New Cyber Tech – Deception Technologies
It's a sad fact that there is an arms race between IT security teams protecting businesses, and the organised cybercriminals who seek to bypass security and illegally access data. The attack surface that is used to probe defences is ever-changing, and with the increase in IoT and 5G based systems, ever-expanding.
We have written about protecting this attack surface in the past, and also discussed it in our seminars and partner events. Maintaining a secure and updated network perimeter is vital to protecting users, systems, and data. However, with the evolving threat landscape, there may come a time when defences are penetrated, and cybercriminals get access to internal networks and the systems residing there. Protection mechanisms that are designed to detect, nullify, and notify of any breaches like this are emerging. They are known as deception technologies.
Deception technologies (DT) place dummy systems on the internal network that mimic the behaviours that real applications, authentication servers, and data stores would do. The user credentials and data that are on these systems are not real but are designed to be targeted for attackers to access, so they think they have successfully penetrated a network's defences. Some people refer to DT dummy systems as honey traps. For obvious reasons!
DT is rapidly becoming an essential tactic in a layered cybersecurity strategy. As outlined below, they allow faster detection of breaches, account for many unknown zero-day exploits, and allow security professionals to secretly monitor and analyse current attack methods to protect real production systems and data better.
Renaissance and out security partners can help you design, deploy, and monitor a comprehensive DT system to enhance your security protection. Contact us to discuss your needs or to find out more.
Fooling the Cybercriminals
Deploying DT and allowing cybercriminals to find and access them within a network requires that the dummy system seem authentic. The attackers should think they have access to real data even when they don't. DT systems should mimic the typical systems that exist on a network. Such as directory servers for credentials, application servers, databases, file stores, and also IoT integration servers that look like they are in communication with devices and sensors outside the network. It is essential to cover all the bases when using decoy systems. That way, all types of attacks can be detected and trapped.
Keeping the data and the users on the dummy systems fresh and dynamic is crucial. So that attackers who have penetrated the perimeter defences and accessed the DT decoys continue to think they are on real systems. Increasingly AI and machine learning (ML) technologies are being used to simulate user activity and to change data on DT decoys. Using ML means that IT staff are not tied up on this task.
Reduce the Security Noise
Regular users will never access DT systems. Only IT staff, possibly ML systems, and attackers will ever access them. This allows alerts to be put in place to let security teams know when a decoy system or account is used. There is data to suggest that the average time between a successful cyberattack getting access to a system and discovery of the breach is 100 days. Having DT decoys in place that report all activity allows the time to detection to mostly drop to zero. Only attackers will be accessing the systems in an unplanned way, so any access is a breach and can be notified as such. This also means that the alerts that security teams get are high fidelity and are high in information, making them much easier to action.
Get Better Security Data
The fast reporting and data on attacks mean that security teams have a choice on how to respond to a breach and access on a DT decoy. They can let the attacker proceed to access the DT system and see what attack methods they are using, or they can cut the attack off immediately. Monitoring the attack vectors in use allows for in-depth analysis and also delivers the ability to ensure that the production systems are protected from the attack methods.
This is true for both known attacks and newly emerging attack vectors. If DT systems are accessed using a novel method, then it can be allowed to proceed on the dummy systems, and valuable data gathered to apply on production systems to protect them.
Conclusion
Deception technologies and defence postures are becoming mainstream. They provide an excellent way to detect breaches to perimeter security and also provide a way to analyse attack methods, which in turn provides the knowledge needed to protect production systems and data better. Contact us to find out more.

