New CISA Guidance Helps Critical Infrastructure Detect, Observe and Impede Malicious Cyber Activity
WASHINGTON – Today, the Cybersecurity and Infrastructure Security Agency (CISA) released guidance that helps critical infrastructure owners and operators implement realistic decoy systems and information assets to quickly detect and disrupt malicious activity occurring in their networks, which will ultimately improve their cyber defenses. Using Cyber Decoys to Strengthen Detection and Response is the first guide from CISA that offers a detailed explanation of the defensive cyber decoy process.
Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land techniques to conduct discovery, move laterally, and access data. In this guide, CISA encourages critical infrastructure organizations to incorporate cyber decoy capabilities alongside existing Zero Trust models. Cyber decoy strategies operate on the expectation that malicious actors may eventually gain some level of access. By placing decoys within internal networks and systems, especially in high-value areas, organizations can enable defenders to:
- Detect adversaries operating within the environment early in the intrusion lifecycle;
- Gather and analyze information taken from intrusions and attempted intrusions;
- Allocate defensive resources more effectively based on observed adversary behaviors;
- Reduce mean time to detection (MTTD) by generating high-fidelity alerts.
“Cyber decoys used in a proactive cyber defense strategy help make critical infrastructure networks unfriendly places for adversaries and enhance resilience to compromise, even against living-off-the-land techniques,” said CISA Acting Executive Assistant Director for Cybersecurity Chris Butera. “With this guide, CISA is raising awareness of cyber decoy techniques and enabling any defensive team regardless of skill level to understand the value and steps to implementing decoy operations. CISA encourages critical infrastructure organizations to review this guide and implement a cyber decoy strategy.”
To effectively use this guide, cyber defenders should have a basic understanding of the MITRE ATT&CK ® Matrix and common enterprise security controls and tools. The guide provides a practical approach to designing and implementing decoy strategies by leveraging the MITRE ATT&CK® knowledge base and the MITRE Engage™ framework.
For more information, please visit Cybersecurity Best Practices.
###
About CISA
As the nation’s cyber defense agency and national coordinator for critical infrastructure security, the Cybersecurity and Infrastructure Security Agency leads the national effort to manage, uncover, and reduce risk to our digital and physical infrastructure Americans rely on every hour of every day.
Visit CISA.gov for more information and follow us on X, Facebook, LinkedIn, Instagram.
Fuente:
Leer la noticia original