Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityLogical SecuritySecurity & Business Resilience

New honeypot techniques for addressing targeted attacks

By Daniel Grant
Honey dripping

Image via Unsplash

July 22, 2024

Automated at-scale attack campaigns now represent the vast majority of online threats, and are starting to blend together with targeted attacks. As the number of these attacks increases, so does the cyber risk for organizations.  

Unfortunately, the most common approaches to defense — including vulnerability management, phishing awareness, signature-based network and endpoint detection — are neither effective nor efficient in addressing these kinds of attacks because traditional third-party threat intelligence cannot provide adequate targeted attack visibility. 

In the second quarter of 2023, GreyNoise researchers observed a substantial change in the behavior of some regular internet scanning idioms. Inventory scans —where both benign and malicious actors perform regular checks for a given technology or specific vulnerability — significantly reduced in frequency and scale. The vast majority of these types of scans now come from benign sources. This, along with the speed at which organizations are compromised after the announcement of a new vulnerability, strongly suggests more capable attacker groups have their own form of “attack surface monitoring,” and use it to avoid tripping existing defenses. 

These targeted attacks threaten to circumvent existing defense capabilities and expose organizations to a new wave of disruptive breaches. In order to adequately protect their networks, defenders must evolve in response.

Honeypots are back in vogue 

Although there are countless sources of third-party intelligence about attacker behavior, many of them are the secondary outputs of some other security program. Managed service providers, hosting providers, endpoint and network security vendors use what they learn about the networks to defend the broader universe of organizations. Since the data is provided by the targeted organizations, it cannot be controlled. This intelligence is a byproduct of another business, with another business model. What’s more, threat intelligence providers cannot collect information about a potential attacker until they have actually attacked a protected network, which biases the data toward widespread attacks.

Another approach to threat intelligence relies on first party (i.e. “primary source”) data, derived from sensors that observe attacker behavior directly. When these sensors are designed to mimic vulnerable systems with the intent to attract attackers, they are referred to as honeypots. On a small scale, this approach is not effective, but when honeypots are deployed on a large scale it becomes possible to detect many internet-wide as well as targeted attacks. 

Honeypots offer some key advantages to defenders when used to complement traditional third-party threat intelligence, especially when addressing the threat of targeted attacks:

  • Velocity. Honeypots avoid the operational lag of traditional threat intel because observations can be automatically tagged and distributed at machine speed.
  • Proactivity. Rather than waiting until an attack has actually happened to collect data, honeypots can research and analyze the behavior of a potential attacker before the targeted system is compromised.
  • Relevance. Instead of relying on inconsistent data collected from verticals, systems and various geographies that may or may not pertain to a specific defender, honeypots collect data from systems that are optimized to resemble key defender assets.
  • Comprehension. Honeypot data is derived from its own network configuration, rather than depending on third party data.

In the past, honeypot programs have struggled due to several challenges with their operational security and detection capabilities. Because of this, few organizations currently have mature, effective honeypot programs. However, new advances in infrastructure automation, network traffic shaping, cloud computing and artificial intelligence can resolve these issues and make it possible to consistently identify novel attacks and reveal attacker infrastructure.

Defenders should define their honeypot strategy by identifying attack risks and intelligence gaps, assessing honeypot maturity and evaluating security partnerships for comprehensive visibility. 

6 criteria for a successful honeypot defense strategy

While honeypots are not a silver bullet, a mature honeypot program can fill the gaps in current intelligence approaches and effectively manage business risks. One of the key advantages is that they offer a unique opportunity to see what potential attackers are doing in real-time before a full-on incident takes place.  

Here are six criteria for a successful and effective honeypot defense strategy:

  1. Ease of deployment. Advances in cloud technology and infrastructure orchestration have made it possible for network architecture to support streamlined operations. This enables new honeypots to be erected as redirects to established cloud resources, permitting resource-constrained teams to deploy and manage multiple honeypots that cover the systems and protocols they wish to defend. 
  2. Flexible persona. In order to be effective, the apparent identity that a honeypot presents to scanners and attackers needs to be frequently updated in response to changing threats. Fortunately, the same cloud architectures that support easy deployments can also deliver dynamic personas. As attackers modify their targeted systems, in response to new vulnerabilities, new attack campaigns and new priorities, defenders need to be able to shift their honeypot networks in response. 
  3. Credibility. Depending on what behavior defenders wish to observe, different levels of honeypot interaction are required (e.g. a clone of login pages, exposed vulnerabilities or even deeper). In many cases, it isn’t enough to imitate — the honeypot must actually become the thing that lures attackers. 
  4. Completeness of data.  A successful honeypot program will collect all of the data that analysts, detection engineers and others require to block automated attacks and identify targeted ones. New honeypots collect more comprehensive data from packet capture and in-persona process, file and network actions, providing analysts with the data they need to observe, identify and understand novel activities and attacks. 
  5. Automatic analysis. While an initial, unadvertised perimeter sensor will only see a trickle of background noise, once the honeypot presents a popular tech persona and is indexed, it will see a high volume of scan and attack traffic. This data can overwhelm defenders, undermining honeypot value. Manual approaches to analyzing this data are possible, but mature programs must increasingly leverage AI to assist in data labeling. 
  6. Global visibility. The true value of honeypots is realized when the data can be effectively aggregated and compared with global threat data. An attack seen by one organization’s honeypots, but not globally, is a targeted attack. A honeypot program that empowers defenders to immediately and systematically contrast what they’re seeing with what’s happening worldwide represents a new source of truth on both mass attack campaigns and targeted activity, allowing defenders to understand, prioritize and respond to the threats that they are facing.

There will always be a need for the unique threat intelligence insights that only large, advanced honeypot networks can safely provide. Organizations that accurately scope their risk profile and honeypot maturity will be best positioned to make effective investments, equipping their defenders with the intelligence they need to deal with the evolving landscape of automated and targeted attacks.

KEYWORDS: best practices organizational resilience security strategies threat intelligence vulnerability management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Daniel grant headshot

Daniel Grant is a Principal Data Scientist at GreyNoise Intelligence. Image courtesy of Grant

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Security Enterprise Services
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Cyber Tactics Column
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Technologies & Solutions
    By: Charles Denyer
Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Computer with binary code hovering nearby

Cyberattacks Targeting US Increased by 136%

White post office truck

Department of Labor Sues USPS Over Texas Whistleblower Termination

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Person holding large ball of twine

Preventing Burnout in The Security Industry

Harrods

Harrods’ Cyberattack: Cybersecurity Leaders Weigh In

2025 Security Benchmark banner

Events

September 29, 2025

Global Security Exchange (GSX)

 

November 17, 2025

SECURITY 500 Conference

This event is designed to provide security executives, government officials and leaders of industry with vital information on how to elevate their programs while allowing attendees to share their strategies and solutions with other security industry executives.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Coding on monitor

    Windows users targeted with zero-day attacks via Internet Explorer

    See More
  • video surveillance

    Techniques and algorithms for video surveillance analytics

    See More
  • Typing on laptop

    In the last year, 70% of organizations were targeted with BEC attacks

    See More

Events

View AllSubmit An Event
  • September 29, 2025

    Global Security Exchange (GSX)

     
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!