Thanks for sharing your interesting research! Can you explain your honeypotting approach further? How are you "presenting" as a SIP relay? What other honeypots or protocols can you detect?
I set up servers on the net that masquerade as a SIP relay by essentially supporting the protocol but with few authentication protections. Malware bots scan the IPv4 space looking for such machines that they can use as a relay. My honeypot is actually an extensible framework, and we also can mimic SSH, Telnet, HTTP, SMB, FTP, RDP, SMTP, MQTT, Node-Red, MODB, S7, and SNMP. Individual servers can easily be set up to scan any subset of those. Check out https://knock-knock.net to get a visual sense of what the honeypot is doing!
Yes - I would have expected better from these institutions as well, but there's always going to be someone who brings their rogue laptop onto the corporate net. The key is how fast the security catches it. They can use the api that I describe in the blog to check my honeypot for their IPs. Very simple to put into a daily or hourly script.
Thanks for sharing your interesting research! Can you explain your honeypotting approach further? How are you "presenting" as a SIP relay? What other honeypots or protocols can you detect?
I set up servers on the net that masquerade as a SIP relay by essentially supporting the protocol but with few authentication protections. Malware bots scan the IPv4 space looking for such machines that they can use as a relay. My honeypot is actually an extensible framework, and we also can mimic SSH, Telnet, HTTP, SMB, FTP, RDP, SMTP, MQTT, Node-Red, MODB, S7, and SNMP. Individual servers can easily be set up to scan any subset of those. Check out https://knock-knock.net to get a visual sense of what the honeypot is doing!
Hell of an opening on this blog post. Solid write up! Glad honeypots like this exist.
This is quite the claim (and I'm not saying you are wrong from making it).
I just would have expected some of these institutions to be better.
Yes - I would have expected better from these institutions as well, but there's always going to be someone who brings their rogue laptop onto the corporate net. The key is how fast the security catches it. They can use the api that I describe in the blog to check my honeypot for their IPs. Very simple to put into a daily or hourly script.
Shades of "KENNEDY SLAIN BY CIA, MAFIA, CASTRO, LBJ, TEAMSTERS, FREEMASONS": https://theonion.com/november-22-1963-1819587981/
Ha! Love it. Totally believe in it too.