Are honeypots legal? It depends on who you ask. You have to consider the following liabilities:
- Can the attacker use the honeypot to attack other organizations? Will you be responsible if this does happen?
- If you prosecute the intruder, will the intruder say that you entrapped them?
- (Training) Do you have the trained personnel to make sure the honeypot is not used as a cyber weapon against organizations?
If you deploy a honeypot, you should get legal advice. If you are given a green light, you must control the honeypot and monitor it daily. Honeypots are created with any server operating system that has logging enabled. Triggers should be set when key stages are 'hacked' in order to notify key network personnel. Firewalls and logs should be examined as often as possible and the validity of having a honeypot in place should be reviewed often during your operating year.