JULY 2022ENTERPRISE SECURITY| | 9(SOC) know something is wrong, and a threat actor is attempting something malicious. A powerful aspect of Deception Systems is that it turns an attacker's interests and objectives against them. This creates an opportunity for defenders to turn targets into Indicators of Compromise. A very relevant example of this is Ransomware. We've seen instances where Ransomware attacks have sought out financial statements or insurance documentation in victim organizations. Using Deception Systems, we can seed our environment with copies of these documents in readily accessible locations. Business units know where to find the real documents and aren't likely to interact with our Deception Systems limiting false positives. However, an attacker looking to leverage these sources are more likely to stumble onto them, alerting the SOC to both the threat actor and their intentions. This can be expanded to include tempting file shares, simulated VMWare servers, or other commonly targeted infrastructure. Functionally you can tie the implementation of the Deception System to the tool, tactic, or procedure you need to detect.These two use cases are just examples, the opportunities to instrument your environment are only limited by your imagination and the threats you face. The net effect of utilizing these types of strategies is that it empowers your SOC to respond faster and with more certainty to threats. It does this while requiring very little maintenance or support to function. Historically most of the Deception Systems that were readily available were Open-Source projects that required some technical skillset to implement and maintain. Today there are commercially available products that are highly streamlined and little to no effort to maintain once implemented. In addition, these products are inexpensive when compared to other solutions Security Teams are commonly pursuing. Open-Source solutions have also progressed significantly and may be worth evaluating alongside of commercial options. In a threat environment where we regularly see Zero Day exploits being exploited and supply chain compromises occurring, Deception Systems are starting to play a bigger role in providing high fidelity alerting. Long term there may be options to negotiate the placement of Deception Systems into third party vendor environments, as part of vendor diligence. Or the ability to deploy entire packages of Ransomware oriented Deception Systems into your environment. For those teams struggling with how to adapt to the current threat environment, its worthwhile to revisit these solutions and see how they might augment your program. ESA POWERFUL ASPECT OF DECEPTION SYSTEMS IS THAT IT TURNS AN ATTACKER'S INTERESTS AND OBJECTIVES AGAINST THEM
<
Page 8 |
Page 10 >