Building a nation-scale evidence base for cyber deception

The big picture
The NCSC recently brought together international government partners and wider UK government and industry in the first of its kind conference to discuss cyber deception in cyber defence at our headquarters in London.
The motivation behind this event is that we recognise the potential value of using cyber deception technologies and techniques to support cyber defence, in certain situations. We have an ambition to establish an evidence base for use cases of cyber deception and their efficacy, on a national scale, in support Active Cyber Defence 2.0.
As part of this endeavour, we see two primary use cases for the technologies and solutions to provide value in cyber defence:
- low-interaction solutions such as digital tripwires and honeytokens to alert to unauthorised access – when deployed by all organisations
- low-interaction and high-interaction honeypots to collect threat intelligence both at internet scale and as discrete instances – when deployed by organisations with mature security operations capabilities, as well as managed cyber security service providers
During discussions, it became clear that ‘deception’ has connotations which can be uncomfortable for some. It is important to acknowledge this, and although there are wider definitions of cyber deception in military and other contexts, they differ to the technology we are referring to here. So for our policy, legal and executive colleagues, when we use these terms in a cyber security context, we mean:
- Tripwires: components and systems designed to detect a threat actor, by interacting with them to disclose their unauthorised presence in an environment which include honeytokens.
- Honeypots: components and systems designed to allow a threat actor to interact with them, allowing observation of their techniques, tactics and procedures, as well as the capability and infrastructure they use – with the aim of collecting cyber threat intelligence.
- Breadcrumbs: digital artefacts distributed in a system that entice a threat actor to interact with a tripwire and/or honeypot.
It's also worth noting that we are aware of wider thinking and approaches designed to produce synthetic behaviours and content, with the aim of degrading an adversary’s efficacy objective, through effects and other means. But this is not our focus, as these approaches and intents are out of scope for our cyber security use cases.
Defining our objectives with numbers
To establish this evidence base, we plan to collect existing evidence, while at the same time encouraging at-scale deployment within the UK, across government and critical national infrastructure.
We are putting in place specific objectives, to achieve as a minimum:
- 5,000 instances on the UK internet of low and high interaction solutions across IPv4 and IPv6
- 20,000 instances within internal networks of low interaction solutions
- 200,000 assets within cloud environments of low interaction solutions
- 2,000,000 tokens deployed
Contributing to research
Our intention is for this scaled deployment to build an evidence base which can help answer three core research questions. We would like to understand:
- How effective are deployments at supporting the discovery of latent compromises within organisation estates?
- How effective are deployments at supporting the enduring discovery of new compromises by threat actors?
- Does knowledge of the presence of such technologies at a national level cause changes in observable behaviour of threat actors?
Can you help?
We are keen to work with public and private sector organisations in the UK who have deployed solutions as described above. If this is you, we would like you to get in touch, and we are interested in the details of:
- what type, and in what use case and scale
- how integration and any breadcrumbing is carried out
- what outcomes or value deployment had led to including but not limited to:
- the discovery of a latent breach
- the discovery of subsequent breaches
- provided enduring value and cost as a proportion of budget
If you can contribute to this, please contact us at [email protected].
What happens next?
The NCSC will collect the evidence from participating organisations as well as its own experiments, summarise in aggregate, and publish.
Ollie Whitehouse, NCSC CTO
Harry W, NCSC Incident Management Technical Director