TL;DR
A honeynet is a deliberately constructed decoy network designed to attract and study hackers in a controlled environment. By monitoring attacker behavior inside a realistic-looking system, security teams can uncover vulnerabilities before real damage occurs. Organizations like the Honeynet Project have formalized this research approach, sharing findings and tools with the broader security community.
How do honeynets work?
Honeynets are designed to look, feel, and act just like a network packed tight with valuable resources. But they also contain plenty of monitoring tools. Lure in a hacker, and you can study how that person moves through your system and tries to steal what is yours. Those results can help you beef up your security setup.
A honeynet can be a standalone network, or you can create a so-called virtual honeynet. Here, you'll create something that appears to be an entire network. In reality, it resides on a single server. Building a realistic trap for a hacker isn't easy. Honeynets rely on a series of elements, all working together seamlessly.
Honeynets contain:
- Honey pots. These computer systems are set up to trap hackers. Sometimes, they're used for research purposes. And sometimes, they're decoys that lure hackers away from valuable resources. When plenty of pots come together, a net is formed.
- Applications and services. Hackers must be convinced that they've entered a valid, worthwhile environment.
- No authorized activity or users. A true honeynet has no use aside from trapping hackers.
- Honeywalls. You must be able to study and learn from the honeynet attack. The system should keep accurate records of traffic moving into and out of the honeypot.
A lure entices your hacker to enter one of your honey pots. Once there, the hacker attempts to gain deeper access to your system. At that point, the attack has moved into your honeynet, and the research can begin.
What are honeynets used for?
Most security professionals spend every minute of the workday trying to keep hackers out. Why would they want to bring them in? The data you pull from a honeypot can be crucial.
Imagine that you believe you've built the strongest, safest network for your company. You've told everyone the system can't be breached. But are you really sure? What vulnerabilities are you leaving behind? And if someone got inside, what would happen next?
Honeynets help you answer questions just like this. You'll watch a hacker move through a mirror image of your system, and you'll see just where you went wrong. You can fix your mistakes long before your company loses anything valuable.
Why use a honeynet instead of a simple honeypot?
You could use simple honey pots for research. But hackers expect to find more than one machine when they breach a company's infrastructure. Building a honeynet allows the deception to last longer, and that could result in more data.
How does the Honeynet Project advance security research?
Individual system administrators aren't the only professionals interested in hacker techniques. Governments, educators, and law enforcement officials also want to know how to stop theft and build a safer online world. The Honeynet Project may help.
What is the Honeynet Project?
Started in 1999, the Honeynet Project exists to research hackers via honeypots and honeynets. Volunteers within the group use normal computers set up as bait, and they monitor activity closely to spot attacks.
The Honeynet Project's mission is to, "Learn the tools, tactics, and motives involved in computer and network attacks, and share the lessons learned." The team follows three basic pillars in their work.
- Conduct research. Volunteers build networks and try out security tools for blocking purposes. They gather up information on how hackers work and what software tools they use.
- Build awareness. The team shares the results of all research, so the security community can understand current threats and prevention approaches.
- Create tools. If organizations want to build their own honeynets and honey pots, the team offers information about the tools and techniques they've developed.
Anyone interested in finding out more about how hacks work and what the current threat landscape looks like should follow the Honeynet Project closely.
If you're interested in testing your security approach, but you're not ready to commit to creating a honeynet, consider penetration testing. We've written up a blog post about what this involves and how it works. We invite you to check it out!
Frequently asked questions
What is the difference between a honeypot and a honeynet?
A honeypot is a single computer system set up to trap hackers, while a honeynet is a network made up of multiple honeypots. Because hackers expect to find more than one machine when they breach a company's infrastructure, a honeynet sustains the deception longer and can yield more research data than a single honeypot alone.
What is a virtual honeynet?
A virtual honeynet is a type of honeynet that simulates an entire network but resides on a single server. It creates the appearance of a full network environment without requiring dedicated hardware for each component.
What are honeywalls and why are they important?
Honeywalls are the monitoring layer within a honeynet that keep accurate records of traffic moving into and out of the honeypot. They are important because they allow security professionals to study and learn from honeynet attacks, capturing the data needed to understand hacker behavior.
Why do security professionals use honeynets instead of just honeypots?
Hackers expect to find more than one machine when they breach a company's infrastructure, so a single honeypot may not sustain the deception for long. Building a honeynet allows the deception to last longer, which could result in more data about how attackers move through a system and what they are after.
What is the Honeynet Project and what does it do?
The Honeynet Project is a volunteer-driven research organization started in 1999 that studies hackers via honeypots and honeynets. It operates around three pillars: conducting research on hacker tools and tactics, building awareness by sharing findings with the security community, and creating tools that organizations can use to build their own honeynets and honeypots.
What should I consider if I'm not ready to build a honeynet?
If you're interested in testing your security approach but aren't ready to commit to creating a honeynet, penetration testing is an alternative worth exploring. It offers a way to assess your security posture without the complexity of standing up a full honeynet environment.
References
Honeypotting. (2009). Virtualization for Security.
What Is a Honeypot? A Trap for Catching Hackers in the Act. (April 2019). CSO.
About Us. The Honeynet Project.