{"id":96260,"date":"2020-10-09T19:42:45","date_gmt":"2020-10-09T17:42:45","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/honeypot-vs-deception-na-primere-xello"},"modified":"2020-10-09T19:42:45","modified_gmt":"2020-10-09T17:42:45","slug":"honeypot-vs-deception-na-primere-xello","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/honeypot-vs-deception-na-primere-xello","title":{"rendered":"Honeypot vs Deception using Xello as an example","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Honeypot vs Deception using Xello as an example\" src=\"\/wp-content\/uploads\/2020\/10\/97eba5f16d9c4be7687e26c81c3b784d.png\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>There are already several articles on Habr about Honeypot and Deception technologies (<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/softline\/blog\/413893\/\">1 article<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/trendmicro\/blog\/490406\/\">2 articles<\/a><\/noindex>). However, we still encounter a lack of understanding regarding the differences between these classes of protection tools. To clarify this, our colleagues from <noindex><a rel=\"nofollow\" href=\"http:\/\/xello.ru\/?utm_source=habr&amp;utm_campaign=tssolution\">Xello Deception<\/a><\/noindex> (the first Russian developer of <noindex><a rel=\"nofollow\" href=\"http:\/\/tssolution.ru\/katalog\/xello?utm_source=habr\">Deception platforms<\/a><\/noindex>) decided to describe in detail the distinctions, advantages, and architectural features of these solutions.<\/p>\n<h2>Let's understand what &laquo;honeypots&raquo; and &laquo;deceptions&raquo; are:<\/h2>\n<p>&laquo;Deception technologies&raquo; emerged in the market of information security systems relatively recently. However, some experts still consider Security Deception to be just a more advanced version of &laquo;honeypots&raquo;.  <\/p>\n<p>In this article, we will highlight both the similarities and fundamental differences between these two solutions. In the first part, we will describe \u201choneypots,\u201d how this technology has developed, and what its advantages and disadvantages are. In the second part, we will focus on the principles of operation for creating a distributed deception infrastructure (Distributed Deception Platform \u2014 DDP). <\/p>\n<p>The basic principle underlying honeypots is the creation of traps for hackers. The earliest Deception solutions were developed based on this same principle. However, modern DDPs significantly surpass honeypots in both functionality and effectiveness. Deception platforms include traps, lures, applications, data, databases, and Active Directory. Modern DDPs can provide extensive capabilities for threat detection, attack analysis, and automated responses. <\/p>\n<p>Thus, Deception represents techniques that simulate a company's IT infrastructure and mislead hackers. As a result, such platforms can halt attacks before they cause significant damage to the company's assets. Honeypots, of course, do not offer such a wide range of functionality or level of automation, making their application require higher qualifications from information security department staff.<\/p>\n<h2>1. Honeypots, Honeynets, and Sandboxing: what are they and how are they applied<\/h2>\n<p>For the first time, the term &laquo;honeypots&raquo; was used in 1989 in Clifford Stoll's book &laquo;The Cuckoo\u2019s Egg&raquo;, which describes events related to tracking a hacker at the Lawrence Berkeley National Laboratory (USA). In practice, this idea was realized in 1999 by Lance Spitzner, an information security specialist at Sun Microsystems, who founded the research project &laquo;Honeynet Project&raquo;. The first honeypots were very resource-intensive, complex to set up and maintain. <\/p>\n<p>Let\u2019s take a closer look at what <strong>honeypots <\/strong>and <strong>honeynets<\/strong>. Honeypots are standalone hosts designed to lure attackers into infiltrating a company's network and attempting to steal valuable data, as well as to expand the network's attack vector. A honeypot (literally translated as \"barrel of honey\") is a specialized server equipped with a variety of network services and protocols, such as HTTP, FTP, etc. (see Fig. 1).<\/p>\n<p><img decoding=\"async\" alt=\"Honeypot vs Deception using Xello as an example\" src=\"\/wp-content\/uploads\/2020\/10\/0511c0aa3bee00cdc3f2ba9adcc52f78.png\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>If we combine several <strong>honeypots <\/strong>into a network, we get a more effective system of <strong>honeynet<\/strong>, which emulates the corporate network of a company (web server, file server, and other network components). This solution allows understanding the strategies employed by attackers and misleading them. A typical honeynet usually operates parallel to the operational network and completely independently of it. Such a \"network\" can be published online via a separate channel, and a separate range of IP addresses can also be allocated for it (see Fig. 2).<\/p>\n<p><img decoding=\"async\" alt=\"Honeypot vs Deception using Xello as an example\" src=\"\/wp-content\/uploads\/2020\/10\/c9500fa0982774476d686dcc9532752e.png\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>The purpose of using a honeynet is to show the hacker that they have allegedly penetrated the corporate network of the organization, while in reality, the attacker is in an \"isolated environment\" and under close observation by information security specialists (see Fig. 3).<\/p>\n<p><img decoding=\"async\" alt=\"Honeypot vs Deception using Xello as an example\" src=\"\/wp-content\/uploads\/2020\/10\/880f61b1d0db18fceb70cebdd32541b2.png\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>It is also important to mention a tool called<strong>sandbox<\/strong>\", which allows attackers to install and run malicious programs in an isolated environment where IT specialists can track their actions to identify potential risks and take necessary countermeasures. Currently, sandboxing is typically implemented on dedicated virtual machines on a virtual host. However, it should be noted that sandboxing only shows how dangerous and malicious programs behave, while a honeynet helps specialists analyze the behavior of \"dangerous actors.\" <strong>sandbox<\/strong>), which allows attackers to install and run malicious programs in an isolated environment where IT specialists can monitor their actions to identify potential risks and implement necessary countermeasures. Currently, sandboxing is typically implemented on dedicated virtual machines on a virtual host. However, it should be noted that sandboxing only shows how dangerous and malicious programs behave, while a honeynet helps specialists analyze the behaviors of \u201cdangerous players.\u201d  <\/p>\n<p>The clear benefit of honeynets is that they mislead attackers, wasting their strength, resources, and time. As a result, instead of real targets, they attack decoys and can cease their attack on the network, achieving nothing. Honeynet technologies are most commonly used in government institutions and large corporations, as these entities are often targets of major cyberattacks. However, small and medium-sized businesses (SMBs) also need effective tools to prevent cybersecurity incidents, although using honeynets in the SMB sector is not straightforward due to a lack of qualified personnel for such complex work.<\/p>\n<p><strong><u>Limitations of Honeypots and Honeynets<\/u><\/strong><\/p>\n<p>Why are honeypots and honeynets not the best solutions for countering attacks today? It should be noted that attacks are becoming more extensive, technically complex, and capable of inflicting serious damage on an organization\u2019s IT infrastructure. Cybercrime has emerged at an entirely different level, representing highly organized shadow business structures equipped with all necessary resources. Additionally, the 'human factor' (errors in software and hardware configuration, insider actions, etc.) must be considered, making the use of only technology to prevent attacks insufficient at this point.  <\/p>\n<p>Below are the main limitations and drawbacks of honeypots (honeynets):<\/p>\n<ol>\n<li>\n<p>Honeypots were initially designed to identify threats that are outside the corporate network, focusing more on analyzing the behavior of attackers rather than on rapid threat response. <\/p>\n<\/li>\n<li>\n<p>Attackers have generally learned to recognize emulated systems and avoid honeypots. <\/p>\n<\/li>\n<li>\n<p>Honeynets (honeypots) have an extremely low level of interactivity and interaction with other security systems, making it difficult to obtain detailed information about attacks and attackers when using honeypots, and thus respond effectively and quickly to cybersecurity incidents. Moreover, cybersecurity specialists receive a high number of false alerts about threats. <\/p>\n<\/li>\n<li>\n<p>In some cases, hackers may use a compromised honeypot as a starting point to continue their attack on the organization's network. <\/p>\n<\/li>\n<li>\n<p>Honeypots often face scalability issues, high operational load, and system configuration challenges (they require highly skilled specialists and lack user-friendly management interfaces, etc.). There are significant difficulties in deploying honeypots in specialized environments such as IoT, POS, and cloud systems.<\/p>\n<\/li>\n<\/ol>\n<h2>2. Deception technology: benefits and core principles of operation<\/h2>\n<p>After examining all the advantages and disadvantages of honeypots, we conclude that a completely new approach to incident response in cybersecurity is necessary to develop a quick and adequate response to attacker actions. Such a solution lies in technologies. <strong>Cyber deception (Security deception)<\/strong>. <\/p>\n<p>The terminology &laquo;Cyber deception&raquo;, &laquo;Security deception&raquo;, &laquo;Deception technology&raquo;, &laquo;Distributed Deception Platform&raquo; (DDP) is relatively new and has emerged not so long ago. In fact, all these terms refer to the use of &laquo;deception technologies&raquo; or &laquo;IT infrastructure imitation and misinformation techniques against attackers&raquo;. The simplest Deception solutions are an evolution of the honeypot concept, but at a more technologically advanced level that implies greater automation in threat detection and response. However, there are already serious DDP-class solutions on the market that offer ease of deployment and scaling, as well as a significant arsenal of traps and lures for attackers. For example, Deception allows for the emulation of IT infrastructure objects such as databases, workstations, routers, switches, ATMs, servers, SCADA, medical equipment, and IoT.  <\/p>\n<p>How does the &laquo;Distributed Deception Platform&raquo; work? After deploying the DDP, the IT infrastructure of the organization will be structured as if it consists of two layers: the first layer is the real infrastructure of the company, and the second is the &laquo;emulated&raquo; environment, consisting of traps (decoys, traps) and lures (lures) that are placed on real physical devices within the network (see Fig. 4).<\/p>\n<p><img decoding=\"async\" alt=\"Honeypot vs Deception using Xello as an example\" src=\"\/wp-content\/uploads\/2020\/10\/268d19660e6ed2fe367487c1c995863a.png\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>For instance, an attacker may discover fake databases with 'confidential documents,' along with counterfeit credentials of supposedly 'privileged users' \u2014 all of these are decoy targets that can attract intruders, diverting their attention from the company's true information assets (see Fig. 5).<\/p>\n<p><img decoding=\"async\" alt=\"Honeypot vs Deception using Xello as an example\" src=\"\/wp-content\/uploads\/2020\/10\/0bf379a6c15735af2c10499a7162f001.png\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>DDP is a newcomer in the cybersecurity product market, having been around for only a few years and currently accessible only to the corporate sector. However, small and medium businesses will soon also be able to benefit from Deception by renting DDP from specialized providers 'as a service.' This option is even more convenient as there's no need for in-house highly skilled staff.<\/p>\n<p>Below are the main advantages of Deception technology:<\/p>\n<ul>\n<li>\n<p><strong>Authenticity<\/strong>. The Deception technology can create a fully authentic IT environment of a company, effectively emulating operating systems, IoT, POS, specialized systems (medical, industrial, etc.), services, applications, credentials, etc. Decoys are carefully blended with the working environment, and an intruder cannot identify them as honeypots. <\/p>\n<\/li>\n<li>\n<p><strong>Implementation<\/strong>. DDP utilizes machine learning (ML) in its operations. ML ensures ease, flexibility in configurations, and efficiency in implementing Deception. The 'traps' and 'lures' are rapidly updated, drawing the intruder into the company's 'false' IT infrastructure, while advanced AI-based analytics can detect active hacker activities and prevent them (for example, attempts to access Active Directory using deceptive credentials).  <\/p>\n<\/li>\n<li>\n<p><strong>Ease of use<\/strong>Modern \"Distributed Deception Platforms\" are easy to maintain and manage. Typically, they are controlled through a local or cloud console, offering integration capabilities with corporate SOC (Security Operations Center) via API and with many existing security monitoring tools. Maintaining and operating DDP do not require the services of highly skilled cybersecurity experts. <\/p>\n<\/li>\n<li>\n<p><strong>Scalability<\/strong>. Security deception can be deployed in physical, virtual, and cloud environments. Successfully, DDP operates in specialized environments such as IoT, ICS, POS, SWIFT, etc. Advanced Deception platforms can project \"deception technologies\" to remote offices and isolated environments without the need for additional complete platform deployment. <\/p>\n<\/li>\n<li>\n<p><strong>Interaction<\/strong>. By using effective and appealing decoys based on real operating systems, cleverly placed within the actual IT infrastructure, the Deception platform collects extensive information about the attacker. Then, DDP provides threat alerts, generates reports, and initiates automated responses to security incidents.<\/p>\n<\/li>\n<li>\n<p><strong>Point of Attack<\/strong>. In modern Deception, traps and decoys are placed within the network range rather than outside of it (as is the case with honeypots). Such a deployment model prevents attackers from using them as a foothold for attacking the real IT infrastructure of the company. More advanced Deception solutions include traffic routing capabilities, allowing all attacker traffic to be directed through a specially allocated connection. This enables the analysis of the attackers' activities without risking valuable company assets.<\/p>\n<\/li>\n<li>\n<p><strong>Persuasiveness of Deception Technologies<\/strong>. At the initial stage of an attack, attackers gather and analyze data about the IT infrastructure, then use it for lateral movement within the corporate network. With \"deception technologies,\" the attacker is bound to fall into \"traps\" that divert them from the organization's real assets. DDP will analyze potential access paths to credentials within the corporate network and present the attacker with \"false targets\" instead of actual credentials. These capabilities were sorely lacking in honeypot technologies. (See Fig. 6).<\/p>\n<\/li>\n<\/ul>\n<p><img decoding=\"async\" alt=\"Honeypot vs Deception using Xello as an example\" src=\"\/wp-content\/uploads\/2020\/10\/f611db51d0aaefef366c046075dc15ca.png\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<h2>Deception vs Honeypot<\/h2>\n<p>And finally, we come to the most interesting point of our study. Let us highlight the main differences between Deception and Honeypot technologies. Despite some similarities, these two technologies differ significantly, from their foundational ideas to their operational effectiveness.<\/p>\n<ol>\n<li>\n<p><strong>Different Foundational Ideas<\/strong>As we mentioned earlier, honeypots are set up as \"decoys\" around the company's valuable assets (outside the corporate network), aiming to distract attackers. The honeypot technology is based on the representation of the organization's infrastructure; however, honeypots can become a pivot point for launching an attack on the company's network. The Deception technology is developed from the attacker\u2019s perspective and allows for the early identification of attacks, thus giving security specialists a significant advantage over attackers and buying time. <\/p>\n<\/li>\n<li>\n<p><strong>\"Attracting\" VS \"Confusing\"<\/strong>When using honeypots, success depends on attracting the attention of attackers and motivating them to target the honeypot. This means that the attacker must reach the honeypot, and only then can you stop them. Therefore, the presence of attackers in the network can continue for several months or more, leading to data breaches and damage. DDP qualitatively mimics the company's real IT infrastructure; their goal is not just to attract the attacker\u2019s attention but to confuse them, so they waste time and resources without gaining access to the company's real assets. <\/p>\n<\/li>\n<li>\n<p><strong>\"Limited scalability\" VS \"automatic scalability\"<\/strong>As previously noted, honeypots and honeynets face scaling issues. This is complex and expensive, and to increase the number of honeypots in the corporate system, one must add new computers, operating systems, purchase licenses, and allocate IPs. Moreover, there is a need for qualified personnel to manage such systems. Deception platforms automatically deploy as the infrastructure scales, without significant overhead costs.  <\/p>\n<\/li>\n<li>\n<p><strong>\"High number of false positives\" VS \"no false positives\"<\/strong>The essence of the problem is that even an average user can encounter a honeypot, so the 'downside' of this technology is the large number of false positives, which distract security professionals from their work. The 'decoys' and 'traps' in DDP are carefully hidden from the average user and are designed solely for attackers; thus, every alert from such a system is a notification of a real threat, not a false positive.<\/p>\n<\/li>\n<\/ol>\n<h2>Conclusion<\/h2>\n<p>In our view, Deception technology is a giant leap forward compared to the older Honeypots technology. Essentially, DDP has become a comprehensive security platform that is easy to deploy and manage.  <\/p>\n<p>Modern platforms of this class play a crucial role in accurately detecting and effectively responding to network threats, and their integration with other components of the security stack enhances automation, increases efficiency, and improves incident response effectiveness. Deception platforms are based on authenticity, scalability, ease of management, and integration with other systems. All of this provides a significant advantage in the speed of incident response. <\/p>\n<p>Moreover, based on observations from penetration tests of companies where the Xello Deception platform has been implemented or piloted, it can be concluded that even experienced pentesters often cannot recognize decoys within the corporate network and fail, falling for the traps set. This fact further confirms the effectiveness of Deception and the great prospects that this technology holds for the future.<\/p>\n<h2>Product Testing<\/h2>\n<p>If you are interested in Deception platforms, we are ready to <noindex><a rel=\"nofollow\" href=\"http:\/\/tssolution.ru\/katalog\/xello?utm_source=habr\">conduct joint testing<\/a><\/noindex>.<\/p>\n<p>Stay updated through our channels (<noindex><a rel=\"nofollow\" href=\"https:\/\/t.me\/tssolution\">Telegram<\/a><\/noindex>,&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/www.facebook.com\/tssolution2020\/\">Facebook<\/a><\/noindex>,&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/vk.com\/ts_solution\">VK<\/a><\/noindex>,&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/blog\">TS Solution Blog<\/a><\/noindex>)!<\/p>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/522374\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0430 \u0425\u0430\u0431\u0440\u0435 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0441\u0442\u0430\u0442\u0435\u0439 \u043f\u0440\u043e \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 Honeypot \u0438 Deception (1 \u0441\u0442\u0430\u0442\u044c\u044f, 2 \u0441\u0442\u0430\u0442\u044c\u044f). \u041e\u0434\u043d\u0430\u043a\u043e, \u0434\u043e \u0441\u0438\u0445 \u043f\u043e\u0440 \u043c\u044b \u0441\u0442\u0430\u043b\u043a\u0438\u0432\u0430\u0435\u043c\u0441\u044f \u0441 \u043d\u0435\u043f\u043e\u043d\u0438\u043c\u0430\u043d\u0438\u0435\u043c \u0440\u0430\u0437\u043d\u0438\u0446\u044b \u043c\u0435\u0436\u0434\u0443 \u044d\u0442\u0438\u043c\u0438 \u043a\u043b\u0430\u0441\u0441\u0430\u043c\u0438 \u0441\u0440\u0435\u0434\u0441\u0442\u0432 \u0437\u0430\u0449\u0438\u0442\u044b. \u0414\u043b\u044f \u044d\u0442\u043e\u0433\u043e \u043d\u0430\u0448\u0438 \u043a\u043e\u043b\u043b\u0435\u0433\u0438 \u0438\u0437 Xello Deception (\u043f\u0435\u0440\u0432\u044b\u0439 \u0440\u043e\u0441\u0441\u0438\u0439\u0441\u043a\u0438\u0439 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a Deception \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b) \u0440\u0435\u0448\u0438\u043b\u0438 \u043f\u043e\u0434\u0440\u043e\u0431\u043d\u043e \u043e\u043f\u0438\u0441\u0430\u0442\u044c \u043e\u0442\u043b\u0438\u0447\u0438\u044f, \u043f\u0440\u0435\u0438\u043c\u0443\u0449\u0435\u0441\u0442\u0432\u0430 \u0438 \u0430\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u0443\u0440\u043d\u044b\u0435 \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u044d\u0442\u0438\u0445 \u0440\u0435\u0448\u0435\u043d\u0438\u0439. \u0420\u0430\u0437\u0431\u0435\u0440\u0435\u043c\u0441\u044f \u0447\u0442\u043e \u0436\u0435 \u0442\u0430\u043a\u043e\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":96261,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-96260","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0430 \u0425\u0430\u0431\u0440\u0435 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0441\u0442\u0430\u0442\u0435\u0439 \u043f\u0440\u043e \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/honeypot-vs-deception-na-primere-xello\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Honeypot vs Deception \u043d\u0430 \u043f\u0440\u0438\u043c\u0435\u0440\u0435 Xello | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0430 \u0425\u0430\u0431\u0440\u0435 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0441\u0442\u0430\u0442\u0435\u0439 \u043f\u0440\u043e \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/honeypot-vs-deception-na-primere-xello\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-10-09T17:42:45+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-10-09T17:42:45+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Honeypot vs Deception using Xello as an Example | ProHoster","description":"There are already several articles about the technologies on Habr.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/honeypot-vs-deception-na-primere-xello","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Honeypot vs Deception \u043d\u0430 \u043f\u0440\u0438\u043c\u0435\u0440\u0435 Xello | ProHoster","og:description":"\u041d\u0430 \u0425\u0430\u0431\u0440\u0435 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0441\u0442\u0430\u0442\u0435\u0439 \u043f\u0440\u043e \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/honeypot-vs-deception-na-primere-xello","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-10-09T17:42:45+00:00","article:modified_time":"2020-10-09T17:42:45+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"96260","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 10:47:23","updated":"2022-09-29 10:28:45","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/96260","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=96260"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/96260\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/96261"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=96260"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=96260"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=96260"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}