Deception Technology
What is deception technology?
Deception technology is a category of incident detection and response technology that helps security teams detect, analyze, and defend against advanced threats by enticing attackers to interact with false IT assets deployed within your network. The deception approach can give you high-fidelity alerts around specific malicious behaviors, many of which are challenging to identify by log analysis or a SIEM tool alone. The benefit: You can identify suspicious activity early in an attack chain, as well as confuse and misdirect an adversary on your internal network. This page will give an overview of deception technology and dive into three examples: honeypots, honey users, and honey credentials.
Get your intel directly from the experts.
We are sharing all the latest and greatest cybersecurity knowledge in our webcasts, events, demos and more–come join us.
Overview of deception technology
Whether you want to picture deception technology as a worm dangling on a fish hook, a chunk of cheddar hidden in a mousetrap, or the notes of an enticing siren song luring sailors to their death, the message is the same: Deception technology is bait. By setting irresistible traps that appear to be legitimate IT assets, it entices attackers on your internal network to interact with them, triggering an alert and giving your team the time, insight, and context they need to respond effectively. Because no one within your organization needs to interact with deception technology as part of their job, any activity it records is automatically suspicious. Therefore, a key benefit of deception technology is high-fidelity alerts that identify very specific malicious behaviors.
Deception technology can reduce attacker dwell time on your network, speed up mean time to detect and remediate, reduce alert fatigue, and provide vital information around indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs).
Honey users
Honeypots are decoy systems or servers that are deployed alongside production systems within your network. They can look like any other machine on the network or be deployed to look like something an attacker could target. There are many applications and use cases for honeypots, as they work to divert malicious traffic away from important systems, identify anomalous network scans, and reveal information about attackers and their methods.
In terms of objectives, there are two types of honeypots. Research honeypots gather information about attacks and are used specifically for studying malicious behavior out in the wild. Looking at both your environment and the wider world, they gather information on attacker trends, malware strains, and vulnerabilities that are actively being targeted by adversaries. This can inform your preventive defenses, patch prioritization, and future investments.
Production honeypots, deployed on your network, help reveal internal compromise across your environment and gives your team more time to respond. Information gathering is still a priority, as honeypots give you additional monitoring opportunities and fill in common detection gaps around identifying network scans and lateral movement.
Straightforward and low-maintenance, honeypots help you break an attack chain and slow adversaries down with high-fidelity alerts and contextual information. Interested in learning more about honeypots? Check out our page on honeypot technology.
