Honeypot testbed for network defence strategy evaluation

In this paper, we describe a network defence strategy testbed, which could be utilized for testing the strategy decision logic against simulated attacks or real attackers. The testbed relies on a network of honeypots and the high level of logging and monitoring the honeypots provide. Its main advantage is that only the decision logic implementation is needed in order to test the strategy. The testbed also evaluates the tested network defence strategy. We demonstrate an example of network defence strategy implementation, the test setup, progress, and results. The source code of the testbed is available on GitHub.

[1]  Jan Vykopal,et al.  Cloud-based testbed for simulation of cyber attacks , 2014, 2014 IEEE Network Operations and Management Symposium (NOMS).

[2]  Martin Drasar,et al.  Network defence strategy evaluation: Simulation vs. live network , 2017, 2017 IFIP/IEEE Symposium on Integrated Network and Service Management (IM).