Skip to content

Decide whether FMC-specific inert persona coverage adds value beyond existing ASA and HTTP decoys #3214

Description

@Xore

Follow-up to #3180. Research proposal, not implemented or live-validated.

F3 — P2 decision, not exploit emulation

Title: Decide whether FMC-specific inert persona coverage adds value beyond existing ASA and HTTP decoys

Labels: security, honeypot, decision, enhancement

Proposal: Document the fidelity, isolation, provenance and maintenance requirements for an optional non-vulnerable management persona. Start with a static design/coverage decision; do not implement exploit-specific authentication bypass, object deserialization, command execution, network callbacks or a vulnerable FMC image. Preserve Conpot/Dionaea/ASA behavior and distinguish the product identity explicitly. Scope any future synthetic management actions as simulations with no firewall side effects. A negative decision is an acceptable result.

Safe synthetic-event acceptance criteria:

  • A static surface inventory separates internal listening ports, host publications and intended public routing, with no live probes.
  • A fixture for an ASA event stays ASA; sharing a management port or Cisco branding never changes it to FMC.
  • A proposed FMC event has explicit persona and simulation provenance and uses no real credentials, certificate keys or production names.
  • The decision states which coverage gaps a persona addresses (attraction/context) and which it cannot (real bypass success, actual policy changes).
  • The design prohibits outbound request-following, execution and deserialization, keeps resource limits, and requires separate deployment authorization before exposure.

Snapshot assessed: 00593d1d693cc7fe792beb7d24724dca5f55b2b8. Evidence paths are relative to APIARY. All acceptance tests must be offline and use inert fixtures; no exploitation, credentials, appliance access or deployment is authorized.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    decisionBlocked on an operator decision — question named in the issueenhancementNew feature or requesthoneypotHoneypot sensor or deception technologysecuritySecurity hardening or a security defect

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions