Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


April 2004

Honeypots for Windows

Distract intruders away from your legitimate resources
RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
SideBar    A Small Consideration

SPECTER
SPECTER contains many unique features but doesn't have the detailed Windows emulation and flexibility of its competitors. SPECTER is among the easiest honeypots to install and configure, although perhaps this ease results from its lack of features and customization.

SPECTER's GUI is unique in that it attempts to display almost every possible configuration option on one screen, as Figure 3, page 37, shows. I found the GUI too busy, and during testing, the GUI edges were cut off when the screen was in 800 * 600 resolution. In addition, most of the configuration windows don't have the Close and Minimize control buttons typically found in Windows applications. Both the online Help file and the help available on SPECTER's Web site could be greatly improved.

SPECTER can emulate 14 OSs (Windows OSs include Windows XP, Win2K, NT, and Windows 98 but not Windows 2003) and many of the ports an intruder might expect to see. However, SPECTER emulates only 11 legitimate (i.e., nonmalicious) network services: DNS, Finger, FTP, POP3, IMAP4, HTTP, Secure Shell (SSH), SMTP, Sun RPC, Telnet, and a generic trap. Three of those services (i.e., Finger, SSH, and Sun RPC) aren't routinely found on Windows systems. SPECTER also emulates three potentially malicious Trojan horse ports: NetBus, SubSeven, and Back Orifice 2000 (BO2K).

You can only enable or disable the ports or services; you can't customize them, add ports or scripts, or extend the honeypot's response beyond what's already hard-coded. Furthermore, SPECTER won't display or log intruder attempts to any other ports on the host, which is a significant limitation for what could be a real honeypot contender. You would almost have to be lucky to notice an intruder with this honeypot.

On the plus side, the banner emulation of SMTP, FTP, HTTP, and POP return Windows-specific information but not updated versions. You can configure each emulated OS with a character. You can choose from five characters: Open (the OS acts like a badly secured system), Secure (the OS acts like a well-secured system), Failing (the OS acts like a machine with various hardware and software problems), Strange (the OS acts unpredictably), and Aggressive (the OS communicates as long as necessary to collect information about the intruder, then reveals its true identity to try to scare the intruder away). It would be better if you could customize the security setting for each emulated service on each OS.

For every point of inflexibility or strangeness, SPECTER offers a unique feature that I would like to see included in the other contenders. One such feature is the ability to collect information about the intruder by using intelligence modules, such as finger, traceroute, and portscan. This feature can save you time in the forensic analysis after an attack, although using these options might alert the intruder. I wish other honeypots would offer this option.

SPECTER comes with decoy data that you can use to make the honeypot look more legitimate, thereby enticing intruders. For example, SPECTER comes with fake password files, with varying levels of difficulty. Or instead of sending the password file when the intruder requests it, the honeypot can send a warning text message. SPECTER also generates programs that the intruder can download. These programs leave hidden markers on the intruder's computer. Supposedly, law enforcement agencies can use these markers as evidence in court. The concept is intriguing. However, to date, no law enforcement agency has used them this way, so their validity and legality remains untested. (Another untested legality concerns administrators' liability when using any honeypot. For more information about this topic, see the sidebar "A Small Consideration.")

SPECTER offers other interesting features as well. For example, it has a remote administration client that's nearly as functional as the local client, an online update button to check for new releases, several methods of alerting and logging, and a log-analyzer engine to parse logs for notable events.

I've been following SPECTER for the past year. Although it has an opportunity to be a major player in the Windows honeypot market, it appears dated and a bit neglected by its developer. Its biggest drawback is the lack of port emulations and customization options. Pricing starts at $599 for a light version and $899 for the full version.


SPECTER 7.0
Network Security Software - (41) (31) 376-0534
http://www.specter.com
PRICE: $899 for full version (includes one license); $399 for each additional license; $99 for extension of upgrade and support period (1 year)
DECISION SUMMARY
PROS: Unique features not found elsewhere
CONS: Not very customizable
Supports only 14 services or ports
Not frequently updated


   Previous  1  2  3  4  [5]  6  Next 


Top Viewed ArticlesView all articles
WinInfo Short Takes: Week of November 9, 2009

An often irreverent look at some of the week's other news, including some more Windows 7 sales momentum, some Sophos stupidity, Microsoft's cloud computing self-loathing, more whining from the browser makers, Zoho's "Fake Office," and much, much more ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

Windows 7 Sets Sales Record

Microsoft CEO Steve Ballmer described Windows 7's first ten days of sales as "fantastic" while in Japan yesterday. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events WinConnections and Microsoft® Exchange Connections

Deep Dive into Windows Server 2008 R2 presented by John Savill

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement