Skip to content

Honeypot experiment

Limitations and pitfalls

Where the data is weak, it is better said up front. This page lists collection outages, traffic that did not come from attackers, mistakes that are easy to make in analysis, and conclusions two servers over one month cannot support.

Data updated: 2026-10-03 10:31:16 UTC+02:00

Report a problem

Known gaps in the data #


Windows in which something did not collect, or data did not reach every destination. The list is generated from the incident analyses and never maintained by hand – each gap links to the incident that caused it. The files from the archive are the source of truth, not the counts in the live syslog.

FromToLengthServersStreamRecoverableRecoveredIncident
2026-08-22 00:15:21 UTC2026-08-22 11:31:30 UTC11 h 16 minsrv3pcap (eth0) — ještě neběželnonot recovered2026-08-22-srv3-pcap-ring-buffer-snaplen
2026-08-22 11:31:30 UTC2026-08-22 11:35:51 UTC4 minsrv3pcap (eth0) — přepsáno po rebootunonot recovered2026-08-22-srv3-pcap-ring-buffer-snaplen
2026-08-22 15:40:00 UTC2026-08-24 18:51:21 UTC2 d 3 hsrv3webtrap-https (443/tcp)nonot recovered2026-08-22-srv3-webtrap-https-tls-accept-hang
2026-08-24 16:18:29 UTC2026-08-24 18:48:28 UTC2 h 30 minsrv3dionaea (všechny emulované protokoly)nonot recovered2026-08-24-srv3-dionaea-mongod-parser-freeze
2026-08-25 09:41:00 UTC2026-08-25 10:04:00 UTC23 minsrv3dionaea (všechny emulované protokoly)nonot recovered2026-08-24-srv3-dionaea-mongod-parser-freeze
2026-08-27 00:33:00 UTC2026-08-27 00:54:00 UTC21 minsrv3dionaea (všechny emulované protokoly)nonot recovered2026-08-24-srv3-dionaea-mongod-parser-freeze
2026-08-27 18:33:00 UTC2026-08-27 18:54:00 UTC21 minsrv3dionaea (všechny emulované protokoly)nonot recovered2026-08-24-srv3-dionaea-mongod-parser-freeze
2026-08-28 08:48:00 UTC2026-08-28 09:09:00 UTC21 minsrv3dionaea (všechny emulované protokoly)nonot recovered2026-08-24-srv3-dionaea-mongod-parser-freeze
2026-08-28 12:08:00 UTC2026-08-28 12:31:00 UTC23 minsrv3dionaea (všechny emulované protokoly)nonot recovered2026-08-24-srv3-dionaea-mongod-parser-freeze
2026-08-28 12:34:00 UTC2026-08-28 13:01:00 UTC27 minsrv3dionaea (všechny emulované protokoly)nonot recovered2026-08-24-srv3-dionaea-mongod-parser-freeze
2026-08-28 18:52:50 UTC2026-09-16 00:00:00 UTC18 d 5 hsrv3dionaea SIP (5060) — emulace vypnutanonot recovered2026-08-24-srv3-dionaea-mongod-parser-freeze
2026-08-28 20:42:00 UTC2026-08-28 20:51:30 UTC10 minsrv3dionaea (všechny emulované protokoly)nonot recovered2026-08-24-srv3-dionaea-mongod-parser-freeze
2026-08-31 13:13:40 UTC2026-08-31 13:26:04 UTC12 minsrv3dionaea (všechny emulované protokoly)nonot recovered2026-08-24-srv3-dionaea-mongod-parser-freeze
2026-08-31 14:12:42 UTC2026-08-31 14:22:03 UTC9 minsrv3dionaea (všechny emulované protokoly)nonot recovered2026-08-24-srv3-dionaea-mongod-parser-freeze
2026-08-31 16:35:03 UTC2026-08-31 16:46:09 UTC11 minsrv3dionaea (všechny emulované protokoly)nonot recovered2026-08-24-srv3-dionaea-mongod-parser-freeze
2026-09-01 04:10:00 UTC2026-09-01 04:20:29 UTC10 minsrv3dionaea (všechny emulované protokoly)nonot recovered2026-08-24-srv3-dionaea-mongod-parser-freeze
2026-09-01 07:22:00 UTC2026-09-01 07:32:36 UTC11 minsrv3dionaea (všechny emulované protokoly)nonot recovered2026-08-24-srv3-dionaea-mongod-parser-freeze
2026-09-01 07:57:00 UTC2026-09-01 08:03:21 UTC6 minsrv3dionaea (všechny emulované protokoly)nonot recovered2026-08-24-srv3-dionaea-mongod-parser-freeze
2026-09-02 08:16:00 UTC2026-09-02 08:26:03 UTC10 minsrv3dionaea (všechny emulované protokoly)nonot recovered2026-08-24-srv3-dionaea-mongod-parser-freeze
2026-09-07 17:35:36 UTC2026-09-07 17:44:17 UTC9 minsrv3dionaea (všechny emulované protokoly)nonot recovered2026-08-24-srv3-dionaea-mongod-parser-freeze
2026-09-07 18:23:40 UTC2026-09-07 18:26:20 UTC3 minsrv3dionaea (všechny emulované protokoly)nonot recovered2026-08-24-srv3-dionaea-mongod-parser-freeze
2026-09-07 20:06:16 UTC2026-09-07 20:07:03 UTC1 minsrv3dionaea (vsechny emulovane protokoly)nonot recovered2026-09-07-srv3-deliberate-dionaea-freeze-repro
2026-09-13 04:22:00 UTC2026-09-13 05:01:50 UTC40 minsrv3 srv4syslogyesfrom the archiveControl channel outage

Source: the data_gaps of every incident in Incidents

Own traffic to filter out #


Not everything in the data comes from attackers. These values belong to monitoring and to tests during deployment, and should be excluded before analysis.

Some records have been translated from Czech into English and are labelled as translations. The Czech originals are authoritative.
Field Value Period Description
src_ip 169.58.205.217 whole run Watchdog probes from srv3. translated
path /hp-watchdog-probe whole run The path the watchdog probes request. translated
user_agent hp-watchdog whole run User-Agent of the watchdog probes. translated
src_ip 127.0.0.1 2026-08-21 — 2026-08-22 Test data from deployment. translated
src_ip 10.222.0.0/24 2026-08-21 — 2026-08-22 Test data from deployment. translated

Analysis pitfalls #


Mistakes that are easy to make with this data – how to spot them and how to avoid them.

  • The ::ffff: prefix on IPv4 addresses cowrie writes IPv4 addresses as ::ffff:203.0.113.5. Unless the prefix is stripped, the same attacker is counted twice – once from cowrie and once from the other sensors.
  • Redirected ports on srv4 On srv4, cowrie sees ports 42222 and 42223 and hpweb sees 42280 and 42443. These are not the ports the attacker aimed at but the nftables redirect target. Only hptcp knows the real destination port. For cowrie and hpweb on srv4, ignore the port or derive it from the session.
  • Own traffic Monitoring probes, test data from deployment and diagnostic commands by agents and the operator. The concrete values to filter out are in the table above.
  • Campaigns Single campaigns could produce most of a day’s traffic. Without separating campaigns from baseline noise, a volume chart looks like a trend or a collection outage.
  • Event time, not processing time For time-based analysis use the timestamp inside the event. Log copies on the collection server also carry a receive time that can be hours or days later.
  • Incomparable servers srv4 exposed a surface orders of magnitude larger than srv3. Absolute counts of the two servers cannot be compared, only their structure and ranking.
  • Format changes during the run The agents adjusted configuration during checks, so the format of some records may have changed mid-run. Specific changes will be added after going through the data; their trace is in the run log.

What the data cannot tell you #


The limits of what this data can support are best stated up front.

  • Two servers are not statistics The results describe what reached two particular servers. General conclusions about the whole internet cannot be drawn from them.
  • One provider, one location Both servers ran at the same provider. Attackers target address ranges differently, and elsewhere the traffic could look different.
  • Less than a month The run captured the campaigns that happened to be active – not long-term trends or seasonality.
  • An address’s country is not the attacker’s origin Geolocation says where a source address is registered. Attacks routinely go through rented servers, proxies and compromised devices, so the address’s country does not tell you where the attacker comes from.
  • Comparing language models Each server was run by a different model, but two runs are not enough to judge which model is better. Differences in the data can have many causes, from the exposed surface to individual technical decisions.

How the data is prepared for publication #


Under the GDPR a source IP address is personal data. It was collected in full for analysis and appears in the results only in aggregate.

How the published raw data is pseudonymised, and what is lost in the process, will be described when the data is published.