North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Arbor Networks DoS defense product

  • From: Dan Hollis
  • Date: Wed May 15 16:56:48 2002

On Wed, 15 May 2002, Rob Thomas wrote:
> ] It could be very useful as deterrence to know their criteria.
> For the low fee of a cool t-shirt or a bit of gear for my lab I'd be
> happy to spread rumours about the mad fast honeypot residing within
> your prefixes.  :)

disinformation as a means to raise the level of uncertainty for the 
attacker, it's classic military tactic. what other military tactics can 
be used to make life more dangerous for attackers?

i've been tossing around an idea for a "land mine network". randomly 
distributed honeypots around the internet. when X landmines are hit from 
the same source, that source gets entered into a BGP blackhole feed which 
anyone can subscribe to. put landmines in popularly targeted networks, 
maybe even make them randomly move about. there are all sorts of wonderful 
tactics that could be put to use.

scanning would quickly become self defeating as attackers would only 
manage to cut themselves off from the net.

-Dan
-- 
[-] Omae no subete no kichi wa ore no mono da. [-]