This systematic review aims to dive into high interaction honeypots for Microsoft SQL Server. Topics covered include various honeypot environments (bare-metal, virtual machine, container) and monitoring methods (network-based, VMM-based, honeypot-based) to understand how to effectively monitor encrypted communications. The main focus is to compare different data monitoring techniques for high-interaction honeypots, especially considering the challenges posed by encrypted protocols such as TDS used by Microsoft SQL Server. This research identifies limitations in current research and proposes the use of encrypted MITM proxies as a potential solution. Ultimately, this research highlights the need for further research in this area due to the limited existing literature on high interaction honeypots for Microsoft SQL Server.
Copyrights © 2025