Talk With an Expert

How Sweet It Is: A Comparative Analysis of Remote Desktop Protocol Honeypots

How Sweet It Is: A Comparative Analysis of Remote Desktop Protocol Honeypots (PDF, 2.89MB)Published: 28 Jan, 2021
Created by
Lauri Marc Ahlman

Remote Desktop Protocol (RDP) and other remote administrative services are consistently targeted by attackers seeking to gain access to protected systems. Honeypots are a valuable tool for network defenders to learn about attacker tools and techniques. This paper proposes an architecture for an RDP honeypot running on a Linux host. The proposed solution includes a capability to replay RDP sessions and observe attacker activity and keystrokes. Further, this paper presents a comparative analysis between this proposed solution and an RDP honeypot using the open-source project PyRDP (Gonzalez, 2020) which is represented as a Windows environment.