CISA's New Advice: Fight Hackers by Feeding Them Fake Data
The Cybersecurity and Infrastructure Security Agency (CISA) has issued its first formal guidance on using cyber decoys, such as fake accounts, systems and data, to trick attackers who have already gained access to a network. The document, titled 'Using Cyber Decoys to Strengthen Detection and Response,' was developed after internal discussions among CISA's threat hunters and penetration testers about low-cost ways to disrupt hackers.
According to Chris Butera, acting executive director of CISA's cybersecurity division, decoys can be a cheap but highly reliable way to spot intruders who have already breached a network. He noted that this approach works well alongside 'zero-trust' security models, which assume no user or device should be automatically trusted, and 'assume-compromise' strategies, which plan for attackers already being inside a network.
The 22-page guidance explains different types of decoys, including 'honeytokens': fake records, credentials or files that have no real business purpose. Because these fake elements should never be accessed legitimately, any interaction with them is a strong sign of malicious activity. CISA highlighted that organisations with limited budgets and staff, such as smaller operators in critical infrastructure sectors, can create these decoys themselves at low cost.