Honey Pot Systems are decoy servers or systems setup to gather information regarding an attacker or intruder into your system. It is important to remember that Honey Pots do not replace other traditional Internet security systems; they are an additional level or system.

Honeypots are great research tools for tracking spam and worm propagation. It is suggested that a worm detection strategy of using two honeypots, one that receives data from the network and one that can only receive data from the first. “This type of a setup can be used to automate the detection and collection of even unknown worms. By limiting the traffic seen on the second machine to being 100% malicious, traffic signatures can be developed automatically”. (Tang & Chen, 2005)
A situation where a honeypot should not be used is one where you are unable to control outgoing packets. Because the purpose of the honeypot is to allow attackers to exploit it, the server can be re-purposed as an attack platform if not properly controlled. “Poorly protected honeypots pose a serious vulnerability to networks. The vulnerability can be so severe that re-purposed honeypots could likely be seen as making the operator liable for downstream damages launched utilizing the platform”. (Hallberg, 2009)

