I keep a honeypot server in the DMZ of my firewall It's interesting to see how many times an hour someone attempts to break into it. I switch up the honeypots once a week or so. Since I snapshot the server after setting it up, it takes little effort to recover from any successful incursions, rare though they might be and the virtualized server has no ability to move laterally through my network.
|