Honeypots and Automation Adam Luck Copyright 2015, all rights reserved
Who am I? Adam Luck Senior Engineer - MicroSolved, Inc. Graduated from Ohio University
Why use Honeypots and Automation? “Set it and forget it” No reliance on signatures Everything alert is actionable
What can I discover? Insider Threats Uncategorized Malware 0-Day Exploits Phishing Campaigns
Prevention vs Detection Traditional methods are failing Redefined network perimeter “Un-hackable” systems and networks Often takes orgs months to discover attacks Still easy to hack a human
Low Interaction vs. High Interaction Do you just want to detect an attack? Are you more interested in learning about the attacker’s methods?
Honeypot Placement and Design Services Applications Critical network segments Internet exposure?
Example: DNS Sinkhole
Example: Retail POS
Example: M&A
Example: Automated Egress Log Review
More Information & Questions Email: aluck@microsolved.com Twitter: @AdamJLuck More information: stateofsecurity.com & microsolved.com Copyright MicroSolved, Inc. 2015, all rights reserved