Skip to content

Security2 publishers2 min readPublished

CISA now tells critical infrastructure to plant fake credentials for attackers to trip over

The federal cyber agency now recommends planting fake records, credentials and files across critical infrastructure networks, and its pitch to understaffed teams is that an alert on a decoy needs no analyst to interpret it.

The Watch · Security desk

Illustration accompanying CISA now tells critical infrastructure to plant fake credentials for attackers to trip over

What happened

  • CISA published "Using Cyber Decoys to Strengthen Detection and Response" on Wednesday, its first guidance telling critical infrastructure owners and operators how to set up phony systems, accounts and data.
  • The document runs 22 pages and covers decoy principles and goals, definitions of the different decoy types and how to use them, and deployment scenarios.
  • It introduces tripwires, breadcrumbs and honeytokens, and maps the implementation steps onto the MITRE Engage and MITRE ATT&CK frameworks.
  • Chris Butera, acting executive director of CISA's cybersecurity division, said the guidance came out of internal discussions with the agency's threat hunters and penetration testers.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • capability A team with no hunt capacity gets one alert class it can act on the first time it fires, because nothing in production has a reason to read a planted credential or file.
  • constraint Decoys report after someone is already inside, so they shorten dwell time. Closing the initial access route takes other means.
  • precedent With CISA on record encouraging implementation, assessors, boards and insurers now have a federal baseline to ask against, and operators will be asked what decoys they run without any rule requiring them.

Deception works because a planted record has no legitimate reader. An alert on one does not require a behavioral baseline. CISA's definition in the document is narrow. Honeytokens are "Data elements or logical objects with no legitimate business use (e.g., fake records, credentials, or files) planted to detect unauthorized access or exfiltration. Any interaction strongly suggests malicious or otherwise unauthorized activity" [8].

The case CISA wants covered is the one where behavioral detection has the least to work with. The agency writes that many organizations struggle to detect adversaries who use legitimate credentials, native tools and living-off-the-land techniques to run discovery, move laterally and access data [11]. Decoys, in the guidance's terms, are assets that look like legitimate systems, accounts or data but exist to distract an adversary, detect their presence, or help collect threat intelligence [15]. Under Zero Trust the agency credits them with four things: continuous monitoring and verification, high-fidelity alerts for suspicious activity, reduced alert fatigue, and detection of post-compromise activity including living-off-the-land tradecraft [12].

"We've been looking at it for a while, and we believe that decoys can be both a very low-cost but actually high-fidelity way to detect an adversary who's already gained access to networks," Chris Butera, acting executive director of CISA's cybersecurity division, told CyberScoop at Google Cloud's Cyber Defense Summit 26 [4]. He said the approach is complementary to zero-trust and assume-compromise programs [5]. The guidance is "really relevant for everyone," Butera said, and especially useful in critical infrastructure sectors that do not have the most personnel or money [6]. "This could be something to prioritize as a lower cost solution," he said. "You can create your own honey tokens yourself" [7].

CISA published no detection rates, deployment counts or cost figures for decoy programs. The low-cost, high-fidelity framing rests on Butera and the guide itself. In the news release Butera said decoys "help make critical infrastructure networks unfriendly places for adversaries and enhance resilience to compromise, even against living-off-the-land techniques" [9]. The agency "encourages critical infrastructure organizations to review this guide and implement a cyber decoy strategy" [10]. No date comes with that, and CISA says it will update the document once Section 508 compliance is finished [14].

What to watch

  • Whether CISA turns the encouragement into a directive or folds decoy checks into its free assessment services.
  • Whether the Section 508 update changes the deployment scenarios operators are copying from the current PDF.
  • Whether the guide starts appearing in sector assessment questionnaires and insurer application forms.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories