Sludge for Good: Slowing and Imposing Costs on Cyber Attackers
Josiah Dykstra, Kelly Shortridge, Jamie Met, Douglas Hough

TL;DR
This paper proposes a novel cybersecurity strategy called the Sludge Strategy, which uses friction and deception to impose costs on attackers, complementing traditional defenses and enhancing overall security.
Contribution
It introduces the concept of using offensive sludge to consume attacker resources, detailing its characteristics, costs, and practical deployment considerations.
Findings
Effective sludge varies from light to heavy friction.
Real-world U.S. government examples demonstrate practical application.
Sludge can significantly increase attacker costs without harming victims.
Abstract
Choice architecture describes the design by which choices are presented to people. Nudges are an aspect intended to make "good" outcomes easy, such as using password meters to encourage strong passwords. Sludge, on the contrary, is friction that raises the transaction cost and is often seen as a negative to users. Turning this concept around, we propose applying sludge for positive cybersecurity outcomes by using it offensively to consume attackers' time and other resources. To date, most cyber defenses have been designed to be optimally strong and effective and prohibit or eliminate attackers as quickly as possible. Our complimentary approach is to also deploy defenses that seek to maximize the consumption of the attackers' time and other resources while causing as little damage as possible to the victim. This is consistent with zero trust and similar mindsets which assume breach.…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Advanced Malware Detection Techniques · Cybersecurity and Cyber Warfare Studies
