community, where it is assumed that placing honeypots in different geographical locations provides better visibility and increases effectiveness. However, how geolocation affects the usefulness of honeypots is not well-studied, especially for threat intelligence as early warning systems. This paper examines attack patterns in a large public dataset of geographically distributed honeypots by answering methodological questions and creating behavioural profiles of attackers. Results show that the location of honeypots helps identify attack patterns and build profiles for the attackers. We conclude that not all the intelligence collected from geographically distributed honeypots is equally valuable and that a good early warning system against resourceful attackers may be built with only two distributed honeypots and a production server.
翻译:蜜罐是网络安全社区中广为人知且广泛使用的技术,通常认为将蜜罐部署在不同地理位置能够提供更好的可见性并提升有效性。然而,地理位置如何影响蜜罐的效用(特别是作为早期预警系统的威胁情报功能)尚未得到充分研究。本文通过回答方法论问题并构建攻击者行为画像,对大型公开地理分布式蜜罐数据集中的攻击模式进行了分析。结果表明,蜜罐的位置有助于识别攻击模式并建立攻击者画像。我们得出结论:并非所有从地理分布式蜜罐收集的情报都具有同等价值,且仅需部署两个分布式蜜罐及一台生产服务器即可构建针对资源丰富型攻击者的有效早期预警系统。