tencent cloud

Overall Overview

Download
Mode fokus
Ukuran font
Terakhir diperbarui: 2026-07-24 08:39:56

What Is Network Honeypot

A Network Honeypot is a simulated business system that runs on the Internet and does not actually host any real business. It is exposed in a user's network through probes. For example, if it is triggered by an attacker, it actively records attacker information and traces attack methods, providing accurate attacker intelligence and countermeasure tracing capabilities for the defense of real business. Meanwhile, in guarantee for important periods scenarios, a Network Honeypot buys sufficient time for real business to achieve the goal of successful defense.
The honeypot service of Tencent Cloud Firewall (CFW) is deployed in Tencent Cloud's honeypot farm. It does not occupy the user's network space and is isolated from each other by deploying different VPCs. Even if an attacker gains access, lateral movement cannot occur. The exposure probes of the honeypot are deployed in the user's network and can be IP addresses or domain names. By forwarding traffic from specified ports/paths to different honeypot services, "traps" are deployed within the business system.

Features and Principles of Network Honeypot

The honeypot service of Tencent Cloud Firewall (CFW) has the following three main features:
It features a high degree of simulation, making it difficult for attackers to detect.
It can collect attacker information and provide countermeasure capabilities to the defense side.
It can delay attackers and provide time protection for network security.
The security of a business system is directly proportional to the number of probes and does not excessively consume the user's network resources. By using highly realistic simulation services in the honeypot farm, it achieves the goal of "deceiving" attackers.

Viewing the Defense Overview

1. Log in to the CFW console. In the left sidebar, click Network Honeypot.
2. The defense overview is displayed in the upper-left corner of the page, allowing you to quickly check the numbers of Honeypot services, Probes, Hit honeypot, Scanned probes, Attack IPs, and Scanning IPs.
3. In the defense overview, clicking Related alerts or View logs navigates you to the Attack deception events page or the honeypot service page under Intrusion Defense logs, respectively.

Viewing the Honeypot Policy Diagram

The honeypot policy diagram includes a policy list and a policy view. Using tables and connection diagrams respectively, it displays the different paths corresponding to various probe addresses, different honeypot service types, and different decoy types.

Policy List

The policy list displays the corresponding honeypot information for different probe addresses in detail using a table format.

Policy View

The policy view uses a connection diagram to intuitively and clearly display the honeypot information corresponding to probe addresses in different regions.
The policy view supports finding corresponding probe addresses through honeypot filter criteria. For example, users can hover the mouse over Probe Address or Honeypot Service to locate the corresponding probe and the decoy associated with the honeypot service. This feature allows users to select any criteria to find the corresponding services, providing greater flexibility and more adaptable visual information.


Bantuan dan Dukungan

Apakah halaman ini membantu?

masukan