Honeybug: Personalized cyber deception for web applications

Amirreza Niakanlahiji, Jafar Haadi Jafarian, Bei Tseng Chu, Ehab Al-Shaer

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

4 Scopus citations

Abstract

Cyber deception is used to reverse cyber warfare asymmetry by diverting adversaries to false targets in order to avoid their attacks, consume their resources, and potentially learn new attack tactics. In practice, effective cyber deception systems must be both attractive, to offer temptation for engagement, and believable, to convince unknown attackers to stay on the course. However, developing such a system is a highly challenging task because attackers have different expectations, expertise levels, and objectives. This makes a deception system with a static configuration only suitable for a specific type of attackers. In order to attract diverse types of attackers and prolong their engagement, we need to dynamically characterize every individual attacker's interactions with the deception system to learn their sophistication level and objectives and personalize the deception system to match with their profile and interest. In this paper, we present an adaptive deception system, called HoneyBug, that dynamically creates a personalized deception plan for web applications to match the attacker's expectation, which is learned by analyzing their behavior over time. Each HoneyBug plan exhibits fake vulnerabilities specifically selected based on the learned attacker's profile. Through evaluation, we show that HoneyBug characterization model can accurately characterize the attacker profile after observing only a few interactions and adapt its cyber deception plan accordingly. The HoneyBug characterization is built on top of a novel and generic evidential reasoning framework for attacker profiling, which is one of the focal contributions of this work.

Original languageEnglish
Title of host publicationProceedings of the 53rd Annual Hawaii International Conference on System Sciences, HICSS 2020
EditorsTung X. Bui
PublisherIEEE Computer Society
Pages1895-1904
Number of pages10
ISBN (Electronic)9780998133133
StatePublished - 2020
Externally publishedYes

Publication series

NameProceedings of the Annual Hawaii International Conference on System Sciences
Volume2020-January
ISSN (Print)1530-1605

Bibliographical note

Publisher Copyright:
© 2020 IEEE Computer Society. All rights reserved.

ASJC Scopus subject areas

  • General Engineering

Fingerprint

Dive into the research topics of 'Honeybug: Personalized cyber deception for web applications'. Together they form a unique fingerprint.

Cite this