Autonomous Deception - Preventing Lateral Movement
Proactive cybersecurity defence is essential when combatting threats from cybercriminals and their unending cyberattacks. Keeping up with the rapidly changing attack surface and risk factors is now probably beyond most people. The volume of data involved and the speed at which attacks proceed and spread requires countermeasures that operate at the same speed and scale.
Thankfully the cybersecurity experts on the good side of the cyberwar can use the computing tools that exist just like the bad guys do. Cybersecurity tools based on sensors that monitor the network, and using machine learning to interpret the data, are an excellent way to stay on top of the deluge of information that needs to be watched to detect and deal with cyberattacks. Coupled with suitable automated actions and backed by expert level human cybersecurity experts.
Acalvio is a pioneer in active defence strategies, leveraging innovations in distributed deception, artificial intelligence, and threat analysis. They enable high-fidelity actionable detection and attacker dwell time reduction, while avoiding false positives and alert fatigue. Renaissance and Acalvio partner to deliver the industry-leading ShadowPlex and ShadowPlex Cloud solutions in the Ireland marketplace. Contact us today to find out how Acalvio's solutions can boost your cyber-defence and response. Read on for an overview of the ShadowPlex solution.
Active Defence
Traditionally the deployment of passive and mostly static cybersecurity defences has been the norm. Using items such as firewalls, anti-virus, endpoint protection, and static log monitoring to look for anomalies. While these solutions could work well in some instances, the problem is that attackers could probe for weaknesses at their leisure. When a vulnerability was discovered (or came to light somewhere else), the attackers could target it and bypass defences. As the adage goes, they only need to be successful once.
What's required today to reduce risk and counter the evolving threat landscape is active defence. Active defence blends cybersecurity tactics that can dynamically modify the defence posture based on what's happening right now on the network. The diagram below outlines various actions that active defence uses.
Acalvio are pioneers in these active defence measures. Using industry innovations in distributed deception, artificial intelligence, and threat analysis, they enable high-fidelity actionable detection and attacker dwell time reduction while avoiding false positives that can cause alert fatigue and undetected attack vectors.
ShadowPlex Autonomous Deception
ShadowPlex Autonomous Deception is Acalvio's industry-leading solution for Enterprise IT, IoT, and ICS environments to deliver:
- Accurate detection
- Timely detection
- Cost-effective detection
All three of these detection metrics are crucial for an autonomous deception solution that can fool attackers and protect production IT systems. Deception solutions place dummy systems on the network that are shadows that mimic the actual servers and applications in use. ShadowPlex does this using deception farms. These use sensors within on-premise and Cloud-based IT deployments to build a shadow network that looks like the real thing, but that has none of the data and other valuable assets to cybercriminals. See the diagram below for a schematic overview of deception farms.
Deception farms is an innovation that delivers scale and adaptability. Sensors are placed in the network segments. All decoys are born and live in a centralised virtual server farm. These dummy systems trap the attackers into thinking they are on real servers, and this prevents them or any malware they deploy from moving laterally on the network to impact real systems. ShadowPlex also uses Fluid Deception to achieve resource efficiency by using just in time decoy creation, minimising costs, and maximising effectiveness.
Integration with other Cybersecurity Tools
ShadowPlex provides comprehensive API support allowing deception technology to be orchestrated from other security tools and environments. This also facilitates integration with 3rd party security tools such as:
- Threat Intelligence
- IT Change Management platforms
- SOAR (Security Orchestration and Response)
- Security Information and Management (SIEM) systems
- Perimeter Defence solutions
- Network Access Control (NAC)
- Vulnerability Managers
- Single Sign-On (SSO), Identity Management, Privileged User Management Systems
- Endpoint Detection and response
Conclusion
Active defence using autonomous deception should be high on your cybersecurity strategy. Acalvio and Renaissance have the tools to deliver an industry-leading solution for organisations of all sizes. Contact us to find out more.

