5 ms·
We maintain a sensor network which consists of multiple nodes which emulate network fingerprint and characteristics of popular services. We did multiple experim
by rishabhd 6y ago
We maintain a sensor network which consists of multiple nodes which emulate network fingerprint and characteristics of popular services. We did multiple experiments over a period of 3 years as part of tuning our sensors one of which was changing the SSH port of one honeypot to 38651. Less than 10 hits were observed on it over a period of 6 months and 7 out of 10 were legitimate (or misguided, depends on how you look at it).
During our experiments, we learnt a lot of lessons -
1) Attackers operate on a budget and are often time-bound (they have bosses as well). They have less incentive to target esoteric ports unless they have specific intel about it.
2) It is always a better strategy to ensure you waste their resources. No one is going to do full port scans of internet. The last I heard, adding an extra port to ZMap takes around 500 MB of extra memory.
3) The advent of intel sharing models typically highlight nasty scanners like a beacon.
4) Very few ISPs provide high bandwidth pipes to their retail (or even privileged) customers do full port scans. Its always a fight between scanning via low bandwidth pipes via multiple nodes over a long period of time and have less updated data or having to pay a lot more to get a 10GB+ pipe to do it which is bad for OPSEC.
5) Corollary to previous point, even if you control a large botnet that may do it for you, you will get reported or will have scanning, co-relation or computation issues. Or all of them.
6) Pareto's principle is everywhere, 20% of security/ sanity measures will solve 80% of your problems. Simply changing network ports, running your infra over a closed VPN environment, reducing your public internet exposure, configuring dual factor authentication et al - it seriously reduced our infra monitoring/ management upkeep.
7) The internet is full of spam (and water is wet), expect mass spam all the time on your mail sensors/ email IDs. Interacting with these will eventually get elevated to targeted attempts. Even simple browsing will sometime give you a high value malware payload served via AD networks that was previously unknown.