Skip to main content

Building a nation-scale evidence base for cyber deception

The NCSC is inviting UK organisations to contribute evidence of cyber deception use cases and efficacy to support our long-term research goals.
,
iStock.com/jossnatu

During discussions, it became clear that ‘deception’ has connotations which can be uncomfortable for some. It is important to acknowledge this, and although there are wider definitions of cyber deception in military and other contexts, they differ to the technology we are referring to here. So for our policy, legal and executive colleagues, when we use these terms in a cyber security context, we mean: 

  • Tripwires: components and systems designed to detect a threat actor, by interacting with them to disclose their unauthorised presence in an environment which include honeytokens. 
  • Honeypots: components and systems designed to allow a threat actor to interact with them, allowing observation of their techniques, tactics and procedures, as well as the capability and infrastructure they use – with the aim of collecting cyber threat intelligence.
  • Breadcrumbs: digital artefacts distributed in a system that entice a threat actor to interact with a tripwire and/or honeypot. 

It's also worth noting that we are aware of wider thinking and approaches designed to produce synthetic behaviours and content, with the aim of degrading an adversary’s efficacy objective, through effects and other means. But this is not our focus, as these approaches and intents are out of scope for our cyber security use cases.





Written by

Ollie Whitehouse Chief Technology Officer (CTO), NCSC
Harry W

Published