USENIX Security2021Top-tier venue
Examining the Efficacy of Decoy-based and Psychological Cyber Deception
Kimberly Ferguson-Walter, Maxine Major, Chelsea K. Johnson, Daniel H. Muhleman
Abstract
The threat of cyber attacks is a growing concern across the world, leading to an increasing need for sophisticated cyber defense techniques. Attackers often rely on direct observation of cyber environments. This reliance provides opportunities for defenders to affect attacker perception and behavior by plying the powerful tools of defensive cyber deception. In this paper we analyze data from a controlled experiment designed to understand how defensive deception, both cyber and psychological, affects attackers [16]. Over 130 professional red teamers participated in a network penetration test in which both the presence and explicit mention of deceptive defensive techniques were controlled. While a detailed description of the experimental design and execution along with preliminary results related to red teamer characteristics has been published, it did not address any of the main hypotheses. Granted access to the cyber and self-report data collected from the experiment, this publication begins to address theses hypotheses by investigating the effectiveness of decoy systems for cyber defense through comparison of various measures of participant forward progress across the four experimental conditions. Results presented in this paper support a new finding that the combination of the presence of decoys and providing information that deception is present has the greatest impact on cyber attack behavior, when compared to a control condition in which no deception was used.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2520b2f4-da1b-4797-8e81-b7368abe8253Cited by top-tier papers1
Ask how each one uses itBuilds on1
Related papers
- Explanations Help: Leveraging Human Capabilities to Detect Cyberattacks on Automated VehiclesYaohan Ding, Jun Ying, Yiheng Feng, Na DuCHI 2025 · 1 citation
- When Can the Defender Effectively Deceive Attackers in Security Games?Thanh Nguyen, Haifeng XuAAAI 2022 · 4 citations
- SoK: Come Together - Unifying Security, Information Theory, and Cognition for a Mixed Reality Deception Attack Ontology & Analysis FrameworkAli Teymourian, Andrew M. Webb, Taha Gharaibeh, Arushi Ghildiyal et al.USENIX Security 2025
- A Cloudified Dynamic Defense Framework for Cyber Deception as a ServiceYan Liu, Sujie Shao, Chao Yang, Shao-Yong Guo et al.INFOCOM 2026
- The Battle for New York: A Case Study of Applied Digital Threat Modeling at the Enterprise LevelRock Stevens, Daniel Votipka, Elissa M. Redmiles, Colin Ahern et al.USENIX Security 2018 · 51 citations
