Howdy,
I'm considering launching a subscription service that helps you strengthen your network's security by providing logs of real-world attacks, gathered from a network of honeypots. The logs would be searchable by protocol, vulnerability, and perhaps more, enabling your IT staff to develop IDS and firewall rulesets from in-the-wild attacks.
Would you pay for this? How much?
I'd also love to hear from anyone who thinks this isn't feasible.
Thanks in advance,
fabulist
Our main pain point is never information - we can get that in spades. Our pet Unix engineer is constantly finding interesting new feeds for us, and I spend a notable amount of time each week keeping up to date with latest developments and any new information sources that crop up.
The challenge is translating this information into sound, actionable, intelligence that measurably provides value to our business and customers. Raw logs of random honeypots are of no interest to us, and if we wanted such a thing we could roll our own relatively easily.
Honeypots based outside of our organization would only be of interest in a few limited scenarios: Firstly, when a major new vulnerability lands it would be invaluable to know right from the start what sort of attacks are being seen in the wild. Ideally it would also be able to look back in time and discover if this zero-day being exploited prior to the vulnerability. Secondly, what we couldn't do is set up honeypots in multiple different sectors and compare attack profiles - eg, between a hospitality company and say a local council.
In both those cases though, what we would want is the results of the analysis and expert recommendations, not the raw logs.
As others have already suggested, what we would be very interested in is honeypots-as-a-service: Being able to drop a fake finance server into our estate and detect access attempts. Create a fake company division website and see who tries to attack it and how. Be alerted to targeted attacks before they actually entire the production estate.
Something I'm fond of saying is that whenever an investigation or assessment is performed, what actually earns you the money is the report at the end. That report and the actionable intelligence within is your product, not the tool you use to generate it.