Farsighted Risk Mitigation of Lateral Movement Using Dynamic Cognitive Honeypots
Linan Huang, Quanyan Zhu

TL;DR
This paper introduces a dynamic cognitive honeypot strategy using a time-expanded network model to detect and mitigate lateral movement of threats, enhancing long-term security of enterprise networks.
Contribution
It proposes a novel time-expanded random network model and a dynamic honeypot policy to proactively reduce long-term vulnerability against persistent lateral threats.
Findings
Honeypots' stealthiness increases with random location changes.
The iterative algorithm efficiently approximates long-term vulnerability.
A critical threshold guides system parameter adjustments for improved security.
Abstract
Lateral movement of advanced persistent threats has posed a severe security challenge. Due to the stealthy and persistent nature of the lateral movement, defenders need to consider time and spatial locations holistically to discover latent attack paths across a large time-scale and achieve long-term security for the target assets. In this work, we propose a time-expanded random network to model the stochastic service links in the user-host enterprise network and the adversarial lateral movement. We design cognitive honeypots at idle production nodes and disguise honey links as service links to detect and deter the adversarial lateral movement. The location of the honeypot changes randomly at different times and increases the honeypots' stealthiness. Since the defender does not know whether, when, and where the initial intrusion and the lateral movement occur, the honeypot policy aims to…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Information and Cyber Security · Complex Network Analysis Techniques
