DRACO: Production Network Deployment and Evaluation of Deceptive Defense As-a-Service
Mathieu Couillard, Britta Hale · 2024
Cybersecurity increasingly involves not only passive security measures, but also an active approach to network defense whereby network managers can potentially gain an a priori view of potential threats. Honeypots have long offered one such active measure through cyber deception, but present realistic deployment challenges in government contexts due to increased security risks (internal honeypots) or disassociation with the real network (external honeypots). Furthermore, while various deployment methods have been proposed, organizational management agreement for deployment of honeypots on real, operational networks is a common research obstacle, leading to a lack of insight about actual use on such systems. In this work, we deploy and analyze a honeypot architecture concept, Deceptive Resistance to Adversary Cyber Operations (DRACO) – a live network honeypot for a government associated network. DRACO strikes a balance between external and internal honeypot placement, successfully mitigating risk and enabling system security management approval. We validate the concept, with analysis showing a difference in adversarial activity on DRACO, as connected to a live government-operated network, versus control honeypot deployments and provides insight on potential honeypot deployment without risk to production networks.