Matilda Moore

I am a Digital Forensics and Incident Response Analyst working in the Defence Sector. Last year I completed my BSc in Cyber Security as an apprentice where I discovered an interest in detecting honeypots. I enjoy blue team CTFs and in my life outside of cyber (if that exists!) love the outdoors and animals.


Session

08-22
13:30
20min
Honeypot detection through machine wear and tear
Matilda Moore

Honeypots, which are a high-fidelity intelligence gathering strategy to detect, delay or study adversarial behaviour by simulating vulnerable targets, face the challenge of irrelevancy if adversaries are able to detect and therefore avoid them. Previous research has observed that external behaviours of fake headers and unconvincing error responses lead to detection, but this presentation argues that it is the absent inevitable ageing through day to day use that gives the game away.

The SANS ISC DShield honeypot was deployed in the cloud and systematically tested against a taxonomy of “wear and tear” across disk, registry, system, browser and network artefacts to assess the level of configuration of the honeypot. Logs from a 30-day period were collected and analysed to identify if adversaries were employing techniques of examining system usage within their attack paths.

It was observed that when DShield is deployed “off the shelf” it has limited configuration of wear and tear artefacts which reveal the true nature of the machine. 78% of artefacts tested were configured to an unsatisfactory level or absent altogether. This presentation highlights how honeypot operators need to further configure honeypots in order to create a more convincing decoy.

Rookie Track