| | JULY 2022ENTERPRISE SECURITY8IN MY OPINIONIN MY OPINIONDeception Systems or Honeypots are systems that are designed to be intentionally desirable to attackers while safely alerting defenders to malicious activity. Five or ten years ago I viewed Deception Systems as primarily useful to research-based organization, threat intelligence providers, and the hobbyist. While there was a role for them in an enterprise environment, tooling like EDR or Application Control was the priority. In the last few years, the offerings and opportunities for Deception Systems have matured significantly and should be reconsidered. A driving factor behind this maturation and subsequently the need for Deception Systems in enterprise environments is the continued evolution of attackers. Attackers have time and again demonstrated the ability to breach environments with sophisticated security programs and go undetected. In addition, the risk of supply chain compromise similar to the SolarWinds breach, continues to rise. Finally, there are threat actors out there who have become comfortable targeting and thriving in systems that can't be instrumented with EDR and other controls. This could include HVAC systems, thermostats, IOT devices, and other non-traditional targets (even a fish tank thermometer) where the Security Team has low visibility. There are two value propositions worth considering immediately when looking at Deception Systems. The first is in securing third-party points of ingress into your environment, and the second is developing early warning systems for Ransomware. Third party due diligence has become an increasingly challenging proposition for Security Teams. How do you ensure every aspect of every service your organization uses is fully vetted and secure? Especially when considering the case of a North American Casino breached through their fish tank thermostat. There isn't the time or resources to complete the due diligence required for every service an organization uses. As a result, its important to adopt a mindset shift. There is a realistic possibility an attacker's first foothold into your organization can occur through a third-party product, service, or point of ingress. That knowledge can empower your defensive strategy. Consider an environment where Deception Systems have been deployed in close proximity to points of third-party ingress. If an attacker breaches your environment through a non-instrumented Internet of Things (IOT) device, their next step is likely persistence and lateral movement. What if there was an intentionally vulnerable server or simulated Domain Controller in the same local IP space? An attackers first few moments of lateral movement, could result in the triggering of a Deception System. This type of high-fidelity alert can immediately let your Security Operation Center By Brenden Smith, Chief Information Security Officer, FirstBankRETHINKING DECEPTION SYSTEMS IN TODAY'S ENTERPRISEBrenden Smith
<
Page 7 |
Page 9 >