Sludge for Good: Slowing and Imposing Costs on Cyber Attackers

dc.contributor.authorDykstra, Josiah
dc.contributor.authorShortridge, Kelly
dc.contributor.authorMet, Jamie
dc.contributor.authorHough, Douglas
dc.date.accessioned2024-12-26T21:05:18Z
dc.date.available2024-12-26T21:05:18Z
dc.date.issued2025-01-07
dc.description.abstractChoice architecture describes the design by which choices are presented to people. Nudges are an aspect intended to make “good” outcomes easy, such as using password meters to encourage strong passwords. Sludge, on the contrary, is friction that raises the transaction cost and is often seen as negative by users. Turning this concept around, we propose applying sludge for positive cybersecurity outcomes by using it offensively against attackers to consume their time and other resources. Most cyber defenses have been designed to be optimally strong and effective and prohibit or eliminate attackers as quickly as possible. Our complementary approach is to deploy defenses that seek to maximize the consumption of attackers’ time and other resources while causing as little damage as possible to the victim. This approach is consistent with zero trust and similar mindsets which assume breach. The Sludge Strategy introduces cost-imposing cyber defense by strategically deploying friction for attackers before, during, and after an attack using deception and authentic design features. We present the characteristics of effective sludge and show a continuum from light to heavy sludge. We describe the quantitative and qualitative costs to attackers and offer practical considerations for deploying sludge in practice. Finally, we examine real-world examples of U.S. government operations to frustrate and impose costs on cyber adversaries. We encourage research and further exploration of how sludge can slow attackers
dc.format.extent10
dc.identifier.doihttps://doi.org/10.24251/HICSS.2025.132
dc.identifier.isbn978-0-9981331-8-8
dc.identifier.othere51cd649-6afc-4c15-9381-bd76370395c0
dc.identifier.urihttps://hdl.handle.net/10125/108971
dc.relation.ispartofProceedings of the 58th Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectCyber Deception and Cyberpsychology for Defense
dc.subjectchoice architecture, cybersecurity, deception, nudge, sludge
dc.titleSludge for Good: Slowing and Imposing Costs on Cyber Attackers
dc.typeConference Paper
dc.type.dcmiText
prism.startingpage1102

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
0109.pdf
Size:
199.33 KB
Format:
Adobe Portable Document Format