Cybersecurity Deception Experimentation System

Jaime C. Acosta, Anjon Basak, Christopher D. Kiekintveld, Nandi Leslie, Charles Kamhoua · 2020

Cybersecurity deception research has had many successes in recent years. While early cyber deception systems (e.g., honeypots) were largely static, recent approaches leverage computational game theory and machine learning techniques to allow for dynamic deception strategies that can potentially observe, react, and adapt to an adversary in both the short and long term. However, applying these theoretical models and algorithms in real-world settings poses additional considerations that are not always apparent in theory. Currently, testbeds and experimentation platforms for dynamic deception are lacking, limiting the ability of researchers and analysts to test and evaluate these approaches using realistic scenarios and data. Honeypots are a technology where these dynamic deception methods can have a great impact on effectiveness. The basic technology to mimic nodes and network services has been used for several decades and is effective against less experienced adversaries, but is less useful against sophisticated intruders. Using adaptation, behavior-based model development and reasoning and other artificial intelligence techniques have the potential to make honeypots much more effective against experienced adversaries by making them less predictable and more targeted. Before these novel technologies can be used in the real world, it is critical that they are tested and validated on realistic systems and in realistic settings. We present the Cybersecurity Deception Experimentation System (CDES) that extends the Common Open Research Emulator (CORE) to provide a platform that is capable of evaluating dynamic deception algorithms. We also provide three case studies that demonstrate how CDES can be used to practically implement dynamic honeypots in increasingly complex scenarios and discuss some nuances of each implementation.

Read the paper · More papers on PaperTik