Proactive Honeypotting

OK, here’s something I don’t do often: praise Microsoft.
Strider HoneyMonkey is a Microsoft Research project to detect and analyze Web sites hosting malicious code. The intent is to help stop attacks that use Web servers to exploit unpatched browser vulnerabilities and install malware on the PCs of unsuspecting users. Such attacks have become one of the most vexing issues confronting Internet security experts. Strider HoneyMonkey is a project of the Cybersecurity and Systems Management group in Microsoft Research.

Strider HoneyMonkey Exploit Detection, Microsoft Research

Instead of waiting around for attacks to happen, this project emulates average users in web browsing, and catches spyware and attacks that occur as a result. Sort of a proactive honeypot. Clever.

This goes beyond traditional Internet security, which normally builds forts and waits for the enemy to attack. This project sends out multiple scouts to entice the enemy to attack ambushes. This is real intelligence, and moves into risk management.

-jsq

PS: Thanks, Chez, for the pointer.