2019
DOI: 10.24251/hicss.2019.874
|View full text |Cite
|
Sign up to set email alerts
|

The Tularosa Study: An Experimental Design and Implementation to Quantify the Effectiveness of Cyber Deception

Abstract: The Tularosa study was designed to understand how defensive deception-including both cyber and psychological-affects cyber attackers. Over 130 red teamers participated in a network penetration task over two days in which we controlled both the presence of and explicit mention of deceptive defensive techniques. To our knowledge, this represents the largest study of its kind ever conducted on a professional red team population. The design was conducted with a battery of questionnaires (e.g., experience, personal… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

1
40
0

Year Published

2019
2019
2022
2022

Publication Types

Select...
5
1
1

Relationship

0
7

Authors

Journals

citations
Cited by 35 publications
(41 citation statements)
references
References 28 publications
1
40
0
Order By: Relevance
“…With enough time spent interacting with such a system, an attacker may eventually care less about correctly identifying machines. Results from a similar study employing deception, which the authors also have access to (Ferguson-Walter et al, 2019), an attacker noted: Such an effect greatly improves the chances that a defensive team will detect and mitigate an attack. Biases in attacker decision-making can lead to psychologically motivated improvements in defense.…”
Section: Biases Exhibited and Observedmentioning
confidence: 99%
See 1 more Smart Citation
“…With enough time spent interacting with such a system, an attacker may eventually care less about correctly identifying machines. Results from a similar study employing deception, which the authors also have access to (Ferguson-Walter et al, 2019), an attacker noted: Such an effect greatly improves the chances that a defensive team will detect and mitigate an attack. Biases in attacker decision-making can lead to psychologically motivated improvements in defense.…”
Section: Biases Exhibited and Observedmentioning
confidence: 99%
“…No doubt all types of rigorous assessment of human performance in cyber operators remains important to conduct. We noted throughout that our assessment of biases here was exploratory; however, a new experiment (Ferguson-Walter et al, 2019) involving 138 professional red teamers will have biases assessed using an inter-rater system combining cyber and psychology SMEs.…”
Section: Disrupting Cyber Attacker Cognitionmentioning
confidence: 99%
“…Creating decoy systems with large numbers of false assets as opposed to real ones can reduce the ability of an attacker to successfully target a real asset through reducing their chances, distracting them from real assets, and forcing them to switch attention and perform additional tasks which, in turn, slows them down [4] [28]. Further benefits of decoy systems can be the improved detection of attackers from their engagement with false assets and increasing their level of confusion about the network's credibility [4].…”
Section: Background and Related Workmentioning
confidence: 99%
“…Further benefits of decoy systems can be the improved detection of attackers from their engagement with false assets and increasing their level of confusion about the network's credibility [4]. Decoy networks have been extensively tested through red-teaming experiments, including detailed exploration of red teamers' behaviour, personality and cognition, and physiological responses to cyber deception [28]. Use of host-based deception and deceptive messages has been shown in experiments to disrupt attacker decision-making, increase the time to conduct the deception and increase confusion within the attacker or attacking team [15].…”
Section: Background and Related Workmentioning
confidence: 99%
See 1 more Smart Citation