The US Cybersecurity and Infrastructure Security Agency (CISA) has published new guidance encouraging critical infrastructure organizations to use cyber decoys as an additional layer of defense against sophisticated attackers.
The guidance explains how organizations can deploy deceptive systems, accounts and data to detect intruders, monitor their activities and collect valuable cyber threat intelligence without making major changes to existing security architectures.
Cyber Decoys Add Another Layer to Zero Trust
CISA describes cyber decoys as systems, accounts or information designed to look legitimate but are deliberately created to attract or identify malicious activity.
The approach complements Zero Trust security models. While Zero Trust continuously verifies users, devices and access requests, cyber decoys operate on the assumption that an attacker may already have obtained some level of access to an organization’s environment.
Once an adversary interacts with a decoy, defenders can receive high-confidence alerts and gain additional visibility into the attacker’s techniques, objectives and movement.
According to CISA, decoy technologies can help organizations detect malicious activity earlier, collect threat intelligence and direct defensive resources toward genuine threats.
Decoys Can Be Deployed Without Major Infrastructure Changes
CISA says cyber deception techniques can be introduced incrementally and scaled according to an organization’s needs.
For effective deployment, decoys should generally be positioned in locations where legitimate users have little reason to interact with them. This helps reduce false positives and makes activity involving a decoy more suspicious.
Organizations can also configure decoys to redirect attackers toward non-sensitive information or controlled environments. This can interfere with reconnaissance by creating a misleading picture of the network while giving defenders an opportunity to observe attacker behavior.
Decoy data can also be designed to consume an attacker’s time and resources without exposing genuine business information.
Lures, Honeytokens and Honeypots
The CISA guidance covers several cyber deception techniques, including:
- Lures designed to attract attackers toward controlled resources
- Tripwires that generate alerts when suspicious activity occurs
- Decoy artifacts that imitate legitimate files or information
- Honeytokens that appear to be valuable credentials or data
- Honeypots that provide controlled environments for observing attackers
These technologies can be combined to create additional detection opportunities across an organization’s environment.
Three-Phase Approach to Cyber Deception
CISA recommends treating cyber decoy deployment as an operational process consisting of three broad phases: preparation, execution and understanding.
During preparation, security teams should assess their threat landscape, establish clear objectives and determine how they want potential attackers to perceive and interact with the environment. Organizations should also identify deployment methods and establish measurable indicators of success.
The execution phase involves deploying and operating the selected deception technologies while monitoring activity generated by them.
The final understanding phase focuses on analyzing collected information and turning it into actionable intelligence. Organizations should also evaluate what worked, identify shortcomings and use those findings to improve future deployments.
Helping Defenders Detect Attackers Using Legitimate Tools
CISA says cyber decoys can be particularly useful against attackers who attempt to remain difficult to detect by using legitimate credentials, built-in administrative tools and so-called living-off-the-land techniques.
Such methods can allow threat actors to perform network discovery, move laterally and access information while generating fewer obvious indicators of compromise.
By introducing carefully designed deceptive resources, defenders can create additional opportunities to identify this behavior and gather intelligence about an intruder’s activities.
Guidance Targets Organizations at Different Security Maturity Levels
CISA said the new guidance is intended for defensive teams with varying levels of cybersecurity maturity.
The document provides information on the benefits and deployment considerations associated with different types of cyber decoys, along with example scenarios designed to demonstrate how deception techniques can be incorporated into security operations.
For critical infrastructure organizations facing increasingly sophisticated intrusion techniques, cyber deception can provide an additional source of high-fidelity detection and threat intelligence while complementing existing security controls.