As hackers obtain ever more dangerous and easy-to-use tools, they are being countered by novel defence strategies, including the concept of a decoy network.
"The idea behind the decoy network is to divert hackers` attention from the `real` network, says Martin May, regional director Enterasys Networks SA. "Of course, to be effective, the decoy network must be completely separate."
May says the decoy network is envisioned as much more than just a single server set up to be a `honeypot` where hackers may break in, find a dead end and have their activities recorded with an eye toward prosecution.
"Rather, the decoy net is an entirely fake network, complete with host computers on a LAN with simulated traffic, to convince hackers for as long as possible that it`s real."
"Whether such networks will be worth the effort is open to debate, but most experts agree that they can be a way to slow hackers long enough to sort the curious from the truly destructive."
Enterasys is currently testing decoy networks with selected customers in SA where hacker activity is rife -- although not often reported -- according to May.
"In future we hope to employ decoy networks with a view toward collecting evidence to prosecute hackers," he notes.
From a technical perspective, it is possible to create a deception network that has the same IP network address as a real network, says May. He acknowledges that deception nets carry obvious administrative burdens, such as the need to generate realistic traffic to fool a hacker and maintain a network no one really uses.
"In the mean time, hackers are becoming smarter," says May. "In the past year alone a new breed of distributed port scanners and sniffers has emerged that make it easier for attackers to hide their intent.
"In addition, there is now a kernel-level root-kit for Linux, called Knark, which when installed by hackers, changes the operating system to hide files and present false information to administrators.
"Another innovation, called Dsniff, can be used to capture traffic on Ethernet switches and inject traffic into a network to direct traffic to itself, known as the man-in-the-middle attack."
Many tools that let hackers carry out surveillance are now Web-based, according to May. "With Web-based tools there are no complicated downloads or zip files. They can hack from anywhere, anonymously.
"While a talented few among hackers actually make attack tools, many of these tools today are freeware," he adds.
Editorial contacts

