What is a Honeywall
What is honeywall?
The gateway device in a honeynet honeypot is called a honeywall. Diagram 1
describes where a honeywall is usually placed in a honeynet network. The
honeywall can be considered the main point of entry and exit for all network
traffic for a honeynet honeypot. This allows for complete control and analysis of
all network traffic to and from a honeynet system.
There have been different phases of development around the honeynet. Most
recently there has been a second generation design that focuses on the
honeywall design. When the first generation honeynet was discusses the
honeywall was basically a router that performed Network Address Translation.
One major flaw to this design is that a remote hacker can now know an extra
“hop” exists before the “bait” honeypot systems. Most hackers want to know as
much as possible about a possible network as possible. Part of this is just the
natural curiosity but mainly it’s to figure out if there are any firewalls or intrusion
detection systems that maybe tracking their movements. If the honeywall has an
IP address the hacker can see this could send red flags to the hacker that there
is some firewall/ids/honeywall in front of the bait systems. This prompted the
next generation honeywall to move to a bridged environment in which a remote
hacker would have no idea that traffic was passing through a honeywall.
Get your intel directly from the experts.
We are sharing all the latest and greatest cybersecurity knowledge in our webcasts, events, demos and more–come join us.
