Fishing for Hackers: Analysis of a Linux Server Attack (2014)
sysdig.com
sysdig.com
It seems like the last time I looked into this, precedents were not well established. In school, we avoided the issue by only doing exercises on virutualized networks not routed to the real internet.
I have been tempted to do this sort of thing myself, but I am uneasy about it. This would seem more defensible under the auspices of protecting a private business owned network, behind other layers of security, and one would also be backed by an organization with deep pockets and skin in the game. Doing this alone with willfully mis-configured servers on the public internet seems to rely on luck, in the hope that the attackers won't attract the attention of anyone important...
https://labs.mwrinfosecurity.com/blog/high-interaction-honey...
Honeypots are good fun. This book introduced me to them many years ago at university.