Deception Technology
Deception Technology: Lures attackers using decoy systems, fake credentials, or simulated resources. This capability supports the early detectionDetectionThe capability to identify suspicious activity, attacks, or policy violations in time. of suspicious activity. Achieving good results requires high-quality data sourcesData SourceA system, sensor, log, or repository that supplies data for security analysis and decisions., tuned detection logic, triage, and continuous optimizationContinuous OptimizationOngoing tuning of rules, processes, and resources using measured operational results..
How it works and where it fits
Deception Technology is a preventive, detective, or corrective security control. Its effect depends on where it sits in the architecture, which data and decisions it processes, and how it might be bypassed. A control reduces a defined risk but rarely removes it completely, so it should be combined with additional layers of protection.
Practical security relevance
Before deployment, the objective, ownership, coverage, and expected behavior should be defined. Secure defaults, controlled exceptions, logging, and periodic effectiveness tests matter more than installation alone. Operational metrics should expose both blocked or detected activity and gaps, false alerts, and effects on legitimate business processes.
Related concepts
- HoneypotHoneypotIntentionally exposed or simulated target used for the detection and analysis of attacks.: Intentionally exposed or simulated target used for the detection and analysis of attacks.
- Canary TokenCanary TokenMonitored artifact whose use signals potential unauthorized access.: Monitored artifact whose use signals potential unauthorized access.
- Threat HuntingThreat HuntingSearches for previously undetected attacker activity based on hypotheses.: Searches for previously undetected attacker activity based on hypotheses.
- Detection EngineeringDetection EngineeringSystematic development, testing, and maintenance of rules for attack detection.: Systematic development, testing, and maintenance of rules for attack detection.