‘It's Not Paranoia If They're Really After You’: When Announcing Deception Technology Can Change Attacker Decisions
| dc.contributor.author | Reeves, Andrew | |
| dc.contributor.author | Ashenden, Debi | |
| dc.date.accessioned | 2024-12-26T21:05:17Z | |
| dc.date.available | 2024-12-26T21:05:17Z | |
| dc.date.issued | 2025-01-07 | |
| dc.description.abstract | As organisations continue to adopt deception technology, adversaries are becoming aware of this technology. Little is known, however, about how this awareness changes the attacker’s behaviour as they navigate a victim's network. Concurrently, work is being done to build algorithms that predict attacker paths to recommend where to place deceptive assets, but it is not clear whether attacker awareness of deception alters their behaviour sufficiently to render these algorithms ineffective. We present an ongoing mixed method study to better understand how attackers move through a network when they are aware of the presence of deception. Thematic analysis of think-aloud sessions revealed three key decision-making themes. Themes suggest that several industry heuristics for the use of decoys may be inaccurate and impact the efficacy of decoy placement strategies. In addition, effect sizes indicate that awareness of deception leads attackers to take longer paths through the network, although no more decoys were required to detect them. | |
| dc.format.extent | 10 | |
| dc.identifier.doi | https://doi.org/10.24251/HICSS.2025.130 | |
| dc.identifier.isbn | 978-0-9981331-8-8 | |
| dc.identifier.other | 5e1897a8-e589-40bd-b84d-1f9f16cfab54 | |
| dc.identifier.uri | https://hdl.handle.net/10125/108969 | |
| dc.relation.ispartof | Proceedings of the 58th Hawaii International Conference on System Sciences | |
| dc.rights | Attribution-NonCommercial-NoDerivatives 4.0 International | |
| dc.rights.uri | https://creativecommons.org/licenses/by-nc-nd/4.0/ | |
| dc.subject | Cyber Deception and Cyberpsychology for Defense | |
| dc.subject | active defence, cyber deception, honeypots, mixed-methods research | |
| dc.title | ‘It's Not Paranoia If They're Really After You’: When Announcing Deception Technology Can Change Attacker Decisions | |
| dc.type | Conference Paper | |
| dc.type.dcmi | Text | |
| prism.startingpage | 1082 |
Files
Original bundle
1 - 1 of 1
